VulnSea

Tagged “osv”

CVEs tagged osv, newest first.

5681 CVEsRSS

MAL-2026-11201None
2mo ago

Malicious code in ml-nps-shared (PyPI)

Malicious code in ml-nps-shared (PyPI)

▾ Sunlitml-nps-shared · ml-nps-sharedvia OSV
MAL-2026-11200None
2mo ago

Malicious code in ml-fdbk-shared (PyPI)

Malicious code in ml-fdbk-shared (PyPI)

▾ Sunlitml-fdbk-shared · ml-fdbk-sharedvia OSV
MAL-2026-11199None
2mo ago

Malicious code in ml-data-shared (PyPI)

Malicious code in ml-data-shared (PyPI)

▾ Sunlitml-data-shared · ml-data-sharedvia OSV
MAL-2026-11198None
2mo ago

Malicious code in mcp-search-server (PyPI)

Malicious code in mcp-search-server (PyPI)

▾ Sunlitmcp-search-server · mcp-search-servervia OSV
MAL-2026-11197None
2mo ago

Malicious code in ai-perf-toolkit (PyPI)

Malicious code in ai-perf-toolkit (PyPI)

▾ Sunlitai-perf-toolkit · ai-perf-toolkitvia OSV
MAL-2026-11195None
2mo ago

Malicious code in phabricator-client (PyPI)

Malicious code in phabricator-client (PyPI)

▾ Sunlitphabricator-client · phabricator-clientvia OSV
CVE-2026-13346Medium· 6.5
2mo ago

pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary locations on disk e…

pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary locations on disk even when installing wheels. This vulnerability requires downloading or installing a package from…

▾ Sunlitpip · pipEPSS 0.29%via OSV
RUSTSEC-2026-0257None
2mo ago

Unix `BROWSER` handling allows browser argument injection

Unix `BROWSER` handling allows browser argument injection

▾ Sunlitwebbrowser · webbrowservia OSV
CVE-2026-55415High· 7.5
2mo ago

datamodel-code-generator vulnerable to code injection via `x-python-import` / `customTypePath` in generated import statements

datamodel-code-generator vulnerable to code injection via `x-python-import` / `customTypePath` in generated import statements

▾ Twilightdatamodel-code-generator · datamodel-code-generatorEPSS 0.49%via OSV
CVE-2026-54690High· 8.2
2mo ago

datamodel-code-generator vulnerable to SSRF via JSON-Schema `$ref` to HTTP URL (silent by default)

datamodel-code-generator vulnerable to SSRF via JSON-Schema `$ref` to HTTP URL (silent by default)

▾ Twilightdatamodel-code-generator · datamodel-code-generatorEPSS 0.39%via OSV
CVE-2026-55391High· 7.5
2mo ago

datamodel-code-generator vulnerable to SSRF protection bypass via DNS rebinding

datamodel-code-generator vulnerable to SSRF protection bypass via DNS rebinding

▾ Twilightdatamodel-code-generator · datamodel-code-generatorEPSS 0.30%via OSV
CVE-2026-54653High· 8.8
2mo ago

`datamodel-code-generator` vulnerable to code injection in via attacker-controlled `default_factory` schema field

`datamodel-code-generator` vulnerable to code injection in via attacker-controlled `default_factory` schema field

▾ Twilightdatamodel-code-generator · datamodel-code-generatorEPSS 0.71%via OSV
CVE-2026-55389High· 7.5
2mo ago

datamodel-code-generator vulnerable to arbitrary local file read via JSON-Schema `$ref` (`file://` and `../` traversal), bypassing `--no-…

datamodel-code-generator vulnerable to arbitrary local file read via JSON-Schema `$ref` (`file://` and `../` traversal), bypassing `--no-allow-remote-refs`

▾ Twilightdatamodel-code-generator · datamodel-code-generatorEPSS 0.55%via OSV
CVE-2026-54654High· 7.8
2mo ago

`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in `--extra-template-data` `comment` field

`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in `--extra-template-data` `comment` field

▾ Twilightdatamodel-code-generator · datamodel-code-generatorEPSS 0.21%via OSV
CVE-2026-54691High· 8.2
2mo ago

datamodel-code-generator vulnerable to SSRF via --url: no host/IP validation, follows redirects

datamodel-code-generator vulnerable to SSRF via --url: no host/IP validation, follows redirects

