VulnSea

Tagged “osv”

CVEs tagged osv, newest first.

5681 CVEsRSS

CVE-2026-45361High· 8.1
4mo ago

Apache Airflow providers-google's `ComputeEngineSSHHook` disables SSH host-key verification by default, exposing SSH traffic between an A…

Apache Airflow providers-google's `ComputeEngineSSHHook` disables SSH host-key verification by default, exposing SSH traffic between an Airflow worker and a Compute Engine VM to in-path network attackers who can intercept or modify the s…

▾ Twilightapache-airflow-providers-google · apache-airflow-providers-googleEPSS 0.80%via OSV
CVE-2026-47157Medium· 6.5
4mo ago

aiograpi: Unsafe signup challenge path handling

aiograpi: Unsafe signup challenge path handling

▾ Sunlitaiograpi · aiograpiEPSS 0.30%via OSV
CVE-2026-42502Medium· 6.1
4mo ago

Invoking incorrect handling of HTML elements in foreign content in golang.org/x/net/html

Invoking incorrect handling of HTML elements in foreign content in golang.org/x/net/html

▾ Sunlitx · golang.org/x/netEPSS 0.22%via OSV
CVE-2026-46715Medium
4mo ago

Flask-Security-Too OAuth reauthentication freshness bypass via cross- user OAuth identity acceptance

Flask-Security-Too OAuth reauthentication freshness bypass via cross- user OAuth identity acceptance

▾ Sunlitflask-security-too · flask-security-tooEPSS 0.49%via OSV
CVE-2026-27136None
4mo ago

Invoking duplicate attributes can cause XSS in golang.org/x/net/html

Invoking duplicate attributes can cause XSS in golang.org/x/net/html

▾ Sunlitx · golang.org/x/netEPSS 0.22%via OSV
CVE-2026-25681None
4mo ago

Invoking incorrect handling of character references in DOCTYPE nodes in golang.org/x/net/html

Invoking incorrect handling of character references in DOCTYPE nodes in golang.org/x/net/html

▾ Sunlitx · golang.org/x/netEPSS 0.22%via OSV
CVE-2026-39821Critical· 9.6
4mo ago

The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label

The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior …

▾ Midnightgolang · netEPSS 0.69%via NVD
CVE-2026-46598Medium· 5.3
4mo ago

Invoking pathological inputs can lead to client panic in golang.org/x/crypto/ssh/agent

Invoking pathological inputs can lead to client panic in golang.org/x/crypto/ssh/agent

▾ Sunlitx · golang.org/x/cryptoEPSS 0.52%via OSV
CVE-2026-39832Critical· 9.1
4mo ago

When adding a key to a remote agent constraint extensions such as [email protected] were not serialized in the request

When adding a key to a remote agent constraint extensions such as [email protected] were not serialized in the request. Destination restrictions were silently stripped when forwarding keys, allowing unrestricted use of…

▾ Midnightgolang · cryptoEPSS 0.72%via NVD
CVE-2026-46597High· 7.5
4mo ago

Invoking byte arithmetic causes underflow and panic in golang.org/x/crypto/ssh

Invoking byte arithmetic causes underflow and panic in golang.org/x/crypto/ssh

▾ Twilightx · golang.org/x/cryptoEPSS 0.62%via OSV
CVE-2026-39835Medium· 5.3
4mo ago

SSH servers which use CertChecker as a public key callback without setting IsUserAuthority or IsHostAuthority could be caused to panic by a client presenting a certificate

SSH servers which use CertChecker as a public key callback without setting IsUserAuthority or IsHostAuthority could be caused to panic by a client presenting a certificate. CertChecker now returns an error instead of panicking when these…

▾ Sunlitgolang · cryptoEPSS 0.66%via NVD
CVE-2026-39827Medium· 6.5
4mo ago

Invoking memory leak when rejecting channels can lead to DoS in golang.org/x/crypto/ssh

Invoking memory leak when rejecting channels can lead to DoS in golang.org/x/crypto/ssh

▾ Sunlitx · golang.org/x/cryptoEPSS 0.28%via OSV
CVE-2026-39830Critical· 9.1
4mo ago

A malicious SSH peer could send unsolicited global request responses to fill an internal buffer, blocking the connection's read loop

A malicious SSH peer could send unsolicited global request responses to fill an internal buffer, blocking the connection's read loop. The blocked goroutine could not be released by calling Close(), resulting in a resource leak per connec…

▾ Midnightgolang · cryptoEPSS 0.62%via NVD
CVE-2026-39829High· 7.5
4mo ago

The RSA and DSA public key parsers did not enforce size limits on key parameters

The RSA and DSA public key parsers did not enforce size limits on key parameters. A crafted public key with an excessively large modulus or DSA parameter could cause several minutes of CPU consumption during signature verification. This …

▾ Twilightgolang · cryptoEPSS 0.62%via NVD
CVE-2026-39831High· 8.1
4mo ago

golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check (CVE-2026-39831)

A flaw was found in golang.org/x/crypto/ssh. The Verify() method, responsible for FIDO/U2F security key types, did not properly check for user presence. This allowed signatures to be accepted without requiring a physical touch on the hardw…

▾ TwilightRed Hat · Red Hat Openshift Data Foundation 4.22EPSS 0.49%via CSAF
CVE-2026-42508Critical· 9.1
4mo ago

Previously, a revoked 'SignatureKey' belonging to a CA was not correctly checked for revocation

Previously, a revoked 'SignatureKey' belonging to a CA was not correctly checked for revocation. Now, both the 'key' and 'key.SignatureKey' are checked for @revoked.

