Tagged “osv”
CVEs tagged osv, newest first.
5710 CVEsRSS
CVE-2026-23877MediumSwing Music has a Directory Traversal & Filesystem can be accessed by a non-admin user
Swing Music has a Directory Traversal & Filesystem can be accessed by a non-admin user
CVE-2026-23996Low· 3.7FastAPI Api Key has a timing side-channel in verify_key that allows statistical key validity detection
FastAPI Api Key has a timing side-channel in verify_key that allows statistical key validity detection
CVE-2026-23833MediumESPHome vulnerable to denial-of-service via out-of-bounds check bypass in the API component
ESPHome vulnerable to denial-of-service via out-of-bounds check bypass in the API component
CVE-2026-23986High· 7.1Copier safe template has arbitrary filesystem write access via directory symlinks when _preserve_symlinks: true
Copier safe template has arbitrary filesystem write access via directory symlinks when _preserve_symlinks: true
CVE-2026-23946Medium· 6.8Tendenci Affected by Authenticated Remote Code Execution via Pickle Deserialization
Tendenci Affected by Authenticated Remote Code Execution via Pickle Deserialization
CVE-2026-22807High· 8.8PoCvLLM is an inference and serving engine for large language models (LLMs)
vLLM is an inference and serving engine for large language models (LLMs). Starting in version 0.10.1 and prior to version 0.14.0, vLLM loads Hugging Face `auto_map` dynamic modules during model resolution without gating on `trust_remote_…
CVE-2026-23644Highesm.sh has a path traversal in extractPackageTarball enables file writes from malicious packages
esm.sh has a path traversal in extractPackageTarball enables file writes from malicious packages
CVE-2026-23842High· 7.5PoCChatterBot Vulnerable to Denial of Service via Database Connection Pool Exhaustion
ChatterBot Vulnerable to Denial of Service via Database Connection Pool Exhaustion
CVE-2026-22219High· 7.7Chainlit contain a server-side request forgery (SSRF) vulnerability
Chainlit contain a server-side request forgery (SSRF) vulnerability
MAL-2026-326NoneMalicious code in urlssser (PyPI)
Malicious code in urlssser (PyPI)
MAL-2026-325NoneMalicious code in marshel (PyPI)
Malicious code in marshel (PyPI)
CVE-2025-68675High· 7.5Apache Airflow proxy credentials for various providers might leak in task logs
Apache Airflow proxy credentials for various providers might leak in task logs
CVE-2025-68438High· 7.5Apache Airflow secrets in rendered templates could contain parts of sensitive values when truncated
Apache Airflow secrets in rendered templates could contain parts of sensitive values when truncated
CVE-2026-23528MediumDask Distributed is Vulnerable to Remote Code Execution via Jupyter Proxy and Dashboard
Dask Distributed is Vulnerable to Remote Code Execution via Jupyter Proxy and Dashboard
CVE-2026-23535High· 8.0Weblate wlc path traversal vulnerability: Unsanitized API slugs in download command
Weblate wlc path traversal vulnerability: Unsanitized API slugs in download command
CVE-2026-23490High· 7.5PoCpyasn1 is a generic ASN.1 library for Python
pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.2, a Denial-of-Service issue has been found that leads to memory exhaustion from malformed RELATIVE-OID with excessive continuation octets. This vulnerability is fixed in 0.6.2.
CVE-2026-23519HighRustCrypto Utilities cmov: `thumbv6m-none-eabi` compiler emits non-constant time assembly when using `cmovnz`
RustCrypto Utilities cmov: `thumbv6m-none-eabi` compiler emits non-constant time assembly when using `cmovnz`
CVE-2025-69725Medium· 4.7chi has an open redirect vulnerability in the RedirectSlashes middleware
chi has an open redirect vulnerability in the RedirectSlashes middleware
CVE-2025-68492Medium· 4.2Chainlit contains an authorization bypass vulnerability
Chainlit contains an authorization bypass vulnerability
CVE-2026-22779MediumBlackSheep's ClientSession is vulnerable to CRLF injection
BlackSheep's ClientSession is vulnerable to CRLF injection
CVE-2026-21889LowWeblate leaks information via screenshots
Weblate leaks information via screenshots
CVE-2026-22772Medium· 5.8Fulcio is vulnerable to Server-Side Request Forgery (SSRF) via MetaIssuer Regex Bypass
Fulcio is vulnerable to Server-Side Request Forgery (SSRF) via MetaIssuer Regex Bypass
CVE-2026-22871HighGuardDog Path Traversal Vulnerability Leads to Arbitrary File Overwrite and RCE
GuardDog Path Traversal Vulnerability Leads to Arbitrary File Overwrite and RCE
CVE-2026-21226High· 7.5Azure Core is vulnerable to deserialization of untrusted data
Azure Core is vulnerable to deserialization of untrusted data
CVE-2026-22798Medium· 5.9hermes's raw options logging may disclose secrets passed in via subcommand options argument
hermes's raw options logging may disclose secrets passed in via subcommand options argument
CVE-2026-22870HighGuardDog Zip Bomb Vulnerability in safe_extract() Allows DoS
GuardDog Zip Bomb Vulnerability in safe_extract() Allows DoS
CVE-2026-22702Medium· 4.5virtualenv Has TOCTOU Vulnerabilities in Directory Creation
virtualenv Has TOCTOU Vulnerabilities in Directory Creation
CVE-2026-23949High· 8.6jaraco.context Has a Path Traversal Vulnerability
jaraco.context Has a Path Traversal Vulnerability
CVE-2026-22777High· 7.5PoCComfyUI-Manager is Vulnerable to CRLF Injection in Configuration Handler
ComfyUI-Manager is Vulnerable to CRLF Injection in Configuration Handler
MAL-2026-237NoneMalicious code in formater (PyPI)
Malicious code in formater (PyPI)