Tagged “osv”
CVEs tagged osv, newest first.
5681 CVEsRSS
GO-2026-5934Nonenetfoil has a domain name filter bypass via multiple questions in github.com/tinfoil-factory/netfoil
netfoil has a domain name filter bypass via multiple questions in github.com/tinfoil-factory/netfoil
GO-2026-5933Nonenetfoil has a resource leak in LRU cache in github.com/tinfoil-factory/netfoil
netfoil has a resource leak in LRU cache in github.com/tinfoil-factory/netfoil
MAL-2026-10771NoneMalicious code in trongridme (PyPI)
Malicious code in trongridme (PyPI)
MAL-2026-10770NoneMalicious code in govpkg (PyPI)
Malicious code in govpkg (PyPI)
GHSA-8rqh-vxpr-x77pMedium· 4.3plone.restapi: Stored XSS by spoofing mime type
plone.restapi: Stored XSS by spoofing mime type
MAL-2026-10768NoneMalicious code in trongridev (PyPI)
Malicious code in trongridev (PyPI)
CVE-2026-50274High· 7.5github.com/DataDog/dd-trace-go: Datadog dd-trace-go: Denial of Service via malicious baggage headers (CVE-2026-50274)
A flaw was found in Datadog dd-trace-go, a Go client library. A remote, unauthenticated attacker can exploit this vulnerability by sending a request with a specially crafted baggage header containing an arbitrarily large number of key-valu…
CVE-2026-15925CriticalSnowflake Connector for Python improperly verifies TLS hostnames
Snowflake Connector for Python improperly verifies TLS hostnames
CVE-2026-18679Mediumkuma-dp connects to control plane without verifying TLS certificate when no CA is configured
kuma-dp connects to control plane without verifying TLS certificate when no CA is configured
CVE-2026-18678Mediumkumactl connects to control plane without verifying TLS certificate when no CA is configured
kumactl connects to control plane without verifying TLS certificate when no CA is configured
MAL-2026-10760NoneMalicious code in abseil-py (PyPI)
Malicious code in abseil-py (PyPI)
MAL-2026-10759NoneMalicious code in ryry-cli (PyPI)
Malicious code in ryry-cli (PyPI)
MAL-2026-10758NoneMalicious code in mfq-private-encoder (PyPI)
Malicious code in mfq-private-encoder (PyPI)
MAL-2026-10757NoneMalicious code in dde-common (PyPI)
Malicious code in dde-common (PyPI)
MAL-2026-10756NoneMalicious code in darkglitch (PyPI)
Malicious code in darkglitch (PyPI)
MAL-2026-10755NoneMalicious code in captcha-solve-api (PyPI)
Malicious code in captcha-solve-api (PyPI)
MAL-2026-10754NoneMalicious code in airflow-provider-spirit (PyPI)
Malicious code in airflow-provider-spirit (PyPI)
MAL-2026-10753NoneMalicious code in a3s-code (PyPI)
Malicious code in a3s-code (PyPI)
CVE-2026-52869High· 7.1MCP Python SDK: HTTP transports serve session requests without verifying the authenticated principal
MCP Python SDK: HTTP transports serve session requests without verifying the authenticated principal
CVE-2026-59950HighMCP Python SDK: WebSocket server transport does not support Host/Origin validation
MCP Python SDK: WebSocket server transport does not support Host/Origin validation
CVE-2026-52870High· 7.6MCP Python SDK: Experimental task handlers allow any client to access and cancel other clients' tasks
MCP Python SDK: Experimental task handlers allow any client to access and cancel other clients' tasks
MAL-2026-10702NoneMalicious code in discordia-telemetria (PyPI)
Malicious code in discordia-telemetria (PyPI)
MAL-2026-10701NoneMalicious code in discord-telemetry (PyPI)
Malicious code in discord-telemetry (PyPI)
CVE-2026-56742Medium· 5.9Cilium is a networking, observability, and security solution
Cilium is a networking, observability, and security solution. Prior to 1.17.17, 1.18.11, and 1.19.5, Cilium clusters using Gateway API allow users with permissions to create or update namespaced HTTPRoutes to mirror HTTP traffic to any S…
CVE-2026-58659High· 7.8PyTorch Lightning through 2.6.5, fixed in commit d710d68, contains a remote code execution vulnerability in the _load_state function that imports and executes attacker-controlled module names from checkpoint _instantiator hyperparameters…
PyTorch Lightning through 2.6.5, fixed in commit d710d68, contains a remote code execution vulnerability in the _load_state function that imports and executes attacker-controlled module names from checkpoint _instantiator hyperparameters…
RUSTSEC-2026-0210None`libcrux-aesgcm` Renamed to `libcrux-aes`
`libcrux-aesgcm` Renamed to `libcrux-aes`
MAL-2026-10690NoneMalicious code in qwen-asr-pvt (PyPI)
Malicious code in qwen-asr-pvt (PyPI)
MAL-2026-10689NoneMalicious code in pylogora (PyPI)
Malicious code in pylogora (PyPI)
MAL-2026-10688NoneMalicious code in log-guru (PyPI)
Malicious code in log-guru (PyPI)
MAL-2026-10685NoneMalicious code in trongridweb (PyPI)
Malicious code in trongridweb (PyPI)