VulnSea

Tagged “osv”

CVEs tagged osv, newest first.

5681 CVEsRSS

MAL-2026-6975None
2mo ago

Malicious code in oxntime (PyPI)

Malicious code in oxntime (PyPI)

▾ Sunlitoxntime · oxntimevia OSV
MAL-2026-6974None
2mo ago

Malicious code in tronhapy (PyPI)

Malicious code in tronhapy (PyPI)

▾ Sunlittronhapy · tronhapyvia OSV
MAL-2026-6971None
2mo ago

Malicious code in tronhap (PyPI)

Malicious code in tronhap (PyPI)

▾ Sunlittronhap · tronhapvia OSV
MAL-2026-6970None
2mo ago

Malicious code in jsonschemavalid (PyPI)

Malicious code in jsonschemavalid (PyPI)

▾ Sunlitjsonschemavalid · jsonschemavalidvia OSV
CVE-2026-48828Medium· 6.5
2mo ago

The Bulk Variables API in Apache Airflow called the redactor without passing the variable's key, so the key-based `should_hide_value_for_key` check (which triggers on secret-suffixed key names like `*_password` / `*_token` / `*_secret`) …

The Bulk Variables API in Apache Airflow called the redactor without passing the variable's key, so the key-based `should_hide_value_for_key` check (which triggers on secret-suffixed key names like `*_password` / `*_token` / `*_secret`) …

▾ Sunlitapache · airflowEPSS 0.66%via NVD
CVE-2026-58473Critical· 9.1
2mo ago

Cognee allows non-superusers to overwrite global LLM configuration

Cognee allows non-superusers to overwrite global LLM configuration

▾ Midnightcognee · cogneeEPSS 0.51%via OSV
CVE-2026-53878Medium· 6.1
2mo ago

Django: DomainNameValidator permits newline characters that may enable HTTP header injection

Django: DomainNameValidator permits newline characters that may enable HTTP header injection

▾ Sunlitdjango · djangoEPSS 0.33%via OSV
CVE-2026-53877Medium· 4.8
2mo ago

Django: GDALRaster may over-read heap memory when constructed from bytes

Django: GDALRaster may over-read heap memory when constructed from bytes

▾ Sunlitdjango · djangoEPSS 0.44%via OSV
CVE-2026-48588Low· 3.1
2mo ago

Django: cache middleware may expose private responses when unrelated request cookies are present

Django: cache middleware may expose private responses when unrelated request cookies are present

▾ Sunlitdjango · djangoEPSS 0.43%via OSV
CVE-2026-49487Medium· 6.5
2mo ago

In Apache Airflow before 3.3.0, the REST API task-instance detail and list endpoints returned a deferred task's trigger kwargs without masking

In Apache Airflow before 3.3.0, the REST API task-instance detail and list endpoints returned a deferred task's trigger kwargs without masking. When a deferred operator passed a secret (for example a provider API key) into its trigger, a…

▾ Sunlitapache · airflowEPSS 0.66%via NVD
CVE-2026-48892Medium· 6.5
2mo ago

The Config API in Apache Airflow surfaced per-key secrets-backend overrides (environment variables like `AIRFLOW__SECRETS__BACKEND_KWARG__SECRET_ID` and `AIRFLOW__WORKERS__SECRETS_BACKEND_KWARG__SECRET_ID`) as synthetic config options wh…

The Config API in Apache Airflow surfaced per-key secrets-backend overrides (environment variables like `AIRFLOW__SECRETS__BACKEND_KWARG__SECRET_ID` and `AIRFLOW__WORKERS__SECRETS_BACKEND_KWARG__SECRET_ID`) as synthetic config options wh…

▾ Sunlitapache · airflowEPSS 0.66%via NVD
CVE-2026-48891Medium· 4.3
2mo ago

A bug in Apache Airflow's `/ui/dependencies` scheduling graph endpoint applied the caller's readable-Dag filter to the top-level serialized Dag key but still emitted referenced Dag IDs through the `dep.source` and `dep.target` fields of …

A bug in Apache Airflow's `/ui/dependencies` scheduling graph endpoint applied the caller's readable-Dag filter to the top-level serialized Dag key but still emitted referenced Dag IDs through the `dep.source` and `dep.target` fields of …

▾ Sunlitapache · airflowEPSS 0.64%via NVD
GO-2026-5932None
2mo ago

The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues

The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues

▾ Sunlitx · golang.org/x/cryptovia OSV
GO-2026-5923None
2mo ago

Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write in github.com/coder/coder

Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write in github.com/coder/coder

▾ Sunlitcoder · github.com/coder/codervia OSV
GO-2026-5764None
2mo ago

DoS due to Panic in AWS SDK for Go v2 SDK EventStream Decoder in github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream

