VulnSea

Tagged “osv”

CVEs tagged osv, newest first.

5681 CVEsRSS

GHSA-gxhx-2686-5h9gMedium
4mo ago

slack-go `SecretsVerifier` accepts empty signing secret without precondition

slack-go `SecretsVerifier` accepts empty signing secret without precondition

▾ Sunlitslack-go · github.com/slack-go/slackvia OSV
CVE-2026-44681Medium· 6.1
4mo ago

Authlib OIDC Implicit/Hybrid Authorization Vulnerable to Open Redirect

Authlib OIDC Implicit/Hybrid Authorization Vulnerable to Open Redirect

▾ Sunlitauthlib · authlibEPSS 0.29%via OSV
RUSTSEC-2026-0235None
4mo ago

Insufficient archive validation can cause out-of-bounds reads in archives containing Rc/Arc

Insufficient archive validation can cause out-of-bounds reads in archives containing Rc/Arc

▾ Sunlitrkyv · rkyvvia OSV
CVE-2026-44697High· 8.6
4mo ago

Klever-Go MultiDataInterceptor has remote OOM via crafted compressed P2P payload

Klever-Go MultiDataInterceptor has remote OOM via crafted compressed P2P payload

▾ Twilightklever-io · github.com/klever-io/klever-goEPSS 0.46%via OSV
CVE-2026-44794Medium· 5.4
4mo ago

Nautobot: REST API permits creation of GenericForeignKey references to objects that the user should not be able to reference

Nautobot: REST API permits creation of GenericForeignKey references to objects that the user should not be able to reference

▾ Sunlitnautobot · nautobotEPSS 0.30%via OSV
CVE-2026-44796Medium· 6.5
4mo ago

Nautobot: Object bulk rename UI actions vulnerable to denial of service by crafted regular expression (REDoS)

Nautobot: Object bulk rename UI actions vulnerable to denial of service by crafted regular expression (REDoS)

▾ Sunlitnautobot · nautobotEPSS 0.56%via OSV
CVE-2026-44798High· 7.1
4mo ago

Nautobot: GitRepository.current_head field should not be writable through REST API

Nautobot: GitRepository.current_head field should not be writable through REST API

▾ Twilightnautobot · nautobotEPSS 0.50%via OSV
CVE-2026-44797High· 8.5
4mo ago

Nautobot: Webhook definitions could be used for server-side request forgery (SSRF)

Nautobot: Webhook definitions could be used for server-side request forgery (SSRF)

▾ Twilightnautobot · nautobotEPSS 0.40%via OSV
CVE-2026-45134High· 7.1
4mo ago

LangSmith SDK: Public prompt pull deserializes untrusted manifests without trust boundary warning

LangSmith SDK: Public prompt pull deserializes untrusted manifests without trust boundary warning

▾ Twilightlangsmith · langsmithEPSS 0.34%via OSV
CVE-2026-45152High· 7.8
4mo ago

uniget is Vulnerable to Command Injection in tool.Check Leading to Arbitrary Code Execution

uniget is Vulnerable to Command Injection in tool.Check Leading to Arbitrary Code Execution

▾ Twilightuniget-org · gitlab.com/uniget-org/cliEPSS 0.87%via OSV
CVE-2026-42266High· 8.8
4mo ago

JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture

JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From 4.0.0 to 4.5.6, the allow-list of extensions that can be installed from PyPI Extension Manager (allowed_…

▾ Twilightjupyter · jupyterlabEPSS 0.85%via NVD
CVE-2026-44432High· 7.5
4mo ago

urllib3 is an HTTP client library for Python

urllib3 is an HTTP client library for Python. From 2.6.0 to before 2.7.0, urllib3 could decompress the whole response instead of the requested portion (1) during the second HTTPResponse.read(amt=N) call when the response was decompressed…

▾ Twilightpython · urllib3EPSS 0.88%via NVD
CVE-2026-44431Medium· 5.3PoC
4mo ago

urllib3 is an HTTP client library for Python

urllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-level API via ProxyManager.connection_from_url().urlopen(..., assert_same_host=False) still forward these sensitive hea…

▾ TwilightRed Hat · Red Hat Enterprise Linux AppStream (v. 8)EPSS 0.34%via NVD
CVE-2026-31233Critical· 9.8
4mo ago

Guardrails AI contains a code injection vulnerability in its Hub package installation mechanism

Guardrails AI contains a code injection vulnerability in its Hub package installation mechanism

▾ Midnightguardrails-ai · guardrails-aiEPSS 0.93%via OSV
RUSTSEC-2026-0253None
4mo ago

Potential use-after-free due to lack of panic safety in `LruCache::pop()`

Potential use-after-free due to lack of panic safety in `LruCache::pop()`

▾ Sunlitlru · lruvia OSV
CVE-2026-31240High· 7.5
4mo ago

mem0 server lacks authentication and authorization controls for its memory management API endpoints

mem0 server lacks authentication and authorization controls for its memory management API endpoints

