Tagged “osv”
CVEs tagged osv, newest first.
5681 CVEsRSS
CVE-2026-67338Medium· 6.1JupyterLab before 4.5.9 contains a stored cross-site scripting vulnerability in the Extension Manager that fails to validate URI protocols in package metadata URLs
JupyterLab before 4.5.9 contains a stored cross-site scripting vulnerability in the Extension Manager that fails to validate URI protocols in package metadata URLs. Attackers can publish malicious PyPI packages with javascript: URLs in p…
CVE-2026-67326High· 7.0GitPython before 3.1.50 fails to validate newline characters in the section parameter of config_writer(), allowing attackers to inject arbitrary section headers into .git/config
GitPython before 3.1.50 fails to validate newline characters in the section parameter of config_writer(), allowing attackers to inject arbitrary section headers into .git/config. Attackers can inject newlines to create a forged [core] se…
CVE-2026-67325High· 8.8GitPython before 3.1.51 contains an incomplete command injection blocklist that fails to account for git's long-option prefix abbreviation feature
GitPython before 3.1.51 contains an incomplete command injection blocklist that fails to account for git's long-option prefix abbreviation feature. Attackers can bypass the unsafe options guard by using abbreviated option names like uplo…
CVE-2026-67324Critical· 9.8GitPython 3.1.50 fails to recognize joined short-option forms such as -u<value> (the short form of --upload-pack=<value>) when enforcing its default unsafe-option gate
GitPython 3.1.50 fails to recognize joined short-option forms such as -u<value> (the short form of --upload-pack=<value>) when enforcing its default unsafe-option gate. When an application passes attacker-influenced clone options into Re…
CVE-2026-67323High· 8.4GitPython before 3.1.51 fails to guard against dangerous Git options passed as keyword arguments in Repo.archive() and git.ls_remote(), allowing command injection via options such as --exec/--upload-pack (leading to arbitrary command exe…
GitPython before 3.1.51 fails to guard against dangerous Git options passed as keyword arguments in Repo.archive() and git.ls_remote(), allowing command injection via options such as --exec/--upload-pack (leading to arbitrary command exe…
CVE-2026-67322High· 7.5GitPython before 3.1.52 is vulnerable to environment-variable exfiltration in Repo.clone_from()
GitPython before 3.1.52 is vulnerable to environment-variable exfiltration in Repo.clone_from(). The caller-supplied remote URL is passed through Git.polish_url(), which on non-Cygwin platforms calls os.path.expandvars() on the URL befor…
RUSTSEC-2026-0224High· 7.5Verification cache poisoning allows forged Nostr events to bypass signature validation
Verification cache poisoning allows forged Nostr events to bypass signature validation
MAL-2026-11426NoneMalicious code in trtllm-subdir-test (PyPI)
Malicious code in trtllm-subdir-test (PyPI)
MAL-2026-11425NoneMalicious code in nvtorch-oot-nightly (PyPI)
Malicious code in nvtorch-oot-nightly (PyPI)
MAL-2026-11424NoneMalicious code in telerape (PyPI)
Malicious code in telerape (PyPI)
MAL-2026-11423NoneMalicious code in asdk-plugin-legacy (PyPI)
Malicious code in asdk-plugin-legacy (PyPI)
MAL-2026-11422NoneMalicious code in asdk-plugin-alphagen (PyPI)
Malicious code in asdk-plugin-alphagen (PyPI)
MAL-2026-11421NoneMalicious code in asdk-plugin-ai-platform (PyPI)
Malicious code in asdk-plugin-ai-platform (PyPI)
CVE-2026-54909Medium· 5.3Pion STUN vulnerable to remote denial of service via panic while parsing a malformed XOR-MAPPED-ADDRESS attribute
Pion STUN vulnerable to remote denial of service via panic while parsing a malformed XOR-MAPPED-ADDRESS attribute
RUSTSEC-2026-0223NonePreemption and traps during bulk operations enable breaking internal VM state
Preemption and traps during bulk operations enable breaking internal VM state
RUSTSEC-2026-0222Low· 3.8Stores can mix up type indices between engines
Stores can mix up type indices between engines
MAL-2026-11420NoneMalicious code in walmart-genai-trace (PyPI)
Malicious code in walmart-genai-trace (PyPI)
MAL-2026-11419NoneMalicious code in cognikit (PyPI)
Malicious code in cognikit (PyPI)
MAL-2026-11418NoneMalicious code in catalogai (PyPI)
Malicious code in catalogai (PyPI)
MAL-2026-11417NoneMalicious code in aiprepkit (PyPI)
Malicious code in aiprepkit (PyPI)
MAL-2026-11416NoneMalicious code in ailaunchkit (PyPI)
Malicious code in ailaunchkit (PyPI)
MAL-2026-11415NoneMalicious code in aichannel (PyPI)
Malicious code in aichannel (PyPI)
MAL-2026-11414NoneMalicious code in aiassistcore (PyPI)
Malicious code in aiassistcore (PyPI)
MAL-2026-11413NoneMalicious code in reguestsc (PyPI)
Malicious code in reguestsc (PyPI)
CVE-2026-12074High· 7.5Natural Language Toolkit (NLTK) has path traversal in FramenetCorpusReader.frame() that allows arbitrary XML file read, bypassing the nlt…
Natural Language Toolkit (NLTK) has path traversal in FramenetCorpusReader.frame() that allows arbitrary XML file read, bypassing the nltk.pathsec sandbox (ENFORCE=True)
CVE-2026-12072High· 7.5Natural Language Toolkit (NLTK): Path Traversal in NKJPCorpusReader leads to Arbitrary File Read and bypasses the nltk.pathsec sandbox (E…
Natural Language Toolkit (NLTK): Path Traversal in NKJPCorpusReader leads to Arbitrary File Read and bypasses the nltk.pathsec sandbox (ENFORCE=True)
CVE-2026-12061High· 7.5Natural Language Toolkit (NLTK): ReDoS in NLTK ReviewsCorpusReader FEATURES regex
Natural Language Toolkit (NLTK): ReDoS in NLTK ReviewsCorpusReader FEATURES regex
CVE-2026-12075High· 8.6Natural Language Toolkit (NLTK): DNS-rebinding SSRF filter bypass in nltk.pathsec.urlopen (nltk.download / nltk.data.load) defeats ENFORC…
Natural Language Toolkit (NLTK): DNS-rebinding SSRF filter bypass in nltk.pathsec.urlopen (nltk.download / nltk.data.load) defeats ENFORCE mode
CVE-2026-59881Medium· 5.3aiohttp: AIOHTTP: Denial of Service via unnegotiated WebSocket compression (CVE-2026-59881)
A flaw was found in AIOHTTP. The WebSocket client in AIOHTTP processes compressed data frames even when the compression mechanism, known as permessage-deflate, has not been properly negotiated. A malicious server can exploit this by sendin…
MAL-2026-11202NoneMalicious code in ml-shared (PyPI)
Malicious code in ml-shared (PyPI)