检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-J9GF-VW2F-9HRW | Appsmith: Configuration-dependent origin validation bypass in password reset and email verification link generation | 高危 | Mavencom.appsmith:server | 已审查 | 2026-06-13 02:28 | 2026-06-13 02:28 |
| GHSA-3GP5-Q4JW-3V94 CVE-2026-48152 | Budibase: Basic app users can exfiltrate stored REST datasource auth by rewriting datasource base URL |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 高危 |
npm@budibase/server |
| 已审查 |
| 2026-06-13 02:28 |
| 2026-06-13 02:28 |
| GHSA-QHV3-WJG8-6FX6 CVE-2026-48151 | Budibase: Webhook schema endpoint authorization bypass allows unauthenticated mutation of webhook and automation schema | 高危 | npm@budibase/server | 已审查 | 2026-06-13 02:28 | 2026-06-13 02:28 |
| GHSA-6XP4-CF37-PPJH CVE-2026-48150 | Budibase: Workspace-scoped builder escalates to global admin via /api/public/v1/roles/assign | 严重 | npm@budibase/server | 已审查 | 2026-06-13 02:28 | 2026-06-13 02:28 |
| GHSA-9WCP-79G5-5C3C | Appsmith Super User Creation Race Condition Allows Multiple Instance Administrators | 高危 | Mavencom.appsmith:server | 已审查 | 2026-06-13 02:27 | 2026-06-13 02:27 |
| GHSA-CV96-5348-P5P8 CVE-2026-48148 | Budibase: Unvalidated VectorDB Host Parameter Enables SSRF | 中危 | npm@budibase/server | 已审查 | 2026-06-13 02:27 | 2026-06-13 02:27 |
| GHSA-WXQ7-X3QP-VCR8 CVE-2026-48147 | Budibase: Unanchored Regex in `matchers.ts` Allows CSRF Bypass via Query String Injection in Budibase Worker | 中危 | npm@budibase/backend-core | 已审查 | 2026-06-13 02:23 | 2026-06-13 02:23 |
| GHSA-X4R9-GMW3-HXWW CVE-2025-58175 | GeoServer has a Server-Side Request Forgery (SSRF) Vulnerability in its XML Entity Resolution | 中危 | Mavenorg.geoserver:gs-main+1 | 已审查 | 2026-06-13 02:23 | 2026-06-13 02:23 |
| GHSA-7QMG-GRCP-QF25 CVE-2025-52465 | GeoServer has an arbitrary file write vulnerability in its Master Password Dump Page | 高危 | Mavenorg.geoserver.web:gs-web-app+1 | 已审查 | 2026-06-13 02:23 | 2026-07-16 05:49 |
| GHSA-G6QX-G4PR-92V7 CVE-2026-48146 | Budibase: SSRF via OAuth2 Config Validation — Missing fetchWithBlacklist Protection | 高危 | npm@budibase/server | 已审查 | 2026-06-12 23:08 | 2026-06-12 23:08 |
| GHSA-6964-PP88-6WP9 CVE-2026-48128 | Budibase: SSRF via User-Controlled queryId in Automation Execute Query Step | 中危 | npmbudibase | 已审查 | 2026-06-12 23:08 | 2026-06-12 23:08 |
| GHSA-4PX2-PW77-VC85 CVE-2026-28898 | SwiftNIO HTTP/2: HTTP/2-to-HTTP/1 Request Smuggling via unvalidated :path pseudo-header in HTTP2ToHTTP1Codec | 中危 | SwiftURLgithub.com/apple/swift-nio-http2 | 已审查 | 2026-06-12 23:08 | 2026-07-16 05:23 |
