Tagged “osv”
CVEs tagged osv, newest first.
5681 CVEsRSS
MAL-2026-7455NoneMalicious code in myproject234 (PyPI)
Malicious code in myproject234 (PyPI)
MAL-2026-7454NoneMalicious code in cyberday26szymon-payments (PyPI)
Malicious code in cyberday26szymon-payments (PyPI)
MAL-2026-7453NoneMalicious code in cyberday26szymon-logging (PyPI)
Malicious code in cyberday26szymon-logging (PyPI)
MAL-2026-7452NoneMalicious code in cyberday26szymon-auth (PyPI)
Malicious code in cyberday26szymon-auth (PyPI)
PYSEC-2026-1075NoneMalicious code in tiktoken-mcp (PyPI)
Malicious code in tiktoken-mcp (PyPI)
PYSEC-2026-1074NoneMalicious code in ray-mcp-server (PyPI)
Malicious code in ray-mcp-server (PyPI)
PYSEC-2026-1073NoneMalicious code in orchestr8-platform (PyPI)
Malicious code in orchestr8-platform (PyPI)
PYSEC-2026-1072NoneMalicious code in openai-mcp (PyPI)
Malicious code in openai-mcp (PyPI)
PYSEC-2026-1071NoneMalicious code in mem8 (PyPI)
Malicious code in mem8 (PyPI)
PYSEC-2026-1070NoneMalicious code in langchain-core-mcp (PyPI)
Malicious code in langchain-core-mcp (PyPI)
PYSEC-2026-1069NoneMalicious code in instructor-mcp (PyPI)
Malicious code in instructor-mcp (PyPI)
PYSEC-2026-1068NoneMalicious code in dreamgen (PyPI)
Malicious code in dreamgen (PyPI)
MAL-2026-6945NoneMalicious code in jsonschemavalidation (PyPI)
Malicious code in jsonschemavalidation (PyPI)
MAL-2026-6929NoneMalicious code in paysafe-sdk (PyPI)
Malicious code in paysafe-sdk (PyPI)
MAL-2026-6928NoneMalicious code in paysafe-payments (PyPI)
Malicious code in paysafe-payments (PyPI)
MAL-2026-6927NoneMalicious code in paysafe-kyc (PyPI)
Malicious code in paysafe-kyc (PyPI)
MAL-2026-6926NoneMalicious code in paysafe-api (PyPI)
Malicious code in paysafe-api (PyPI)
GHSA-f66q-9rf6-8795MediumFlask-Security-Too: WebAuthn reauthentication freshness bypass via cross-user assertion
Flask-Security-Too: WebAuthn reauthentication freshness bypass via cross-user assertion
CVE-2026-44512Medium· 5.5ONNX has Null Pointer Dereference in Upsample Version Converter Adapter (Zero Inputs)
ONNX has Null Pointer Dereference in Upsample Version Converter Adapter (Zero Inputs)
CVE-2026-54234High· 7.5vllm: vLLM: Denial of Service via malformed speculative decoding workload (CVE-2026-54234)
A flaw was found in vLLM, a high-throughput and memory-efficient inference and serving engine for Large Language Models (LLMs). A remote attacker can exploit this vulnerability by sending a specially crafted multi-request speculative decod…
CVE-2026-55646Medium· 6.5vLLM is an inference and serving engine for large language models. From 0.22.0 to 0.23.0, the /v1/audio/transcriptions and /v1/audio/tran…
vLLM is an inference and serving engine for large language models. From 0.22.0 to 0.23.0, the /v1/audio/transcriptions and /v1/audio/translations routes call request.file.read() to fully materialize an uploaded audio file into memory bef…
CVE-2026-55574High· 7.5vllm: vLLM: Denial of Service via adversarial regular expression in structured outputs API (CVE-2026-55574)
A flaw was found in vLLM, a high-throughput and memory-efficient inference and serving engine for large language models (LLMs). A remote attacker could exploit this vulnerability by providing a specially crafted regular expression to the s…
CVE-2026-55380High· 7.5python-pillow: Pillow: Denial of Service via crafted GD 2.x image file (CVE-2026-55380)
A flaw was found in Pillow, a Python imaging library. A remote attacker could exploit this vulnerability by providing a specially crafted GD 2.x image file. The GdImageFile._open() function reads image dimensions without proper validation,…
CVE-2026-55379High· 7.5python-pillow: Pillow: Denial of Service via crafted BDF font file (CVE-2026-55379)
A flaw was found in Pillow, a Python imaging library. This vulnerability allows a remote attacker to cause a Denial of Service (DoS) by providing a specially crafted BDF font file. The library's image processing function fails to properly …
CVE-2026-54060High· 7.5python-pillow: Pillow: Denial of Service via excessive memory allocation when processing font files (CVE-2026-54060)
A flaw was found in Pillow, a Python imaging library. When processing a specially crafted font file, the library's font compilation function does not adequately check for excessive memory allocation. This oversight allows a remote attacker…
CVE-2026-49297High· 8.1Apache Airflow's Google provider operators `GCSToSFTPOperator` and `GCSTimeSpanFileTransformOperator` joined GCS object names returned by…
Apache Airflow's Google provider operators `GCSToSFTPOperator` and `GCSTimeSpanFileTransformOperator` joined GCS object names returned by the bucket listing API directly to a destination filesystem path without normalisation or containme…
CVE-2026-24014Critical· 9.8Apache IoTDB DataNode’s internal RPC interface for creating Trigger instances uses the uploaded Trigger JAR name to build a file path wit…
Apache IoTDB DataNode’s internal RPC interface for creating Trigger instances uses the uploaded Trigger JAR name to build a file path without sufficient validation. If the internal DataNode RPC port is exposed to an untrusted network, an…
CVE-2026-24013Critical· 9.1Authentication Bypass by Spoofing vulnerability in Apache IoTDB.
Authentication Bypass by Spoofing vulnerability in Apache IoTDB. Certain Thrift RPC query handlers lack strict validation of the sessionId parameter. An attacker can construct requests with a forged sessionId and, without performing open…
CVE-2026-24012High· 7.5Uncontrolled Resource Consumption vulnerability in Apache IoTDB.
Uncontrolled Resource Consumption vulnerability in Apache IoTDB. Some interface fails to impose reasonable limits on the time span and aggregation interval of the query. An attacker can construct a request with extreme parameters (e.g.…
MAL-2026-6759NoneMalicious code in urlllib321 (PyPI)
Malicious code in urlllib321 (PyPI)