Tagged “osv”
CVEs tagged osv, newest first.
5681 CVEsRSS
GHSA-gxhx-2686-5h9gMediumslack-go `SecretsVerifier` accepts empty signing secret without precondition
slack-go `SecretsVerifier` accepts empty signing secret without precondition
CVE-2026-44681Medium· 6.1Authlib OIDC Implicit/Hybrid Authorization Vulnerable to Open Redirect
Authlib OIDC Implicit/Hybrid Authorization Vulnerable to Open Redirect
RUSTSEC-2026-0235NoneInsufficient archive validation can cause out-of-bounds reads in archives containing Rc/Arc
Insufficient archive validation can cause out-of-bounds reads in archives containing Rc/Arc
CVE-2026-44697High· 8.6Klever-Go MultiDataInterceptor has remote OOM via crafted compressed P2P payload
Klever-Go MultiDataInterceptor has remote OOM via crafted compressed P2P payload
CVE-2026-44794Medium· 5.4Nautobot: REST API permits creation of GenericForeignKey references to objects that the user should not be able to reference
Nautobot: REST API permits creation of GenericForeignKey references to objects that the user should not be able to reference
CVE-2026-44796Medium· 6.5Nautobot: Object bulk rename UI actions vulnerable to denial of service by crafted regular expression (REDoS)
Nautobot: Object bulk rename UI actions vulnerable to denial of service by crafted regular expression (REDoS)
CVE-2026-44798High· 7.1Nautobot: GitRepository.current_head field should not be writable through REST API
Nautobot: GitRepository.current_head field should not be writable through REST API
CVE-2026-44797High· 8.5Nautobot: Webhook definitions could be used for server-side request forgery (SSRF)
Nautobot: Webhook definitions could be used for server-side request forgery (SSRF)
CVE-2026-45134High· 7.1LangSmith SDK: Public prompt pull deserializes untrusted manifests without trust boundary warning
LangSmith SDK: Public prompt pull deserializes untrusted manifests without trust boundary warning
CVE-2026-45152High· 7.8uniget is Vulnerable to Command Injection in tool.Check Leading to Arbitrary Code Execution
uniget is Vulnerable to Command Injection in tool.Check Leading to Arbitrary Code Execution
CVE-2026-42266High· 8.8JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture
JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From 4.0.0 to 4.5.6, the allow-list of extensions that can be installed from PyPI Extension Manager (allowed_…
CVE-2026-44432High· 7.5urllib3 is an HTTP client library for Python
urllib3 is an HTTP client library for Python. From 2.6.0 to before 2.7.0, urllib3 could decompress the whole response instead of the requested portion (1) during the second HTTPResponse.read(amt=N) call when the response was decompressed…
CVE-2026-44431Medium· 5.3PoCurllib3 is an HTTP client library for Python
urllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-level API via ProxyManager.connection_from_url().urlopen(..., assert_same_host=False) still forward these sensitive hea…
CVE-2026-31233Critical· 9.8Guardrails AI contains a code injection vulnerability in its Hub package installation mechanism
Guardrails AI contains a code injection vulnerability in its Hub package installation mechanism
RUSTSEC-2026-0253NonePotential use-after-free due to lack of panic safety in `LruCache::pop()`
Potential use-after-free due to lack of panic safety in `LruCache::pop()`
CVE-2026-31240High· 7.5mem0 server lacks authentication and authorization controls for its memory management API endpoints
mem0 server lacks authentication and authorization controls for its memory management API endpoints
CVE-2026-31241Medium· 6.5mem0 server lacks authentication and authorization controls for its memory deletion API endpoint
mem0 server lacks authentication and authorization controls for its memory deletion API endpoint
CVE-2026-31224High· 8.8Snorkel MultitaskClassifier.load uses an unsafe torch.load
Snorkel MultitaskClassifier.load uses an unsafe torch.load
CVE-2026-31223High· 8.8Snorkel BaseLabeler.load uses an unsafe pickle.load
Snorkel BaseLabeler.load uses an unsafe pickle.load
CVE-2026-31245Medium· 5.3mem0 server lacks authentication and authorization controls for its memory creation API endpoint
mem0 server lacks authentication and authorization controls for its memory creation API endpoint
CVE-2026-31222High· 8.8Snorkel Trainer.load uses an unsafe torch.load
Snorkel Trainer.load uses an unsafe torch.load
CVE-2026-31221High· 8.0pytorch-lightning: PyTorch-Lightning: Arbitrary code execution via insecure deserialization of checkpoint files (CVE-2026-31221)
A flaw was found in PyTorch-Lightning. This vulnerability, categorized as insecure deserialization (CWE-502), exists in the checkpoint loading mechanism. A remote attacker can exploit this by providing a maliciously crafted checkpoint file…
CVE-2026-31225High· 8.8Superduper: Remote code execution via unsafe eval in superduper query parsing
Superduper: Remote code execution via unsafe eval in superduper query parsing
CVE-2026-44223Medium· 6.5vLLM is an inference and serving engine for large language models (LLMs)
vLLM is an inference and serving engine for large language models (LLMs). From 0.18.0 to before 0.20.0, the extract_hidden_states speculative decoding proposer in vLLM returns a tensor with an incorrect shape after the first decode step,…
CVE-2026-44477Critical· 9.9CloudNativePG's metrics exporter allows privilege escalation to PostgreSQL superuser and OS RCE
CloudNativePG's metrics exporter allows privilege escalation to PostgreSQL superuser and OS RCE
CVE-2026-7813Critical· 9.9pgAdmin 4 server mode has an authorization vulnerability affecting Server Groups, Servers, Shared Servers, Background Processes, and Debu…
pgAdmin 4 server mode has an authorization vulnerability affecting Server Groups, Servers, Shared Servers, Background Processes, and Debugger modules
CVE-2026-41018Medium· 6.5Apache Airflow Providers Elasticsearch: Elasticsearch task-log handlers leak credentials embedded in the host URL
Apache Airflow Providers Elasticsearch: Elasticsearch task-log handlers leak credentials embedded in the host URL
CVE-2026-45017High· 7.5python-liquid: Absolute paths escape filesystem loader search path
python-liquid: Absolute paths escape filesystem loader search path
RUSTSEC-2026-0234NoneInsufficient archive validation can cause out-of-bounds reads in archives containing hash tables
Insufficient archive validation can cause out-of-bounds reads in archives containing hash tables
RUSTSEC-2026-0233NoneCrafted archives can cause a use-after-free during deserialization
Crafted archives can cause a use-after-free during deserialization