Tagged “osv”
CVEs tagged osv, newest first.
5634 CVEsRSS
CVE-2026-76819High· 8.6Rejected reason: Further research determined the issue results from a dependency.
Rejected reason: Further research determined the issue results from a dependency.
CVE-2026-85709Medium· 5.3PoCLightRAG provides simple and fast retrieval-augmented generation
LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, the LightRAG API server returns raw Python exception text from error handlers in document_routes.py, graph_routes.py, query_routes.py, ollama_api.py, and l…
CVE-2026-85725Medium· 5.9PoCLightRAG provides simple and fast retrieval-augmented generation
LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, verify_password in lightrag/api/passwords.py compares plaintext AUTH_ACCOUNTS password values with Python's == operator. The comparison can return after th…
CVE-2026-85740High· 7.1LightRAG provides simple and fast retrieval-augmented generation
LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, _validated_addresses in lightrag/parser/markdown/parser.py evaluates the literal resolved address with ipaddress.is_global without consistently classifying…
CVE-2026-85734Critical· 9.1LightRAG provides simple and fast retrieval-augmented generation
LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, the POST /login endpoint in lightrag/api/lightrag_server.py does not impose a rate limit, account lockout, delay, or counter for failed authentication atte…
CVE-2026-86062Medium· 6.1PoCLightRAG provides simple and fast retrieval-augmented generation
LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, lightrag_webui/src/components/retrieval/ChatMessage.tsx renders answer and thinking content with react-markdown, rehypeRaw, and skipHtml=false without an H…
CVE-2026-76805Medium· 5.3Nuclei is a vulnerability scanner built on a simple YAML-based DSL
Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From 3.0.0 until 3.10.0, the DAST/fuzz payload path in pkg/fuzz/parts.go can evaluate substituted runtime data more than once, creating a second evaluation pass that all…
CVE-2026-76804Medium· 5.5Nuclei is a vulnerability scanner built on a simple YAML-based DSL
Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From 3.0.0 until 3.10.0, the workflow template loading path does not enforce the -file capability gate when resolving file: protocol templates referenced by a workflow. …
CVE-2026-76803Medium· 5.3Nuclei is a vulnerability scanner built on a simple YAML-based DSL
Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From 3.0.0 until 3.10.0, the nuclei/mysql JavaScript library does not enforce the local-file sandbox when a JavaScript template supplies the allowAllFiles MySQL DSN opti…
CVE-2026-76802Medium· 4.7⚖ disputedNuclei is a vulnerability scanner built on a simple YAML-based DSL
Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From 3.0.0 until 3.10.0, the DAST template loading branch does not apply the unsigned code-template signature check before accepting a template that contains both a fuzz…
CVE-2026-79913Medium· 6.5Cloudreve is a self-hosted file management and sharing system
Cloudreve is a self-hosted file management and sharing system. Prior to 4.18.0, the ValidateExternalURL server-side request forgery guard in pkg/request/ssrf.go passes resolved addresses to checkIP without decoding NAT64, IPv4-compatible…
CVE-2026-77633High· 7.1Cloudreve is a self-hosted file management and sharing system
Cloudreve is a self-hosted file management and sharing system. Prior to 4.18.0, PrepareUpload in pkg/filemanager/fs/dbfs/upload.go checks a stale in-memory user storage value through validateUserCapacity and later applies an unconditiona…
CVE-2026-77637Low· 3.8Cloudreve is a self-hosted file management and sharing system
Cloudreve is a self-hosted file management and sharing system. Prior to 4.18.0, tool.GET("wopi") and tool.POST("mail") in routers/router.go inherit ScopeAdminRead but omit the RequiredScopes(types.ScopeAdminWrite) middleware applied to n…
CVE-2026-88010Medium· 6.3Traefik is an open source HTTP reverse proxy and load balancer
Traefik is an open source HTTP reverse proxy and load balancer. From 3.6.11 until 3.7.13, checkPassword in pkg/middlewares/auth/basic_auth.go constructs the BasicAuth singleflight key from the submitted password and stored secret. Concur…
CVE-2026-63374Critical· 9.3AnyIO is a high level asynchronous concurrency and networking framework that works on top of either Trio or asyncio
