VulnSea

Tagged “osv”

CVEs tagged osv, newest first.

5670 CVEsRSS

CVE-2026-77281Medium· 6.5
1w ago

Caddy is an extensible server platform that uses TLS by default

Caddy is an extensible server platform that uses TLS by default. In version 2.11.3 and earlier, three configuration-dependent weaknesses affect the handler and placeholder layer. In modules/caddyhttp/rewrite/rewrite.go, Rewrite.Rewrite()…

▾ Sunlitcaddyserver · caddyEPSS 0.49%via NVD
CVE-2026-68537High· 7.5
1w ago

`fulgur` converts untrusted HTML/CSS into PDF, commonly on a server that processes input supplied by many tenants

`fulgur` converts untrusted HTML/CSS into PDF, commonly on a server that processes input supplied by many tenants. In versions prior to 0.19.0, a body-direct child whose CSS-resolved height greatly exceeds the page height was sliced into…

▾ Twilightfulgur-rs · fulgurEPSS 0.61%via NVD
CVE-2026-68523High· 7.5
1w ago

`fulgur` converts untrusted HTML/CSS into PDF, commonly on a server that processes input supplied by many tenants

`fulgur` converts untrusted HTML/CSS into PDF, commonly on a server that processes input supplied by many tenants. In versions prior to 0.19.0, a body-direct child whose CSS-resolved height greatly exceeds the page height was sliced into…

▾ Twilightfulgur-rs · fulgurEPSS 0.61%via NVD
CVE-2026-86000Medium· 5.3PoC
1w ago

Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4

Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.9, the selector parser in src/soupsieve/css_parser.py defines IDENTIFIER with adjacent quantified groups over overlapping character classes, and V…

▾ Twilightfacelessuser · soupsieveEPSS 0.61%via NVD
CVE-2026-85999Medium· 5.3PoC
1w ago

Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4

Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.9, selector_iter in src/soupsieve/css_parser.py trims the raw selector with RE_WS_END, an end-anchored WSC whitespace-and-comment expression used …

▾ Twilightfacelessuser · soupsieveEPSS 0.61%via NVD
MAL-2026-16250Critical⚠ Exploited
1w ago

Malicious code in marketing-mcp (PyPI)

Malicious code in marketing-mcp (PyPI)

▾ Abyssalmarketing-mcp · marketing-mcpvia OSV
CVE-2026-85078Medium· 6.5
1w ago

Sanic is an opensource python web server/framework

Sanic is an opensource python web server/framework. In version 25.12.0, Sanic's core HTTP/1.1 chunked-body handling does not fully consume the trailer-part after the terminating zero chunk before reusing the keep-alive connection buffer.…

▾ Sunlitsanic-org · sanicEPSS 0.51%via NVD
GO-2026-6449None
1w ago

Komari: Management Interface CSRF in github.com/komari-monitor/komari

Komari: Management Interface CSRF in github.com/komari-monitor/komari

▾ Sunlitkomari-monitor · github.com/komari-monitor/komarivia OSV
RUSTSEC-2026-0286None
1w ago

Out-of-bounds read when decoding CKA_ALLOWED_MECHANISMS

Out-of-bounds read when decoding CKA_ALLOWED_MECHANISMS

▾ Sunlitcryptoki · cryptokivia OSV
MAL-2026-16242Critical⚠ Exploited
1w ago

Malicious code in trongappy (PyPI)

Malicious code in trongappy (PyPI)

▾ Abyssaltrongappy · trongappyvia OSV
MAL-2026-16241Critical⚠ Exploited
1w ago

Malicious code in rak-lab-yoav-orca-zrktd2cp5hjmo4x7 (PyPI)

Malicious code in rak-lab-yoav-orca-zrktd2cp5hjmo4x7 (PyPI)

▾ Abyssalrak-lab-yoav-orca-zrktd2cp5hjmo4x7 · rak-lab-yoav-orca-zrktd2cp5hjmo4x7via OSV
MAL-2026-16240Critical⚠ Exploited
1w ago

Malicious code in praetorian-mind-rce-test-2026 (PyPI)

Malicious code in praetorian-mind-rce-test-2026 (PyPI)

▾ Abyssalpraetorian-mind-rce-test-2026 · praetorian-mind-rce-test-2026via OSV
CVE-2026-61599High· 8.8
1w ago

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, the djust live transport resolves the LiveView to mount from a client-supplied dotted path by calling …

▾ Twilightdjust-org · djustEPSS 0.60%via NVD
CVE-2026-61589Medium· 6.3
1w ago

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, the WebSocket `handle_mount` and `ViewRuntime._build_request` rebuild an `HttpRequest` via `RequestFac…

▾ Sunlitdjust-org · djustEPSS 0.18%via NVD
CVE-2026-64684Medium· 6.8
1w ago

RMCP is an official Rust SDK for the Model Context Protocol

RMCP is an official Rust SDK for the Model Context Protocol. Prior to 2.1.0, the rmcp crate's StreamableHttpClientTransport in crates/rmcp/src/transport/common/reqwest/streamable_http_client.rs builds its default_http_client with reqwest…

▾ Sunlitmodelcontextprotocol · rust-sdkEPSS 0.50%via NVD
CVE-2026-61597Medium· 5.1
1w ago

