Vulnerabilities

Recent vulnerabilities

Recent vulnerabilities from
Select from 81 available sources using the dropdown above.

OSV Homebrew 🍺 is not individually searchable yet β€” the search will cover the sources available on the search page.

OSV Homebrew 🍺

Recent vulnerabilities Β· 13895 entries
ID Description Published Updated
brew-vdirsyncer-cve-2026-49265 Oauthlib: Timing Attack Vulnerability in PKCE code_verifier Comparison (CWE-208) 2026-09-30T21:43:26Z 2026-10-02T21:08:48Z
brew-vdirsyncer-cve-2026-49264 Oauthlib : Unsafe JSONP callback injection in RevocationEndpoint allows arbitrary JavaScript response generation 2026-09-30T21:43:26Z 2026-10-02T21:08:48Z
brew-legit-cve-2026-87819 GitPython: Denial of Service via catastrophic backtracking (ReDoS) in Actor.name_email_regex β€” commit author/committer field parsing 2026-09-30T21:16:48Z 2026-10-02T21:08:48Z
brew-legit-cve-2026-87817 GitPython: Repository content can impersonate the git directory, leading to arbitrary code execution 2026-09-30T21:16:48Z 2026-10-02T21:08:48Z
brew-legit-cve-2026-78679 GitPython: TagReference.create positional reference bypasses kwargs-only --file guard, enabling arbitrary file read (incomplete fix of 3af0c251) 2026-09-30T21:16:48Z 2026-10-02T21:08:48Z
brew-gitup-cve-2026-87819 GitPython: Denial of Service via catastrophic backtracking (ReDoS) in Actor.name_email_regex β€” commit author/committer field parsing 2026-09-30T18:47:21Z 2026-10-02T21:08:48Z
brew-gitup-cve-2026-87817 GitPython: Repository content can impersonate the git directory, leading to arbitrary code execution 2026-09-30T18:47:21Z 2026-10-02T21:08:48Z
brew-waybackpy-cve-2026-97688 urllib3: Chunked Deflate streaming can enter an infinite loop 2026-09-30T21:47:03Z 2026-10-02T11:40:24Z
brew-watson-cve-2026-97687 urllib3: HTTPS proxy TLS configuration may be ignored or overridden 2026-09-30T21:46:45Z 2026-10-02T11:37:44Z
brew-vdirsyncer-cve-2026-97689 urllib3: HTTPResponse.stream()/read_chunked() buffers an unbounded chunk-size line into memory 2026-09-30T21:43:26Z 2026-10-02T11:35:39Z
brew-vdirsyncer-cve-2026-97688 urllib3: Chunked Deflate streaming can enter an infinite loop 2026-09-30T21:43:26Z 2026-10-02T11:35:39Z
brew-vdirsyncer-cve-2026-97687 urllib3: HTTPS proxy TLS configuration may be ignored or overridden 2026-09-30T21:43:26Z 2026-10-02T11:35:39Z
brew-snakemake-cve-2026-97688 urllib3: Chunked Deflate streaming can enter an infinite loop 2026-09-30T21:33:39Z 2026-10-02T11:24:17Z
brew-snakemake-cve-2026-97687 urllib3: HTTPS proxy TLS configuration may be ignored or overridden 2026-09-30T21:33:39Z 2026-10-02T11:24:17Z
brew-parliament-cve-2026-97689 urllib3: HTTPResponse.stream()/read_chunked() buffers an unbounded chunk-size line into memory 2026-09-30T21:25:53Z 2026-10-02T11:14:40Z
brew-parliament-cve-2026-97688 urllib3: Chunked Deflate streaming can enter an infinite loop 2026-09-30T21:25:53Z 2026-10-02T11:14:40Z
brew-parliament-cve-2026-97687 urllib3: HTTPS proxy TLS configuration may be ignored or overridden 2026-09-30T21:25:53Z 2026-10-02T11:14:40Z
brew-moto-cve-2026-97688 urllib3: Chunked Deflate streaming can enter an infinite loop 2026-09-30T21:22:03Z 2026-10-02T11:09:56Z
brew-mlx-lm-cve-2026-9856 Transformers save_pretrained path traversal allows arbitrary file writes through chat template names 2026-09-02T09:23:51Z 2026-10-02T11:08:29Z
brew-mlx-lm-cve-2026-80047 Hugging Face Transformers downloads custom generation code before trust consent 2026-10-01T11:27:48Z 2026-10-02T11:08:29Z
brew-mlx-lm-cve-2025-14930 2026-08-13T17:14:17Z 2026-10-02T11:08:29Z
brew-mlx-lm-cve-2025-14929 2026-08-13T17:14:17Z 2026-10-02T11:08:29Z
brew-mlx-lm-cve-2025-14928 2026-08-13T17:14:17Z 2026-10-02T11:08:29Z
brew-mlx-lm-cve-2025-14927 2026-08-13T17:14:17Z 2026-10-02T11:08:29Z
brew-mlx-lm-cve-2025-14926 2026-08-13T17:14:17Z 2026-10-02T11:08:29Z
brew-mlx-lm-cve-2026-5241 huggingface/transformers: Arbitrary Code Execution During Model Initialization in the LightGlue Model Loading Path 2026-08-13T17:14:17Z 2026-10-02T11:08:28Z
brew-mlx-lm-cve-2026-45409 Internationalized Domain Names in Applications (IDNA): Specially crafted inputs to idna.encode() can bypass CVE-2024-3651 fix 2026-08-13T17:14:17Z 2026-10-02T11:08:28Z
brew-mlx-lm-cve-2026-4372 HuggingFace transformers vulnerable to remote code execution 2026-08-13T17:14:17Z 2026-10-02T11:08:28Z
brew-mlx-lm-cve-2026-1839 HuggingFace Transformers allows for arbitrary code execution in the `Trainer` class 2026-08-13T17:14:17Z 2026-10-02T11:08:28Z
brew-mlx-lm-cve-2026-0994 protobuf affected by a JSON recursion depth bypass 2026-08-13T17:14:17Z 2026-10-02T11:08:28Z