Open Source Vulnerabilities

    Dashboard / Open Source Vulnerabilities

    PYSEC-2026-3934
    Fix available
    Packages

    vllm

    Summary

    vLLM: SSRF + arbitrary local file read in MiMoV2OmniMultiModalProcessor `_fetch_image` and audio loader bypass MediaConnector protections

    Published
    10 Sept 2026
    PYSEC-2026-3935
    Fix available
    Packages

    vllm

    Summary

    vLLM: Cross-User Data Leak Vulnerability

    Published
    10 Sept 2026
    PYSEC-2026-3837
    Fix available
    Packages

    gitpython

    Summary

    GitPython: TagReference.create positional reference bypasses kwargs-only --file guard, enabling arbitrary file read (incomplete fix of 3af0c251)

    Published
    10 Sept 2026
    PYSEC-2026-3908
    Fix available
    Packages

    prowler-cloud

    Summary

    Prowler: Stored XSS in HTML reports through unescaped cloud resource tags

    Published
    10 Sept 2026
    PYSEC-2026-3907
    Fix available
    Packages

    prowler

    Summary

    Prowler: Stored XSS in HTML reports through unescaped cloud resource tags

    Published
    10 Sept 2026
    PYSEC-2026-3938
    Fix available
    Packages

    vllm

    Summary

    vLLM: Incomplete CVE-2025-62164 remediation can be bypassed by concurrent prompt parts

    Published
    10 Sept 2026
    PYSEC-2026-3933
    Fix available
    Packages

    vllm

    Summary

    vLLM: ReDoS via structured_outputs.regex in the lm-format-enforcer backend (no compile timeout) — missed sibling of GHSA-rwxx-mrjm-wc2m

    Published
    10 Sept 2026
    PYSEC-2026-3937
    Fix available
    Packages

    vllm

    Summary

    vLLM: Unauthenticated Internal Path and Username Disclosure via Validation Error Messages

    Published
    10 Sept 2026
    PYSEC-2026-3936
    Fix available
    Packages

    vllm

    Summary

    vLLM: Derender endpoints decode caller-supplied GenerateResponse token IDs without output bounds

    Published
    10 Sept 2026
    PYSEC-2026-3864
    Fix available
    Packages

    mkdocs-material

    Summary

    Material for MkDocs: DOM XSS in search suggestions via query parameter

    Published
    10 Sept 2026
    PYSEC-2026-3930
    Fix available
    Packages

    unstructured

    Summary

    unstructured: Server-Side Request Forgery in the URL-based partitioning

    Published
    10 Sept 2026
    PYSEC-2026-3918
    Fix available
    Packages

    scrapy

    Summary

    Scrapy: S3DownloadHandler sends signed S3 requests over plaintext HTTP by default

    Published
    10 Sept 2026
    PYSEC-2026-3873
    Fix available
    Packages

    omnigent

    Summary

    Omnigent Guardrail policy bypass: shell-command parser fails open in policies/builtins/_shell.py

    Published
    10 Sept 2026
    PYSEC-2026-3875
    Fix available
    Packages

    omnigent

    Summary

    Omnigent: Unvalidated os_env.cwd in agent bundle yields arbitrary host filesystem access on runners without OMNIGENT_RUNNER_WORKSPACE

    Published
    10 Sept 2026
    PYSEC-2026-3874
    Fix available
    Packages

    omnigent

    Summary

    Omnigent: Shared Agent Bundle Overwrite Leads to Authenticated Runner RCE

    Published
    10 Sept 2026
    PYSEC-2026-3872
    Fix available
    Packages

    omnigent

    Summary

    Omnigent: Uploaded Agent Bundle Allows Authenticated Runner RCE via Python Callable Tools

    Published
    10 Sept 2026
    PYSEC-2026-3863
    Fix available
    Packages

    mistune

    Summary

    Mistune: Denial of Service — RecursionError via Excessive Emphasis Markers in Markdown

    Published
    10 Sept 2026
    PYSEC-2026-3928
    Fix available
    Packages

    tornado

    Summary

    Tornado: Urlencoded body parsing omits max_num_fields, so one request can stall the event loop

    Published
    10 Sept 2026
    PYSEC-2026-3810
    Fix available
    Packages

    banks

    Summary

    Banks: Path traversal in `DirectoryPromptRegistry.set()` allows arbitrary file write outside the registry root

    Published
    10 Sept 2026
    PYSEC-2026-3912
    Fix available
    Packages

    pypdf

    Summary

    pypdf: Inefficient handling of non-whitespace inputs in read_until_whitespace

    Published
    10 Sept 2026
    PYSEC-2026-3871
    Fix available
    Packages

    nltk

    Summary

    NLTK: Quadratic CPU Exhaustion in `XMLCorpusView._read_xml_fragment()`

    Published
    10 Sept 2026
    PYSEC-2026-3869
    Fix available
    Packages

    nltk

    Summary

    NLTK: Uncontrolled resource consumption in RecursiveDescentParser via ambiguous or left-recursive grammars

