Tagged “osv”
CVEs tagged osv, newest first.
5681 CVEsRSS
CVE-2026-10812Low· 3.6GPTCache: File and image cache keys collide because BufferedReader.peek() only reads the buffered prefix
GPTCache: File and image cache keys collide because BufferedReader.peek() only reads the buffered prefix
CVE-2026-10804Low· 3.6Streamlit @st.cache_data hash collision via fixed sampling seed and PIL P-mode palette omission
Streamlit @st.cache_data hash collision via fixed sampling seed and PIL P-mode palette omission
CVE-2026-50266Low· 2.2OpenStack Neutron: Neutron port RBAC policy bypass allows project managers to set trusted device owners on shared networks
OpenStack Neutron: Neutron port RBAC policy bypass allows project managers to set trusted device owners on shared networks
CVE-2026-44393High· 7.4OpenStack oslo.messaging does not verify RabbitMQ broker hostname during TLS handshake
OpenStack oslo.messaging does not verify RabbitMQ broker hostname during TLS handshake
CVE-2026-10803Low· 2.5mlflow: MLflow: Use of weak hash in Dataset Digest Computation (CVE-2026-10803)
A flaw was found in MLflow. This vulnerability stems from the use of a weak hash algorithm within the Dataset Digest Computation component. A local attacker could potentially exploit this weakness, which may impact the integrity or authent…
CVE-2026-10813Low· 3.6LMCache: 16-bit multimodal hash collision can poison KV cache entries
LMCache: 16-bit multimodal hash collision can poison KV cache entries
CVE-2026-10801Low· 3.6ms-swift: Image Cache Hash Collision via Missing Dimension Metadata
ms-swift: Image Cache Hash Collision via Missing Dimension Metadata
CVE-2026-46447Medium· 5.8OpenStack Ironic allows Boot Script Injection
OpenStack Ironic allows Boot Script Injection
CVE-2026-48681Medium· 5.9OpenStack Ironic allows file overwrite via directory traversal during deployment with a crafted ISO image
OpenStack Ironic allows file overwrite via directory traversal during deployment with a crafted ISO image
CVE-2026-41283Critical· 9.9OpenStack Mistral allows Arbitrary Remote Code Execution when the API is exposed
OpenStack Mistral allows Arbitrary Remote Code Execution when the API is exposed
CVE-2026-10783Low· 2.5Gradio: Audio cache key ignores metadata when saving numpy audio outputs
Gradio: Audio cache key ignores metadata when saving numpy audio outputs
CVE-2026-47706Medium· 5.3Strawberry GraphQL has a Circular Fragment Reference DOS
Strawberry GraphQL has a Circular Fragment Reference DOS
CVE-2026-47707Medium· 5.3Strawberry GraphQL's Bypass of MaxAliasesLimiter via Fragment Spreads leading to GraphQL Alias Amplification
Strawberry GraphQL's Bypass of MaxAliasesLimiter via Fragment Spreads leading to GraphQL Alias Amplification
CVE-2026-10722Low· 3.3ebpf-go is vulnerable to integer overflow via LoadCollectionSpecFromReader
ebpf-go is vulnerable to integer overflow via LoadCollectionSpecFromReader
CVE-2026-35193Low· 3.1Django: UpdateCacheMiddleware may disclose private cached responses by omitting Authorization from Vary
Django: UpdateCacheMiddleware may disclose private cached responses by omitting Authorization from Vary
CVE-2026-6873Low· 3.1Django: signed cookies are vulnerable to salt namespace collisions
Django: signed cookies are vulnerable to salt namespace collisions
CVE-2026-48587Low· 3.1Django: has_vary_header may expose cached responses when Vary values contain whitespace
Django: has_vary_header may expose cached responses when Vary values contain whitespace
CVE-2026-8404Low· 3.1Django: UpdateCacheMiddleware may disclose cached responses due to case-sensitive Cache-Control handling
Django: UpdateCacheMiddleware may disclose cached responses due to case-sensitive Cache-Control handling
CVE-2026-37462High· 7.3GoBGP: Integer underflow in the BGPUpdate.DecodeFromBytes function
GoBGP: Integer underflow in the BGPUpdate.DecodeFromBytes function
MAL-2026-5173NoneMalicious code in spadata (PyPI)
Malicious code in spadata (PyPI)
CVE-2026-44020High· 7.5Docling: Unsafe XML Entity Expansion in USPTO Patent Backend
Docling: Unsafe XML Entity Expansion in USPTO Patent Backend
CVE-2026-10766Low· 3.6mlrun: DataFrame hash collisions can cause dataset artifact path conflicts and silent data corruption
mlrun: DataFrame hash collisions can cause dataset artifact path conflicts and silent data corruption
CVE-2026-44018Medium· 5.5Docling: Unsafe Archive Extraction and XML Parsing in METS-GBS Backend
Docling: Unsafe Archive Extraction and XML Parsing in METS-GBS Backend
CVE-2026-44016High· 8.2Docling: Unsafe Playwright-based HTML Rendering
Docling: Unsafe Playwright-based HTML Rendering
CVE-2026-7666Low· 3.1Django fails to prevent reuse of a partially-initialized connection after a failed `STARTTLS` handshake
Django fails to prevent reuse of a partially-initialized connection after a failed `STARTTLS` handshake
CVE-2026-44023High· 8.6Docling Core: Unsafe remote filename resolution
Docling Core: Unsafe remote filename resolution
CVE-2026-44019High· 8.1Docling Core: Insufficient validation of image reference URIs
Docling Core: Insufficient validation of image reference URIs
CVE-2026-47265MediumAIOHTTP is vulnerable to cross-origin redirect with per-request cookies
AIOHTTP is vulnerable to cross-origin redirect with per-request cookies
CVE-2026-5241High· 7.7python-transformers: python-transformers: Arbitrary code execution due to overridden trust_remote_code setting (CVE-2026-5241)
A flaw was found in python-transformers. An attacker can exploit this vulnerability by providing a malicious model repository. During model initialization, the `trust_remote_code` parameter, intended to prevent remote code execution, is ov…
CVE-2026-44017High· 7.5Docling: Unsafe Zip Extraction in EasyOCR Model Download
Docling: Unsafe Zip Extraction in EasyOCR Model Download