Tagged “osv”
CVEs tagged osv, newest first.
5683 CVEsRSS
CVE-2026-35397High· 8.8PoCJupyter Server is the backend for Jupyter web applications
Jupyter Server is the backend for Jupyter web applications. In versions 2.17.0 and earlier, a path traversal vulnerability in the REST API allows an authenticated user to escape the configured root_dir and access sibling directories whos…
GHSA-h5fq-653g-gxrmMedium· 5.3ots has a negative expire override that can bypass its secret retention policy
ots has a negative expire override that can bypass its secret retention policy
CVE-2026-7776High· 7.5Hashicorp Boundary workers are vulnerable to a denial-of-service condition during node enrollment TLS handshakes
Hashicorp Boundary workers are vulnerable to a denial-of-service condition during node enrollment TLS handshakes
CVE-2026-42220Medium· 6.5Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and r…
Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback
CVE-2026-44219Low· 3.7ciguard: SCA HTTP client reads response body without size cap
ciguard: SCA HTTP client reads response body without size cap
CVE-2026-7846Low· 2.6Langchain-Chatchat has a Race Condition in its OpenAI-Compatible File Upload API
Langchain-Chatchat has a Race Condition in its OpenAI-Compatible File Upload API
CVE-2026-7845Low· 2.6Langchain-Chatchat Uses a Broken or Risky Cryptographic Algorithm
Langchain-Chatchat Uses a Broken or Risky Cryptographic Algorithm
CVE-2026-43002Medium· 5.3An issue was discovered in OpenStack Horizon 25.6 and 25.7 before 25.7.3
An issue was discovered in OpenStack Horizon 25.6 and 25.7 before 25.7.3. There is a write operation to the session storage backend before authentication and thus storage can be exhausted by unauthenticated requests. This is a regression…
CVE-2026-42175Medium· 6.5requests-hardened is Vulnerable to Server-Side Request Forgery
requests-hardened is Vulnerable to Server-Side Request Forgery
CVE-2026-42303MediumEthyca Fides has a Privacy Request Identity Verification Bypass Vulnerability via Duplicate Detection
Ethyca Fides has a Privacy Request Identity Verification Bypass Vulnerability via Duplicate Detection
CVE-2026-42080Medium· 4.6PPTAgent: Arbitrary File Write via `save_generated_slides`
PPTAgent: Arbitrary File Write via `save_generated_slides`
CVE-2026-40864Medium· 5.4PoCJupyterHub has cross-origin form POSTs bypass XSRF (CWE-352)
JupyterHub has cross-origin form POSTs bypass XSRF (CWE-352)
CVE-2026-7847Low· 2.6Langchain-Chatchat Uses Insufficiently Random Values
Langchain-Chatchat Uses Insufficiently Random Values
CVE-2026-44218Low· 3.0ciguard: Container image runs as root (no USER directive)
ciguard: Container image runs as root (no USER directive)
CVE-2026-42078Medium· 4.6PPTAgent: Arbitrary File Write + Directory Creation via markdown_table_to_image
PPTAgent: Arbitrary File Write + Directory Creation via markdown_table_to_image
CVE-2026-44222Medium· 6.5vLLM Vulnerable to Remote DoS via Special-Token Placeholders
vLLM Vulnerable to Remote DoS via Special-Token Placeholders
CVE-2026-44220None· 0.0ciguard: discover_pipeline_files follows symlinks out of scan root
ciguard: discover_pipeline_files follows symlinks out of scan root
CVE-2026-42079High· 8.6PPTAgent: Arbitrary Code Execution via Python eval() of LLM-Generated Code with Builtins in Scope
PPTAgent: Arbitrary Code Execution via Python eval() of LLM-Generated Code with Builtins in Scope
CVE-2026-42874Low· 3.7Microdot has HTTP response splitting in Response.set_cookie()
Microdot has HTTP response splitting in Response.set_cookie()
CVE-2026-43901Medium· 6.8wireshark-mcp vulnerable to arbitrary file write via export_objects when WIRESHARK_MCP_ALLOWED_DIRS is not configured
wireshark-mcp vulnerable to arbitrary file write via export_objects when WIRESHARK_MCP_ALLOWED_DIRS is not configured
CVE-2026-40110HighJupyter Server has a CORS Origin Validation Bypass via `re.match()` in `allow_origin_pat`
Jupyter Server has a CORS Origin Validation Bypass via `re.match()` in `allow_origin_pat`
CVE-2026-43891High· 7.5changedetection.io has an Arbitrary Local File Read via a crafted backup restore
changedetection.io has an Arbitrary Local File Read via a crafted backup restore
CVE-2026-42997High· 7.7An issue was discovered in idrac in OpenStack Ironic before 35.0.1
An issue was discovered in idrac in OpenStack Ironic before 35.0.1. During import, a user invoking molds can request authorization to be sent to a remote endpoint. The credential forwarded is a time-limited Keystone token (which provides…
CVE-2026-43868Medium· 5.3Memory Allocation with Excessive Size Value vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.
Memory Allocation with Excessive Size Value vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.
CVE-2026-41181MediumTraefik's errors middleware forwards Authorization and Cookie headers to separate error page service
Traefik's errors middleware forwards Authorization and Cookie headers to separate error page service
CVE-2026-7482Critical· 9.1PoCOllama contains a heap out-of-bounds read vulnerability in the GGUF model loader
Ollama contains a heap out-of-bounds read vulnerability in the GGUF model loader
CVE-2026-42294High· 7.5Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor
Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor
CVE-2026-42295HighArgo vulnerable to exposure of artifact repository credentials
Argo vulnerable to exposure of artifact repository credentials
CVE-2026-42088High· 8.1OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version …
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version 7.0.0-rc3, the Script Runner widget allows users to execute Python and Ruby scripts directly from th…
CVE-2026-42087Critical· 9.6OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. From version 6.7.…
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. From version 6.7.0 to before version 7.0.0-rc3, a SQL injection vulnerability exists in the Time-Series Database (TSD…