VulnSea

Tagged “osv”

CVEs tagged osv, newest first.

5683 CVEsRSS

CVE-2026-8596High· 7.2
4mo ago

Cleartext storage of HMAC signing key in Amazon SageMaker Python SDK ModelBuilder/Serve path

Cleartext storage of HMAC signing key in Amazon SageMaker Python SDK ModelBuilder/Serve path

▾ Twilightsagemaker · sagemakerEPSS 0.80%via OSV
CVE-2026-46486Medium
4mo ago

Mobile Verification Toolkit (MVT): Path Traversal via unsanitized File identifiers in iOS Backup processing

Mobile Verification Toolkit (MVT): Path Traversal via unsanitized File identifiers in iOS Backup processing

▾ Sunlitmvt · mvtEPSS 0.52%via OSV
CVE-2026-46645Medium· 4.3PoC
4mo ago

SQLAdmin: Authorization Bypass on `ajax_lookup`

SQLAdmin: Authorization Bypass on `ajax_lookup`

▾ Twilightsqladmin · sqladminEPSS 0.37%via OSV
CVE-2026-46497Low
4mo ago

Crawlee for Python: SSRF via sitemap-derived URLs

Crawlee for Python: SSRF via sitemap-derived URLs

▾ Sunlitcrawlee · crawleeEPSS 0.46%via OSV
CVE-2026-48989High
4mo ago

Windows-MCP: HTTP transports expose unauthenticated PowerShell control with wildcard CORS

Windows-MCP: HTTP transports expose unauthenticated PowerShell control with wildcard CORS

▾ Twilightwindows-mcp · windows-mcpEPSS 0.69%via OSV
CVE-2026-47102High· 8.8PoC
4mo ago

LiteLLM prior to 1.83.10 allows a user to modify their own user_role via the /user/update endpoint

LiteLLM prior to 1.83.10 allows a user to modify their own user_role via the /user/update endpoint. While the endpoint correctly restricts users to updating only their own account, it does not restrict which fields may be changed. A user…

▾ Midnightlitellm · litellmEPSS 0.82%via NVD
CVE-2026-47101High· 8.8PoC
4mo ago

LiteLLM prior to 1.83.14 allows an authenticated internal_user to create API keys with access to routes that their role does not permit

LiteLLM prior to 1.83.14 allows an authenticated internal_user to create API keys with access to routes that their role does not permit. When generating a key, the allowed_routes field is stored without verifying that the specified route…

▾ Midnightlitellm · litellmEPSS 1.3%via NVD
CVE-2026-45792Medium· 5.5
4mo ago

RTK improperly trusts project-local filter configuration, allowing silent tampering of command output shown to LLM

RTK improperly trusts project-local filter configuration, allowing silent tampering of command output shown to LLM

▾ Sunlitrtk · rtkEPSS 0.11%via OSV
CVE-2026-45781Low· 3.5
4mo ago

MCP Registry: OCI validator skips ownership check on upstream rate limits

MCP Registry: OCI validator skips ownership check on upstream rate limits

▾ Sunlitmodelcontextprotocol · github.com/modelcontextprotocol/registryEPSS 0.25%via OSV
CVE-2026-45712Medium· 5.9
4mo ago

Mailpit: Concurrent map read & write in proxy CSS rewriter - remote unauth crash (fatal error: concurrent map read and map write)

Mailpit: Concurrent map read & write in proxy CSS rewriter - remote unauth crash (fatal error: concurrent map read and map write)

▾ Sunlitaxllent · github.com/axllent/mailpitEPSS 0.34%via OSV
CVE-2026-45711Medium· 5.9
4mo ago

Mailpit: Path traversal & arbitrary file write in mailpit dump --http via attacker-controlled message IDs

Mailpit: Path traversal & arbitrary file write in mailpit dump --http via attacker-controlled message IDs

▾ Sunlitaxllent · github.com/axllent/mailpitEPSS 0.39%via OSV
CVE-2026-45709Medium· 5.8
4mo ago

Mailpit has an incomplete fix for GHSA-6jxm: HTML check still permits SSRF to private/loopback/IMDS via missing IP-filter dialer

Mailpit has an incomplete fix for GHSA-6jxm: HTML check still permits SSRF to private/loopback/IMDS via missing IP-filter dialer

▾ Sunlitaxllent · github.com/axllent/mailpitEPSS 0.32%via OSV
CVE-2026-45713High· 7.5
4mo ago

Mailpit: Unauthenticated remote memory-exhaustion DoS via unlimited SMTP DATA and /api/v1/send body sizes

Mailpit: Unauthenticated remote memory-exhaustion DoS via unlimited SMTP DATA and /api/v1/send body sizes

▾ Twilightaxllent · github.com/axllent/mailpitEPSS 0.61%via OSV
GHSA-wwhq-w58m-w29cMedium
4mo ago

Caddy CVE-2026-30852 Fix Bypass

Caddy CVE-2026-30852 Fix Bypass

▾ Sunlitcaddyserver · github.com/caddyserver/caddy/v2via OSV
GHSA-gx7w-56w6-g48xMedium· 4.3
4mo ago

Caddy: Remote Admin Authorization Bypass on PKI Endpoints via Prefix-Based Path Matching

Caddy: Remote Admin Authorization Bypass on PKI Endpoints via Prefix-Based Path Matching

