Tagged “osv”
CVEs tagged osv, newest first.
5681 CVEsRSS
CVE-2026-42544High· 7.5Granian vulnerable to unauthenticated DoS via WebSocket subprotocol header panic
Granian vulnerable to unauthenticated DoS via WebSocket subprotocol header panic
CVE-2026-44305Medium· 6.8Lemur: LDAP Authentication Globally Disables TLS Certificate Verification When LDAP_USE_TLS Is Enabled
Lemur: LDAP Authentication Globally Disables TLS Certificate Verification When LDAP_USE_TLS Is Enabled
CVE-2026-44405Low· 3.4Paramiko rsakey.py allows the SHA-1 algorithm
Paramiko rsakey.py allows the SHA-1 algorithm
CVE-2026-44335Critical· 9.8PraisonAI has an SSRF bypass
PraisonAI has an SSRF bypass
CVE-2026-42561High· 7.5python-multipart has Denial of Service via unbounded multipart part headers
python-multipart has Denial of Service via unbounded multipart part headers
CVE-2026-42557Critical· 9.6JupyterLab's command linker attributes in HTML enable one-click command execution from untrusted content
JupyterLab's command linker attributes in HTML enable one-click command execution from untrusted content
CVE-2026-44363Mediummisp-modules has nsafe remote resource fetching in expansion
misp-modules has nsafe remote resource fetching in expansion
CVE-2026-42545Medium· 5.9Granian vulnerable to DoS via WSGI response header panic
Granian vulnerable to DoS via WSGI response header panic
CVE-2026-42448Low· 3.5Magic Wormhole: receive, with --output pointing at an existing directory can be path-traversed
Magic Wormhole: receive, with --output pointing at an existing directory can be path-traversed
CVE-2026-44226Medium· 5.3PyLoad vulnerable to unauthenticated traceback disclosure via global exception handler in WebUI
PyLoad vulnerable to unauthenticated traceback disclosure via global exception handler in WebUI
CVE-2026-44368Mediumpyquorum: Timing side‑channel in mul_mod
pyquorum: Timing side‑channel in mul_mod
CVE-2026-44243High· 7.1GitPython reference APIs has a path traversal vulnerability that allows arbitrary file write and delete outside the repository
GitPython reference APIs has a path traversal vulnerability that allows arbitrary file write and delete outside the repository
CVE-2026-44439High· 7.5Playwright Capture permits access to local files and internal network resources during page capture
Playwright Capture permits access to local files and internal network resources during page capture
CVE-2026-44304High· 8.1Lemur: LDAP Filter Injection enables post-authentication privilege escalation
Lemur: LDAP Filter Injection enables post-authentication privilege escalation
CVE-2026-44307HighMako vulnerable to path traversal via backslash URI on Windows in TemplateLookup
Mako vulnerable to path traversal via backslash URI on Windows in TemplateLookup
CVE-2025-71261High· 8.6Harvester's SUSE Virtualization Registration Client Vulnerable to MITM and DOS
Harvester's SUSE Virtualization Registration Client Vulnerable to MITM and DOS
CVE-2026-33079High· 7.5In versions 3.0.0a1 through 3.2.0 of Mistune, there is a ReDoS (Regular Expression Denial of Service) vulnerability in `LINK_TITLE_RE` that allows an attacker who can supply Markdown for parsing to cause denial of service
In versions 3.0.0a1 through 3.2.0 of Mistune, there is a ReDoS (Regular Expression Denial of Service) vulnerability in `LINK_TITLE_RE` that allows an attacker who can supply Markdown for parsing to cause denial of service. The regular ex…
CVE-2026-5766Medium· 5.3Django has an Improper Handling of Length Parameter Inconsistency
Django has an Improper Handling of Length Parameter Inconsistency
CVE-2025-61669MediumJupyter Server has an open redirection vulnerability in `next` query parameter
Jupyter Server has an open redirection vulnerability in `next` query parameter
CVE-2026-42304High· 7.5Twisted has a Denial of Service (DoS) in twisted.names via Crafted DNS Compression Pointer Chains
Twisted has a Denial of Service (DoS) in twisted.names via Crafted DNS Compression Pointer Chains
CVE-2026-40934Medium· 6.8Jupyter Server's Authentication Cookies Remain Valid After Password Reset and Server Restart
Jupyter Server's Authentication Cookies Remain Valid After Password Reset and Server Restart
CVE-2026-6907Medium· 4.3Django Uses Cache Containing Sensitive Information
Django Uses Cache Containing Sensitive Information
CVE-2026-82254Highgix-pack has multiple DoS vectors: unchecked indexing panics and uncapped OOM allocations from crafted pack data
gix-pack has multiple DoS vectors: unchecked indexing panics and uncapped OOM allocations from crafted pack data
CVE-2026-82252Highgix and gitoxide's symlinked .gitmodules are followed and parsed from outside of the repository
gix and gitoxide's symlinked .gitmodules are followed and parsed from outside of the repository
CVE-2026-82253Highgix's submodule name validation bypass + trust inheritance flaw enables path traversal and credential disclosure
gix's submodule name validation bypass + trust inheritance flaw enables path traversal and credential disclosure
CVE-2026-82251Highgix and gitoxide: unvalidated submodule name traverses out of .git/modules and redirects state() / open() to another repository
gix and gitoxide: unvalidated submodule name traverses out of .git/modules and redirects state() / open() to another repository
CVE-2026-40034High· 7.8gitoxide: CommandForbiddenInModulesConfiguration Bypass in gix_submodule::File::update() Enables Arbitrary Command Execution via .gitmodules
gitoxide: CommandForbiddenInModulesConfiguration Bypass in gix_submodule::File::update() Enables Arbitrary Command Execution via .gitmodules
CVE-2026-42186LowOpenBao's Namespace Deletion May Not Delete Data Properly
OpenBao's Namespace Deletion May Not Delete Data Properly
CVE-2026-42554MediumFiber vulnerable to XSS in AutoFormat Content Negotiation
Fiber vulnerable to XSS in AutoFormat Content Negotiation
CVE-2026-44166MediumPoCPocketBase vulnerable to account pre-hijacking via OAuth2 unverfied->verified autolinking upgrade
PocketBase vulnerable to account pre-hijacking via OAuth2 unverfied->verified autolinking upgrade