| GHSA-6PH5-FWW6-VFWV CVE-2026-28975 | NIOExtras: NIOHTTPRequestDecompressor ratio limit bypass via inflated Content-Length | 中危 | SwiftURLgithub.com/apple/swift-nio-extras | 已审查 | 2026-06-12 23:08 | 2026-06-12 23:08 |
| GHSA-RJ37-6J9X-74Q6 CVE-2026-28980 | SwiftNIO NIOHTTP1: HTTPDecoder accepts unbounded HTTP/1 header blocks, enabling remote DoS | 高危 | SwiftURLgithub.com/apple/swift-nio | 已审查 | 2026-06-12 23:07 | 2026-06-12 23:07 |
| GHSA-R3RC-9HPW-54V9 CVE-2026-43671 | SwiftNIO: Out-of-bounds write via ByteBuffer index and length UInt32 overflow | 高危 | SwiftURLgithub.com/apple/swift-nio | 已审查 | 2026-06-12 23:07 | 2026-06-12 23:07 |
| GHSA-CQ87-8R7H-962V CVE-2026-28970 | SwiftNIO: CRLF Injection in outbound HTTP request URI via NIOHTTPRequestHeadersValidator | 中危 | SwiftURLgithub.com/apple/swift-nio | 已审查 | 2026-06-12 23:07 | 2026-06-12 23:07 |
| GHSA-98XF-R82G-9MHX CVE-2026-48121 | LangGraph has NoSQL parameter injection in MongoDBSaver, allowing cross-tenant state access | 中危 | npm@langchain/langgraph-checkpoint-mongodb | 已审查 | 2026-06-12 23:05 | 2026-06-12 23:05 |
| GHSA-6JQ6-X4CX-QVCM | Firefly II has Stored XSS in Audit Log Entry view via piggy bank name (ale.twig) | 中危 | Packagistgrumpydictator/firefly-iii | 已审查 | 2026-06-12 23:04 | 2026-06-12 23:04 |
| GHSA-9R4W-JG96-92MV CVE-2026-12681 | Go-Attestation: Hash injection into trusted measurement list via unskipped SignatureHeaderSize vendor bytes in parseEfiSignatureList() | 高危 | Gogithub.com/google/go-attestation | 已审查 | 2026-06-12 23:04 | 2026-08-29 04:48 |
| GHSA-24FP-5V3P-RVPW CVE-2026-48113 | Chisel has an ACL Bypass via Post-Handshake SSH Channel ExtraData Injection | 高危 | Gogithub.com/jpillora/chisel | 已审查 | 2026-06-12 23:04 | 2026-06-12 23:04 |
| GHSA-QP3F-RVJ8-46C8 CVE-2026-50633 | Apache CXF JNDI Injection vulnerability in DispatchMDBMessageListenerImpl | 严重 | Mavenorg.apache.cxf:cxf-integration-jca | 已审查 | 2026-06-12 20:31 | 2026-08-21 02:32 |
| GHSA-GHVC-7HP8-2G2V CVE-2026-50645 | Apache cxf-core: No restriction on attachment headers per message | 高危 | Mavenorg.apache.cxf:cxf-core | 已审查 | 2026-06-12 20:31 | 2026-08-13 02:43 |
| GHSA-93G8-QQV3-MRX8 CVE-2026-50632 | Apache CXF has JNDI Injection Vulnerability in JMSConfigFactory | 严重 | Mavenorg.apache.cxf:cxf-rt-transports-jms | 已审查 | 2026-06-12 20:31 | 2026-08-21 02:32 |
| GHSA-33J8-J763-4FV5 CVE-2026-50634 | Apache CXF: WS JSON request filter trusts metadata from an unvalidated first signature entry | 中危 | Mavenorg.apache.cxf:cxf-rt-rs-security-jose-jaxrs | 已审查 | 2026-06-12 20:31 | 2026-08-21 02:33 |
| GHSA-XF62-WR5P-5P95 CVE-2026-50630 | Apache CXF OAuth2 HTTP Response Splitting via WWW-Authenticate Realm Injection | 中危 | Mavenorg.apache.cxf:cxf-rt-rs-security-oauth2 | 已审查 | 2026-06-12 20:31 | 2026-08-21 02:32 |