VulnSea

Tagged “osv”

CVEs tagged osv, newest first.

5642 CVEsRSS

CVE-2025-66455Critical· 9.8
1w ago

LMDeploy is a toolkit for compressing, deploying, and serving large language models

LMDeploy is a toolkit for compressing, deploying, and serving large language models. Starting in version 0.9.2 and prior to version 0.16.0, LMDeploy's PyTorch DistServe/PD-disaggregation control plane used `recv_pyobj()` to deserialize m…

▾ MidnightInternLM · lmdeployEPSS 0.69%via NVD
GHSA-39wr-7q6h-cf68High· 7.5
1w ago

LMDeploy has an SSRF bypass

LMDeploy has an SSRF bypass

▾ Twilightlmdeploy · lmdeployvia OSV
CVE-2026-33625High· 8.8PoC
1w ago

LMDeploy is a toolkit for compressing, deploying, and serving large language models

LMDeploy is a toolkit for compressing, deploying, and serving large language models. Versions 012.1 through 0.12.2 contain a code injection vulnerability in `lmdeploy/pytorch/config.py` line 620 that allows an attacker to execute arbitra…

▾ MidnightInternLM · lmdeployEPSS 0.44%via NVD
CVE-2026-64847Medium· 6.8
1w ago

AnyIO is a high level asynchronous concurrency and networking framework that works on top of either Trio or asyncio

AnyIO is a high level asynchronous concurrency and networking framework that works on top of either Trio or asyncio. Prior to 4.14.2, AnyIO starts process-pool workers with standard error connected to a pipe that the parent never drains,…

▾ Sunlitagronholm · anyioEPSS 0.16%via NVD
CVE-2026-63458High· 7.1
1w ago

Perses is an open-source dashboard and visualization project for observability data

Perses is an open-source dashboard and visualization project for observability data. Prior to 0.54.0-beta.3, an authenticated user with viewer access to one project can supply another project through the project query parameter on projec…

▾ Twilightperses · persesEPSS 0.30%via NVD
CVE-2026-63445High· 7.1
1w ago

Perses is an open-source dashboard and visualization project for observability data

Perses is an open-source dashboard and visualization project for observability data. Prior to 0.54.0-rc.0, list endpoints used with the file-system database bind the request-controlled project query parameter into the resource Query stru…

▾ Twilightperses · github.com/perses/persesEPSS 0.56%via NVD
CVE-2026-63199High· 8.3
1w ago

Perses is an open-source dashboard and visualization project for observability data

Perses is an open-source dashboard and visualization project for observability data. From 0.43.0 until 0.54.0-rc.0, the datasource creation and unsaved datasource proxy paths authorize the caller on a Datasource or GlobalDatasource scope…

▾ Twilightperses · persesEPSS 0.27%via NVD
CVE-2026-63406Medium· 5.9PoC
1w ago

AnyCable is a realtime server for reliable two-way communication that supports any backend

AnyCable is a realtime server for reliable two-way communication that supports any backend. Prior to 1.6.15, the telemetry subsystem in telemetry/config.go enables tracking with a hardcoded public authToken, while clusterFingerprint in t…

▾ Twilightanycable · github.com/anycable/anycableEPSS 0.30%via NVD
CVE-2026-63405Medium· 5.9PoC
1w ago

AnyCable is a realtime server for reliable two-way communication that supports any backend

AnyCable is a realtime server for reliable two-way communication that supports any backend. Prior to 1.6.15, the Pusher-compatible REST API in pusher/http.go includes the caller-supplied body_md5 value in the HMAC input but does not calc…

▾ Twilightanycable · github.com/anycable/anycableEPSS 0.21%via NVD
CVE-2026-63349High· 7.0⚖ disputed
1w ago

AnyIO is a high level asynchronous concurrency and networking framework that works on top of either Trio or asyncio

AnyIO is a high level asynchronous concurrency and networking framework that works on top of either Trio or asyncio. In 4.14.0, AnyIO accepts the POSIX extra_groups argument in anyio.run_process() and anyio.open_process(), but open_proce…

