Tagged “osv”
CVEs tagged osv, newest first.
5681 CVEsRSS
CVE-2026-57585High· 7.5msgpack: MessagePack for Python: Denial of Service via Unpacker reuse after error (CVE-2026-57585)
A flaw was found in MessagePack for Python, a serializer implementation. This vulnerability, categorized as a Use-After-Free (CWE-416), occurs when the Unpacker component is reused after an error. A remote attacker could exploit this by re…
CVE-2026-27197Critical· 9.1Sentry: Improper authentication on SAML SSO process allows user identity linking
Sentry: Improper authentication on SAML SSO process allows user identity linking
CVE-2020-7941Critical· 9.8Plone Unauthenticated Write Vulnerability
Plone Unauthenticated Write Vulnerability
CVE-2026-11720Critical· 9.1MCP Toolbox HTTP tool path parameters allow traversal to unintended endpoints
MCP Toolbox HTTP tool path parameters allow traversal to unintended endpoints
MAL-2026-6593NoneMalicious code in django-bkvision (PyPI)
Malicious code in django-bkvision (PyPI)
MAL-2026-6561NoneMalicious code in skillspector (PyPI)
Malicious code in skillspector (PyPI)
CVE-2026-49486High· 7.5The Apache Airflow FTP provider's `FTPSHook.get_conn()` created an `ftplib.FTP_TLS` connection but never called `prot_p()`, so although the control channel was TLS-protected the data channel was transmitted in cleartext
The Apache Airflow FTP provider's `FTPSHook.get_conn()` created an `ftplib.FTP_TLS` connection but never called `prot_p()`, so although the control channel was TLS-protected the data channel was transmitted in cleartext. Any deployment u…
MAL-2026-6515NoneMalicious code in sqligen (PyPI)
Malicious code in sqligen (PyPI)
CVE-2026-48797CriticalBackpropagate: backprop ui --auth and backprop ui --share do not enforce authentication
Backpropagate: backprop ui --auth and backprop ui --share do not enforce authentication
CVE-2026-48990Medium· 5.3joserfc: b64=false RFC7797 JWS payloads bypass JWSRegistry payload-size limits during deserialization
joserfc: b64=false RFC7797 JWS payloads bypass JWSRegistry payload-size limits during deserialization
CVE-2026-77088Medium· 6.1justhtml: to_markdown() code-span blank-line breakout enables XSS
justhtml: to_markdown() code-span blank-line breakout enables XSS
CVE-2026-41568NoneRace condition in 'docker cp' in github.com/docker/docker allows creation of arbitrary files
Race condition in 'docker cp' in github.com/docker/docker allows creation of arbitrary files
CVE-2026-40161NoneTekton Pipelines git resolver leaks API token to user-controlled serverURL in github.com/tektoncd/pipeline
Tekton Pipelines git resolver leaks API token to user-controlled serverURL in github.com/tektoncd/pipeline
CVE-2026-40923NoneTekton Pipelines VolumeMount path restriction bypass via missing filepath.Clean in github.com/tektoncd/pipeline
Tekton Pipelines VolumeMount path restriction bypass via missing filepath.Clean in github.com/tektoncd/pipeline
CVE-2026-25542NoneTekton Pipelines has VerificationPolicy regex pattern bypass via substring matching in github.com/tektoncd/pipeline
Tekton Pipelines has VerificationPolicy regex pattern bypass via substring matching in github.com/tektoncd/pipeline
CVE-2026-40924NoneTekton Pipelines HTTP resolver denial of service via memory exhaustion in github.com/tektoncd/pipeline
Tekton Pipelines HTTP resolver denial of service via memory exhaustion in github.com/tektoncd/pipeline
CVE-2026-42576Noneapko `DiscoverKeys` has a panic on non-rsa jwks key that causes crash during key discovery in chainguard.dev/apko
apko `DiscoverKeys` has a panic on non-rsa jwks key that causes crash during key discovery in chainguard.dev/apko
CVE-2026-42575Noneapko doesn't verify downloaded apk packages against APKINDEX checksum (package substitution possible) in chainguard.dev/apko
apko doesn't verify downloaded apk packages against APKINDEX checksum (package substitution possible) in chainguard.dev/apko
CVE-2026-40179NonePoCPrometheus has Stored XSS via metric names and label values in Prometheus web UI in github.com/prometheus/prometheus
Prometheus has Stored XSS via metric names and label values in Prometheus web UI in github.com/prometheus/prometheus
CVE-2026-58494Medium· 6.5WASI hard links and renames bypass wasmtime-wasi's FilePerms for destination
WASI hard links and renames bypass wasmtime-wasi's FilePerms for destination
CVE-2026-50221Medium· 5.4OpenStack Swift vulnerable to authenticated server-side request forgery
OpenStack Swift vulnerable to authenticated server-side request forgery
CVE-2026-10609Medium· 6.8OpenShift Cluster Logging Operator missing authorization flaw
OpenShift Cluster Logging Operator missing authorization flaw
CVE-2026-56695Medium· 6.5OpenHarness remote resume commands expose other users' saved session snapshots
OpenHarness remote resume commands expose other users' saved session snapshots
CVE-2026-56696Medium· 5.4OpenHarness remote project-context commands allow persistent prompt poisoning
OpenHarness remote project-context commands allow persistent prompt poisoning
CVE-2026-45135High· 8.1caddy: github.com/caddyserver/caddy/v2: Caddy: Remote Code Execution via Unsafe Unicode Handling in FastCGI (CVE-2026-45135)
A flaw was found in Caddy. This vulnerability stems from unsafe handling of Unicode characters within the FastCGI component, specifically when processing request paths containing non-ASCII bytes. An attacker capable of placing content into…
CVE-2023-54365High· 7.5Traefik before 2.10.5 and 3.0.0-beta4 is affected by a denial-of-service vulnerability in HTTP/2 request handling inherited from the Go standard library's HTTP/2 implementation (CVE-2023-44487 / CVE-2023-39325, the 'Rapid Reset' techniqu…
Traefik before 2.10.5 and 3.0.0-beta4 is affected by a denial-of-service vulnerability in HTTP/2 request handling inherited from the Go standard library's HTTP/2 implementation (CVE-2023-44487 / CVE-2023-39325, the 'Rapid Reset' techniqu…
MAL-2026-6327NoneMalicious code in security-alerts-sdk (PyPI)
Malicious code in security-alerts-sdk (PyPI)
CVE-2026-9073Medium· 6.2A flaw was found in foreman-mcp-server
A flaw was found in foreman-mcp-server. This component utilizes two distinct logging mechanisms that can expose sensitive session and authentication data. One mechanism logs session identifiers, which are treated as authentication creden…
CVE-2026-8823Low· 3.8Mattermost has an Incorrect Authorization issue
Mattermost has an Incorrect Authorization issue
CVE-2026-56104High· 7.4Chainlit contains a session hijacking vulnerability
Chainlit contains a session hijacking vulnerability