检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-HM92-R4W5-C3MJ CVE-2026-6734 | undici vulnerable to cross-origin request routing via SOCKS5 proxy pool reuse | 高危 | npmundici | 已审查 | 2026-06-19 22:20 | 2026-06-19 22:20 |
| GHSA-35P6-XMWP-9G52 CVE-2026-6733 | undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 低危 |
npmundici |
| 已审查 |
| 2026-06-19 22:19 |
| 2026-08-06 05:48 |
| GHSA-WPWQ-4J6V-78M3 CVE-2026-55568 | guzzlehttp/guzzle: Silent HTTPS-Proxy Downgrade to Cleartext | 中危 | Packagistguzzlehttp/guzzle | 已审查 | 2026-06-19 22:17 | 2026-06-19 22:17 |
| GHSA-XM3X-9CFW-JHX4 CVE-2026-55414 | NL Portal Backend Libraries: Unauthenticated form resolver forwards the privileged Objecten-API token to a caller-supplied URL (SSRF) | 中危 | Mavennl.nl-portal:form | 已审查 | 2026-06-19 22:17 | 2026-06-19 22:17 |
| GHSA-37PM-83G7-R22V CVE-2026-55375 | canto-saas-api: OAuth credentials exposed in URL query string and exception messages | 中危 | Packagistjleehr/canto-saas-api | 已审查 | 2026-06-19 22:16 | 2026-06-19 22:16 |
| GHSA-9QFV-WGH2-M6P8 CVE-2026-55374 | canto-saas-api: Authenticated API requests can be redirected via unencoded path variables | 中危 | Packagistjleehr/canto-saas-api | 已审查 | 2026-06-19 22:13 | 2026-06-19 22:13 |
| GHSA-C73Q-8XXR-RGQM CVE-2026-55884 | Tilt: Missing authentication on the network-exposed Tilt HUD server | 严重 | Gogithub.com/tilt-dev/tilt | 已审查 | 2026-06-19 21:58 | 2026-06-19 21:58 |
| GHSA-6M68-R693-78QX CVE-2026-55883 | Tilt: Cross-site WebSocket hijacking of the Tilt HUD stream | 高危 | Gogithub.com/tilt-dev/tilt | 已审查 | 2026-06-19 21:53 | 2026-07-21 21:44 |
| GHSA-P749-9W62-W533 CVE-2026-55882 | Tilt: Unauthenticated pprof debug endpoints on the Tilt HUD server | 高危 | Gogithub.com/tilt-dev/tilt | 已审查 | 2026-06-19 21:52 | 2026-06-19 21:52 |
| GHSA-QW6V-5FCF-5666 CVE-2026-54051 | Network-AI: Improper Neutralization of Special Elements used in an OS Command | 严重 | npmnetwork-ai | 已审查 | 2026-06-19 21:35 | 2026-06-19 21:35 |
| GHSA-R78R-RWRF-RJWP CVE-2026-48814 | Network-AI: CVE-2026-46701 fix incomplete — empty default secret still authorizes all requests | 严重 | npmnetwork-ai | 已审查 | 2026-06-19 21:34 | 2026-06-19 21:34 |
| GHSA-87MF-GV2C-C62C CVE-2026-12644 | ts-deepmerge: Prototype Method Override leads to DoS | 中危 | npmts-deepmerge | 已审查 | 2026-06-19 14:31 | 2026-06-20 05:41 |
| GHSA-XG3J-C7Q4-F9PH CVE-2026-10720 | Canonical MicroCeph: path traversal issue in the remote-import AP | 中危 | Gogithub.com/canonical/microceph/microceph | 已审查 | 2026-06-19 14:31 | 2026-07-21 23:01 |
| GHSA-X44P-GG67-52FC | Duplicate Advisory: PraisonAI: Coarse-Grained Tool Approval Cache Bypasses Per-Invocation Consent for Shell Commands 已撤回 | 中危 | PyPIpraisonai | 已审查 | 2026-06-19 08:31 | 2026-06-20 05:32 |
| GHSA-FWH2-95JW-G4J6 | Duplicate Advisory: PraisonAI has Memory State Leakage and Path Traversal in MultiAgent Context Handling 已撤回 | 高危 | PyPIpraisonai | 已审查 | 2026-06-19 08:31 | 2026-06-20 05:33 |
| GHSA-Q59X-JC9F-GFQF CVE-2026-55591 | Signal K Server: Server-Side Request Forgery via Remote Connection Endpoints | 中危 | npmsignalk-server | 已审查 | 2026-06-19 05:13 | 2026-06-19 05:13 |
| GHSA-5739-39V2-5754 | PHP JWT Library: RSA1_5 (RSAES-PKCS1-v1_5) decryption lacks implicit rejection, exposing a Bleichenbacher/Marvin padding oracle | 中危 | Packagistweb-token/jwt-library | 已审查 | 2026-06-19 05:09 | 2026-08-31 22:52 |
| GHSA-JC38-X7X8-2XC8 | PHP JWT Framework: JWSVerifier uses algorithm from unprotected header, enabling algorithm confusion attacks | 高危 | Packagistweb-token/jwt-bundle+3 | 已审查 | 2026-06-19 05:09 | 2026-07-07 00:29 |
| GHSA-3PRJ-6HQW-CM82 | PHP JWT Library: PBES2-HS*+A*KW unwrap accepts an unbounded p2c iteration count, enabling CPU-amplification denial of service | 高危 | Packagistweb-token/jwt-framework+1 | 已审查 | 2026-06-19 05:09 | 2026-07-16 05:51 |
| GHSA-6VVH-PXR4-25R7 | PHP JWT Framework: Chacha20Poly1305 key-encryption algorithm discards the Poly1305 authentication tag, performing no authentication on decryption | 中危 | Packagistweb-token/jwt-experimental+1 | 已审查 | 2026-06-19 05:08 | 2026-06-19 05:08 |
| GHSA-2JX3-65F3-XR8R | spomky-labs/otphp: Mass-assignment in Factory::loadFromProvisioningUri lets a hostile provisioning URI corrupt OTP state or leak an uncaught TypeError | 中危 | Packagistspomky-labs/otphp | 已审查 | 2026-06-19 05:07 | 2026-06-19 05:07 |
| GHSA-G7M4-839X-CH6V | spomky-labs/otphp: Unbounded digits parameter in a provisioning URI triggers an uncaught DivisionByZeroError in OTP generation | 高危 | Packagistspomky-labs/otphp | 已审查 | 2026-06-19 04:45 | 2026-06-19 04:45 |
| GHSA-4H5R-5JM8-JXJM CVE-2026-0755 | gemini-mcp-tool vulnerable to OS command injection and @file exfiltration via prompt quoting (CVE-2026-0755) | 严重 | npmgemini-mcp-tool | 已审查 | 2026-06-19 04:44 | 2026-06-19 04:44 |
| GHSA-4HPG-MP64-X7XQ CVE-2026-53854 | OpenClaw: Internal/webchat command auth could inherit ownerAllowFrom wildcard state | 中危 | npmopenclaw | 已审查 | 2026-06-19 04:44 | 2026-06-19 04:44 |
| GHSA-8MG9-J9CF-54CJ CVE-2026-53852 | OpenClaw: Empty-scope device re-pairing could confuse caller scope containment | 低危 | npmopenclaw | 已审查 | 2026-06-19 04:42 | 2026-06-19 04:42 |