Tagged “osv”
CVEs tagged osv, newest first.
5683 CVEsRSS
MAL-2026-10681NoneMalicious code in xyq-drama-skill (PyPI)
Malicious code in xyq-drama-skill (PyPI)
CVE-2026-50271High· 7.5dd-trace-py: Improper parsing of W3C baggage headers may lead to DoS
dd-trace-py: Improper parsing of W3C baggage headers may lead to DoS
MAL-2026-10672NoneMalicious code in northstart-sdk (PyPI)
Malicious code in northstart-sdk (PyPI)
MAL-2026-10643NoneMalicious code in ethereum-input-decorder (PyPI)
Malicious code in ethereum-input-decorder (PyPI)
MAL-2026-10642NoneMalicious code in data-proxy-for-test (PyPI)
Malicious code in data-proxy-for-test (PyPI)
CVE-2026-45804High· 7.5diffusers: Diffusers: Arbitrary code execution due to trust_remote_code guard bypass (CVE-2026-45804)
A flaw was found in Diffusers, a library for pretrained diffusion models. A remote attacker could exploit this vulnerability by crafting a malicious Hub repository with custom Python pipeline code. The `DiffusionPipeline.from_pretrained` f…
CVE-2026-15736High· 8.3Snowflake SQLAlchemy affected by SQL injection and local file disclosure vulnerabilities
Snowflake SQLAlchemy affected by SQL injection and local file disclosure vulnerabilities
CVE-2026-12482Low· 3.1Keras: tar extraction permits symlink-based path traversal
Keras: tar extraction permits symlink-based path traversal
CVE-2026-56852High· 7.5PoCInfinite loop on invalid input in golang.org/x/text
Infinite loop on invalid input in golang.org/x/text
CVE-2026-59885High· 7.5pyasn1: python-pyasn1: pyasn1: Denial of Service via crafted ASN.1 OBJECT IDENTIFIER (CVE-2026-59885)
A flaw was found in pyasn1, a Python library for Abstract Syntax Notation One (ASN.1). The BER, CER, and DER decoders process OBJECT IDENTIFIER and RELATIVE-OID values in quadratic time relative to the number of arcs. A remote attacker cou…
CVE-2026-59886High· 7.5pyasn1: pyasn1: Denial of Service via crafted ASN.1 REAL values (CVE-2026-59886)
A remote attacker can exploit this by providing specially crafted BER/CER/DER-encoded ASN.1 data with a large exponent in the REAL value. When the application subsequently prints, logs, compares, or performs arithmetic on the decoded value…
CVE-2026-59197High· 8.2Pillow: Pillow: Native heap out-of-bounds write (CVE-2026-59197)
A flaw was found in Pillow prior to 12.3.0. The public RankFilter API can trigger a native heap out-of-bounds write when given a very large odd filter size. ImageFilter.RankFilter.filter() calls image.expand(size // 2, size // 2) before ra…
CVE-2026-59200High· 7.5Pillow: Pillow: Denial of service via crafted PDF stream (CVE-2026-59200)
A flaw was found in Pillow, a Python imaging library. A remote attacker could exploit a vulnerability in the PdfParser.PdfStream.decode() function when processing a crafted FlateDecode PDF stream. By providing a specially designed PDF file…
CVE-2026-59204High· 7.5Pillow: Pillow: Denial of Service via crafted JPEG2000 image (CVE-2026-59204)
A flaw was found in Pillow, a Python imaging library. A remote attacker could exploit this vulnerability by providing a specially crafted JPEG2000 image file. Due to incorrect calculation of memory requirements for image tiles, processing …
CVE-2026-54058Critical· 9.1Pillow: Pillow: Memory disclosure or denial of service via crafted McIdas AREA image (CVE-2026-54058)
A flaw was found in Pillow prior to 12.3.0. When an uncompressed McIdas AREA image is loaded from a filename through the mmap raw codec path, attacker-controlled header words can set a row stride smaller than the natural row width. Pixel a…
RUSTSEC-2026-0211NoneNon-constant time Authentication Tag Check in AES-GCM Decryption
Non-constant time Authentication Tag Check in AES-GCM Decryption
CVE-2026-59205High· 7.5Pillow: Pillow: Controlled native heap corruption in ImageCms.ImageCmsTransform.apply API (CVE-2026-59205)
A flaw was found in Pillow, a Python imaging library. This vulnerability allows an attacker to trigger controlled native heap corruption by supplying an output image whose mode does not match the transform's declared output mode when using…
CVE-2026-59199High· 7.5Pillow: Pillow: Denial of Service via out-of-bounds write in image processing (CVE-2026-59199)
A flaw was found in Pillow, a Python imaging library. A remote attacker could exploit a vulnerability in the library's image processing functions, specifically when handling image coordinates near certain limits. This flaw, a native heap o…
MAL-2026-10644NoneMalicious code in proxy-checker-j (PyPI)
Malicious code in proxy-checker-j (PyPI)
MAL-2026-10624NoneMalicious code in tronwe (PyPI)
Malicious code in tronwe (PyPI)
MAL-2026-10618NoneMalicious code in cosmos-gradio (PyPI)
Malicious code in cosmos-gradio (PyPI)
MAL-2026-10617NoneMalicious code in cosmos-cuda (PyPI)
Malicious code in cosmos-cuda (PyPI)
MAL-2026-10610NoneMalicious code in proxy-check-ii (PyPI)
Malicious code in proxy-check-ii (PyPI)
MAL-2026-10576NoneMalicious code in tennacity (PyPI)
Malicious code in tennacity (PyPI)
MAL-2026-10547NoneMalicious code in pokee-data-utils (PyPI)
Malicious code in pokee-data-utils (PyPI)
CVE-2026-49855High· 7.5tornado: Tornado: Denial of Service via uncontrolled gzip decompression memory consumption (CVE-2026-49855)
A flaw was found in Tornado, a Python web framework and asynchronous networking library. Its gzip decompression routines process data in limited-size chunks but do not enforce an overall limit on the total accumulated decompressed data. Th…
CVE-2026-49853High· 7.7tornado: Tornado: Information disclosure via improper handling of credentials during HTTP redirects (CVE-2026-49853)
A flaw was found in Tornado's SimpleAsyncHTTPClient. When following a redirect to a different origin, the client improperly retains and forwards sensitive authentication credentials, such as Authorization headers, to the new, potentially u…
CVE-2026-62240High· 7.4PoCCrewAI before 1.15.1 contains a server-side request forgery vulnerability in the validate_url function that performs one-shot DNS resolution and blocklist checks before returning the original URL unchanged
CrewAI before 1.15.1 contains a server-side request forgery vulnerability in the validate_url function that performs one-shot DNS resolution and blocklist checks before returning the original URL unchanged. Attackers can bypass the secur…
RUSTSEC-2026-0221None`event-listener` allows `!Send` tags to cross thread boundaries via `StackSlot`
`event-listener` allows `!Send` tags to cross thread boundaries via `StackSlot`
CVE-2026-15685High· 7.50dayOllama downloadBlob Improper Validation of Array Index Denial-of-Service Vulnerability. This vulnerability allows remote attackers to cre…
Ollama downloadBlob Improper Validation of Array Index Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Ollama. Authentication is not require…