VulnSea

Tagged “osv”

CVEs tagged osv, newest first.

5683 CVEsRSS

CVE-2026-44555High· 7.6
4mo ago

Open WebUI's Base Model Routing Bypasses Access Control via Model Chaining

Open WebUI's Base Model Routing Bypasses Access Control via Model Chaining

▾ Twilightopen-webui · open-webuiEPSS 0.35%via OSV
CVE-2026-44566High· 7.3
4mo ago

Open WebUI Vulnerable to Arbitrary File Upload and Path Traversal

Open WebUI Vulnerable to Arbitrary File Upload and Path Traversal

▾ Twilightopen-webui · open-webuiEPSS 0.46%via OSV
CVE-2026-44708Medium· 6.1
4mo ago

Mistune Math Plugin has an XSS Escape Bypass

Mistune Math Plugin has an XSS Escape Bypass

▾ Sunlitmistune · mistuneEPSS 0.27%via OSV
CVE-2026-44558Medium· 5.4
4mo ago

Open WebUI's Channel Access Grants Bypass filter_allowed_access_grants

Open WebUI's Channel Access Grants Bypass filter_allowed_access_grants

▾ Sunlitopen-webui · open-webuiEPSS 0.27%via OSV
CVE-2026-44554High· 8.1
4mo ago

Open WebUI has Knowledge Base Destruction and RAG Poisoning via Unauthorized Collection Overwrite

Open WebUI has Knowledge Base Destruction and RAG Poisoning via Unauthorized Collection Overwrite

▾ Twilightopen-webui · open-webuiEPSS 0.43%via OSV
CVE-2026-44557Medium· 4.3
4mo ago

Open WebUI vulnerable to Global Knowledge Base Enumeration via knowledge-bases Meta-Collection

Open WebUI vulnerable to Global Knowledge Base Enumeration via knowledge-bases Meta-Collection

▾ Sunlitopen-webui · open-webuiEPSS 0.30%via OSV
CVE-2026-44567High· 7.3
4mo ago

Open WebUI has Improper Authorization Control

Open WebUI has Improper Authorization Control

▾ Twilightopen-webui · open-webuiEPSS 0.34%via OSV
CVE-2026-44553High· 8.1
4mo ago

Open WebUI: Stale Admin Role in Socket.IO Session Pool Enables Post-Demotion Cross-User Note Access

Open WebUI: Stale Admin Role in Socket.IO Session Pool Enables Post-Demotion Cross-User Note Access

▾ Twilightopen-webui · open-webuiEPSS 0.39%via OSV
CVE-2026-44552High· 8.7
4mo ago

Open WebUI: Redis Cache Keys tool_servers and terminal_servers Missing Instance Prefix Enable Cross-Instance Cache Poisoning

Open WebUI: Redis Cache Keys tool_servers and terminal_servers Missing Instance Prefix Enable Cross-Instance Cache Poisoning

▾ Twilightopen-webui · open-webuiEPSS 0.42%via OSV
CVE-2026-42271High· 8.8CISA KEVPoC
4mo ago

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.74.2 to before version 1.83.7, two endpoints used to preview an MCP server before saving it — POST /mcp-rest/test/connection and POST /m…

▾ Abyssallitellm · litellmEPSS 93%via NVD
CVE-2026-42208Critical· 9.8CISA KEV0dayPoC
4mo ago

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.81.16 to before version 1.83.7, a database query used during proxy API key checks mixed the caller-supplied key value into the query tex…

▾ Hadallitellm · litellmEPSS 5.8%via NVD
CVE-2026-44471High· 7.8
4mo ago

gix-fs: Symlink prefix-reuse allows worktree escape during checkout

gix-fs: Symlink prefix-reuse allows worktree escape during checkout

▾ Twilightgix-fs · gix-fsEPSS 0.21%via OSV
CVE-2026-25705High· 8.4
4mo ago

Rancher Extensions have arbitrary file access via path traversal

Rancher Extensions have arbitrary file access via path traversal

▾ Twilightrancher · github.com/rancher/rancherEPSS 0.49%via OSV
CVE-2026-44484Critical· 9.8
4mo ago

Compromise of PyTorch Lightning PyPi Package Versions

Compromise of PyTorch Lightning PyPi Package Versions

▾ Midnightpytorch-lightning · pytorch-lightningEPSS 0.67%via OSV
CVE-2026-79660Medium· 5.3
4mo ago

Ech0 comment model's Email field returned on public /api/comments endpoints

Ech0 comment model's Email field returned on public /api/comments endpoints

▾ Sunlitlin-snow · github.com/lin-snow/Ech0EPSS 0.41%via OSV
CVE-2026-79668Medium· 5.3
4mo ago

Ech0's Unauthenticated Like Endpoint Enables Arbitrary Engagement Metric Inflation

Ech0's Unauthenticated Like Endpoint Enables Arbitrary Engagement Metric Inflation

▾ Sunlitlin-snow · github.com/lin-snow/ech0EPSS 0.43%via OSV
CVE-2026-79661Medium· 6.5
4mo ago

Ech0 allows PUT /api/echo/like/:id unauthenticated: anonymous callers to modify any echo's fav_count

Ech0 allows PUT /api/echo/like/:id unauthenticated: anonymous callers to modify any echo's fav_count

▾ Sunlitlin-snow · github.com/lin-snow/Ech0EPSS 0.43%via OSV
CVE-2026-79662High· 8.0
4mo ago

