Tagged “osv”
CVEs tagged osv, newest first.
5681 CVEsRSS
RUSTSEC-2026-0214Nonegumdrop is unmaintained
gumdrop is unmaintained
GO-2026-6019NoneSkipper: Incomplete fix for CVE-2026-50197: an oversized body can bypass OPA deny-on-presence Rego policies in github.com/zalando/skipper
Skipper: Incomplete fix for CVE-2026-50197: an oversized body can bypass OPA deny-on-presence Rego policies in github.com/zalando/skipper
GO-2026-6016Noneoapi-codegen: OpenAPI Server Description Escapes Generated Go Comment and Injects Executable Code in github.com/oapi-codegen/oapi-codegen
oapi-codegen: OpenAPI Server Description Escapes Generated Go Comment and Injects Executable Code in github.com/oapi-codegen/oapi-codegen
MAL-2026-10993NoneMalicious code in torch-musa (PyPI)
Malicious code in torch-musa (PyPI)
MAL-2026-10992NoneMalicious code in dev-helper-bg (PyPI)
Malicious code in dev-helper-bg (PyPI)
MAL-2026-10991NoneMalicious code in make-helper (PyPI)
Malicious code in make-helper (PyPI)
GHSA-h5v5-8746-g7mmMediumJupyterLab PluginManager lock-rule enforcement bypass
JupyterLab PluginManager lock-rule enforcement bypass
CVE-2026-64825Critical· 9.3Home Assistant Core vulnerable to Path Traversal via backup upload during onboarding
Home Assistant Core vulnerable to Path Traversal via backup upload during onboarding
CVE-2026-47143Medium· 5.9Capstone is a disassembly framework. Versions prior to 6.0.0-Alpha8 and 5.0.8 have a NULL pointer dereference in `modRMRequired()` and `d…
Capstone is a disassembly framework. Versions prior to 6.0.0-Alpha8 and 5.0.8 have a NULL pointer dereference in `modRMRequired()` and `decode()` when disassembling 3DNow! opcodes (`0F 0F`) in builds compiled with `-DCAPSTONE_X86_REDUCE`…
RUSTSEC-2026-0218None`Enum` trait allows type confusion when manually implemented
`Enum` trait allows type confusion when manually implemented
MAL-2026-10986NoneMalicious code in comp-colors (PyPI)
Malicious code in comp-colors (PyPI)
MAL-2026-10985NoneMalicious code in animated-octo-spoon (PyPI)
Malicious code in animated-octo-spoon (PyPI)
MAL-2026-10978NoneMalicious code in reimagined-broccoli (PyPI)
Malicious code in reimagined-broccoli (PyPI)
MAL-2026-10977NoneMalicious code in lebinfmt (PyPI)
Malicious code in lebinfmt (PyPI)
MAL-2026-10976NoneMalicious code in colorstack (PyPI)
Malicious code in colorstack (PyPI)
MAL-2026-10975NoneMalicious code in rasterkit-demo (PyPI)
Malicious code in rasterkit-demo (PyPI)
MAL-2026-10974NoneMalicious code in rasterkit (PyPI)
Malicious code in rasterkit (PyPI)
MAL-2026-10973NoneMalicious code in fluffy-octo-broccoli (PyPI)
Malicious code in fluffy-octo-broccoli (PyPI)
RUSTSEC-2026-0213NoneXSS in ammonia via SVG `animate` and `set` animation tags
XSS in ammonia via SVG `animate` and `set` animation tags
CVE-2026-46600High· 7.5golang.org/x/net/dns/dnsmessage: golang.org/x/net/dns/dnsmessage: Denial of Service via invalid DNS record parsing (CVE-2026-46600)
A flaw was found in golang.org/x/net/dns/dnsmessage. A remote attacker could send a specially crafted Service Binding (SVCB) or HTTPS resource record (RR) to a system using this component. When parsing this invalid record, the system may p…
CVE-2026-56657Medium· 6.2Gitea SSH Key Parser Denial of Service
Gitea SSH Key Parser Denial of Service
CVE-2026-58314High· 7.7Gitea: Two SSRF findings
Gitea: Two SSRF findings
CVE-2026-56443Medium· 4.3Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / …
Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118
CVE-2026-59890Medium· 6.1setuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization collision (NFC/NFD) on macOS APFS/HFS+
setuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization collision (NFC/NFD) on macOS APFS/HFS+
CVE-2026-59884High· 7.5pyasn1 BER/CER/DER decoder denial of service via unbounded long-form tag IDs
pyasn1 BER/CER/DER decoder denial of service via unbounded long-form tag IDs
MAL-2026-10930NoneMalicious code in trongridmy (PyPI)
Malicious code in trongridmy (PyPI)
MAL-2026-10929NoneMalicious code in trongrider (PyPI)
Malicious code in trongrider (PyPI)
MAL-2026-10927NoneMalicious code in roles-royce (PyPI)
Malicious code in roles-royce (PyPI)
MAL-2026-10926NoneMalicious code in defi-kit (PyPI)
Malicious code in defi-kit (PyPI)
MAL-2026-10919NoneMalicious code in ml-core-airflow-auth (PyPI)
Malicious code in ml-core-airflow-auth (PyPI)