VulnSea

Tagged “osv”

CVEs tagged osv, newest first.

5681 CVEsRSS

CVE-2026-6357Medium· 5.8
5mo ago

pip: pip: Arbitrary code execution or information disclosure via malicious wheel package installation (CVE-2026-6357)

A flaw was found in pip. Prior to version 26.1, pip's self-update check functionality would execute after installing wheel packages. This process involved importing newly installed Python modules. A malicious actor could craft a specially …

▾ SunlitRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.17%via CSAF
CVE-2026-7158High· 7.3
5mo ago

mcp-url-downloader has a Server-Side Request Forgery issue

mcp-url-downloader has a Server-Side Request Forgery issue

▾ Twilightmcp-url-downloader · mcp-url-downloaderEPSS 0.47%via OSV
CVE-2026-7020Medium· 5.6PoC
5mo ago

Ollama is Vulnerable to Path Traversal

Ollama is Vulnerable to Path Traversal

▾ Twilightollama · github.com/ollama/ollamaEPSS 0.90%via OSV
CVE-2026-6993Medium· 5.3
5mo ago

go-kratos: go-kratos kratos: Information disclosure via unintended HTTP server intermediary (CVE-2026-6993)

A flaw was found in go-kratos kratos. A remote attacker could exploit a vulnerability in the HTTP server's `NewServer` function, specifically within the `http.DefaultServeMux Fallback Handler`. This manipulation creates an unintended inter…

▾ SunlitRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.54%via CSAF
CVE-2026-6984Medium· 4.7
5mo ago

AstrBot has Incomplete Filtering of Special Elements

AstrBot has Incomplete Filtering of Special Elements

▾ Sunlitastrbot · astrbotEPSS 0.41%via OSV
CVE-2026-41327Critical· 9.1
5mo ago

Dgraph: Pre-Auth Full Database Exfiltration via DQL Injection in Upsert Condition Field

Dgraph: Pre-Auth Full Database Exfiltration via DQL Injection in Upsert Condition Field

▾ Midnightdgraph-io · github.com/dgraph-io/dgraph/v25EPSS 0.47%via OSV
CVE-2026-41492Critical· 9.8PoC
5mo ago

Dgraph: Unauthenticated Admin Token Disclosure Leading to Authentication Bypass via /debug/vars

Dgraph: Unauthenticated Admin Token Disclosure Leading to Authentication Bypass via /debug/vars

▾ Abyssaldgraph-io · github.com/dgraph-io/dgraph/v25EPSS 2.5%via OSV
CVE-2026-40912High· 8.2
5mo ago

Traefik has an StripPrefixRegex Middleware Authorization Bypass via Path/RawPath Desync

Traefik has an StripPrefixRegex Middleware Authorization Bypass via Path/RawPath Desync

▾ Twilighttraefik · github.com/traefik/traefik/v3EPSS 0.72%via OSV
CVE-2026-42203HighPoC
5mo ago

LiteLLM: Server-Side Template Injection in /prompts/test endpoint

LiteLLM: Server-Side Template Injection in /prompts/test endpoint

▾ Midnightlitellm · litellmEPSS 0.66%via OSV
CVE-2026-40690Medium· 4.3
5mo ago

Apache Airflow's asset dependency graph did not restrict nodes by the viewer's DAG read permissions

Apache Airflow's asset dependency graph did not restrict nodes by the viewer's DAG read permissions

▾ Sunlitapache-airflow · apache-airflowEPSS 0.57%via OSV
CVE-2026-6550Medium· 4.7
5mo ago

AWS Encryption SDK for Python: Key commitment policy bypass via shared key cache

AWS Encryption SDK for Python: Key commitment policy bypass via shared key cache

▾ Sunlitaws-encryption-sdk · aws-encryption-sdkEPSS 0.10%via OSV
CVE-2026-38743Medium· 4.3
5mo ago

Apache Airflow's authenticated /ui/dags endpoint did not enforce per-DAG access control on embedded Human-in-the-Loop (HITL) and TaskInst…

Apache Airflow's authenticated /ui/dags endpoint did not enforce per-DAG access control on embedded Human-in-the-Loop (HITL) and TaskInstance record

▾ Sunlitapache-airflow · apache-airflowEPSS 0.57%via OSV
CVE-2026-41486High
5mo ago

Ray: Remote Code Execution via Parquet Arrow Extension Type Deserialization

Ray: Remote Code Execution via Parquet Arrow Extension Type Deserialization

▾ Twilightray · rayEPSS 0.70%via OSV
CVE-2026-42150Medium· 5.1
5mo ago

wlc: print_html outputs API data without HTML escaping

wlc: print_html outputs API data without HTML escaping

▾ Sunlitwlc · wlcEPSS 0.30%via OSV
CVE-2026-41140High· 8.7
5mo ago

poetry: Poetry: Path traversal vulnerability allows arbitrary file write via malicious package extraction (CVE-2026-41140)

