检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-QPGP-93VX-G8V8 CVE-2026-47736 | Puma PROXY Protocol v1 Parser Allows Remote Memory Exhaustion | 高危 | RubyGemspuma | 已审查 | 2026-06-09 07:55 | 2026-06-09 07:55 |
| GHSA-P2J4-C4G6-RPF5 CVE-2026-47735 | Arc has an authenticated arbitrary local-file read via DuckDB I/O functions that bypasses RBAC table-level checks |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 高危 |
Gogithub.com/basekick-labs/arc |
| 已审查 |
| 2026-06-09 07:51 |
| 2026-06-09 07:51 |
| GHSA-XRVJ-V92F-53GJ CVE-2026-47734 | Dulwich has unbounded memory allocation in receive-pack from crafted thin packs | 中危 | PyPIdulwich | 已审查 | 2026-06-09 07:43 | 2026-06-11 22:07 |
| GHSA-QM33-P5P9-F8VG CVE-2026-47726 | nebula-mesh: GET /api/v1/audit-log discloses all entries to any operator | 高危 | Gogithub.com/juev/nebula-mesh | 已审查 | 2026-06-09 07:35 | 2026-06-09 07:35 |
| GHSA-273Q-QGH5-WRJ6 CVE-2026-47725 | nebula-mesh's web UI lacks CSRF tokens on /ui/* mutating endpoints | 高危 | Gogithub.com/juev/nebula-mesh | 已审查 | 2026-06-09 07:09 | 2026-06-09 07:09 |
| GHSA-598G-H2VC-H5VG CVE-2026-47724 | nebula-mesh: API endpoints lack ownership checks, enabling cross-operator privilege escalation | 严重 | Gogithub.com/juev/nebula-mesh | 已审查 | 2026-06-09 07:09 | 2026-06-09 07:09 |
| GHSA-W7W5-5GCP-38RW CVE-2026-47723 | nebula-mesh: Web UI and API responses lack security headers (CSP, X-Frame-Options, HSTS, etc.) | 高危 | Gogithub.com/juev/nebula-mesh | 已审查 | 2026-06-09 07:08 | 2026-06-09 07:08 |
| GHSA-7HP6-G3PQ-3PC3 CVE-2026-47722 | nebula-mesh: Host advanced overrides allow YAML injection into agent config.yml | 高危 | Gogithub.com/juev/nebula-mesh | 已审查 | 2026-06-09 07:08 | 2026-06-09 07:08 |
| GHSA-8GHR-W65F-J3QR CVE-2026-47721 | FUXA's scheduler API missing admin check enables operator-to-admin escalation via scheduled device actions | 中危 | npmfuxa-server | 已审查 | 2026-06-09 07:07 | 2026-06-09 07:07 |
| GHSA-H9FJ-C2QR-76G2 CVE-2026-47720 | FUXA has SQL Injection in its TDengine DAQ connector via backslash bypass of escapeTdString | 中危 | npmfuxa-server | 已审查 | 2026-06-09 07:06 | 2026-06-09 07:06 |
| GHSA-W86F-RF9W-H3X6 CVE-2026-47719 | FUXA: Unauthenticated SSRF via Socket.IO DEVICE_WEBAPI_REQUEST and DEVICE_PROPERTY with response reading | 高危 | npmfuxa-server | 已审查 | 2026-06-09 07:06 | 2026-06-09 07:06 |
| GHSA-555P-6GRF-MH7F CVE-2026-47712 | Dulwich doesn't sanitize commit subjects in `porcelain.format_patch` | 低危 | PyPIdulwich | 已审查 | 2026-06-09 07:04 | 2026-06-11 22:07 |
| GHSA-3H6H-67X3-CV5X CVE-2026-47693 | Poweradmin: CSV Injection in log export endpoints allows formula execution in spreadsheet applications | 中危 | Packagistpoweradmin/poweradmin | 已审查 | 2026-06-09 07:04 | 2026-07-21 05:22 |
| GHSA-HRJ8-HJV8-MGWC CVE-2026-47252 | Anyquery: AppleScript/JXA Code Injection via Unescaped URL in macOS Chrome Plugin | 严重 | Gogithub.com/julien040/anyquery/plugins/brave+3 | 已审查 | 2026-06-09 07:04 | 2026-06-09 07:04 |
| GHSA-5PVG-856G-CP85 CVE-2026-47691 | Netty has Insufficient Bailiwick Validation for NS Records | 高危 | Mavenio.netty:netty-resolver-dns | 已审查 | 2026-06-09 07:02 | 2026-09-02 23:34 |
| GHSA-5X3R-WRVG-RP6Q CVE-2026-47244 | Netty HTTP/2: Advertised MAX_CONCURRENT_STREAMS are not enforced | 中危 | Mavenio.netty:netty-codec-http2 | 已审查 | 2026-06-09 07:02 | 2026-06-13 03:30 |
| GHSA-5XRH-QMMQ-W6CH CVE-2026-46340 | Netty: SCTP reassembly nests buffers without bound | 高危 | Mavenio.netty:netty-transport-sctp | 已审查 | 2026-06-09 07:02 | 2026-06-13 03:29 |
| GHSA-676X-F7GG-47VC CVE-2026-45674 | Netty Vulnerable to DNS Cache Poisoning via Missing Bailiwick Checks in CNAME Records | 高危 | Mavenio.netty:netty-resolver-dns | 已审查 | 2026-06-09 07:02 | 2026-09-02 23:34 |
| GHSA-XMV7-R254-6Q78 CVE-2026-45673 | Netty: DNS Cache Poisoning due to Predictable PRNG and Default Static Source Port | 中危 | Mavenio.netty:netty-resolver-dns | 已审查 | 2026-06-09 07:02 | 2026-06-13 03:29 |
| GHSA-W573-9FFJ-6FF9 CVE-2026-45536 | Netty: Unix-socket fd receive leaks descriptors when peer sends two at once | 中危 | Mavenio.netty:netty-transport-native-epoll+1 | 已审查 | 2026-06-09 07:01 | 2026-06-13 03:29 |
| GHSA-X4GW-5CX5-PGMH CVE-2026-45416 | Netty: SNI handler pre-allocates up to 16 MiB from nine attacker bytes | 高危 | Mavenio.netty:netty-handler | 已审查 | 2026-06-09 07:01 | 2026-06-13 03:29 |
| GHSA-87M4-826X-3CRX CVE-2026-45034 | PHPSpreadsheet has a patch bypass for CVE-2026-34084 | 严重 | Packagistphpoffice/phpspreadsheet | 已审查 | 2026-06-09 07:00 | 2026-06-09 07:00 |
| GHSA-CMM3-54F8-PX4J CVE-2026-44894 | Netty's Default QUIC token handler accepts any client-supplied token | 高危 | Mavenio.netty:netty-codec-classes-quic | 已审查 | 2026-06-09 06:59 | 2026-06-13 03:29 |
| GHSA-CC37-9Q2J-3HFV CVE-2026-44893 | Netty: HAProxy SSL TLV parsing leaks retained slice on invalid TLV length | 高危 | Mavenio.netty:netty-codec-haproxy | 已审查 | 2026-06-09 03:02 | 2026-06-13 03:29 |
| GHSA-C2RX-5R8W-8XR2 CVE-2026-44892 | Netty has a Vulnerable Default Configuration Which Leads to Denial of Service via Unbounded HTTP/3 Header Size | 高危 | Mavenio.netty:netty-codec-http3 | 已审查 | 2026-06-09 03:02 | 2026-06-13 03:27 |