检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-R47G-FVHR-H676 CVE-2026-49459 | DOMPurify: IN_PLACE mode preserves attributes of a clobbered root element, allowing XSS via attacker-controlled root DOM | 中危 | npmdompurify | 已审查 | 2026-06-16 03:53 | 2026-06-16 03:53 |
| GHSA-W7VC-732C-9M39 CVE-2026-48525 | PyJWT: Unauthenticated DoS via unbounded Base64URL decoding of unused payload segment in b64=false detached JWS |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 中危 |
PyPIpyjwt |
| 已审查 |
| 2026-06-16 03:29 |
| 2026-06-16 03:29 |
| GHSA-993G-76C3-P5M4 CVE-2026-48522 | PyJWKClient: missing scheme allowlist enables CVE-2024-21643-class SSRF + token forgery via file://, ftp://, data: schemes | 中危 | PyPIPyJWT | 已审查 | 2026-06-16 03:28 | 2026-08-01 06:13 |
| GHSA-XGMM-8J9V-C9WX CVE-2026-48526 | PyJWT: Public-key JWK accepted as HMAC secret enables forged HS256 tokens when mixed families are allowed | 高危 | PyPIpyjwt | 已审查 | 2026-06-16 03:28 | 2026-06-16 03:28 |
| GHSA-JQ35-7PRP-9V3F CVE-2026-48523 | PyJWT: Algorithm allow-list bypass when decoding with `PyJWK` / `PyJWKClient` keys | 中危 | PyPIpyjwt | 已审查 | 2026-06-16 03:27 | 2026-06-16 03:27 |
| GHSA-268H-HP4C-CRQ3 | Nodemailer: CRLF injection in Nodemailer List-* header comments allows arbitrary message header injection | 中危 | npmnodemailer | 已审查 | 2026-06-16 01:36 | 2026-06-16 01:36 |
| GHSA-WQVQ-JVPQ-H66F | Nodemailer jsonTransport bypasses disableFileAccess and disableUrlAccess during message normalization | 中危 | npmnodemailer | 已审查 | 2026-06-16 01:35 | 2026-06-16 01:35 |
| GHSA-R7G4-QG5F-QQM2 | Nodemailer: Improper TLS Certificate Validation in OAuth2 Token Fetch Enables Credential Interception | 中危 | npmnodemailer | 已审查 | 2026-06-16 01:34 | 2026-06-16 01:34 |
| GHSA-H5X3-XFC9-M39H CVE-2026-48784 | Symfony: UrlGenerator Dot-Segment Encoding Skips Every Other Chained `../` or `./` → Generated URL Collapses Off-Route Under RFC 3986 Normalization | 中危 | Packagistsymfony/routing+1 | 已审查 | 2026-06-16 01:33 | 2026-06-16 01:33 |
| GHSA-V3WM-QF9P-C549 CVE-2026-48760 | Symfony: HtmlSanitizer URL Parser Deny Gates Underinclusive: Percent-Encoded BiDi Marks and Unicode Whitespace Bypass Visual-Spoofing Defense | 中危 | Packagistsymfony/html-sanitizer+1 | 已审查 | 2026-06-16 01:32 | 2026-06-16 01:32 |
| GHSA-RRJ9-5Q2J-4GVR CVE-2026-48747 | Symfony: Mailomat Mailer Webhook Parser Reads the HMAC Algorithm from the Request: Signature Algorithm Downgrade | 中危 | Packagistsymfony/mailomat-mailer+1 | 已审查 | 2026-06-16 01:32 | 2026-06-16 01:32 |
| GHSA-38CX-CQ6F-5755 CVE-2026-48736 | Symfony: IpUtils::PRIVATE_SUBNETS Omits IPv6 Transition Forms (6to4, NAT64, Teredo, IPv4-compatible): SSRF Bypass in NoPrivateNetworkHttpClient | 中危 | Packagistsymfony/http-client+2 | 已审查 | 2026-06-16 01:31 | 2026-06-16 01:31 |