▾ Twilightmem0ai · mem0aiEPSS 0.54%via OSV
CVE-2026-31241Medium· 6.5
4mo ago

mem0 server lacks authentication and authorization controls for its memory deletion API endpoint

mem0 server lacks authentication and authorization controls for its memory deletion API endpoint

▾ Sunlitmem0ai · mem0aiEPSS 0.55%via OSV
CVE-2026-31224High· 8.8
4mo ago

Snorkel MultitaskClassifier.load uses an unsafe torch.load

Snorkel MultitaskClassifier.load uses an unsafe torch.load

▾ Twilightsnorkel · snorkelEPSS 0.69%via OSV
CVE-2026-31223High· 8.8
4mo ago

Snorkel BaseLabeler.load uses an unsafe pickle.load

Snorkel BaseLabeler.load uses an unsafe pickle.load

▾ Twilightsnorkel · snorkelEPSS 0.69%via OSV
CVE-2026-31245Medium· 5.3
4mo ago

mem0 server lacks authentication and authorization controls for its memory creation API endpoint

mem0 server lacks authentication and authorization controls for its memory creation API endpoint

▾ Sunlitmem0ai · mem0aiEPSS 0.48%via OSV
CVE-2026-31222High· 8.8
4mo ago

Snorkel Trainer.load uses an unsafe torch.load

Snorkel Trainer.load uses an unsafe torch.load

▾ Twilightsnorkel · snorkelEPSS 0.69%via OSV
CVE-2026-31221High· 8.0
4mo ago

pytorch-lightning: PyTorch-Lightning: Arbitrary code execution via insecure deserialization of checkpoint files (CVE-2026-31221)

A flaw was found in PyTorch-Lightning. This vulnerability, categorized as insecure deserialization (CWE-502), exists in the checkpoint loading mechanism. A remote attacker can exploit this by providing a maliciously crafted checkpoint file…

▾ TwilightRed Hat · Red Hat Enterprise Linux AI (RHEL AI) 3EPSS 0.55%via CSAF
CVE-2026-31225High· 8.8
4mo ago

Superduper: Remote code execution via unsafe eval in superduper query parsing

Superduper: Remote code execution via unsafe eval in superduper query parsing

▾ Twilightsuperduper-framework · superduper-frameworkEPSS 0.70%via OSV
CVE-2026-44223Medium· 6.5
4mo ago

vLLM is an inference and serving engine for large language models (LLMs)

vLLM is an inference and serving engine for large language models (LLMs). From 0.18.0 to before 0.20.0, the extract_hidden_states speculative decoding proposer in vLLM returns a tensor with an incorrect shape after the first decode step,…

▾ SunlitRed Hat · Red Hat Enterprise Linux AI 3.4EPSS 0.43%via NVD
CVE-2026-44477Critical· 9.9
4mo ago

CloudNativePG's metrics exporter allows privilege escalation to PostgreSQL superuser and OS RCE

CloudNativePG's metrics exporter allows privilege escalation to PostgreSQL superuser and OS RCE

▾ Midnightcloudnative-pg · github.com/cloudnative-pg/cloudnative-pgEPSS 0.52%via OSV
CVE-2026-7813Critical· 9.9
4mo ago

pgAdmin 4 server mode has an authorization vulnerability affecting Server Groups, Servers, Shared Servers, Background Processes, and Debu…

pgAdmin 4 server mode has an authorization vulnerability affecting Server Groups, Servers, Shared Servers, Background Processes, and Debugger modules

▾ Midnightpgadmin4 · pgadmin4EPSS 0.65%via OSV
CVE-2026-41018Medium· 6.5
4mo ago

Apache Airflow Providers Elasticsearch: Elasticsearch task-log handlers leak credentials embedded in the host URL

Apache Airflow Providers Elasticsearch: Elasticsearch task-log handlers leak credentials embedded in the host URL

▾ Sunlitapache-airflow-providers-elasticsearch · apache-airflow-providers-elasticsearchEPSS 0.66%via OSV
CVE-2026-45017High· 7.5
4mo ago

python-liquid: Absolute paths escape filesystem loader search path

python-liquid: Absolute paths escape filesystem loader search path

▾ Twilightpython-liquid · python-liquidEPSS 0.50%via OSV
RUSTSEC-2026-0234None
4mo ago

Insufficient archive validation can cause out-of-bounds reads in archives containing hash tables

Insufficient archive validation can cause out-of-bounds reads in archives containing hash tables

▾ Sunlitrkyv · rkyvvia OSV
RUSTSEC-2026-0233None
4mo ago

Crafted archives can cause a use-after-free during deserialization

Crafted archives can cause a use-after-free during deserialization

▾ Sunlitrkyv · rkyvvia OSV
CVEs tagged “osv” — page 64 · VulnSea