检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-W5FV-7X5Q-G8QP CVE-2026-54563 | Cloudreve WebDAV (`/dav`) has Path Traversal / Broken Access Control — scoped DAV credential escapes its configured account root | 高危 | Gogithub.com/cloudreve/Cloudreve/v3+1 | 已审查 | 2026-08-26 23:22 | 2026-08-26 23:22 |
| GHSA-X287-5C68-36WP |
当前筛选结果 366,391 条 · 时间按北京时间显示
| 中危 |
PyPIopenwisp-ipam |
| 已审查 |
| 2026-08-26 22:38 |
| 2026-08-26 22:38 |
| GHSA-93QJ-5Q5V-3C2H | Trojanized pantheon-agents 0.6.1 and 0.6.2 on PyPI ship a credential stealer (supply-chain account compromise) | 严重 | PyPIpantheon-agents | 已审查 | 2026-08-26 22:36 | 2026-08-26 22:36 |
| GHSA-M452-Q8C9-RG2F CVE-2026-55688 | AsyncHttpClient stores cookie for an unrelated domain (cookie tossing) via ThreadSafeCookieStore | 中危 | Mavenorg.asynchttpclient:async-http-client | 已审查 | 2026-08-26 22:35 | 2026-08-26 22:35 |
| GHSA-3P27-QVP9-27QF CVE-2026-54786 | Wasmtime has a leak in WASIp1 `fd_renumber` implementation | 低危 | crates.iowasmtime-wasi | 已审查 | 2026-08-26 22:30 | 2026-08-26 22:31 |
| GHSA-8H6H-X5PQ-56FQ CVE-2026-54511 | @logtape/syslog: syslog log injection via unescaped control characters and unvalidated SD-NAME keys | 高危 | npm@logtape/syslog | 已审查 | 2026-08-26 22:28 | 2026-08-26 22:28 |
| GHSA-F63G-88CJ-HJF9 CVE-2026-54550 | IzPack has Path Traversal in UnpackerBase that allows writing files outside the installation directory via malicious pack entries | 高危 | Mavenorg.codehaus.izpack:izpack-installer | 已审查 | 2026-08-26 22:24 | 2026-08-26 22:24 |
| GHSA-79GF-7FRW-68M9 CVE-2026-54523 | Kyverno's NamespacedGeneratingPolicy generator.apply() namespace argument unvalidated -- background controller creates RoleBindings in any namespace including kube-system | 严重 | Gogithub.com/kyverno/kyverno | 已审查 | 2026-08-26 22:21 | 2026-08-26 22:21 |
| GHSA-MV8M-V9V6-5F94 CVE-2026-54548 | kas Persistently Disables SSH Host Key Checking | 低危 | PyPIkas | 已审查 | 2026-08-26 22:18 | 2026-08-26 22:18 |
| GHSA-6753-GR46-6WPR CVE-2026-54553 | Starlette-Admin's unvalidated `order_by` parameter allows ordering by hidden columns (info-exposure oracle) and HTTP 500 DoS | 中危 | PyPIstarlette-admin | 已审查 | 2026-08-26 22:14 | 2026-08-26 22:14 |
| GHSA-VMM3-XGCX-67HM CVE-2026-54556 | http4s has HTTP/2 Denial of Service with Ember Backend | 高危 | Mavenorg.http4s:http4s-ember-core_2.12+2 | 已审查 | 2026-08-26 22:10 | 2026-08-26 22:10 |
| GHSA-6X9P-4R67-5GJX CVE-2026-54356 | Budibase authenticated arbitrary S3 signed upload URL issuance via `/api/attachments/:datasourceId/url` | 高危 | npm@budibase/server | 已审查 | 2026-08-26 22:07 | 2026-08-26 22:07 |
| GHSA-WGFC-85P2-7526 CVE-2026-79911 | 无摘要 | 严重 | —— | 未审查 | 2026-08-26 08:31 | 2026-08-26 08:31 |
| GHSA-H7WF-MRFW-7FXQ CVE-2026-80138 | 无摘要 | 严重 | —— | 未审查 | 2026-08-26 08:31 | 2026-08-26 08:31 |
| GHSA-7P5V-7F42-F3JJ CVE-2026-79912 | 无摘要 | 中危 | —— | 未审查 | 2026-08-26 08:31 | 2026-08-26 08:31 |
| GHSA-XGJG-VWWH-M3X2 CVE-2026-18985 | 无摘要 | 高危 | —— | 未审查 | 2026-08-26 08:31 | 2026-08-27 05:31 |
| GHSA-VQM5-MJXV-776V CVE-2026-55805 | 无摘要 | 中危 | —— | 未审查 | 2026-08-26 08:31 | 2026-08-27 02:31 |
| GHSA-QH47-PX62-GXRG CVE-2026-18261 | 无摘要 | 中危 | —— | 未审查 | 2026-08-26 08:31 | 2026-08-27 05:31 |
| GHSA-PRXM-C7P3-5GV7 CVE-2026-18259 | 无摘要 | 高危 | —— | 未审查 | 2026-08-26 08:31 | 2026-08-27 05:31 |
| GHSA-96V6-MJQX-WQV5 CVE-2026-18260 | 无摘要 | 中危 | —— | 未审查 | 2026-08-26 08:31 | 2026-08-27 05:31 |
| GHSA-3488-4MH8-47J4 CVE-2026-41707 | 无摘要 | 高危 | —— | 未审查 | 2026-08-26 08:31 | 2026-08-26 08:31 |
| GHSA-X2XM-563P-WRQW CVE-2026-16641 | 无摘要 | 严重 | —— | 未审查 | 2026-08-26 08:31 | 2026-08-27 05:31 |
| GHSA-WQ7X-7X4J-792V CVE-2026-16645 | 无摘要 | 严重 | —— | 未审查 | 2026-08-26 08:31 | 2026-08-27 05:31 |
| GHSA-V8XF-HG3W-8W7M CVE-2026-15088 | 无摘要 | 中危 | —— | 未审查 | 2026-08-26 08:31 | 2026-08-27 05:31 |
| GHSA-R78P-M3M3-CX34 CVE-2026-16646 | 无摘要 | 中危 | —— | 未审查 | 2026-08-26 08:31 | 2026-08-28 23:30 |