检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-3VFR-4GWF-QXFP CVE-2026-55629 | Whistle vulnerable to path traversal | 高危 | npmwhistle | 已审查 | 2026-08-26 02:32 | 2026-08-26 02:32 |
| GHSA-XQQH-3W52-Q8P7 | Duplicate Advisory: Nokogiri does not check the return value from xmlC14NExecute |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 中危 |
RubyGemsnokogiri |
| 已审查 |
| 2026-08-26 02:31 |
| 2026-09-02 22:42 |
| GHSA-W5Q8-6JPP-4246 | Duplicate Advisory: Corpus readers follow symlinks outside trusted roots despite pathsec enforcement 已撤回 | 高危 | PyPInltk | 已审查 | 2026-08-26 02:31 | 2026-09-02 22:49 |
| GHSA-RH9X-7XJC-VWX2 | Duplicate Advisory: Nokogiri XSLT transform has a memory leak 已撤回 | 中危 | RubyGemsnokogiri | 已审查 | 2026-08-26 02:31 | 2026-09-02 22:42 |
| GHSA-RCW8-9QRW-27M2 | Duplicate Advisory: NLTK: Corpus Reader Sandbox Bypass 已撤回 | 高危 | PyPInltk | 已审查 | 2026-08-26 02:31 | 2026-09-02 22:48 |
| GHSA-5JHF-FPP7-V2PV | Duplicate Advisory: Nokogiri CSS selector tokenizer has regular expression backtracking 已撤回 | 高危 | RubyGemsnokogiri | 已审查 | 2026-08-26 02:31 | 2026-09-02 22:43 |
| GHSA-3H2G-J4WP-7QQQ | Duplicate Advisory: JVM argument injection bypass via per-call options in the NLTK Stanford wrappers (incomplete fix of CVE-2026-12841) 已撤回 | 严重 | PyPInltk | 已审查 | 2026-08-26 02:31 | 2026-09-02 04:38 |
| GHSA-G7GC-GMGP-WGQG CVE-2026-55620 | eml_parser vulnerable to DoS via deeply nested parens in Received headers | 高危 | PyPIeml_parser | 已审查 | 2026-08-26 02:27 | 2026-08-26 02:27 |
| GHSA-M66C-FW79-6359 CVE-2026-55619 | eml_parser has parser DoS via deeply nested parentheses in e-mail headers | 中危 | PyPIeml_parser | 已审查 | 2026-08-26 02:25 | 2026-08-26 02:25 |
| GHSA-FXGQ-9M89-CXJ9 CVE-2026-55618 | eml_parser has a URL extraction bypass via HTML entities in URLs | 中危 | PyPIeml_parser | 已审查 | 2026-08-26 02:23 | 2026-08-26 02:23 |
| GHSA-777C-2FXX-QR28 CVE-2026-49757 | AshAuthentication vulnerable to OAuth2/OIDC account takeover via email-based user matching | 严重 | Hexash_authentication | 已审查 | 2026-08-26 02:20 | 2026-08-26 02:20 |
| GHSA-P7X2-G5CQ-FHMQ CVE-2026-55663 | mediasoup: SCTP state cookie lacks cryptographic authentication, enabling unauthorized association establishment (RFC 9260 violation) | 中危 | crates.iomediasoup | 已审查 | 2026-08-26 02:17 | 2026-08-26 02:17 |
| GHSA-6CCX-9C9F-327W CVE-2026-53430 | gRPC Erlang package has unbounded gzip decompression (decompression bomb) | 高危 | Hexgrpc | 已审查 | 2026-08-26 02:12 | 2026-08-26 02:12 |
| GHSA-Q8GF-9RVJ-GMGJ CVE-2026-48854 | gRPC Erlang package has unbounded request body accumulation in `read_full_body/3` | 高危 | Hexgrpc | 已审查 | 2026-08-26 02:12 | 2026-08-26 02:12 |
| GHSA-MWR4-5G34-J5CQ CVE-2026-48599 | gRPC Erlang package's path bindings are overridable by query string and request body | 高危 | Hexgrpc | 已审查 | 2026-08-26 02:11 | 2026-08-26 02:11 |
| GHSA-GRP7-V8XH-RJ7H CVE-2026-48853 | gRPC Erlang package vulnerable to Remote Code Execution with attacker-controlled gRPC payloads | 严重 | Hexgrpc | 已审查 | 2026-08-26 02:09 | 2026-08-26 02:09 |
| GHSA-CMWV-WF9P-P8WX CVE-2026-55637 | genieacs-mcp: DNS rebinding reaches local GenieACS MCP Streamable HTTP transport | 高危 | Gogithub.com/geiserx/genieacs-mcp | 已审查 | 2026-08-26 02:05 | 2026-08-26 02:05 |
| GHSA-VWF3-4XXJ-QG6H | mcp-contextforge-gateway has Server-Side Template Injection (SSTI) leading to Remote Code Execution in `PromptService._render_template` via unsandboxed Jinja2 Environment | 高危 | PyPImcp-contextforge-gateway | 已审查 | 2026-08-26 01:42 | 2026-08-26 01:42 |
| GHSA-M2PC-3Q4Q-W6JR CVE-2026-55419 | reachy_mini Allows Unrestricted Upload of File with Dangerous Type | 中危 | PyPIreachy-mini | 已审查 | 2026-08-26 01:38 | 2026-08-26 01:38 |
| GHSA-MCJ4-MPHF-J9FF CVE-2026-55092 | Trivy has a path traversal via a crafted vulnerability database or other downloaded artifacts | 高危 | Gogithub.com/aquasecurity/trivy | 已审查 | 2026-08-26 01:33 | 2026-08-26 01:33 |
| GHSA-PG62-F8G4-4WQH | phpMyFAQ privilege escalation: GroupController::updatePermissions lets a GROUP_EDIT admin grant rights they do not hold | 高危 | Packagistphpmyfaq/phpmyfaq+1 | 已审查 | 2026-08-26 01:32 | 2026-08-26 01:32 |
| GHSA-MF8R-WM2W-F8C5 | phpMyFAQ public FAQ APIs expose inactive FAQ content | 中危 | Packagistphpmyfaq/phpmyfaq+1 | 已审查 | 2026-08-26 01:30 | 2026-08-26 01:30 |
| GHSA-88G4-74F3-63X9 | phpMyFAQ has Potential Authenticated Path Traversal in PDF Export | 中危 | Packagistphpmyfaq/phpmyfaq+1 | 已审查 | 2026-08-26 01:28 | 2026-08-26 01:28 |
| GHSA-QJ6X-XX2H-8HVV CVE-2026-55596 | Plate: Media embed provider metadata can bypass URL sanitization and execute iframe JavaScript | 高危 | npm@platejs/media | 已审查 | 2026-08-26 00:29 | 2026-08-26 00:29 |
| GHSA-M9MQ-7M7Q-XC6P CVE-2026-55557 | browse-mcp has an arbitrary file write via unconfined download and state paths | 高危 | npmbrowse-mcp | 已审查 | 2026-08-26 00:28 | 2026-08-26 00:28 |