检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-FMGP-Q6JX-GG3X CVE-2026-55108 | KubeVela Terraform remote loader DoS via unbounded file read | 高危 | Gogithub.com/oam-dev/kubevela | 已审查 | 2026-08-29 00:13 | 2026-08-29 00:13 |
| GHSA-2VH6-HW4J-32WW | gix-packetline: reachable panic on empty side-band packet (pre-auth network DoS) |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 中危 |
crates.iogix-packetline |
| 已审查 |
| 2026-08-29 00:09 |
| 2026-08-29 00:09 |
| GHSA-8X7X-83CF-C3PG CVE-2026-54746 | Hatchet allows cross-tenant write/DoS to other tenants' workers via Dispatcher gRPC UpsertWorkerLabels and Unsubscribe | 中危 | Gogithub.com/hatchet-dev/hatchet | 已审查 | 2026-08-29 00:08 | 2026-08-29 00:08 |
| GHSA-X7RJ-F32V-7JJG CVE-2026-57584 | Phalcon: Catastrophic backtracking (ReDoS) in the default Phalcon Router route lead to remote unauthenticated DoS | 高危 | Packagistphalcon/cphalcon | 已审查 | 2026-08-29 00:06 | 2026-08-29 00:06 |
| GHSA-8JQH-95G6-7JPJ CVE-2026-54736 | Phalcon: Non-constant-time HMAC verification in `Encryption\Crypt::decrypt` (timing side-channel) | 高危 | Packagistphalcon/cphalcon | 已审查 | 2026-08-29 00:01 | 2026-08-29 00:01 |
| GHSA-VXJ7-4XRP-5VR4 CVE-2026-55558 | aiosmtplib: STARTTLS response injection | 中危 | PyPIaiosmtplib | 已审查 | 2026-08-28 07:32 | 2026-08-28 07:32 |
| GHSA-6HX8-3WJJ-GR8G CVE-2026-54770 | WebOb: Open redirect in Location header normalization via leading C0 control / space characters | 中危 | PyPIwebob | 已审查 | 2026-08-28 06:10 | 2026-08-28 06:10 |
| GHSA-PF76-Q698-37V8 | Duplicate Advisory: Uncontrolled recursion in nltk.featstruct.FeatStructReader causes unhandled RecursionError (DoS) via deeply nested feature-structure input 已撤回 | 中危 | PyPInltk | 已审查 | 2026-08-28 02:32 | 2026-09-02 22:33 |
| GHSA-HQJ7-PHWP-C3FP | Duplicate Advisory: Model-artifact APIs bypass pathsec and touch files outside allowed roots 已撤回 | 高危 | PyPInltk | 已审查 | 2026-08-28 02:32 | 2026-09-02 22:34 |
| GHSA-4XW3-JF9X-X7MF | Duplicate Advisory: Downloader.download follows hardlinks and overwrites outside-root files 已撤回 | 中危 | PyPInltk | 已审查 | 2026-08-28 02:32 | 2026-09-02 22:35 |
| GHSA-3M7F-6HXV-6796 | Duplicate Advisory: Pl196xCorpusReader has quadratic ReDoS on malformed TEI blocks 已撤回 | 中危 | PyPInltk | 已审查 | 2026-08-28 02:32 | 2026-09-02 22:49 |
| GHSA-HQV3-XM29-P9HQ | Duplicate Advisory: Quadratic CPU Exhaustion in `XMLCorpusView._read_xml_fragment()` 已撤回 | 中危 | PyPInltk | 已审查 | 2026-08-28 02:32 | 2026-09-02 22:34 |
| GHSA-8X48-8G7J-RQXP | Duplicate Advisory: Quadratic-time DoS in PorterStemmer via long runs of 'y' 已撤回 | 高危 | PyPInltk | 已审查 | 2026-08-28 02:32 | 2026-09-02 22:36 |
| GHSA-MF7Q-R4RV-JV94 | Crossplane's TOCTOU between cosign verification and image fetch in xpkg.CachedClient allows tag-based package install to bypass signature check | 高危 | Gogithub.com/crossplane/crossplane-runtime/v2 | 已审查 | 2026-08-28 01:25 | 2026-08-28 01:25 |
| GHSA-GMXC-R82Q-347R CVE-2026-54732 | libreoffice-convert vulnerable to path traversal / arbitrary file write | 中危 | npmlibreoffice-convert | 已审查 | 2026-08-28 01:23 | 2026-08-28 01:23 |
| GHSA-39MM-RWM3-29JP CVE-2026-54718 | silverstripe-advancedworkflow vulnerable to remote code execution via advanced workflow email template | 高危 | Packagistsymbiote/silverstripe-advancedworkflow | 已审查 | 2026-08-28 01:20 | 2026-08-28 01:20 |
| GHSA-G7GW-M874-7RMF CVE-2026-42350 | Kargo has Open Redirect in UI OIDC Login Flow via redirectTo Query Parameter | 低危 | Gogithub.com/akuity/kargo | 已审查 | 2026-08-28 01:17 | 2026-08-28 01:17 |
| GHSA-Q7M3-RHXG-7VXR CVE-2026-54687 | n8n-nodes-sqlite3 vulnerable to path traversal via user-controlled database file path (db_path parameter) | 中危 | npmn8n-nodes-sqlite3 | 已审查 | 2026-08-28 01:06 | 2026-08-28 01:06 |
| GHSA-R5PM-VRC5-3M73 CVE-2026-54713 | cakephp/queue's Incomplete Comparison in getUniqueId vulnerable to collisions | 低危 | Packagistcakephp/queue | 已审查 | 2026-08-28 01:03 | 2026-08-28 01:03 |
| GHSA-G8WR-R2V2-VQC6 CVE-2026-54721 | silverstripe/userforms vulnerable to remote code execution via userforms email subject | 高危 | Packagistsilverstripe/userforms | 已审查 | 2026-08-28 00:53 | 2026-08-28 00:53 |
| GHSA-GVRW-QQP5-JGC5 CVE-2026-54720 | Silverstripe Framework: Possible XSS attack through media embed | 中危 | Packagistsilverstripe/framework | 已审查 | 2026-08-28 00:49 | 2026-08-28 00:49 |
| GHSA-CRX4-7MMQ-J74J CVE-2026-44701 | OpenSTAManager has HTML Injection in modules/utenti/edit.php | 低危 | Packagistdevcode-it/openstamanager | 已审查 | 2026-08-27 02:12 | 2026-08-27 02:12 |
| GHSA-7W8C-QGXG-M7JX | LibreNMS — Stored XSS via SNMP/Syslog Data in Legacy Templates | 高危 | Packagistlibrenms/librenms | 已审查 | 2026-08-27 02:05 | 2026-08-27 02:05 |
| GHSA-2WXC-X7RJ-HG8F CVE-2026-54591 | asyncssh has SCP Path Traversal to Arbitrary File Write | 高危 | PyPIasyncssh | 已审查 | 2026-08-26 23:34 | 2026-08-26 23:34 |
| GHSA-QR67-GV47-XWWH CVE-2026-54590 | asyncssh has an incomplete fix for CVE-2026-45309 — AuthorizedKeysFile %u still escapes the intended directory via a leading ~ (and weakly via ${ENV}) username substitution | 中危 | PyPIasyncssh | 已审查 | 2026-08-26 23:32 | 2026-08-26 23:32 |