Vulnerabilities

Recent vulnerabilities

Recent vulnerabilities from
Select from 81 available sources using the dropdown above.

OSV Homebrew 🍺 is not individually searchable yet β€” the search will cover the sources available on the search page.

OSV Homebrew 🍺

Recent vulnerabilities Β· 13873 entries
ID Description Published Updated
brew-snakeviz-ghsa-chx6-46f5-w4vp tornado: CurlAsyncHTTPClient enforces no response-size limit β€” decompression bomb drives unbounded memory accumulation to OOM 2026-10-01T11:45:24Z 2026-10-01T11:45:24Z
brew-snakeviz-ghsa-c2m8-h5v5-343r Tornado: StaticFileHandler follows symlinks outside static root (path traversal) 2026-10-01T11:45:24Z 2026-10-01T11:45:24Z
brew-snakeviz-ghsa-3hv7-mjh2-fv65 Tornado: Unbounded query-string argument count allows event-loop-stalling DoS 2026-10-01T11:45:24Z 2026-10-01T11:45:24Z
brew-snakemake-cve-2026-100689 GitPython submodule update path traversal can write outside the repository 2026-10-01T11:43:20Z 2026-10-01T11:43:20Z
brew-mlx-lm-cve-2026-80047 Hugging Face Transformers downloads custom generation code before trust consent 2026-10-01T11:27:48Z 2026-10-01T11:27:48Z
brew-kimi-cli-cve-2026-103001 PyJWT.decode() reintroduces options-dict mutation, enabling silent claim-verification bypass on dict reuse 2026-10-01T11:20:23Z 2026-10-01T11:20:23Z
brew-kimi-cli-cve-2026-100689 GitPython submodule update path traversal can write outside the repository 2026-10-01T11:20:16Z 2026-10-01T11:20:16Z
brew-howdoi-cve-2026-103001 PyJWT.decode() reintroduces options-dict mutation, enabling silent claim-verification bypass on dict reuse 2026-10-01T11:14:16Z 2026-10-01T11:14:16Z
brew-localstack-cve-2026-103001 PyJWT.decode() reintroduces options-dict mutation, enabling silent claim-verification bypass on dict reuse 2026-10-01T11:14:06Z 2026-10-01T11:14:06Z
brew-livereload-ghsa-chx6-46f5-w4vp tornado: CurlAsyncHTTPClient enforces no response-size limit β€” decompression bomb drives unbounded memory accumulation to OOM 2026-10-01T11:13:05Z 2026-10-01T11:13:05Z
brew-livereload-ghsa-c2m8-h5v5-343r Tornado: StaticFileHandler follows symlinks outside static root (path traversal) 2026-10-01T11:13:05Z 2026-10-01T11:13:05Z
brew-livereload-ghsa-3hv7-mjh2-fv65 Tornado: Unbounded query-string argument count allows event-loop-stalling DoS 2026-10-01T11:13:05Z 2026-10-01T11:13:05Z
brew-tern-cve-2026-100689 GitPython submodule update path traversal can write outside the repository 2026-10-01T11:08:14Z 2026-10-01T11:08:14Z
brew-tartufo-cve-2026-100689 GitPython submodule update path traversal can write outside the repository 2026-10-01T11:08:05Z 2026-10-01T11:08:05Z
brew-azure-cli-cve-2026-103001 PyJWT.decode() reintroduces options-dict mutation, enabling silent claim-verification bypass on dict reuse 2026-10-01T11:08:01Z 2026-10-01T11:08:01Z
brew-ggshield-cve-2026-103001 PyJWT.decode() reintroduces options-dict mutation, enabling silent claim-verification bypass on dict reuse 2026-10-01T11:07:53Z 2026-10-01T11:07:53Z
brew-cruft-cve-2026-100689 GitPython submodule update path traversal can write outside the repository 2026-10-01T11:04:12Z 2026-10-01T11:04:12Z
brew-checkov-cve-2026-100689 GitPython submodule update path traversal can write outside the repository 2026-10-01T11:03:46Z 2026-10-01T11:03:46Z
brew-scoutsuite-cve-2026-103001 PyJWT.decode() reintroduces options-dict mutation, enabling silent claim-verification bypass on dict reuse 2026-10-01T11:02:07Z 2026-10-01T11:02:07Z
brew-mcpm-cve-2026-103001 PyJWT.decode() reintroduces options-dict mutation, enabling silent claim-verification bypass on dict reuse 2026-10-01T10:53:03Z 2026-10-01T10:53:03Z
brew-parsedmarc-cve-2026-103001 PyJWT.decode() reintroduces options-dict mutation, enabling silent claim-verification bypass on dict reuse 2026-10-01T10:47:46Z 2026-10-01T10:47:46Z
brew-nbdime-cve-2026-100689 GitPython submodule update path traversal can write outside the repository 2026-10-01T10:44:10Z 2026-10-01T10:44:10Z
brew-dvc-cve-2026-103001 PyJWT.decode() reintroduces options-dict mutation, enabling silent claim-verification bypass on dict reuse 2026-10-01T10:40:49Z 2026-10-01T10:40:49Z
brew-dvc-cve-2026-100689 GitPython submodule update path traversal can write outside the repository 2026-10-01T10:40:26Z 2026-10-01T10:40:26Z
brew-mistral-vibe-cve-2026-103001 PyJWT.decode() reintroduces options-dict mutation, enabling silent claim-verification bypass on dict reuse 2026-10-01T10:34:03Z 2026-10-01T10:34:03Z
brew-mistral-vibe-cve-2026-100689 GitPython submodule update path traversal can write outside the repository 2026-10-01T10:34:01Z 2026-10-01T10:34:01Z
brew-mcp-proxy-cve-2026-103001 PyJWT.decode() reintroduces options-dict mutation, enabling silent claim-verification bypass on dict reuse 2026-10-01T10:32:25Z 2026-10-01T10:32:25Z
brew-fastmcp-cve-2026-103001 PyJWT.decode() reintroduces options-dict mutation, enabling silent claim-verification bypass on dict reuse 2026-10-01T10:32:10Z 2026-10-01T10:32:10Z
brew-sysaidmin-cve-2026-103001 PyJWT.decode() reintroduces options-dict mutation, enabling silent claim-verification bypass on dict reuse 2026-10-01T10:23:58Z 2026-10-01T10:23:58Z
brew-rapid-mlx-cve-2026-103001 PyJWT.decode() reintroduces options-dict mutation, enabling silent claim-verification bypass on dict reuse 2026-10-01T10:20:54Z 2026-10-01T10:20:54Z