检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-6V8J-33HC-MV84 CVE-2026-55877 | symfony/ux-icons: XSS via unsanitized SVG content in local files and Iconify on-demand responses | 中危 | Packagistsymfony/ux-icons | 已审查 | 2026-06-20 05:42 | 2026-06-20 05:42 |
| GHSA-4VRG-R928-H5VV CVE-2026-55866 | SpiceDB: Checks involving relations with caveats can result in unconditional permission when conditional permission is expected |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 低危 |
Gogithub.com/authzed/spicedb |
| 已审查 |
| 2026-06-20 05:42 |
| 2026-06-20 05:42 |
| GHSA-8W8F-R2XV-4Q4J CVE-2026-55776 | OpenBao: Transit secrets engine crashes on key creation with `derived: true` for asymmetric key types | 中危 | Gogithub.com/openbao/openbao | 已审查 | 2026-06-20 05:42 | 2026-06-20 05:42 |
| GHSA-MWR2-WMGP-CRJ6 CVE-2026-55775 | OpenBao's System Backend allows Unauthorized Management of the containing Namespace | 低危 | Gogithub.com/openbao/openbao | 已审查 | 2026-06-20 05:42 | 2026-06-20 05:42 |
| GHSA-C36X-H252-G9X2 CVE-2026-55774 | OpenBao: Cross-namespace lease revocation/renewal via canonical sys/leases/{revoke,renew} — incomplete fix of CVE-2026-45808 | 低危 | Gogithub.com/openbao/openbao | 已审查 | 2026-06-20 05:42 | 2026-06-20 05:42 |
| GHSA-6MWX-4547-5VC9 CVE-2026-55770 | OpenBao: LDAPi ldaputil (wrong escape func) | 中危 | Gogithub.com/openbao/openbao | 已审查 | 2026-06-20 05:42 | 2026-06-20 05:42 |
| GHSA-5C7P-G73Q-RPG5 CVE-2026-55692 | StarCitizenWiki Extension Embed Video: Stored XSS via malformed src url with $wgEmbedVideoRequireConsent enabled | 高危 | Packagiststarcitizenwiki/embedvideo | 已审查 | 2026-06-20 05:41 | 2026-06-20 05:41 |
| GHSA-6XFF-CPCQ-VPW2 CVE-2026-27878 | Grafana Tempo vulnerable to an out-of-memory crash | 中危 | Gogithub.com/grafana/tempo | 已审查 | 2026-06-20 05:32 | 2026-08-29 05:50 |
| GHSA-WWF9-7JRC-RV4Q CVE-2026-55650 | Outerbase Studio: Stored XSS in Text Widget Leads to Authentication Token Exposure | 中危 | npm@outerbase/studio | 已审查 | 2026-06-20 05:18 | 2026-06-20 05:18 |
| GHSA-CCV6-R384-XP75 CVE-2026-55447 | Langflow: BaseFileComponent-based nodes arbitrary file read with RCE exploit | 严重 | PyPIlangflow | 已审查 | 2026-06-20 05:18 | 2026-06-20 05:18 |
| GHSA-QWQC-P3Q8-WCG9 CVE-2026-55446 | Langflow: Unauthenticated DoS through multipart form boundary file upload | 高危 | PyPIlangflow | 已审查 | 2026-06-20 05:17 | 2026-06-20 05:17 |
| GHSA-7HW8-6Q6R-4276 CVE-2026-55423 | Langflow: Logout button does not clear session | 中危 | PyPIlangflow | 已审查 | 2026-06-20 05:17 | 2026-06-20 05:17 |
| GHSA-QRPV-Q767-XQQ2 CVE-2026-55255 | Langflow: IDOR Vulnerability in `/api/v1/responses` Endpoint Allows Authenticated Attackers to Access Another User's Flow | 高危 | PyPIlangflow | 已审查 | 2026-06-20 05:16 | 2026-07-08 06:14 |
| GHSA-H4GH-22QQ-72R7 CVE-2026-55206 | py7zr: O(n^2) algorithmic complexity DoS in PackInfo._read() | 中危 | PyPIpy7zr | 已审查 | 2026-06-20 05:16 | 2026-06-20 05:16 |
| GHSA-GJRG-MPP7-G774 CVE-2026-55195 | py7zr: Decompression bomb (zip bomb) denial of service via unchecked extraction size | 中危 | PyPIpy7zr | 已审查 | 2026-06-20 05:16 | 2026-06-20 05:16 |
| GHSA-W4MC-HHC6-XP28 CVE-2026-55187 | Mailpit: Incomplete SSRF protection in Link Check API via IPv6 transition mechanisms | 中危 | Gogithub.com/axllent/mailpit | 已审查 | 2026-06-20 05:16 | 2026-09-03 07:40 |
| GHSA-M999-J542-5W3R CVE-2026-55185 | Open Redirect Bypass in miniflux-v2 | 中危 | Gominiflux.app/v2 | 已审查 | 2026-06-20 05:16 | 2026-06-20 05:16 |
| GHSA-C7JM-38GQ-H67H | http4k: `ServerFilters.DigestAuth` / `DigestAuthProvider` defaulted to an always-true nonce verifier, disabling replay protection in default deployments | 中危 | Mavenorg.http4k:http4k-security-digest | 已审查 | 2026-06-20 05:16 | 2026-06-20 05:16 |
| GHSA-PR33-38XX-6R26 | http4k: BasicCookieStorage` (renamed `InsecureCookieStorage`) did not enforce RFC 6265 cookie scoping; new `DefaultCookieStorage` is now the default | 中危 | Mavenorg.http4k:http4k-core | 已审查 | 2026-06-20 05:16 | 2026-06-20 05:16 |
| GHSA-M4W9-HJFW-VWJ4 | http4k: `HmacSha256.hash` (despite the `Hmac` naming) computed a plain unkeyed digest; clarified by deprecation in favour of `Sha256.hash` / `Sha256.hmac` | 高危 | Mavenorg.http4k:http4k-core | 已审查 | 2026-06-20 05:16 | 2026-06-20 05:16 |
| GHSA-JRPC-7VXP-69P6 | http4k: `reverseProxy()` defaulted to substring (`Contains`) matching on `Host`; tightened to `Exact` | 中危 | Mavenorg.http4k:http4k-core | 已审查 | 2026-06-20 05:15 | 2026-06-20 05:15 |
| GHSA-4MR2-FG2P-W63C CVE-2026-54762 | Traefik Kubernetes Ingress NGINX provider fails open when auth-secret resolution fails | 中危 | Gogithub.com/traefik/traefik/v3 | 已审查 | 2026-06-20 05:15 | 2026-07-21 05:13 |
| GHSA-GX93-M64W-5M6H CVE-2026-55847 | Allure Report: Stored XSS via unescaped ANSI helper in status message/trace rendering | 中危 | Mavenio.qameta.allure:allure-generator | 已审查 | 2026-06-20 05:15 | 2026-06-20 05:15 |
| GHSA-82CG-3HV7-74GC CVE-2026-55846 | Allure Report: Path Traversal in HTTP Server Allows Arbitrary File Read | 中危 | Mavenio.qameta.allure:allure-commandline | 已审查 | 2026-06-20 05:15 | 2026-06-20 05:15 |
| GHSA-RPJ2-4HQ8-938G | VCR.py: Arbitrary code execution via unsafe YAML deserialization of cassette files | 高危 | PyPIvcrpy | 已审查 | 2026-06-20 05:15 | 2026-06-20 05:15 |