检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-G5V7-JCHF-7JRR CVE-2026-50628 | Apache CXF OAuth2 has Inverted IP Binding Check that Defeats Security Control | 严重 | Mavenorg.apache.cxf:cxf-rt-rs-security-oauth2 | 已审查 | 2026-06-12 20:31 | 2026-08-21 02:31 |
| GHSA-F8P7-H97Q-7VX7 CVE-2026-50629 |
当前筛选结果 35,190 条 · 时间按北京时间显示
Apache CXF OAuth2 Log Injection via Unsanitized Client Identifier |
| 高危 |
Mavenorg.apache.cxf:cxf-rt-rs-security-oauth2 |
| 已审查 |
| 2026-06-12 20:31 |
| 2026-08-21 02:31 |
| GHSA-9MRV-8PVF-HF4M CVE-2026-50627 | Apache CXF OAuth2 Missing JWT Audience and Issuer Validation in Access Token Validator | 严重 | Mavenorg.apache.cxf:cxf-rt-rs-security-oauth2 | 已审查 | 2026-06-12 20:31 | 2026-08-21 02:32 |
| GHSA-83R6-96M8-R52P CVE-2026-50631 | Apache CXF OAuth2 TOCTOU Race Condition in Refresh Token Processing | 高危 | Mavenorg.apache.cxf:cxf-rt-rs-security-oauth2 | 已审查 | 2026-06-12 20:31 | 2026-08-21 02:32 |
| GHSA-542G-M3FX-Q86F CVE-2026-50623 | Apache CXF has Authentication Bypass in OAuth2 TokenIntrospectionService | 中危 | Mavenorg.apache.cxf:cxf-rt-rs-security-oauth2 | 已审查 | 2026-06-12 20:31 | 2026-08-21 02:31 |
| GHSA-3VX2-VQX8-JXFG CVE-2026-53782 | @steipete/summarize vulnerable to SSRF via podcast:transcript URL fetch | 中危 | npm@steipete/summarize | 已审查 | 2026-06-12 05:31 | 2026-08-21 02:33 |
| GHSA-Q9XM-F36C-XM3Q CVE-2026-53781 | @steipete/summarize is Vulnerable to Disk Exhaustion via Crafted Media Responses | 中危 | npm@steipete/summarize-core | 已审查 | 2026-06-12 05:31 | 2026-07-28 00:06 |
| GHSA-HV8M-JJ95-WG3X CVE-2026-48109 | MessagePack's LZ4 decompression may fail with AccessViolationException after dereferencing memory from bad input | 高危 | NuGetMessagePack | 已审查 | 2026-06-12 04:34 | 2026-06-25 23:01 |
| GHSA-G628-R368-6VH7 CVE-2025-27511 | GeoServer DB2 DataStore Extension has a JNDI Vulnerability via Store Connection | 高危 | Mavenorg.geoserver.extension:gs-db2 | 已审查 | 2026-06-12 04:34 | 2026-07-16 05:49 |
| GHSA-4R3C-5HPG-58QR CVE-2026-48110 | Russh SSH message fields were decoded through allocation-first parsers before field-specific bounds | 高危 | crates.iorussh | 已审查 | 2026-06-12 04:33 | 2026-06-12 04:33 |
| GHSA-R236-5PC3-3QCP CVE-2026-11401 | AWS Advanced Go Wrapper has Privilege Escalation in Aurora PostgreSQL instance | 高危 | Gogithub.com/aws/aws-advanced-go-wrapper/auth-helpers+10 | 已审查 | 2026-06-12 04:33 | 2026-06-12 04:33 |
| GHSA-76R6-X97P-67VR CVE-2026-48108 | Russh: SSH identification parsing accepted non-canonical client banners and did not bound pre-banner input | 中危 | crates.iorussh | 已审查 | 2026-06-12 04:29 | 2026-06-12 04:29 |
