Tagged “osv”
CVEs tagged osv, newest first.
5683 CVEsRSS
MAL-2026-11068NoneMalicious code in random-ua-generator (PyPI)
Malicious code in random-ua-generator (PyPI)
RUSTSEC-2026-0216High· 7.5Remote Denial of Service via malformed NIP‑44 v2 payload
Remote Denial of Service via malformed NIP‑44 v2 payload
MAL-2026-11067NoneMalicious code in blessclient (PyPI)
Malicious code in blessclient (PyPI)
CVE-2026-66007Medium· 6.5datasets: Datasets: Information disclosure via path traversal vulnerability (CVE-2026-66007)
A flaw was found in datasets. This path traversal vulnerability allows a remote attacker to read arbitrary local files. By providing specially crafted file names in the metadata, an attacker can trick the system into including sensitive lo…
CVE-2026-73622High· 7.5GitPython: Environment-variable exfiltration via Repo.create_remote() / Remote.add() URL (incomplete fix of GHSA-rwj8-pgh3-r573)
GitPython: Environment-variable exfiltration via Repo.create_remote() / Remote.add() URL (incomplete fix of GHSA-rwj8-pgh3-r573)
CVE-2025-71408High· 7.8NLTK (Natural Language Toolkit) before version 3.9.3 contains an eval injection vulnerability in the nltk.collocations module that allows an attacker who controls command-line arguments to execute arbitrary Python code
NLTK (Natural Language Toolkit) before version 3.9.3 contains an eval injection vulnerability in the nltk.collocations module that allows an attacker who controls command-line arguments to execute arbitrary Python code. When collocations…
GO-2026-5884NoneORAS Go forwards registry credentials across registry redirects in oras.land/oras-go
ORAS Go forwards registry credentials across registry redirects in oras.land/oras-go
GO-2026-5777NoneChi's RealIP Middleware allows IP spoofing via unvalidated X-Forwarded-For header in github.com/go-chi/chi
Chi's RealIP Middleware allows IP spoofing via unvalidated X-Forwarded-For header in github.com/go-chi/chi
GO-2026-5775NoneChi Middleware vulnerable to IP spoofing via X-Forwarded-For header in github.com/go-chi/chi
Chi Middleware vulnerable to IP spoofing via X-Forwarded-For header in github.com/go-chi/chi
GO-2026-5774NoneChi has an IP spoofing vulnerability in middleware.RealIP in github.com/go-chi/chi
Chi has an IP spoofing vulnerability in middleware.RealIP in github.com/go-chi/chi
GO-2026-5730NoneCaddy CVE-2026-30852 Fix Bypass in github.com/caddyserver/caddy
Caddy CVE-2026-30852 Fix Bypass in github.com/caddyserver/caddy
GO-2026-5693NoneGo-git: Malformed Git object data may cause panics or resource exhaustion in github.com/go-git/go-git
Go-git: Malformed Git object data may cause panics or resource exhaustion in github.com/go-git/go-git
GO-2026-5408NoneCaddy: Remote Admin Authorization Bypass on PKI Endpoints via Prefix-Based Path Matching in github.com/caddyserver/caddy
Caddy: Remote Admin Authorization Bypass on PKI Endpoints via Prefix-Based Path Matching in github.com/caddyserver/caddy
MAL-2026-11051NoneMalicious code in trongridy (PyPI)
Malicious code in trongridy (PyPI)
MAL-2026-11050NoneMalicious code in discordnv (PyPI)
Malicious code in discordnv (PyPI)
MAL-2026-11049NoneMalicious code in mrmustard (PyPI)
Malicious code in mrmustard (PyPI)
MAL-2026-11048NoneMalicious code in karpatkit (PyPI)
Malicious code in karpatkit (PyPI)
MAL-2026-11047NoneMalicious code in karpatkey (PyPI)
Malicious code in karpatkey (PyPI)
MAL-2026-11046NoneMalicious code in intel-cicd-repo-infrastructure (PyPI)
Malicious code in intel-cicd-repo-infrastructure (PyPI)
GHSA-464c-974j-9xm6Low· 3.3AWS CDK CodeBuild S3 Log Encryption Boolean Inversion
AWS CDK CodeBuild S3 Log Encryption Boolean Inversion
CVE-2026-13769Medium· 5.5AWS CLI: Overly permissive File Permissions
AWS CLI: Overly permissive File Permissions
CVE-2026-61632Medium· 5.3PyMdown Extensions: Path traversal in the b64 extension lets <img src> read files outside base_path
PyMdown Extensions: Path traversal in the b64 extension lets <img src> read files outside base_path
CVE-2026-44210Critical· 9.9kata-containers: Kata Containers: Privilege escalation and information disclosure via command-line argument injection (CVE-2026-44210)
A flaw was found in Kata Containers, an open-source project that provides lightweight virtual machines (VMs) for containers. A user with privileges to create pods can inject malicious command-line arguments into the virtiofsd process, whic…
CVE-2026-25800High· 7.5quinn: Quinn: Remote memory exhaustion via malformed QUIC stream fragments (CVE-2026-25800)
A flaw was found in Quinn, a Rust implementation of the QUIC transport protocol. A remote attacker can exploit this vulnerability by sending specially crafted QUIC stream fragments with many gaps. This can lead to high buffer overhead in t…
MAL-2026-11031NoneMalicious code in govapkg (PyPI)
Malicious code in govapkg (PyPI)
CVE-2026-59936Highpypdf: Possible infinite loop for not terminated inline images
pypdf: Possible infinite loop for not terminated inline images
CVE-2026-59935Highpypdf: Possible infinite loop for not terminated inline images (ASCII85 and ASCIIHex filter)
pypdf: Possible infinite loop for not terminated inline images (ASCII85 and ASCIIHex filter)
CVE-2026-59938Mediumpypdf: Possible large memory usage for wrong image dimensions
pypdf: Possible large memory usage for wrong image dimensions
CVE-2026-59937Mediumpypdf: Possible long runtimes for repeated malformed cross-reference entries
pypdf: Possible long runtimes for repeated malformed cross-reference entries
RUSTSEC-2026-0215Nonesmallstr is unmaintained
smallstr is unmaintained