检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-RV63-4MWF-QQC2 CVE-2026-54288 | hono: Body Limit Middleware can be bypassed on AWS Lambda by understating `Content-Length` | 中危 | npmhono | 已审查 | 2026-06-16 22:32 | 2026-07-21 23:26 |
| GHSA-WGPF-JWQJ-8H8P CVE-2026-54289 | hono: Lambda@Edge adapter keeps only the last value of a repeated request header, dropping the rest |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 中危 |
npmhono |
| 已审查 |
| 2026-06-16 22:32 |
| 2026-07-21 23:26 |
| GHSA-88FW-HQM2-52QC CVE-2026-54290 | hono: CORS Middleware reflects any Origin with credentials when `origin` defaults to the wildcard | 高危 | npmhono | 已审查 | 2026-06-16 22:15 | 2026-07-21 23:27 |
| GHSA-WWFH-H76J-FC44 CVE-2026-54286 | hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`) | 中危 | npmhono | 已审查 | 2026-06-16 22:09 | 2026-07-21 23:27 |
| GHSA-J6C9-X7QJ-28XF CVE-2026-54287 | hono: AWS Lambda adapter merges multiple `Set-Cookie` headers into one value, dropping cookies on ALB single-header and Lattice | 中危 | npmhono | 已审查 | 2026-06-16 22:08 | 2026-07-21 23:26 |
| GHSA-GJ48-438W-JH9V | Bleach clean() / Cleaner() fails to sanitize dangerous URI schemes in allowed formaction attributes | 中危 | PyPIbleach | 已审查 | 2026-06-16 22:07 | 2026-06-16 22:07 |
| GHSA-G75F-G53V-794X | Bleach linkify(parse_email=True) CPU exhaustion via unbounded email regex scanning | 中危 | PyPIbleach | 已审查 | 2026-06-16 22:07 | 2026-06-16 22:07 |
| GHSA-8RFP-98V4-MMR6 | Bleach: URI sanitization allows disallowed URI schemes with Unicode > U+00A0 in output | 低危 | PyPIbleach | 已审查 | 2026-06-16 22:06 | 2026-06-16 22:06 |
| GHSA-M2V9-299J-RV96 CVE-2026-54531 | pypdf: Possible infinite loop when processing outlines/bookmarks in writer | 中危 | PyPIpypdf | 已审查 | 2026-06-16 22:05 | 2026-06-16 22:05 |
| GHSA-52X6-GQ3R-VPF4 CVE-2026-54530 | pypdf: Possible infinite loop when retrieving fonts for layout-mode text extraction | 中危 | PyPIpypdf | 已审查 | 2026-06-16 22:05 | 2026-06-16 22:05 |
| GHSA-8HV8-536X-4WQP CVE-2026-50146 | Astro: Reflected XSS via unescaped slot name | 高危 | npmastro | 已审查 | 2026-06-16 22:05 | 2026-08-13 04:37 |
| GHSA-934W-87QH-QR26 CVE-2026-53722 | Nuxt: Reflected XSS in `<NuxtLink>` via unsanitised `javascript:` or `data:` URL | 中危 | npmnuxt | 已审查 | 2026-06-16 21:49 | 2026-08-15 02:45 |
| GHSA-534H-C3CW-V3H9 | Nuxt dev server vite-node IPC socket is world-connectable on Linux | 中危 | npmnuxt | 已审查 | 2026-06-16 21:49 | 2026-06-16 21:49 |
| GHSA-MM7M-92G8-7M47 CVE-2026-53721 | Nuxt: Route-rule middleware bypass via case-sensitivity mismatch between vue-router and the routeRules matcher | 高危 | npmnuxt | 已审查 | 2026-06-16 21:48 | 2026-06-16 21:48 |
| GHSA-C9CV-MQ2M-PPP3 CVE-2026-56326 | Nuxt: URL-handling weaknesses in `navigateTo` and `reloadNuxtApp`: SSR open redirect, client-side script execution via the `open` option, and protocol-relative bypass in `reloadNuxtApp` | 中危 | npmnuxt | 已审查 | 2026-06-16 21:47 | 2026-08-15 02:43 |
| GHSA-J543-4VMF-QM7V CVE-2026-49461 | pypdf: Possible large memory usage for form XObjects during text extraction | 中危 | PyPIpypdf | 已审查 | 2026-06-16 21:47 | 2026-06-16 21:47 |
| GHSA-5HGR-HG42-57JG CVE-2026-49460 | pypdf: Inefficient decoding of FlateDecode PNG predictor streams | 中危 | PyPIpypdf | 已审查 | 2026-06-16 21:46 | 2026-06-16 21:46 |
| GHSA-WJQC-6W8F-H24C CVE-2026-48735 | pypdf: Manipulated XMP metadata streams can exhaust RAM | 中危 | PyPIpypdf | 已审查 | 2026-06-16 21:45 | 2026-06-16 21:45 |
| GHSA-RCQF-CPV9-G5JF CVE-2026-50891 | Filestash allows attackers to escalate privileges via sending a crafted request | 高危 | Gogithub.com/mickael-kerjean/filestash | 已审查 | 2026-06-16 05:30 | 2026-08-28 00:48 |
| GHSA-P85R-X2WJ-MXQJ CVE-2026-50887 | shlink has a Server-Side Request Forgery issue | 严重 | Packagistshlinkio/shlink | 已审查 | 2026-06-16 05:30 | 2026-08-28 00:42 |
| GHSA-GMXH-HJFV-QC2W CVE-2026-50888 | Koillection has an authenticated Server-Side Request Forgery issue | 高危 | Packagistkoillection/koillection | 已审查 | 2026-06-16 05:30 | 2026-08-28 00:44 |
| GHSA-G743-M6X3-V6WM CVE-2026-50879 | linx-server has an issue in the uploadPostHandler component that allows attackers to cause a Denial of Service (DoS) via a crafted POST request | 高危 | Gogithub.com/andreimarcu/linx-server | 已审查 | 2026-06-16 05:30 | 2026-08-26 23:03 |
| GHSA-9MMG-Q95P-GP67 CVE-2026-50886 | Project Firefly III has incorrect access control in the webhook management component | 严重 | Packagistgrumpydictator/firefly-iii | 已审查 | 2026-06-16 05:30 | 2026-08-28 00:41 |
| GHSA-68MC-H6H8-79WJ CVE-2026-50880 | YouTransfer has an issue in the sendmail transport integration that allows arbitrary code execution | 严重 | npmyoutransfer | 已审查 | 2026-06-16 05:30 | 2026-08-26 23:04 |
| GHSA-5442-MH7F-72PX CVE-2026-50884 | statping-ng allows attackers to escalate privileges to Administrator and access sensitive components | 高危 | Gogithub.com/statping-ng/statping-ng | 已审查 | 2026-06-16 05:30 | 2026-08-28 00:41 |