| GHSA-G9G7-5CGW-6V28 CVE-2026-48107 | Russh: Unchecked keyboard-interactive prompt count in client auth path | 中危 | crates.iorussh | 已审查 | 2026-06-12 04:28 | 2026-06-12 04:28 |
| GHSA-WXQ4-CC2Q-338Q CVE-2026-48099 | WsgiDAV encoded dot segments can escape filesystem share roots | 高危 | PyPIwsgidav | 已审查 | 2026-06-12 04:28 | 2026-06-12 04:28 |
| GHSA-8396-JFFM-QX4W CVE-2026-48096 | OpenFGA has cache-key delimiter injection in shared-iterator and v2 iterator that caches enables intra-store authorization-decision poisoning | 中危 | Gogithub.com/openfga/openfga | 已审查 | 2026-06-12 04:28 | 2026-07-21 21:54 |
| GHSA-6P54-FW2F-Q7GF CVE-2026-48089 | DevGuard has improper authorization on public assets | 高危 | Gogithub.com/l3montree-dev/devguard | 已审查 | 2026-06-12 04:26 | 2026-07-16 05:58 |
| GHSA-7Q3W-XQJW-G3CR CVE-2026-48067 | Filament has inconsistent scope enforcement for its AttachAction and AssociateAction Select fields | 中危 | Packagistfilament/actions+1 | 已审查 | 2026-06-12 04:26 | 2026-07-19 01:26 |
| GHSA-H2QV-FJ59-J46J CVE-2026-48059 | Netty HAProxy: Unbalanced Reference Count in Nested PP2_TYPE_SSL TLV Parsing Leads to Memory Exhaustion | 高危 | Mavenio.netty:netty-codec-haproxy | 已审查 | 2026-06-12 04:19 | 2026-08-13 23:34 |
| GHSA-6W3V-MCFH-M3Q7 CVE-2026-11986 | Keycloak Admin UI REST Extensions: bulk role-removal endpoints fail to perform granular permission checks | 中危 | Mavenorg.keycloak:keycloak-rest-admin-ui-ext | 已审查 | 2026-06-12 02:31 | 2026-08-20 03:32 |
| GHSA-2GR4-PPC7-7MHX CVE-2026-48062 | CodeIgniter4 has a validation bypass when uploading file extensions via `ext_in` rule | 严重 | Packagistcodeigniter4/framework | 已审查 | 2026-06-12 01:16 | 2026-06-12 01:16 |
| GHSA-4MJ9-PF4R-CQRC CVE-2026-48053 | Kolibri has Unauthenticated Server-Side Request Forgery (SSRF) in RemoteFacilityUserViewset | 中危 | PyPIkolibri | 已审查 | 2026-06-12 01:10 | 2026-06-12 01:10 |
| GHSA-J93G-RP6M-J32M CVE-2026-48050 | Arc: Unauthenticated access to Go debug pprof endpoints leaks runtime state and enables CPU-burn DoS | 高危 | Gogithub.com/basekick-labs/arc | 已审查 | 2026-06-12 01:10 | 2026-06-12 01:10 |
| GHSA-RCVQ-M9J9-6F4G CVE-2026-48049 | @hapi/inert has a static-file confinement bypass via sibling-prefix path | 中危 | npm@hapi/inert | 已审查 | 2026-06-12 01:10 | 2026-06-12 01:10 |
| GHSA-HQP4-2352-XF5R CVE-2026-11816 | Keras archive extraction utilities allow path traversal and arbitrary file writes | 高危 | PyPIkeras | 已审查 | 2026-06-11 23:31 | 2026-08-08 04:09 |
| GHSA-9663-MQMP-P9MM CVE-2026-48045 | python-zeroconf: Unbounded TC-deferred queue allows LAN-local memory exhaustion via spoofed-source flood | 中危 | PyPIzeroconf | 已审查 | 2026-06-11 21:28 | 2026-06-11 21:28 |