Tagged “osv”
CVEs tagged osv, newest first.
5642 CVEsRSS
CVE-2026-62987Medium· 5.8PoCFabio is an HTTP(S) and TCP router for deploying applications managed by consul
Fabio is an HTTP(S) and TCP router for deploying applications managed by consul. From 1.6.6 until 1.7.2, the CVE-2025-48865 fix in proxy/http_headers.go uses protectHeaders for a hardcoded set of forwarded headers but omits the operator-…
CVE-2026-77582Medium· 6.9PoCTinyauth is an authentication and authorization server
Tinyauth is an authentication and authorization server. Prior to 5.1.0, Tinyauth exposes a remotely observable timing difference between authentication attempts for existing and nonexistent local usernames. internal/controller/user_contr…
CVE-2026-77560High· 8.1Tinyauth is an authentication and authorization server
Tinyauth is an authentication and authorization server. Prior to 5.1.2, Tinyauth compares forwarded hostnames case-sensitively while reverse proxies route equivalent hostnames case-insensitively, allowing an authenticated low-privilege u…
RUSTSEC-2026-0296None`unzip` is unmaintained
`unzip` is unmaintained
CVE-2026-61681Medium· 4.1Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale
Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.91.1, the SNS UnsubscribeConfirmation handler in internal/integrations/ingestors/sns/sns.go calls http.Get() on payload.Unsub…
CVE-2026-63342Medium· 6.3Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale
Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.91.1, api-contracts/openapi/paths/v1/workflow-runs/workflow_run.yaml defines the GET /api/v1/stable/durable-tasks/{durable-ta…
CVE-2026-84298Low· 3.1Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale
Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.95.3, the V1 DurableTask stream handler stores worker-supplied task_external_id values in the durableInvocations routing map …
CVE-2026-88978Medium· 4.3Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale
Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.106.1, the WorkerStatus gRPC polling path in pkg/repository/durable_events.go passes caller-supplied durable task, node, and …
CVE-2026-61687High· 7.1Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale
Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.91.1, ValidateOAuthState clears the oauth_state_ session value to an empty string after a successful OAuth callback and later…
RUSTSEC-2026-0293NoneDouble free / use-after-free in `Consumer::skip` and `Consumer::clear` when an element's `Drop` panics
Double free / use-after-free in `Consumer::skip` and `Consumer::clear` when an element's `Drop` panics
MAL-2026-16346Critical⚠ ExploitedMalicious code in rrs (PyPI)
Malicious code in rrs (PyPI)
CVE-2026-71543High· 7.2OpenBao is an open source identity-based secrets management system
OpenBao is an open source identity-based secrets management system. Prior to 2.6.0, templated ACL, PKI, and SSH policies could substitute attacker-controlled identity data without rejecting syntax-significant characters. In ACL templated…
CVE-2026-61628High· 8.1PoCnginx ignition is a user interface for the nginx web server
nginx ignition is a user interface for the nginx web server. Prior to version 2.41.1, `POST /api/users/onboarding/finish` is registered as anonymous (unauthenticated) and creates a user with full ReadWrite admin permissions. Because the …
CVE-2026-61629High· 7.5PoCnginx ignition is a user interface for the nginx web server
nginx ignition is a user interface for the nginx web server. In versions 2.29.0 through 2.40.0, the gin i18n middleware in nginx-ignition's API server runs in front of every HTTP request and calls `golang.org/x/text/language.ParseAcceptL…
CVE-2026-61630Medium· 4.2nginx ignition is a user interface for the nginx web server
nginx ignition is a user interface for the nginx web server. In versions 2.33.0 through 2.35.0, any user that has enabled the OTP 2FA can have their TOTP reused during the standard 30 second validity window. Version 2.35.1 patches the is…
CVE-2026-82355Medium· 4.2When a request to the Airflow core API carries both a session cookie and an explicit `Authorization: Bearer` token, Airflow resolves the caller from the cookie and ignores the bearer token, inverting the intended precedence of bearer ove…
When a request to the Airflow core API carries both a session cookie and an explicit `Authorization: Bearer` token, Airflow resolves the caller from the cookie and ignores the bearer token, inverting the intended precedence of bearer ove…
CVE-2026-75158Medium· 4.3Apache Airflow's `/assets/events` API returned asset events for every Dag in the deployment, with no filter restricting them to the Dags the caller is authorized to read
Apache Airflow's `/assets/events` API returned asset events for every Dag in the deployment, with no filter restricting them to the Dags the caller is authorized to read. Any authenticated user holding asset-read access could therefore e…
CVE-2026-86473Critical· 9.1Apache Airflow: the Core API logout endpoint revokes only a session token presented as the _token cookie
Apache Airflow: the Core API logout endpoint revokes only a session token presented as the _token cookie. When a client logs out presenting its credential as an Authorization bearer header instead, the endpoint returns its normal logout …
CVE-2026-92612Low· 1.0PoCIn Eclipse iceoryx2 versions greater than v0.8.0, the StaticString exposes its contents as mutable bytes through safe APIs, while String::as_str() converts those bytes into a Rust string slice without validating UTF-8
In Eclipse iceoryx2 versions greater than v0.8.0, the StaticString exposes its contents as mutable bytes through safe APIs, while String::as_str() converts those bytes into a Rust string slice without validating UTF-8. An application can…
RUSTSEC-2026-0309None`SinglyLinkedList::remove` dereferences a null link
`SinglyLinkedList::remove` dereferences a null link
RUSTSEC-2026-0306None`hex_decode_unchecked` AVX2 path reads past `src`
`hex_decode_unchecked` AVX2 path reads past `src`
MAL-2026-16298Critical⚠ ExploitedMalicious code in urc (PyPI)
Malicious code in urc (PyPI)
RUSTSEC-2026-0294NoneUnsoundness in UTF-8 'String' trait
Unsoundness in UTF-8 'String' trait
MAL-2026-16296Critical⚠ ExploitedMalicious code in py-venv-doctor (PyPI)
Malicious code in py-venv-doctor (PyPI)
CVE-2026-61670Medium· 6.5microsandbox is an easy, fast, local-first microVM runtime and library
microsandbox is an easy, fast, local-first microVM runtime and library. Prior to 0.5.10, sdk/rust/lib/runtime/spawn.rs serializes NetworkConfig secret values into the --network-config argument and passes per-sandbox secrets through repea…
CVE-2026-77528Medium· 5.3Autobahn Python is a WebSocket and WAMP implementation for Python that supports Twisted and asyncio
Autobahn Python is a WebSocket and WAMP implementation for Python that supports Twisted and asyncio. Prior to 26.7.1, WebSocket endpoints that accept permessage-deflate and rely on maxMessagePayloadSize enforce that limit against the com…
GHSA-xwmw-prc4-v3crHigh· 8.8Obot: OAuth Dynamic Client Registration Enables API Token Theft via Audience Confusion
Obot: OAuth Dynamic Client Registration Enables API Token Theft via Audience Confusion
GHSA-pr6h-vr44-xq8jMedium· 5.3Obot: MCP Registry API readable without authentication
Obot: MCP Registry API readable without authentication
GHSA-jgh3-fggc-mcpmHigh· 7.6Obot: Server-Side Request Forgery via remote MCP server URL
Obot: Server-Side Request Forgery via remote MCP server URL
CVE-2026-59163Critical· 9.1PoCMnemosyne is a memory layer for artificial intelligence agents
Mnemosyne is a memory layer for artificial intelligence agents. Prior to v3.10.1, the auth check in mnemosyne/core/sync_server.py parsed the JWT's header and payload using base64 decoding, then passed the token to a jwt library call with…