VulnSea

Tagged “osv”

CVEs tagged osv, newest first.

5681 CVEsRSS

MAL-2026-5876None
3mo ago

Malicious code in temp-development-package-test (PyPI)

Malicious code in temp-development-package-test (PyPI)

▾ Sunlittemp-development-package-test · temp-development-package-testvia OSV
CVE-2026-55443Medium· 5.1
3mo ago

LangChain: Path traversal and sandbox escape in LangChain file-search middleware and loaders

LangChain: Path traversal and sandbox escape in LangChain file-search middleware and loaders

▾ Sunlitlangchain · langchainEPSS 0.21%via OSV
CVE-2026-56262Critical· 9.8
3mo ago

Crawl4AI: Multiple Docker API Vulnerabilities - File Write, SSRF, Auth Bypass, XSS, JS Execution

Crawl4AI: Multiple Docker API Vulnerabilities - File Write, SSRF, Auth Bypass, XSS, JS Execution

▾ Midnightcrawl4ai · crawl4aiEPSS 0.76%via OSV
CVE-2026-54530Medium
3mo ago

pypdf: Possible infinite loop when retrieving fonts for layout-mode text extraction

pypdf: Possible infinite loop when retrieving fonts for layout-mode text extraction

▾ Sunlitpypdf · pypdfEPSS 0.17%via OSV
CVE-2026-54531Medium
3mo ago

pypdf: Possible infinite loop when processing outlines/bookmarks in writer

pypdf: Possible infinite loop when processing outlines/bookmarks in writer

▾ Sunlitpypdf · pypdfEPSS 0.17%via OSV
GHSA-8rfp-98v4-mmr6Low· 0.0
3mo ago

Bleach: URI sanitization allows disallowed URI schemes with Unicode > U+00A0 in output

Bleach: URI sanitization allows disallowed URI schemes with Unicode > U+00A0 in output

▾ Sunlitbleach · bleachvia OSV
GHSA-gj48-438w-jh9vMedium· 6.1
3mo ago

Bleach clean() / Cleaner() fails to sanitize dangerous URI schemes in allowed formaction attributes

Bleach clean() / Cleaner() fails to sanitize dangerous URI schemes in allowed formaction attributes

▾ Sunlitbleach · bleachvia OSV
CVE-2026-46448Medium· 5.4
3mo ago

OpenStack Nova: Nova scheduler hint injection bypasses Placement resource claims and scheduling constraints

OpenStack Nova: Nova scheduler hint injection bypasses Placement resource claims and scheduling constraints

▾ Sunlitnova · novaEPSS 0.46%via OSV
CVE-2026-49468Critical· 9.8PoC
3mo ago

LiteLLM: Authentication Bypass via Host Header Injection

LiteLLM: Authentication Bypass via Host Header Injection

▾ Abyssallitellm · litellmEPSS 0.82%via OSV
CVE-2026-50891High· 8.1
3mo ago

Filestash allows attackers to escalate privileges via sending a crafted request

Filestash allows attackers to escalate privileges via sending a crafted request

▾ Twilightmickael-kerjean · github.com/mickael-kerjean/filestashEPSS 0.35%via OSV
CVE-2026-50884High· 8.8
3mo ago

statping-ng allows attackers to escalate privileges to Administrator and access sensitive components

statping-ng allows attackers to escalate privileges to Administrator and access sensitive components

▾ Twilightstatping-ng · github.com/statping-ng/statping-ngEPSS 0.42%via OSV
CVE-2026-50879High· 7.5
3mo ago

linx-server has an issue in the uploadPostHandler component that allows attackers to cause a Denial of Service (DoS) via a crafted POST r…

linx-server has an issue in the uploadPostHandler component that allows attackers to cause a Denial of Service (DoS) via a crafted POST request

▾ Twilightandreimarcu · github.com/andreimarcu/linx-serverEPSS 0.46%via OSV
CVE-2026-54786None
3mo ago

Leak in WASIp1 `fd_renumber` implementation

Leak in WASIp1 `fd_renumber` implementation

▾ Sunlitwasmtime-wasi · wasmtime-wasiEPSS 0.37%via OSV
MAL-2026-5824None
3mo ago

Malicious code in testpgagent (PyPI)

Malicious code in testpgagent (PyPI)

▾ Sunlittestpgagent · testpgagentvia OSV
MAL-2026-5812None
3mo ago

Malicious code in hello-test-s1 (PyPI)

Malicious code in hello-test-s1 (PyPI)

▾ Sunlithello-test-s1 · hello-test-s1via OSV
CVE-2026-48524Low· 3.7
3mo ago

PyJWKClient unbounded JWKS endpoint requests via attacker-controlled kid values (DoS)

