VulnSea

Tagged “osv”

CVEs tagged osv, newest first.

5683 CVEsRSS

MAL-2026-11068None
2mo ago

Malicious code in random-ua-generator (PyPI)

Malicious code in random-ua-generator (PyPI)

▾ Sunlitrandom-ua-generator · random-ua-generatorvia OSV
RUSTSEC-2026-0216High· 7.5
2mo ago

Remote Denial of Service via malformed NIP‑44 v2 payload

Remote Denial of Service via malformed NIP‑44 v2 payload

▾ Twilightnostr · nostrvia OSV
MAL-2026-11067None
2mo ago

Malicious code in blessclient (PyPI)

Malicious code in blessclient (PyPI)

▾ Sunlitblessclient · blessclientvia OSV
CVE-2026-66007Medium· 6.5
2mo ago

datasets: Datasets: Information disclosure via path traversal vulnerability (CVE-2026-66007)

A flaw was found in datasets. This path traversal vulnerability allows a remote attacker to read arbitrary local files. By providing specially crafted file names in the metadata, an attacker can trick the system into including sensitive lo…

▾ SunlitRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.79%via CSAF
CVE-2026-73622High· 7.5
2mo ago

GitPython: Environment-variable exfiltration via Repo.create_remote() / Remote.add() URL (incomplete fix of GHSA-rwj8-pgh3-r573)

GitPython: Environment-variable exfiltration via Repo.create_remote() / Remote.add() URL (incomplete fix of GHSA-rwj8-pgh3-r573)

▾ Twilightgitpython · gitpythonEPSS 0.51%via OSV
CVE-2025-71408High· 7.8
2mo ago

NLTK (Natural Language Toolkit) before version 3.9.3 contains an eval injection vulnerability in the nltk.collocations module that allows an attacker who controls command-line arguments to execute arbitrary Python code

NLTK (Natural Language Toolkit) before version 3.9.3 contains an eval injection vulnerability in the nltk.collocations module that allows an attacker who controls command-line arguments to execute arbitrary Python code. When collocations…

▾ Twilightnltk · nltkEPSS 0.27%via NVD
GO-2026-5884None
2mo ago

ORAS Go forwards registry credentials across registry redirects in oras.land/oras-go

ORAS Go forwards registry credentials across registry redirects in oras.land/oras-go

▾ Sunlitoras-go · oras.land/oras-go/v2via OSV
GO-2026-5777None
2mo ago

Chi's RealIP Middleware allows IP spoofing via unvalidated X-Forwarded-For header in github.com/go-chi/chi

Chi's RealIP Middleware allows IP spoofing via unvalidated X-Forwarded-For header in github.com/go-chi/chi

▾ Sunlitgo-chi · github.com/go-chi/chi/v5via OSV
GO-2026-5775None
2mo ago

Chi Middleware vulnerable to IP spoofing via X-Forwarded-For header in github.com/go-chi/chi

Chi Middleware vulnerable to IP spoofing via X-Forwarded-For header in github.com/go-chi/chi

▾ Sunlitgo-chi · github.com/go-chi/chi/v5via OSV
GO-2026-5774None
2mo ago

Chi has an IP spoofing vulnerability in middleware.RealIP in github.com/go-chi/chi

Chi has an IP spoofing vulnerability in middleware.RealIP in github.com/go-chi/chi

▾ Sunlitgo-chi · github.com/go-chi/chi/v5via OSV
GO-2026-5730None
2mo ago

Caddy CVE-2026-30852 Fix Bypass in github.com/caddyserver/caddy

Caddy CVE-2026-30852 Fix Bypass in github.com/caddyserver/caddy

▾ Sunlitcaddyserver · github.com/caddyserver/caddy/v2via OSV
GO-2026-5693None
2mo ago

Go-git: Malformed Git object data may cause panics or resource exhaustion in github.com/go-git/go-git

Go-git: Malformed Git object data may cause panics or resource exhaustion in github.com/go-git/go-git

▾ Sunlitgo-git · github.com/go-git/go-git/v5via OSV
GO-2026-5408None
2mo ago

Caddy: Remote Admin Authorization Bypass on PKI Endpoints via Prefix-Based Path Matching in github.com/caddyserver/caddy

Caddy: Remote Admin Authorization Bypass on PKI Endpoints via Prefix-Based Path Matching in github.com/caddyserver/caddy

▾ Sunlitcaddyserver · github.com/caddyserver/caddy/v2via OSV
MAL-2026-11051None
2mo ago

