VulnSea

Tagged “osv”

CVEs tagged osv, newest first.

5681 CVEsRSS

CVE-2026-44022Medium· 5.5
3mo ago

Docling: Potential Path Traversal via LaTeX \includegraphics and \input Commands

Docling: Potential Path Traversal via LaTeX \includegraphics and \input Commands

▾ Sunlitdocling · doclingEPSS 0.21%via OSV
CVE-2026-44546Low· 3.7
3mo ago

daphne: WebSocket handshake header smuggling through autobahn splitlines() mishandling of non-standard line separators

daphne: WebSocket handshake header smuggling through autobahn splitlines() mishandling of non-standard line separators

▾ Sunlitdaphne · daphneEPSS 0.29%via OSV
CVE-2026-44545Medium· 5.3
3mo ago

daphne: Unauthenticated attackers can cause excessive memory consumption by sending arbitrarily large WebSocket messages/frames

daphne: Unauthenticated attackers can cause excessive memory consumption by sending arbitrarily large WebSocket messages/frames

▾ Sunlitdaphne · daphneEPSS 0.57%via OSV
CVE-2026-4035Critical· 9.1
3mo ago

MLflow: Environment variable injection in AI Gateway secrets enables server-side credential exfiltration

MLflow: Environment variable injection in AI Gateway secrets enables server-side credential exfiltration

▾ Midnightmlflow · mlflowEPSS 0.66%via OSV
CVE-2026-10692Medium· 4.3
3mo ago

Code Index MCP is vulnerable to Uncontrolled Resource Consumption

Code Index MCP is vulnerable to Uncontrolled Resource Consumption

▾ Sunlitcode-index-mcp · code-index-mcpEPSS 0.31%via OSV
CVE-2026-40898Medium· 5.3
3mo ago

quic-go: HTTP/3 QPACK Trailer Expansion Memory Exhaustion

quic-go: HTTP/3 QPACK Trailer Expansion Memory Exhaustion

▾ Sunlitquic-go · github.com/quic-go/quic-goEPSS 0.49%via OSV
RUSTSEC-2026-0279High· 8.1
4mo ago

Rojo development server vulnerable to DNS rebinding, allowing unauthenticated read/write access and local program execution

Rojo development server vulnerable to DNS rebinding, allowing unauthenticated read/write access and local program execution

▾ Twilightrojo · rojovia OSV
CVE-2026-42507Medium· 5.3
4mo ago

net/textproto: golang: Golang net/textproto: Misleading error messages via input injection (CVE-2026-42507)

A flaw was found in the net/textproto package in Golang. When functions in this package return errors, they include their input as part of the error message. An attacker could exploit this by injecting misleading content into these error m…

▾ SunlitRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.41%via CSAF
MAL-2026-5171None
4mo ago

Malicious code in spaysdata (PyPI)

Malicious code in spaysdata (PyPI)

▾ Sunlitspaysdata · spaysdatavia OSV
MAL-2026-5170None
4mo ago

Malicious code in spaysrbdata (PyPI)

Malicious code in spaysrbdata (PyPI)

▾ Sunlitspaysrbdata · spaysrbdatavia OSV
CVE-2026-42504High· 7.5
4mo ago

Quadratic complexity in WordDecoder.DecodeHeader in mime

Decoding a maliciously-crafted MIME header containing many invalid encoded-words can consume excessive CPU.

▾ TwilightGo standard library · mimeEPSS 0.56%via CVEORG
CVE-2026-47117Critical· 9.8PoC
4mo ago

OpenMed vulnerable to remote code injection through privacy-filter model loading path

OpenMed vulnerable to remote code injection through privacy-filter model loading path

▾ Abyssalopenmed · openmedEPSS 1.3%via OSV
CVE-2026-34993High· 7.2
4mo ago

aiohttp: AIOHTTP: Arbitrary code execution via untrusted input to CookieJar.load() (CVE-2026-34993)

A flaw was found in AIOHTTP, an asynchronous HTTP client/server framework for asyncio and Python. An attacker could exploit this vulnerability by providing untrusted input to the `CookieJar.load()` function. This could potentially lead to …

▾ TwilightRed Hat · Red Hat OpenShift AI 3.4EPSS 0.50%via CSAF
RUSTSEC-2026-0155None
4mo ago

`exploration` was removed from crates.io for malicious code

`exploration` was removed from crates.io for malicious code

▾ Sunlitexploration · explorationvia OSV
CVE-2026-3198Medium· 6.5
4mo ago

MLflow: Any authenticated user can enumerate all gateway secrets, endpoints, and model definitions

MLflow: Any authenticated user can enumerate all gateway secrets, endpoints, and model definitions

