Tagged “osv”
CVEs tagged osv, newest first.
5712 CVEsRSS
MAL-2026-236NoneMalicious code in graponater (PyPI)
Malicious code in graponater (PyPI)
CVE-2025-14279High· 8.1MLFlow is vulnerable to DNS rebinding attacks due to a lack of Origin header validation
MLFlow is vulnerable to DNS rebinding attacks due to a lack of Origin header validation
CVE-2026-22251Medium· 5.3Weblate wlc has insecure API key configuration
Weblate wlc has insecure API key configuration
CVE-2026-22033HighLabel Studio is vulnerable to full account takeover by chaining Stored XSS + IDOR in User Profile via custom_hotkeys field
Label Studio is vulnerable to full account takeover by chaining Stored XSS + IDOR in User Profile via custom_hotkeys field
CVE-2026-22250Low· 2.5Weblate command-line client susceptible to SSL verification skip
Weblate command-line client susceptible to SSL verification skip
CVE-2025-15506Low· 3.3AcademySoftwareFoundation OpenColorIO has an out-of-bounds vulnerability
AcademySoftwareFoundation OpenColorIO has an out-of-bounds vulnerability
CVE-2026-22703Medium· 5.5github.com/sigstore/cosign: Cosign verification accepts any valid Rekor entry under certain conditions (CVE-2026-22703)
A data verification flaw has been discovered in the golang cosign library. A Cosign bundle can be crafted to successfully verify an artifact even if the embedded Rekor entry does not reference the artifact's digest, signature or public key…
CVE-2026-22701Medium· 5.3filelock: filelock Time-of-Check-Time-of-Use (TOCTOU) in SoftFileLock (CVE-2026-22701)
A Time-of-Check-Time-of-Use (TOCTOU) flaw has been discovered in the pypi filelock package. The TOCTOU race condition vulnerability exists in the SoftFileLock implementation of the filelock package. An attacker with local filesystem access…
CVE-2025-15504Low· 3.3LIEF is vulnerable to segmentation fault
LIEF is vulnerable to segmentation fault
CVE-2026-22606HighFickling has a bypass via runpy.run_path() and runpy.run_module()
Fickling has a bypass via runpy.run_path() and runpy.run_module()
CVE-2026-22609HighFickling has Static Analysis Bypass via Incomplete Dangerous Module Blocklist
Fickling has Static Analysis Bypass via Incomplete Dangerous Module Blocklist
CVE-2026-22607HighFickling Blocklist Bypass: cProfile.run()
Fickling Blocklist Bypass: cProfile.run()
CVE-2026-22612HighFickling vulnerable to detection bypass due to "builtins" blindness
Fickling vulnerable to detection bypass due to "builtins" blindness
CVE-2026-22608HighFickling vulnerable to use of ctypes and pydoc gadget chain to bypass detection
Fickling vulnerable to use of ctypes and pydoc gadget chain to bypass detection
CVE-2026-22690Lowpypdf has possible long runtimes for missing /Root object with large /Size values
pypdf has possible long runtimes for missing /Root object with large /Size values
CVE-2026-22691Lowpypdf has possible long runtimes for malformed startxref
pypdf has possible long runtimes for malformed startxref
CVE-2025-68151MediumCoreDNS gRPC/HTTPS/HTTP3 servers lack resource limits, enabling DoS via unbounded connections and oversized messages
CoreDNS gRPC/HTTPS/HTTP3 servers lack resource limits, enabling DoS via unbounded connections and oversized messages
CVE-2023-7333Medium· 5.3records-mover Injection vulnerability
records-mover Injection vulnerability
CVE-2026-21874Medium· 5.3NiceGUI has Redis connection leak via tab storage causes service degradation
NiceGUI has Redis connection leak via tab storage causes service degradation
CVE-2026-21873High· 7.2NiceGUI apps which use `ui.sub_pages` vulnerable to zero-click XSS
NiceGUI apps which use `ui.sub_pages` vulnerable to zero-click XSS
CVE-2026-21872Medium· 6.1NiceGUI apps are vulnerable to XSS which uses `ui.sub_pages` and render arbitrary user-provided links
NiceGUI apps are vulnerable to XSS which uses `ui.sub_pages` and render arbitrary user-provided links
CVE-2025-68158Medium· 5.7Authlib has 1-click Account Takeover vulnerability
Authlib has 1-click Account Takeover vulnerability
CVE-2026-53872High· 7.5picklescan has Arbitrary file read using `io.FileIO`
picklescan has Arbitrary file read using `io.FileIO`
CVE-2026-21860Medium· 5.3Werkzeug safe_join() allows Windows special device names with compound extensions
Werkzeug safe_join() allows Windows special device names with compound extensions
CVE-2026-21871Medium· 6.1NiceGUI is vulnerable to XSS via Unescaped URL in ui.navigate.history.push() / replace()
NiceGUI is vulnerable to XSS via Unescaped URL in ui.navigate.history.push() / replace()
CVE-2025-61782Medium· 6.1OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to version 6.8.3, an open redi…
OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to version 6.8.3, an open redirect vulnerability exists in the OpenCTI platform's SAML authentication endpoint (/auth/saml/callbac…
CVE-2026-22041Lowloggingredactor converts non-string types to string types in logs
loggingredactor converts non-string types to string types in logs
CVE-2026-21441High· 7.5urllib3 is an HTTP client library for Python
urllib3 is an HTTP client library for Python. urllib3's streaming API is designed for the efficient handling of large HTTP responses by reading the content in chunks, rather than loading the entire response body into memory at once. urll…
MAL-2026-96NoneMalicious code in pycolorom (PyPI)
Malicious code in pycolorom (PyPI)
CVE-2025-69230Medium· 5.3AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. In versions 3.13.2 and below, reading multiple invalid cookies can lead to a logging storm. If the cookies attribute is accessed in an application, then an a…