检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-5VPF-XVV7-C8VH CVE-2026-41711 | Spring Data Commons: StackOverflowException when parsing Sort parameters (DoS) | 中危 | Mavenorg.springframework.data:spring-data-commons | 已审查 | 2026-06-10 08:31 | 2026-08-13 00:16 |
| GHSA-4R8W-73JC-3M7Q CVE-2026-41008 | Spring Security OAuth2 Authorization Server: Authorization endpoint performs insufficient validation of the request_uri parameter |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 中危 |
Mavenorg.springframework.security:spring-security-oauth2-authorization-server |
| 已审查 |
| 2026-06-10 08:31 |
| 2026-08-13 00:23 |
| GHSA-3PJJ-QPW6-5FCM CVE-2026-41003 | Spring Security SAML2 Service Provider: RelyingPartyRegistration may run arbitrary code on HTML forms generated by Spring Security filters | 高危 | Mavenorg.springframework.security:spring-security-saml2-service-provider | 已审查 | 2026-06-10 08:31 | 2026-08-13 01:04 |
| GHSA-2Q7C-5GJM-7Q23 CVE-2026-40993 | Spring Security SAML2 Service Provider is vulnerable to Deserialization of Untrusted Data via JdbcAssertingPartyMetadataRepository | 高危 | Mavenorg.springframework.security:spring-security-saml2-service-provider | 已审查 | 2026-06-10 08:31 | 2026-08-13 01:04 |
| GHSA-JVC5-6G7Q-C843 CVE-2026-48030 | Pheditor: OS Command Injection in terminal handler via unsanitized 'dir' parameter | 严重 | Packagistpheditor/pheditor | 已审查 | 2026-06-10 06:00 | 2026-06-10 06:00 |
| GHSA-7QJX-GP9H-65QJ | Dex: Token-exchange endpoint is missing AllowedConnectors enforcement | 高危 | Gogithub.com/dexidp/dex | 已审查 | 2026-06-10 05:59 | 2026-06-10 05:59 |
| GHSA-MRHX-6PW9-Q5FH CVE-2026-47068 | PhoenixStorybook has cross-session PubSub topic injection via URL parameter | 低危 | Hexphoenix_storybook | 已审查 | 2026-06-10 05:59 | 2026-06-10 05:59 |
| GHSA-833P-95JQ-929Q CVE-2026-8469 | PhoenixStorybook: Unbounded atom creation from LiveView event params (atom-table DoS) | 高危 | Hexphoenix_storybook | 已审查 | 2026-06-10 05:59 | 2026-06-10 05:59 |
| GHSA-55HG-8QXV-QJ4P CVE-2026-8467 | PhoenixStorybook: Unauthenticated remote code execution via HEEx template injection in phoenix_storybook playground | 严重 | Hexphoenix_storybook | 已审查 | 2026-06-10 05:58 | 2026-06-10 05:58 |
| GHSA-FQC7-9XJW-JRH3 CVE-2026-47767 | SymfonyRuntime CVE-2024-50340 Patch Bypass: Web Requests Can Still Set APP_ENV/APP_DEBUG via parse_str/SAPI Argv Mismatch | 中危 | Packagistsymfony/runtime+1 | 已审查 | 2026-06-10 05:58 | 2026-06-10 05:58 |
| GHSA-46Q3-7GV7-QMGG CVE-2026-47242 | Net::IMAP: Command Injection via ID command argument | 中危 | RubyGemsnet-imap | 已审查 | 2026-06-10 04:31 | 2026-07-07 06:54 |
| GHSA-C4FP-CXRR-MJ66 CVE-2026-47241 | Net::IMAP: Denial of Service via incomplete raw argument validation | 低危 | RubyGemsnet-imap | 已审查 | 2026-06-10 02:36 | 2026-07-07 06:53 |
| GHSA-8P34-64R3-MWG8 CVE-2026-47240 | Net::IMAP: Command Injection via non-synchronizing literal in "raw" argument | 中危 | RubyGemsnet-imap | 已审查 | 2026-06-10 02:36 | 2026-07-07 06:53 |
| GHSA-PR6F-87HF-HX24 CVE-2026-50636 | LimeSurvey has a SQL Injection issue | 高危 | Packagistlimesurvey/limesurvey | 已审查 | 2026-06-10 02:31 | 2026-08-01 03:24 |
| GHSA-5C37-5J7W-8MH8 CVE-2026-50635 | LimeSurvey constructs account password-reset links from the client-supplied HTTP Host header without validating it. | 高危 | Packagistlimesurvey/limesurvey | 已审查 | 2026-06-10 02:31 | 2026-08-01 03:22 |
| GHSA-W7JW-789Q-3M8P CVE-2026-9277 | shell-quote quote() does not escape newlines in object .op values | 严重 | npmshell-quote | 已审查 | 2026-06-09 22:27 | 2026-06-09 22:27 |
| GHSA-G29C-RGQ6-GXGJ CVE-2026-52902 | awxkit has a path traversal vulnerability | 中危 | PyPIawxkit | 已审查 | 2026-06-09 20:32 | 2026-08-01 00:39 |
| GHSA-X4F6-MQG6-28XX CVE-2026-34031 | Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability | 中危 | Gogithub.com/apache/incubator-answer | 已审查 | 2026-06-09 17:32 | 2026-07-31 23:45 |
| GHSA-W754-5646-XQ9J CVE-2026-25699 | Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability | 中危 | Gogithub.com/apache/incubator-answer | 已审查 | 2026-06-09 17:32 | 2026-07-31 02:31 |
| GHSA-V553-G2W6-295P CVE-2026-33582 | Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability | 中危 | Gogithub.com/apache/incubator-answer | 已审查 | 2026-06-09 17:32 | 2026-07-31 23:49 |
| GHSA-HMR2-99JM-8X45 CVE-2026-25688 | Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability | 中危 | Gogithub.com/apache/incubator-answer | 已审查 | 2026-06-09 17:32 | 2026-07-31 00:49 |
| GHSA-F6VJ-48FM-HMVX CVE-2026-49818 | Apache Airflow has a Path Traversal issue | 中危 | PyPIapache-airflow-providers-samba | 已审查 | 2026-06-09 17:32 | 2026-08-01 00:37 |
| GHSA-85R2-PVG8-89R9 CVE-2026-34905 | Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability | 中危 | Gogithub.com/apache/incubator-answer | 已审查 | 2026-06-09 17:32 | 2026-07-31 23:51 |
| GHSA-6QWM-5FM9-CVJX CVE-2026-34033 | Apache Answer vulnerable to Cross-site Scripting | 中危 | Gogithub.com/apache/incubator-answer | 已审查 | 2026-06-09 17:32 | 2026-07-31 23:53 |
| GHSA-77C7-PQ4R-6MCQ CVE-2026-11572 | degit has a Command Injection issue | 高危 | npmdegit | 已审查 | 2026-06-09 14:31 | 2026-07-31 02:35 |