检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-33VJ-92QQ-66HC CVE-2026-53492 | containerd CRI checkpoint restore CDI annotation smuggling | 高危 | Gogithub.com/containerd/containerd/v2 | 已审查 | 2026-06-20 03:35 | 2026-06-20 03:35 |
| GHSA-RGH6-RFWX-V388 CVE-2026-53489 | Arbitrary host CRI log file read via symlink following in CRI checkpoint restore |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 高危 |
Gogithub.com/containerd/containerd/v2 |
| 已审查 |
| 2026-06-20 03:35 |
| 2026-06-20 03:35 |
| GHSA-XHF5-7WJV-PQXP CVE-2026-53488 | containerd CRI — image-config `LABEL` flows to restart-monitor `binary://` logger: host-root command execution from an image pull | 高危 | Gogithub.com/containerd/containerd+1 | 已审查 | 2026-06-20 03:35 | 2026-06-20 03:35 |
| GHSA-3V45-F3VH-WG7M CVE-2026-54502 | Oj: Stack Buffer Overflow in Oj.dump via Large Indent | 高危 | RubyGemsoj | 已审查 | 2026-06-20 03:35 | 2026-06-20 03:35 |
| GHSA-CVXM-645Q-P574 CVE-2026-50195 | containerd: CRI checkpoint import allows local image tag poisoning | 中危 | Gogithub.com/containerd/containerd/v2 | 已审查 | 2026-06-20 03:35 | 2026-07-21 22:41 |
| GHSA-WMWX-JR2P-4J4R CVE-2026-53726 | parse-server: Relation `$relatedTo` query bypasses `protectedFields` and owning-object ACL | 中危 | npmparse-server | 已审查 | 2026-06-20 03:35 | 2026-06-20 03:35 |
| GHSA-75V4-M273-5J49 CVE-2026-53725 | parse-server: Endpoints `/login` and `/verifyPassword` disclose MFA secrets and protected fields when `_User` get is denied | 中危 | npmparse-server | 已审查 | 2026-06-20 03:35 | 2026-06-20 03:35 |
| GHSA-7WQV-XJF3-X35V CVE-2026-53724 | parse-server: Stored XSS via trailing-dot filename bypassing file upload extension blocklist | 低危 | npmparse-server | 已审查 | 2026-06-20 03:35 | 2026-06-20 03:35 |
| GHSA-MWQM-4FW3-CJVR CVE-2026-49216 | symfony/ux-autocomplete: XSS via unescaped AJAX response data | 中危 | Packagistsymfony/ux-autocomplete | 已审查 | 2026-06-20 03:35 | 2026-06-20 03:35 |
| GHSA-4M4J-HMQQ-3GXM CVE-2026-49215 | symfony/ux-live-component: CSRF Protection Bypass — Accept Header is CORS-Safelisted | 低危 | Packagistsymfony/ux-live-component | 已审查 | 2026-06-20 03:35 | 2026-06-20 03:35 |
| GHSA-34W5-C283-J9FG CVE-2026-49212 | symfony/ux-live-component: LiveComponentHydrator HMAC checksum lacks component and slot binding | 低危 | Packagistsymfony/ux-live-component | 已审查 | 2026-06-20 03:34 | 2026-06-20 03:34 |
| GHSA-946H-JP5C-8FVH CVE-2026-49211 | symfony/ux-autocomplete: Information exposure via unescaped LIKE wildcards in EntitySearchUtil | 中危 | Packagistsymfony/ux-autocomplete | 已审查 | 2026-06-20 03:34 | 2026-06-20 03:34 |
| GHSA-38X5-RCV4-XF7X CVE-2026-49210 | symfony/ux-live-component: XSS via attacker-controlled child component tag | 中危 | Packagistsymfony/ux-live-component | 已审查 | 2026-06-20 03:34 | 2026-06-20 03:34 |
| GHSA-MM82-C99C-H2CF CVE-2026-49209 | symfony/ux-live-component: Denial of service via unbounded batch action requests | 低危 | Packagistsymfony/ux-live-component | 已审查 | 2026-06-20 03:34 | 2026-06-20 03:34 |
| GHSA-P84R-H6RX-F2XR CVE-2026-50008 | parse-server: Server option routeAllowList is bypassable through batch sub-requests | 中危 | npmparse-server | 已审查 | 2026-06-20 03:34 | 2026-06-20 03:34 |
| GHSA-JPCC-P29G-P8MQ CVE-2026-47262 | containerd image-triggered runtime DoS via unbounded group parsing | 中危 | Gogithub.com/containerd/containerd+1 | 已审查 | 2026-06-20 03:34 | 2026-06-20 03:34 |
| GHSA-2CW7-V8FF-P88R CVE-2026-54899 | Oj: Use-After-Free in Oj::Parser Symbol Key Cache Toggle | 高危 | RubyGemsoj | 已审查 | 2026-06-20 03:34 | 2026-06-20 03:34 |
| GHSA-89G7-22C8-3J23 CVE-2026-49208 | ux-live-component: Format-less date LiveProps parsed with the permissive DateTime constructor | 中危 | Packagistsymfony/ux-live-component | 已审查 | 2026-06-20 03:23 | 2026-06-20 03:23 |
| GHSA-Q6RC-2CGV-63H7 CVE-2026-23879 | py7zr: Arbitrary File Write Vulnerability | 高危 | PyPIpy7zr | 已审查 | 2026-06-20 03:21 | 2026-07-21 21:17 |
| GHSA-9GGV-8W38-R7PM | TypeORM: SQL Injection in UpdateQueryBuilder/SoftDeleteQueryBuilder orderBy (MySQL/MariaDB) | 中危 | npmtypeorm | 已审查 | 2026-06-20 03:18 | 2026-06-20 03:18 |
| GHSA-R46F-3RPW-HXRV | Hugo: security.http.urls deny rules bypassed by alternate IPv4 encodings (SSRF) | 高危 | Gogithub.com/gohugoio/hugo | 已审查 | 2026-06-20 03:18 | 2026-06-20 03:18 |
| GHSA-MQQ5-J7W8-2HGH | AlchemyCMS: Unauthenticated nested page API leaks restricted & unpublished content | 高危 | RubyGemsalchemy_cms | 已审查 | 2026-06-20 01:47 | 2026-06-20 01:47 |
| GHSA-C3WQ-J5VH-68RC | Hugo: Symlink confinement bypass in os.ReadFile | 中危 | Gogithub.com/gohugoio/hugo | 已审查 | 2026-06-20 01:45 | 2026-06-20 01:45 |
| GHSA-Q76J-GCG9-VXC6 | Hugo: XSS via unescaped code-fence language in default code block renderer | 中危 | Gogithub.com/gohugoio/hugo | 已审查 | 2026-06-20 01:45 | 2026-06-20 01:45 |
| GHSA-9WXG-VF3R-56HC | OpenZeppelin Contracts Wizard: Line terminators in info.securityContact / info.license can inject lines into generated source | 低危 | npm@openzeppelin/wizard+3 | 已审查 | 2026-06-20 01:45 | 2026-06-20 01:45 |