VulnSea

Tagged “osv”

CVEs tagged osv, newest first.

5681 CVEsRSS

MAL-2026-7455None
2mo ago

Malicious code in myproject234 (PyPI)

Malicious code in myproject234 (PyPI)

▾ Sunlitmyproject234 · myproject234via OSV
MAL-2026-7454None
2mo ago

Malicious code in cyberday26szymon-payments (PyPI)

Malicious code in cyberday26szymon-payments (PyPI)

▾ Sunlitcyberday26szymon-payments · cyberday26szymon-paymentsvia OSV
MAL-2026-7453None
2mo ago

Malicious code in cyberday26szymon-logging (PyPI)

Malicious code in cyberday26szymon-logging (PyPI)

▾ Sunlitcyberday26szymon-logging · cyberday26szymon-loggingvia OSV
MAL-2026-7452None
2mo ago

Malicious code in cyberday26szymon-auth (PyPI)

Malicious code in cyberday26szymon-auth (PyPI)

▾ Sunlitcyberday26szymon-auth · cyberday26szymon-authvia OSV
PYSEC-2026-1075None
2mo ago

Malicious code in tiktoken-mcp (PyPI)

Malicious code in tiktoken-mcp (PyPI)

▾ Sunlittiktoken-mcp · tiktoken-mcpvia OSV
PYSEC-2026-1074None
2mo ago

Malicious code in ray-mcp-server (PyPI)

Malicious code in ray-mcp-server (PyPI)

▾ Sunlitray-mcp-server · ray-mcp-servervia OSV
PYSEC-2026-1073None
2mo ago

Malicious code in orchestr8-platform (PyPI)

Malicious code in orchestr8-platform (PyPI)

▾ Sunlitorchestr8-platform · orchestr8-platformvia OSV
PYSEC-2026-1072None
2mo ago

Malicious code in openai-mcp (PyPI)

Malicious code in openai-mcp (PyPI)

▾ Sunlitopenai-mcp · openai-mcpvia OSV
PYSEC-2026-1071None
2mo ago

Malicious code in mem8 (PyPI)

Malicious code in mem8 (PyPI)

▾ Sunlitmem8 · mem8via OSV
PYSEC-2026-1070None
2mo ago

Malicious code in langchain-core-mcp (PyPI)

Malicious code in langchain-core-mcp (PyPI)

▾ Sunlitlangchain-core-mcp · langchain-core-mcpvia OSV
PYSEC-2026-1069None
2mo ago

Malicious code in instructor-mcp (PyPI)

Malicious code in instructor-mcp (PyPI)

▾ Sunlitinstructor-mcp · instructor-mcpvia OSV
PYSEC-2026-1068None
2mo ago

Malicious code in dreamgen (PyPI)

Malicious code in dreamgen (PyPI)

▾ Sunlitdreamgen · dreamgenvia OSV
MAL-2026-6945None
2mo ago

Malicious code in jsonschemavalidation (PyPI)

Malicious code in jsonschemavalidation (PyPI)

▾ Sunlitjsonschemavalidation · jsonschemavalidationvia OSV
MAL-2026-6929None
2mo ago

Malicious code in paysafe-sdk (PyPI)

Malicious code in paysafe-sdk (PyPI)

▾ Sunlitpaysafe-sdk · paysafe-sdkvia OSV
MAL-2026-6928None
2mo ago

Malicious code in paysafe-payments (PyPI)

Malicious code in paysafe-payments (PyPI)

▾ Sunlitpaysafe-payments · paysafe-paymentsvia OSV
MAL-2026-6927None
2mo ago

Malicious code in paysafe-kyc (PyPI)

Malicious code in paysafe-kyc (PyPI)

▾ Sunlitpaysafe-kyc · paysafe-kycvia OSV
MAL-2026-6926None
2mo ago

Malicious code in paysafe-api (PyPI)

Malicious code in paysafe-api (PyPI)

▾ Sunlitpaysafe-api · paysafe-apivia OSV
GHSA-f66q-9rf6-8795Medium
2mo ago

Flask-Security-Too: WebAuthn reauthentication freshness bypass via cross-user assertion

Flask-Security-Too: WebAuthn reauthentication freshness bypass via cross-user assertion

▾ Sunlitflask-security-too · flask-security-toovia OSV
CVE-2026-44512Medium· 5.5
2mo ago

ONNX has Null Pointer Dereference in Upsample Version Converter Adapter (Zero Inputs)

ONNX has Null Pointer Dereference in Upsample Version Converter Adapter (Zero Inputs)

▾ Sunlitonnx · onnxEPSS 0.19%via OSV
CVE-2026-54234High· 7.5
2mo ago

vllm: vLLM: Denial of Service via malformed speculative decoding workload (CVE-2026-54234)