AnyIO is a high level asynchronous concurrency and networking framework that works on top of either Trio or asyncio. Prior to 4.14.2, connect_tcp() and TLSStream.wrap() can validate internationalized host names after the standard library…
RUSTSEC-2026-0304NoneFinished streaming calls keep reading a stalled request body indefinitely
Finished streaming calls keep reading a stalled request body indefinitely
MAL-2026-16366Critical⚠ ExploitedMalicious code in pullgetsage (PyPI)
Malicious code in pullgetsage (PyPI)
MAL-2026-16356Critical⚠ ExploitedMalicious code in starlette-healthchecks (PyPI)
Malicious code in starlette-healthchecks (PyPI)
CVE-2026-61652High· 8.7Zapros, a Python HTTP client, prior to version 0.14.0 is vulnerable to denial of service via memory exhaustion
Zapros, a Python HTTP client, prior to version 0.14.0 is vulnerable to denial of service via memory exhaustion. The issue affects all callers who streamed compressed responses relying on the chunk size — explicit (`iter_bytes(chunk_size=…
CVE-2026-61541Medium· 6.9Zapros, a Python HTTP client, prior to version 0.14.0 is vulnerable to denial of service when an application requests content from an untrusted server, or follows a redirect to one, because a malicious response containing an excessive nu…
Zapros, a Python HTTP client, prior to version 0.14.0 is vulnerable to denial of service when an application requests content from an untrusted server, or follows a redirect to one, because a malicious response containing an excessive nu…
GHSA-jhjp-4c2q-xmx4Medium· 4.3k8saudit shipped rules do not detect privileged/sensitive settings on init or ephemeral containers
k8saudit shipped rules do not detect privileged/sensitive settings on init or ephemeral containers
CVE-2026-62369High· 8.1KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge
KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. From 1.16.0 until 1.21.2, 1.22.2, and 1.23.1, the DecompressTarGz function in keadm/cmd/keadm/app/cmd/util/comm…
CVE-2026-62182High· 8.8KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge
KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. From 1.21.0 until 1.21.2, 1.22.2, and 1.23.1, ConfigUpdateJob processing in edge/pkg/taskmanager/actions/config…
CVE-2026-77561Medium· 5.3PoCTinyauth is an authentication and authorization server
Tinyauth is an authentication and authorization server. Prior to 5.1.0, an unauthenticated remote attacker can send POST /api/user/login requests with 257 distinct nonexistent usernames to fill MaxLoginAttemptRecords and activate a globa…
CVE-2026-62866Medium· 6.2PoCDasel is a command-line tool and library for querying, modifying, and transforming data structures
Dasel is a command-line tool and library for querying, modifying, and transforming data structures. From 3.0.0 until 3.11.2, selector/lexer/tokenize.go parseCurRune advances the input index across trailing whitespace and then reads the s…
CVE-2026-62371High· 8.8KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge
KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. From 1.12.0 until 1.21.2, 1.22.2, and 1.23.1, the v1alpha2 NodeUpgradeJob handler in edge/pkg/taskmanager/actio…
CVE-2026-62370Medium· 6.5KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge
KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. From 1.0.0 until 1.21.2, 1.22.2, and 1.23.1, Reader.Read in pkg/viaduct/pkg/packer trusts the 32-bit PackageHea…
CVE-2026-59168Medium· 6.2Dasel is a command-line tool and library for querying, modifying, and transforming data structures
Dasel is a command-line tool and library for querying, modifying, and transforming data structures. From 3.0.0 until 3.11.1, parsing/json/json_reader.go decodeValue, decodeObject, and decodeArray, and parsing/xml/reader.go parseElement, …
CVE-2026-62987Medium· 5.8PoCFabio is an HTTP(S) and TCP router for deploying applications managed by consul
Fabio is an HTTP(S) and TCP router for deploying applications managed by consul. From 1.6.6 until 1.7.2, the CVE-2025-48865 fix in proxy/http_headers.go uses protectHeaders for a hardcoded set of forwarded headers but omits the operator-…
CVE-2026-77582Medium· 6.9PoCTinyauth is an authentication and authorization server
Tinyauth is an authentication and authorization server. Prior to 5.1.0, Tinyauth exposes a remotely observable timing difference between authentication attempts for existing and nonexistent local usernames. internal/controller/user_contr…