VulnSea

Tagged “osv”

CVEs tagged osv, newest first.

5710 CVEsRSS

CVE-2026-39429High· 8.2
5mo ago

kcp's cache server is accessible without authentication or authorization checks

kcp's cache server is accessible without authentication or authorization checks

▾ Twilightkcp-dev · github.com/kcp-dev/kcpEPSS 0.54%via OSV
CVE-2026-39844Medium· 5.9
5mo ago

NiceGUI: Upload filename sanitization bypass via backslashes allows path traversal on Windows

NiceGUI: Upload filename sanitization bypass via backslashes allows path traversal on Windows

▾ Sunlitnicegui · niceguiEPSS 0.49%via OSV
CVE-2026-40071Medium· 5.4
5mo ago

pyload-ng has a WebUI JSON permission mismatch that lets ADD/DELETE users invoke MODIFY-only actions

pyload-ng has a WebUI JSON permission mismatch that lets ADD/DELETE users invoke MODIFY-only actions

▾ Sunlitpyload-ng · pyload-ngEPSS 0.32%via OSV
CVE-2026-34589Medium· 5.0
5mo ago

OpenEXR: DWA Lossy Decoder Heap Out-of-Bounds Write

OpenEXR: DWA Lossy Decoder Heap Out-of-Bounds Write

▾ Sunlitopenexr · openexrEPSS 0.48%via OSV
CVE-2026-31040High
5mo ago

stata-mcp has insufficient validation of user-supplied Stata do-file content that can lead to command execution

stata-mcp has insufficient validation of user-supplied Stata do-file content that can lead to command execution

▾ Twilightstata-mcp · stata-mcpEPSS 1.1%via OSV
CVE-2026-39891High· 8.8
5mo ago

PraisonAI has Template Injection in Agent Tool Definitions

PraisonAI has Template Injection in Agent Tool Definitions

▾ Twilightpraisonai · praisonaiEPSS 0.56%via OSV
CVE-2026-39889High· 7.5
5mo ago

PraisonAI Has Unauthenticated SSE Event Stream that Exposes All Agent Activity in A2U Server

PraisonAI Has Unauthenticated SSE Event Stream that Exposes All Agent Activity in A2U Server

▾ Twilightpraisonai · praisonaiEPSS 0.48%via OSV
CVE-2026-40087Medium· 5.3
5mo ago

LangChain has incomplete f-string validation in prompt templates

LangChain has incomplete f-string validation in prompt templates

▾ Sunlitlangchain-core · langchain-coreEPSS 0.45%via OSV
CVE-2026-1163Medium· 4.1
5mo ago

parisneo/lollms has an insufficient session expiration vulnerability

parisneo/lollms has an insufficient session expiration vulnerability

▾ Sunlitlollms · lollmsEPSS 0.23%via OSV
CVE-2026-39413Medium· 4.2
5mo ago

lightrag-hku: JWT Algorithm Confusion Vulnerability

lightrag-hku: JWT Algorithm Confusion Vulnerability

▾ Sunlitlightrag-hku · lightrag-hkuEPSS 0.21%via OSV
CVE-2026-56078Medium· 6.5
5mo ago

PraisonAI has Memory State Leakage and Path Traversal in MultiAgent Context Handling

PraisonAI has Memory State Leakage and Path Traversal in MultiAgent Context Handling

▾ Sunlitpraisonaiagents · praisonaiagentsEPSS 0.92%via OSV
CVE-2026-39981High· 8.8
5mo ago

AGiXT Vulnerable to Path Traversal in safe_join()

AGiXT Vulnerable to Path Traversal in safe_join()

▾ Twilightagixt · agixtEPSS 1.4%via OSV
CVE-2026-33753Medium· 6.2
5mo ago

rfc3161-client Has Improper Certificate Validation

rfc3161-client Has Improper Certificate Validation

▾ Sunlitrfc3161-client · rfc3161-clientEPSS 0.21%via OSV
CVE-2026-32289Medium· 5.4
5mo ago

html/template: golang: html/template: Cross-Site Scripting (XSS) via improper context and brace depth tracking in JS template literals (CVE…

A flaw was found in the `html/template` package. This vulnerability arises from improper tracking of context and brace depth within JavaScript (JS) template literals. A remote attacker could exploit these issues to cause content to be inco…

▾ SunlitRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.33%via CSAF
CVE-2026-32281Medium· 5.9
5mo ago

crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation (CVE-2026-32281)

A flaw was found in Go's `crypto/x509` package. A remote attacker could exploit this by presenting a specially crafted certificate chain containing a large number of policy mappings. This inefficient validation process consumes excessive r…

▾ SunlitRed Hat · Red Hat Enterprise Linux AppStream EUS (v.9.6)EPSS 0.36%via CSAF
CVE-2026-32282High· 7.8
5mo ago

golang: internal/syscall/unix: Root.Chmod can follow symlinks out of the root (CVE-2026-32282)

A flaw was found in the internal/syscall/unix package in the Go standard library. If the target of the `Root.Chmod` function is replaced with a symbolic link during execution, specifically after `Root.Chmod` checks the target but before ac…

▾ TwilightRed Hat · Red Hat Enterprise Linux AppStream (v. 10)EPSS 0.29%via CSAF
GHSA-xmrv-pmrh-hhx2Medium· 5.9
5mo ago

