检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-6X4J-8954-5HXM CVE-2026-50550 | Snipe-IT has a 2FA reset privilege bypass | 中危 | Packagistsnipe/snipe-it | 已审查 | 2026-06-24 07:03 | 2026-06-24 07:03 |
| GHSA-P68W-RGMG-3C2V CVE-2026-49976 | Snipe-IT Vulnerable to User Account Escalation via CSV Import |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 中危 |
Packagistsnipe/snipe-it |
| 已审查 |
| 2026-06-24 07:02 |
| 2026-06-24 07:02 |
| GHSA-W2J7-F3C6-G8CW | Flask-Security has an Open Redirect issue | 中危 | PyPIFlask-Security | 已审查 | 2026-06-24 06:46 | 2026-06-24 06:46 |
| GHSA-MR8G-2MJ4-PCQ2 CVE-2026-49870 | Snipe-IT's TOTP is Brute-Forceable Due to Missing Rate Limiting on `POST /two-factor` | 中危 | Packagistsnipe/snipe-it | 已审查 | 2026-06-24 06:32 | 2026-06-24 06:32 |
| GHSA-8C6H-7G6X-M5X4 CVE-2026-49205 | phpMyFAQ: Missing userHasPermission() in 4 API write endpoints (CVE-2026-24421 Incomplete Fix) | 中危 | Packagistphpmyfaq/phpmyfaq+1 | 已审查 | 2026-06-24 06:27 | 2026-06-24 06:27 |
| GHSA-6F75-X745-XCPR CVE-2026-48507 | Snipe-IT: Bulk editing users allowed `ldap_import` and `activated_in` bulk editing users | 高危 | Packagistsnipe/snipe-it | 已审查 | 2026-06-24 06:24 | 2026-08-22 04:00 |
| GHSA-WCMJ-X466-56MM | OpenTofu: Provider cache installation follows root-module-controlled package directory symlink and writes outside the working tree | 中危 | Gogithub.com/opentofu/opentofu | 已审查 | 2026-06-24 06:23 | 2026-06-24 06:23 |
| GHSA-44WP-G8F4-F4V5 CVE-2026-48500 | Filament: Unauthenticated temporary file upload on auth pages | 中危 | Packagistfilament/filament | 已审查 | 2026-06-24 06:16 | 2026-06-24 06:16 |
| GHSA-F2R5-5M7W-P5CX CVE-2026-48496 | opentelemetry-ebpf-profiler: Unprivileged process can trigger a denial of service on the ebpf-profiler agent | 中危 | Gogo.opentelemetry.io/ebpf-profiler | 已审查 | 2026-06-24 06:16 | 2026-06-24 06:16 |
| GHSA-52FW-7FW2-FMV5 CVE-2026-48493 | Snipe-IT Vulnerable to Privilege Escalation for self via API Permissions Assignment | 中危 | Packagistsnipe/snipe-it | 已审查 | 2026-06-24 06:12 | 2026-07-21 05:22 |
| GHSA-F3C5-6CW8-FG57 CVE-2026-48492 | Snipe-IT's selectlist visibility is too permissive | 中危 | Packagistsnipe/snipe-it | 已审查 | 2026-06-24 06:11 | 2026-06-24 06:11 |
| GHSA-58FG-62FG-3FCJ CVE-2026-48488 | phpMyFAQ has Weak Cryptography - SHA1 for Password Hashing | 低危 | Packagistphpmyfaq/phpmyfaq+1 | 已审查 | 2026-06-24 06:02 | 2026-06-24 06:02 |
| GHSA-R6FJ-869H-4F6Q CVE-2026-48480 | OHttpVersionChunkDraft: Missing Final-Chunk Enforcement Leads to Undetected Stream Truncation | 中危 | Mavenio.netty.incubator:netty-incubator-codec-ohttp | 已审查 | 2026-06-24 05:59 | 2026-06-24 05:59 |
| GHSA-3FC8-8HP6-6JR4 CVE-2026-48167 | Filament: Unvalidated ImageColumn and ImageEntry values can be used for XSS | 中危 | Packagistfilament/infolists+1 | 已审查 | 2026-06-24 05:57 | 2026-06-24 05:57 |
| GHSA-5W46-G9PQ-WH6F CVE-2026-48166 | Filament: Timing-based user enumeration on login page | 中危 | Packagistfilament/filament | 已审查 | 2026-06-24 05:54 | 2026-06-24 05:54 |
| GHSA-53H4-8RC4-F539 CVE-2026-48157 | Slim has Reflected XSS in the HtmlErrorRenderer | 中危 | Packagistslim/slim | 已审查 | 2026-06-24 05:54 | 2026-06-24 05:54 |
| GHSA-JC3J-X6PG-4HMV CVE-2026-48126 | Algernon: Host header path traversal in --domain mode reads files and runs Lua from parent dir | 高危 | Gogithub.com/xyproto/algernon | 已审查 | 2026-06-24 05:49 | 2026-06-24 05:49 |
| GHSA-5HH8-Q8HV-FR38 CVE-2026-54517 | jackson-databind has @JsonView bypass for setterless creator properties | 中危 | Mavencom.fasterxml.jackson.core:jackson-databind+1 | 已审查 | 2026-06-24 05:24 | 2026-07-21 05:21 |
| GHSA-9FXM-VC8V-HJ55 CVE-2026-54516 | jackson-databind's renamed @JsonIgnore'd setters can deserialize via private fields | 中危 | Mavencom.fasterxml.jackson.core:jackson-databind+1 | 已审查 | 2026-06-24 05:24 | 2026-07-21 05:21 |
| GHSA-5JMJ-H7XM-6Q6V CVE-2026-54515 | jackson-databind has case-insensitive deserialization bypasses per-property @JsonIgnoreProperties | 中危 | Mavencom.fasterxml.jackson.core:jackson-databind+1 | 已审查 | 2026-06-24 05:23 | 2026-07-17 05:25 |
| GHSA-HGJ6-7826-R7M5 CVE-2026-54514 | jackson-databind: InetSocketAddress deserialization triggers eager DNS resolution (SSRF) | 中危 | Mavencom.fasterxml.jackson.core:jackson-databind+1 | 已审查 | 2026-06-24 05:22 | 2026-07-21 05:21 |
| GHSA-RMJ7-2VXQ-3G9F CVE-2026-54513 | jackson-databind has an array subtype allowlist bypass in BasicPolymorphicTypeValidator (allowIfSubTypeIsArray) | 高危 | Mavencom.fasterxml.jackson.core:jackson-databind+1 | 已审查 | 2026-06-24 05:22 | 2026-09-02 23:34 |
| GHSA-J3RV-43J4-C7QM CVE-2026-54512 | jackson-databind has a PolymorphicTypeValidator bypass via generic type parameters that allows arbitrary class instantiation | 高危 | Mavencom.fasterxml.jackson.core:jackson-databind+1 | 已审查 | 2026-06-24 05:21 | 2026-07-21 05:21 |
| GHSA-3WRR-7QPF-2PRH CVE-2026-50193 | jackson-databind: Deeply nested JsonNode throws StackOverflowError for toString() | 中危 | Mavencom.fasterxml.jackson.core:jackson-databind | 已审查 | 2026-06-24 05:21 | 2026-07-21 05:19 |
| GHSA-RCQC-6CW3-H962 CVE-2026-54518 | jackson-databind has a @JsonView bypass for unwrapped creator parameters | 中危 | Mavencom.fasterxml.jackson.core:jackson-databind+1 | 已审查 | 2026-06-24 05:17 | 2026-07-21 05:22 |