检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-2F55-G35J-5JMF CVE-2026-55471 | HAPI FHIR: XXE in XsltUtilities.saxonTransform via unhardened Saxon TransformerFactory | 严重 | Mavenca.uhn.hapi.fhir:org.hl7.fhir.utilities | 已审查 | 2026-06-18 02:47 | 2026-06-18 02:47 |
| GHSA-FXJ4-P9XP-37V5 CVE-2026-55470 |
当前筛选结果 35,190 条 · 时间按北京时间显示
HAPI FHIR: Incomplete fix for CVE-2026-45367: DSTU2 FHIRPathEngine.matches() missing RegexTimeout protection allows ReDoS |
| 高危 |
Mavenca.uhn.hapi.fhir:org.hl7.fhir.convertors+3 |
| 已审查 |
| 2026-06-18 02:47 |
| 2026-06-18 02:47 |
| GHSA-X223-P2GF-V735 CVE-2026-55450 | Langflow: Unauthenticated file upload leads to DoS (space exhaustion) and information leak | 严重 | PyPIlangflow | 已审查 | 2026-06-18 02:43 | 2026-06-18 02:43 |
| GHSA-R4GV-QR8J-P3PG CVE-2026-55760 | handlebars.java FileTemplateLoader Path Traversal | 高危 | Mavencom.github.jknack:handlebars | 已审查 | 2026-06-18 02:42 | 2026-06-18 02:42 |
| GHSA-M9CV-24RX-8MV7 CVE-2026-55409 | Filament: Disabled RichEditor field state can be used for XSS | 高危 | Packagistfilament/forms | 已审查 | 2026-06-18 02:41 | 2026-06-18 02:41 |
| GHSA-2MFG-CC43-9PCJ CVE-2026-55405 | LangChain4j: SQL injection via metadata filters in langchain4j-mariadb and langchain4j-pgvector | 高危 | Mavendev.langchain4j:langchain4j-mariadb+1 | 已审查 | 2026-06-18 02:39 | 2026-06-18 02:39 |
| GHSA-52MM-H59V-F3C7 CVE-2026-48591 | earmark: Stored XSS via unescaped HTML attribute values | 中危 | Hexearmark | 已审查 | 2026-06-18 02:35 | 2026-06-18 22:47 |
| GHSA-J6C9-QVP8-699F | Duplicate Advisory: picklescan missing detection by simple obfuscation of a `builtins.eval` call 已撤回 | 严重 | PyPIpicklescan | 已审查 | 2026-06-18 02:35 | 2026-06-18 22:41 |
| GHSA-CC5P-54X3-HCF8 | Duplicate Advisory: Picklescan (scan_pytorch) Bypass via dynamic eval MAGIC_NUMBER 已撤回 | 高危 | PyPIpicklescan | 已审查 | 2026-06-18 02:35 | 2026-06-18 22:43 |
| GHSA-C43C-RF7G-5XPG CVE-2026-12515 | katello: missing repository authorization in content_uploads exposes cross-product content existence | 中危 | RubyGemskatello | 已审查 | 2026-06-18 02:35 | 2026-08-05 08:30 |
| GHSA-82FG-2R99-H7V6 | Duplicate Advisory: PickleScan's pkgutil.resolve_name has a universal blocklist bypass 已撤回 | 严重 | PyPIpicklescan | 已审查 | 2026-06-18 02:35 | 2026-06-18 22:45 |
| GHSA-5V23-73V4-W2FP | Duplicate Advisory: picklescan has Arbitrary file read using `io.FileIO` 已撤回 | 高危 | PyPIpicklescan | 已审查 | 2026-06-18 02:35 | 2026-06-18 22:46 |
| GHSA-4MPJ-78P6-RJ59 | Duplicate Advisory: PickleScan's profile.run blocklist mismatch allows exec() bypass 已撤回 | 严重 | PyPIpicklescan | 已审查 | 2026-06-18 02:35 | 2026-06-18 22:43 |
| GHSA-RMPP-8WF5-XX5Q | Duplicate Advisory: Picklescan vulnerable to Arbitrary File Writing 已撤回 | 严重 | PyPIpicklescan | 已审查 | 2026-06-18 02:35 | 2026-06-18 22:44 |
| GHSA-9G3X-6X24-VF9F CVE-2025-26240 | pdfkit: Path traversal in from_string | 高危 | PyPIpdfkit | 已审查 | 2026-06-18 02:35 | 2026-06-18 22:38 |
| GHSA-7F79-RVX6-VXC4 | Duplicate Advisory: Picklescan does not block ctypes 已撤回 | 严重 | PyPIpicklescan | 已审查 | 2026-06-18 02:35 | 2026-06-18 22:44 |
| GHSA-6WRM-X65G-HR4P CVE-2026-55748 | OpenStack Horizon RC file generation does not escape special characters in project names | 中危 | PyPIhorizon | 已审查 | 2026-06-18 02:35 | 2026-06-18 22:37 |
| GHSA-6V84-V468-3C7F | Duplicate Advisory: Picklescan has Incomplete List of Disallowed Inputs 已撤回 | 严重 | PyPIpicklescan | 已审查 | 2026-06-18 02:35 | 2026-06-18 22:40 |
| GHSA-5RPH-Q42J-36J9 | Duplicate Advisory: Picklescan has pickle parsing logic flaw that leads to malicious pickle file bypass 已撤回 | 严重 | PyPIpicklescan | 已审查 | 2026-06-18 02:35 | 2026-06-18 22:40 |
| GHSA-5GP7-4733-2W2V | Duplicate Advisory: Picklescan Bypasses Unsafe Globals Check using pty.spawn 已撤回 | 高危 | PyPIpicklescan | 已审查 | 2026-06-18 02:35 | 2026-06-18 22:41 |
| GHSA-X96M-RH44-VGV8 CVE-2026-49268 | Apache Shiro: LDAP DN Injection in DefaultLdapRealm | 高危 | Mavenorg.apache.shiro:shiro-core | 已审查 | 2026-06-18 02:35 | 2026-06-18 22:37 |
| GHSA-QF38-JQ28-3CCQ CVE-2026-50203 | Apache Airflow SFTP provider: Path traversal in SFTPHook.retrieve_directory | 严重 | PyPIapache-airflow-providers-sftp | 已审查 | 2026-06-18 02:35 | 2026-07-10 05:07 |
| GHSA-694G-J8PJ-CJJ5 CVE-2026-47340 | Apache DolphinScheduler: An incorrect authorization vulnerability allows authenticated users to access alert instances associated with alert groups they do not have permission to access. | 中危 | Mavenorg.apache.dolphinscheduler:dolphinscheduler-api | 已审查 | 2026-06-18 02:35 | 2026-06-18 22:34 |
| GHSA-WV7F-C794-82V6 CVE-2026-42357 | Apache DolphinScheduler: Incorrect Authorization vulnerability allows users to access workflow instance information belonging to projects they do not have permission to access. | 中危 | Mavenorg.apache.dolphinscheduler:dolphinscheduler-api | 已审查 | 2026-06-18 02:35 | 2026-06-18 22:34 |
| GHSA-WH3W-V6GJ-FQH2 CVE-2026-41280 | Apache DolphinScheduler: Incorrect Authorization vulnerability allows users with system login privileges to delete task definitions in unauthorized projects | 中危 | Mavenorg.apache.dolphinscheduler:dolphinscheduler-api | 已审查 | 2026-06-18 02:35 | 2026-06-18 22:32 |