检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-64MM-VXMG-Q3VJ CVE-2026-55602 | http-proxy-middleware `router` host+path substring matching allows Host-header-driven backend routing bypass | 中危 | npmhttp-proxy-middleware | 已审查 | 2026-06-18 21:06 | 2026-06-22 23:59 |
| GHSA-3W5P-95MH-GQ75 CVE-2026-55254 | NCalc: Denial of Service via Unbounded and Non-Terminating Factorial Evaluation |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 中危 |
NuGetNCalc.Core+1 |
| 已审查 |
| 2026-06-18 21:05 |
| 2026-06-18 21:05 |
| GHSA-X9G3-XRWR-CWFG CVE-2026-55388 | piscina: Prototype Pollution Gadget → RCE via inherited options.filename | 高危 | npmpiscina | 已审查 | 2026-06-18 21:05 | 2026-06-18 21:05 |
| GHSA-R2XF-7JW5-PJG6 CVE-2026-55887 | Docker MCP Gateway: Argument injection via OCI image label YAML | 高危 | Gogithub.com/docker/mcp-gateway | 已审查 | 2026-06-18 21:05 | 2026-06-18 21:05 |
| GHSA-VPMM-X3FM-QR5C CVE-2026-55886 | jodit: Prototype pollution in Jodit via Jodit.modules.Helpers.set() | 中危 | npmjodit | 已审查 | 2026-06-18 21:05 | 2026-07-31 22:32 |
| GHSA-2MRG-35HW-X3X9 CVE-2026-55229 | Gotenberg: SSRF via LibreOffice document processing | 高危 | Gogithub.com/gotenberg/gotenberg/v8 | 已审查 | 2026-06-18 21:04 | 2026-06-18 21:04 |
| GHSA-R427-J2H7-WV3M CVE-2026-55226 | Strimzi: Unrestricted access to all Secrets within namespace watched by the Topic operator | 中危 | Mavenio.strimzi:strimzi | 已审查 | 2026-06-18 21:04 | 2026-06-18 21:04 |
| GHSA-MW9R-P8XP-WX96 CVE-2026-55225 | Strimzi: Cross-namespace privilege escalation via `Kafka.spec.entityOperator` | 高危 | Mavenio.strimzi:strimzi | 已审查 | 2026-06-18 21:04 | 2026-06-18 21:04 |
| GHSA-985F-72MJ-8GF7 CVE-2026-53863 | OpenClaw: Tool group policy callers could accept unvalidated group IDs | 中危 | npmopenclaw | 已审查 | 2026-06-18 21:04 | 2026-06-18 21:04 |
| GHSA-FQ9J-VW4W-FR6V CVE-2026-53842 | OpenClaw: Workspace .env CLOUDSDK_PYTHON could influence Gmail setup gcloud execution | 高危 | npmopenclaw | 已审查 | 2026-06-18 21:04 | 2026-06-18 21:04 |
| GHSA-F397-5VJW-V2C2 CVE-2026-53866 | OpenClaw: Shell inline-command parsing could miss an allowlist check | 高危 | npmopenclaw | 已审查 | 2026-06-18 21:03 | 2026-06-18 21:03 |
| GHSA-Q99W-VH6V-Q3V7 CVE-2026-53843 | OpenClaw: Pairing-scoped device session could restore revoked node token authority | 高危 | npmopenclaw | 已审查 | 2026-06-18 21:03 | 2026-06-18 21:03 |
| GHSA-CCWH-WWPP-6WG5 CVE-2026-53864 | OpenClaw: Host environment sanitizer missed two Node.js control variables | 高危 | npmopenclaw | 已审查 | 2026-06-18 21:02 | 2026-06-18 21:02 |
| GHSA-29JH-8CFQ-RR8X CVE-2026-55671 | ZITADEL: Server-Side Request Forgery (SSRF) and Denylist Bypass in Outgoing HTTP Components | 低危 | Gogithub.com/zitadel/zitadel | 已审查 | 2026-06-18 21:01 | 2026-06-18 21:01 |
| GHSA-HP3V-WP32-953H CVE-2026-55745 | Cotonti: Cross-Site Request Forgery in the Personal File Storage (PFS) module | 中危 | Packagistcotonti/cotonti | 已审查 | 2026-06-18 20:40 | 2026-06-19 22:51 |
| GHSA-86HP-HF3J-3M8R CVE-2026-55746 | Cotonti: Stored Cross-Site Scripting in the Personal File Storage (PFS) module | 高危 | Packagistcotonti/cotonti | 已审查 | 2026-06-18 20:40 | 2026-06-19 22:52 |
| GHSA-WX35-CV59-9GWR CVE-2026-55744 | Cotonti: Cross-Site Request Forgery in the Personal File Storage (PFS) module | 高危 | Packagistcotonti/cotonti | 已审查 | 2026-06-18 20:40 | 2026-06-19 22:53 |
| GHSA-7G3P-35VC-MGJR CVE-2026-55742 | Cotonti: Cross-Site Request Forgery in the administration rights handler | 严重 | Packagistcotonti/cotonti | 已审查 | 2026-06-18 20:40 | 2026-06-19 22:52 |
| GHSA-8M59-7XV8-735H CVE-2026-54386 | marimo contains a reflected cross-site scripting vulnerability in the notebook page | 中危 | PyPImarimo | 已审查 | 2026-06-18 08:32 | 2026-06-19 01:20 |
| GHSA-99F9-J8R3-P853 CVE-2026-53870 | Hermes Agent creates response_store.db and webhook_subscriptions.json with world-readable permissions (mode 0o644) | 中危 | PyPIhermes-agent | 已审查 | 2026-06-18 05:34 | 2026-06-19 22:48 |
| GHSA-7P36-FQ2R-4H7R CVE-2026-11407 | Pimcore CMS Twig Sandbox Bypass via SecurityPolicy checkMethodAllowed | 高危 | Packagistpimcore/pimcore | 已审查 | 2026-06-18 05:34 | 2026-09-03 00:05 |
| GHSA-4PQM-J46F-795X CVE-2026-53869 | Hermes Agent contains a DNS rebinding vulnerability in WebSocket endpoints that allows remote attackers to bypass Host and Origin validation | 高危 | PyPIhermes-agent | 已审查 | 2026-06-18 05:34 | 2026-06-19 22:47 |
| GHSA-HHPQ-7WG4-36JM CVE-2026-55590 | CakePHP Authentication: Open redirect weakness via backslash bypass | 中危 | Packagistcakephp/authentication | 已审查 | 2026-06-18 02:52 | 2026-08-15 02:35 |
| GHSA-8FQ9-273G-6MRG CVE-2026-55518 | Avo: Missing Authorization in Avo Association Attach Endpoint Allows Unauthorized Relationship Manipulation and Privilege Escalation | 严重 | RubyGemsavo | 已审查 | 2026-06-18 02:49 | 2026-07-19 01:22 |
| GHSA-X2QC-CMH9-F4HF CVE-2026-55517 | Deno: Denial of service via non-ASCII bytes in WebSocket response headers | 中危 | crates.iodeno | 已审查 | 2026-06-18 02:48 | 2026-06-18 02:48 |