VulnSea

Tagged “osv”

CVEs tagged osv, newest first.

5681 CVEsRSS

CVE-2026-42597Medium· 5.9
4mo ago

Gotenberg allows Chromium URL conversion routes to read arbitrary files under /tmp via file:// scheme

Gotenberg allows Chromium URL conversion routes to read arbitrary files under /tmp via file:// scheme

▾ Sunlitgotenberg · github.com/gotenberg/gotenberg/v8EPSS 0.36%via OSV
GHSA-fpw6-hrg5-q5x5High· 7.4
4mo ago

ech0's acess tokens with expiry=never cannot be revoked: logout panics, delete does not blacklist JTI

ech0's acess tokens with expiry=never cannot be revoked: logout panics, delete does not blacklist JTI

▾ Twilightlin-snow · github.com/lin-snow/ech0via OSV
CVE-2026-42590High· 8.2
4mo ago

Gotenberg's ExifTool group-prefix syntax bypasses dangerous-tag blocklist

Gotenberg's ExifTool group-prefix syntax bypasses dangerous-tag blocklist

▾ Twilightgotenberg · github.com/gotenberg/gotenberg/v8EPSS 0.44%via OSV
CVE-2026-8086High· 7.8
4mo ago

A vulnerability was identified in OSGeo gdal up to 3.13.0dev-4. This issue affects the function SWnentries of the file frmts/hdf4/hdf-eos…

A vulnerability was identified in OSGeo gdal up to 3.13.0dev-4. This issue affects the function SWnentries of the file frmts/hdf4/hdf-eos/SWapi.c. Such manipulation of the argument DimensionName leads to heap-based buffer overflow. The a…

▾ Twilightgdal · gdalEPSS 0.27%via OSV
CVE-2026-8084Medium· 5.5
4mo ago

A vulnerability was determined in OSGeo gdal up to 3.13.0dev-4. This vulnerability affects the function memmove of the file frmts/hdf4/hd…

A vulnerability was determined in OSGeo gdal up to 3.13.0dev-4. This vulnerability affects the function memmove of the file frmts/hdf4/hdf-eos/SWapi.c of the component HDF-EOS Grid File Handler. This manipulation causes out-of-bounds rea…

▾ Sunlitgdal · gdalEPSS 0.22%via OSV
CVE-2026-44641High· 7.1
4mo ago

Microsoft APM CLI's plugin.json component paths escape plugin root and copy arbitrary host files during install

Microsoft APM CLI's plugin.json component paths escape plugin root and copy arbitrary host files during install

▾ Twilightapm-cli · apm-cliEPSS 0.53%via OSV
CVE-2026-42284High· 7.5
4mo ago

GitPython: GitPython: Arbitrary code execution via improper validation of clone options (CVE-2026-42284)

A flaw was found in GitPython, a Python library for interacting with Git repositories. A remote attacker could exploit an input validation vulnerability in the `_clone()` function. By crafting a malicious string in the `multi_options` para…

▾ TwilightRed Hat · Red Hat OpenShift AI 3.4EPSS 0.71%via CSAF
CVE-2026-44244High· 7.3
4mo ago

GitPython: GitPython: Arbitrary code execution via injected newlines in Git configuration (CVE-2026-44244)

A flaw was found in GitPython, a Python library used to interact with Git repositories. The `GitConfigParser.set_value()` function does not properly validate input for newlines. This vulnerability allows an attacker to inject malicious con…

▾ TwilightRed Hat · Red Hat OpenShift AI 3.4EPSS 0.22%via CSAF
CVE-2026-42215High· 7.5
4mo ago

GitPython: GitPython: Arbitrary command execution due to bypass of dangerous Git option checks (CVE-2026-42215)

A flaw was found in GitPython, a Python library used to interact with Git repositories. This vulnerability allows an attacker to achieve arbitrary command execution by providing specially crafted arguments (kwargs) to functions such as Rep…

▾ TwilightRed Hat · Red Hat OpenShift AI 3.4EPSS 0.90%via CSAF
CVE-2026-44742High· 7.2
4mo ago

Postorius is vulnerable to XSS

Postorius is vulnerable to XSS

▾ Twilightpostorius · postoriusEPSS 0.33%via OSV
CVE-2026-40610Medium· 5.5
4mo ago

BentoML has Information Disclosure in `bentoml build` via symlink traversal in the build context

BentoML has Information Disclosure in `bentoml build` via symlink traversal in the build context

▾ Sunlitbentoml · bentomlEPSS 0.20%via OSV
CVE-2026-44504High
4mo ago

Aegra has cross-user run injection in /threads/{thread_id}/runs (IDOR)

Aegra has cross-user run injection in /threads/{thread_id}/runs (IDOR)

