检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-G759-4PXW-6692 CVE-2026-48032 | @hulumi/policies bypasses IAM-role policy checks when the role trusts multiple OIDC providers | 高危 | npm@hulumi/policies | 已审查 | 2026-06-10 21:37 | 2026-06-10 21:37 |
| GHSA-G82F-9PW7-773W CVE-2026-10721 | Concrete CMS: PHP Object Injection via unserialize() calls |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 高危 |
Packagistconcrete5/concrete5 |
| 已审查 |
| 2026-06-10 17:31 |
| 2026-08-13 07:21 |
| GHSA-WMJR-58RF-XGRC CVE-2026-53675 | BuddyPress: Any authenticated attacker can enumerate another user's complete friend list via IDOR | 中危 | Packagistbuddypress/buddypress | 已审查 | 2026-06-10 08:31 | 2026-08-13 03:13 |
| GHSA-J3J5-5M8V-7GVC CVE-2026-53673 | BuddyPress: Authenticated attackers can access arbitrary private message threads via user_id request parameter | 高危 | Packagistbuddypress/buddypress | 已审查 | 2026-06-10 08:31 | 2026-08-13 02:47 |
| GHSA-293Q-567P-WMWQ CVE-2026-47838 | Spring Security Vulnerable to Unauthorized User Impersonation when Using X.509 Client Certificates | 中危 | Mavenorg.springframework.security:spring-security-web | 已审查 | 2026-06-10 08:31 | 2026-07-01 05:35 |
| GHSA-XVFQ-4Q6Q-GXX7 CVE-2026-41726 | In Spring for Apache Kafka, unbounded delegate cache keyed on user-controlled, potentially malicious selector header | 中危 | Mavenorg.springframework.kafka:spring-kafka | 已审查 | 2026-06-10 08:31 | 2026-06-13 05:51 |
| GHSA-XQ69-5H5V-X9X4 CVE-2026-41731 | In Spring for Apache Kafka, overly broad trusted-package matching in header mappers exposes JDK classes to deserialization | 高危 | Mavenorg.springframework.kafka:spring-kafka | 已审查 | 2026-06-10 08:31 | 2026-06-13 05:51 |
| GHSA-XG2J-3HJ6-PC24 CVE-2026-41719 | Spring Data KeyValue: Remote code execution via SpEL Injection in Sort-based repository queries | 中危 | Mavenorg.springframework.data:spring-data-keyvalue | 已审查 | 2026-06-10 08:31 | 2026-08-12 23:40 |
| GHSA-P5MM-XWGQ-WHFR CVE-2026-41730 | Spring Data REST potentially exposes persistence-layer internals to HTTP clients | 中危 | Mavenorg.springframework.data:spring-data-rest-core | 已审查 | 2026-06-10 08:31 | 2026-08-13 01:42 |
| GHSA-MWPV-RG79-863C CVE-2026-41837 | Spring Data REST Querydsl Integration Exposes Persistent Property Paths, Bypassing Jackson Customizations | 中危 | Mavenorg.springframework.data:spring-data-rest-core | 已审查 | 2026-06-10 08:31 | 2026-08-13 01:04 |
| GHSA-J388-8RM5-P97F CVE-2026-41729 | Spring Data REST is vulnerable to SpEL expression injection through map-typed properties when processing JSON Patch requests | 高危 | Mavenorg.springframework.data:spring-data-rest-core | 已审查 | 2026-06-10 08:31 | 2026-08-13 01:41 |
| GHSA-GG69-9WWP-6JX2 CVE-2026-41732 | Spring for Apache Pulsar: JsonPulsarHeaderMapper Trusted-Package Prefix Check Allows Unintended Subpackage Deserialization | 高危 | Mavenorg.springframework.pulsar:spring-pulsar | 已审查 | 2026-06-10 08:31 | 2026-08-13 01:40 |
| GHSA-CV39-X4C6-HHP2 CVE-2026-41728 | Spring Data REST has Improper Access Control in its JSON Patch Implementation | 高危 | Mavenorg.springframework.data:spring-data-rest-core | 已审查 | 2026-06-10 08:31 | 2026-08-13 01:41 |