▾ Twilightagronholm · anyioEPSS 0.11%via NVD
CVE-2026-61833High· 8.1PoC
1w ago

zot is a container image and artifact registry based on the Open Container Initiative Distribution Specification

zot is a container image and artifact registry based on the Open Container Initiative Distribution Specification. Prior to 2.1.18, the bearer authentication handler in pkg/api/authn.go maps every HTTP method other than GET and HEAD to th…

▾ Midnightproject-zot · zotEPSS 0.51%via NVD
CVE-2026-81505High· 7.1PoC
1w ago

Convoy is a cloud native webhooks gateway

Convoy is a cloud native webhooks gateway. Prior to 26.6.8, Convoy's GET /api/v1/projects/{projectID}/sources/{sourceID} endpoint authorizes access to the project in the URL, but Handler.GetSource calls sources.Service.FindSourceByID() a…

▾ Midnightfrain-dev · github.com/frain-dev/convoyEPSS 0.46%via NVD
CVE-2026-61794Medium· 6.8PoC
1w ago

Capsule is a multi-tenancy and policy-based framework for Kubernetes

Capsule is a multi-tenancy and policy-based framework for Kubernetes. From 0.13.0 until 0.13.7, the Tenant update validation in internal/webhook/tenant/validation/forbidden_annotations_regex.go compiles ForbiddenLabels.Regex for both the…

▾ Twilightprojectcapsule · capsuleEPSS 0.59%via NVD
CVE-2026-61795Medium· 6.8
1w ago

Capsule is a multi-tenancy and policy-based framework for Kubernetes

Capsule is a multi-tenancy and policy-based framework for Kubernetes. From 0.13.0 until 0.13.7, hostnameRegexHandler.OnUpdate in internal/webhook/tenant/validation/hostname_regex.go reverses the new and old Tenant parameters and validate…

▾ Sunlitprojectcapsule · capsuleEPSS 0.59%via NVD
CVE-2026-61672High· 7.1PoC
1w ago

Capsule is a multi-tenancy and policy-based framework for Kubernetes

Capsule is a multi-tenancy and policy-based framework for Kubernetes. Prior to 0.13.7, ForbiddenListSpec.ExactMatch in pkg/api/forbidden_list.go sorts denied metadata keys case-insensitively and then uses sort.SearchStrings, which assume…

▾ Midnightprojectcapsule · capsuleEPSS 0.33%via NVD
CVE-2026-77339Medium· 5.1PoC
1w ago

Process Compose is a scheduler and orchestrator for non-containerized applications

Process Compose is a scheduler and orchestrator for non-containerized applications. Prior to 1.120.0, the MCP SSE listener in src/mcp/server.go accepts browser-origin requests to /sse and the returned message endpoint without validating …

▾ Twilightf1bonacc1 · github.com/f1bonacc1/process-composeEPSS 0.26%via NVD
CVE-2026-58197High· 8.8PoC
1w ago

ToolHive is a utility designed to simplify the deployment and management of Model Context Protocol servers

ToolHive is a utility designed to simplify the deployment and management of Model Context Protocol servers. Prior to ToolHive CLI 0.30.1 and ToolHive Studio 0.38.0, locally run MCP server containers use the default network permission pro…

▾ Midnightstacklok · github.com/stacklok/toolhiveEPSS 0.37%via NVD
CVE-2026-61682Critical· 9.9
1w ago

kcp is a Kubernetes-like control plane for form-factors and use-cases beyond Kubernetes and container workloads

kcp is a Kubernetes-like control plane for form-factors and use-cases beyond Kubernetes and container workloads. Prior to 0.31.4 and 0.32.2, the kcp front-proxy does not remove inbound X-Remote-User, X-Remote-Group, or X-Remote-Extra-* i…

▾ Midnightkcp-dev · kcpEPSS 0.38%via NVD
CVE-2026-62282Medium· 6.5PoC
1w ago

OpenCVE is a vulnerability intelligence platform

OpenCVE is a vulnerability intelligence platform. Prior to 3.0.0, OpenCVE notification testing for Webhook and Slack integrations does not sufficiently validate user-supplied HTTP or HTTPS destinations. An authenticated user with permiss…

