Tagged “osv”
CVEs tagged osv, newest first.
5683 CVEsRSS
CVE-2026-8596High· 7.2Cleartext storage of HMAC signing key in Amazon SageMaker Python SDK ModelBuilder/Serve path
Cleartext storage of HMAC signing key in Amazon SageMaker Python SDK ModelBuilder/Serve path
CVE-2026-46486MediumMobile Verification Toolkit (MVT): Path Traversal via unsanitized File identifiers in iOS Backup processing
Mobile Verification Toolkit (MVT): Path Traversal via unsanitized File identifiers in iOS Backup processing
CVE-2026-46645Medium· 4.3PoCSQLAdmin: Authorization Bypass on `ajax_lookup`
SQLAdmin: Authorization Bypass on `ajax_lookup`
CVE-2026-46497LowCrawlee for Python: SSRF via sitemap-derived URLs
Crawlee for Python: SSRF via sitemap-derived URLs
CVE-2026-48989HighWindows-MCP: HTTP transports expose unauthenticated PowerShell control with wildcard CORS
Windows-MCP: HTTP transports expose unauthenticated PowerShell control with wildcard CORS
CVE-2026-47102High· 8.8PoCLiteLLM prior to 1.83.10 allows a user to modify their own user_role via the /user/update endpoint
LiteLLM prior to 1.83.10 allows a user to modify their own user_role via the /user/update endpoint. While the endpoint correctly restricts users to updating only their own account, it does not restrict which fields may be changed. A user…
CVE-2026-47101High· 8.8PoCLiteLLM prior to 1.83.14 allows an authenticated internal_user to create API keys with access to routes that their role does not permit
LiteLLM prior to 1.83.14 allows an authenticated internal_user to create API keys with access to routes that their role does not permit. When generating a key, the allowed_routes field is stored without verifying that the specified route…
CVE-2026-45792Medium· 5.5RTK improperly trusts project-local filter configuration, allowing silent tampering of command output shown to LLM
RTK improperly trusts project-local filter configuration, allowing silent tampering of command output shown to LLM
CVE-2026-45781Low· 3.5MCP Registry: OCI validator skips ownership check on upstream rate limits
MCP Registry: OCI validator skips ownership check on upstream rate limits
CVE-2026-45712Medium· 5.9Mailpit: Concurrent map read & write in proxy CSS rewriter - remote unauth crash (fatal error: concurrent map read and map write)
Mailpit: Concurrent map read & write in proxy CSS rewriter - remote unauth crash (fatal error: concurrent map read and map write)
CVE-2026-45711Medium· 5.9Mailpit: Path traversal & arbitrary file write in mailpit dump --http via attacker-controlled message IDs
Mailpit: Path traversal & arbitrary file write in mailpit dump --http via attacker-controlled message IDs
CVE-2026-45709Medium· 5.8Mailpit has an incomplete fix for GHSA-6jxm: HTML check still permits SSRF to private/loopback/IMDS via missing IP-filter dialer
Mailpit has an incomplete fix for GHSA-6jxm: HTML check still permits SSRF to private/loopback/IMDS via missing IP-filter dialer
CVE-2026-45713High· 7.5Mailpit: Unauthenticated remote memory-exhaustion DoS via unlimited SMTP DATA and /api/v1/send body sizes
Mailpit: Unauthenticated remote memory-exhaustion DoS via unlimited SMTP DATA and /api/v1/send body sizes
GHSA-wwhq-w58m-w29cMediumCaddy CVE-2026-30852 Fix Bypass
Caddy CVE-2026-30852 Fix Bypass
GHSA-gx7w-56w6-g48xMedium· 4.3Caddy: Remote Admin Authorization Bypass on PKI Endpoints via Prefix-Based Path Matching
Caddy: Remote Admin Authorization Bypass on PKI Endpoints via Prefix-Based Path Matching
CVE-2026-45571Medium· 5.4go-git: Crafted repositories may modify main and submodule .git directories
go-git: Crafted repositories may modify main and submodule .git directories
GHSA-g53w-w6mj-hrppCriticalMCP Gateway: Authority-injection and JWT/session bypass via the unauthenticated router hair-pin "router-key" / "mcp-init-host" path
MCP Gateway: Authority-injection and JWT/session bypass via the unauthenticated router hair-pin "router-key" / "mcp-init-host" path
CVE-2026-45739Low· 3.1Strawberry GraphQL: Default GraphiQL may expose HTTP headers in URLs
Strawberry GraphQL: Default GraphiQL may expose HTTP headers in URLs
CVE-2025-51427High· 7.3ModelScope is vulnerable to arbitrary code injection via a crafted module
ModelScope is vulnerable to arbitrary code injection via a crafted module
CVE-2026-46338Medium· 4.3Regression in pymdownx.snippets reintroduces sibling-prefix path traversal bypass despite restrict_base_path
Regression in pymdownx.snippets reintroduces sibling-prefix path traversal bypass despite restrict_base_path
CVE-2026-45692Medium· 5.4Caddy: Remote Admin Authorization Bypass in `/config` API via Array Index Normalization
Caddy: Remote Admin Authorization Bypass in `/config` API via Array Index Normalization
CVE-2026-46373High· 7.5SQLFluff: Recursive Stack Overflow in Parser
SQLFluff: Recursive Stack Overflow in Parser
CVE-2026-46374High· 7.5SQLFluff: Uncontrolled Resource Consumption in SQLFluff Parser
SQLFluff: Uncontrolled Resource Consumption in SQLFluff Parser
GHSA-mx64-mj3q-7prjHigh· 7.5iskorotkov/avro: Denial-of-Service Vulnerability in Decoder
iskorotkov/avro: Denial-of-Service Vulnerability in Decoder
CVE-2026-8838Critical· 9.8PoCUnsafe use of Python's eval() on server-received data in the vector_in() function in amazon-redshift-python-driver before 2.1.14 allows a rogue server or man-in-the-middle actor to execute arbitrary code on the client
Unsafe use of Python's eval() on server-received data in the vector_in() function in amazon-redshift-python-driver before 2.1.14 allows a rogue server or man-in-the-middle actor to execute arbitrary code on the client. To remediate t…
CVE-2026-45539High· 7.4Microsoft APM: Symlinks under `.apm/prompts/` and `.apm/agents/` are dereferenced during `apm install`, copying host-local file contents …
Microsoft APM: Symlinks under `.apm/prompts/` and `.apm/agents/` are dereferenced during `apm install`, copying host-local file contents into the project tree
CVE-2026-45554Medium· 5.3NiceGUI: Unauthenticated log-volume denial of service in dynamic resource routes
NiceGUI: Unauthenticated log-volume denial of service in dynamic resource routes
CVE-2026-45727HighCloakBrowser: Unauthenticated path traversal via fingerprint parameter in cloakserve leads to arbitrary directory deletion
CloakBrowser: Unauthenticated path traversal via fingerprint parameter in cloakserve leads to arbitrary directory deletion
CVE-2026-45553High· 7.5NiceGUI: Local file disclosure via Docutils file insertion in ui.restructured_text()
NiceGUI: Local file disclosure via Docutils file insertion in ui.restructured_text()
CVE-2026-4137High· 7.0MLFlow Creates a Temporary File With Insecure Permissions
MLFlow Creates a Temporary File With Insecure Permissions