VulnSea

Tagged “osv”

CVEs tagged osv, newest first.

5670 CVEsRSS

CVE-2026-85731High· 8.8PoC
1w ago

oras-go is a Go library for managing OCI artifacts

oras-go is a Go library for managing OCI artifacts. Prior to 2.6.2, content/file.Store extraction of OCI layers marked with io.deis.oras.content.unpack=true can write outside the store working directory. The pushDir path through extractT…

▾ Midnightoras-project · oras-goEPSS 0.63%via NVD
CVE-2026-57173Medium· 6.5
1w ago

vLLM is an inference and serving engine for large language models

vLLM is an inference and serving engine for large language models. Prior to 0.24.0, the input_audio handling path for /v1/chat/completions calls AudioMediaIO.load_bytes or AudioMediaIO.load_file without passing VLLM_MAX_AUDIO_DECODE_DURA…

▾ Sunlitvllm-project · vllmEPSS 0.69%via NVD
MAL-2026-16219Critical⚠ Exploited
1w ago

Malicious code in licloud (PyPI)

Malicious code in licloud (PyPI)

▾ Abyssallicloud · licloudvia OSV
MAL-2026-16212Critical⚠ Exploited
1w ago

Malicious code in cli-anything-ai-market (PyPI)

Malicious code in cli-anything-ai-market (PyPI)

▾ Abyssalcli-anything-ai-market · cli-anything-ai-marketvia OSV
CVE-2026-61595High· 7.7
1w ago

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, `djust.tenants` isolation was enforced only on the HTTP path. The current tenant was stored in `thread…

▾ Twilightdjust · djustEPSS 0.39%via NVD
CVE-2025-59953Critical· 9.8PoC
1w ago

LMDeploy is a toolkit for compressing, deploying, and serving large language models

LMDeploy is a toolkit for compressing, deploying, and serving large language models. Starting in version 0.9.1 and prior to version 0.10.2, the LMdeploy implements an rpc server (AsyncRPCServer in zmq_rpc.py) for supporting the RPC commu…

▾ AbyssalInternLM · lmdeployEPSS 0.80%via NVD
CVE-2026-61593High· 8.1
1w ago

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, the SSE client→server POST endpoints are `@csrf_exempt` and the SSE GET stream endpoint had no Origin …

▾ Twilightdjust · djustEPSS 0.21%via NVD
CVE-2026-82410High· 8.7
1w ago

Pocketbase is an open source web backend written in go

Pocketbase is an open source web backend written in go. Prior to 0.22.48 and 0.39.7, PocketBase's panic-recovery middleware covers regular request handling but not internal child and worker goroutines. A panic in one of these internal go…

▾ Twilightpocketbase · pocketbaseEPSS 0.58%via NVD
CVE-2026-61709Medium· 5.3
1w ago

OpenFGA is an authorization and permission engine built for developers

OpenFGA is an authorization and permission engine built for developers. Prior to 1.18.1, the ListUsers API could return a user that should have been excluded when an authorization relation used an intersection containing a base but not e…

▾ Sunlitopenfga · openfgaEPSS 0.35%via NVD
CVE-2026-76825High· 8.4
1w ago

RestrictedPython is a tool that helps define a subset of the Python language for accepting program input in a trusted environment

RestrictedPython is a tool that helps define a subset of the Python language for accepting program input in a trusted environment. Prior to 8.4, RestrictedPython could allow a sandbox escape when a custom import policy or globals exposed…

▾ Twilightzopefoundation · RestrictedPythonEPSS 0.62%via NVD
CVE-2026-77401Medium· 6.8
1w ago

Zope AccessControl provides a general security framework for use in Zope

Zope AccessControl provides a general security framework for use in Zope. Prior to 7.4, applications that allow untrusted users to create and execute AccessControl-controlled Python code do not safely guard str.format and str.format_map …

▾ Sunlitzopefoundation · AccessControlEPSS 0.47%via NVD
CVE-2026-77408Critical· 9.1
1w ago

RabbitMQ amqp091-go is a Go AMQP 0.9.1 client

RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, the writeShortstr function in write.go casts the byte length of AMQP shortstr property values to uint8 without first rejecting values longer than 255 bytes. An application t…

▾ Midnightrabbitmq · amqp091-goEPSS 0.52%via NVD
CVE-2026-77407High· 7.0
1w ago

RabbitMQ amqp091-go is a Go AMQP 0.9.1 client

RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, PlainAuth values defined in auth.go retain passwords as exported plaintext fields in Connection.Config.SASL after a successful PLAIN authentication handshake. The Connection…

▾ Twilightrabbitmq · amqp091-goEPSS 0.13%via NVD
CVE-2026-77406High· 8.2
1w ago

RabbitMQ amqp091-go is a Go AMQP 0.9.1 client

RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, Channel.Qos in channel.go accepts negative prefetchCount and prefetchSize integers and casts them directly to uint16 and uint32 fields in the basic.qos method because valida…

▾ Twilightrabbitmq · amqp091-goEPSS 0.41%via NVD
CVE-2026-77403High· 8.9
1w ago

RabbitMQ amqp091-go is a Go AMQP 0.9.1 client

RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, Connection.openTune in connection.go accepts a server-advertised FrameMax below the AMQP frameMinSize value of 4096 bytes because the connection negotiation loop does not en…

▾ Twilightrabbitmq · amqp091-goEPSS 0.52%via NVD
CVE-2026-77410High· 8.9
1w ago

RabbitMQ amqp091-go is a Go AMQP 0.9.1 client

RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, Channel.recvContent in channel.go preallocates the message body slice with the uint64 ch.header.Size value supplied by an AMQP content header without capping the allocation …

