Tagged “osv”
CVEs tagged osv, newest first.
5683 CVEsRSS
CVE-2026-47412High· 8.1praisonai-platform: Any workspace member can delete the entire workspace via DELETE /workspaces/{id}
praisonai-platform: Any workspace member can delete the entire workspace via DELETE /workspaces/{id}
CVE-2026-47417High· 8.1praisonai-platform: Comment endpoints accept any issue_id without workspace ownership check, cross-workspace comment read and post IDOR
praisonai-platform: Comment endpoints accept any issue_id without workspace ownership check, cross-workspace comment read and post IDOR
CVE-2026-47418High· 8.1praisonai-platform: Project endpoints accept any project_id without workspace ownership check, cross-workspace read/update/delete IDOR
praisonai-platform: Project endpoints accept any project_id without workspace ownership check, cross-workspace read/update/delete IDOR
CVE-2026-10219High· 7.3GoClaw has a Command Injection issue
GoClaw has a Command Injection issue
CVE-2026-45426Low· 3.1Apache Airflow has an Incorrect Authorization issue
Apache Airflow has an Incorrect Authorization issue
CVE-2026-41014Medium· 4.3Apache Airflow has a Missing Authorization issue
Apache Airflow has a Missing Authorization issue
CVE-2026-42359High· 8.8Apache Airflow has a Deserialization of Untrusted Data vulnerability
Apache Airflow has a Deserialization of Untrusted Data vulnerability
CVE-2026-46764Medium· 4.3Apache Airflow has an Authorization Bypass Through User-Controlled Key
Apache Airflow has an Authorization Bypass Through User-Controlled Key
CVE-2026-41084High· 7.5Apache Airflow Vulnerable to Authorization Bypass Through User-Controlled Key
Apache Airflow Vulnerable to Authorization Bypass Through User-Controlled Key
CVE-2026-10222Medium· 5.6hermes-agent has an Injection issue
hermes-agent has an Injection issue
CVE-2026-40963Low· 3.1Apache Airflow has an Improper Authorization issue
Apache Airflow has an Improper Authorization issue
CVE-2026-42360Medium· 6.5Apache Airflow vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
Apache Airflow vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
CVE-2026-42252Critical· 9.1Apache Airflow vulnerable to Improper Neutralization of Special Elements Used in a Template Engine
Apache Airflow vulnerable to Improper Neutralization of Special Elements Used in a Template Engine
CVE-2026-41017Medium· 5.9Apache Airflow has a Sensitive Cookie in HTTPS Session Without 'Secure' Attribute
Apache Airflow has a Sensitive Cookie in HTTPS Session Without 'Secure' Attribute
CVE-2026-40861Medium· 6.5Apache Airflow has a Link Following issue
Apache Airflow has a Link Following issue
CVE-2026-49267Medium· 5.9Apache Airflow has no certificate validation on SMTP STARTTLS connections
Apache Airflow has no certificate validation on SMTP STARTTLS connections
CVE-2026-42358Medium· 6.5Apache Airflow Vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
Apache Airflow Vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
CVE-2026-45360High· 7.3Apache Airflow Vulnerable to Deserialization of Untrusted Data
Apache Airflow Vulnerable to Deserialization of Untrusted Data
CVE-2026-10517Medium· 5.8Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints
Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints
CVE-2026-48726Medium· 6.5Apache Airflow: Auth manager doesn't invalidate JWT tokens after users click logout
Apache Airflow: Auth manager doesn't invalidate JWT tokens after users click logout
CVE-2026-49298High· 8.8Apache Airflow: Execution API JWT leaked via KubernetesExecutor worker command-line args
Apache Airflow: Execution API JWT leaked via KubernetesExecutor worker command-line args
CVE-2026-10212Medium· 6.3AstrBot: Manipulation of astr_main_agent's session_id parameter leads to authorization bypass
AstrBot: Manipulation of astr_main_agent's session_id parameter leads to authorization bypass
CVE-2026-40961High· 7.2Apache Airflow: Authenticated users can bypass the `is_safe_url` check
Apache Airflow: Authenticated users can bypass the `is_safe_url` check
CVE-2026-45192Medium· 6.5Apache Airflow: Incomplete redaction allowlist exposes secrets in Connection `extra` to read-permitted users
Apache Airflow: Incomplete redaction allowlist exposes secrets in Connection `extra` to read-permitted users
CVE-2026-8643Medium· 5.5⚖ disputedpip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory.
pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory.
CVE-2026-10177Medium· 6.3Aider has an SSRF vulnerability through its AWS EC2 Metadata Endpoint
Aider has an SSRF vulnerability through its AWS EC2 Metadata Endpoint
CVE-2026-10175Medium· 6.3Aider is vulnerable to Code Injection via editor_coder.run function
Aider is vulnerable to Code Injection via editor_coder.run function
MAL-2026-5086NoneMalicious code in polymarket-data (PyPI)
Malicious code in polymarket-data (PyPI)
CVE-2026-42500NonePanic when reading out of bound palette index in golang.org/x/image/bmp
Panic when reading out of bound palette index in golang.org/x/image/bmp
GHSA-w5pp-99ch-qj29Medium· 6.5go-git: Malformed Git object data may cause panics or resource exhaustion
go-git: Malformed Git object data may cause panics or resource exhaustion