▾ Sunlitcaddyserver · github.com/caddyserver/caddy/v2via OSV
CVE-2026-45571Medium· 5.4
4mo ago

go-git: Crafted repositories may modify main and submodule .git directories

go-git: Crafted repositories may modify main and submodule .git directories

▾ Sunlitgo-git · github.com/go-git/go-git/v5EPSS 0.33%via OSV
GHSA-g53w-w6mj-hrppCritical
4mo ago

MCP Gateway: Authority-injection and JWT/session bypass via the unauthenticated router hair-pin "router-key" / "mcp-init-host" path

MCP Gateway: Authority-injection and JWT/session bypass via the unauthenticated router hair-pin "router-key" / "mcp-init-host" path

▾ MidnightKuadrant · github.com/Kuadrant/mcp-gatewayvia OSV
CVE-2026-45739Low· 3.1
4mo ago

Strawberry GraphQL: Default GraphiQL may expose HTTP headers in URLs

Strawberry GraphQL: Default GraphiQL may expose HTTP headers in URLs

▾ Sunlitstrawberry-graphql · strawberry-graphqlEPSS 0.36%via OSV
CVE-2025-51427High· 7.3
4mo ago

ModelScope is vulnerable to arbitrary code injection via a crafted module

ModelScope is vulnerable to arbitrary code injection via a crafted module

▾ Twilightmodelscope · modelscopeEPSS 0.52%via OSV
CVE-2026-46338Medium· 4.3
4mo ago

Regression in pymdownx.snippets reintroduces sibling-prefix path traversal bypass despite restrict_base_path

Regression in pymdownx.snippets reintroduces sibling-prefix path traversal bypass despite restrict_base_path

▾ Sunlitpymdown-extensions · pymdown-extensionsEPSS 0.40%via OSV
CVE-2026-45692Medium· 5.4
4mo ago

Caddy: Remote Admin Authorization Bypass in `/config` API via Array Index Normalization

Caddy: Remote Admin Authorization Bypass in `/config` API via Array Index Normalization

▾ Sunlitcaddyserver · github.com/caddyserver/caddy/v2EPSS 0.24%via OSV
CVE-2026-46373High· 7.5
4mo ago

SQLFluff: Recursive Stack Overflow in Parser

SQLFluff: Recursive Stack Overflow in Parser

▾ Twilightsqlfluff · sqlfluffEPSS 0.46%via OSV
CVE-2026-46374High· 7.5
4mo ago

SQLFluff: Uncontrolled Resource Consumption in SQLFluff Parser

SQLFluff: Uncontrolled Resource Consumption in SQLFluff Parser

▾ Twilightsqlfluff · sqlfluffEPSS 0.46%via OSV
GHSA-mx64-mj3q-7prjHigh· 7.5
4mo ago

iskorotkov/avro: Denial-of-Service Vulnerability in Decoder

iskorotkov/avro: Denial-of-Service Vulnerability in Decoder

▾ Twilightiskorotkov · github.com/iskorotkov/avro/v2via OSV
CVE-2026-8838Critical· 9.8PoC
4mo ago

Unsafe use of Python's eval() on server-received data in the vector_in() function in amazon-redshift-python-driver before 2.1.14 allows a rogue server or man-in-the-middle actor to execute arbitrary code on the client

Unsafe use of Python's eval() on server-received data in the vector_in() function in amazon-redshift-python-driver before 2.1.14 allows a rogue server or man-in-the-middle actor to execute arbitrary code on the client. To remediate t…

▾ Abyssalredshift-connector · redshift-connectorEPSS 0.80%via NVD
CVE-2026-45539High· 7.4
4mo ago

Microsoft APM: Symlinks under `.apm/prompts/` and `.apm/agents/` are dereferenced during `apm install`, copying host-local file contents …

Microsoft APM: Symlinks under `.apm/prompts/` and `.apm/agents/` are dereferenced during `apm install`, copying host-local file contents into the project tree

▾ Twilightapm · apmEPSS 1.1%via OSV
CVE-2026-45554Medium· 5.3
4mo ago

NiceGUI: Unauthenticated log-volume denial of service in dynamic resource routes

NiceGUI: Unauthenticated log-volume denial of service in dynamic resource routes

▾ Sunlitnicegui · niceguiEPSS 0.60%via OSV
CVE-2026-45727High
4mo ago

CloakBrowser: Unauthenticated path traversal via fingerprint parameter in cloakserve leads to arbitrary directory deletion

CloakBrowser: Unauthenticated path traversal via fingerprint parameter in cloakserve leads to arbitrary directory deletion

▾ Twilightcloakbrowser · cloakbrowserEPSS 0.65%via OSV
CVE-2026-45553High· 7.5
4mo ago

NiceGUI: Local file disclosure via Docutils file insertion in ui.restructured_text()

NiceGUI: Local file disclosure via Docutils file insertion in ui.restructured_text()

▾ Twilightnicegui · niceguiEPSS 0.43%via OSV
CVE-2026-4137High· 7.0
4mo ago

MLFlow Creates a Temporary File With Insecure Permissions

MLFlow Creates a Temporary File With Insecure Permissions

▾ Twilightmlflow · mlflowEPSS 0.16%via OSV
CVEs tagged “osv” — page 61 · VulnSea