PyJWKClient unbounded JWKS endpoint requests via attacker-controlled kid values (DoS)

▾ Sunlitpyjwt · pyjwtEPSS 0.32%via OSV
CVE-2026-48522Medium· 4.2
3mo ago

PyJWKClient: missing scheme allowlist enables CVE-2024-21643-class SSRF + token forgery via file://, ftp://, data: schemes

PyJWKClient: missing scheme allowlist enables CVE-2024-21643-class SSRF + token forgery via file://, ftp://, data: schemes

▾ Sunlitpyjwt · pyjwtEPSS 0.22%via OSV
CVE-2026-48525Medium· 5.3
3mo ago

PyJWT: Unauthenticated DoS via unbounded Base64URL decoding of unused payload segment in b64=false detached JWS

PyJWT: Unauthenticated DoS via unbounded Base64URL decoding of unused payload segment in b64=false detached JWS

▾ Sunlitpyjwt · pyjwtEPSS 0.41%via OSV
CVE-2026-50269Low
3mo ago

aiohttp: CRLF injection in multipart headers

aiohttp: CRLF injection in multipart headers

▾ Sunlitaiohttp · aiohttpEPSS 0.53%via OSV
CVE-2026-54279Low
3mo ago

aiohttp: Host-Only Cookies Become Domain Cookies After CookieJar Persistence

aiohttp: Host-Only Cookies Become Domain Cookies After CookieJar Persistence

▾ Sunlitaiohttp · aiohttpEPSS 0.49%via OSV
CVE-2026-54277Medium
3mo ago

aiohttp: C HTTP Parser Bypasses max_line_size for Fragmented Lines

aiohttp: C HTTP Parser Bypasses max_line_size for Fragmented Lines

▾ Sunlitaiohttp · aiohttpEPSS 0.56%via OSV
CVE-2026-54278Medium
3mo ago

aiohttp: Unread Compressed Request Bodies Bypass client_max_size During Cleanup

aiohttp: Unread Compressed Request Bodies Bypass client_max_size During Cleanup

▾ Sunlitaiohttp · aiohttpEPSS 0.49%via OSV
CVE-2026-54273Medium
3mo ago

aiohttp: HTTP/1 Pipelined Requests Queue Without Limit

aiohttp: HTTP/1 Pipelined Requests Queue Without Limit

▾ Sunlitaiohttp · aiohttpEPSS 0.49%via OSV
CVE-2026-54275Low
3mo ago

aiohttp: TLS Server Hostname Override Is Ignored When Reusing HTTPS Connections

aiohttp: TLS Server Hostname Override Is Ignored When Reusing HTTPS Connections

▾ Sunlitaiohttp · aiohttpEPSS 0.47%via OSV
CVE-2026-54274Medium
3mo ago

aiohttp: Incomplete websocket frame payloads bypass memory limits

aiohttp: Incomplete websocket frame payloads bypass memory limits

▾ Sunlitaiohttp · aiohttpEPSS 0.54%via OSV
GHSA-537c-gmf6-5ccfHigh· 7.5
3mo ago

Vulnerable OpenSSL included in cryptography wheels

Vulnerable OpenSSL included in cryptography wheels

▾ Twilightcryptography · cryptographyvia OSV
CVE-2026-48817Medium· 5.3
3mo ago

Starlette: Arbitrary HTTP method dispatched to `HTTPEndpoint` attributes via `getattr`

Starlette: Arbitrary HTTP method dispatched to `HTTPEndpoint` attributes via `getattr`

▾ Sunlitstarlette · starletteEPSS 0.35%via OSV
CVE-2026-48818High· 7.5
3mo ago

Starlette: SSRF and NTLM credential theft via UNC paths in StaticFiles on Windows

Starlette: SSRF and NTLM credential theft via UNC paths in StaticFiles on Windows

▾ Twilightstarlette · starletteEPSS 0.65%via OSV
CVE-2026-53537Low· 3.7
3mo ago

python-multipart: Content-Disposition parameter smuggling via RFC 2231/5987 extended parameters

python-multipart: Content-Disposition parameter smuggling via RFC 2231/5987 extended parameters

▾ Sunlitpython-multipart · python-multipartEPSS 0.29%via OSV
CVE-2026-53538Low· 3.7
3mo ago

python-multipart: Semicolon treated as querystring field separator enables parameter smuggling

python-multipart: Semicolon treated as querystring field separator enables parameter smuggling

▾ Sunlitpython-multipart · python-multipartEPSS 0.26%via OSV
CVEs tagged “osv” — page 50 · VulnSea