Vulnerabilities
Recent vulnerabilities
Recent vulnerabilities from
Select from 81 available sources using the dropdown above.
OSV Homebrew πΊ is not individually searchable yet β the search will cover the sources available on the search page.
| ID | Description | Published | Updated |
|---|---|---|---|
| brew-snakeviz-ghsa-chx6-46f5-w4vp | tornado: CurlAsyncHTTPClient enforces no response-size limit β decompression bomb drives unbounded memory accumulation to OOM | 2026-10-01T11:45:24Z | 2026-10-01T11:45:24Z |
| brew-snakeviz-ghsa-c2m8-h5v5-343r | Tornado: StaticFileHandler follows symlinks outside static root (path traversal) | 2026-10-01T11:45:24Z | 2026-10-01T11:45:24Z |
| brew-snakeviz-ghsa-3hv7-mjh2-fv65 | Tornado: Unbounded query-string argument count allows event-loop-stalling DoS | 2026-10-01T11:45:24Z | 2026-10-01T11:45:24Z |
| brew-snakemake-cve-2026-87819 | GitPython: Denial of Service via catastrophic backtracking (ReDoS) in Actor.name_email_regex β commit author/committer field parsing | 2026-09-20T12:28:17Z | 2026-10-01T11:43:20Z |
| brew-snakemake-cve-2026-87818 | GitPython: --no-index bypasses diff unsafe-option protections and enables a blind local-file content oracle | 2026-09-18T18:39:20Z | 2026-10-01T11:43:20Z |
| brew-snakemake-cve-2026-87817 | GitPython: Repository content can impersonate the git directory, leading to arbitrary code execution | 2026-09-20T12:28:17Z | 2026-10-01T11:43:20Z |
| brew-snakemake-cve-2026-100689 | GitPython submodule update path traversal can write outside the repository | 2026-10-01T11:43:20Z | 2026-10-01T11:43:20Z |
| brew-mlx-lm-cve-2026-80047 | Hugging Face Transformers downloads custom generation code before trust consent | 2026-10-01T11:27:48Z | 2026-10-01T11:27:48Z |
| brew-legit-cve-2026-87819 | GitPython: Denial of Service via catastrophic backtracking (ReDoS) in Actor.name_email_regex β commit author/committer field parsing | 2026-09-30T21:16:48Z | 2026-10-01T11:22:53Z |
| brew-legit-cve-2026-87817 | GitPython: Repository content can impersonate the git directory, leading to arbitrary code execution | 2026-09-30T21:16:48Z | 2026-10-01T11:21:36Z |
| brew-kimi-cli-cve-2026-103001 | PyJWT.decode() reintroduces options-dict mutation, enabling silent claim-verification bypass on dict reuse | 2026-10-01T11:20:23Z | 2026-10-01T11:20:23Z |
| brew-kimi-cli-cve-2026-87819 | GitPython: Denial of Service via catastrophic backtracking (ReDoS) in Actor.name_email_regex β commit author/committer field parsing | 2026-09-20T12:18:02Z | 2026-10-01T11:20:16Z |
| brew-kimi-cli-cve-2026-100689 | GitPython submodule update path traversal can write outside the repository | 2026-10-01T11:20:16Z | 2026-10-01T11:20:16Z |
| brew-kimi-cli-cve-2026-87817 | GitPython: Repository content can impersonate the git directory, leading to arbitrary code execution | 2026-09-20T12:18:02Z | 2026-10-01T11:20:15Z |
| brew-howdoi-cve-2026-103001 | PyJWT.decode() reintroduces options-dict mutation, enabling silent claim-verification bypass on dict reuse | 2026-10-01T11:14:16Z | 2026-10-01T11:14:16Z |
| brew-localstack-cve-2026-103001 | PyJWT.decode() reintroduces options-dict mutation, enabling silent claim-verification bypass on dict reuse | 2026-10-01T11:14:06Z | 2026-10-01T11:14:06Z |
| brew-livereload-ghsa-chx6-46f5-w4vp | tornado: CurlAsyncHTTPClient enforces no response-size limit β decompression bomb drives unbounded memory accumulation to OOM | 2026-10-01T11:13:05Z | 2026-10-01T11:13:05Z |
| brew-livereload-ghsa-c2m8-h5v5-343r | Tornado: StaticFileHandler follows symlinks outside static root (path traversal) | 2026-10-01T11:13:05Z | 2026-10-01T11:13:05Z |
| brew-livereload-ghsa-3hv7-mjh2-fv65 | Tornado: Unbounded query-string argument count allows event-loop-stalling DoS | 2026-10-01T11:13:05Z | 2026-10-01T11:13:05Z |
| brew-cloudiscovery-cve-2026-102938 | virtualenv writes prompt values into pyvenv.cfg without sanitizing line boundaries, allowing configuration injection | 2026-09-30T21:05:15Z | 2026-10-01T11:09:02Z |
| brew-cloudiscovery-cve-2026-102930 | virtualenv: Downloaded seed wheels (pip/setuptools) are not integrity-checked before use | 2026-09-30T21:05:15Z | 2026-10-01T11:09:02Z |
| brew-tern-cve-2026-87819 | GitPython: Denial of Service via catastrophic backtracking (ReDoS) in Actor.name_email_regex β commit author/committer field parsing | 2026-09-20T12:19:34Z | 2026-10-01T11:08:14Z |
| brew-tern-cve-2026-100689 | GitPython submodule update path traversal can write outside the repository | 2026-10-01T11:08:14Z | 2026-10-01T11:08:14Z |
| brew-tern-cve-2026-87817 | GitPython: Repository content can impersonate the git directory, leading to arbitrary code execution | 2026-09-20T12:19:34Z | 2026-10-01T11:08:05Z |
| brew-tartufo-cve-2026-87819 | GitPython: Denial of Service via catastrophic backtracking (ReDoS) in Actor.name_email_regex β commit author/committer field parsing | 2026-09-20T12:19:31Z | 2026-10-01T11:08:05Z |
| brew-tartufo-cve-2026-78679 | GitPython: TagReference.create positional reference bypasses kwargs-only --file guard, enabling arbitrary file read (incomplete fix of 3af0c251) | 2026-09-10T21:09:42Z | 2026-10-01T11:08:05Z |
| brew-tartufo-cve-2026-78678 | GitPython: Incomplete unsafe_git_revision_options denylist omits --contents/-S, enabling arbitrary file read via Repo.blame() | 2026-09-04T10:12:20Z | 2026-10-01T11:08:05Z |
| brew-tartufo-cve-2026-78677 | GitPython: clone_from()/clone() omit --separate-git-dir from unsafe_git_clone_options, enabling arbitrary git-directory creation outside the destination | 2026-09-04T10:12:20Z | 2026-10-01T11:08:05Z |
| brew-tartufo-cve-2026-78675 | GitPython: Arbitrary local file content disclosure via [include] directive in untrusted .gitmodules (SubmoduleConfigParser never disables merge_includes) | 2026-09-04T10:12:20Z | 2026-10-01T11:08:05Z |
| brew-tartufo-cve-2026-76222 | GitPython: Arbitrary Git Repository Creation Outside the Working Tree via Unvalidated .gitmodules Submodule Name in GitPython | 2026-08-20T09:45:22Z | 2026-10-01T11:08:05Z |