VulnSea

Tagged “osv”

CVEs tagged osv, newest first.

5681 CVEsRSS

CVE-2026-57585High· 7.5
3mo ago

msgpack: MessagePack for Python: Denial of Service via Unpacker reuse after error (CVE-2026-57585)

A flaw was found in MessagePack for Python, a serializer implementation. This vulnerability, categorized as a Use-After-Free (CWE-416), occurs when the Unpacker component is reused after an error. A remote attacker could exploit this by re…

▾ TwilightRed Hat · Red Hat AI Inference Server 3.4EPSS 0.49%via CSAF
CVE-2026-27197Critical· 9.1
3mo ago

Sentry: Improper authentication on SAML SSO process allows user identity linking

Sentry: Improper authentication on SAML SSO process allows user identity linking

▾ Midnightsentry · sentryEPSS 0.58%via OSV
CVE-2020-7941Critical· 9.8
3mo ago

Plone Unauthenticated Write Vulnerability

Plone Unauthenticated Write Vulnerability

▾ Midnightplone-app-contenttypes · plone-app-contenttypesEPSS 2.3%via OSV
CVE-2026-11720Critical· 9.1
3mo ago

MCP Toolbox HTTP tool path parameters allow traversal to unintended endpoints

MCP Toolbox HTTP tool path parameters allow traversal to unintended endpoints

▾ Midnightgoogleapis · github.com/googleapis/mcp-toolboxEPSS 0.53%via OSV
MAL-2026-6593None
3mo ago

Malicious code in django-bkvision (PyPI)

Malicious code in django-bkvision (PyPI)

▾ Sunlitdjango-bkvision · django-bkvisionvia OSV
MAL-2026-6561None
3mo ago

Malicious code in skillspector (PyPI)

Malicious code in skillspector (PyPI)

▾ Sunlitskillspector · skillspectorvia OSV
CVE-2026-49486High· 7.5
3mo ago

The Apache Airflow FTP provider's `FTPSHook.get_conn()` created an `ftplib.FTP_TLS` connection but never called `prot_p()`, so although the control channel was TLS-protected the data channel was transmitted in cleartext

The Apache Airflow FTP provider's `FTPSHook.get_conn()` created an `ftplib.FTP_TLS` connection but never called `prot_p()`, so although the control channel was TLS-protected the data channel was transmitted in cleartext. Any deployment u…

▾ Twilightapache · apache-airflow-providers-ftpEPSS 0.44%via NVD
MAL-2026-6515None
3mo ago

Malicious code in sqligen (PyPI)

Malicious code in sqligen (PyPI)

▾ Sunlitsqligen · sqligenvia OSV
CVE-2026-48797Critical
3mo ago

Backpropagate: backprop ui --auth and backprop ui --share do not enforce authentication

Backpropagate: backprop ui --auth and backprop ui --share do not enforce authentication

▾ Midnightbackpropagate · backpropagateEPSS 0.57%via OSV
CVE-2026-48990Medium· 5.3
3mo ago

joserfc: b64=false RFC7797 JWS payloads bypass JWSRegistry payload-size limits during deserialization

joserfc: b64=false RFC7797 JWS payloads bypass JWSRegistry payload-size limits during deserialization

▾ Sunlitjoserfc · joserfcEPSS 0.27%via OSV
CVE-2026-77088Medium· 6.1
3mo ago

justhtml: to_markdown() code-span blank-line breakout enables XSS

justhtml: to_markdown() code-span blank-line breakout enables XSS

▾ Sunlitjusthtml · justhtmlEPSS 0.26%via OSV
CVE-2026-41568None
3mo ago

Race condition in 'docker cp' in github.com/docker/docker allows creation of arbitrary files

Race condition in 'docker cp' in github.com/docker/docker allows creation of arbitrary files

▾ Sunlitdocker · github.com/docker/dockerEPSS 0.10%via OSV
CVE-2026-40161None
3mo ago

Tekton Pipelines git resolver leaks API token to user-controlled serverURL in github.com/tektoncd/pipeline

Tekton Pipelines git resolver leaks API token to user-controlled serverURL in github.com/tektoncd/pipeline

▾ Sunlittektoncd · github.com/tektoncd/pipelineEPSS 0.43%via OSV
CVE-2026-40923None
3mo ago

Tekton Pipelines VolumeMount path restriction bypass via missing filepath.Clean in github.com/tektoncd/pipeline

Tekton Pipelines VolumeMount path restriction bypass via missing filepath.Clean in github.com/tektoncd/pipeline

▾ Sunlittektoncd · github.com/tektoncd/pipelineEPSS 0.32%via OSV
CVE-2026-25542None
3mo ago

Tekton Pipelines has VerificationPolicy regex pattern bypass via substring matching in github.com/tektoncd/pipeline

Tekton Pipelines has VerificationPolicy regex pattern bypass via substring matching in github.com/tektoncd/pipeline

▾ Sunlittektoncd · github.com/tektoncd/pipelineEPSS 0.39%via OSV
CVE-2026-40924None
3mo ago

Tekton Pipelines HTTP resolver denial of service via memory exhaustion in github.com/tektoncd/pipeline

