检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-2288-8H3R-CQGG CVE-2026-54784 | CoreWCF: SPNEGO SecurityContextToken proof key wrapped without confidentiality | 高危 | NuGetCoreWCF.Primitives | 已审查 | 2026-06-20 04:47 | 2026-06-20 04:47 |
| GHSA-GQV6-PWCG-87R8 CVE-2026-54783 | CoreWCF: XML Signature Wrapping in WS-Security endorsing/supporting signature verification allows replay of captured signed messages |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 高危 |
NuGetCoreWCF.Primitives |
| 已审查 |
| 2026-06-20 04:47 |
| 2026-06-20 04:47 |
| GHSA-XJR9-GG9Q-JX3V CVE-2026-54782 | CoreWCF: Authentication bypass in CoreWCF SAML 1.1 / 2.0 token signature validation | 严重 | NuGetCoreWCF.Primitives | 已审查 | 2026-06-20 04:47 | 2026-06-20 04:47 |
| GHSA-48PQ-2XQ3-C2M4 CVE-2026-54781 | CoreWCF: SAML SubjectConfirmation methods and holder-of-key proof keys are not enforced | 高危 | NuGetCoreWCF.Primitives | 已审查 | 2026-06-20 04:47 | 2026-06-20 04:47 |
| GHSA-4V55-CPMV-3VCM CVE-2026-54780 | CoreWCF: WS-Security Reference DigestMethod Algorithm-Suite Bypass | 低危 | NuGetCoreWCF.Primitives | 已审查 | 2026-06-20 04:47 | 2026-06-20 04:47 |
| GHSA-9JR3-RJ99-8JQ3 CVE-2026-54779 | CoreWCF: SAML token replay protection is inoperative | 中危 | NuGetCoreWCF.Primitives | 已审查 | 2026-06-20 04:47 | 2026-06-20 04:47 |
| GHSA-Q6V9-43V5-JV9Q CVE-2026-54778 | CoreWCF: UnixDomainSocket Non-Reentrant POSIX Identity Resolution | 中危 | NuGetCoreWCF.UnixDomainSocket | 已审查 | 2026-06-20 04:46 | 2026-06-20 04:46 |
| GHSA-6JJ2-4Q5C-X8G6 CVE-2026-54777 | CoreWCF NetNamedPipe transport accepts attach to a pre-existing named pipe instance | 中危 | NuGetCoreWCF.NetNamedPipe | 已审查 | 2026-06-20 04:46 | 2026-06-20 04:46 |
| GHSA-WJPQ-6766-7F5J CVE-2026-54776 | CoreWCF: Unix Domain Socket PosixIdentity transport accepts connections that skip the security upgrade | 中危 | NuGetCoreWCF.UnixDomainSocket | 已审查 | 2026-06-20 04:46 | 2026-06-20 04:46 |
| GHSA-M744-JHQ9-PPW6 CVE-2026-54775 | CoreWCF: Kafka consume pump halts permanently on a Kafka tombstone (null-value record), causing persistent endpoint denial of service. | 中危 | NuGetCoreWCF.Kafka | 已审查 | 2026-06-20 04:46 | 2026-06-20 04:46 |
| GHSA-RPJ7-HR7H-W6P9 CVE-2026-54774 | CoreWCF: SamlSerializer skips SignatureValue verification when SAML signing token is not an X.509 certificate | 高危 | NuGetCoreWCF.Primitives | 已审查 | 2026-06-20 04:46 | 2026-06-20 04:46 |
| GHSA-JC6X-RJ79-W4MX CVE-2026-54773 | CoreWCF: WS-Security signature substitution via document-wide Signature lookup | 中危 | NuGetCoreWCF.Primitives | 已审查 | 2026-06-20 04:46 | 2026-06-20 04:46 |
| GHSA-P86G-XRR2-PF7C CVE-2026-54772 | CoreWCF: Pre-authentication infinite-loop CPU exhaustion in CoreWCF net.tcp / net.pipe / net.uds framing handshake | 高危 | NuGetCoreWCF.NetFramingBase | 已审查 | 2026-06-20 04:46 | 2026-06-20 04:46 |
| GHSA-VQ2F-VCC9-J8MV CVE-2026-55865 | Python Liquid: Infinite loop when parsing malformed `{% case %}` tags | 中危 | PyPIpython-liquid | 已审查 | 2026-06-20 04:46 | 2026-06-20 04:46 |
| GHSA-Q2GM-54R6-8FWM CVE-2026-54898 | Oj: Use-After-Free in Oj::Parser SAJ Callback via Input Mutation | 高危 | RubyGemsoj | 已审查 | 2026-06-20 03:36 | 2026-06-20 03:36 |
| GHSA-9PPP-W3G4-FH4Q CVE-2026-54897 | Oj: Use-After-Free in Oj::Doc Iterators via Reentrant Close | 高危 | RubyGemsoj | 已审查 | 2026-06-20 03:36 | 2026-06-20 03:36 |
| GHSA-35W3-PJM6-WJ95 CVE-2026-54896 | Oj: Heap Buffer Overflow in Oj.dump Exception Serialization via Large Indent | 高危 | RubyGemsoj | 已审查 | 2026-06-20 03:36 | 2026-06-20 03:36 |
| GHSA-V8X7-R927-CC93 CVE-2026-55778 | parse-server: Stored XSS via non-standard file extension bypassing file upload extension blocklist | 低危 | npmparse-server | 已审查 | 2026-06-20 03:36 | 2026-06-20 03:36 |
| GHSA-3M6Q-JJ5J-38C9 CVE-2026-54592 | Oj: Stack Buffer Overflow in Oj::Doc#each_child via Deeply Nested Input | 高危 | RubyGemsoj | 已审查 | 2026-06-20 03:36 | 2026-06-20 03:36 |
| GHSA-436Q-JWFR-RM2H CVE-2026-54528 | jupyterlab-git excluded_paths Case-Sensitivity Bypass Allows Reading Excluded Directories | 高危 | PyPIjupyterlab-git | 已审查 | 2026-06-20 03:36 | 2026-06-20 03:36 |
| GHSA-F962-V9HR-PFG5 CVE-2026-54527 | jupyterlab-git extension: Stored XSS leading to RCE | 高危 | npm@jupyterlab/git+2 | 已审查 | 2026-06-20 03:36 | 2026-06-20 03:36 |
| GHSA-FM7P-MPRW-WJM9 CVE-2026-54500 | Oj: intern.c form_attr (uninitialized stack read) | 中危 | RubyGemsoj | 已审查 | 2026-06-20 03:35 | 2026-06-20 03:35 |
| GHSA-V5JW-96JM-7H2C CVE-2026-54499 | Stanza: Remote Code Execution via Unsafe Pickle Deserialization in Model Loaders | 高危 | PyPIstanza | 已审查 | 2026-06-20 03:35 | 2026-06-20 03:35 |
| GHSA-X84V-G949-293W CVE-2026-54317 | Home Assistant: Konnected alarm-panel switch state and zone topology disclosed to unauthenticated actors on the LAN | 高危 | PyPIhomeassistant | 已审查 | 2026-06-20 03:35 | 2026-07-21 05:11 |
| GHSA-98M9-HRRM-R99R CVE-2026-54297 | Faraday: Uncontrolled recursion in NestedParamsEncoder allows stack exhaustion DoS via deeply nested query parameters | 高危 | RubyGemsfaraday | 已审查 | 2026-06-20 03:35 | 2026-06-27 03:27 |