Tagged “osv”
CVEs tagged osv, newest first.
5683 CVEsRSS
MAL-2026-5317NoneMalicious code in instructor-mcp (PyPI)
Malicious code in instructor-mcp (PyPI)
MAL-2026-5313NoneMalicious code in dreamgen (PyPI)
Malicious code in dreamgen (PyPI)
MAL-2026-5299NoneMalicious code in pantheon-agents (PyPI)
Malicious code in pantheon-agents (PyPI)
MAL-2026-5285NoneMalicious code in ufish (PyPI)
Malicious code in ufish (PyPI)
MAL-2026-5284NoneMalicious code in synago (PyPI)
Malicious code in synago (PyPI)
MAL-2026-5283NoneMalicious code in okite (PyPI)
Malicious code in okite (PyPI)
MAL-2026-5279NoneMalicious code in uprobe (PyPI)
Malicious code in uprobe (PyPI)
MAL-2026-5277NoneMalicious code in pantheon-toolsets (PyPI)
Malicious code in pantheon-toolsets (PyPI)
MAL-2026-5276NoneMalicious code in nucbox (PyPI)
Malicious code in nucbox (PyPI)
MAL-2026-5275NoneMalicious code in napari-ufish (PyPI)
Malicious code in napari-ufish (PyPI)
RUSTSEC-2026-0172NonePossible use after free when deserializing a SQLite database via `SqliteConnection::deserialize_readonly_database`
Possible use after free when deserializing a SQLite database via `SqliteConnection::deserialize_readonly_database`
CVE-2026-37737Medium· 6.5sanic-cors contains an improper regular expression in the try_match() function
sanic-cors contains an improper regular expression in the try_match() function
CVE-2026-50589Medium· 5.3OpenStack Ironic: Crafted JSON String to Certain Endpoints on the API or JSON-RPC Service May Result in Service Crash
OpenStack Ironic: Crafted JSON String to Certain Endpoints on the API or JSON-RPC Service May Result in Service Crash
CVE-2026-11312Low· 3.3bytedance InfiniStore: Denial of Service via Non-Cryptographic Hashing in InfiniStore KV Map
bytedance InfiniStore: Denial of Service via Non-Cryptographic Hashing in InfiniStore KV Map
CVE-2026-47715Low· 3.1Bugsink: Issue event views can show an event from another project if its UUID is known
Bugsink: Issue event views can show an event from another project if its UUID is known
CVE-2026-47716Low· 3.1Bugsink: Issue bulk actions can affect another project’s issue if its UUID is known
Bugsink: Issue bulk actions can affect another project’s issue if its UUID is known
CVE-2026-47419High· 8.3praisonai-platform: Agent endpoints accept any agent_id without workspace ownership check, cross-workspace read/update/delete IDOR
praisonai-platform: Agent endpoints accept any agent_id without workspace ownership check, cross-workspace read/update/delete IDOR
CVE-2024-24769LowVantage6: No limit on emails sent for password/MFA reset
Vantage6: No limit on emails sent for password/MFA reset
CVE-2026-47728Medium· 4.3Bugsink: Project scoping missing in sourcemap and debug-file lookup
Bugsink: Project scoping missing in sourcemap and debug-file lookup
CVE-2024-27928MediumVantage6: 2FA can be circumvented with hacked email access
Vantage6: 2FA can be circumvented with hacked email access
CVE-2026-54533Mediumvantage6 node has an Improper Access Control issue
vantage6 node has an Improper Access Control issue
CVE-2026-54445MediumVantage6: Set admin user and password from environment or configuration
Vantage6: Set admin user and password from environment or configuration
CVE-2026-47261High· 7.5wasmtime-wasi: WASI path_open(TRUNCATE) bypasses `FilePerms::WRITE` host restriction
wasmtime-wasi: WASI path_open(TRUNCATE) bypasses `FilePerms::WRITE` host restriction
MAL-2026-5273NoneMalicious code in anthropy (PyPI)
Malicious code in anthropy (PyPI)
CVE-2026-45409Medium· 5.3python-idna: idna: Denial of Service via specially crafted long inputs (CVE-2026-45409)
A flaw was found in the idna library, which handles Internationalized Domain Names in Python applications. A remote attacker could exploit this vulnerability by sending specially crafted, excessively long inputs to the library's encoding f…
CVE-2026-10775Low· 3.6SGLang is Vulnerable to DoS via the data_hash Function
SGLang is Vulnerable to DoS via the data_hash Function
CVE-2026-41178High· 7.5github.com/open-telemetry/opentelemetry-go: go.opentelemetry.io/otel/baggage: go.opentelemetry.io/otel/propagation: OpenTelemetry-Go: Denia…
A flaw was found in OpenTelemetry-Go. This vulnerability allows a remote attacker to cause a Denial of Service (DoS) by sending oversized or invalid baggage headers. The `Parse` function, in affected versions, failed to reject raw-length i…
CVE-2026-47703MediumAdGuard Home: DoQ-to-UDP State Reduction and Source-Port Oracle
AdGuard Home: DoQ-to-UDP State Reduction and Source-Port Oracle
CVE-2026-44889Medium· 6.1WebOb: Location header normalization during redirect leads to open redirect - again
WebOb: Location header normalization during redirect leads to open redirect - again
CVE-2026-10814Medium· 4.5milvus: RBAC grantee-id uses truncated MD5 (64-bit), enabling privilege-binding collisions and cross-role privilege forgery
milvus: RBAC grantee-id uses truncated MD5 (64-bit), enabling privilege-binding collisions and cross-role privilege forgery