Tagged “osv”
CVEs tagged osv, newest first.
5681 CVEsRSS
CVE-2026-53540Low· 3.7python-multipart: Negative Content-Length in parse_form buffers the entire body in memory
python-multipart: Negative Content-Length in parse_form buffers the entire body in memory
CVE-2026-53539High· 7.5python-multipart: Quadratic-time querystring parsing with semicolon separators causes CPU denial of service
python-multipart: Quadratic-time querystring parsing with semicolon separators causes CPU denial of service
GHSA-pw6j-qg29-8w7fMedium· 5.9Tornado: CurlAsyncHTTPClient leaks per-request credentials on handle reuse
Tornado: CurlAsyncHTTPClient leaks per-request credentials on handle reuse
CVE-2026-54282Low· 3.7Starlette: Unvalidated request path concatenated into authority poisons request.url.hostname
Starlette: Unvalidated request path concatenated into authority poisons request.url.hostname
CVE-2026-54421Medium· 6.8OpenStack Ironic can return unredacted sensitive information when applying a PATCH to update fields in volume properties
OpenStack Ironic can return unredacted sensitive information when applying a PATCH to update fields in volume properties
MAL-2026-5768NoneMalicious code in bash8 (PyPI)
Malicious code in bash8 (PyPI)
CVE-2026-11624CriticalMCP Toolbox for Databases has an Origin Validation Error
MCP Toolbox for Databases has an Origin Validation Error
RUSTSEC-2026-0180NonePanic decoding a malformed `hstore` value allows denial of service
Panic decoding a malformed `hstore` value allows denial of service
RUSTSEC-2026-0179NoneUnbounded SCRAM iteration count allows a malicious server to cause CPU-exhaustion denial of service
Unbounded SCRAM iteration count allows a malicious server to cause CPU-exhaustion denial of service
RUSTSEC-2026-0178NonePanic on a `DataRow` with fewer fields than columns allows denial of service
Panic on a `DataRow` with fewer fields than columns allows denial of service
CVE-2026-3433Medium· 4.3Mattermost doesn't restrict role_updated websocket event broadcasts to members of the affected team or channel
Mattermost doesn't restrict role_updated websocket event broadcasts to members of the affected team or channel
CVE-2026-6739Medium· 6.7Mattermost doesn't require system-level permission when patching protected default system roles
Mattermost doesn't require system-level permission when patching protected default system roles
CVE-2026-6689Medium· 4.3Mattermost doesn't enforce PermissionInviteUser when setting AllowOpenInvite or AllowedDomains during team creation
Mattermost doesn't enforce PermissionInviteUser when setting AllowOpenInvite or AllowedDomains during team creation
CVE-2026-7184Medium· 6.5Mattermost doesn't sanitize the Remote Cluster API response on PATCH operations
Mattermost doesn't sanitize the Remote Cluster API response on PATCH operations
CVE-2026-6961High· 7.6Mattermost doesn't sanitize FileInfo.Name received from federated peers during shared channel file sync
Mattermost doesn't sanitize FileInfo.Name received from federated peers during shared channel file sync
CVE-2026-7387High· 8.8Mattermost doesn't require role-management authorization when setting the scheme_admin flag on group syncable link and patch endpoints
Mattermost doesn't require role-management authorization when setting the scheme_admin flag on group syncable link and patch endpoints
CVE-2026-6046Medium· 5.3Mattermost doesn't validate that a username returned during bot registration belongs to a bot account
Mattermost doesn't validate that a username returned during bot registration belongs to a bot account
CVE-2026-45831High· 8.8ChromaDB's SimpleRBACAuthorizationProvider doesn't check which tenant, database, or collection a permission applies to
ChromaDB's SimpleRBACAuthorizationProvider doesn't check which tenant, database, or collection a permission applies to
CVE-2026-45833CriticalPoCChromaDB has a code injection vulnerability
ChromaDB has a code injection vulnerability
CVE-2026-45830High· 8.8ChromaDB allows any authenticated users to arbitrarily read, write, update, or delete data in any tenant's collection
ChromaDB allows any authenticated users to arbitrarily read, write, update, or delete data in any tenant's collection
CVE-2026-42306High· 7.2github.com/docker/docker: github.com/moby/moby: Moby container framework: Host file overwrite via race condition in docker cp mount setup (…
A flaw was found in the Moby container framework. A race condition occurs during the `docker cp` mount setup, which a malicious container can exploit. This vulnerability allows the container to redirect a bind mount target to an arbitrary …
MAL-2026-5698NoneMalicious code in nagios-xi (PyPI)
Malicious code in nagios-xi (PyPI)
CVE-2026-12681Medium· 6.8Go-Attestation: Hash injection into trusted measurement list via unskipped SignatureHeaderSize vendor bytes in parseEfiSignatureList()
Go-Attestation: Hash injection into trusted measurement list via unskipped SignatureHeaderSize vendor bytes in parseEfiSignatureList()
CVE-2026-48155Mediumpypdf: Possible large memory usage for large offsets for layout mode text
pypdf: Possible large memory usage for large offsets for layout mode text
CVE-2026-48156Low· 3.3pypdf: Possible long runtimes for zero-only width values in cross-reference streamsuntimes for zero-only width values in cross-reference …
pypdf: Possible long runtimes for zero-only width values in cross-reference streamsuntimes for zero-only width values in cross-reference streams
CVE-2026-49854Low· 3.7Tornado has out-of-bounds memory access via C extension
Tornado has out-of-bounds memory access via C extension
CVE-2026-11816High· 8.1Keras versions prior to 3.14.0 are vulnerable to a path traversal issue in the archive extraction utilities located in `keras/src/utils/f…
Keras versions prior to 3.14.0 are vulnerable to a path traversal issue in the archive extraction utilities located in `keras/src/utils/file_utils.py`. The functions `filter_safe_tarinfos()` and `filter_safe_zipinfos()` validate archive …
MAL-2026-5545NoneMalicious code in acme-widget-layout-utils (PyPI)
Malicious code in acme-widget-layout-utils (PyPI)
CVE-2026-48096Medium· 5.0OpenFGA has cache-key delimiter injection in shared-iterator and v2 iterator that caches enables intra-store authorization-decision poiso…
OpenFGA has cache-key delimiter injection in shared-iterator and v2 iterator that caches enables intra-store authorization-decision poisoning
RUSTSEC-2026-0175None`onering` 1.4.1 was removed from crates.io for malicious code
`onering` 1.4.1 was removed from crates.io for malicious code