检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-P46M-G734-VPC4 CVE-2026-54614 | cakephp/debug_kit: MailPreview contains unsafe reflection | 中危 | Packagistcakephp/debug_kit | 已审查 | 2026-08-26 23:31 | 2026-08-26 23:31 |
| GHSA-JRW6-7X4Q-W25J CVE-2026-54569 | senaite.core Vulnerable to Eval Injection and Missing Authorization |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 严重 |
PyPIsenaite.core |
| 已审查 |
| 2026-08-26 23:28 |
| 2026-08-26 23:28 |
| GHSA-W93Q-CQ9W-58P7 CVE-2026-54606 | SunEditor Embed Plugin has DOM XSS via External Script Element After Iframe Embed | 高危 | npmsuneditor | 已审查 | 2026-08-26 23:26 | 2026-08-26 23:26 |
| GHSA-W5FV-7X5Q-G8QP CVE-2026-54563 | Cloudreve WebDAV (`/dav`) has Path Traversal / Broken Access Control — scoped DAV credential escapes its configured account root | 高危 | Gogithub.com/cloudreve/Cloudreve/v3+1 | 已审查 | 2026-08-26 23:22 | 2026-08-26 23:22 |
| GHSA-X287-5C68-36WP | OpenWISP IPAM has broken object-level authorization: ExportSubnetView lets a member of one organization export another organization's subnet and all its IP addresses | 中危 | PyPIopenwisp-ipam | 已审查 | 2026-08-26 22:38 | 2026-08-26 22:38 |
| GHSA-93QJ-5Q5V-3C2H | Trojanized pantheon-agents 0.6.1 and 0.6.2 on PyPI ship a credential stealer (supply-chain account compromise) | 严重 | PyPIpantheon-agents | 已审查 | 2026-08-26 22:36 | 2026-08-26 22:36 |
| GHSA-M452-Q8C9-RG2F CVE-2026-55688 | AsyncHttpClient stores cookie for an unrelated domain (cookie tossing) via ThreadSafeCookieStore | 中危 | Mavenorg.asynchttpclient:async-http-client | 已审查 | 2026-08-26 22:35 | 2026-08-26 22:35 |
| GHSA-3P27-QVP9-27QF CVE-2026-54786 | Wasmtime has a leak in WASIp1 `fd_renumber` implementation | 低危 | crates.iowasmtime-wasi | 已审查 | 2026-08-26 22:30 | 2026-08-26 22:31 |
| GHSA-8H6H-X5PQ-56FQ CVE-2026-54511 | @logtape/syslog: syslog log injection via unescaped control characters and unvalidated SD-NAME keys | 高危 | npm@logtape/syslog | 已审查 | 2026-08-26 22:28 | 2026-08-26 22:28 |
| GHSA-F63G-88CJ-HJF9 CVE-2026-54550 | IzPack has Path Traversal in UnpackerBase that allows writing files outside the installation directory via malicious pack entries | 高危 | Mavenorg.codehaus.izpack:izpack-installer | 已审查 | 2026-08-26 22:24 | 2026-08-26 22:24 |
| GHSA-79GF-7FRW-68M9 CVE-2026-54523 | Kyverno's NamespacedGeneratingPolicy generator.apply() namespace argument unvalidated -- background controller creates RoleBindings in any namespace including kube-system | 严重 | Gogithub.com/kyverno/kyverno | 已审查 | 2026-08-26 22:21 | 2026-08-26 22:21 |
| GHSA-MV8M-V9V6-5F94 CVE-2026-54548 | kas Persistently Disables SSH Host Key Checking | 低危 | PyPIkas | 已审查 | 2026-08-26 22:18 | 2026-08-26 22:18 |
| GHSA-6753-GR46-6WPR CVE-2026-54553 | Starlette-Admin's unvalidated `order_by` parameter allows ordering by hidden columns (info-exposure oracle) and HTTP 500 DoS | 中危 | PyPIstarlette-admin | 已审查 | 2026-08-26 22:14 | 2026-08-26 22:14 |
| GHSA-VMM3-XGCX-67HM CVE-2026-54556 | http4s has HTTP/2 Denial of Service with Ember Backend | 高危 | Mavenorg.http4s:http4s-ember-core_2.12+2 | 已审查 | 2026-08-26 22:10 | 2026-08-26 22:10 |
| GHSA-6X9P-4R67-5GJX CVE-2026-54356 | Budibase authenticated arbitrary S3 signed upload URL issuance via `/api/attachments/:datasourceId/url` | 高危 | npm@budibase/server | 已审查 | 2026-08-26 22:07 | 2026-08-26 22:07 |
| GHSA-H3X4-894J-XPX5 CVE-2026-68525 | Apache Tomcat's FORM authentication process has an Incorrect Authorization vulnerability | 严重 | Mavenorg.apache.tomcat:tomcat+2 | 已审查 | 2026-08-26 08:30 | 2026-09-03 06:39 |
| GHSA-GCX9-497G-6CP6 CVE-2026-65182 | Apache Tomcat has an Improper Access Control, Incorrect Authorization vulnerability | 严重 | Mavenorg.apache.tomcat:tomcat+2 | 已审查 | 2026-08-26 08:30 | 2026-09-03 06:37 |
| GHSA-9XV2-5V5Q-P794 CVE-2026-65905 | Apache Tomcat's DIGEST authenticator has an Authentication Bypass by Capture-replay vulnerability | 严重 | Mavenorg.apache.tomcat:tomcat+2 | 已审查 | 2026-08-26 08:30 | 2026-09-03 06:38 |
| GHSA-P43P-WHWX-Q52H CVE-2026-54338 | JupyterHub has Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login | 中危 | PyPIjupyterhub | 已审查 | 2026-08-26 03:29 | 2026-08-26 03:29 |
| GHSA-CV84-9P8J-FJ68 CVE-2026-55099 | icalendar has Algorithmic Complexity in Equality | 高危 | PyPIicalendar | 已审查 | 2026-08-26 03:27 | 2026-08-26 03:27 |
| GHSA-HVFH-5MJ3-5F3J CVE-2026-45019 | Chainlist has SSRF via MCP SSE and streamable-http transports that allows unauthenticated internal network access | 高危 | PyPIchainlit | 已审查 | 2026-08-26 03:21 | 2026-08-26 03:21 |
| GHSA-W3FX-MC44-MF6J CVE-2026-45018 | Chainlit has command injection via MCP stdio transport that allows unauthenticated remote code execution | 严重 | PyPIchainlit | 已审查 | 2026-08-26 03:19 | 2026-08-26 03:19 |
| GHSA-72F3-6W86-7RV3 CVE-2026-55605 | @arikusi/deepseek-mcp-server: Missing Authentication on Self-Hosted HTTP MCP Endpoint | 中危 | npm@arikusi/deepseek-mcp-server | 已审查 | 2026-08-26 02:38 | 2026-08-26 02:38 |
| GHSA-FH3R-G96V-F578 CVE-2026-55604 | @arikusi/deepseek-mcp-server has an Authorization Bypass Through User-Controlled Key | 高危 | npm@arikusi/deepseek-mcp-server | 已审查 | 2026-08-26 02:37 | 2026-08-26 02:37 |
| GHSA-XC9G-J69Q-37XW CVE-2026-55609 | consciousness-explorer / sublinear-time-solver MCP export_state has an arbitrary file write | 高危 | npmconsciousness-explorer+1 | 已审查 | 2026-08-26 02:35 | 2026-08-26 02:35 |