▾ Twilightaegra-api · aegra-apiEPSS 0.35%via OSV
CVE-2026-8088Low· 3.3
4mo ago

OSGeo GDAL vulnerable to out-of-bounds read

OSGeo GDAL vulnerable to out-of-bounds read

▾ Sunlitgdal · gdalEPSS 0.21%via OSV
CVE-2026-8087Medium· 5.3
4mo ago

OSGeo GDAL vulnerable to heap-based buffer overflow

OSGeo GDAL vulnerable to heap-based buffer overflow

▾ Sunlitgdal · gdalEPSS 0.26%via OSV
CVE-2026-44263Medium· 4.3
4mo ago

Weblate Vulnerable to Private Translation Enumeration via Screenshot API

Weblate Vulnerable to Private Translation Enumeration via Screenshot API

▾ Sunlitweblate · weblateEPSS 0.38%via OSV
CVE-2026-44520Medium· 5.7
4mo ago

docling-graph has SSRF via Missing Internal IP Validation in URLInputHandler

docling-graph has SSRF via Missing Internal IP Validation in URLInputHandler

▾ Sunlitdocling-graph · docling-graphEPSS 0.31%via OSV
CVE-2026-44503High
4mo ago

Kiota abstractions RedirectHandler leaks Cookie/Proxy-Authorization headers on cross-host redirect

Kiota abstractions RedirectHandler leaks Cookie/Proxy-Authorization headers on cross-host redirect

▾ Twilightmicrosoft · com.microsoft.kiota:microsoft-kiota-abstractionsEPSS 0.84%via OSV
CVE-2026-44264Medium· 4.3
4mo ago

Weblate vulnerable to XSS via crafted Markdown

Weblate vulnerable to XSS via crafted Markdown

▾ Sunlitweblate · weblateEPSS 0.37%via OSV
CVE-2026-44661Medium· 4.7
4mo ago

utcp-http vulnerable to SSRF via attacker-controlled OpenAPI servers[0].url in HTTP communication protocol

utcp-http vulnerable to SSRF via attacker-controlled OpenAPI servers[0].url in HTTP communication protocol

▾ Sunlitutcp-http · utcp-httpEPSS 0.20%via OSV
CVE-2026-7461High· 7.2
4mo ago

Amazon ECS Container Agent (Windows) is vulnerable to Information Disclosure

Amazon ECS Container Agent (Windows) is vulnerable to Information Disclosure

▾ Twilightaws · github.com/aws/amazon-ecs-agentEPSS 0.81%via OSV
CVE-2026-42880Critical· 9.6PoC
4mo ago

ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction

ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction

▾ Abyssalargoproj · github.com/argoproj/argo-cd/v3EPSS 0.56%via OSV
MAL-2026-3370None
4mo ago

Malicious code in sufiagent (PyPI)

Malicious code in sufiagent (PyPI)

▾ Sunlitsufiagent · sufiagentvia OSV
CVE-2026-33814High· 7.5
4mo ago

When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it receives a SETTINGS_MAX_FRAME_SIZE with a value of 0.

When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it receives a SETTINGS_MAX_FRAME_SIZE with a value of 0.

▾ Twilightgolang · goEPSS 0.78%via NVD
CVE-2026-42499High· 7.5
4mo ago

Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322.

Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322.

▾ Twilightgolang · goEPSS 0.80%via NVD
CVE-2026-39820High· 7.5
4mo ago

Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion and memory allocations.

Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion and memory allocations.

▾ Twilightgolang · goEPSS 0.87%via NVD
CVE-2026-33811High· 7.5
4mo ago

When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a crash.

When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a crash.

▾ Twilightgolang · goEPSS 0.81%via NVD
GHSA-qcxq-75wr-5cm8High
4mo ago

ldap3_proto has LDAP Filter stack exhaustion

ldap3_proto has LDAP Filter stack exhaustion

▾ Twilightldap3_proto · ldap3_protovia OSV
CVE-2026-44301Medium
4mo ago

Hugo's Node tool execution allows file system access outside the project directory

Hugo's Node tool execution allows file system access outside the project directory

▾ Sunlitgohugoio · github.com/gohugoio/hugoEPSS 0.43%via OSV
CVE-2026-44423Medium· 6.5
4mo ago

ShellHub has cross-tenant IDOR in `GET /api/sessions/:uid` that discloses SSH session data

ShellHub has cross-tenant IDOR in `GET /api/sessions/:uid` that discloses SSH session data

▾ Sunlitshellhub-io · github.com/shellhub-io/shellhubEPSS 0.35%via OSV
CVE-2026-44334High· 8.4
4mo ago

PraisonAI has unauthenticated RCE via `tool_override.py` (CVE-2026-40287 patch bypass)

PraisonAI has unauthenticated RCE via `tool_override.py` (CVE-2026-40287 patch bypass)

▾ Twilightpraisonai · praisonaiEPSS 0.23%via OSV
CVEs tagged “osv” — page 68 · VulnSea