Tagged “osv”
CVEs tagged osv, newest first.
5683 CVEsRSS
CVE-2026-8212Medium· 5.3OSGeo gdal has a heap-based buffer overflow
OSGeo gdal has a heap-based buffer overflow
MAL-2026-3411NoneMalicious code in web3-py-checksum (PyPI)
Malicious code in web3-py-checksum (PyPI)
CVE-2026-42308Medium· 6.2Pillow: Pillow: Denial of Service via integer overflow in font processing (CVE-2026-42308)
A flaw was found in Pillow, a Python imaging library. If a font advances for each glyph by an exceeding large amount, an integer overflow can occur when Pillow tracks the current position. This could lead to a denial of service (DoS) condi…
CVE-2026-8213Medium· 5.5A vulnerability has been found in OSGeo gdal up to 3.13.0dev-4. Affected by this issue is the function GDSDfldsrch of the file frmts/hdf4…
A vulnerability has been found in OSGeo gdal up to 3.13.0dev-4. Affected by this issue is the function GDSDfldsrch of the file frmts/hdf4/hdf-eos/GDapi.c of the component Grid File Handler. The manipulation leads to heap-based buffer ove…
CVE-2026-44897Medium· 6.1Mistune Heading ID Attribute has Injection XSS
Mistune Heading ID Attribute has Injection XSS
CVE-2026-42301High· 7.3pyp2spec: pyp2spec: Arbitrary command execution via unescaped RPM macro directives (CVE-2026-42301)
A flaw was found in pyp2spec, a tool that generates Fedora RPM spec files for Python projects. This vulnerability allows a malicious Python Package Index (PyPI) package to execute arbitrary commands on a build machine. This occurs because …
CVE-2026-42311High· 7.8Pillow: python-pillow: Pillow: Arbitrary code execution via malicious PSD file processing (CVE-2026-42311)
A flaw was found in Pillow, a Python imaging library. An attacker could exploit this vulnerability by tricking a user into processing a specially crafted malicious PSD file. This could lead to memory corruption, potentially causing the app…
CVE-2026-44309Medium· 5.3gitsign verify accepts signatures over go-git-normalized bytes, enabling trust confusion on malformed commits
gitsign verify accepts signatures over go-git-normalized bytes, enabling trust confusion on malformed commits
CVE-2026-44310Medium· 5.4gitsign --verify panics on empty-certificate PKCS7 and exits 0, bypassing exit-code callers
gitsign --verify panics on empty-certificate PKCS7 and exits 0, bypassing exit-code callers
CVE-2026-44896Medium· 6.1Mistune has XSS via unescaped figclass/figwidth in Figure directive
Mistune has XSS via unescaped figclass/figwidth in Figure directive
CVE-2026-38360Critical· 9.8PoCdash-uploader has a directory traversal vulnerability
dash-uploader has a directory traversal vulnerability
CVE-2026-4671Lowjusthtml introduces denial-of-service hardening
justhtml introduces denial-of-service hardening
CVE-2026-44327Critical· 10.0free5GC's NEF nnef-oam route group is unauthenticated; no-token requests reach the OAM handler
free5GC's NEF nnef-oam route group is unauthenticated; no-token requests reach the OAM handler
CVE-2026-44564Medium· 5.4Read-Only Open WebUI Users Can Modify Collaborative Documents via Socket.IO
Read-Only Open WebUI Users Can Modify Collaborative Documents via Socket.IO
CVE-2026-44563Medium· 5.4Open WebUI's Ollama Model Access Control Bypass via /api/generate, /api/embed, /api/embeddings, and /api/show
Open WebUI's Ollama Model Access Control Bypass via /api/generate, /api/embed, /api/embeddings, and /api/show
CVE-2026-44843High· 8.2LangChain vulnerable to unsafe deserialization of attacker-controlled objects through overly broad `load()` allowlists
LangChain vulnerable to unsafe deserialization of attacker-controlled objects through overly broad `load()` allowlists
CVE-2026-44562Medium· 6.5Open WebUI's Model Import Overwrites Any Model Without Ownership Check
Open WebUI's Model Import Overwrites Any Model Without Ownership Check
CVE-2026-40214Medium· 6.3OpenStack Cyborg's Accelerator Request (ARQ) API does not enforce project ownership at any layer
OpenStack Cyborg's Accelerator Request (ARQ) API does not enforce project ownership at any layer
CVE-2026-40213High· 7.4OpenStack Cyborg uses rule:allow (check_str='@') as the default policy for multiple API endpoints
OpenStack Cyborg uses rule:allow (check_str='@') as the default policy for multiple API endpoints
CVE-2026-44549High· 7.3Open WebUI has stored XSS in Excel file preview
Open WebUI has stored XSS in Excel file preview
CVE-2026-44550Medium· 5.0Open WebUI's Mass Assignment via Pydantic extra='allow' Allows Creating Folders in Other Users' Accounts
Open WebUI's Mass Assignment via Pydantic extra='allow' Allows Creating Folders in Other Users' Accounts
CVE-2026-44556High· 7.1Open WebUI's responses passthrough endpoint lacks access control authorization
Open WebUI's responses passthrough endpoint lacks access control authorization
CVE-2026-44561Medium· 5.4Open WebUI: Deactivated Channel Members Retain Full Access to Group/DM Channels
Open WebUI: Deactivated Channel Members Retain Full Access to Group/DM Channels
CVE-2026-44560Medium· 6.5Open WebUI has Unauthorized File and Knowledge Base Content Access via RAG Vector Search
Open WebUI has Unauthorized File and Knowledge Base Content Access via RAG Vector Search
CVE-2026-44209High· 7.5banks has Critical Remote Code Execution (RCE) via Jinja2 SSTI
banks has Critical Remote Code Execution (RCE) via Jinja2 SSTI
CVE-2026-44721High· 7.3open-webui Vulnerable to Stored XSS via Model Description
open-webui Vulnerable to Stored XSS via Model Description
CVE-2026-44844Mediumeml_parser has recursion DoS via nested message/rfc822 attachments
eml_parser has recursion DoS via nested message/rfc822 attachments
CVE-2026-44568Medium· 4.8Open WebUI has Stored XSS in Pending User Overlay via Incorrect DOMPurify Application Order
Open WebUI has Stored XSS in Pending User Overlay via Incorrect DOMPurify Application Order
CVE-2026-44502Medium· 4.3Bunsink has an SSRF bypass in `validate_webhook_url`
Bunsink has an SSRF bypass in `validate_webhook_url`
CVE-2026-44559Medium· 4.3Open WebUI Missing Access Check on Channel Members Endpoint for Standard Channels
Open WebUI Missing Access Check on Channel Members Endpoint for Standard Channels