Ech0's OAuth redirect URI validation ignores path component, enables exchange-code theft

Ech0's OAuth redirect URI validation ignores path component, enables exchange-code theft

▾ Twilightlin-snow · github.com/lin-snow/Ech0EPSS 0.32%via OSV
CVE-2026-79663Medium· 4.8
4mo ago

Ech0's RSS feed renders unescaped tag names and raw-HTML markdown, stored XSS against subscribers

Ech0's RSS feed renders unescaped tag names and raw-HTML markdown, stored XSS against subscribers

▾ Sunlitlin-snow · github.com/lin-snow/Ech0EPSS 0.25%via OSV
CVE-2026-42501Medium· 5.3
4mo ago

cmd/go: golang: Go command (cmd/go): Integrity bypass due to checksum validation flaw via malicious module proxy (CVE-2026-42501)

A flaw was found in the Go command (`cmd/go`). A malicious module proxy can exploit this vulnerability by bypassing the validation of module checksums. This allows the proxy to serve altered versions of the Go toolchain, which the `go` com…

▾ SunlitRed Hat · Red Hat Enterprise Linux AppStream (v. 8)EPSS 0.29%via CSAF
CVE-2026-39823Medium· 5.4
4mo ago

html/template: golang: Go html/template: Cross-Site Scripting via improper URL escaping in meta tag content (CVE-2026-39823)

A flaw was found in the `html/template` package of Go. A remote attacker could exploit this vulnerability by inserting ASCII whitespaces around the equals sign (`=`) within a URL's content attribute inside a `<meta>` tag. This improper esc…

▾ SunlitRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.33%via CSAF
CVE-2026-39826Medium· 5.4
4mo ago

html/template: golang: html/template: Cross-site scripting due to incorrect script tag escaping (CVE-2026-39826)

A flaw was found in html/template. A trusted template author could craft a script tag with an empty or whitespace-only 'type' attribute. This vulnerability causes the template engine to incorrectly escape data passed into the script block,…

▾ SunlitRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.39%via CSAF
CVE-2026-39817Medium· 5.9
4mo ago

Invoking "go tool pack" does not sanitize output paths in cmd/go

Invoking "go tool pack" does not sanitize output paths in cmd/go

▾ Sunlittoolchain · toolchainEPSS 0.16%via OSV
CVE-2026-39819Medium· 4.4
4mo ago

Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go

Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go

▾ Sunlittoolchain · toolchainEPSS 0.15%via OSV
CVE-2026-39825Medium· 6.5
4mo ago

net/http/httputil: golang: net/http/httputil: ReverseProxy forwards hidden query parameters, potentially bypassing security controls (CVE-2…

A flaw was found in the `net/http/httputil` package, specifically within the `ReverseProxy` component. This vulnerability allows the `ReverseProxy` to forward query parameters that are not visible to `Rewrite` functions. This occurs becaus…

▾ SunlitRed Hat · Red Hat OpenShift Container Platform 4.22EPSS 0.41%via CSAF
CVE-2026-42592Medium· 5.3
4mo ago

Gotenberg's DNS rebinding bypasses SSRF validation on Chromium URL conversion routes

Gotenberg's DNS rebinding bypasses SSRF validation on Chromium URL conversion routes

▾ Sunlitgotenberg · github.com/gotenberg/gotenberg/v8EPSS 0.25%via OSV
CVE-2026-39836High· 7.5
4mo ago

net: golang: Go net package: Denial of Service via NUL byte in Dial and LookupPort on Windows (CVE-2026-39836)

A flaw was found in the `net` package of Go (golang). When running on Windows, the `Dial` and `LookupPort` functions can panic if they receive an input containing a NUL (0) byte. This can be triggered by a remote attacker providing a speci…

▾ TwilightRed Hat · Red Hat Enterprise Linux AppStream (v. 8)EPSS 0.62%via CSAF
CVE-2026-42328Medium· 6.2
4mo ago

go-ipld-prime's DAG-CBOR and DAG-JSON decoders have unbounded recursion depth

go-ipld-prime's DAG-CBOR and DAG-JSON decoders have unbounded recursion depth

▾ Sunlitipld · github.com/ipld/go-ipld-primeEPSS 0.16%via OSV
CVE-2026-42285High· 7.5
4mo ago

github.com/osrg/gobgp: GoBGP: Denial of Service due to specially crafted BGP UPDATE message (CVE-2026-42285)

A flaw was found in GoBGP 4.4.0. A crafted BGP UPDATE with inconsistent attribute lengths mishandles the withdraw state transition in AdjRib.Update, causing a nil pointer dereference and full process crash. Fixed in GoBGP 4.5.0.

▾ TwilightRed Hat · github.com/osrg/gobgp/v4EPSS 0.60%via CSAF
CVE-2026-41642High· 7.5
4mo ago

github.com/osrg/gobgp: GoBGP: Denial of Service via malformed BGP UPDATE message (CVE-2026-41642)

A flaw was found in GoBGP 4.3.0. A malformed BGP UPDATE with an unrecognized Path Attribute marked as well-known is not rejected cleanly, triggering a nil pointer dereference that crashes the GoBGP daemon. Fixed in GoBGP 4.4.0.

▾ TwilightRed Hat · github.com/osrg/gobgp/v4EPSS 0.60%via CSAF
CVEs tagged “osv” — page 67 · VulnSea