VulnSea

Tagged “osv”

CVEs tagged osv, newest first.

5712 CVEsRSS

CVE-2026-28229High· 7.5
6mo ago

Unauthorized access to Argo Workflows Template

Unauthorized access to Argo Workflows Template

▾ Twilightargoproj · github.com/argoproj/argo-workflows/v3EPSS 0.78%via OSV
CVE-2026-31892High· 8.5
6mo ago

github.com/argoproj/argo-workflows: Argo Workflows: Security bypass allows privilege escalation via podSpecPatch field (CVE-2026-31892)

A flaw was found in Argo Workflows. A user with privileges to submit workflows can bypass security settings defined in a WorkflowTemplate by including a `podSpecPatch` field in their workflow submission. This allows them to circumvent rest…

▾ TwilightRed Hat · Red Hat OpenShift AI 2.25EPSS 0.65%via CSAF
CVE-2026-31900Critical· 9.8PoC
6mo ago

Black is the uncompromising Python code formatter. Black provides a GitHub action for formatting code. This action supports an option, us…

Black is the uncompromising Python code formatter. Black provides a GitHub action for formatting code. This action supports an option, use_pyproject: true, for reading the version of Black to use from the repository pyproject.toml. A mal…

▾ Abyssalblack · blackEPSS 0.64%via OSV
CVE-2026-31826Medium
6mo ago

pypdf: manipulated stream length values can exhaust RAM

pypdf: manipulated stream length values can exhaust RAM

▾ Sunlitpypdf · pypdfEPSS 0.18%via OSV
CVE-2026-31815Medium· 5.3
6mo ago

django-unicorn affected by component state manipulation via unvalidated attribute access

django-unicorn affected by component state manipulation via unvalidated attribute access

▾ Sunlitdjango-unicorn · django-unicornEPSS 0.31%via OSV
CVE-2026-30974Medium· 4.6
6mo ago

copyparty: volflag `nohtml` did not block javascript in svg files

copyparty: volflag `nohtml` did not block javascript in svg files

▾ Sunlitcopyparty · copypartyEPSS 0.34%via OSV
CVE-2026-26118High· 8.8PoC
6mo ago

Azure MCP Server has Server-Side Request Forgery issue that allows authorized attacker to elevate privileges over a network

Azure MCP Server has Server-Side Request Forgery issue that allows authorized attacker to elevate privileges over a network

▾ MidnightAzure · Azure.McpEPSS 0.86%via OSV
CVE-2026-27826High· 8.2PoC
6mo ago

MCP Atlassian has SSRF via unvalidated X-Atlassian-Jira-Url / X-Atlassian-Confluence-Url headers

MCP Atlassian has SSRF via unvalidated X-Atlassian-Jira-Url / X-Atlassian-Confluence-Url headers

▾ Midnightmcp-atlassian · mcp-atlassianEPSS 1.0%via OSV
CVE-2026-30930High
6mo ago

Glances has SQL Injection via Process Names in TimescaleDB Export

Glances has SQL Injection via Process Names in TimescaleDB Export

▾ Twilightglances · glancesEPSS 0.41%via OSV
CVE-2026-25960Medium· 5.4
6mo ago

vLLM has SSRF Protection Bypass

vLLM has SSRF Protection Bypass

▾ Sunlitvllm · vllmEPSS 0.72%via OSV
CVE-2026-30928HighPoC
6mo ago

Glances Exposes Unauthenticated Configuration Secrets

Glances Exposes Unauthenticated Configuration Secrets

▾ Midnightglances · glancesEPSS 1.6%via OSV
CVE-2025-69219High· 8.8PoC
6mo ago

Apache Airflow Providers Http has Unsafe Pickle Deserializatio leading to RCE via HttpOperator

Apache Airflow Providers Http has Unsafe Pickle Deserializatio leading to RCE via HttpOperator

▾ Midnightapache-airflow-providers-http · apache-airflow-providers-httpEPSS 0.69%via OSV
CVE-2026-25604Medium· 5.4PoC
6mo ago

In AWS Auth manager, the origin of the SAML authentication has been used as provided by the client and not verified against the actual instance URL.  This allowed to gain access to different instances with potentially different access co…

In AWS Auth manager, the origin of the SAML authentication has been used as provided by the client and not verified against the actual instance URL.  This allowed to gain access to different instances with potentially different access co…

▾ Twilightapache · apache-airflow-providers-amazonEPSS 0.51%via NVD
CVE-2026-33010High· 8.1
6mo ago

mcp-memory-service's Wildcard CORS with Credentials Enables Cross-Origin Memory Theft

mcp-memory-service's Wildcard CORS with Credentials Enables Cross-Origin Memory Theft

▾ Twilightmcp-memory-service · mcp-memory-serviceEPSS 0.46%via OSV
CVE-2026-29049Medium· 4.3
6mo ago

melange allows users to build apk packages using declarative pipelines

melange allows users to build apk packages using declarative pipelines. In version 0.40.5 and prior, melange update-cache downloads URIs from build configs via io.Copy without any size limit or HTTP client timeout (pkg/renovate/cache/cac…

