Vulnerabilities
Recent vulnerabilities
Recent vulnerabilities from
Select from 81 available sources using the dropdown above.
OSV Homebrew πΊ is not individually searchable yet β the search will cover the sources available on the search page.
| ID | Description | Published | Updated |
|---|---|---|---|
| brew-snakeviz-ghsa-chx6-46f5-w4vp | tornado: CurlAsyncHTTPClient enforces no response-size limit β decompression bomb drives unbounded memory accumulation to OOM | 2026-10-01T11:45:24Z | 2026-10-01T11:45:24Z |
| brew-snakeviz-ghsa-c2m8-h5v5-343r | Tornado: StaticFileHandler follows symlinks outside static root (path traversal) | 2026-10-01T11:45:24Z | 2026-10-01T11:45:24Z |
| brew-snakeviz-ghsa-3hv7-mjh2-fv65 | Tornado: Unbounded query-string argument count allows event-loop-stalling DoS | 2026-10-01T11:45:24Z | 2026-10-01T11:45:24Z |
| brew-snakemake-cve-2026-100689 | GitPython submodule update path traversal can write outside the repository | 2026-10-01T11:43:20Z | 2026-10-01T11:43:20Z |
| brew-mlx-lm-cve-2026-80047 | Hugging Face Transformers downloads custom generation code before trust consent | 2026-10-01T11:27:48Z | 2026-10-01T11:27:48Z |
| brew-kimi-cli-cve-2026-103001 | PyJWT.decode() reintroduces options-dict mutation, enabling silent claim-verification bypass on dict reuse | 2026-10-01T11:20:23Z | 2026-10-01T11:20:23Z |
| brew-kimi-cli-cve-2026-100689 | GitPython submodule update path traversal can write outside the repository | 2026-10-01T11:20:16Z | 2026-10-01T11:20:16Z |
| brew-howdoi-cve-2026-103001 | PyJWT.decode() reintroduces options-dict mutation, enabling silent claim-verification bypass on dict reuse | 2026-10-01T11:14:16Z | 2026-10-01T11:14:16Z |
| brew-localstack-cve-2026-103001 | PyJWT.decode() reintroduces options-dict mutation, enabling silent claim-verification bypass on dict reuse | 2026-10-01T11:14:06Z | 2026-10-01T11:14:06Z |
| brew-livereload-ghsa-chx6-46f5-w4vp | tornado: CurlAsyncHTTPClient enforces no response-size limit β decompression bomb drives unbounded memory accumulation to OOM | 2026-10-01T11:13:05Z | 2026-10-01T11:13:05Z |
| brew-livereload-ghsa-c2m8-h5v5-343r | Tornado: StaticFileHandler follows symlinks outside static root (path traversal) | 2026-10-01T11:13:05Z | 2026-10-01T11:13:05Z |
| brew-livereload-ghsa-3hv7-mjh2-fv65 | Tornado: Unbounded query-string argument count allows event-loop-stalling DoS | 2026-10-01T11:13:05Z | 2026-10-01T11:13:05Z |
| brew-tern-cve-2026-100689 | GitPython submodule update path traversal can write outside the repository | 2026-10-01T11:08:14Z | 2026-10-01T11:08:14Z |
| brew-tartufo-cve-2026-100689 | GitPython submodule update path traversal can write outside the repository | 2026-10-01T11:08:05Z | 2026-10-01T11:08:05Z |
| brew-azure-cli-cve-2026-103001 | PyJWT.decode() reintroduces options-dict mutation, enabling silent claim-verification bypass on dict reuse | 2026-10-01T11:08:01Z | 2026-10-01T11:08:01Z |
| brew-ggshield-cve-2026-103001 | PyJWT.decode() reintroduces options-dict mutation, enabling silent claim-verification bypass on dict reuse | 2026-10-01T11:07:53Z | 2026-10-01T11:07:53Z |
| brew-cruft-cve-2026-100689 | GitPython submodule update path traversal can write outside the repository | 2026-10-01T11:04:12Z | 2026-10-01T11:04:12Z |
| brew-checkov-cve-2026-100689 | GitPython submodule update path traversal can write outside the repository | 2026-10-01T11:03:46Z | 2026-10-01T11:03:46Z |
| brew-scoutsuite-cve-2026-103001 | PyJWT.decode() reintroduces options-dict mutation, enabling silent claim-verification bypass on dict reuse | 2026-10-01T11:02:07Z | 2026-10-01T11:02:07Z |
| brew-mcpm-cve-2026-103001 | PyJWT.decode() reintroduces options-dict mutation, enabling silent claim-verification bypass on dict reuse | 2026-10-01T10:53:03Z | 2026-10-01T10:53:03Z |
| brew-parsedmarc-cve-2026-103001 | PyJWT.decode() reintroduces options-dict mutation, enabling silent claim-verification bypass on dict reuse | 2026-10-01T10:47:46Z | 2026-10-01T10:47:46Z |
| brew-nbdime-cve-2026-100689 | GitPython submodule update path traversal can write outside the repository | 2026-10-01T10:44:10Z | 2026-10-01T10:44:10Z |
| brew-dvc-cve-2026-103001 | PyJWT.decode() reintroduces options-dict mutation, enabling silent claim-verification bypass on dict reuse | 2026-10-01T10:40:49Z | 2026-10-01T10:40:49Z |
| brew-dvc-cve-2026-100689 | GitPython submodule update path traversal can write outside the repository | 2026-10-01T10:40:26Z | 2026-10-01T10:40:26Z |
| brew-mistral-vibe-cve-2026-103001 | PyJWT.decode() reintroduces options-dict mutation, enabling silent claim-verification bypass on dict reuse | 2026-10-01T10:34:03Z | 2026-10-01T10:34:03Z |
| brew-mistral-vibe-cve-2026-100689 | GitPython submodule update path traversal can write outside the repository | 2026-10-01T10:34:01Z | 2026-10-01T10:34:01Z |
| brew-mcp-proxy-cve-2026-103001 | PyJWT.decode() reintroduces options-dict mutation, enabling silent claim-verification bypass on dict reuse | 2026-10-01T10:32:25Z | 2026-10-01T10:32:25Z |
| brew-fastmcp-cve-2026-103001 | PyJWT.decode() reintroduces options-dict mutation, enabling silent claim-verification bypass on dict reuse | 2026-10-01T10:32:10Z | 2026-10-01T10:32:10Z |
| brew-sysaidmin-cve-2026-103001 | PyJWT.decode() reintroduces options-dict mutation, enabling silent claim-verification bypass on dict reuse | 2026-10-01T10:23:58Z | 2026-10-01T10:23:58Z |
| brew-rapid-mlx-cve-2026-103001 | PyJWT.decode() reintroduces options-dict mutation, enabling silent claim-verification bypass on dict reuse | 2026-10-01T10:20:54Z | 2026-10-01T10:20:54Z |