▾ Midnightgolang · cryptoEPSS 0.65%via NVD
CVE-2026-39834Medium· 6.5⚖ disputed
4mo ago

Invoking infinite loop on large channel writes in golang.org/x/crypto/ssh

Invoking infinite loop on large channel writes in golang.org/x/crypto/ssh

▾ Sunlitx · golang.org/x/cryptoEPSS 0.64%via OSV
CVE-2026-46695Critical· 10.0
4mo ago

BoxLite: Permission Bypass Allows Modification of Read-Only Files

BoxLite: Permission Bypass Allows Modification of Read-Only Files

▾ Midnightboxlite · boxliteEPSS 0.48%via OSV
CVE-2026-46703Critical· 9.6
4mo ago

Boxlite: Path Traversal Vulnerability Leads to Arbitrary File Write on the Host

Boxlite: Path Traversal Vulnerability Leads to Arbitrary File Write on the Host

▾ Midnightboxlite · boxliteEPSS 0.78%via OSV
CVE-2026-46612High· 8.8
4mo ago

Fission StorageSvc /v1/archive endpoint exposes unauthenticated CRUD over all function archives

Fission StorageSvc /v1/archive endpoint exposes unauthenticated CRUD over all function archives

▾ Twilightfission · github.com/fission/fissionEPSS 0.66%via OSV
CVE-2026-46617High
4mo ago

Fission runtime pods automount the fission-fetcher service-account token into the user function container, granting function code names…

Fission runtime pods automount the fission-fetcher service-account token into the user function container, granting function code namespace-wide secret / configmap read

▾ Twilightfission · github.com/fission/fissionEPSS 0.48%via OSV
RUSTSEC-2026-0208None
4mo ago

Potential Panic in AVX2 SHAKE-256

Potential Panic in AVX2 SHAKE-256

▾ Sunlitlibcrux-sha3 · libcrux-sha3via OSV
CVE-2026-46556Medium· 6.5
4mo ago

FlaskBB: SSRF in get_image_info() via unrestricted avatar URL

FlaskBB: SSRF in get_image_info() via unrestricted avatar URL

▾ Sunlitflaskbb · flaskbbEPSS 0.35%via OSV
CVE-2026-2734Medium· 6.5
4mo ago

MLflow authenticated users can enumerate any registered model versions due to lack of per-model permissions checks

MLflow authenticated users can enumerate any registered model versions due to lack of per-model permissions checks

▾ Sunlitmlflow · mlflowEPSS 0.50%via OSV
CVE-2026-8597High· 7.2
4mo ago

Amazon SageMaker Python SDK is missing integrity verification in its Triton inference handler

Amazon SageMaker Python SDK is missing integrity verification in its Triton inference handler

▾ Twilightsagemaker · sagemakerEPSS 0.61%via OSV
CVE-2026-48207Critical· 9.8
4mo ago

Apache Fory PyFory Deserialization of Untrusted Data

Apache Fory PyFory Deserialization of Untrusted Data

▾ Midnightpyfory · pyforyEPSS 0.82%via OSV
CVE-2026-46432High· 7.8
4mo ago

LMDeploy: Arbitrary code execution via hardcoded trust_remote_code=True in lmdeploy model initialization

LMDeploy: Arbitrary code execution via hardcoded trust_remote_code=True in lmdeploy model initialization

▾ Twilightlmdeploy · lmdeployEPSS 0.20%via OSV
CVE-2026-46678Medium· 6.8
4mo ago

Pydantic AI: SSRF cloud-metadata blocklist bypass via IPv4-mapped IPv6 (Incomplete fix of CVE-2026-25580)

Pydantic AI: SSRF cloud-metadata blocklist bypass via IPv4-mapped IPv6 (Incomplete fix of CVE-2026-25580)

▾ Sunlitpydantic-ai · pydantic-aiEPSS 0.38%via OSV
CVE-2026-46517High· 7.8
4mo ago

lmdeploy: Hardcoded trust_remote_code=True is an implicit unsafe remote-code load path with no user opt-out

lmdeploy: Hardcoded trust_remote_code=True is an implicit unsafe remote-code load path with no user opt-out

▾ Twilightlmdeploy · lmdeployEPSS 0.43%via OSV
CVE-2026-46561Medium· 5.0
4mo ago

pyload-ng: SSRF via HTTP Redirect Bypass in parse_urls API

pyload-ng: SSRF via HTTP Redirect Bypass in parse_urls API

▾ Sunlitpyload-ng · pyload-ngEPSS 0.29%via OSV
CVEs tagged “osv” — page 60 · VulnSea