Vulnerabilities

Recent vulnerabilities

Recent vulnerabilities from
Select from 81 available sources using the dropdown above.

OSV Homebrew 🍺 is not individually searchable yet β€” the search will cover the sources available on the search page.

OSV Homebrew 🍺

Recent vulnerabilities Β· 13873 entries
ID Description Published Updated
brew-snakeviz-ghsa-chx6-46f5-w4vp tornado: CurlAsyncHTTPClient enforces no response-size limit β€” decompression bomb drives unbounded memory accumulation to OOM 2026-10-01T11:45:24Z 2026-10-01T11:45:24Z
brew-snakeviz-ghsa-c2m8-h5v5-343r Tornado: StaticFileHandler follows symlinks outside static root (path traversal) 2026-10-01T11:45:24Z 2026-10-01T11:45:24Z
brew-snakeviz-ghsa-3hv7-mjh2-fv65 Tornado: Unbounded query-string argument count allows event-loop-stalling DoS 2026-10-01T11:45:24Z 2026-10-01T11:45:24Z
brew-snakemake-cve-2026-87819 GitPython: Denial of Service via catastrophic backtracking (ReDoS) in Actor.name_email_regex β€” commit author/committer field parsing 2026-09-20T12:28:17Z 2026-10-01T11:43:20Z
brew-snakemake-cve-2026-87818 GitPython: --no-index bypasses diff unsafe-option protections and enables a blind local-file content oracle 2026-09-18T18:39:20Z 2026-10-01T11:43:20Z
brew-snakemake-cve-2026-87817 GitPython: Repository content can impersonate the git directory, leading to arbitrary code execution 2026-09-20T12:28:17Z 2026-10-01T11:43:20Z
brew-snakemake-cve-2026-100689 GitPython submodule update path traversal can write outside the repository 2026-10-01T11:43:20Z 2026-10-01T11:43:20Z
brew-mlx-lm-cve-2026-80047 Hugging Face Transformers downloads custom generation code before trust consent 2026-10-01T11:27:48Z 2026-10-01T11:27:48Z
brew-legit-cve-2026-87819 GitPython: Denial of Service via catastrophic backtracking (ReDoS) in Actor.name_email_regex β€” commit author/committer field parsing 2026-09-30T21:16:48Z 2026-10-01T11:22:53Z
brew-legit-cve-2026-87817 GitPython: Repository content can impersonate the git directory, leading to arbitrary code execution 2026-09-30T21:16:48Z 2026-10-01T11:21:36Z
brew-kimi-cli-cve-2026-103001 PyJWT.decode() reintroduces options-dict mutation, enabling silent claim-verification bypass on dict reuse 2026-10-01T11:20:23Z 2026-10-01T11:20:23Z
brew-kimi-cli-cve-2026-87819 GitPython: Denial of Service via catastrophic backtracking (ReDoS) in Actor.name_email_regex β€” commit author/committer field parsing 2026-09-20T12:18:02Z 2026-10-01T11:20:16Z
brew-kimi-cli-cve-2026-100689 GitPython submodule update path traversal can write outside the repository 2026-10-01T11:20:16Z 2026-10-01T11:20:16Z
brew-kimi-cli-cve-2026-87817 GitPython: Repository content can impersonate the git directory, leading to arbitrary code execution 2026-09-20T12:18:02Z 2026-10-01T11:20:15Z
brew-howdoi-cve-2026-103001 PyJWT.decode() reintroduces options-dict mutation, enabling silent claim-verification bypass on dict reuse 2026-10-01T11:14:16Z 2026-10-01T11:14:16Z
brew-localstack-cve-2026-103001 PyJWT.decode() reintroduces options-dict mutation, enabling silent claim-verification bypass on dict reuse 2026-10-01T11:14:06Z 2026-10-01T11:14:06Z
brew-livereload-ghsa-chx6-46f5-w4vp tornado: CurlAsyncHTTPClient enforces no response-size limit β€” decompression bomb drives unbounded memory accumulation to OOM 2026-10-01T11:13:05Z 2026-10-01T11:13:05Z
brew-livereload-ghsa-c2m8-h5v5-343r Tornado: StaticFileHandler follows symlinks outside static root (path traversal) 2026-10-01T11:13:05Z 2026-10-01T11:13:05Z
brew-livereload-ghsa-3hv7-mjh2-fv65 Tornado: Unbounded query-string argument count allows event-loop-stalling DoS 2026-10-01T11:13:05Z 2026-10-01T11:13:05Z
brew-cloudiscovery-cve-2026-102938 virtualenv writes prompt values into pyvenv.cfg without sanitizing line boundaries, allowing configuration injection 2026-09-30T21:05:15Z 2026-10-01T11:09:02Z
brew-cloudiscovery-cve-2026-102930 virtualenv: Downloaded seed wheels (pip/setuptools) are not integrity-checked before use 2026-09-30T21:05:15Z 2026-10-01T11:09:02Z
brew-tern-cve-2026-87819 GitPython: Denial of Service via catastrophic backtracking (ReDoS) in Actor.name_email_regex β€” commit author/committer field parsing 2026-09-20T12:19:34Z 2026-10-01T11:08:14Z
brew-tern-cve-2026-100689 GitPython submodule update path traversal can write outside the repository 2026-10-01T11:08:14Z 2026-10-01T11:08:14Z
brew-tern-cve-2026-87817 GitPython: Repository content can impersonate the git directory, leading to arbitrary code execution 2026-09-20T12:19:34Z 2026-10-01T11:08:05Z
brew-tartufo-cve-2026-87819 GitPython: Denial of Service via catastrophic backtracking (ReDoS) in Actor.name_email_regex β€” commit author/committer field parsing 2026-09-20T12:19:31Z 2026-10-01T11:08:05Z
brew-tartufo-cve-2026-78679 GitPython: TagReference.create positional reference bypasses kwargs-only --file guard, enabling arbitrary file read (incomplete fix of 3af0c251) 2026-09-10T21:09:42Z 2026-10-01T11:08:05Z
brew-tartufo-cve-2026-78678 GitPython: Incomplete unsafe_git_revision_options denylist omits --contents/-S, enabling arbitrary file read via Repo.blame() 2026-09-04T10:12:20Z 2026-10-01T11:08:05Z
brew-tartufo-cve-2026-78677 GitPython: clone_from()/clone() omit --separate-git-dir from unsafe_git_clone_options, enabling arbitrary git-directory creation outside the destination 2026-09-04T10:12:20Z 2026-10-01T11:08:05Z
brew-tartufo-cve-2026-78675 GitPython: Arbitrary local file content disclosure via [include] directive in untrusted .gitmodules (SubmoduleConfigParser never disables merge_includes) 2026-09-04T10:12:20Z 2026-10-01T11:08:05Z
brew-tartufo-cve-2026-76222 GitPython: Arbitrary Git Repository Creation Outside the Working Tree via Unvalidated .gitmodules Submodule Name in GitPython 2026-08-20T09:45:22Z 2026-10-01T11:08:05Z