A flaw was found in Poetry, a dependency manager for Python. This vulnerability allows a remote attacker to perform a path traversal attack. By crafting a malicious software package, the `extractall()` function in Poetry can be tricked int…

▾ TwilightRed Hat · Red Hat Ansible Automation Platform 2.6EPSS 0.47%via CSAF
CVE-2026-41328Critical· 9.1
5mo ago

Dgraph: Pre-Auth Full Database Exfiltration via DQL Injection in NQuad Lang Field

Dgraph: Pre-Auth Full Database Exfiltration via DQL Injection in NQuad Lang Field

▾ Midnightdgraph-io · github.com/dgraph-io/dgraph/v25EPSS 0.48%via OSV
CVE-2026-40886High· 7.7
5mo ago

Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows Controller

Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows Controller

▾ Twilightargoproj · github.com/argoproj/argo-workflows/v4EPSS 0.59%via OSV
CVE-2026-32952Medium· 5.3
5mo ago

go-ntlmssp NTLM challenges can panic on malformed payloads

go-ntlmssp NTLM challenges can panic on malformed payloads

▾ SunlitAzure · github.com/Azure/go-ntlmsspEPSS 1.5%via OSV
CVE-2026-3960Critical· 9.8
5mo ago

A critical remote code execution vulnerability exists in the unauthenticated REST API endpoint /99/ImportSQLTable in H2O-3 version 3.46.0…

A critical remote code execution vulnerability exists in the unauthenticated REST API endpoint /99/ImportSQLTable in H2O-3 version 3.46.0.9 and prior. The vulnerability arises due to insufficient security controls in the parameter blackl…

▾ Midnighth2o · h2oEPSS 1.0%via OSV
CVE-2026-6878Medium· 5.6
5mo ago

verl's math_equal() Vulnerable to Arbitrary Code Execution via Unsafe eval()

verl's math_equal() Vulnerable to Arbitrary Code Execution via Unsafe eval()

▾ Sunlitverl · verlEPSS 0.42%via OSV
CVE-2026-6827Medium
5mo ago

justhtml has sanitization bypass in custom policies and programmatic DOM

justhtml has sanitization bypass in custom policies and programmatic DOM

▾ Sunlitjusthtml · justhtmlEPSS 0.26%via OSV
CVE-2026-41179Critical· 9.8PoC
5mo ago

RClone: Unauthenticated operations/fsinfo allows attacker-controlled backend instantiation and local command execution

RClone: Unauthenticated operations/fsinfo allows attacker-controlled backend instantiation and local command execution

▾ Abyssalrclone · github.com/rclone/rcloneEPSS 5.3%via OSV
RUSTSEC-2026-0207None
5mo ago

Incorrect Output of Incremental Portable SHAKE API on Multiple Squeeze Calls

Incorrect Output of Incremental Portable SHAKE API on Multiple Squeeze Calls

▾ Sunlitlibcrux-sha3 · libcrux-sha3via OSV
RUSTSEC-2026-0104None
5mo ago

Reachable panic in certificate revocation list parsing

Reachable panic in certificate revocation list parsing

▾ Sunlitrustls-webpki · rustls-webpkivia OSV
CVE-2026-6859High· 8.8
5mo ago

InstructLab Includes Functionality from Untrusted Control Sphere

InstructLab Includes Functionality from Untrusted Control Sphere

▾ Twilightinstructlab · instructlabEPSS 0.77%via OSV
CVE-2026-41131Medium· 5.0
5mo ago

OpenFGA has Improper Policy Enforcement

OpenFGA has Improper Policy Enforcement

▾ Sunlitopenfga · github.com/openfga/openfgaEPSS 0.23%via OSV
CVE-2026-41282Medium· 5.3
5mo ago

Nuclei: Environment variable disclosure via Response-Derived DSL Expressions

Nuclei: Environment variable disclosure via Response-Derived DSL Expressions

▾ Sunlitprojectdiscovery · github.com/projectdiscovery/nuclei/v3EPSS 0.43%via OSV
CVE-2026-33812None
5mo ago

Excessive memory allocation when decoding malicious SFNT in golang.org/x/image

Excessive memory allocation when decoding malicious SFNT in golang.org/x/image

▾ Sunlitx · golang.org/x/imageEPSS 0.16%via OSV
CVE-2026-41066High· 7.5
5mo ago

lxml: Default configuration of iterparse() and ETCompatXMLParser() allows XXE to local files

lxml: Default configuration of iterparse() and ETCompatXMLParser() allows XXE to local files

▾ Twilightlxml · lxmlEPSS 0.41%via OSV
CVE-2026-39396Low· 3.1
5mo ago

OpenBao: Decompression Bomb via Unbounded Copy in OCI Plugin Extraction (DoS)

OpenBao: Decompression Bomb via Unbounded Copy in OCI Plugin Extraction (DoS)

▾ Sunlitopenbao · github.com/openbao/openbaoEPSS 0.33%via OSV
CVEs tagged “osv” — page 73 · VulnSea