Open Source Vulnerabilities

    Dashboard / Open Source Vulnerabilities

    CGA-69g3-j2f4-xv55
    No fix available
    Packages

    datadog-agent-7.82

    Summary

    Published
    10 Sept 2026
    Packages

    cryptography

    Summary

    CVE-2024-12797 in cryptography - Patched by Root

    Published
    10 Sept 2026
    Packages

    cryptography

    Summary

    CVE-2026-34073 in cryptography - Patched by Root

    Published
    10 Sept 2026
    Packages

    cryptography

    Summary

    CVE-2026-26007 in cryptography - Patched by Root

    Published
    10 Sept 2026
    CVE-2026-87803
    Fix available
    Packages

    Summary

    Published
    10 Sept 2026
    CGA-g93h-p62r-3j9p
    Fix available
    Packages

    harvester-webhook

    Summary

    Published
    10 Sept 2026
    CGA-crrh-32h4-657q
    No fix available
    Packages

    commercial-gitlab-rails-ee-fips-19.3

    Summary

    Published
    10 Sept 2026
    CGA-523c-qg8j-j2ff
    Fix available
    Packages

    teleport-17

    Summary

    Published
    10 Sept 2026
    CGA-g8xw-g5wc-f7xx
    Fix available
    Packages

    trivy-operator, trivy-operator

    Summary

    Published
    10 Sept 2026
    PYSEC-2026-3877
    Fix available
    Packages

    open-webui

    Summary

    Open WebUI: Any authenticated user can hang the server via message deletion in a cyclic chat tree

    Published
    10 Sept 2026
    PYSEC-2026-3878
    Fix available
    Packages

    open-webui

    Summary

    Open WebUI: Server-side fetches reach blocked and internal hosts via unvalidated HTTP redirect targets

    Published
    10 Sept 2026
    PYSEC-2026-3879
    Fix available
    Packages

    open-webui

    Summary

    Open WebUI: Any authenticated user can hang the server via a cyclic chat message history

    Published
    10 Sept 2026
    PYSEC-2026-3834
    Fix available
    Packages

    esphome-device-builder

    Summary

    ESPHome Device Builder Dashboard: Unauthenticated dashboard access via the HA add-on ingress site bound to all interfaces

    Published
    10 Sept 2026
    PYSEC-2026-3940
    Fix available
    Packages

    weasyprint

    Summary

    weasyprint Has Server-Side Request Forgery (SSRF)

    Published
    10 Sept 2026
    PYSEC-2026-3922
    Fix available
    Packages

    sqladmin

    Summary

    SQLAdmin: Unvalidated sortBy parameter in `ModelView` bypasses `column_sortable_list`

    Published
    10 Sept 2026
    PYSEC-2026-3835
    Fix available
    Packages

    githacker

    Summary

    GitHacker: Path traversal in ref/hash parsing enables existence oracle and hex-fragment exfiltration via malicious .git server

    Published
    10 Sept 2026
    PYSEC-2026-3944
    Fix available
    Packages

    winml-cli

    Summary

    Windows ML CLI: CORS misconfig enables localhost RCE

    Published
    10 Sept 2026
    PYSEC-2026-3846
    Fix available
    Packages

    httpx2

    Summary

    HTTPX2: Streaming response decompression does not bound peak memory (decompression amplification)

    Published
    10 Sept 2026
    PYSEC-2026-3849
    Fix available
    Packages

    httpx2

    Summary

    HTTPX2: Conflicting Content-Length and Transfer-Encoding headers can be auto-generated

    Published
    10 Sept 2026
    PYSEC-2026-3848
    Fix available
    Packages

    httpx2

    Summary

    HTTPX2: Multipart part header injection via unvalidated file Content-Type and custom headers

    Published
    10 Sept 2026
    PYSEC-2026-3847
    Fix available
    Packages

    httpx2

    Summary

    HTTPX2: Quadratic SSE line buffering can cause CPU denial of service

    Published
    10 Sept 2026
    PYSEC-2026-3845
    Fix available
    Packages

    httpx2

    Summary

    HTTPX2: Secure WebSocket traffic sent without TLS through SOCKS proxies

    Published
    10 Sept 2026
    PYSEC-2026-3844
    Fix available
    Packages

    httpcore2

    Summary

    HTTPX2: Secure WebSocket traffic sent without TLS through SOCKS proxies

    Published
    10 Sept 2026
    PYSEC-2026-3934
    Fix available
    Packages

    vllm

    Summary

    vLLM: SSRF + arbitrary local file read in MiMoV2OmniMultiModalProcessor `_fetch_image` and audio loader bypass MediaConnector protections

    Published
    10 Sept 2026
    PYSEC-2026-3935
    Fix available
    Packages

    vllm

    Summary

    vLLM: Cross-User Data Leak Vulnerability

    Published
    10 Sept 2026
    PYSEC-2026-3837
    Fix available
    Packages

    gitpython

    Summary

    GitPython: TagReference.create positional reference bypasses kwargs-only --file guard, enabling arbitrary file read (incomplete fix of 3af0c251)

