VulnSea

Tagged “osv”

CVEs tagged osv, newest first.

5683 CVEsRSS

MAL-2026-10681None
2mo ago

Malicious code in xyq-drama-skill (PyPI)

Malicious code in xyq-drama-skill (PyPI)

▾ Sunlitxyq-drama-skill · xyq-drama-skillvia OSV
CVE-2026-50271High· 7.5
2mo ago

dd-trace-py: Improper parsing of W3C baggage headers may lead to DoS

dd-trace-py: Improper parsing of W3C baggage headers may lead to DoS

▾ Twilightddtrace · ddtraceEPSS 0.79%via OSV
MAL-2026-10672None
2mo ago

Malicious code in northstart-sdk (PyPI)

Malicious code in northstart-sdk (PyPI)

▾ Sunlitnorthstart-sdk · northstart-sdkvia OSV
MAL-2026-10643None
2mo ago

Malicious code in ethereum-input-decorder (PyPI)

Malicious code in ethereum-input-decorder (PyPI)

▾ Sunlitethereum-input-decorder · ethereum-input-decordervia OSV
MAL-2026-10642None
2mo ago

Malicious code in data-proxy-for-test (PyPI)

Malicious code in data-proxy-for-test (PyPI)

▾ Sunlitdata-proxy-for-test · data-proxy-for-testvia OSV
CVE-2026-45804High· 7.5
2mo ago

diffusers: Diffusers: Arbitrary code execution due to trust_remote_code guard bypass (CVE-2026-45804)

A flaw was found in Diffusers, a library for pretrained diffusion models. A remote attacker could exploit this vulnerability by crafting a malicious Hub repository with custom Python pipeline code. The `DiffusionPipeline.from_pretrained` f…

▾ TwilightRed Hat · Red Hat AI Inference Server 3.4EPSS 0.37%via CSAF
CVE-2026-15736High· 8.3
2mo ago

Snowflake SQLAlchemy affected by SQL injection and local file disclosure vulnerabilities

Snowflake SQLAlchemy affected by SQL injection and local file disclosure vulnerabilities

▾ Twilightsnowflake-sqlalchemy · snowflake-sqlalchemyEPSS 0.38%via OSV
CVE-2026-12482Low· 3.1
2mo ago

Keras: tar extraction permits symlink-based path traversal

Keras: tar extraction permits symlink-based path traversal

▾ Sunlitkeras · kerasEPSS 0.33%via OSV
CVE-2026-56852High· 7.5PoC
2mo ago

Infinite loop on invalid input in golang.org/x/text

Infinite loop on invalid input in golang.org/x/text

▾ Midnightx · golang.org/x/textEPSS 0.47%via OSV
CVE-2026-59885High· 7.5
2mo ago

pyasn1: python-pyasn1: pyasn1: Denial of Service via crafted ASN.1 OBJECT IDENTIFIER (CVE-2026-59885)

A flaw was found in pyasn1, a Python library for Abstract Syntax Notation One (ASN.1). The BER, CER, and DER decoders process OBJECT IDENTIFIER and RELATIVE-OID values in quadratic time relative to the number of arcs. A remote attacker cou…

▾ TwilightRed Hat · Red Hat OpenShift AI 3.4EPSS 0.62%via CSAF
CVE-2026-59886High· 7.5
2mo ago

pyasn1: pyasn1: Denial of Service via crafted ASN.1 REAL values (CVE-2026-59886)

A remote attacker can exploit this by providing specially crafted BER/CER/DER-encoded ASN.1 data with a large exponent in the REAL value. When the application subsequently prints, logs, compares, or performs arithmetic on the decoded value…

▾ TwilightRed Hat · Red Hat Enterprise Linux AppStream EUS (v.9.6)EPSS 0.62%via CSAF
CVE-2026-59197High· 8.2
2mo ago

Pillow: Pillow: Native heap out-of-bounds write (CVE-2026-59197)

A flaw was found in Pillow prior to 12.3.0. The public RankFilter API can trigger a native heap out-of-bounds write when given a very large odd filter size. ImageFilter.RankFilter.filter() calls image.expand(size // 2, size // 2) before ra…

▾ TwilightRed Hat · Red Hat OpenShift AI 3.4EPSS 0.58%via CSAF
CVE-2026-59200High· 7.5
2mo ago

Pillow: Pillow: Denial of service via crafted PDF stream (CVE-2026-59200)

A flaw was found in Pillow, a Python imaging library. A remote attacker could exploit a vulnerability in the PdfParser.PdfStream.decode() function when processing a crafted FlateDecode PDF stream. By providing a specially designed PDF file…

▾ TwilightRed Hat · Red Hat OpenShift AI 3.4EPSS 0.66%via CSAF
CVE-2026-59204High· 7.5
2mo ago

Pillow: Pillow: Denial of Service via crafted JPEG2000 image (CVE-2026-59204)

A flaw was found in Pillow, a Python imaging library. A remote attacker could exploit this vulnerability by providing a specially crafted JPEG2000 image file. Due to incorrect calculation of memory requirements for image tiles, processing …

▾ TwilightRed Hat · Red Hat OpenShift AI 3.4EPSS 0.66%via CSAF
CVE-2026-54058Critical· 9.1
2mo ago