▾ Sunlitchainguard · melangeEPSS 0.39%via NVD
CVE-2026-27137High· 7.5
6mo ago

When verifying a certificate chain which contains a certificate containing multiple email address constraints which share common local portions but different domain portions, these constraints will not be properly applied, and only the l…

When verifying a certificate chain which contains a certificate containing multiple email address constraints which share common local portions but different domain portions, these constraints will not be properly applied, and only the l…

▾ Twilightgolang · goEPSS 0.66%via NVD
CVE-2026-28802Critical· 9.8⚖ disputed
6mo ago

Authlib is a Python library which builds OAuth and OpenID Connect servers

Authlib is a Python library which builds OAuth and OpenID Connect servers. From version 1.6.5 to before version 1.6.7, previous tests involving passing a malicious JWT containing alg: none and an empty signature was passing the signature…

▾ Midnightauthlib · authlibEPSS 0.55%via NVD
CVE-2026-25679High· 7.5
6mo ago

url.Parse insufficiently validated the host/authority component and accepted some invalid URLs.

url.Parse insufficiently validated the host/authority component and accepted some invalid URLs.

▾ Twilightgolang · goEPSS 0.80%via NVD
GHSA-5r2p-pjr8-7fh7High
6mo ago

SageMaker Python SDK replaced eval() with safe parser in JumpStart search functionality

SageMaker Python SDK replaced eval() with safe parser in JumpStart search functionality

▾ Twilightsagemaker · sagemakervia OSV
CVE-2025-69534High· 7.5
6mo ago

Python-Markdown version 3.8 contain a vulnerability where malformed HTML-like sequences can cause html.parser.HTMLParser to raise an unhandled AssertionError during Markdown parsing

Python-Markdown version 3.8 contain a vulnerability where malformed HTML-like sequences can cause html.parser.HTMLParser to raise an unhandled AssertionError during Markdown parsing. Because Python-Markdown does not catch this exception,…

▾ Twilightpython-markdown · markdownEPSS 0.57%via NVD
CVE-2026-29790Low
6mo ago

dbt-common's commonprefix() doesn't protect against path traversal

dbt-common's commonprefix() doesn't protect against path traversal

▾ Sunlitdbt-common · dbt-commonEPSS 0.38%via OSV
CVE-2025-45691High· 7.5
6mo ago

RAGAS has an Arbitrary File Read vulnerability

RAGAS has an Arbitrary File Read vulnerability

▾ Twilightragas · ragasEPSS 0.53%via OSV
CVE-2026-25048High
6mo ago

xgrammar vulnerable to DoS via multi-layer nesting

xgrammar vulnerable to DoS via multi-layer nesting

▾ Twilightxgrammar · xgrammarEPSS 0.71%via OSV
CVE-2026-29787Medium· 5.3
6mo ago

mcp-memory-service Vulnerable to System Information Disclosure via Health Endpoint

mcp-memory-service Vulnerable to System Information Disclosure via Health Endpoint

▾ Sunlitmcp-memory-service · mcp-memory-serviceEPSS 0.41%via OSV
CVE-2026-29780Medium· 5.5PoC
6mo ago

eml_parser: Path Traversal in Official Example Script Leads to Arbitrary File Write

eml_parser: Path Traversal in Official Example Script Leads to Arbitrary File Write

▾ Twilighteml-parser · eml-parserEPSS 0.18%via OSV
CVE-2026-29038Medium· 6.1
7mo ago

changedetection.io has Reflected XSS in its RSS Tag Error Response

changedetection.io has Reflected XSS in its RSS Tag Error Response

▾ Sunlitchangedetection-io · changedetection-ioEPSS 0.34%via OSV
CVE-2026-29039High
7mo ago

changedetection.io vulnerable to XPath - Arbitrary File Read via unparsed-text()

changedetection.io vulnerable to XPath - Arbitrary File Read via unparsed-text()

▾ Twilightchangedetection-io · changedetection-ioEPSS 0.51%via OSV
CVE-2026-29065High
7mo ago

changedetection.io has Zip Slip vulnerability in the backup restore functionality

changedetection.io has Zip Slip vulnerability in the backup restore functionality

▾ Twilightchangedetection-io · changedetection-ioEPSS 0.56%via OSV
CVE-2026-28681High· 8.1
7mo ago

IRRd: web UI host header injection allows password reset poisoning via attacker-controlled email links

IRRd: web UI host header injection allows password reset poisoning via attacker-controlled email links

▾ Twilightirrd · irrdEPSS 0.55%via OSV
CVE-2026-28518High· 7.8
7mo ago

OpenViking contains a Path Traversal vulnerability

OpenViking contains a Path Traversal vulnerability

▾ Twilightopenviking · openvikingEPSS 0.18%via OSV
CVEs tagged “osv” — page 88 · VulnSea