| GHSA-WCPC-WJ8M-HJX6 CVE-2026-48712 | protobufjs: Denial of service through unbounded Any expansion during JSON conversion | 高危 | npmprotobufjs | 已审查 | 2026-06-16 01:30 | 2026-07-16 06:04 |
| GHSA-FHV5-28VV-H8M8 CVE-2026-48524 | PyJWKClient unbounded JWKS endpoint requests via attacker-controlled kid values (DoS) | 低危 | PyPIpyjwt | 已审查 | 2026-06-16 01:28 | 2026-08-01 06:13 |
| GHSA-6H46-9JF5-Q59X CVE-2026-48489 | Symfony: Security Firewall Bypass via failure_forward Subrequest: Unauthenticated Access to access_control-Protected GET Routes | 高危 | Packagistsymfony/security-http+1 | 已审查 | 2026-06-16 01:28 | 2026-06-16 01:28 |
| GHSA-F38Q-MGVJ-VPH7 CVE-2026-54269 | protobufjs : Schema-derived names can shadow runtime-significant properties | 中危 | npmprotobufjs+1 | 已审查 | 2026-06-16 01:27 | 2026-07-16 06:06 |
| GHSA-HMW2-7CC7-3QXX CVE-2026-12143 | form-data: CRLF injection in form-data via unescaped multipart field names and filenames | 高危 | npmform-data | 已审查 | 2026-06-16 01:26 | 2026-06-16 01:26 |
| GHSA-QXH6-94W6-9R5P CVE-2026-54264 | @angular/service-worker: Sensitive Header Leakage on Cross-Origin Redirects in Angular Service Worker | 高危 | npm@angular/service-worker | 已审查 | 2026-06-16 01:25 | 2026-07-16 06:04 |
| GHSA-48R7-HPM6-GFXM CVE-2026-54268 | @angular/common: Denial of Service (DoS) via OOM in Date Formatting (formatDate) | 高危 | npm@angular/common | 已审查 | 2026-06-16 01:24 | 2026-07-16 06:04 |
| GHSA-39PV-4J6C-2G6V CVE-2026-54266 | @angular/common: Weak 32-Bit Cache Key Hashing in `HttpTransferCache` Leading to Cross-Request Data Leakage and State Poisoning | 高危 | npm@angular/common | 已审查 | 2026-06-16 01:24 | 2026-07-16 06:03 |
| GHSA-58W9-8G37-X9V5 CVE-2026-54265 | @angular/compiler: Two-Way Property Binding Sanitization Bypass (XSS) | 中危 | npm@angular/compiler | 已审查 | 2026-06-16 01:22 | 2026-07-16 06:03 |
| GHSA-F3M7-GQXR-G87X CVE-2026-50557 | Angular: Template and Attribute Namespace Sanitization Bypass (XSS) | 中危 | npm@angular/compiler+1 | 已审查 | 2026-06-16 01:21 | 2026-07-16 06:03 |
| GHSA-GXX4-3XCV-F8QX CVE-2026-50556 | @angular/platform-server: Missing `<noscript>` Raw-Text Serialization Escaping leads to Cross-Site Scripting (XSS) in Angular SSR | 高危 | npm@angular/platform-server | 已审查 | 2026-06-16 01:21 | 2026-06-16 01:21 |
| GHSA-HQR9-C56F-3X7F CVE-2026-50555 | @angular/platform-server: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | 高危 | npm@angular/platform-server | 已审查 | 2026-06-16 01:20 | 2026-07-16 06:05 |
| GHSA-VMF3-W455-68VH CVE-2026-53655 | node-tar applies PAX size override to intermediary GNU long-name/long-link headers, causing tar parser interpretation differential (file smuggling) | 中危 | npmtar | 已审查 | 2026-06-16 01:19 | 2026-06-16 01:19 |