Open Source Vulnerabilities
cryptography
CVE-2024-12797 in cryptography - Patched by Root
cryptography
CVE-2024-12797 in cryptography - Patched by Root
cryptography
CVE-2026-34073 in cryptography - Patched by Root
cryptography
CVE-2026-34073 in cryptography - Patched by Root
cryptography
CVE-2026-26007 in cryptography - Patched by Root
cryptography
CVE-2026-26007 in cryptography - Patched by Root
commercial-gitlab-rails-ee-fips-19.3
open-webui
Open WebUI: Any authenticated user can hang the server via message deletion in a cyclic chat tree
open-webui
Open WebUI: Any authenticated user can hang the server via message deletion in a cyclic chat tree
open-webui
Open WebUI: Server-side fetches reach blocked and internal hosts via unvalidated HTTP redirect targets
open-webui
Open WebUI: Server-side fetches reach blocked and internal hosts via unvalidated HTTP redirect targets
open-webui
Open WebUI: Any authenticated user can hang the server via a cyclic chat message history
open-webui
Open WebUI: Any authenticated user can hang the server via a cyclic chat message history
esphome-device-builder
ESPHome Device Builder Dashboard: Unauthenticated dashboard access via the HA add-on ingress site bound to all interfaces
esphome-device-builder
ESPHome Device Builder Dashboard: Unauthenticated dashboard access via the HA add-on ingress site bound to all interfaces
weasyprint
weasyprint Has Server-Side Request Forgery (SSRF)
sqladmin
SQLAdmin: Unvalidated sortBy parameter in `ModelView` bypasses `column_sortable_list`
sqladmin
SQLAdmin: Unvalidated sortBy parameter in `ModelView` bypasses `column_sortable_list`
githacker
GitHacker: Path traversal in ref/hash parsing enables existence oracle and hex-fragment exfiltration via malicious .git server
githacker
GitHacker: Path traversal in ref/hash parsing enables existence oracle and hex-fragment exfiltration via malicious .git server
winml-cli
Windows ML CLI: CORS misconfig enables localhost RCE
winml-cli
Windows ML CLI: CORS misconfig enables localhost RCE
httpx2
HTTPX2: Streaming response decompression does not bound peak memory (decompression amplification)
httpx2
HTTPX2: Streaming response decompression does not bound peak memory (decompression amplification)
httpx2
HTTPX2: Conflicting Content-Length and Transfer-Encoding headers can be auto-generated
httpx2
HTTPX2: Conflicting Content-Length and Transfer-Encoding headers can be auto-generated
httpx2
HTTPX2: Multipart part header injection via unvalidated file Content-Type and custom headers
httpx2
HTTPX2: Multipart part header injection via unvalidated file Content-Type and custom headers
httpx2
HTTPX2: Quadratic SSE line buffering can cause CPU denial of service
httpx2
HTTPX2: Quadratic SSE line buffering can cause CPU denial of service
httpx2
HTTPX2: Secure WebSocket traffic sent without TLS through SOCKS proxies
httpx2
HTTPX2: Secure WebSocket traffic sent without TLS through SOCKS proxies
httpcore2
HTTPX2: Secure WebSocket traffic sent without TLS through SOCKS proxies
httpcore2
HTTPX2: Secure WebSocket traffic sent without TLS through SOCKS proxies
vllm
vLLM: SSRF + arbitrary local file read in MiMoV2OmniMultiModalProcessor `_fetch_image` and audio loader bypass MediaConnector protections
vllm
vLLM: SSRF + arbitrary local file read in MiMoV2OmniMultiModalProcessor `_fetch_image` and audio loader bypass MediaConnector protections
vllm
vLLM: Cross-User Data Leak Vulnerability
gitpython
GitPython: TagReference.create positional reference bypasses kwargs-only --file guard, enabling arbitrary file read (incomplete fix of 3af0c251)
gitpython
GitPython: TagReference.create positional reference bypasses kwargs-only --file guard, enabling arbitrary file read (incomplete fix of 3af0c251)
prowler-cloud
Prowler: Stored XSS in HTML reports through unescaped cloud resource tags
prowler-cloud
Prowler: Stored XSS in HTML reports through unescaped cloud resource tags
prowler
Prowler: Stored XSS in HTML reports through unescaped cloud resource tags
prowler
Prowler: Stored XSS in HTML reports through unescaped cloud resource tags
vllm
vLLM: Incomplete CVE-2025-62164 remediation can be bypassed by concurrent prompt parts