Denial of Service due to Panic in AWS SDK for Go v2 SDK EventStream Decoder

Denial of Service due to Panic in AWS SDK for Go v2 SDK EventStream Decoder

▾ Sunlitaws · github.com/aws/aws-sdk-go-v2/aws/protocol/eventstreamvia OSV
CVE-2026-39882High· 7.5⚖ disputed
5mo ago

github.com/open-telemetry/opentelemetry-go: OpenTelemetry-Go: Memory exhaustion via uncapped HTTP response body reading (CVE-2026-39882)

A flaw was found in OpenTelemetry-Go. The otlp HTTP exporters read the full HTTP response body into an in-memory buffer without a size cap. A remote attacker, by controlling the collector endpoint or performing a man-in-the-middle (MITM) a…

▾ TwilightRed Hat · Red Hat OpenShift Container Platform 4.22EPSS 0.19%via CSAF
CVE-2026-40035Critical· 9.1PoC
5mo ago

Unfurl - Werkzeug Debugger Exposure via String Config Parsing

Unfurl through 2025.08 contains an improper input validation vulnerability in config parsing that enables Flask debug mode by default. The debug configuration value is read as a string and passed directly to app.run(), causing any non-em…

▾ Abyssalobsidianforensics · dfir-unfurlEPSS 0.72%via CVEORG
CVE-2026-40036High· 7.5PoC
5mo ago

Unfurl < 2026.04 - Denial of Service via Unbounded zlib Decompression

Unfurl before 2026.04 contains an unbounded zlib decompression vulnerability in parse_compressed.py that allows remote attackers to cause denial of service. Attackers can submit highly compressed payloads via URL parameters to the /json/…

▾ Midnightobsidianforensics · dfir-unfurlEPSS 0.79%via CVEORG
CVE-2026-39892Critical· 9.8⚖ disputed
5mo ago

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 45.0.0 to before 46.0.7, if a non-contiguous buffer was passed to APIs which accepted Python buffers (e.g. Hash.update()), this …

▾ Midnightcryptography.io · cryptographyEPSS 0.76%via NVD
CVE-2026-32283High· 7.5
5mo ago

If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources

If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources. This can lead to a denial of service. This only affects T…

▾ Twilightgolang · goEPSS 0.62%via NVD
CVE-2026-32280High· 7.5
5mo ago

During chain building, the amount of work that is done is not correctly limited when a large number of intermediate certificates are passed in VerifyOptions.Intermediates, which can lead to a denial of service

During chain building, the amount of work that is done is not correctly limited when a large number of intermediate certificates are passed in VerifyOptions.Intermediates, which can lead to a denial of service. This affects both direct u…

▾ Twilightgolang · goEPSS 0.61%via NVD
CVE-2026-33810High· 8.2
5mo ago

When verifying a certificate chain containing excluded DNS constraints, these constraints are not correctly applied to wildcard DNS SANs which use a different case than the constraint

When verifying a certificate chain containing excluded DNS constraints, these constraints are not correctly applied to wildcard DNS SANs which use a different case than the constraint. This only affects validation of otherwise trusted ce…

▾ Twilightgolang · goEPSS 0.34%via NVD
CVE-2026-4292Low· 2.7
5mo ago

Django vulnerable to privilege abuse in ModelAdmin.list_editable

Django vulnerable to privilege abuse in ModelAdmin.list_editable

▾ Sunlitdjango · djangoEPSS 0.36%via OSV
CVE-2026-39373High· 7.5⚖ disputed
5mo ago

JWCrypto: python-cryptography: python: JWCrypto: Memory exhaustion via crafted compressed JWE tokens (CVE-2026-39373)

A flaw was found in JWCrypto, a Python library for JSON Web Key (JWK), JSON Web Signature (JWS), and JSON Web Encryption (JWE) specifications. An unauthenticated attacker can exploit this vulnerability by sending specially crafted JWE toke…

▾ TwilightRed Hat · Red Hat Ansible Automation Platform 2.5 for RHEL 8EPSS 0.43%via CSAF
CVE-2026-33034High· 7.5
5mo ago

Django: SGI requests with a missing or understated `Content-Length` header could bypass the `DATA_UPLOAD_MAX_MEMORY_SIZE` limit

Django: SGI requests with a missing or understated `Content-Length` header could bypass the `DATA_UPLOAD_MAX_MEMORY_SIZE` limit

▾ Twilightdjango · djangoEPSS 0.85%via OSV
CVE-2026-33033Medium· 6.5PoC
5mo ago

Django has potential DoS via MultiPartParser through crafted multipart uploads

Django has potential DoS via MultiPartParser through crafted multipart uploads

▾ Twilightdjango · djangoEPSS 0.88%via OSV
CVE-2026-33866Medium· 4.3
5mo ago

MLflow is vulnerable to an authorization bypass affecting the AJAX endpoint

MLflow is vulnerable to an authorization bypass affecting the AJAX endpoint

▾ Sunlitmlflow · mlflowEPSS 0.37%via OSV
RUSTSEC-2026-0273None
5mo ago

Stubbed cryptography without warnings

Stubbed cryptography without warnings

▾ Sunlitmanzana · manzanavia OSV
CVEs tagged “osv” — page 80 · VulnSea