Malicious code in trongridy (PyPI)

Malicious code in trongridy (PyPI)

▾ Sunlittrongridy · trongridyvia OSV
MAL-2026-11050None
2mo ago

Malicious code in discordnv (PyPI)

Malicious code in discordnv (PyPI)

▾ Sunlitdiscordnv · discordnvvia OSV
MAL-2026-11049None
2mo ago

Malicious code in mrmustard (PyPI)

Malicious code in mrmustard (PyPI)

▾ Sunlitmrmustard · mrmustardvia OSV
MAL-2026-11048None
2mo ago

Malicious code in karpatkit (PyPI)

Malicious code in karpatkit (PyPI)

▾ Sunlitkarpatkit · karpatkitvia OSV
MAL-2026-11047None
2mo ago

Malicious code in karpatkey (PyPI)

Malicious code in karpatkey (PyPI)

▾ Sunlitkarpatkey · karpatkeyvia OSV
MAL-2026-11046None
2mo ago

Malicious code in intel-cicd-repo-infrastructure (PyPI)

Malicious code in intel-cicd-repo-infrastructure (PyPI)

▾ Sunlitintel-cicd-repo-infrastructure · intel-cicd-repo-infrastructurevia OSV
GHSA-464c-974j-9xm6Low· 3.3
2mo ago

AWS CDK CodeBuild S3 Log Encryption Boolean Inversion

AWS CDK CodeBuild S3 Log Encryption Boolean Inversion

▾ Sunlitaws-cdk-lib · aws-cdk-libvia OSV
CVE-2026-13769Medium· 5.5
2mo ago

AWS CLI: Overly permissive File Permissions

AWS CLI: Overly permissive File Permissions

▾ Sunlitawscli · awscliEPSS 0.16%via OSV
CVE-2026-61632Medium· 5.3
2mo ago

PyMdown Extensions: Path traversal in the b64 extension lets <img src> read files outside base_path

PyMdown Extensions: Path traversal in the b64 extension lets <img src> read files outside base_path

▾ Sunlitpymdown-extensions · pymdown-extensionsEPSS 0.40%via OSV
CVE-2026-44210Critical· 9.9
2mo ago

kata-containers: Kata Containers: Privilege escalation and information disclosure via command-line argument injection (CVE-2026-44210)

A flaw was found in Kata Containers, an open-source project that provides lightweight virtual machines (VMs) for containers. A user with privileges to create pods can inject malicious command-line arguments into the virtiofsd process, whic…

▾ MidnightRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.59%via CSAF
CVE-2026-25800High· 7.5
2mo ago

quinn: Quinn: Remote memory exhaustion via malformed QUIC stream fragments (CVE-2026-25800)

A flaw was found in Quinn, a Rust implementation of the QUIC transport protocol. A remote attacker can exploit this vulnerability by sending specially crafted QUIC stream fragments with many gaps. This can lead to high buffer overhead in t…

▾ TwilightRed Hat · quinn-protoEPSS 0.84%via CSAF
MAL-2026-11031None
2mo ago

Malicious code in govapkg (PyPI)

Malicious code in govapkg (PyPI)

▾ Sunlitgovapkg · govapkgvia OSV
CVE-2026-59936High
2mo ago

pypdf: Possible infinite loop for not terminated inline images

pypdf: Possible infinite loop for not terminated inline images

▾ Twilightpypdf · pypdfEPSS 0.62%via OSV
CVE-2026-59935High
2mo ago

pypdf: Possible infinite loop for not terminated inline images (ASCII85 and ASCIIHex filter)

pypdf: Possible infinite loop for not terminated inline images (ASCII85 and ASCIIHex filter)

▾ Twilightpypdf · pypdfEPSS 0.62%via OSV
CVE-2026-59938Medium
2mo ago

pypdf: Possible large memory usage for wrong image dimensions

pypdf: Possible large memory usage for wrong image dimensions

▾ Sunlitpypdf · pypdfEPSS 0.52%via OSV
CVE-2026-59937Medium
2mo ago

pypdf: Possible long runtimes for repeated malformed cross-reference entries

pypdf: Possible long runtimes for repeated malformed cross-reference entries

▾ Sunlitpypdf · pypdfEPSS 0.62%via OSV
RUSTSEC-2026-0215None
2mo ago

smallstr is unmaintained

smallstr is unmaintained

▾ Sunlitsmallstr · smallstrvia OSV
CVEs tagged “osv” — page 36 · VulnSea