检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-C2GF-V879-257J CVE-2026-48043 | netty-codec-http2: ByteBuf Reference-Count Leak in DelegatingDecompressorFrameListener Leads to Memory Exhaustion | 中危 | Mavenio.netty:netty-codec-http2 | 已审查 | 2026-06-11 21:28 | 2026-08-13 23:34 |
| GHSA-32HF-8JW3-V4QQ CVE-2026-48040 | netty-incubator-codec-ohttp's Incorrect Native Pointer Derivation in Pooled Direct ByteBuf Fallback Leads to Out-of-Bounds Native Memory Access |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 中危 |
Mavenio.netty.incubator:netty-incubator-codec-ohttp-hpke-native-boringssl |
| 已审查 |
| 2026-06-11 21:28 |
| 2026-06-11 21:28 |
| GHSA-9GW6-46QC-99VR CVE-2026-48039 | Meta Ads MCP: Unauthenticated HTTP MCP Tool Execution Leaks Operator Meta Access Token | 严重 | PyPImeta-ads-mcp | 已审查 | 2026-06-11 21:28 | 2026-08-08 03:29 |
| GHSA-5375-PQ7M-F5R2 CVE-2026-48068 | @grpc/grpc-js: A malformed request can cause a server crash | 高危 | npm@grpc/grpc-js | 已审查 | 2026-06-11 21:27 | 2026-06-11 21:27 |
| GHSA-99F4-GRH7-6PCQ CVE-2026-48069 | @grpc/grpc-js: An incoming malformed compressed message can cause a client or server crash | 高危 | npm@grpc/grpc-js | 已审查 | 2026-06-11 21:27 | 2026-06-11 21:27 |
| GHSA-Q7CG-457F-VX79 CVE-2026-48038 | joi has an uncaught RangeError on deeply nested input through recursive `link()` schemas | 中危 | npmjoi | 已审查 | 2026-06-11 21:27 | 2026-06-13 03:28 |
| GHSA-4X76-22X2-RX8V CVE-2026-48054 | OpenZeppelin Contracts Wizard has Code Injection in Generated Hardhat and Foundry Tests via Unsanitized opts.name / opts.uri | 高危 | npm@openzeppelin/wizard | 已审查 | 2026-06-11 21:27 | 2026-06-11 21:27 |
| GHSA-X426-X7CC-3FPC CVE-2026-48022 | @hapi/wreck: Sensitive credential headers leak across cross-port and cross-scheme redirects | 中危 | npm@hapi/wreck | 已审查 | 2026-06-11 21:27 | 2026-06-11 21:27 |
| GHSA-XF64-8MW2-4GR2 CVE-2026-48020 | Traefik has a StripPrefix Route-Level Auth Bypass via Path Normalization | 高危 | Gogithub.com/traefik/traefik/v2+1 | 已审查 | 2026-06-11 21:26 | 2026-09-02 23:34 |
| GHSA-6VHH-4XW6-H2H2 CVE-2026-48007 | Element Call reports full URLs of visited pages to analytics server | 高危 | npm@element-hq/element-call-embedded | 已审查 | 2026-06-11 21:26 | 2026-06-11 21:26 |
| GHSA-6JV9-X5W9-2CCM CVE-2026-48006 | Netty's Lack of Lifecycle Cleanup Leads to Pooled ByteBuf Leak in RedisArrayAggregator | 高危 | Mavenio.netty:netty-codec-redis | 已审查 | 2026-06-11 21:26 | 2026-08-12 20:32 |
| GHSA-QQ6C-99PV-PRVF CVE-2026-47781 | PDM: Project-Controlled `.pdm-plugins` Content Executes Before CLI Parsing | 高危 | PyPIpdm | 已审查 | 2026-06-11 21:25 | 2026-06-11 21:25 |
