VulnSea

Tagged “osv”

CVEs tagged osv, newest first.

5681 CVEsRSS

CVE-2026-59930Medium· 4.3
2mo ago

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, the toc plugin and TableOfContents directive generate hea…

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, the toc plugin and TableOfContents directive generate heading IDs as predictable toc_N values without slugifying the heading text, allowing attacker-controll…

▾ Sunlitmistune · mistuneEPSS 0.19%via OSV
CVE-2026-59929Medium· 6.1
2mo ago

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, the safe_url filter in src/mistune/renderers/html.py bloc…

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, the safe_url filter in src/mistune/renderers/html.py blocks only javascript:, vbscript:, file:, and data: schemes, allowing legacy or chained schemes such as…

▾ Sunlitmistune · mistuneEPSS 0.34%via OSV
CVE-2026-59928High· 7.5
2mo ago

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, a Markdown document containing many repeated or distinct …

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, a Markdown document containing many repeated or distinct reference-link definitions causes quadratic work in src/mistune/block_parser.py and the ref_links en…

▾ Twilightmistune · mistuneEPSS 0.65%via OSV
CVE-2026-59927Medium· 5.3
2mo ago

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, the Include directive in src/mistune/directives/include.p…

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, the Include directive in src/mistune/directives/include.py detects only direct self-includes and not indirect cycles, allowing two markdown files that includ…

▾ Sunlitmistune · mistuneEPSS 0.53%via OSV
CVE-2026-59926Medium· 6.1
2mo ago

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.2.1, render_admonition() in src/mistune/directives/admonition.…

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.2.1, render_admonition() in src/mistune/directives/admonition.py concatenates the Admonition directive :class: option into the HTML class attribute without escapi…

▾ Sunlitmistune · mistuneEPSS 0.33%via OSV
CVE-2026-59925High· 7.5
2mo ago

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, long sequences of well-formed double-asterisk or triple-a…

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, long sequences of well-formed double-asterisk or triple-asterisk emphasis pairs around a character cause quadratic work in src/mistune/inline_parser.py becau…

▾ Twilightmistune · mistuneEPSS 0.64%via OSV
CVE-2026-59924Medium· 5.9
2mo ago

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, Include.parse() joins and normalizes user-supplied includ…

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, Include.parse() joins and normalizes user-supplied include paths without verifying that the result remains within the intended markdown directory, allowing c…

▾ Sunlitmistune · mistuneEPSS 0.46%via OSV
CVE-2026-59923Medium· 6.1
2mo ago

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, HTMLRenderer.safe_url() does not block percent-encoded ja…

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, HTMLRenderer.safe_url() does not block percent-encoded javascript URIs, allowing attacker-supplied Markdown links or images to bypass URL protections and exe…

▾ Sunlitmistune · mistuneEPSS 0.35%via OSV
CVE-2026-59922High· 7.5
2mo ago

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, a run of closed tilde, equals-sign, or caret marker pairs…

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, a run of closed tilde, equals-sign, or caret marker pairs around a character causes quadratic work in src/mistune/plugins/formatting.py when the strikethroug…

▾ Twilightmistune · mistuneEPSS 0.64%via OSV
CVE-2026-59822High· 8.2CISA KEVPoC
2mo ago

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, LiteLLM's MCP Streamable HTTP endpoint allowed an unauthenticated attacker to use a fabricated Authorization header to trigger an OAut…

▾ Abyssallitellm · litellmEPSS 0.84%via NVD
CVE-2026-59821High· 7.2
2mo ago

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.82.0-stable, LiteLLM's Custom Code Guardrails production create and update paths did not apply the same sandboxing and validation used by th…

▾ Twilightlitellm · litellmEPSS 0.90%via NVD
CVE-2026-59939High· 7.5
2mo ago

httplib2 is a comprehensive HTTP client library for Python

httplib2 is a comprehensive HTTP client library for Python. Prior to 0.32.0, httplib2 performs unbounded decompression of HTTP response bodies encoded with Content-Encoding: gzip or deflate in _decompressContent in httplib2/init.py, allo…

