Tagged “osv”
CVEs tagged osv, newest first.
5681 CVEsRSS
MAL-2026-6975NoneMalicious code in oxntime (PyPI)
Malicious code in oxntime (PyPI)
MAL-2026-6974NoneMalicious code in tronhapy (PyPI)
Malicious code in tronhapy (PyPI)
MAL-2026-6971NoneMalicious code in tronhap (PyPI)
Malicious code in tronhap (PyPI)
MAL-2026-6970NoneMalicious code in jsonschemavalid (PyPI)
Malicious code in jsonschemavalid (PyPI)
CVE-2026-48828Medium· 6.5The Bulk Variables API in Apache Airflow called the redactor without passing the variable's key, so the key-based `should_hide_value_for_key` check (which triggers on secret-suffixed key names like `*_password` / `*_token` / `*_secret`) …
The Bulk Variables API in Apache Airflow called the redactor without passing the variable's key, so the key-based `should_hide_value_for_key` check (which triggers on secret-suffixed key names like `*_password` / `*_token` / `*_secret`) …
CVE-2026-58473Critical· 9.1Cognee allows non-superusers to overwrite global LLM configuration
Cognee allows non-superusers to overwrite global LLM configuration
CVE-2026-53878Medium· 6.1Django: DomainNameValidator permits newline characters that may enable HTTP header injection
Django: DomainNameValidator permits newline characters that may enable HTTP header injection
CVE-2026-53877Medium· 4.8Django: GDALRaster may over-read heap memory when constructed from bytes
Django: GDALRaster may over-read heap memory when constructed from bytes
CVE-2026-48588Low· 3.1Django: cache middleware may expose private responses when unrelated request cookies are present
Django: cache middleware may expose private responses when unrelated request cookies are present
CVE-2026-49487Medium· 6.5In Apache Airflow before 3.3.0, the REST API task-instance detail and list endpoints returned a deferred task's trigger kwargs without masking
In Apache Airflow before 3.3.0, the REST API task-instance detail and list endpoints returned a deferred task's trigger kwargs without masking. When a deferred operator passed a secret (for example a provider API key) into its trigger, a…
CVE-2026-48892Medium· 6.5The Config API in Apache Airflow surfaced per-key secrets-backend overrides (environment variables like `AIRFLOW__SECRETS__BACKEND_KWARG__SECRET_ID` and `AIRFLOW__WORKERS__SECRETS_BACKEND_KWARG__SECRET_ID`) as synthetic config options wh…
The Config API in Apache Airflow surfaced per-key secrets-backend overrides (environment variables like `AIRFLOW__SECRETS__BACKEND_KWARG__SECRET_ID` and `AIRFLOW__WORKERS__SECRETS_BACKEND_KWARG__SECRET_ID`) as synthetic config options wh…
CVE-2026-48891Medium· 4.3A bug in Apache Airflow's `/ui/dependencies` scheduling graph endpoint applied the caller's readable-Dag filter to the top-level serialized Dag key but still emitted referenced Dag IDs through the `dep.source` and `dep.target` fields of …
A bug in Apache Airflow's `/ui/dependencies` scheduling graph endpoint applied the caller's readable-Dag filter to the top-level serialized Dag key but still emitted referenced Dag IDs through the `dep.source` and `dep.target` fields of …
GO-2026-5932NoneThe golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues
The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues
GO-2026-5923NoneCoder's workspace agent API insecure redirect handling allowed cross-agent file read and write in github.com/coder/coder
Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write in github.com/coder/coder
GO-2026-5764NoneDoS due to Panic in AWS SDK for Go v2 SDK EventStream Decoder in github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream
DoS due to Panic in AWS SDK for Go v2 SDK EventStream Decoder in github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream
GO-2026-5410NoneSecretsVerifier accepts empty signing secret without precondition in github.com/slack-go/slack
SecretsVerifier accepts empty signing secret without precondition in github.com/slack-go/slack
CVE-2026-49296Medium· 6.5Before apache-airflow 3.3.0, a user authorized to read one Dag could disclose the source of other Dags co-located in the same source file
Before apache-airflow 3.3.0, a user authorized to read one Dag could disclose the source of other Dags co-located in the same source file. `GET /api/v2/dagSources/{dag_id}` — and the equivalent Dag-source view in the UI — returned the en…
CVE-2026-33264Critical· 9.8A bug in `BaseSerialization.deserialize()` allowed unrestricted `import_string()` of attacker-controlled class paths when the Scheduler /…
A bug in `BaseSerialization.deserialize()` allowed unrestricted `import_string()` of attacker-controlled class paths when the Scheduler / API Server loaded a serialized DAG: a DAG author could embed a malicious trigger into a DAG to gain…
MAL-2026-7467NoneMalicious code in scanvia (PyPI)
Malicious code in scanvia (PyPI)
MAL-2026-7466NoneMalicious code in scan-checker (PyPI)
Malicious code in scan-checker (PyPI)
MAL-2026-7465NoneMalicious code in quatre (PyPI)
Malicious code in quatre (PyPI)
MAL-2026-7464NoneMalicious code in pygremlinbox-malware-network-indicators (PyPI)
Malicious code in pygremlinbox-malware-network-indicators (PyPI)
MAL-2026-7463NoneMalicious code in pygremlinbox-malware-install-execution (PyPI)
Malicious code in pygremlinbox-malware-install-execution (PyPI)
MAL-2026-7462NoneMalicious code in pygremlinbox-malware-cryptomining-indicators (PyPI)
Malicious code in pygremlinbox-malware-cryptomining-indicators (PyPI)
MAL-2026-7461NoneMalicious code in pygremlinbox-malware-credential-harvesting (PyPI)
Malicious code in pygremlinbox-malware-credential-harvesting (PyPI)
MAL-2026-7460NoneMalicious code in pygremlinbox-malware-code-obfuscation (PyPI)
Malicious code in pygremlinbox-malware-code-obfuscation (PyPI)
MAL-2026-7459NoneMalicious code in pygremlinbox-malware-c2-beacon (PyPI)
Malicious code in pygremlinbox-malware-c2-beacon (PyPI)
MAL-2026-7458NoneMalicious code in pycryptoshuffle (PyPI)
Malicious code in pycryptoshuffle (PyPI)
MAL-2026-7457NoneMalicious code in piirgg (PyPI)
Malicious code in piirgg (PyPI)
MAL-2026-7456NoneMalicious code in notrandompacketname (PyPI)
Malicious code in notrandompacketname (PyPI)