DoS due to Panic in AWS SDK for Go v2 SDK EventStream Decoder in github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream

▾ Sunlitaws · github.com/aws/aws-sdk-go-v2/aws/protocol/eventstreamvia OSV
GO-2026-5410None
2mo ago

SecretsVerifier accepts empty signing secret without precondition in github.com/slack-go/slack

SecretsVerifier accepts empty signing secret without precondition in github.com/slack-go/slack

▾ Sunlitslack-go · github.com/slack-go/slackvia OSV
CVE-2026-49296Medium· 6.5
2mo ago

Before apache-airflow 3.3.0, a user authorized to read one Dag could disclose the source of other Dags co-located in the same source file

Before apache-airflow 3.3.0, a user authorized to read one Dag could disclose the source of other Dags co-located in the same source file. `GET /api/v2/dagSources/{dag_id}` — and the equivalent Dag-source view in the UI — returned the en…

▾ Sunlitapache · airflowEPSS 0.60%via NVD
CVE-2026-33264Critical· 9.8
2mo ago

A bug in `BaseSerialization.deserialize()` allowed unrestricted `import_string()` of attacker-controlled class paths when the Scheduler /…

A bug in `BaseSerialization.deserialize()` allowed unrestricted `import_string()` of attacker-controlled class paths when the Scheduler / API Server loaded a serialized DAG: a DAG author could embed a malicious trigger into a DAG to gain…

▾ Midnightapache-airflow · apache-airflowEPSS 1.6%via OSV
MAL-2026-7467None
2mo ago

Malicious code in scanvia (PyPI)

Malicious code in scanvia (PyPI)

▾ Sunlitscanvia · scanviavia OSV
MAL-2026-7466None
2mo ago

Malicious code in scan-checker (PyPI)

Malicious code in scan-checker (PyPI)

▾ Sunlitscan-checker · scan-checkervia OSV
MAL-2026-7465None
2mo ago

Malicious code in quatre (PyPI)

Malicious code in quatre (PyPI)

▾ Sunlitquatre · quatrevia OSV
MAL-2026-7464None
2mo ago

Malicious code in pygremlinbox-malware-network-indicators (PyPI)

Malicious code in pygremlinbox-malware-network-indicators (PyPI)

▾ Sunlitpygremlinbox-malware-network-indicators · pygremlinbox-malware-network-indicatorsvia OSV
MAL-2026-7463None
2mo ago

Malicious code in pygremlinbox-malware-install-execution (PyPI)

Malicious code in pygremlinbox-malware-install-execution (PyPI)

▾ Sunlitpygremlinbox-malware-install-execution · pygremlinbox-malware-install-executionvia OSV
MAL-2026-7462None
2mo ago

Malicious code in pygremlinbox-malware-cryptomining-indicators (PyPI)

Malicious code in pygremlinbox-malware-cryptomining-indicators (PyPI)

▾ Sunlitpygremlinbox-malware-cryptomining-indicators · pygremlinbox-malware-cryptomining-indicatorsvia OSV
MAL-2026-7461None
2mo ago

Malicious code in pygremlinbox-malware-credential-harvesting (PyPI)

Malicious code in pygremlinbox-malware-credential-harvesting (PyPI)

▾ Sunlitpygremlinbox-malware-credential-harvesting · pygremlinbox-malware-credential-harvestingvia OSV
MAL-2026-7460None
2mo ago

Malicious code in pygremlinbox-malware-code-obfuscation (PyPI)

Malicious code in pygremlinbox-malware-code-obfuscation (PyPI)

▾ Sunlitpygremlinbox-malware-code-obfuscation · pygremlinbox-malware-code-obfuscationvia OSV
MAL-2026-7459None
2mo ago

Malicious code in pygremlinbox-malware-c2-beacon (PyPI)

Malicious code in pygremlinbox-malware-c2-beacon (PyPI)

▾ Sunlitpygremlinbox-malware-c2-beacon · pygremlinbox-malware-c2-beaconvia OSV
MAL-2026-7458None
2mo ago

Malicious code in pycryptoshuffle (PyPI)

Malicious code in pycryptoshuffle (PyPI)

▾ Sunlitpycryptoshuffle · pycryptoshufflevia OSV
MAL-2026-7457None
2mo ago

Malicious code in piirgg (PyPI)

Malicious code in piirgg (PyPI)

▾ Sunlitpiirgg · piirggvia OSV
MAL-2026-7456None
2mo ago

Malicious code in notrandompacketname (PyPI)

Malicious code in notrandompacketname (PyPI)

▾ Sunlitnotrandompacketname · notrandompacketnamevia OSV
CVEs tagged “osv” — page 43 · VulnSea