▾ Sunlitmlflow · mlflowEPSS 0.36%via OSV
CVE-2026-5422Medium· 6.8
4mo ago

Jupyter Server vulnerable to Path Traversal via incorrect root directory boundary check in _get_os_path()

Jupyter Server vulnerable to Path Traversal via incorrect root directory boundary check in _get_os_path()

▾ Sunlitjupyter-server · jupyter-serverEPSS 0.55%via OSV
CVE-2026-3514High· 7.5
4mo ago

Prefect has an Authentication Middleware Bypass when URL paths are appended with 'health' or 'ready'

Prefect has an Authentication Middleware Bypass when URL paths are appended with 'health' or 'ready'

▾ Twilightprefect · prefectEPSS 0.63%via OSV
CVE-2026-10300Low· 3.7
4mo ago

SGLang: Reachable Assertion via  lora_path  in LoRAManager enables remote Denial of Dervice

SGLang: Reachable Assertion via  lora_path  in LoRAManager enables remote Denial of Dervice

▾ Sunlitsglang · sglangEPSS 0.37%via OSV
CVE-2026-10566Medium· 5.3
4mo ago

FoundationAgents MetaGPT: Deserialization through flawed argument mapping via Message.check_instruct_content()

FoundationAgents MetaGPT: Deserialization through flawed argument mapping via Message.check_instruct_content()

▾ Sunlitmetagpt · metagptEPSS 0.12%via OSV
MAL-2026-5160None
4mo ago

Malicious code in bt-signal-utils (PyPI)

Malicious code in bt-signal-utils (PyPI)

▾ Sunlitbt-signal-utils · bt-signal-utilsvia OSV
CVE-2026-27145Medium· 6.5PoC
4mo ago

(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries

(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, ".") to execute repeatedly on the same input hostname. With a large DNS SA…

▾ TwilightGo standard library · crypto/x509EPSS 0.59%via NVD
CVE-2026-48119High· 7.1
4mo ago

Nezha's authenticated agents can forge service-monitor results for other users' services

Nezha's authenticated agents can forge service-monitor results for other users' services

▾ Twilightnezhahq · github.com/nezhahq/nezhaEPSS 0.37%via OSV
CVE-2026-10224Medium· 5.3
4mo ago

hermes-agent has an Uncontrolled Resource Consumption issue

hermes-agent has an Uncontrolled Resource Consumption issue

▾ Sunlithermes-agent · hermes-agentEPSS 0.37%via OSV
CVE-2026-10223Medium· 6.3
4mo ago

hermes-agent has an Injection issue

hermes-agent has an Injection issue

▾ Sunlithermes-agent · hermes-agentEPSS 0.23%via OSV
CVE-2026-10221High· 7.3
4mo ago

hermes-agent has an Injection issue

hermes-agent has an Injection issue

▾ Twilighthermes-agent · hermes-agentEPSS 0.30%via OSV
CVE-2026-49138Medium· 5.0
4mo ago

Nanobot contains a server-side request forgery vulnerability in the web_fetch tool

Nanobot contains a server-side request forgery vulnerability in the web_fetch tool

▾ Sunlitnanobot-ai · nanobot-aiEPSS 0.49%via OSV
CVE-2026-44740High· 7.5
4mo ago

github.com/go-git/go-billy: Billy: Denial of Service via crafted input due to insufficient validation (CVE-2026-44740)

A flaw was found in Billy, an interface filesystem abstraction for Go. This vulnerability allows a remote attacker to cause a Denial of Service (DoS) by providing crafted or malformed input. The issue arises from insufficient validation an…

▾ TwilightRed Hat · Red Hat Openshift Data Foundation 4.22EPSS 0.53%via CSAF
CVE-2026-47415High· 8.3
4mo ago

praisonai-platform: Issue endpoints accept any issue_id without workspace ownership check, cross-workspace read/update/delete IDOR

praisonai-platform: Issue endpoints accept any issue_id without workspace ownership check, cross-workspace read/update/delete IDOR

▾ Twilightpraisonai-platform · praisonai-platformEPSS 0.39%via OSV
CVE-2026-47411Medium· 6.5
4mo ago

praisonai-platform: Any workspace member can rewrite workspace name, description, and settings via PATCH /workspaces/{id}

praisonai-platform: Any workspace member can rewrite workspace name, description, and settings via PATCH /workspaces/{id}

▾ Sunlitpraisonai-platform · praisonai-platformEPSS 0.34%via OSV
CVE-2026-47425Medium
4mo ago

rattler has an entry-point path traversal in noarch:python install (arbitrary file write)

rattler has an entry-point path traversal in noarch:python install (arbitrary file write)

▾ Sunlitrattler · rattlerEPSS 0.20%via OSV
CVEs tagged “osv” — page 56 · VulnSea