▾ Twilighthttplib2_project · httplib2EPSS 0.66%via NVD
CVE-2026-59820Medium· 6.5
2mo ago

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.7-stable, LiteLLM Skills archive extraction did not sufficiently validate file paths from uploaded skill ZIP archives, allowing an authen…

▾ Sunlitlitellm · litellmEPSS 0.59%via NVD
CVE-2026-59819Medium· 4.9
2mo ago

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.10-stable, LiteLLM's /health/test_connection endpoint resolved request-supplied environment and OIDC file references in litellm_params, a…

▾ Sunlitlitellm · litellmEPSS 0.57%via NVD
CVE-2026-15035High· 7.8
2mo ago

A vulnerability was found in bentoml OpenLLM 0.6.30. This affects the function async_run_command of the file src/openllm/common.py of the…

A vulnerability was found in bentoml OpenLLM 0.6.30. This affects the function async_run_command of the file src/openllm/common.py of the component Model Repository Directory Name Handler. Performing a manipulation of the argument cmd re…

▾ Twilightbentoml · bentomlEPSS 2.2%via OSV
MAL-2026-6959None
2mo ago

Malicious code in proton_pfff (crates.io)

Malicious code in proton_pfff (crates.io)

▾ Sunlitproton-pfff · proton-pfffvia OSV
CVE-2026-42505Medium· 5.3
2mo ago

Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of pre-shared key identities in the unencrypted client hello.

Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of pre-shared key identities in the unencrypted client hello.

▾ Sunlitgolang · goEPSS 0.41%via NVD
CVE-2026-39822High· 7.8
2mo ago

On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the final path component of the a path is a symbolic link and the path ends in /

On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the final path component of the a path is a symbolic link and the path ends in /. For example, 'root.Open("symlink/")' will o…

▾ Twilightgolang · goEPSS 0.18%via NVD
MAL-2026-7025None
2mo ago

Malicious code in tronsev (PyPI)

Malicious code in tronsev (PyPI)

▾ Sunlittronsev · tronsevvia OSV
MAL-2026-7023None
2mo ago

Malicious code in dbzy-tools (PyPI)

Malicious code in dbzy-tools (PyPI)

▾ Sunlitdbzy-tools · dbzy-toolsvia OSV
MAL-2026-6961None
2mo ago

Malicious code in waymo-waymax (PyPI)

Malicious code in waymo-waymax (PyPI)

▾ Sunlitwaymo-waymax · waymo-waymaxvia OSV
MAL-2026-6960None
2mo ago

Malicious code in pyqt6darktheme (PyPI)

Malicious code in pyqt6darktheme (PyPI)

▾ Sunlitpyqt6darktheme · pyqt6darkthemevia OSV
MAL-2026-7015None
2mo ago

Malicious code in turbom (PyPI)

Malicious code in turbom (PyPI)

▾ Sunlitturbom · turbomvia OSV
MAL-2026-7007None
2mo ago

Malicious code in manom (PyPI)

Malicious code in manom (PyPI)

▾ Sunlitmanom · manomvia OSV
MAL-2026-7006None
2mo ago

Malicious code in manik (PyPI)

Malicious code in manik (PyPI)

▾ Sunlitmanik · manikvia OSV
MAL-2026-6983None
2mo ago

Malicious code in tronpak (PyPI)

Malicious code in tronpak (PyPI)

▾ Sunlittronpak · tronpakvia OSV
MAL-2026-6979None
2mo ago

Malicious code in turbod (PyPI)

Malicious code in turbod (PyPI)

▾ Sunlitturbod · turbodvia OSV
MAL-2026-6978None
2mo ago

Malicious code in manin (PyPI)

Malicious code in manin (PyPI)

▾ Sunlitmanin · maninvia OSV
MAL-2026-6977None
2mo ago

Malicious code in rarcore (PyPI)

Malicious code in rarcore (PyPI)

▾ Sunlitrarcore · rarcorevia OSV
MAL-2026-6976None
2mo ago

Malicious code in py-slugify (PyPI)

Malicious code in py-slugify (PyPI)

▾ Sunlitpy-slugify · py-slugifyvia OSV
CVEs tagged “osv” — page 42 · VulnSea