Tagged “osv”
CVEs tagged osv, newest first.
5681 CVEsRSS
MAL-2026-11201NoneMalicious code in ml-nps-shared (PyPI)
Malicious code in ml-nps-shared (PyPI)
MAL-2026-11200NoneMalicious code in ml-fdbk-shared (PyPI)
Malicious code in ml-fdbk-shared (PyPI)
MAL-2026-11199NoneMalicious code in ml-data-shared (PyPI)
Malicious code in ml-data-shared (PyPI)
MAL-2026-11198NoneMalicious code in mcp-search-server (PyPI)
Malicious code in mcp-search-server (PyPI)
MAL-2026-11197NoneMalicious code in ai-perf-toolkit (PyPI)
Malicious code in ai-perf-toolkit (PyPI)
MAL-2026-11195NoneMalicious code in phabricator-client (PyPI)
Malicious code in phabricator-client (PyPI)
CVE-2026-13346Medium· 6.5pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary locations on disk e…
pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary locations on disk even when installing wheels. This vulnerability requires downloading or installing a package from…
RUSTSEC-2026-0257NoneUnix `BROWSER` handling allows browser argument injection
Unix `BROWSER` handling allows browser argument injection
CVE-2026-55415High· 7.5datamodel-code-generator vulnerable to code injection via `x-python-import` / `customTypePath` in generated import statements
datamodel-code-generator vulnerable to code injection via `x-python-import` / `customTypePath` in generated import statements
CVE-2026-54690High· 8.2datamodel-code-generator vulnerable to SSRF via JSON-Schema `$ref` to HTTP URL (silent by default)
datamodel-code-generator vulnerable to SSRF via JSON-Schema `$ref` to HTTP URL (silent by default)
CVE-2026-55391High· 7.5datamodel-code-generator vulnerable to SSRF protection bypass via DNS rebinding
datamodel-code-generator vulnerable to SSRF protection bypass via DNS rebinding
CVE-2026-54653High· 8.8`datamodel-code-generator` vulnerable to code injection in via attacker-controlled `default_factory` schema field
`datamodel-code-generator` vulnerable to code injection in via attacker-controlled `default_factory` schema field
CVE-2026-55389High· 7.5datamodel-code-generator vulnerable to arbitrary local file read via JSON-Schema `$ref` (`file://` and `../` traversal), bypassing `--no-…
datamodel-code-generator vulnerable to arbitrary local file read via JSON-Schema `$ref` (`file://` and `../` traversal), bypassing `--no-allow-remote-refs`
CVE-2026-54654High· 7.8`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in `--extra-template-data` `comment` field
`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in `--extra-template-data` `comment` field
CVE-2026-54691High· 8.2datamodel-code-generator vulnerable to SSRF via --url: no host/IP validation, follows redirects
datamodel-code-generator vulnerable to SSRF via --url: no host/IP validation, follows redirects
CVE-2026-55403Low· 3.7datamodel-code-generator: Authorization / request headers leaked to cross-origin redirect target when fetching remote schemas
datamodel-code-generator: Authorization / request headers leaked to cross-origin redirect target when fetching remote schemas
CVE-2026-54621High· 7.8`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in GraphQL Union description
`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in GraphQL Union description
MAL-2026-11156NoneMalicious code in vtranalytic (PyPI)
Malicious code in vtranalytic (PyPI)
CVE-2026-54345MediumGoPacket's Diameter AVP decoder: uint32 underflow on vendor header size leads to unbounded ~4 GiB allocation (unauthenticated remote DoS)
GoPacket's Diameter AVP decoder: uint32 underflow on vendor header size leads to unbounded ~4 GiB allocation (unauthenticated remote DoS)
CVE-2026-66053Medium· 5.9Apache Thrift Python bindings have a Improper Validation of Certificate with Host Mismatch vulnerabilit
Apache Thrift Python bindings have a Improper Validation of Certificate with Host Mismatch vulnerabilit
CVE-2026-43871High· 7.5thrift: Apache Thrift: Denial of Service via infinite loop (CVE-2026-43871)
A flaw was found in Apache Thrift, affecting its Python, Go, PHP, and Java components. This vulnerability, known as an 'Infinite Loop', could allow a remote attacker to disrupt service availability. By exploiting this flaw, an attacker can…
CVE-2026-41608High· 7.5Apache Thrift Python bindings have an Improper Handling of Highly Compressed Data (Data Amplification) vulnerability
Apache Thrift Python bindings have an Improper Handling of Highly Compressed Data (Data Amplification) vulnerability
MAL-2026-11094NoneMalicious code in cfgzen (PyPI)
Malicious code in cfgzen (PyPI)
GO-2026-6074NoneGitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
GO-2026-6061NoneVulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc
Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc
GO-2026-5841NoneOOB read in github.com/klauspost/compress/s2
OOB read in github.com/klauspost/compress/s2
GO-2026-5781NoneUncatchable stack-overflow denial of service in rsc.io/pdf
Uncatchable stack-overflow denial of service in rsc.io/pdf
GO-2026-5051NoneOut-of-bounds read and panic in ReadDir in github.com/cloudsoda/go-smb2 and github.com/hirochachacha/go-smb2
Out-of-bounds read and panic in ReadDir in github.com/cloudsoda/go-smb2 and github.com/hirochachacha/go-smb2
GO-2026-5048NoneDenial of service via unbounded map allocations in github.com/iskorotkov/avro/v2 and github.com/hamba/avro/v2
Denial of service via unbounded map allocations in github.com/iskorotkov/avro/v2 and github.com/hamba/avro/v2
RUSTSEC-2026-0219High· 7.5Remote Denial of Service via malformed NIP-04 IV
Remote Denial of Service via malformed NIP-04 IV