Tekton Pipelines HTTP resolver denial of service via memory exhaustion in github.com/tektoncd/pipeline

▾ Sunlittektoncd · github.com/tektoncd/pipelineEPSS 0.47%via OSV
CVE-2026-42576None
3mo ago

apko `DiscoverKeys` has a panic on non-rsa jwks key that causes crash during key discovery in chainguard.dev/apko

apko `DiscoverKeys` has a panic on non-rsa jwks key that causes crash during key discovery in chainguard.dev/apko

▾ Sunlitapko · chainguard.dev/apkoEPSS 0.45%via OSV
CVE-2026-42575None
3mo ago

apko doesn't verify downloaded apk packages against APKINDEX checksum (package substitution possible) in chainguard.dev/apko

apko doesn't verify downloaded apk packages against APKINDEX checksum (package substitution possible) in chainguard.dev/apko

▾ Sunlitapko · chainguard.dev/apkoEPSS 0.23%via OSV
CVE-2026-40179NonePoC
3mo ago

Prometheus has Stored XSS via metric names and label values in Prometheus web UI in github.com/prometheus/prometheus

Prometheus has Stored XSS via metric names and label values in Prometheus web UI in github.com/prometheus/prometheus

▾ Twilightprometheus · github.com/prometheus/prometheusEPSS 0.31%via OSV
CVE-2026-58494Medium· 6.5
3mo ago

WASI hard links and renames bypass wasmtime-wasi's FilePerms for destination

WASI hard links and renames bypass wasmtime-wasi's FilePerms for destination

▾ Sunlitwasmtime-wasi · wasmtime-wasiEPSS 0.17%via OSV
CVE-2026-50221Medium· 5.4
3mo ago

OpenStack Swift vulnerable to authenticated server-side request forgery

OpenStack Swift vulnerable to authenticated server-side request forgery

▾ Sunlitswift · swiftEPSS 0.22%via OSV
CVE-2026-10609Medium· 6.8
3mo ago

OpenShift Cluster Logging Operator missing authorization flaw

OpenShift Cluster Logging Operator missing authorization flaw

▾ Sunlitopenshift · github.com/openshift/cluster-logging-operatorEPSS 0.38%via OSV
CVE-2026-56695Medium· 6.5
3mo ago

OpenHarness remote resume commands expose other users' saved session snapshots

OpenHarness remote resume commands expose other users' saved session snapshots

▾ Sunlitopenharness-ai · openharness-aiEPSS 0.40%via OSV
CVE-2026-56696Medium· 5.4
3mo ago

OpenHarness remote project-context commands allow persistent prompt poisoning

OpenHarness remote project-context commands allow persistent prompt poisoning

▾ Sunlitopenharness-ai · openharness-aiEPSS 0.37%via OSV
CVE-2026-45135High· 8.1
3mo ago

caddy: github.com/caddyserver/caddy/v2: Caddy: Remote Code Execution via Unsafe Unicode Handling in FastCGI (CVE-2026-45135)

A flaw was found in Caddy. This vulnerability stems from unsafe handling of Unicode characters within the FastCGI component, specifically when processing request paths containing non-ASCII bytes. An attacker capable of placing content into…

▾ TwilightRed Hat · github.com/caddyserver/caddy/v2EPSS 0.68%via CSAF
CVE-2023-54365High· 7.5
3mo ago

Traefik before 2.10.5 and 3.0.0-beta4 is affected by a denial-of-service vulnerability in HTTP/2 request handling inherited from the Go standard library's HTTP/2 implementation (CVE-2023-44487 / CVE-2023-39325, the 'Rapid Reset' techniqu…

Traefik before 2.10.5 and 3.0.0-beta4 is affected by a denial-of-service vulnerability in HTTP/2 request handling inherited from the Go standard library's HTTP/2 implementation (CVE-2023-44487 / CVE-2023-39325, the 'Rapid Reset' techniqu…

▾ Twilighttraefik · traefikEPSS 0.77%via NVD
MAL-2026-6327None
3mo ago

Malicious code in security-alerts-sdk (PyPI)

Malicious code in security-alerts-sdk (PyPI)

▾ Sunlitsecurity-alerts-sdk · security-alerts-sdkvia OSV
CVE-2026-9073Medium· 6.2
3mo ago

A flaw was found in foreman-mcp-server

A flaw was found in foreman-mcp-server. This component utilizes two distinct logging mechanisms that can expose sensitive session and authentication data. One mechanism logs session identifiers, which are treated as authentication creden…

▾ Sunlitredhat · satelliteEPSS 0.21%via NVD
CVE-2026-8823Low· 3.8
3mo ago

Mattermost has an Incorrect Authorization issue

Mattermost has an Incorrect Authorization issue

▾ Sunlitmattermost · github.com/mattermost/mattermost-serverEPSS 0.32%via OSV
CVE-2026-56104High· 7.4
3mo ago

Chainlit contains a session hijacking vulnerability

Chainlit contains a session hijacking vulnerability

▾ Twilightchainlit · chainlitEPSS 0.42%via OSV
CVEs tagged “osv” — page 46 · VulnSea