检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-CMWH-W62W-R2MF CVE-2026-47835 | Spring AI vector store metadata filtering to handle special characters in Elasticsearch, OpenSearch, and GemFire Vector Stores | 高危 | Mavenorg.springframework.ai:spring-ai-elasticsearch-store+2 | 已审查 | 2026-06-16 05:30 | 2026-08-26 23:01 |
| GHSA-7H7J-7VWP-CWFG |
当前筛选结果 35,190 条 · 时间按北京时间显示
SNMP4J-Agent allows a remote attacker to execute arbitrary code via the snmp4jCfgStoragePath component |
| 严重 |
Mavenorg.snmp4j:snmp4j-agent |
| 已审查 |
| 2026-06-16 05:30 |
| 2026-08-26 22:53 |
| GHSA-26M2-9G2Q-V45Q CVE-2026-41708 | Spring Cloud Sleuth instrumentation of Spring TX DoS vulnerability | 高危 | Mavenorg.springframework.cloud:spring-cloud-sleuth-instrumentation | 已审查 | 2026-06-16 05:30 | 2026-08-26 22:59 |
| GHSA-G6PC-6676-C23J CVE-2026-30121 | Remotion: arbitrary file write vulnerability | 严重 | npmremotion | 已审查 | 2026-06-16 05:30 | 2026-06-20 04:47 |
| GHSA-2JQP-F4GR-44FR CVE-2026-30120 | Remotion: remote code execution (RCE) vulnerability | 严重 | npmremotion | 已审查 | 2026-06-16 05:30 | 2026-06-20 04:48 |
| GHSA-RQ7W-G337-39QQ | Nuxt: Dev server discloses project absolute path and persistent workspace UUID via `/.well-known/appspecific/com.chrome.devtools.json` | 低危 | npmnuxt | 已审查 | 2026-06-16 04:56 | 2026-06-16 04:56 |
| GHSA-999R-QQ7V-R334 CVE-2026-11417 | aws-cdk-lib: OS Command Injection in NodejsFunction Bundling | 高危 | npmaws-cdk-lib | 已审查 | 2026-06-16 04:47 | 2026-06-16 04:47 |
| GHSA-563Q-J3CM-6JXM CVE-2026-50560 | Netty susceptible to HTTP/2 Reset Attack with different on-the-wire signature | 中危 | Mavenio.netty:netty-codec-http2 | 已审查 | 2026-06-16 04:46 | 2026-06-16 04:46 |
| GHSA-HVCG-QMG6-JM4C CVE-2026-50020 | Netty: HttpObjectDecoder skips arbitrary initial control characters when only initial CRLF characters are permitted | 中危 | Mavenio.netty:netty-codec-http | 已审查 | 2026-06-16 04:46 | 2026-06-16 04:46 |
| GHSA-5W86-C3RQ-VJJ7 CVE-2026-50011 | Netty: Unbounded pre-allocation in RedisArrayAggregator from RESP array length | 高危 | Mavenio.netty:netty-codec-redis | 已审查 | 2026-06-16 04:46 | 2026-06-16 04:46 |
| GHSA-C653-97M9-RCG9 CVE-2026-50010 | Netty: Wrapping plain trust manager silently disables hostname verification | 高危 | Mavenio.netty:netty-handler | 已审查 | 2026-06-16 04:45 | 2026-06-16 04:45 |
| GHSA-CQ4Q-CV5G-R8Q5 CVE-2026-50009 | Netty: QUIC stateless reset token material exposed through header-visible connection IDs | 中危 | Mavenio.netty:netty-codec-classes-quic | 已审查 | 2026-06-16 04:44 | 2026-06-16 04:44 |
| GHSA-4GRM-H2QV-H6W6 CVE-2026-48748 | Netty HTTP/3 QPACK Blocked Streams Memory Exhaustion | 高危 | Mavenio.netty:netty-codec-http3 | 已审查 | 2026-06-16 04:43 | 2026-08-05 05:50 |
| GHSA-6V5V-WF23-FMFQ CVE-2026-48988 | markdown-it: Quadratic complexity DoS in smartquotes rule via replaceAt string operations | 中危 | npmmarkdown-it | 已审查 | 2026-06-16 04:41 | 2026-06-16 04:41 |
| GHSA-82W8-QH3P-5JFQ CVE-2026-54283 | Starlette: request.form() limits silently ignored for application/x-www-form-urlencoded enable DoS | 高危 | PyPIstarlette | 已审查 | 2026-06-16 04:39 | 2026-06-16 04:39 |
| GHSA-8988-4F7V-96QF CVE-2026-54285 | OpenTelemetry Core: Unbounded memory allocation in W3C Baggage propagation | 中危 | npm@opentelemetry/core | 已审查 | 2026-06-16 04:38 | 2026-08-25 02:08 |
| GHSA-JP82-JPQV-5VV3 CVE-2026-54282 | Starlette: Unvalidated request path concatenated into authority poisons request.url.hostname | 低危 | PyPIStarlette | 已审查 | 2026-06-16 04:38 | 2026-07-16 06:07 |
| GHSA-PW6J-QG29-8W7F | Tornado: CurlAsyncHTTPClient leaks per-request credentials on handle reuse | 中危 | PyPItornado | 已审查 | 2026-06-16 04:37 | 2026-06-16 04:37 |
| GHSA-6V32-FJC9-9QF6 CVE-2026-54281 | Nest: Middleware Bypass on Fastify via Trailing Slash | 高危 | npm@nestjs/platform-fastify | 已审查 | 2026-06-16 04:36 | 2026-07-19 01:26 |
| GHSA-5RVQ-CXJ2-64VF CVE-2026-53539 | python-multipart: Quadratic-time querystring parsing with semicolon separators causes CPU denial of service | 高危 | PyPIpython-multipart | 已审查 | 2026-06-16 04:24 | 2026-06-16 04:24 |
| GHSA-V9PG-7XVM-68HF CVE-2026-53540 | python-multipart: Negative Content-Length in parse_form buffers the entire body in memory | 低危 | PyPIpython-multipart | 已审查 | 2026-06-16 04:23 | 2026-06-16 04:23 |
| GHSA-6JV3-5F52-599M CVE-2026-53538 | python-multipart: Semicolon treated as querystring field separator enables parameter smuggling | 低危 | PyPIpython-multipart | 已审查 | 2026-06-16 04:22 | 2026-06-16 04:22 |
| GHSA-VFFW-93WF-4J4Q CVE-2026-53537 | python-multipart: Content-Disposition parameter smuggling via RFC 2231/5987 extended parameters | 低危 | PyPIpython-multipart | 已审查 | 2026-06-16 04:20 | 2026-07-16 06:06 |
| GHSA-Q6M5-F73J-M9MC CVE-2026-54257 | Electron: Buffer performs incorrect byte length calculations resulting in heap buffer under/overflow | 严重 | npmelectron | 已审查 | 2026-06-16 04:20 | 2026-07-21 05:02 |
| GHSA-3X9G-8VMP-WQVF CVE-2026-49853 | Tornado: Authorization header forwarded across cross-origin redirects in SimpleAsyncHTTPClient | 高危 | PyPItornado | 已审查 | 2026-06-16 04:20 | 2026-06-16 04:20 |