Tagged “osv”
CVEs tagged osv, newest first.
5681 CVEsRSS
CVE-2026-6357Medium· 5.8pip: pip: Arbitrary code execution or information disclosure via malicious wheel package installation (CVE-2026-6357)
A flaw was found in pip. Prior to version 26.1, pip's self-update check functionality would execute after installing wheel packages. This process involved importing newly installed Python modules. A malicious actor could craft a specially …
CVE-2026-7158High· 7.3mcp-url-downloader has a Server-Side Request Forgery issue
mcp-url-downloader has a Server-Side Request Forgery issue
CVE-2026-7020Medium· 5.6PoCOllama is Vulnerable to Path Traversal
Ollama is Vulnerable to Path Traversal
CVE-2026-6993Medium· 5.3go-kratos: go-kratos kratos: Information disclosure via unintended HTTP server intermediary (CVE-2026-6993)
A flaw was found in go-kratos kratos. A remote attacker could exploit a vulnerability in the HTTP server's `NewServer` function, specifically within the `http.DefaultServeMux Fallback Handler`. This manipulation creates an unintended inter…
CVE-2026-6984Medium· 4.7AstrBot has Incomplete Filtering of Special Elements
AstrBot has Incomplete Filtering of Special Elements
CVE-2026-41327Critical· 9.1Dgraph: Pre-Auth Full Database Exfiltration via DQL Injection in Upsert Condition Field
Dgraph: Pre-Auth Full Database Exfiltration via DQL Injection in Upsert Condition Field
CVE-2026-41492Critical· 9.8PoCDgraph: Unauthenticated Admin Token Disclosure Leading to Authentication Bypass via /debug/vars
Dgraph: Unauthenticated Admin Token Disclosure Leading to Authentication Bypass via /debug/vars
CVE-2026-40912High· 8.2Traefik has an StripPrefixRegex Middleware Authorization Bypass via Path/RawPath Desync
Traefik has an StripPrefixRegex Middleware Authorization Bypass via Path/RawPath Desync
CVE-2026-42203HighPoCLiteLLM: Server-Side Template Injection in /prompts/test endpoint
LiteLLM: Server-Side Template Injection in /prompts/test endpoint
CVE-2026-40690Medium· 4.3Apache Airflow's asset dependency graph did not restrict nodes by the viewer's DAG read permissions
Apache Airflow's asset dependency graph did not restrict nodes by the viewer's DAG read permissions
CVE-2026-6550Medium· 4.7AWS Encryption SDK for Python: Key commitment policy bypass via shared key cache
AWS Encryption SDK for Python: Key commitment policy bypass via shared key cache
CVE-2026-38743Medium· 4.3Apache Airflow's authenticated /ui/dags endpoint did not enforce per-DAG access control on embedded Human-in-the-Loop (HITL) and TaskInst…
Apache Airflow's authenticated /ui/dags endpoint did not enforce per-DAG access control on embedded Human-in-the-Loop (HITL) and TaskInstance record
CVE-2026-41486HighRay: Remote Code Execution via Parquet Arrow Extension Type Deserialization
Ray: Remote Code Execution via Parquet Arrow Extension Type Deserialization
CVE-2026-42150Medium· 5.1wlc: print_html outputs API data without HTML escaping
wlc: print_html outputs API data without HTML escaping
CVE-2026-41140High· 8.7poetry: Poetry: Path traversal vulnerability allows arbitrary file write via malicious package extraction (CVE-2026-41140)
A flaw was found in Poetry, a dependency manager for Python. This vulnerability allows a remote attacker to perform a path traversal attack. By crafting a malicious software package, the `extractall()` function in Poetry can be tricked int…
CVE-2026-41328Critical· 9.1Dgraph: Pre-Auth Full Database Exfiltration via DQL Injection in NQuad Lang Field
Dgraph: Pre-Auth Full Database Exfiltration via DQL Injection in NQuad Lang Field
CVE-2026-40886High· 7.7Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows Controller
Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows Controller
CVE-2026-32952Medium· 5.3go-ntlmssp NTLM challenges can panic on malformed payloads
go-ntlmssp NTLM challenges can panic on malformed payloads
CVE-2026-3960Critical· 9.8A critical remote code execution vulnerability exists in the unauthenticated REST API endpoint /99/ImportSQLTable in H2O-3 version 3.46.0…
A critical remote code execution vulnerability exists in the unauthenticated REST API endpoint /99/ImportSQLTable in H2O-3 version 3.46.0.9 and prior. The vulnerability arises due to insufficient security controls in the parameter blackl…
CVE-2026-6878Medium· 5.6verl's math_equal() Vulnerable to Arbitrary Code Execution via Unsafe eval()
verl's math_equal() Vulnerable to Arbitrary Code Execution via Unsafe eval()
CVE-2026-6827Mediumjusthtml has sanitization bypass in custom policies and programmatic DOM
justhtml has sanitization bypass in custom policies and programmatic DOM
CVE-2026-41179Critical· 9.8PoCRClone: Unauthenticated operations/fsinfo allows attacker-controlled backend instantiation and local command execution
RClone: Unauthenticated operations/fsinfo allows attacker-controlled backend instantiation and local command execution
RUSTSEC-2026-0207NoneIncorrect Output of Incremental Portable SHAKE API on Multiple Squeeze Calls
Incorrect Output of Incremental Portable SHAKE API on Multiple Squeeze Calls
RUSTSEC-2026-0104NoneReachable panic in certificate revocation list parsing
Reachable panic in certificate revocation list parsing
CVE-2026-6859High· 8.8InstructLab Includes Functionality from Untrusted Control Sphere
InstructLab Includes Functionality from Untrusted Control Sphere
CVE-2026-41131Medium· 5.0OpenFGA has Improper Policy Enforcement
OpenFGA has Improper Policy Enforcement
CVE-2026-41282Medium· 5.3Nuclei: Environment variable disclosure via Response-Derived DSL Expressions
Nuclei: Environment variable disclosure via Response-Derived DSL Expressions
CVE-2026-33812NoneExcessive memory allocation when decoding malicious SFNT in golang.org/x/image
Excessive memory allocation when decoding malicious SFNT in golang.org/x/image
CVE-2026-41066High· 7.5lxml: Default configuration of iterparse() and ETCompatXMLParser() allows XXE to local files
lxml: Default configuration of iterparse() and ETCompatXMLParser() allows XXE to local files
CVE-2026-39396Low· 3.1OpenBao: Decompression Bomb via Unbounded Copy in OCI Plugin Extraction (DoS)
OpenBao: Decompression Bomb via Unbounded Copy in OCI Plugin Extraction (DoS)