    Published
    10 Sept 2026
    PYSEC-2026-3910
    Fix available
    Packages

    pypdf

    Summary

    pypdf: Possible long runtimes/large memory usage when retrieving outlines

    Published
    10 Sept 2026
    PYSEC-2026-3911
    Fix available
    Packages

    pypdf

    Summary

    pypdf: Possible long runtimes/large memory usage when extracting XForm objects

    Published
    10 Sept 2026
    PYSEC-2026-3913
    Fix available
    Packages

    pypdf

    Summary

    pypdf: Possible infinite loop for TreeObject.insert_child

    Published
    10 Sept 2026
    PYSEC-2026-3923
    Fix available
    Packages

    sqlparse

    Summary

    sqlparse: Reindentation of tuple lists causes near-cap quadratic CPU consumption

    Published
    10 Sept 2026
    PYSEC-2026-3868
    Fix available
    Packages

    nltk

    Summary

    NLTK: Uncontrolled search path when invoking the Graphviz 'dot' binary

    Published
    10 Sept 2026
    PYSEC-2026-3827
    Fix available
    Packages

    djangorestframework

    Summary

    Django REST framework: Potential bypass of Django `DATA_UPLOAD_MAX_MEMORY_SIZE` when parsing oversized JSON and urlencoded request bodies via DRF `request.data`

    Published
    10 Sept 2026
    PYSEC-2026-3828
    Fix available
    Packages

    djangorestframework

    Summary

    Django REST framework: AdminRenderer may disclose GET-protected data when rendering invalid write requests

    Published
    10 Sept 2026
    PYSEC-2026-3917
    Fix available
    Packages

    restrictedpython

    Summary

    RestrictedPython guard hooks can be shadowed via positional-only arguments

    Published
    10 Sept 2026
    PYSEC-2026-3883
    Fix available
    Packages

    plone-app-event

    Summary

    plone.app.event vulnerable to denial of service via iCalendar import

    Published
    10 Sept 2026
    PYSEC-2026-3942
    Fix available
    Packages

    weblate

    Summary

    Weblate has IDOR in GroupViewSet that allows authenticated project manager to gain unauthorized read access to any private project

    Published
    10 Sept 2026
    PYSEC-2026-3941
    Fix available
    Packages

    weblate

    Summary

    Private Weblate projects vulnerable to observable object existence disclosure via globally scoped object lookups

    Published
    10 Sept 2026
    PYSEC-2026-3906
    Fix available
    Packages

    protego

    Summary

    Protego has exponential backtracking ReDoS in robots.txt URL wildcard matching

    Published
    10 Sept 2026
    PYSEC-2026-3884
    Fix available
    Packages

    plone-app-portlets

    Summary

    plone.app.portlets vulnerable to denial of service via RSS feed portlet

    Published
    10 Sept 2026
    PYSEC-2026-3882
    Fix available
    Packages

    piccolo-admin

    Summary

    piccolo-admin has a privilege escalation issue - admin to superuser via session-token disclosure in GET /api/tables/sessions/.

    Published
    10 Sept 2026
    PYSEC-2026-3945
    Fix available
    Packages

    wsgidav

    Summary

    WsgiDAV MySQL provider has a blind SQL injection

    Published
    10 Sept 2026
    PYSEC-2026-3817
    Fix available
    Packages

    compliance-trestle

    Summary

    Trestle has Server-Side Template Injection (SSTI) via Recursive Template Re-evaluation of Untrusted Data

    Published
    10 Sept 2026
    PYSEC-2026-3805
    Fix available
    Packages

    aiosmtplib

    Summary

    aiosmtplib: STARTTLS response injection

    Published
    10 Sept 2026
    PYSEC-2026-3943
    Fix available
    Packages

    webob

    Summary

    WebOb: Open redirect in Location header normalization via leading C0 control / space characters

    Published
    10 Sept 2026
    PYSEC-2026-3861
    Fix available
    Packages

    litellm

    Summary

    LiteLLM vulnerable to server-side template injection in the /prompts/test endpoint

    Published
    10 Sept 2026
    PYSEC-2026-3808
    Fix available
    Packages

    asyncssh

    Summary

    asyncssh has SCP Path Traversal to Arbitrary File Write

    Published
    10 Sept 2026
    PYSEC-2026-3809
    Fix available
    Packages

    asyncssh

    Summary

    asyncssh has an incomplete fix for CVE-2026-45309 — AuthorizedKeysFile %u still escapes the intended directory via a leading ~ (and weakly via ${ENV}) username substitution

    Published
    10 Sept 2026
    PYSEC-2026-3919
    No fix available
    Packages

    senaite-core

    Summary

    senaite.core Vulnerable to Eval Injection and Missing Authorization

    Published
    10 Sept 2026
    PYSEC-2026-3855
    Fix available
    Packages

    kas

    Summary

    kas Persistently Disables SSH Host Key Checking

    Published
    10 Sept 2026
    PYSEC-2026-3924
    Fix available
    Packages

    starlette-admin

    Summary

    Starlette-Admin's unvalidated `order_by` parameter allows ordering by hidden columns (info-exposure oracle) and HTTP 500 DoS

    Published
    10 Sept 2026
    PYSEC-2026-3853
    Fix available
    Packages

    jupyterhub

    Summary

    JupyterHub has Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login

    Published
    10 Sept 2026
    PYSEC-2026-3851
    Fix available
    Packages

    icalendar

    Summary

    icalendar has Algorithmic Complexity in Equality

    Published
    10 Sept 2026
    PYSEC-2026-3811
    Fix available
    Packages

    chainlit

    Summary

    Chainlist has SSRF via MCP SSE and streamable-http transports that allows unauthenticated internal network access

    Published
    10 Sept 2026
    PYSEC-2026-3812
    Fix available
    Packages

    chainlit

    Summary

    Chainlit has command injection via MCP stdio transport that allows unauthenticated remote code execution

    Published
    10 Sept 2026