Vulnerabilities
Recent vulnerabilities
Recent vulnerabilities from
Select from 81 available sources using the dropdown above.
OSV Homebrew πΊ is not individually searchable yet β the search will cover the sources available on the search page.
| ID | Description | Published | Updated |
|---|---|---|---|
| brew-vdirsyncer-cve-2026-49265 | Oauthlib: Timing Attack Vulnerability in PKCE code_verifier Comparison (CWE-208) | 2026-09-30T21:43:26Z | 2026-10-02T21:08:48Z |
| brew-vdirsyncer-cve-2026-49264 | Oauthlib : Unsafe JSONP callback injection in RevocationEndpoint allows arbitrary JavaScript response generation | 2026-09-30T21:43:26Z | 2026-10-02T21:08:48Z |
| brew-legit-cve-2026-87819 | GitPython: Denial of Service via catastrophic backtracking (ReDoS) in Actor.name_email_regex β commit author/committer field parsing | 2026-09-30T21:16:48Z | 2026-10-02T21:08:48Z |
| brew-legit-cve-2026-87817 | GitPython: Repository content can impersonate the git directory, leading to arbitrary code execution | 2026-09-30T21:16:48Z | 2026-10-02T21:08:48Z |
| brew-legit-cve-2026-78679 | GitPython: TagReference.create positional reference bypasses kwargs-only --file guard, enabling arbitrary file read (incomplete fix of 3af0c251) | 2026-09-30T21:16:48Z | 2026-10-02T21:08:48Z |
| brew-gitup-cve-2026-87819 | GitPython: Denial of Service via catastrophic backtracking (ReDoS) in Actor.name_email_regex β commit author/committer field parsing | 2026-09-30T18:47:21Z | 2026-10-02T21:08:48Z |
| brew-gitup-cve-2026-87817 | GitPython: Repository content can impersonate the git directory, leading to arbitrary code execution | 2026-09-30T18:47:21Z | 2026-10-02T21:08:48Z |
| brew-waybackpy-cve-2026-97688 | urllib3: Chunked Deflate streaming can enter an infinite loop | 2026-09-30T21:47:03Z | 2026-10-02T11:40:24Z |
| brew-watson-cve-2026-97687 | urllib3: HTTPS proxy TLS configuration may be ignored or overridden | 2026-09-30T21:46:45Z | 2026-10-02T11:37:44Z |
| brew-vdirsyncer-cve-2026-97689 | urllib3: HTTPResponse.stream()/read_chunked() buffers an unbounded chunk-size line into memory | 2026-09-30T21:43:26Z | 2026-10-02T11:35:39Z |
| brew-vdirsyncer-cve-2026-97688 | urllib3: Chunked Deflate streaming can enter an infinite loop | 2026-09-30T21:43:26Z | 2026-10-02T11:35:39Z |
| brew-vdirsyncer-cve-2026-97687 | urllib3: HTTPS proxy TLS configuration may be ignored or overridden | 2026-09-30T21:43:26Z | 2026-10-02T11:35:39Z |
| brew-snakemake-cve-2026-97688 | urllib3: Chunked Deflate streaming can enter an infinite loop | 2026-09-30T21:33:39Z | 2026-10-02T11:24:17Z |
| brew-snakemake-cve-2026-97687 | urllib3: HTTPS proxy TLS configuration may be ignored or overridden | 2026-09-30T21:33:39Z | 2026-10-02T11:24:17Z |
| brew-parliament-cve-2026-97689 | urllib3: HTTPResponse.stream()/read_chunked() buffers an unbounded chunk-size line into memory | 2026-09-30T21:25:53Z | 2026-10-02T11:14:40Z |
| brew-parliament-cve-2026-97688 | urllib3: Chunked Deflate streaming can enter an infinite loop | 2026-09-30T21:25:53Z | 2026-10-02T11:14:40Z |
| brew-parliament-cve-2026-97687 | urllib3: HTTPS proxy TLS configuration may be ignored or overridden | 2026-09-30T21:25:53Z | 2026-10-02T11:14:40Z |
| brew-moto-cve-2026-97688 | urllib3: Chunked Deflate streaming can enter an infinite loop | 2026-09-30T21:22:03Z | 2026-10-02T11:09:56Z |
| brew-mlx-lm-cve-2026-9856 | Transformers save_pretrained path traversal allows arbitrary file writes through chat template names | 2026-09-02T09:23:51Z | 2026-10-02T11:08:29Z |
| brew-mlx-lm-cve-2026-80047 | Hugging Face Transformers downloads custom generation code before trust consent | 2026-10-01T11:27:48Z | 2026-10-02T11:08:29Z |
| brew-mlx-lm-cve-2025-14930 | 2026-08-13T17:14:17Z | 2026-10-02T11:08:29Z | |
| brew-mlx-lm-cve-2025-14929 | 2026-08-13T17:14:17Z | 2026-10-02T11:08:29Z | |
| brew-mlx-lm-cve-2025-14928 | 2026-08-13T17:14:17Z | 2026-10-02T11:08:29Z | |
| brew-mlx-lm-cve-2025-14927 | 2026-08-13T17:14:17Z | 2026-10-02T11:08:29Z | |
| brew-mlx-lm-cve-2025-14926 | 2026-08-13T17:14:17Z | 2026-10-02T11:08:29Z | |
| brew-mlx-lm-cve-2026-5241 | huggingface/transformers: Arbitrary Code Execution During Model Initialization in the LightGlue Model Loading Path | 2026-08-13T17:14:17Z | 2026-10-02T11:08:28Z |
| brew-mlx-lm-cve-2026-45409 | Internationalized Domain Names in Applications (IDNA): Specially crafted inputs to idna.encode() can bypass CVE-2024-3651 fix | 2026-08-13T17:14:17Z | 2026-10-02T11:08:28Z |
| brew-mlx-lm-cve-2026-4372 | HuggingFace transformers vulnerable to remote code execution | 2026-08-13T17:14:17Z | 2026-10-02T11:08:28Z |
| brew-mlx-lm-cve-2026-1839 | HuggingFace Transformers allows for arbitrary code execution in the `Trainer` class | 2026-08-13T17:14:17Z | 2026-10-02T11:08:28Z |
| brew-mlx-lm-cve-2026-0994 | protobuf affected by a JSON recursion depth bypass | 2026-08-13T17:14:17Z | 2026-10-02T11:08:28Z |