vllm
vLLM: Incomplete CVE-2025-62164 remediation can be bypassed by concurrent prompt parts
vllm
vLLM: ReDoS via structured_outputs.regex in the lm-format-enforcer backend (no compile timeout) — missed sibling of GHSA-rwxx-mrjm-wc2m
vllm
vLLM: ReDoS via structured_outputs.regex in the lm-format-enforcer backend (no compile timeout) — missed sibling of GHSA-rwxx-mrjm-wc2m
vllm
vLLM: Unauthenticated Internal Path and Username Disclosure via Validation Error Messages
vllm
vLLM: Unauthenticated Internal Path and Username Disclosure via Validation Error Messages
vllm
vLLM: Derender endpoints decode caller-supplied GenerateResponse token IDs without output bounds
vllm
vLLM: Derender endpoints decode caller-supplied GenerateResponse token IDs without output bounds
mkdocs-material
Material for MkDocs: DOM XSS in search suggestions via query parameter
mkdocs-material
Material for MkDocs: DOM XSS in search suggestions via query parameter
unstructured
unstructured: Server-Side Request Forgery in the URL-based partitioning
unstructured
unstructured: Server-Side Request Forgery in the URL-based partitioning
scrapy
Scrapy: S3DownloadHandler sends signed S3 requests over plaintext HTTP by default
scrapy
Scrapy: S3DownloadHandler sends signed S3 requests over plaintext HTTP by default
omnigent
Omnigent Guardrail policy bypass: shell-command parser fails open in policies/builtins/_shell.py
omnigent
Omnigent Guardrail policy bypass: shell-command parser fails open in policies/builtins/_shell.py
omnigent
Omnigent: Unvalidated os_env.cwd in agent bundle yields arbitrary host filesystem access on runners without OMNIGENT_RUNNER_WORKSPACE
omnigent
Omnigent: Unvalidated os_env.cwd in agent bundle yields arbitrary host filesystem access on runners without OMNIGENT_RUNNER_WORKSPACE
omnigent
Omnigent: Shared Agent Bundle Overwrite Leads to Authenticated Runner RCE
omnigent
Omnigent: Shared Agent Bundle Overwrite Leads to Authenticated Runner RCE
omnigent
Omnigent: Uploaded Agent Bundle Allows Authenticated Runner RCE via Python Callable Tools
omnigent
Omnigent: Uploaded Agent Bundle Allows Authenticated Runner RCE via Python Callable Tools
mistune
Mistune: Denial of Service — RecursionError via Excessive Emphasis Markers in Markdown
mistune
Mistune: Denial of Service — RecursionError via Excessive Emphasis Markers in Markdown
tornado
Tornado: Urlencoded body parsing omits max_num_fields, so one request can stall the event loop
tornado
Tornado: Urlencoded body parsing omits max_num_fields, so one request can stall the event loop
banks
Banks: Path traversal in `DirectoryPromptRegistry.set()` allows arbitrary file write outside the registry root
banks
Banks: Path traversal in `DirectoryPromptRegistry.set()` allows arbitrary file write outside the registry root
pypdf
pypdf: Inefficient handling of non-whitespace inputs in read_until_whitespace
pypdf
pypdf: Inefficient handling of non-whitespace inputs in read_until_whitespace
nltk
NLTK: Quadratic CPU Exhaustion in `XMLCorpusView._read_xml_fragment()`
nltk
NLTK: Quadratic CPU Exhaustion in `XMLCorpusView._read_xml_fragment()`
nltk
NLTK: Uncontrolled resource consumption in RecursiveDescentParser via ambiguous or left-recursive grammars
nltk
NLTK: Uncontrolled resource consumption in RecursiveDescentParser via ambiguous or left-recursive grammars
pypdf
pypdf: Possible long runtimes/large memory usage when retrieving outlines
pypdf
pypdf: Possible long runtimes/large memory usage when retrieving outlines
pypdf
pypdf: Possible long runtimes/large memory usage when extracting XForm objects
pypdf
pypdf: Possible long runtimes/large memory usage when extracting XForm objects
pypdf
pypdf: Possible infinite loop for TreeObject.insert_child
pypdf
pypdf: Possible infinite loop for TreeObject.insert_child
sqlparse
sqlparse: Reindentation of tuple lists causes near-cap quadratic CPU consumption
sqlparse
sqlparse: Reindentation of tuple lists causes near-cap quadratic CPU consumption
nltk
NLTK: Uncontrolled search path when invoking the Graphviz 'dot' binary
nltk
NLTK: Uncontrolled search path when invoking the Graphviz 'dot' binary
