检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-JR33-MW75-7J8F CVE-2026-55837 | dbt MCP Server: Unauthenticated OAuth Context Endpoint Leaks dbt Platform Tokens | 中危 | PyPIdbt-mcp | 已审查 | 2026-06-20 05:15 | 2026-06-20 05:15 |
| GHSA-P5WC-9W9R-M232 | Ultimate Sitemap Parser (USP): XML Entity Expansion (Billion Laughs) DoS in XMLSitemapParser |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 高危 |
PyPIultimate-sitemap-parser |
| 已审查 |
| 2026-06-20 05:15 |
| 2026-06-20 05:15 |
| GHSA-8823-QG2X-PV9F | Ultimate Sitemap Parser (USP): Gzip Decompression Bomb Bypasses Sitemap Size Limit | 高危 | PyPIultimate-sitemap-parser | 已审查 | 2026-06-20 05:15 | 2026-06-20 05:15 |
| GHSA-F9M7-VC86-P6JJ CVE-2026-55828 | go.qbee.io/transport: Symlink-chain path traversal in tar extraction (one level outside destination) | 中危 | Gogo.qbee.io/transport | 已审查 | 2026-06-20 05:15 | 2026-06-20 05:15 |
| GHSA-G5QX-H5F3-MP2F CVE-2026-55660 | TinaCMS: Cross-origin postMessage handlers and rich-text URL-sanitization bypass enable stored XSS and session takeover | 高危 | npm@tinacms/app+1 | 已审查 | 2026-06-20 05:15 | 2026-06-20 05:15 |
| GHSA-H5GM-X9WR-VHCM CVE-2026-55795 | Craft Commerce: Coupon Code Brute-Force via Rate Limit Bypass | 中危 | Packagistcraftcms/commerce | 已审查 | 2026-06-20 05:15 | 2026-06-20 05:15 |
| GHSA-78VR-Q6CF-C7P6 | Craft Commerce: Partial Payment Amount Without Lower Bound Validation | 中危 | Packagistcraftcms/commerce | 已审查 | 2026-06-20 05:15 | 2026-06-20 05:15 |
| GHSA-C55V-343G-5XFF CVE-2026-55791 | Craft CMS: Blind SSRF and Arbitrary JavaScript Injection via Host Header Poisoning in actionResourceJs | 严重 | Packagistcraftcms/cms | 已审查 | 2026-06-20 05:15 | 2026-06-20 05:15 |
| GHSA-4936-9HRH-QQPW CVE-2026-54074 | @tinacms/cli: Remote Code Execution in @tinacms/cli via Forestry migration — unsanitised __TINA_INTERNAL__ marker in user-controlled YAML labels | 高危 | npm@tinacms/cli | 已审查 | 2026-06-20 05:15 | 2026-06-20 05:15 |
| GHSA-7H5P-637F-JFR7 CVE-2026-55691 | StarCitizenWiki Extension Embed Video: Stored XSS via unsanitized class passed to template | 高危 | Packagiststarcitizenwiki/embedvideo | 已审查 | 2026-06-20 05:15 | 2026-06-20 05:15 |
| GHSA-C29Q-5XM7-5P62 CVE-2026-55690 | StarCitizenWiki Extension Embed Video: Stored XSS via unsanitized service name in exception text | 高危 | Packagiststarcitizenwiki/embedvideo | 已审查 | 2026-06-20 05:14 | 2026-06-20 05:14 |
| GHSA-FCW4-WWQM-M8CF CVE-2026-11769 | Grafana Operator: Privilege escalation from namespace admin to cluster admin via GrafanaDashboard jsonnetLib fileName | 中危 | Gogithub.com/grafana/grafana-operator+1 | 已审查 | 2026-06-20 04:51 | 2026-06-20 04:51 |
| GHSA-WFQX-GJRF-G28R | Crossplane: Signature verification TOCTOU allows installing unverified package content via mutable tag | 严重 | Gogithub.com/crossplane/crossplane+1 | 已审查 | 2026-06-20 04:47 | 2026-06-20 04:47 |
| GHSA-HP36-V28F-W3R4 CVE-2026-55091 | flat-to-nested: Prototype pollution in flat-to-nested convert() via __proto__ parent/id key | 高危 | npmflat-to-nested | 已审查 | 2026-06-20 04:47 | 2026-06-20 04:47 |
| GHSA-V75R-VX73-82PJ CVE-2026-55849 | @cyclonedx/cyclonedx-npm: Shell Injection via Unsanitized --workspace Argument | 高危 | npm@cyclonedx/cyclonedx-npm | 已审查 | 2026-06-20 04:47 | 2026-06-20 04:47 |
| GHSA-X845-2F78-7V36 | Blocky DNSSEC validation bypass and validation-cache scope pollution | 高危 | Gogithub.com/0xERR0R/blocky | 已审查 | 2026-06-20 04:47 | 2026-06-20 04:47 |
| GHSA-3J69-69WJ-XQX2 CVE-2026-54911 | UltraJSON: Malformed/Truncated UTF-8 Accepted and Silently Rewritten in ujson.dumps() | 中危 | PyPIujson | 已审查 | 2026-06-20 04:47 | 2026-07-19 01:28 |
| GHSA-6WX8-W4F5-WWCR CVE-2026-54906 | Concurrent Ruby: ReadWriteLock allows wrong-thread write release and stray read-release counter corruption | 低危 | RubyGemsconcurrent-ruby | 已审查 | 2026-06-20 04:47 | 2026-06-20 04:47 |
| GHSA-WV3X-4VXV-WHPP CVE-2026-54905 | Concurrent Ruby: `ReentrantReadWriteLock` read-count overflow grants a write lock without exclusivity | 低危 | RubyGemsconcurrent-ruby | 已审查 | 2026-06-20 04:47 | 2026-07-20 21:36 |
| GHSA-H8W8-99G7-QMVJ CVE-2026-54904 | Concurrent Ruby : `AtomicReference#update` livelocks when the stored value is `Float::NAN` | 高危 | RubyGemsconcurrent-ruby | 已审查 | 2026-06-20 04:47 | 2026-08-06 01:36 |
| GHSA-475M-PH3X-64GP CVE-2026-54903 | Oj: Integer Overflow in Oj.load 2GB String Handling | 高危 | RubyGemsoj | 已审查 | 2026-06-20 04:47 | 2026-06-20 04:47 |
| GHSA-M578-W5VF-RFCM CVE-2026-54902 | Oj: Use-After-Free in Oj::Parser SAJ Long Key Callback | 高危 | RubyGemsoj | 已审查 | 2026-06-20 04:47 | 2026-06-20 04:47 |
| GHSA-VWM4-62GF-X745 CVE-2026-54901 | Oj: Use-After-Free in Oj::Parser array_class/hash_class GC Marking | 高危 | RubyGemsoj | 已审查 | 2026-06-20 04:47 | 2026-06-20 04:47 |
| GHSA-9CV6-QCJW-4GRX CVE-2026-54900 | Oj: Negative-Size memcpy in Oj::Parser create_id Attribute Handling | 高危 | RubyGemsoj | 已审查 | 2026-06-20 04:47 | 2026-06-20 04:47 |
| GHSA-V52W-28XH-V562 | Kozou: Unauthenticated MCP HTTP server and bundled dev-stack hardening (DNS-rebinding, request-body limits, read-only reads, default network exposure) | 高危 | npm@kozou/api+3 | 已审查 | 2026-06-20 04:47 | 2026-06-20 04:47 |