| GHSA-6GXQ-GPR8-XGJP CVE-2026-47780 | free5GC UDR has improper `ueId` validation in EE subscription handlers that allows arbitrary identifier persistence | 中危 | Gogithub.com/free5gc/udr | 已审查 | 2026-06-11 21:25 | 2026-06-11 21:25 |
| GHSA-Q8R6-5HFW-5JFF CVE-2026-53723 | guzzlehttp/guzzle-services' XML Request Serialization Vulnerable to XML Injection via CDATA Terminator | 中危 | Packagistguzzlehttp/guzzle-services | 已审查 | 2026-06-11 21:05 | 2026-07-16 05:58 |
| GHSA-34XG-WGJX-8XPH CVE-2026-48998 | guzzlehttp/psr7 has Host Confusion via Authority Reinterpretation | 中危 | Packagistguzzlehttp/psr7 | 已审查 | 2026-06-11 21:04 | 2026-07-16 05:58 |
| GHSA-HQ7V-MX3G-29HW CVE-2026-49214 | guzzlehttp/psr7 has CRLF Injection via URI Host Component | 中危 | Packagistguzzlehttp/psr7 | 已审查 | 2026-06-11 21:04 | 2026-07-16 05:58 |
| GHSA-WCWG-C5FC-9VRC CVE-2026-5497 | vLLM is vulnerable to an Out-of-Memory (OOM) Denial of Service (DoS) attack due to unbounded frame count processing in the `VideoMediaIO.load_base64()` method | 高危 | PyPIvllm | 已审查 | 2026-06-11 20:32 | 2026-08-19 04:16 |
| GHSA-WHPP-XV3H-RWXF CVE-2026-40999 | Spring Web Services: SSRF via unvalidated WS-Addressing reply destinations | 高危 | Mavenorg.springframework.ws:spring-ws-core | 已审查 | 2026-06-11 17:31 | 2026-08-22 03:13 |
| GHSA-PX92-Q6RC-6MWV CVE-2026-41699 | Spring for GraphQL: Unsafe Deserialization | 高危 | Mavenorg.springframework.graphql:spring-graphql | 已审查 | 2026-06-11 17:31 | 2026-08-22 03:13 |
| GHSA-PHXQ-526M-79PX CVE-2026-41856 | Spring for GraphQL: Annotation Detection Vulnerability | 高危 | Mavenorg.springframework.graphql:spring-graphql | 已审查 | 2026-06-11 17:31 | 2026-08-22 03:14 |
| GHSA-P7QJ-2Q5W-F9R7 CVE-2026-40996 | Spring Web Services: Inbound WS-Security allows RSA PKCS#1 v1.5 key transport by default | 中危 | Mavenorg.springframework.ws:spring-ws-security | 已审查 | 2026-06-11 17:31 | 2026-08-22 03:12 |
| GHSA-M39W-HQXX-3R48 CVE-2026-41700 | Spring for GraphQL: Cross-Site WebSocket Hijacking | 高危 | Mavenorg.springframework.graphql:spring-graphql | 已审查 | 2026-06-11 17:31 | 2026-08-22 03:14 |
| GHSA-GGG2-9786-HWC8 CVE-2026-41001 | Spring Boot: Predictable Temp Directory in Artemis Auto-configuration | 中危 | Mavenorg.springframework.boot:spring-boot-autoconfigure | 已审查 | 2026-06-11 17:31 | 2026-08-22 03:13 |
| GHSA-GG9R-WR4P-W63H CVE-2026-40994 | Spring Web Services: Wss4jSecurityInterceptor disables WS-I BSP validation by default | 高危 | Mavenorg.springframework.ws:spring-ws-security | 已审查 | 2026-06-11 17:31 | 2026-08-22 03:12 |
| GHSA-8QQ9-R6CC-QJV9 CVE-2026-41000 | Spring Web Services: WSS4J validation does not use configured replay cache | 低危 | Mavenorg.springframework.ws:spring-ws-security | 已审查 | 2026-06-11 17:31 | 2026-08-22 03:13 |