Tagged “osv”
CVEs tagged osv, newest first.
5712 CVEsRSS
CVE-2026-28229High· 7.5Unauthorized access to Argo Workflows Template
Unauthorized access to Argo Workflows Template
CVE-2026-31892High· 8.5github.com/argoproj/argo-workflows: Argo Workflows: Security bypass allows privilege escalation via podSpecPatch field (CVE-2026-31892)
A flaw was found in Argo Workflows. A user with privileges to submit workflows can bypass security settings defined in a WorkflowTemplate by including a `podSpecPatch` field in their workflow submission. This allows them to circumvent rest…
CVE-2026-31900Critical· 9.8PoCBlack is the uncompromising Python code formatter. Black provides a GitHub action for formatting code. This action supports an option, us…
Black is the uncompromising Python code formatter. Black provides a GitHub action for formatting code. This action supports an option, use_pyproject: true, for reading the version of Black to use from the repository pyproject.toml. A mal…
CVE-2026-31826Mediumpypdf: manipulated stream length values can exhaust RAM
pypdf: manipulated stream length values can exhaust RAM
CVE-2026-31815Medium· 5.3django-unicorn affected by component state manipulation via unvalidated attribute access
django-unicorn affected by component state manipulation via unvalidated attribute access
CVE-2026-30974Medium· 4.6copyparty: volflag `nohtml` did not block javascript in svg files
copyparty: volflag `nohtml` did not block javascript in svg files
CVE-2026-26118High· 8.8PoCAzure MCP Server has Server-Side Request Forgery issue that allows authorized attacker to elevate privileges over a network
Azure MCP Server has Server-Side Request Forgery issue that allows authorized attacker to elevate privileges over a network
CVE-2026-27826High· 8.2PoCMCP Atlassian has SSRF via unvalidated X-Atlassian-Jira-Url / X-Atlassian-Confluence-Url headers
MCP Atlassian has SSRF via unvalidated X-Atlassian-Jira-Url / X-Atlassian-Confluence-Url headers
CVE-2026-30930HighGlances has SQL Injection via Process Names in TimescaleDB Export
Glances has SQL Injection via Process Names in TimescaleDB Export
CVE-2026-25960Medium· 5.4vLLM has SSRF Protection Bypass
vLLM has SSRF Protection Bypass
CVE-2026-30928HighPoCGlances Exposes Unauthenticated Configuration Secrets
Glances Exposes Unauthenticated Configuration Secrets
CVE-2025-69219High· 8.8PoCApache Airflow Providers Http has Unsafe Pickle Deserializatio leading to RCE via HttpOperator
Apache Airflow Providers Http has Unsafe Pickle Deserializatio leading to RCE via HttpOperator
CVE-2026-25604Medium· 5.4PoCIn AWS Auth manager, the origin of the SAML authentication has been used as provided by the client and not verified against the actual instance URL. This allowed to gain access to different instances with potentially different access co…
In AWS Auth manager, the origin of the SAML authentication has been used as provided by the client and not verified against the actual instance URL. This allowed to gain access to different instances with potentially different access co…
CVE-2026-33010High· 8.1mcp-memory-service's Wildcard CORS with Credentials Enables Cross-Origin Memory Theft
mcp-memory-service's Wildcard CORS with Credentials Enables Cross-Origin Memory Theft
CVE-2026-29049Medium· 4.3melange allows users to build apk packages using declarative pipelines
melange allows users to build apk packages using declarative pipelines. In version 0.40.5 and prior, melange update-cache downloads URIs from build configs via io.Copy without any size limit or HTTP client timeout (pkg/renovate/cache/cac…
CVE-2026-27137High· 7.5When verifying a certificate chain which contains a certificate containing multiple email address constraints which share common local portions but different domain portions, these constraints will not be properly applied, and only the l…
When verifying a certificate chain which contains a certificate containing multiple email address constraints which share common local portions but different domain portions, these constraints will not be properly applied, and only the l…
CVE-2026-28802Critical· 9.8⚖ disputedAuthlib is a Python library which builds OAuth and OpenID Connect servers
Authlib is a Python library which builds OAuth and OpenID Connect servers. From version 1.6.5 to before version 1.6.7, previous tests involving passing a malicious JWT containing alg: none and an empty signature was passing the signature…
CVE-2026-25679High· 7.5url.Parse insufficiently validated the host/authority component and accepted some invalid URLs.
url.Parse insufficiently validated the host/authority component and accepted some invalid URLs.
GHSA-5r2p-pjr8-7fh7HighSageMaker Python SDK replaced eval() with safe parser in JumpStart search functionality
SageMaker Python SDK replaced eval() with safe parser in JumpStart search functionality
CVE-2025-69534High· 7.5Python-Markdown version 3.8 contain a vulnerability where malformed HTML-like sequences can cause html.parser.HTMLParser to raise an unhandled AssertionError during Markdown parsing
Python-Markdown version 3.8 contain a vulnerability where malformed HTML-like sequences can cause html.parser.HTMLParser to raise an unhandled AssertionError during Markdown parsing. Because Python-Markdown does not catch this exception,…
CVE-2026-29790Lowdbt-common's commonprefix() doesn't protect against path traversal
dbt-common's commonprefix() doesn't protect against path traversal
CVE-2025-45691High· 7.5RAGAS has an Arbitrary File Read vulnerability
RAGAS has an Arbitrary File Read vulnerability
CVE-2026-25048Highxgrammar vulnerable to DoS via multi-layer nesting
xgrammar vulnerable to DoS via multi-layer nesting
CVE-2026-29787Medium· 5.3mcp-memory-service Vulnerable to System Information Disclosure via Health Endpoint
mcp-memory-service Vulnerable to System Information Disclosure via Health Endpoint
CVE-2026-29780Medium· 5.5PoCeml_parser: Path Traversal in Official Example Script Leads to Arbitrary File Write
eml_parser: Path Traversal in Official Example Script Leads to Arbitrary File Write
CVE-2026-29038Medium· 6.1changedetection.io has Reflected XSS in its RSS Tag Error Response
changedetection.io has Reflected XSS in its RSS Tag Error Response
CVE-2026-29039Highchangedetection.io vulnerable to XPath - Arbitrary File Read via unparsed-text()
changedetection.io vulnerable to XPath - Arbitrary File Read via unparsed-text()
CVE-2026-29065Highchangedetection.io has Zip Slip vulnerability in the backup restore functionality
changedetection.io has Zip Slip vulnerability in the backup restore functionality
CVE-2026-28681High· 8.1IRRd: web UI host header injection allows password reset poisoning via attacker-controlled email links
IRRd: web UI host header injection allows password reset poisoning via attacker-controlled email links
CVE-2026-28518High· 7.8OpenViking contains a Path Traversal vulnerability
OpenViking contains a Path Traversal vulnerability