Tagged “osv”
CVEs tagged osv, newest first.
5681 CVEsRSS
CVE-2026-40256Medium· 5.0Weblate: Prefix-Based Repository Boundary Check Bypass via Symlink/Junction Path Prefix Collision
Weblate: Prefix-Based Repository Boundary Check Bypass via Symlink/Junction Path Prefix Collision
CVE-2026-41312Medium· 6.5pypdf: Manipulated FlateDecode predictor parameters can exhaust RAM
pypdf: Manipulated FlateDecode predictor parameters can exhaust RAM
CVE-2026-40353Medium· 5.4wger has Stored XSS via Unescaped License Attribution Fields
wger has Stored XSS via Unescaped License Attribution Fields
CVE-2026-33440Medium· 5.0Weblate: Authenticated SSRF via redirect bypass of ALLOWED_ASSET_DOMAINS in screenshot URL uploads
Weblate: Authenticated SSRF via redirect bypass of ALLOWED_ASSET_DOMAINS in screenshot URL uploads
CVE-2026-41313Medium· 6.5pypdf: Possible long runtimes for wrong size values in incremental mode
pypdf: Possible long runtimes for wrong size values in incremental mode
CVE-2026-40602Medium· 5.6Home Assistant Command-line Interface: Handling of user-supplied Jinja2 templates
Home Assistant Command-line Interface: Handling of user-supplied Jinja2 templates
CVE-2024-53412High· 8.4NietThijmen ShoppingCart: Command injection in the connect function
NietThijmen ShoppingCart: Command injection in the connect function
CVE-2026-40574Medium· 6.8OAuth2 Proxy has an Authorization Bypass in Email Domain Validation via Malformed Multi-@ Email Claims
OAuth2 Proxy has an Authorization Bypass in Email Domain Validation via Malformed Multi-@ Email Claims
CVE-2026-40575Critical· 9.1OAuth2 Proxy has an Authentication Bypass via X-Forwarded-Uri Header Spoofing
OAuth2 Proxy has an Authentication Bypass via X-Forwarded-Uri Header Spoofing
CVE-2026-6855High· 7.1instructlab: InstructLab: Path traversal allows arbitrary directory creation and file write (CVE-2026-6855)
A flaw was found in InstructLab. A local attacker could exploit a path traversal vulnerability in the chat session handler by manipulating the `logs_dir` parameter. This allows the attacker to create new directories and write files to arbi…
CVE-2026-40347Medium· 5.3python-multipart affected by Denial of Service via large multipart preamble or epilogue data
python-multipart affected by Denial of Service via large multipart preamble or epilogue data
CVE-2026-41168Medium· 5.3pypdf has long runtimes for wrong size values in cross-reference and object streams
pypdf has long runtimes for wrong size values in cross-reference and object streams
CVE-2026-25219Medium· 6.5Apache Airlfow: Sensitive Azure Service Bus connection string (and possibly other providers) exposed to users with view access
Apache Airlfow: Sensitive Azure Service Bus connection string (and possibly other providers) exposed to users with view access
CVE-2026-21726Medium· 5.3Grafana Loki Path Traversal - CVE-2021-36156 Bypass
Grafana Loki Path Traversal - CVE-2021-36156 Bypass
CVE-2026-40192High· 7.5Pillow is a Python imaging library
Pillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did not limit the amount of GZIP-compressed data read when decoding a FITS image, making them vulnerable to decompression bomb attacks. A specially crafted FITS file coul…
CVE-2026-7808LowMultiple security fixes in justhtml
Multiple security fixes in justhtml
CVE-2026-40090High· 7.1Zarf has a Path Traversal via Malicious Package Metadata.Name — Arbitrary File Write
Zarf has a Path Traversal via Malicious Package Metadata.Name — Arbitrary File Write
CVE-2026-40246High· 7.5free5gc UDR improper path validation allows unauthenticated deletion of Traffic Influence Subscriptions
free5gc UDR improper path validation allows unauthenticated deletion of Traffic Influence Subscriptions
RUSTSEC-2026-0099NoneName constraints were accepted for certificates asserting a wildcard name
Name constraints were accepted for certificates asserting a wildcard name
RUSTSEC-2026-0098NoneName constraints for URI names were incorrectly accepted
Name constraints for URI names were incorrectly accepted
CVE-2026-40319Medium· 5.5Giskard has a Regular Expression Denial of Service (ReDoS) in RegexMatching Check
Giskard has a Regular Expression Denial of Service (ReDoS) in RegexMatching Check
CVE-2026-40683High· 7.7OpenStack Keystone: OpenStack Keystone: Unauthorized access due to incorrect LDAP user status handling (CVE-2026-40683)
A flaw was found in OpenStack Keystone. When using the LDAP identity backend, the system incorrectly processes the user enabled attribute if the user_enabled_invert configuration option is set to False. This error causes users marked as di…
CVE-2026-40320High· 7.8Giskard has Unsandboxed Jinja2 Template Rendering in ConformityCheck
Giskard has Unsandboxed Jinja2 Template Rendering in ConformityCheck
CVE-2026-40491Medium· 6.5gdown Affected by Arbitrary File Write via Path Traversal in gdown.extractall
gdown Affected by Arbitrary File Write via Path Traversal in gdown.extractall
CVE-2026-41133High· 8.8pyLoad has Stale Session Privilege After Role/Permission Change (Privilege Revocation Bypass)
pyLoad has Stale Session Privilege After Role/Permission Change (Privilege Revocation Bypass)
CVE-2026-40922Medium· 5.4SiYuan has incomplete fix for CVE-2026-33066: XSS
SiYuan has incomplete fix for CVE-2026-33066: XSS
CVE-2025-66236High· 7.5Apache Airflow: Secrets from Airflow config file logged in plain text in DAG run logs UI
Before Airflow 3.2.0, it was unclear that secure Airflow deployments require the Deployment Manager to take appropriate actions and pay attention to security details and security model of Airflow. Some assumptions the Deployment Manager …
CVE-2026-34476High· 7.1Apache SkyWalking MCP: Server-Side Request Forgery via SW-URL Header in MCP Server
Apache SkyWalking MCP: Server-Side Request Forgery via SW-URL Header in MCP Server
CVE-2026-1462High· 7.8A vulnerability in the `TFSMLayer` class of the `keras` package, version 3.13.0, allows attacker-controlled TensorFlow SavedModels to be loaded during deserialization of `.keras` models, even when `safe_mode=True`
A vulnerability in the `TFSMLayer` class of the `keras` package, version 3.13.0, allows attacker-controlled TensorFlow SavedModels to be loaded during deserialization of `.keras` models, even when `safe_mode=True`. This bypasses the secu…
CVE-2026-1116Medium· 6.1A Cross-site Scripting (XSS) vulnerability was identified in the `from_dict` method of the `AppLollmsMessage` class in parisneo/lollms pr…
A Cross-site Scripting (XSS) vulnerability was identified in the `from_dict` method of the `AppLollmsMessage` class in parisneo/lollms prior to version 2.2.0. The vulnerability arises from the lack of sanitization or HTML encoding of the…