▾ Twilightopencve · opencveEPSS 0.42%via NVD
CVE-2026-93601Low· 2.2
1w ago

rustls-webpki (the Rust webpki fork used by rustls) versions >= 0.101.0 and prior to 0.103.12 and 0.104.0-alpha.6 incorrectly accepted permitted-subtree DNS name constraints for certificates asserting a wildcard name

rustls-webpki (the Rust webpki fork used by rustls) versions >= 0.101.0 and prior to 0.103.12 and 0.104.0-alpha.6 incorrectly accepted permitted-subtree DNS name constraints for certificates asserting a wildcard name. For example, a name…

▾ Sunlitrustls · webpkiEPSS 0.18%via NVD
CVE-2026-93599High· 7.5PoC
1w ago

rustls-webpki through 0.103.12 (and 0.104.0-alpha releases before 0.104.0-alpha.7) contains a reachable panic in bit_string_flags() in src/der.rs

rustls-webpki through 0.103.12 (and 0.104.0-alpha releases before 0.104.0-alpha.7) contains a reachable panic in bit_string_flags() in src/der.rs. The input guard fails to reject a named-bit BIT STRING whose content is exactly [0x00] (ze…

▾ Midnightrustls · webpkiEPSS 0.49%via NVD
CVE-2026-93602Medium· 4.4
1w ago

rustls-webpki versions before 0.103.10 and 0.104.0-alpha.5 contain faulty CRL authority-matching logic that compares only the first distributionPoint against each CRL's IssuingDistributionPoint, ignoring additional distributionPoints

rustls-webpki versions before 0.103.10 and 0.104.0-alpha.5 contain faulty CRL authority-matching logic that compares only the first distributionPoint against each CRL's IssuingDistributionPoint, ignoring additional distributionPoints. At…

▾ Sunlitrustls · webpkiEPSS 0.21%via NVD
CVE-2026-93600Low· 2.2
1w ago

rustls-webpki (rustls/webpki) versions 0.101.0 through 0.103.11 and 0.104.0-alpha releases before 0.104.0-alpha.6 ignore X.509 name constraints that apply to URI names, causing such constraints to be accepted rather than enforced

rustls-webpki (rustls/webpki) versions 0.101.0 through 0.103.11 and 0.104.0-alpha releases before 0.104.0-alpha.6 ignore X.509 name constraints that apply to URI names, causing such constraints to be accepted rather than enforced. Becaus…

▾ Sunlitrustls · webpkiEPSS 0.18%via NVD
RUSTSEC-2026-0289None
1w ago

pqc_kyber is unmaintained

pqc_kyber is unmaintained

▾ Sunlitpqc_kyber · pqc_kybervia OSV
RUSTSEC-2026-0287None
1w ago

cosmian_kyber is unmaintained

cosmian_kyber is unmaintained

▾ Sunlitcosmian_kyber · cosmian_kybervia OSV
MAL-2026-16275Critical⚠ Exploited
1w ago

Malicious code in requests-triwes (PyPI)

Malicious code in requests-triwes (PyPI)

▾ Abyssalrequests-triwes · requests-triwesvia OSV
MAL-2026-16274Critical⚠ Exploited
1w ago

Malicious code in requests-auroras (PyPI)

Malicious code in requests-auroras (PyPI)

▾ Abyssalrequests-auroras · requests-aurorasvia OSV
MAL-2026-16269Critical⚠ Exploited
1w ago

Malicious code in requests-asetwe (PyPI)

Malicious code in requests-asetwe (PyPI)

▾ Abyssalrequests-asetwe · requests-asetwevia OSV
MAL-2026-16268Critical⚠ Exploited
1w ago

Malicious code in index-forum (PyPI)

Malicious code in index-forum (PyPI)

▾ Abyssalindex-forum · index-forumvia OSV
MAL-2026-16267Critical⚠ Exploited
1w ago

Malicious code in pyjstat-smooth (PyPI)

Malicious code in pyjstat-smooth (PyPI)

▾ Abyssalpyjstat-smooth · pyjstat-smoothvia OSV
CVEs tagged “osv” — page 6 · VulnSea