Tagged “osv”
CVEs tagged osv, newest first.
5681 CVEsRSS
MAL-2026-6246NoneMalicious code in d0rk3r (PyPI)
Malicious code in d0rk3r (PyPI)
MAL-2026-6245NoneMalicious code in request-cache-py (PyPI)
Malicious code in request-cache-py (PyPI)
MAL-2026-6236NoneMalicious code in query-profile (PyPI)
Malicious code in query-profile (PyPI)
CVE-2026-63738Medium· 4.3SurrealDB: Field-level SELECT permissions bypassed via graph and reference traversals
SurrealDB: Field-level SELECT permissions bypassed via graph and reference traversals
CVE-2026-27878Medium· 6.5Grafana Tempo vulnerable to an out-of-memory crash
Grafana Tempo vulnerable to an out-of-memory crash
CVE-2026-66065Highouroboros-ai: Incomplete fix of CVE-2026-47211: untrusted project .env can still reach RCE via omitted execution-routing keys
ouroboros-ai: Incomplete fix of CVE-2026-47211: untrusted project .env can still reach RCE via omitted execution-routing keys
CVE-2026-58198Medium· 5.5ChatterBot: Symlink-Following Arbitrary Write via UbuntuCorpusTrainer
ChatterBot: Symlink-Following Arbitrary Write via UbuntuCorpusTrainer
CVE-2026-58501Medium· 5.9Zeep: Server-Side Request Forgery (SSRF)
Zeep: Server-Side Request Forgery (SSRF)
CVE-2026-58404HighHugo: security.http.urls deny rules bypassed by alternate IPv4 encodings (SSRF)
Hugo: security.http.urls deny rules bypassed by alternate IPv4 encodings (SSRF)
CVE-2026-58402MediumHugo: XSS via unescaped code-fence language in default code block renderer
Hugo: XSS via unescaped code-fence language in default code block renderer
CVE-2026-58403MediumHugo: Symlink confinement bypass in os.ReadFile
Hugo: Symlink confinement bypass in os.ReadFile
CVE-2026-59152High· 7.7LangSmith SDK TracingMiddleware: Arbitrary server-side file read
LangSmith SDK TracingMiddleware: Arbitrary server-side file read
CVE-2026-58266Medium· 6.5Anki: User scripts in iframes have access to the internal Anki API
Anki: User scripts in iframes have access to the internal Anki API
CVE-2026-59153HighAnki's local HTTP server does not sufficiently validate requests
Anki's local HTTP server does not sufficiently validate requests
CVE-2026-58203Medium· 5.3pydantic-settings: NestedSecretsSettingsSource follows symlinks outside secrets_dir, enabling local file read and bypassing secrets_dir_m…
pydantic-settings: NestedSecretsSettingsSource follows symlinks outside secrets_dir, enabling local file read and bypassing secrets_dir_max_size
CVE-2026-55865MediumPython Liquid: Infinite loop when parsing malformed `{% case %}` tags
Python Liquid: Infinite loop when parsing malformed `{% case %}` tags
CVE-2026-54911Medium· 6.5UltraJSON: Malformed/Truncated UTF-8 Accepted and Silently Rewritten in ujson.dumps()
UltraJSON: Malformed/Truncated UTF-8 Accepted and Silently Rewritten in ujson.dumps()
CVE-2026-54762High· 8.6Traefik Kubernetes Ingress NGINX provider fails open when auth-secret resolution fails
Traefik Kubernetes Ingress NGINX provider fails open when auth-secret resolution fails
CVE-2026-55423Medium· 6.1Langflow: Logout button does not clear session
Langflow: Logout button does not clear session
CVE-2026-57209HighHeimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy Mode
Heimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy Mode
CVE-2026-57210HighHeimdall: IP Spoofing via Unvalidated Forwarding Headers
Heimdall: IP Spoofing via Unvalidated Forwarding Headers
CVE-2026-57118Critical· 9.8PraisonAI AgentTeam.launch exposes unauthenticated remote agent listing and invocation endpoints
PraisonAI AgentTeam.launch exposes unauthenticated remote agent listing and invocation endpoints
CVE-2026-57117High· 8.8PraisonAI: Compute-bridged file tools allow shell command injection
PraisonAI: Compute-bridged file tools allow shell command injection
CVE-2026-56838High· 7.8PraisonAI recipe.run_stream skips dangerous-tool policy enforcement
PraisonAI recipe.run_stream skips dangerous-tool policy enforcement
CVE-2026-57114High· 7.2PraisonAI: Jobs webhook SSRF protection bypass via DNS rebinding
PraisonAI: Jobs webhook SSRF protection bypass via DNS rebinding
CVE-2026-57121High· 8.1PraisonAI: Missing ownership check on DELETE endpoints allows members to delete others' content in Platform API
PraisonAI: Missing ownership check on DELETE endpoints allows members to delete others' content in Platform API
CVE-2026-56835High· 8.3PraisonAI Slack app_mention bypasses configured user/channel authorization
PraisonAI Slack app_mention bypasses configured user/channel authorization
CVE-2026-57146High· 7.5PraisonAI A2U incomplete authentication fix leaves current serve command unauthenticated by default
PraisonAI A2U incomplete authentication fix leaves current serve command unauthenticated by default
CVE-2026-56834High· 7.5PraisonAI dynamic-context artifact tools read arbitrary host files outside artifact storage
PraisonAI dynamic-context artifact tools read arbitrary host files outside artifact storage
CVE-2026-57496Critical· 9.6netlicensing-mcp: REST Path Traversal Bypasses Token Redaction
netlicensing-mcp: REST Path Traversal Bypasses Token Redaction