Pillow: Pillow: Memory disclosure or denial of service via crafted McIdas AREA image (CVE-2026-54058)

A flaw was found in Pillow prior to 12.3.0. When an uncompressed McIdas AREA image is loaded from a filename through the mmap raw codec path, attacker-controlled header words can set a row stride smaller than the natural row width. Pixel a…

▾ MidnightRed Hat · Red Hat OpenShift AI 3.4EPSS 0.68%via CSAF
RUSTSEC-2026-0211None
2mo ago

Non-constant time Authentication Tag Check in AES-GCM Decryption

Non-constant time Authentication Tag Check in AES-GCM Decryption

▾ Sunlitlibcrux-aesgcm · libcrux-aesgcmvia OSV
CVE-2026-59205High· 7.5
2mo ago

Pillow: Pillow: Controlled native heap corruption in ImageCms.ImageCmsTransform.apply API (CVE-2026-59205)

A flaw was found in Pillow, a Python imaging library. This vulnerability allows an attacker to trigger controlled native heap corruption by supplying an output image whose mode does not match the transform's declared output mode when using…

▾ TwilightRed Hat · Red Hat OpenShift AI 3.4EPSS 0.66%via CSAF
CVE-2026-59199High· 7.5
2mo ago

Pillow: Pillow: Denial of Service via out-of-bounds write in image processing (CVE-2026-59199)

A flaw was found in Pillow, a Python imaging library. A remote attacker could exploit a vulnerability in the library's image processing functions, specifically when handling image coordinates near certain limits. This flaw, a native heap o…

▾ TwilightRed Hat · Red Hat OpenShift AI 3.4EPSS 0.66%via CSAF
MAL-2026-10644None
2mo ago

Malicious code in proxy-checker-j (PyPI)

Malicious code in proxy-checker-j (PyPI)

▾ Sunlitproxy-checker-j · proxy-checker-jvia OSV
MAL-2026-10624None
2mo ago

Malicious code in tronwe (PyPI)

Malicious code in tronwe (PyPI)

▾ Sunlittronwe · tronwevia OSV
MAL-2026-10618None
2mo ago

Malicious code in cosmos-gradio (PyPI)

Malicious code in cosmos-gradio (PyPI)

▾ Sunlitcosmos-gradio · cosmos-gradiovia OSV
MAL-2026-10617None
2mo ago

Malicious code in cosmos-cuda (PyPI)

Malicious code in cosmos-cuda (PyPI)

▾ Sunlitcosmos-cuda · cosmos-cudavia OSV
MAL-2026-10610None
2mo ago

Malicious code in proxy-check-ii (PyPI)

Malicious code in proxy-check-ii (PyPI)

▾ Sunlitproxy-check-ii · proxy-check-iivia OSV
MAL-2026-10576None
2mo ago

Malicious code in tennacity (PyPI)

Malicious code in tennacity (PyPI)

▾ Sunlittennacity · tennacityvia OSV
MAL-2026-10547None
2mo ago

Malicious code in pokee-data-utils (PyPI)

Malicious code in pokee-data-utils (PyPI)

▾ Sunlitpokee-data-utils · pokee-data-utilsvia OSV
CVE-2026-49855High· 7.5
2mo ago

tornado: Tornado: Denial of Service via uncontrolled gzip decompression memory consumption (CVE-2026-49855)

A flaw was found in Tornado, a Python web framework and asynchronous networking library. Its gzip decompression routines process data in limited-size chunks but do not enforce an overall limit on the total accumulated decompressed data. Th…

▾ TwilightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.61%via CSAF
CVE-2026-49853High· 7.7
2mo ago

tornado: Tornado: Information disclosure via improper handling of credentials during HTTP redirects (CVE-2026-49853)

A flaw was found in Tornado's SimpleAsyncHTTPClient. When following a redirect to a different origin, the client improperly retains and forwards sensitive authentication credentials, such as Authorization headers, to the new, potentially u…

▾ TwilightRed Hat · Red Hat Enterprise Linux AppStream (v. 10)EPSS 0.45%via CSAF
CVE-2026-62240High· 7.4PoC
2mo ago

CrewAI before 1.15.1 contains a server-side request forgery vulnerability in the validate_url function that performs one-shot DNS resolution and blocklist checks before returning the original URL unchanged

CrewAI before 1.15.1 contains a server-side request forgery vulnerability in the validate_url function that performs one-shot DNS resolution and blocklist checks before returning the original URL unchanged. Attackers can bypass the secur…

▾ Midnightcrewai · crewaiEPSS 0.52%via NVD
RUSTSEC-2026-0221None
2mo ago

`event-listener` allows `!Send` tags to cross thread boundaries via `StackSlot`

`event-listener` allows `!Send` tags to cross thread boundaries via `StackSlot`

▾ Sunlitevent-listener · event-listenervia OSV
CVE-2026-15685High· 7.50day
2mo ago

Ollama downloadBlob Improper Validation of Array Index Denial-of-Service Vulnerability. This vulnerability allows remote attackers to cre…

Ollama downloadBlob Improper Validation of Array Index Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Ollama. Authentication is not require…

▾ Abyssalollama · ollamaEPSS 0.71%via OSV
CVEs tagged “osv” — page 40 · VulnSea