▾ Twilightdatamodel-code-generator · datamodel-code-generatorEPSS 0.38%via OSV
CVE-2026-55403Low· 3.7
2mo ago

datamodel-code-generator: Authorization / request headers leaked to cross-origin redirect target when fetching remote schemas

datamodel-code-generator: Authorization / request headers leaked to cross-origin redirect target when fetching remote schemas

▾ Sunlitdatamodel-code-generator · datamodel-code-generatorEPSS 0.34%via OSV
CVE-2026-54621High· 7.8
2mo ago

`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in GraphQL Union description

`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in GraphQL Union description

▾ Twilightdatamodel-code-generator · datamodel-code-generatorEPSS 0.21%via OSV
MAL-2026-11156None
2mo ago

Malicious code in vtranalytic (PyPI)

Malicious code in vtranalytic (PyPI)

▾ Sunlitvtranalytic · vtranalyticvia OSV
CVE-2026-54345Medium
2mo ago

GoPacket's Diameter AVP decoder: uint32 underflow on vendor header size leads to unbounded ~4 GiB allocation (unauthenticated remote DoS)

GoPacket's Diameter AVP decoder: uint32 underflow on vendor header size leads to unbounded ~4 GiB allocation (unauthenticated remote DoS)

▾ Sunlitgopacket · github.com/gopacket/gopacketEPSS 0.79%via OSV
CVE-2026-66053Medium· 5.9
2mo ago

Apache Thrift Python bindings have a Improper Validation of Certificate with Host Mismatch vulnerabilit

Apache Thrift Python bindings have a Improper Validation of Certificate with Host Mismatch vulnerabilit

▾ Sunlitthrift · thriftEPSS 0.29%via OSV
CVE-2026-43871High· 7.5
2mo ago

thrift: Apache Thrift: Denial of Service via infinite loop (CVE-2026-43871)

A flaw was found in Apache Thrift, affecting its Python, Go, PHP, and Java components. This vulnerability, known as an 'Infinite Loop', could allow a remote attacker to disrupt service availability. By exploiting this flaw, an attacker can…

▾ TwilightRed Hat · Red Hat Hardened ImagesEPSS 1.0%via CSAF
CVE-2026-41608High· 7.5
2mo ago

Apache Thrift Python bindings have an Improper Handling of Highly Compressed Data (Data Amplification) vulnerability

Apache Thrift Python bindings have an Improper Handling of Highly Compressed Data (Data Amplification) vulnerability

▾ Twilightthrift · thriftEPSS 1.0%via OSV
MAL-2026-11094None
2mo ago

Malicious code in cfgzen (PyPI)

Malicious code in cfgzen (PyPI)

▾ Sunlitcfgzen · cfgzenvia OSV
GO-2026-6074None
2mo ago

Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea

Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea

▾ Sunlitgitea · code.gitea.io/giteavia OSV
GO-2026-6061None
2mo ago

Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc

Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc

▾ Sunlitgrpc · google.golang.org/grpcvia OSV
GO-2026-5841None
2mo ago

OOB read in github.com/klauspost/compress/s2

OOB read in github.com/klauspost/compress/s2

▾ Sunlitklauspost · github.com/klauspost/compressvia OSV
GO-2026-5781None
2mo ago

Uncatchable stack-overflow denial of service in rsc.io/pdf

Uncatchable stack-overflow denial of service in rsc.io/pdf

▾ Sunlitpdf · rsc.io/pdfvia OSV
GO-2026-5051None
2mo ago

Out-of-bounds read and panic in ReadDir in github.com/cloudsoda/go-smb2 and github.com/hirochachacha/go-smb2

Out-of-bounds read and panic in ReadDir in github.com/cloudsoda/go-smb2 and github.com/hirochachacha/go-smb2

▾ Sunlitcloudsoda · github.com/cloudsoda/go-smb2via OSV
GO-2026-5048None
2mo ago

Denial of service via unbounded map allocations in github.com/iskorotkov/avro/v2 and github.com/hamba/avro/v2

Denial of service via unbounded map allocations in github.com/iskorotkov/avro/v2 and github.com/hamba/avro/v2

▾ Sunlitiskorotkov · github.com/iskorotkov/avro/v2via OSV
RUSTSEC-2026-0219High· 7.5
2mo ago

Remote Denial of Service via malformed NIP-04 IV

Remote Denial of Service via malformed NIP-04 IV

▾ Twilightnostr · nostrvia OSV
CVEs tagged “osv” — page 35 · VulnSea