检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-6MFM-98WV-32WM CVE-2026-40995 | Spring Web Services: X.509 authentication bypasses Spring Security account checks | 中危 | Mavenorg.springframework.ws:spring-ws-security | 已审查 | 2026-06-11 17:31 | 2026-08-22 03:12 |
| GHSA-5X25-C2RF-F2JX CVE-2026-40997 | Spring Web Services: SOAP security faults leak Spring Security account state |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 中危 |
Mavenorg.springframework.ws:spring-ws-security |
| 已审查 |
| 2026-06-11 17:31 |
| 2026-08-22 03:13 |
| GHSA-2MPF-M756-HXJM CVE-2026-40998 | Spring Web Services: Jaxp13 XPath XXE via StreamSource and SAXSource | 高危 | Mavenorg.springframework.ws:spring-xml | 已审查 | 2026-06-11 17:31 | 2026-08-22 03:13 |
| GHSA-HW5C-XM3C-V96W CVE-2026-40986 | Spring Web Flow JS RemotingHandler renders non-HTML Response as HTML | 中危 | Mavenorg.springframework.webflow:spring-webflow | 已审查 | 2026-06-11 17:31 | 2026-08-19 04:14 |
| GHSA-9WXP-W4PX-32VH CVE-2026-40992 | Spring Boot's Mail Auto-Configuration Does Not Enable SSL Hostname Verification | 中危 | Mavenorg.springframework.boot:spring-boot-starter-mail | 已审查 | 2026-06-11 17:31 | 2026-08-19 04:13 |
| GHSA-792X-6VQ6-J8R9 CVE-2026-40987 | Spring Integration File Support: FTP/SFTP/SMB server can write arbitrary files anywhere on the client filesystem | 高危 | Mavenorg.springframework.integration:spring-integration-file | 已审查 | 2026-06-11 17:31 | 2026-08-08 02:59 |
| GHSA-9GGW-87M9-9GFC CVE-2026-40985 | Spring Web Flow has Data Binding Vulnerability with Unified EL Parser | 中危 | Mavenorg.springframework.webflow:spring-webflow | 已审查 | 2026-06-11 14:30 | 2026-08-19 04:10 |
| GHSA-M3PX-Q5GJ-J9X7 CVE-2026-10142 | kafka-python vulnerable to denial of service through an unvalidated protocol frame length | 高危 | PyPIkafka-python | 已审查 | 2026-06-11 08:32 | 2026-09-02 01:15 |
| GHSA-2JCM-HQ8R-84WX CVE-2026-10143 | kafka-python vulnerable to denial of service through an unbounded SCRAM iteration count | 高危 | PyPIkafka-python | 已审查 | 2026-06-11 08:32 | 2026-09-02 01:16 |
| GHSA-9PG3-25FQ-P6CC CVE-2026-47768 | nebula-mesh: Newly-minted operator API key exposed in redirect URL (Referer, history, proxy logs) | 中危 | Gogithub.com/juev/nebula-mesh | 已审查 | 2026-06-11 06:13 | 2026-06-11 06:13 |
| GHSA-78V8-VPJP-CJQH CVE-2026-47764 | PDM wheel installation leads to Path Traversal via overridden write_to_fs | 高危 | PyPIpdm | 已审查 | 2026-06-11 04:33 | 2026-06-11 04:33 |
| GHSA-GHQ2-5C67-FPRM CVE-2026-47763 | PDM: Project-Local State and Config Writes Follow Symlinks | 中危 | PyPIpdm | 已审查 | 2026-06-11 04:32 | 2026-06-11 04:32 |
| GHSA-8G7M-96C8-8WWC CVE-2026-47753 | Incus has a Nil-Pointer Dereference Panic via Instance Backup Import (volume omitted) | 中危 | Gogithub.com/lxc/incus/v7 | 已审查 | 2026-06-11 04:07 | 2026-06-11 04:07 |
| GHSA-8Q5R-MMJF-575Q CVE-2026-47751 | Claude Code Action: Malicious MCP Server Configuration in PRs Enables Remote Code Execution and Secret Exfiltration | 中危 | GitHub Actionsanthropics/claude-code-action | 已审查 | 2026-06-11 03:33 | 2026-09-01 08:59 |
| GHSA-QVV5-JQ5G-4CGG CVE-2026-48063 | Baileys has message upsert / hist sync spoofing and app state corruption when using maliciously crafted protocolMessage payload | 严重 | npm@whiskeysockets/baileys+1 | 已审查 | 2026-06-11 03:33 | 2026-06-11 03:33 |
| GHSA-3QMC-CJ7Q-62HV CVE-2026-48061 | Litestar: AllowedHostsMiddleware bypasses host validation via client-controlled X-Forwarded-Host header | 中危 | PyPIlitestar | 已审查 | 2026-06-11 03:12 | 2026-06-11 03:12 |
| GHSA-542P-WVX7-72M4 CVE-2026-48060 | Litestar has HTML Injection Through its CSRF Token | 高危 | PyPIlitestar | 已审查 | 2026-06-11 03:12 | 2026-06-11 03:12 |
| GHSA-RQFJ-VV8R-XHQC CVE-2026-48058 | nebula-mesh: Session and OIDC state cookies lack the Secure attribute | 中危 | Gogithub.com/juev/nebula-mesh | 已审查 | 2026-06-11 02:49 | 2026-06-11 02:49 |
| GHSA-8H84-FHQQ-Q58V CVE-2026-48025 | nebula-mesh: Decrypted CA private key persists in heap after signing | 中危 | Gogithub.com/forgekeep/nebula-mesh+1 | 已审查 | 2026-06-11 02:34 | 2026-06-27 04:48 |
| GHSA-QV8H-RQR3-MPH9 CVE-2026-53698 | Silverpeas mishandles the "Personal space" feature that is selected when no componentId is set | 中危 | Mavenorg.silverpeas.core:silverpeas-core+1 | 已审查 | 2026-06-11 02:31 | 2026-08-18 05:54 |
| GHSA-4GW2-VG4X-7P29 CVE-2026-25700 | Apache Answer: AdminToken not invalidated after admin deactivation | 高危 | Gogithub.com/apache/answer+1 | 已审查 | 2026-06-11 02:31 | 2026-08-18 05:53 |
| GHSA-CXH2-4639-VMC5 CVE-2026-47701 | OpenTelemetry Operator for Kubernetes's ServiceMonitor bearerTokenFile reads arbitrary local file and sends contents as bearer auth | 高危 | Gogithub.com/open-telemetry/opentelemetry-operator | 已审查 | 2026-06-11 01:24 | 2026-06-11 01:24 |
| GHSA-J9RX-RPPG-6HH4 CVE-2026-47253 | Anyquery has Path Traversal through `clear_plugin_cache`, Allowing Arbitrary Directory Deletion | 高危 | Gogithub.com/julien040/anyquery | 已审查 | 2026-06-11 01:11 | 2026-06-11 01:11 |
| GHSA-3WW4-5JV9-J5GM CVE-2026-47155 | vLLM's Artifact Pin Decay allows pinned deployments to load unpinned code, weights, and processors | 中危 | PyPIvllm | 已审查 | 2026-06-11 01:11 | 2026-07-18 00:21 |
| GHSA-CQGJ-H8VF-4W59 CVE-2025-53114 | Acknowledgement extension out of memory | 高危 | Mavenorg.cometd.java:cometd-java-server-common | 已审查 | 2026-06-11 00:46 | 2026-06-11 00:46 |