▾ Twilightrabbitmq · amqp091-goEPSS 0.52%via NVD
CVE-2026-77404High· 8.7
1w ago

RabbitMQ amqp091-go is a Go AMQP 0.9.1 client

RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, URI.String in uri.go concatenates CertFile, KeyFile, CACertFile, and ServerName values directly into an AMQPS query string instead of encoding them as URL query parameters w…

▾ Twilightrabbitmq · amqp091-goEPSS 0.10%via NVD
CVE-2026-77412High· 8.9
1w ago

RabbitMQ amqp091-go is a Go AMQP 0.9.1 client

RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, readField in read.go reads the length of an AMQP byte-array field with type tag x into a signed int32 and passes the value directly to make when allocating the field buffer.…

▾ Twilightrabbitmq · amqp091-goEPSS 0.52%via NVD
CVE-2026-77405Critical· 9.4
1w ago

RabbitMQ amqp091-go is a Go AMQP 0.9.1 client

RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, tlsConfigFromURI in uri.go creates tls.Config values without setting MinVersion to tls.VersionTLS12. Builds using a Go runtime whose default permits TLS 1.0 or TLS 1.1 can t…

▾ Midnightrabbitmq · amqp091-goEPSS 0.28%via NVD
CVE-2026-77411Critical· 9.5
1w ago

RabbitMQ amqp091-go is a Go AMQP 0.9.1 client

RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, readLongstr in read.go returns an empty string and a nil error when a declared AMQP longstr length exceeds 0x7FFFFFFF instead of returning ErrSyntax. The function leaves the…

▾ Midnightrabbitmq · amqp091-goEPSS 0.52%via NVD
CVE-2026-63128High· 7.5PoC
1w ago

RMCP is an official Rust SDK for the Model Context Protocol

RMCP is an official Rust SDK for the Model Context Protocol. Prior to 2.0.0, the rmcp crate's stateful Streamable HTTP server in crates/rmcp/src/transport/streamable_http_server/tower.rs allows an unauthenticated client to send a well-fo…

▾ Midnightmodelcontextprotocol · rust-sdkEPSS 0.63%via NVD
CVE-2026-63127High· 8.2PoC
1w ago

RMCP is an official Rust SDK for the Model Context Protocol

RMCP is an official Rust SDK for the Model Context Protocol. Prior to 2.0.0, the rmcp crate's OAuth implementation in crates/rmcp/src/transport/auth.rs omits the RFC 9728 resource field from ResourceServerMetadata and allows discover_oau…

▾ Midnightmodelcontextprotocol · rust-sdkEPSS 0.20%via NVD
CVE-2026-61590High· 7.4
1w ago

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, djust's observability endpoints expose live view/session state and a remote method-invocation surface …

▾ Twilightdjust-org · djustEPSS 0.36%via NVD
CVE-2026-61598High· 7.1
1w ago

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, `djust.mixins.model_binding.ModelBindingMixin` provides a default `update_model` event handler and is …

▾ Twilightdjust · djustEPSS 0.43%via NVD
CVE-2026-86792High· 8.8
1w ago

Apache Airflow Apache Kafka provider versions 1.15.0 before 2.0.0 resolve dotted-path strings found in a Kafka connection's `extra` field into Python callables via `import_string`, with no allowlist, and hand them to the confluent-kafka …

Apache Airflow Apache Kafka provider versions 1.15.0 before 2.0.0 resolve dotted-path strings found in a Kafka connection's `extra` field into Python callables via `import_string`, with no allowlist, and hand them to the confluent-kafka …

▾ Twilightapache · apache-airflow-providers-apache-kafkaEPSS 1.2%via NVD
CVE-2026-61554High· 7.5PoC
1w ago

emp3r0r is a C2 designed by Linux users for Linux environments

emp3r0r is a C2 designed by Linux users for Linux environments. Prior to version 4.2.5, the `http_poll` C2 transport accepts attacker-controlled HTTP polling sessions before CBOR `MsgAuth` authentication is completed. A remote unauthenti…

▾ Midnightjm33-m0 · github.com/jm33-m0/emp3r0r/coreEPSS 0.71%via NVD
GHSA-rf68-8gjr-36q7Low
1w ago

Nezha: OAuth2 redirect_uri Host header injection regression when dashboard_host is empty

Nezha: OAuth2 redirect_uri Host header injection regression when dashboard_host is empty

▾ Sunlitnezhahq · github.com/nezhahq/nezhavia OSV
CVE-2026-61544High· 8.2PoC
1w ago

libp2p-rust is the official Rust language implementation of the libp2p networking stack

libp2p-rust is the official Rust language implementation of the libp2p networking stack. Prior to 0.13.1, libp2p-quic could panic during an inbound QUIC handshake when a remote peer presented a valid short-lived libp2p TLS certificate an…

▾ Midnightlibp2p · rust-libp2pEPSS 0.28%via NVD
CVE-2026-32599Medium· 5.3
1w ago

Netmaker makes networks with WireGuard

Netmaker makes networks with WireGuard. Prior to version 1.5.0, the `sqliteDeleteRecord` function in Netmaker's database layer constructs SQL `DELETE` statements using direct string concatenation of user-supplied input. This allows an au…

▾ Sunlitgravitl · netmakerEPSS 0.36%via NVD
CVE-2026-63443High· 8.3
1w ago

Coder allows organizations to provision remote development environments via Terraform

Coder allows organizations to provision remote development environments via Terraform. Prior to 2.29.19, 2.32.9, 2.33.10, and 2.34.4, agentConn.apiClient() follows redirects while its custom transport accepts the host from the redirected…

▾ Twilightcoder · coderEPSS 0.76%via NVD
CVEs tagged “osv” — page 9 · VulnSea