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, many djust built-in component template tags (`djust.components.templatetags.*`) render a developer/use…

▾ Sunlitdjust-org · djustEPSS 0.41%via NVD
CVE-2026-61592High· 7.4
1w ago

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, SSE sessions were keyed solely by a client-chosen `session_id` with no binding to the authenticated us…

▾ Twilightdjust-org · djustEPSS 0.39%via NVD
CVE-2026-61594Critical· 9.1
1w ago

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, the live (WebSocket) transport authorizes a mount via `check_view_auth`, not Django's `View.dispatch()…

▾ Midnightdjust-org · djustEPSS 0.48%via NVD
CVE-2026-61591High· 8.1
1w ago

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, for views that opt into state snapshots, the snapshot `state_json` embedded in the client page was res…

▾ Twilightdjust-org · djustEPSS 0.22%via NVD
CVE-2026-61588Medium· 6.5
1w ago

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, when a Django `Model` instance is assigned to a public view attribute, djust serialized it to the clie…

▾ Sunlitdjust-org · djustEPSS 0.39%via NVD
CVE-2026-61596High· 7.1
1w ago

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, djust's per-object authorization (`get_object` + `has_object_permission`, ADR-017) was enforced on the…

▾ Twilightdjust-org · djustEPSS 0.33%via NVD
CVE-2026-81871Medium· 6.3
1w ago

OpenTelemetry-Go is the Go implementation of OpenTelemetry

OpenTelemetry-Go is the Go implementation of OpenTelemetry. Prior to version 0.21.0, the exporters/otlp/otlplog/otlploggrpc package loads OTEL_EXPORTER_OTLP_LOGS_CERTIFICATE, OTEL_EXPORTER_OTLP_CERTIFICATE, and related client certificate…

▾ Sunlitopen-telemetry · opentelemetry-goEPSS 0.33%via NVD
CVE-2026-81870Low· 2.0PoC
1w ago

OpenTelemetry-Go is the Go implementation of OpenTelemetry

OpenTelemetry-Go is the Go implementation of OpenTelemetry. From version 1.5.0 to 1.44.0, sdk/trace.NewTracerProvider emits a TracerProvider created internal Info-level diagnostic event whose MarshalLog implementations recursively includ…

▾ Twilightopen-telemetry · opentelemetry-goEPSS 0.19%via NVD
CVE-2026-62949Medium· 6.5
1w ago

AsyncSSH is a Python package which provides an asynchronous client and server implementation of the SSHv2 protocol on top of the Python asyncio framework

AsyncSSH is a Python package which provides an asynchronous client and server implementation of the SSHv2 protocol on top of the Python asyncio framework. Prior to 2.24.0, _process_channel_open and _process_channel_open_confirmation in a…

▾ Sunlitronf · asyncsshEPSS 0.39%via NVD
CVE-2026-59823Medium· 5.3
1w ago

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.9, an authenticated LiteLLM Proxy caller with a valid virtual key can place api_base inside the user_config request body to bypass is_req…

▾ SunlitBerriAI · litellmEPSS 0.44%via NVD
CVE-2026-82399High· 7.5PoC
1w ago

CoreDNS is a DNS server written in Go

CoreDNS is a DNS server written in Go. Prior to 1.14.7, the DNS-over-HTTPS, DNS-over-HTTP/3, DNS-over-QUIC, and DNS-over-gRPC request paths in plugin/pkg/doh/doh.go, core/dnsserver/server_quic.go, and core/dnsserver/server_grpc.go call d…

▾ Midnightcoredns · corednsEPSS 0.61%via NVD
CVE-2026-86003High· 7.5
1w ago

CoreDNS is a DNS server written in Go

CoreDNS is a DNS server written in Go. Prior to 1.14.7, the DNS-over-HTTPS, DNS-over-HTTP/3, DNS-over-QUIC, and DNS-over-gRPC listeners in plugin/pkg/doh/doh.go, core/dnsserver/server_quic.go, and core/dnsserver/server_grpc.go call dns.M…

▾ Twilightcoredns · corednsEPSS 0.44%via NVD
CVE-2026-86043High· 7.5PoC
1w ago

Skipper is an HTTP router and reverse proxy for service composition

Skipper is an HTTP router and reverse proxy for service composition. Prior to version 0.27.37, the opaAuthorizeRequestWithBody filter can authorize an oversized request after Skipper truncates the body presented to Open Policy Agent beca…

▾ Midnightzalando · skipperEPSS 0.45%via NVD
CVE-2026-69147Medium· 6.5PoC
1w ago

vLLM is an inference and serving engine for large language models

vLLM is an inference and serving engine for large language models. Prior to 0.28.0, request bodies for Chat Completions and Responses can set media_io_kwargs.video.video_backend to pynvvideocodec, and MediaConnector.fetch_video forwards …

▾ Twilightvllm-project · vllmEPSS 0.55%via NVD
CVE-2026-85732Medium· 4.7PoC
1w ago

oras-go is a Go library for managing OCI artifacts

oras-go is a Go library for managing OCI artifacts. Prior to 2.6.2, the parseLink function in registry/remote/utils.go accepts an absolute URL from a registry-controlled Link response header without validating its scheme, host, or port. …

▾ Twilightoras-project · oras-goEPSS 0.35%via NVD
CVEs tagged “osv” — page 8 · VulnSea