Tagged “osv”
CVEs tagged osv, newest first.
5681 CVEsRSS
CVE-2026-45361High· 8.1Apache Airflow providers-google's `ComputeEngineSSHHook` disables SSH host-key verification by default, exposing SSH traffic between an A…
Apache Airflow providers-google's `ComputeEngineSSHHook` disables SSH host-key verification by default, exposing SSH traffic between an Airflow worker and a Compute Engine VM to in-path network attackers who can intercept or modify the s…
CVE-2026-47157Medium· 6.5aiograpi: Unsafe signup challenge path handling
aiograpi: Unsafe signup challenge path handling
CVE-2026-42502Medium· 6.1Invoking incorrect handling of HTML elements in foreign content in golang.org/x/net/html
Invoking incorrect handling of HTML elements in foreign content in golang.org/x/net/html
CVE-2026-46715MediumFlask-Security-Too OAuth reauthentication freshness bypass via cross- user OAuth identity acceptance
Flask-Security-Too OAuth reauthentication freshness bypass via cross- user OAuth identity acceptance
CVE-2026-27136NoneInvoking duplicate attributes can cause XSS in golang.org/x/net/html
Invoking duplicate attributes can cause XSS in golang.org/x/net/html
CVE-2026-25681NoneInvoking incorrect handling of character references in DOCTYPE nodes in golang.org/x/net/html
Invoking incorrect handling of character references in DOCTYPE nodes in golang.org/x/net/html
CVE-2026-39821Critical· 9.6The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label
The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior …
CVE-2026-46598Medium· 5.3Invoking pathological inputs can lead to client panic in golang.org/x/crypto/ssh/agent
Invoking pathological inputs can lead to client panic in golang.org/x/crypto/ssh/agent
CVE-2026-39832Critical· 9.1When adding a key to a remote agent constraint extensions such as [email protected] were not serialized in the request
When adding a key to a remote agent constraint extensions such as [email protected] were not serialized in the request. Destination restrictions were silently stripped when forwarding keys, allowing unrestricted use of…
CVE-2026-46597High· 7.5Invoking byte arithmetic causes underflow and panic in golang.org/x/crypto/ssh
Invoking byte arithmetic causes underflow and panic in golang.org/x/crypto/ssh
CVE-2026-39835Medium· 5.3SSH servers which use CertChecker as a public key callback without setting IsUserAuthority or IsHostAuthority could be caused to panic by a client presenting a certificate
SSH servers which use CertChecker as a public key callback without setting IsUserAuthority or IsHostAuthority could be caused to panic by a client presenting a certificate. CertChecker now returns an error instead of panicking when these…
CVE-2026-39827Medium· 6.5Invoking memory leak when rejecting channels can lead to DoS in golang.org/x/crypto/ssh
Invoking memory leak when rejecting channels can lead to DoS in golang.org/x/crypto/ssh
CVE-2026-39830Critical· 9.1A malicious SSH peer could send unsolicited global request responses to fill an internal buffer, blocking the connection's read loop
A malicious SSH peer could send unsolicited global request responses to fill an internal buffer, blocking the connection's read loop. The blocked goroutine could not be released by calling Close(), resulting in a resource leak per connec…
CVE-2026-39829High· 7.5The RSA and DSA public key parsers did not enforce size limits on key parameters
The RSA and DSA public key parsers did not enforce size limits on key parameters. A crafted public key with an excessively large modulus or DSA parameter could cause several minutes of CPU consumption during signature verification. This …
CVE-2026-39831High· 8.1golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check (CVE-2026-39831)
A flaw was found in golang.org/x/crypto/ssh. The Verify() method, responsible for FIDO/U2F security key types, did not properly check for user presence. This allowed signatures to be accepted without requiring a physical touch on the hardw…
CVE-2026-42508Critical· 9.1Previously, a revoked 'SignatureKey' belonging to a CA was not correctly checked for revocation
Previously, a revoked 'SignatureKey' belonging to a CA was not correctly checked for revocation. Now, both the 'key' and 'key.SignatureKey' are checked for @revoked.
CVE-2026-39834Medium· 6.5⚖ disputedInvoking infinite loop on large channel writes in golang.org/x/crypto/ssh
Invoking infinite loop on large channel writes in golang.org/x/crypto/ssh
CVE-2026-46695Critical· 10.0BoxLite: Permission Bypass Allows Modification of Read-Only Files
BoxLite: Permission Bypass Allows Modification of Read-Only Files
CVE-2026-46703Critical· 9.6Boxlite: Path Traversal Vulnerability Leads to Arbitrary File Write on the Host
Boxlite: Path Traversal Vulnerability Leads to Arbitrary File Write on the Host
CVE-2026-46612High· 8.8Fission StorageSvc /v1/archive endpoint exposes unauthenticated CRUD over all function archives
Fission StorageSvc /v1/archive endpoint exposes unauthenticated CRUD over all function archives
CVE-2026-46617HighFission runtime pods automount the fission-fetcher service-account token into the user function container, granting function code names…
Fission runtime pods automount the fission-fetcher service-account token into the user function container, granting function code namespace-wide secret / configmap read
RUSTSEC-2026-0208NonePotential Panic in AVX2 SHAKE-256
Potential Panic in AVX2 SHAKE-256
CVE-2026-46556Medium· 6.5FlaskBB: SSRF in get_image_info() via unrestricted avatar URL
FlaskBB: SSRF in get_image_info() via unrestricted avatar URL
CVE-2026-2734Medium· 6.5MLflow authenticated users can enumerate any registered model versions due to lack of per-model permissions checks
MLflow authenticated users can enumerate any registered model versions due to lack of per-model permissions checks
CVE-2026-8597High· 7.2Amazon SageMaker Python SDK is missing integrity verification in its Triton inference handler
Amazon SageMaker Python SDK is missing integrity verification in its Triton inference handler
CVE-2026-48207Critical· 9.8Apache Fory PyFory Deserialization of Untrusted Data
Apache Fory PyFory Deserialization of Untrusted Data
CVE-2026-46432High· 7.8LMDeploy: Arbitrary code execution via hardcoded trust_remote_code=True in lmdeploy model initialization
LMDeploy: Arbitrary code execution via hardcoded trust_remote_code=True in lmdeploy model initialization
CVE-2026-46678Medium· 6.8Pydantic AI: SSRF cloud-metadata blocklist bypass via IPv4-mapped IPv6 (Incomplete fix of CVE-2026-25580)
Pydantic AI: SSRF cloud-metadata blocklist bypass via IPv4-mapped IPv6 (Incomplete fix of CVE-2026-25580)
CVE-2026-46517High· 7.8lmdeploy: Hardcoded trust_remote_code=True is an implicit unsafe remote-code load path with no user opt-out
lmdeploy: Hardcoded trust_remote_code=True is an implicit unsafe remote-code load path with no user opt-out
CVE-2026-46561Medium· 5.0pyload-ng: SSRF via HTTP Redirect Bypass in parse_urls API
pyload-ng: SSRF via HTTP Redirect Bypass in parse_urls API