检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-V6WH-96G9-6WX3 CVE-2026-53632 | launch-editor: NTLMv2 hash disclosure via UNC path handling on Windows | 中危 | npmlaunch-editor+2 | 已审查 | 2026-06-16 01:18 | 2026-06-16 01:18 |
| GHSA-FX2H-PF6J-XCFF CVE-2026-53571 | vite: `server.fs.deny` bypass on Windows alternate paths |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 高危 |
npmvite+1 |
| 已审查 |
| 2026-06-16 01:17 |
| 2026-07-16 06:05 |
| GHSA-H67P-54HQ-RP68 CVE-2026-53550 | JS-YAML: Quadratic-complexity DoS in merge key handling via repeated aliases | 中危 | npmjs-yaml | 已审查 | 2026-06-16 01:15 | 2026-06-29 23:05 |
| GHSA-4X5R-PXFX-6JF8 CVE-2026-49356 | @babel/core: Arbitrary File Read via sourceMappingURL Comment | 低危 | npm@babel/core | 已审查 | 2026-06-16 01:14 | 2026-07-16 06:05 |
| GHSA-95QP-CMMW-MGQV CVE-2026-50184 | @angular/service-worker: Request Credential & Cache Policy Stripping | 中危 | npm@angular/service-worker | 已审查 | 2026-06-16 01:13 | 2026-07-16 06:05 |
| GHSA-P3VC-36G9-X9GR CVE-2026-50171 | @angular/common: Denial of Service (DoS) via OOM in Number Formatting (digitsInfo) | 高危 | npm@angular/common | 已审查 | 2026-06-16 00:52 | 2026-07-16 06:05 |
| GHSA-Q6F4-QQRG-JV6X CVE-2026-50170 | @angular/common: Information Leak via Default Caching of Credentialed Requests in HttpTransferCache | 高危 | npm@angular/common | 已审查 | 2026-06-16 00:51 | 2026-07-16 06:05 |
| GHSA-692R-GRFM-V8X7 CVE-2026-52725 | @angular/core: Angular Template and Dynamic Component Namespace Bypass leading to Cross-Site Scripting (XSS) | 中危 | npm@angular/core | 已审查 | 2026-06-16 00:51 | 2026-07-16 06:03 |
| GHSA-X5QJ-865H-MGVM CVE-2026-48761 | Symfony: HtmlSanitizer UrlAttributeSanitizer Misses URL Attributes | 中危 | Packagistsymfony/html-sanitizer+1 | 已审查 | 2026-06-16 00:46 | 2026-06-16 00:46 |
| GHSA-GV2Q-MQQV-365M CVE-2026-50169 | Angular Service Worker Policy-Bypass & Credential-Stripping Vulnerabilities | 中危 | npm@angular/service-worker | 已审查 | 2026-06-16 00:44 | 2026-07-16 06:05 |
| GHSA-XRXM-CP7J-8XF6 CVE-2026-50168 | @angular/platform-server: URL Parser Differential leading to SSRF Allowlist Bypass | 高危 | npm@angular/platform-server | 已审查 | 2026-06-16 00:39 | 2026-07-16 06:04 |
| GHSA-7C78-JF6Q-G5CM CVE-2026-49982 | tmp: Type-confusion bypass of _assertPath allows path traversal via non-string prefix/postfix/template | 高危 | npmtmp | 已审查 | 2026-06-16 00:36 | 2026-06-16 00:36 |
| GHSA-96HV-2XVQ-FX4P CVE-2026-48779 | ws: Memory exhaustion DoS from tiny fragments and data chunks | 高危 | npmws | 已审查 | 2026-06-16 00:34 | 2026-07-13 23:31 |
| GHSA-RGJC-H3X7-9MWG CVE-2026-54267 | Angular Client Hydration DOM Clobbering & Response-Cache Poisoning | 高危 | npm@angular/core | 已审查 | 2026-06-15 23:16 | 2026-07-16 06:04 |
| GHSA-WRCG-234W-HFHQ CVE-2026-12202 | Subrion CMS vulnerable to Cross-site Scripting | 低危 | Packagistintelliants/subrion | 已审查 | 2026-06-15 11:30 | 2026-08-26 01:43 |
| GHSA-VG9F-Q4XH-62R4 | Duplicate Advisory: utcp-gql SSRF: CVE-2026-44661 fix not applied to the GraphQL and WebSocket plugins 已撤回 | 低危 | PyPIutcp-gql | 已审查 | 2026-06-15 11:30 | 2026-08-26 02:09 |
| GHSA-VV4X-QCPQ-WGRG CVE-2026-12198 | Microweber vulnerable to Path Traversal | 中危 | Packagistmicroweber/microweber | 已审查 | 2026-06-15 08:31 | 2026-08-26 01:43 |
| GHSA-J4CW-MCG2-2Q78 CVE-2026-54421 | OpenStack Ironic can return unredacted sensitive information when applying a PATCH to update fields in volume properties | 中危 | PyPIironic | 已审查 | 2026-06-14 14:30 | 2026-08-26 00:34 |
| GHSA-76G7-M3XW-X9GR CVE-2026-11624 | MCP Toolbox for Databases has an Origin Validation Error | 严重 | Gogithub.com/googleapis/mcp-toolbox | 已审查 | 2026-06-13 20:31 | 2026-08-25 06:06 |
| GHSA-V82C-5C2Q-HX9G | Duplicate Advisory: Privilege escalation from namespace admin to cluster admin via GrafanaDashboard jsonnetLib fileName 已撤回 | 中危 | Gogithub.com/grafana/grafana-operator | 已审查 | 2026-06-13 14:30 | 2026-06-20 04:50 |
| GHSA-CHQM-WXM2-W73W | Duplicate Advisory: OpenClaw: Mattermost handlers could fall open when channel type was missing 已撤回 | 中危 | npmopenclaw | 已审查 | 2026-06-13 08:34 | 2026-08-28 23:53 |
| GHSA-C85P-9PVR-F7F5 | Duplicate Advisory: OpenClaw: Node pairing reconnection could confuse approval scope state 已撤回 | 中危 | npmopenclaw | 已审查 | 2026-06-13 08:34 | 2026-08-26 00:39 |
| GHSA-R27J-FXMQ-RG2Q | Duplicate Advisory: OpenClaw: QQBot streaming command could mutate config without explicit allowFrom 已撤回 | 高危 | npmopenclaw | 已审查 | 2026-06-13 08:34 | 2026-08-28 05:56 |
| GHSA-P68J-Q8J9-JWF5 | Duplicate Advisory: OpenClaw: Slack and Zalo webhook secrets could remain active after secrets.reload 已撤回 | 中危 | npmopenclaw | 已审查 | 2026-06-13 08:34 | 2026-08-25 05:05 |
| GHSA-GWCQ-453V-2FRR | Duplicate Advisory: OpenClaw's POSIX node system.run safe-bin allowlist could be widened by shell expansion 已撤回 | 高危 | npmopenclaw | 已审查 | 2026-06-13 08:34 | 2026-08-26 00:38 |