检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-CPGJ-F7G3-2PP2 CVE-2026-49859 | Deno: `fetch()` API sandbox bypass via missing DNS resolution check | 中危 | crates.iodeno | 已审查 | 2026-06-17 03:02 | 2026-07-21 05:01 |
| GHSA-5R4W-85F3-PW66 CVE-2026-48491 | Traefik: SNICheck ignores wildcard TLSOptions mappings, allowing domain-fronted mTLS bypass |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 高危 |
Gogithub.com/traefik/traefik/v2+1 |
| 已审查 |
| 2026-06-17 03:02 |
| 2026-09-02 23:34 |
| GHSA-9C38-2MCM-Q7F7 CVE-2026-54311 | n8n: Merge Node SQL Mode Prototype Pollution | 中危 | npmn8n | 已审查 | 2026-06-17 03:01 | 2026-07-20 21:39 |
| GHSA-2VFF-HJ5X-8GQ7 CVE-2026-54306 | n8n: Prototype Pollution enables confused-deputy execution via public webhooks | 中危 | npmn8n | 已审查 | 2026-06-17 03:00 | 2026-07-20 21:45 |
| GHSA-V733-MWR6-FGCM CVE-2026-54301 | n8n: Same-Origin XSS in Respond to Webhook Node | 高危 | npmn8n | 已审查 | 2026-06-17 03:00 | 2026-07-20 21:43 |
| GHSA-JVC7-762P-3743 CVE-2026-54308 | n8n: Missing Token Validation on Microsoft Agent 365 Trigger and Stripe Nodes | 中危 | npmn8n | 已审查 | 2026-06-17 03:00 | 2026-07-20 21:43 |
| GHSA-HV7X-3X78-GX53 | n8n: Wrong OAuth Scope On Evaluations Test Run Creation Endpoint | 中危 | npmn8n | 已审查 | 2026-06-17 02:59 | 2026-06-17 02:59 |
| GHSA-JPQ7-226W-6CXX CVE-2026-54313 | n8n: NoSQL Injection in MongoDB Node Find And Replace Operation | 中危 | npmn8n | 已审查 | 2026-06-17 02:59 | 2026-07-20 21:39 |
| GHSA-C37G-W77Q-M4VP CVE-2026-54310 | n8n: SQL Injection in Postgres v1/TimesclaeDB Nodes | 中危 | npmn8n | 已审查 | 2026-06-17 01:51 | 2026-07-20 21:39 |
| GHSA-5XP3-2W67-427V CVE-2026-49465 | n8n: Git Node Clone and Push Operations Bypass File Sandbox | 中危 | npmn8n | 已审查 | 2026-06-17 01:37 | 2026-07-20 21:43 |
| GHSA-9PQ8-M8GP-4P53 CVE-2026-49444 | n8n: Python sandbox escape | 高危 | npmn8n | 已审查 | 2026-06-17 01:37 | 2026-07-20 21:41 |
| GHSA-94F4-HR76-P5J6 CVE-2026-48746 | vLLM: OpenAI auth bypass | 严重 | PyPIvllm | 已审查 | 2026-06-17 01:36 | 2026-09-01 23:30 |
| GHSA-RCJH-R59H-GQ37 CVE-2026-48520 | Langflow: Unauthenticated Shareable Playground arbitrary local or S3 file read | 中危 | PyPIlangflow | 已审查 | 2026-06-17 01:36 | 2026-07-20 21:42 |
| GHSA-V5FF-9Q35-Q26F CVE-2026-48519 | Langflow: Unauthenticated RCE in Shareable Playgrounds | 严重 | PyPIlangflow | 已审查 | 2026-06-17 01:35 | 2026-07-20 21:42 |
| GHSA-79PH-745M-6WXQ CVE-2026-42867 | Langflow: Path Traversal in Knowledge Bases API via Creation Endpoint | 中危 | PyPIlangflow | 已审查 | 2026-06-17 01:35 | 2026-07-20 21:41 |
| GHSA-Q8GQ-377P-JQ3R CVE-2026-41523 | vLLM: Security Check Bypass via assert Statement in Activation Function Loading Allows Arbitrary Code Execution | 高危 | PyPIvllm | 已审查 | 2026-06-17 01:34 | 2026-09-03 23:31 |
| GHSA-9C59-2MVC-VFR8 CVE-2026-33760 | Langflow: IDOR/BOLA in Monitor API — Missing Ownership Enforcement on 7 Endpoints | 高危 | PyPIlangflow | 已审查 | 2026-06-17 01:34 | 2026-07-20 21:40 |
| GHSA-6HW7-J4JW-WPFF CVE-2026-12398 | Galaxy NG: command injection vulnerability | 高危 | PyPIgalaxy-ng | 已审查 | 2026-06-16 23:33 | 2026-06-20 04:48 |
| GHSA-M557-WRGG-6RP4 CVE-2026-55599 | phpseclib: X.509 certificate validation sends attacker-controlled outbound requests (server-side request forgery) via Authority Information Access | 中危 | Packagistphpseclib/phpseclib | 已审查 | 2026-06-16 23:03 | 2026-07-09 01:37 |
| GHSA-GR75-JV2W-4656 CVE-2026-55443 | LangChain: Path traversal and sandbox escape in LangChain file-search middleware and loaders | 中危 | PyPIlangchain+1 | 已审查 | 2026-06-16 23:03 | 2026-07-09 01:36 |
| GHSA-JRPJ-WCV7-9FH9 CVE-2026-54298 | Astro: XSS via Unescaped Attribute Names in Spread Props | 中危 | npmastro | 已审查 | 2026-06-16 22:57 | 2026-07-19 01:25 |
| GHSA-2PVR-WF23-7PC7 CVE-2026-54299 | Astro: Host header SSRF in prerendered error page fetch | 高危 | npmastro | 已审查 | 2026-06-16 22:38 | 2026-08-13 04:37 |
| GHSA-529G-XQ4F-CW38 CVE-2026-54300 | @astrojs/netlify broadens Astro image.remotePatterns in Netlify Image CDN config | 中危 | npm@astrojs/netlify | 已审查 | 2026-06-16 22:37 | 2026-07-19 01:24 |
| GHSA-P4GQ-832X-FM9V CVE-2026-54293 | Natural Language Toolkit (NLTK): URL-Encoded Path Traversal in nltk.data.load() Allows Arbitrary Local File Read | 高危 | PyPInltk | 已审查 | 2026-06-16 22:34 | 2026-07-21 20:33 |
| GHSA-7Q4V-2MR6-5GPX CVE-2026-45491 | Microsoft Security Advisory CVE-2026-45491 – .NET Tampering Vulnerability | 中危 | NuGetMicrosoft.NETCore.App.Runtime.linux-x64+2 | 已审查 | 2026-06-16 22:33 | 2026-06-16 22:33 |