Tagged “osv”
CVEs tagged osv, newest first.
5681 CVEsRSS
MAL-2026-10918NoneMalicious code in automatic-octo-invention (PyPI)
Malicious code in automatic-octo-invention (PyPI)
MAL-2026-10912NoneMalicious code in shark-e2e-bnsneo (PyPI)
Malicious code in shark-e2e-bnsneo (PyPI)
MAL-2026-10911NoneMalicious code in mysuperlicense (PyPI)
Malicious code in mysuperlicense (PyPI)
MAL-2026-10910NoneMalicious code in mysupergoodpython (PyPI)
Malicious code in mysupergoodpython (PyPI)
MAL-2026-10909NoneMalicious code in ibreak (PyPI)
Malicious code in ibreak (PyPI)
MAL-2026-10908NoneMalicious code in hello-world-test-mh3 (PyPI)
Malicious code in hello-world-test-mh3 (PyPI)
MAL-2026-10907NoneMalicious code in hello-world-test-mh2 (PyPI)
Malicious code in hello-world-test-mh2 (PyPI)
CVE-2026-59198Medium· 6.5Pillow TGA RLE encoder can serialize up to ~57 KB of adjacent heap data into generated images
Pillow TGA RLE encoder can serialize up to ~57 KB of adjacent heap data into generated images
MAL-2026-10869NoneMalicious code in paperclip-ai (PyPI)
Malicious code in paperclip-ai (PyPI)
MAL-2026-10868NoneMalicious code in neroteam-v1 (PyPI)
Malicious code in neroteam-v1 (PyPI)
MAL-2026-10867NoneMalicious code in vantrala (PyPI)
Malicious code in vantrala (PyPI)
MAL-2026-10866NoneMalicious code in nemopush (PyPI)
Malicious code in nemopush (PyPI)
MAL-2026-10865NoneMalicious code in kimitalk (PyPI)
Malicious code in kimitalk (PyPI)
MAL-2026-10864NoneMalicious code in kimichat (PyPI)
Malicious code in kimichat (PyPI)
MAL-2026-10863NoneMalicious code in telebot-bot-run (PyPI)
Malicious code in telebot-bot-run (PyPI)
CVE-2026-59203Medium· 5.3Pillow EpsImagePlugin negative %%BeginBinary byte count causes infinite loop denial of service
Pillow EpsImagePlugin negative %%BeginBinary byte count causes infinite loop denial of service
CVE-2026-55514High· 6.5vLLM denial of service via prompt embeds on M-RoPE models
vLLM denial of service via prompt embeds on M-RoPE models
CVE-2026-55798Medium· 4.5Pillow: WindowsViewer.get_command() OS command injection via unescaped shell path
Pillow: WindowsViewer.get_command() OS command injection via unescaped shell path
CVE-2026-54059High· 7.5Pillow `PcfFontFile._load_bitmaps()`: `Image.frombytes()` called without `_decompression_bomb_check()` — bomb protection bypass via PCF f…
Pillow `PcfFontFile._load_bitmaps()`: `Image.frombytes()` called without `_decompression_bomb_check()` — bomb protection bypass via PCF font loading
CVE-2026-12484High· 7.8Keras: TorchModuleWrapper can deserialize unsafe PyTorch pickle data
Keras: TorchModuleWrapper can deserialize unsafe PyTorch pickle data
MAL-2026-10780NoneMalicious code in data-parser-utils (PyPI)
Malicious code in data-parser-utils (PyPI)
MAL-2026-10917NoneMalicious code in tinkoff-cloud-apis-internal (PyPI)
Malicious code in tinkoff-cloud-apis-internal (PyPI)
MAL-2026-10916NoneMalicious code in python-devplatform-client (PyPI)
Malicious code in python-devplatform-client (PyPI)
MAL-2026-10779Critical⚠ ExploitedMalicious code in mlflow-ui (PyPI)
Malicious code in mlflow-ui (PyPI)
MAL-2026-10915NoneMalicious code in dwh-kafka-client (PyPI)
Malicious code in dwh-kafka-client (PyPI)
GO-2026-5985NoneNebula-mesh allows non-admin operators to disable webhook SSRF protection via `allow_private` in github.com/forgekeep/nebula-mesh
Nebula-mesh allows non-admin operators to disable webhook SSRF protection via `allow_private` in github.com/forgekeep/nebula-mesh
GO-2026-5982NoneTsDProxy: X-Forwarded-For header injection allows IP spoofing in proxied requests to backend services in github.com/almeidapaulopt/tsdproxy
TsDProxy: X-Forwarded-For header injection allows IP spoofing in proxied requests to backend services in github.com/almeidapaulopt/tsdproxy
GO-2026-5981NoneEch0: ParseAcceptLanguage `_` separator bypass enables ~70x CPU amplification via Accept-Language header in i18n.Middleware in github.com…
Ech0: ParseAcceptLanguage `_` separator bypass enables ~70x CPU amplification via Accept-Language header in i18n.Middleware in github.com/lin-snow/ech0
GO-2026-5969NoneTSDProxy: Internal proxy auth token forwarded to backend services enables management API escalation in github.com/almeidapaulopt/tsdproxy
TSDProxy: Internal proxy auth token forwarded to backend services enables management API escalation in github.com/almeidapaulopt/tsdproxy
GO-2026-5935Nonenetfoil: Attacker controlled data written to logs in github.com/tinfoil-factory/netfoil
netfoil: Attacker controlled data written to logs in github.com/tinfoil-factory/netfoil