A flaw was found in vLLM, a high-throughput and memory-efficient inference and serving engine for Large Language Models (LLMs). A remote attacker can exploit this vulnerability by sending a specially crafted multi-request speculative decod…

▾ TwilightRed Hat · Red Hat AI Inference Server 3.4EPSS 0.62%via CSAF
CVE-2026-55646Medium· 6.5
2mo ago

vLLM is an inference and serving engine for large language models. From 0.22.0 to 0.23.0, the /v1/audio/transcriptions and /v1/audio/tran…

vLLM is an inference and serving engine for large language models. From 0.22.0 to 0.23.0, the /v1/audio/transcriptions and /v1/audio/translations routes call request.file.read() to fully materialize an uploaded audio file into memory bef…

▾ Sunlitvllm · vllmEPSS 0.52%via OSV
CVE-2026-55574High· 7.5
2mo ago

vllm: vLLM: Denial of Service via adversarial regular expression in structured outputs API (CVE-2026-55574)

A flaw was found in vLLM, a high-throughput and memory-efficient inference and serving engine for large language models (LLMs). A remote attacker could exploit this vulnerability by providing a specially crafted regular expression to the s…

▾ TwilightRed Hat · Red Hat AI Inference Server 3.4EPSS 0.58%via CSAF
CVE-2026-55380High· 7.5
2mo ago

python-pillow: Pillow: Denial of Service via crafted GD 2.x image file (CVE-2026-55380)

A flaw was found in Pillow, a Python imaging library. A remote attacker could exploit this vulnerability by providing a specially crafted GD 2.x image file. The GdImageFile._open() function reads image dimensions without proper validation,…

▾ TwilightRed Hat · Red Hat OpenShift AI 3.4EPSS 0.64%via CSAF
CVE-2026-55379High· 7.5
2mo ago

python-pillow: Pillow: Denial of Service via crafted BDF font file (CVE-2026-55379)

A flaw was found in Pillow, a Python imaging library. This vulnerability allows a remote attacker to cause a Denial of Service (DoS) by providing a specially crafted BDF font file. The library's image processing function fails to properly …

▾ TwilightRed Hat · Red Hat OpenShift AI 3.4EPSS 0.65%via CSAF
CVE-2026-54060High· 7.5
2mo ago

python-pillow: Pillow: Denial of Service via excessive memory allocation when processing font files (CVE-2026-54060)

A flaw was found in Pillow, a Python imaging library. When processing a specially crafted font file, the library's font compilation function does not adequately check for excessive memory allocation. This oversight allows a remote attacker…

▾ TwilightRed Hat · Red Hat OpenShift AI 3.4EPSS 0.64%via CSAF
CVE-2026-49297High· 8.1
2mo ago

Apache Airflow's Google provider operators `GCSToSFTPOperator` and `GCSTimeSpanFileTransformOperator` joined GCS object names returned by…

Apache Airflow's Google provider operators `GCSToSFTPOperator` and `GCSTimeSpanFileTransformOperator` joined GCS object names returned by the bucket listing API directly to a destination filesystem path without normalisation or containme…

▾ Twilightapache-airflow-providers-google · apache-airflow-providers-googleEPSS 0.99%via OSV
CVE-2026-24014Critical· 9.8
2mo ago

Apache IoTDB DataNode’s internal RPC interface for creating Trigger instances uses the uploaded Trigger JAR name to build a file path wit…

Apache IoTDB DataNode’s internal RPC interface for creating Trigger instances uses the uploaded Trigger JAR name to build a file path without sufficient validation. If the internal DataNode RPC port is exposed to an untrusted network, an…

▾ Midnightapache-iotdb · apache-iotdbEPSS 0.69%via OSV
CVE-2026-24013Critical· 9.1
2mo ago

Authentication Bypass by Spoofing vulnerability in Apache IoTDB.

Authentication Bypass by Spoofing vulnerability in Apache IoTDB. Certain Thrift RPC query handlers lack strict validation of the sessionId parameter. An attacker can construct requests with a forged sessionId and, without performing open…

▾ Midnightapache-iotdb · apache-iotdbEPSS 0.64%via OSV
CVE-2026-24012High· 7.5
2mo ago

Uncontrolled Resource Consumption vulnerability in Apache IoTDB. 

Uncontrolled Resource Consumption vulnerability in Apache IoTDB.  Some interface fails to impose reasonable limits on the time span and aggregation interval of the query. An attacker can construct a request with extreme parameters (e.g.…

▾ Twilightapache-iotdb · apache-iotdbEPSS 0.74%via OSV
MAL-2026-6759None
2mo ago

Malicious code in urlllib321 (PyPI)

Malicious code in urlllib321 (PyPI)

▾ Sunliturlllib321 · urlllib321via OSV
CVEs tagged “osv” — page 44 · VulnSea