Tagged “osv”
CVEs tagged osv, newest first.
5681 CVEsRSS
CVE-2026-40171High· 8.8Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS
Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS
CVE-2025-13030High· 7.1django-mdeditor is Missing Authentication for Critical Function
django-mdeditor is Missing Authentication for Critical Function
CVE-2026-41654MediumWeblate Vulnerable to Authenticated SSRF via Project Backup Import bypassing validate_repo_url
Weblate Vulnerable to Authenticated SSRF via Project Backup Import bypassing validate_repo_url
CVE-2026-42032MediumCKAN has Unauthenticated Authorization Bypass in `datastore_search_sql`
CKAN has Unauthenticated Authorization Bypass in `datastore_search_sql`
CVE-2026-41519Medium· 4.2Weblate Doesn't Invalidate API Token on Password Change
Weblate Doesn't Invalidate API Token on Password Change
CVE-2026-42254HighHickory DNS's Record Cache Accepts AUTHORITY-Section NS from Sibling Zone via Parent-Pool Zone-Context Elevation
Hickory DNS's Record Cache Accepts AUTHORITY-Section NS from Sibling Zone via Parent-Pool Zone-Context Elevation
CVE-2026-40280Critical· 9.3PoCGotenberg has case-insensitive URL scheme that bypasses webhook and downloadFrom deny-list SSRF protection
Gotenberg has case-insensitive URL scheme that bypasses webhook and downloadFrom deny-list SSRF protection
CVE-2026-41643High· 7.5GoBGP has Remote Denial of Service (Panic) in UpdatePathAttrs4ByteAs via Malformed BGP UPDATE
GoBGP has Remote Denial of Service (Panic) in UpdatePathAttrs4ByteAs via Malformed BGP UPDATE
CVE-2026-41132MediumCKAN has no certificate validation on STMP connection
CKAN has no certificate validation on STMP connection
CVE-2026-41255Medium· 6.1CKAN has CSRF exemption primed by anonymous requests
CKAN has CSRF exemption primed by anonymous requests
CVE-2026-42352High· 8.6pygeoapi 0.23.x: Unauthenticated SSRF via OGC API - Processes Subscriber
pygeoapi 0.23.x: Unauthenticated SSRF via OGC API - Processes Subscriber
CVE-2026-42031HighPoCCKAN has Unauthenticated SQL Injection and Authorization Bypass in `datastore_search_sql`
CKAN has Unauthenticated SQL Injection and Authorization Bypass in `datastore_search_sql`
CVE-2026-42351High· 7.5pygeoapi 0.23.x: Path Traversal in STAC FileSystemProvider
pygeoapi 0.23.x: Path Traversal in STAC FileSystemProvider
CVE-2026-7404High· 7.3mcpo-simple-server has a Path Traversal issue
mcpo-simple-server has a Path Traversal issue
CVE-2026-32936High· 7.5CoreDNS DoH GET oversized dns= query parameter causes pre-validation CPU and memory amplification
CoreDNS DoH GET oversized dns= query parameter causes pre-validation CPU and memory amplification
CVE-2026-32934High· 7.5CoreDNS' DoQ worker pool does not bound stream backlog
CoreDNS' DoQ worker pool does not bound stream backlog
CVE-2026-30246Medium· 6.5Fiber's cache middleware default key generator ignores query string, causing response mix-up across distinct query parameters
Fiber's cache middleware default key generator ignores query string, causing response mix-up across distinct query parameters
MAL-2026-3129NoneMalicious code in supertag (crates.io)
Malicious code in supertag (crates.io)
MAL-2026-3126NoneMalicious code in lsh (crates.io)
Malicious code in lsh (crates.io)
CVE-2026-7159High· 7.3mkdocs-mcp-plugin has a Path Traversal issue
mkdocs-mcp-plugin has a Path Traversal issue
CVE-2026-7212High· 7.3notes-mcp has a Path Traversal issue
notes-mcp has a Path Traversal issue
CVE-2026-7206High· 7.3sqlite-mcp has an Injection issue
sqlite-mcp has an Injection issue
CVE-2026-42510Medium· 6.6OpenStack Ironic is Vulnerable to Inclusion of Functionality from Untrusted Control Sphere
OpenStack Ironic is Vulnerable to Inclusion of Functionality from Untrusted Control Sphere
MAL-2026-3103NoneMalicious code in amzn_codewhisperer_streaming_client (crates.io)
Malicious code in amzn_codewhisperer_streaming_client (crates.io)
MAL-2026-3102NoneMalicious code in semantic_search_client (crates.io)
Malicious code in semantic_search_client (crates.io)
MAL-2026-3101NoneMalicious code in amzn_consolas_client (crates.io)
Malicious code in amzn_consolas_client (crates.io)
CVE-2026-7141Medium· 5.6vLLM makes Use of Uninitialized Resource
vLLM makes Use of Uninitialized Resource
CVE-2026-7142Medium· 6.3Wooey has an Incorrect Privilege Assignment issue
Wooey has an Incorrect Privilege Assignment issue
CVE-2026-7150Medium· 6.3auto-favicon has a Server-Side Request Forgery issue
auto-favicon has a Server-Side Request Forgery issue
CVE-2026-7149High· 7.3kaggle-mcp has a Path Traversal issue
kaggle-mcp has a Path Traversal issue