    Published
    10 Sept 2026
    PYSEC-2026-3908
    Fix available
    Packages

    prowler-cloud

    Summary

    Prowler: Stored XSS in HTML reports through unescaped cloud resource tags

    Published
    10 Sept 2026
    PYSEC-2026-3907
    Fix available
    Packages

    prowler

    Summary

    Prowler: Stored XSS in HTML reports through unescaped cloud resource tags

    Published
    10 Sept 2026
    PYSEC-2026-3938
    Fix available
    Packages

    vllm

    Summary

    vLLM: Incomplete CVE-2025-62164 remediation can be bypassed by concurrent prompt parts

    Published
    10 Sept 2026
    PYSEC-2026-3933
    Fix available
    Packages

    vllm

    Summary

    vLLM: ReDoS via structured_outputs.regex in the lm-format-enforcer backend (no compile timeout) — missed sibling of GHSA-rwxx-mrjm-wc2m

    Published
    10 Sept 2026
    PYSEC-2026-3937
    Fix available
    Packages

    vllm

    Summary

    vLLM: Unauthenticated Internal Path and Username Disclosure via Validation Error Messages

    Published
    10 Sept 2026
    PYSEC-2026-3936
    Fix available
    Packages

    vllm

    Summary

    vLLM: Derender endpoints decode caller-supplied GenerateResponse token IDs without output bounds

    Published
    10 Sept 2026
    PYSEC-2026-3864
    Fix available
    Packages

    mkdocs-material

    Summary

    Material for MkDocs: DOM XSS in search suggestions via query parameter

    Published
    10 Sept 2026
    PYSEC-2026-3930
    Fix available
    Packages

    unstructured

    Summary

    unstructured: Server-Side Request Forgery in the URL-based partitioning

    Published
    10 Sept 2026
    PYSEC-2026-3918
    Fix available
    Packages

    scrapy

    Summary

    Scrapy: S3DownloadHandler sends signed S3 requests over plaintext HTTP by default

    Published
    10 Sept 2026
    PYSEC-2026-3873
    Fix available
    Packages

    omnigent

    Summary

    Omnigent Guardrail policy bypass: shell-command parser fails open in policies/builtins/_shell.py

    Published
    10 Sept 2026
    PYSEC-2026-3875
    Fix available
    Packages

    omnigent

    Summary

    Omnigent: Unvalidated os_env.cwd in agent bundle yields arbitrary host filesystem access on runners without OMNIGENT_RUNNER_WORKSPACE

    Published
    10 Sept 2026
    PYSEC-2026-3874
    Fix available
    Packages

    omnigent

    Summary

    Omnigent: Shared Agent Bundle Overwrite Leads to Authenticated Runner RCE

    Published
    10 Sept 2026
    PYSEC-2026-3872
    Fix available
    Packages

    omnigent

    Summary

    Omnigent: Uploaded Agent Bundle Allows Authenticated Runner RCE via Python Callable Tools

    Published
    10 Sept 2026
    PYSEC-2026-3863
    Fix available
    Packages

    mistune

    Summary

    Mistune: Denial of Service — RecursionError via Excessive Emphasis Markers in Markdown

    Published
    10 Sept 2026
    PYSEC-2026-3928
    Fix available
    Packages

    tornado

    Summary

    Tornado: Urlencoded body parsing omits max_num_fields, so one request can stall the event loop

    Published
    10 Sept 2026
    PYSEC-2026-3810
    Fix available
    Packages

    banks

    Summary

    Banks: Path traversal in `DirectoryPromptRegistry.set()` allows arbitrary file write outside the registry root

    Published
    10 Sept 2026
    PYSEC-2026-3912
    Fix available
    Packages

    pypdf

    Summary

    pypdf: Inefficient handling of non-whitespace inputs in read_until_whitespace

    Published
    10 Sept 2026
    PYSEC-2026-3871
    Fix available
    Packages

    nltk

    Summary

    NLTK: Quadratic CPU Exhaustion in `XMLCorpusView._read_xml_fragment()`

    Published
    10 Sept 2026
    PYSEC-2026-3869
    Fix available
    Packages

    nltk

    Summary

    NLTK: Uncontrolled resource consumption in RecursiveDescentParser via ambiguous or left-recursive grammars

    Published
    10 Sept 2026
    PYSEC-2026-3910
    Fix available
    Packages

    pypdf

    Summary

    pypdf: Possible long runtimes/large memory usage when retrieving outlines

    Published
    10 Sept 2026
    PYSEC-2026-3911
    Fix available
    Packages

    pypdf

    Summary

    pypdf: Possible long runtimes/large memory usage when extracting XForm objects

    Published
    10 Sept 2026
    PYSEC-2026-3913
    Fix available
    Packages

    pypdf

    Summary

    pypdf: Possible infinite loop for TreeObject.insert_child

    Published
    10 Sept 2026
    PYSEC-2026-3923
    Fix available
    Packages

    sqlparse

    Summary

    sqlparse: Reindentation of tuple lists causes near-cap quadratic CPU consumption

    Published
    10 Sept 2026
    PYSEC-2026-3868
    Fix available
    Packages

    nltk

    Summary

    NLTK: Uncontrolled search path when invoking the Graphviz 'dot' binary

    Published
    10 Sept 2026