| GHSA-5M4M-73W9-8433 CVE-2026-41721 | Spring Data Commons: Denial of Service via excessive memory allocation in projection binding | 中危 | Mavenorg.springframework.data:spring-data-commons | 已审查 | 2026-06-10 08:31 | 2026-08-13 02:00 |
| GHSA-53W6-V7CV-FC9H CVE-2026-41727 | Spring for Apache Kafka: Improper Validation of Retry Topic Header Values Leads to Retry Sequence Manipulation | 中危 | Mavenorg.springframework.kafka:spring-kafka | 已审查 | 2026-06-10 08:31 | 2026-08-13 01:42 |
| GHSA-X2R2-RVHQ-2MQV CVE-2026-41706 | Spring Security: Open Redirect via Unvalidated Post-Login Redirect URL Stored in CookieRequestCache | 中危 | Mavenorg.springframework.security:spring-security-web | 已审查 | 2026-06-10 08:31 | 2026-08-13 00:17 |
| GHSA-WW38-37G9-M3Q3 CVE-2026-41694 | Spring Security SAML2 Service Provider: Decryption Oracle Vulnerability from Unsigned SAML Response and Logout Payloads | 低危 | Mavenorg.springframework.security:spring-security-saml2-service-provider | 已审查 | 2026-06-10 08:31 | 2026-08-13 00:22 |
| GHSA-P8QJ-FJ6R-W7Q9 CVE-2026-41714 | Spring AMQP Core: Missing Certificate and Hostname Verification for amqps URIs in RabbitConnectionFactoryBean | 中危 | Mavenorg.springframework.amqp:spring-amqp | 已审查 | 2026-06-10 08:31 | 2026-08-13 00:14 |
| GHSA-P5F7-RJHP-PXVC CVE-2026-41701 | Spring AMQP Has Predictable Correlation IDs in RabbitTemplate.sendAndReceive() with Fixed Reply Queue | 中危 | Mavenorg.springframework.amqp:spring-amqp | 已审查 | 2026-06-10 08:31 | 2026-08-13 00:21 |
| GHSA-M69X-PW9P-7J3Q CVE-2026-40988 | Spring Security SAML2 Service Provider: Unbounded writer inflates the compressed SAML payload into memory (DoS) | 高危 | Mavenorg.springframework.security:spring-security-saml2-service-provider | 已审查 | 2026-06-10 08:31 | 2026-08-12 23:40 |
| GHSA-HC43-M36C-8V33 CVE-2026-41696 | Spring Data MongoDB Has Regex Parameter Binding Injection in @Query Repository Methods | 中危 | Mavenorg.springframework.data:spring-data-mongodb | 已审查 | 2026-06-10 08:31 | 2026-08-13 00:21 |
| GHSA-9FW2-H3HF-293R CVE-2026-41716 | Spring Data Commons: Heap exhaustion from unbounded property-lookup cache retaining crafted string keys | 高危 | Mavenorg.springframework.data:spring-data-commons | 已审查 | 2026-06-10 08:31 | 2026-08-13 00:10 |
| GHSA-8R2H-XH92-GQ57 CVE-2026-41697 | Spring Data Relational: Attackers can supply wildcard characters to perform boolean-based blind data inference | 中危 | Mavenorg.springframework.data:spring-data-relational | 已审查 | 2026-06-10 08:31 | 2026-08-13 00:19 |
| GHSA-6RPQ-6VV2-5222 CVE-2026-40991 | Spring REST Docs REST Assured & WebFlux are vulnerable to Improper Restriction of XML External Entity Reference | 中危 | Mavenorg.springframework.restdocs:spring-restdocs-restassured+1 | 已审查 | 2026-06-10 08:31 | 2026-08-12 23:26 |
| GHSA-5WHC-4Q84-FJ73 CVE-2026-41717 | Spring Data MongoDB is vulnerable to SpEL (Spring Expression Language) expression injection | 高危 | Mavenorg.springframework.data:spring-data-mongodb | 已审查 | 2026-06-10 08:31 | 2026-08-12 23:41 |