Tagged “osv”
CVEs tagged osv, newest first.
5681 CVEsRSS
MAL-2026-5876NoneMalicious code in temp-development-package-test (PyPI)
Malicious code in temp-development-package-test (PyPI)
CVE-2026-55443Medium· 5.1LangChain: Path traversal and sandbox escape in LangChain file-search middleware and loaders
LangChain: Path traversal and sandbox escape in LangChain file-search middleware and loaders
CVE-2026-56262Critical· 9.8Crawl4AI: Multiple Docker API Vulnerabilities - File Write, SSRF, Auth Bypass, XSS, JS Execution
Crawl4AI: Multiple Docker API Vulnerabilities - File Write, SSRF, Auth Bypass, XSS, JS Execution
CVE-2026-54530Mediumpypdf: Possible infinite loop when retrieving fonts for layout-mode text extraction
pypdf: Possible infinite loop when retrieving fonts for layout-mode text extraction
CVE-2026-54531Mediumpypdf: Possible infinite loop when processing outlines/bookmarks in writer
pypdf: Possible infinite loop when processing outlines/bookmarks in writer
GHSA-8rfp-98v4-mmr6Low· 0.0Bleach: URI sanitization allows disallowed URI schemes with Unicode > U+00A0 in output
Bleach: URI sanitization allows disallowed URI schemes with Unicode > U+00A0 in output
GHSA-gj48-438w-jh9vMedium· 6.1Bleach clean() / Cleaner() fails to sanitize dangerous URI schemes in allowed formaction attributes
Bleach clean() / Cleaner() fails to sanitize dangerous URI schemes in allowed formaction attributes
CVE-2026-46448Medium· 5.4OpenStack Nova: Nova scheduler hint injection bypasses Placement resource claims and scheduling constraints
OpenStack Nova: Nova scheduler hint injection bypasses Placement resource claims and scheduling constraints
CVE-2026-49468Critical· 9.8PoCLiteLLM: Authentication Bypass via Host Header Injection
LiteLLM: Authentication Bypass via Host Header Injection
CVE-2026-50891High· 8.1Filestash allows attackers to escalate privileges via sending a crafted request
Filestash allows attackers to escalate privileges via sending a crafted request
CVE-2026-50884High· 8.8statping-ng allows attackers to escalate privileges to Administrator and access sensitive components
statping-ng allows attackers to escalate privileges to Administrator and access sensitive components
CVE-2026-50879High· 7.5linx-server has an issue in the uploadPostHandler component that allows attackers to cause a Denial of Service (DoS) via a crafted POST r…
linx-server has an issue in the uploadPostHandler component that allows attackers to cause a Denial of Service (DoS) via a crafted POST request
CVE-2026-54786NoneLeak in WASIp1 `fd_renumber` implementation
Leak in WASIp1 `fd_renumber` implementation
MAL-2026-5824NoneMalicious code in testpgagent (PyPI)
Malicious code in testpgagent (PyPI)
MAL-2026-5812NoneMalicious code in hello-test-s1 (PyPI)
Malicious code in hello-test-s1 (PyPI)
CVE-2026-48524Low· 3.7PyJWKClient unbounded JWKS endpoint requests via attacker-controlled kid values (DoS)
PyJWKClient unbounded JWKS endpoint requests via attacker-controlled kid values (DoS)
CVE-2026-48522Medium· 4.2PyJWKClient: missing scheme allowlist enables CVE-2024-21643-class SSRF + token forgery via file://, ftp://, data: schemes
PyJWKClient: missing scheme allowlist enables CVE-2024-21643-class SSRF + token forgery via file://, ftp://, data: schemes
CVE-2026-48525Medium· 5.3PyJWT: Unauthenticated DoS via unbounded Base64URL decoding of unused payload segment in b64=false detached JWS
PyJWT: Unauthenticated DoS via unbounded Base64URL decoding of unused payload segment in b64=false detached JWS
CVE-2026-50269Lowaiohttp: CRLF injection in multipart headers
aiohttp: CRLF injection in multipart headers
CVE-2026-54279Lowaiohttp: Host-Only Cookies Become Domain Cookies After CookieJar Persistence
aiohttp: Host-Only Cookies Become Domain Cookies After CookieJar Persistence
CVE-2026-54277Mediumaiohttp: C HTTP Parser Bypasses max_line_size for Fragmented Lines
aiohttp: C HTTP Parser Bypasses max_line_size for Fragmented Lines
CVE-2026-54278Mediumaiohttp: Unread Compressed Request Bodies Bypass client_max_size During Cleanup
aiohttp: Unread Compressed Request Bodies Bypass client_max_size During Cleanup
CVE-2026-54273Mediumaiohttp: HTTP/1 Pipelined Requests Queue Without Limit
aiohttp: HTTP/1 Pipelined Requests Queue Without Limit
CVE-2026-54275Lowaiohttp: TLS Server Hostname Override Is Ignored When Reusing HTTPS Connections
aiohttp: TLS Server Hostname Override Is Ignored When Reusing HTTPS Connections
CVE-2026-54274Mediumaiohttp: Incomplete websocket frame payloads bypass memory limits
aiohttp: Incomplete websocket frame payloads bypass memory limits
GHSA-537c-gmf6-5ccfHigh· 7.5Vulnerable OpenSSL included in cryptography wheels
Vulnerable OpenSSL included in cryptography wheels
CVE-2026-48817Medium· 5.3Starlette: Arbitrary HTTP method dispatched to `HTTPEndpoint` attributes via `getattr`
Starlette: Arbitrary HTTP method dispatched to `HTTPEndpoint` attributes via `getattr`
CVE-2026-48818High· 7.5Starlette: SSRF and NTLM credential theft via UNC paths in StaticFiles on Windows
Starlette: SSRF and NTLM credential theft via UNC paths in StaticFiles on Windows
CVE-2026-53537Low· 3.7python-multipart: Content-Disposition parameter smuggling via RFC 2231/5987 extended parameters
python-multipart: Content-Disposition parameter smuggling via RFC 2231/5987 extended parameters
CVE-2026-53538Low· 3.7python-multipart: Semicolon treated as querystring field separator enables parameter smuggling
python-multipart: Semicolon treated as querystring field separator enables parameter smuggling