检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-6GHJ-FRRJ-JJJ3 CVE-2026-44890 | Netty has Unbounded Direct Memory Consumption in its RedisDecoder | 高危 | Mavenio.netty:netty-codec-redis | 已审查 | 2026-06-09 03:02 | 2026-06-13 03:27 |
| GHSA-3244-J874-RHC2 CVE-2026-44250 | Netty: Memory Exhaustion in RedisArrayAggregator due to Deeply Nested Arrays |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 高危 |
Mavenio.netty:netty-codec-redis |
| 已审查 |
| 2026-06-09 03:01 |
| 2026-06-13 03:27 |
| GHSA-3QP7-7MW8-WX86 CVE-2026-44249 | Netty has an IPv6 Subnet Filter Bypass via Incorrect Comparator Masking | 高危 | Mavenio.netty:netty-handler | 已审查 | 2026-06-09 03:00 | 2026-06-13 03:27 |
| GHSA-W4F7-4CXR-RV3C CVE-2026-43966 | cowboy and gun affected by an HTTP Request/Response Splitting vulnerability | 中危 | Hexcowboy+1 | 已审查 | 2026-06-09 02:31 | 2026-07-29 23:48 |
| GHSA-MVQ4-39WX-6H5G CVE-2026-11529 | MySQL MCP Server is Vulnerable to SQL Injection Through its mysql URI Handler | 低危 | PyPImysql-mcp-server | 已审查 | 2026-06-09 02:31 | 2026-07-25 04:34 |
| GHSA-7RVM-XJPP-63R9 CVE-2026-42890 | actual Allows Electron to Run As Node | 中危 | npmactual | 已审查 | 2026-06-09 02:21 | 2026-06-13 05:59 |
| GHSA-W8P2-R796-3VMQ CVE-2026-41479 | Authlib OAuth 2.0 has Open Redirect in Authorization API that allows attacker-controlled redirect_uri through unsupported response_type | 中危 | PyPIauthlib | 已审查 | 2026-06-09 01:52 | 2026-07-19 01:25 |
| GHSA-R53J-FJJ5-MV77 CVE-2026-43973 | gun has an Uncontrolled Resource Consumption vulnerability | 高危 | Hexgun | 已审查 | 2026-06-08 23:33 | 2026-07-29 23:45 |
| GHSA-GC6Q-CWCJ-3VH9 CVE-2026-49234 | Routinator crashes when sending a maliciously crafted select-asn query parameter | 高危 | crates.ioroutinator | 已审查 | 2026-06-08 23:33 | 2026-06-13 03:06 |
| GHSA-5QF9-CF9C-HJC6 CVE-2026-49235 | Routinator crashes when encountering maliciously crafted RRDP XML files | 高危 | crates.ioroutinator | 已审查 | 2026-06-08 23:33 | 2026-06-13 03:06 |
| GHSA-33MJ-99MG-8G73 CVE-2026-49233 | Routinator has cache path traversal when processing the module component of rsync URIs | 高危 | crates.ioroutinator | 已审查 | 2026-06-08 23:33 | 2026-06-13 03:06 |
| GHSA-2J82-37XG-F9WP CVE-2026-43974 | gun has an Unexpected Status Code or Return Value vulnerability | 高危 | Hexgun | 已审查 | 2026-06-08 23:33 | 2026-07-29 23:45 |
| GHSA-36W4-95HV-5VWG CVE-2026-43972 | gun_http2 has an Origin Validation Error vulnerability | 中危 | Hexgun | 已审查 | 2026-06-08 23:32 | 2026-07-29 23:44 |
| GHSA-HW9R-6M78-W6H3 CVE-2026-39922 | GeoNode contains a server-side request forgery vulnerability in the service registration endpoint | 中危 | PyPIgeonode | 已审查 | 2026-06-08 20:51 | 2026-06-08 20:51 |
| GHSA-Q42J-X8RQ-PJG6 CVE-2026-47430 | Cordova Plugin InAppBrowser: iOS: Arbitrary Cordova callback IDs can be dispatched without validation from InAppBrowser WebViews. | 严重 | npmcordova-plugin-inappbrowser | 已审查 | 2026-06-08 20:30 | 2026-06-13 05:01 |
| GHSA-JQPM-WF57-QX5C CVE-2026-11500 | Weaviate has an Improper Authorization issue | 低危 | Gogithub.com/weaviate/weaviate | 已审查 | 2026-06-08 20:30 | 2026-07-29 23:41 |
| GHSA-Q76H-P6JH-9RW3 CVE-2026-11481 | grepai Uses a Broken or Risky Cryptographic Algorithm | 低危 | Gogithub.com/yoanbernabeu/grepai | 已审查 | 2026-06-08 11:47 | 2026-07-29 04:56 |
| GHSA-FXR3-GVM4-M8VC CVE-2026-11477 | hsweb-framework has an open redirect issue | 低危 | Mavenorg.hswebframework.web:hsweb-authorization-oauth2 | 已审查 | 2026-06-08 11:47 | 2026-07-29 04:55 |
| GHSA-6H35-9P2W-3J3R CVE-2026-11479 | grepai Uses a Broken or Risky Cryptographic Algorithm | 低危 | Gogithub.com/yoanbernabeu/grepai | 已审查 | 2026-06-08 11:47 | 2026-07-29 04:54 |
| GHSA-VJMR-F5FC-VR2W CVE-2026-11470 | hsweb-framework has a Path Traversal issue | 低危 | Mavenorg.hswebframework.web:hsweb-system-file | 已审查 | 2026-06-08 11:47 | 2026-07-29 04:56 |
| GHSA-7V3V-CP44-VC8M CVE-2026-11465 | songquanpeng one-api has an issue that results in business logic errors | 低危 | Gogithub.com/songquanpeng/one-api | 已审查 | 2026-06-08 08:30 | 2026-07-29 04:03 |
| GHSA-43PX-GPWC-Q84V CVE-2026-11466 | zilliztech deep-searcher has an Incorrect Privilege Assignment issue | 低危 | PyPIdeepsearcher | 已审查 | 2026-06-08 08:30 | 2026-07-29 04:54 |
| GHSA-PR2W-4GPJ-CPQ4 CVE-2026-47732 | Twig: Sandbox: multiple `__toString()` policy bypasses via unguarded string coercion points | 高危 | Packagisttwig/twig | 已审查 | 2026-06-06 05:47 | 2026-06-06 05:47 |
| GHSA-2G2G-8P8H-FGWM CVE-2026-47730 | Twig: XSS in profiler HtmlDumper via unescaped template and profile names | 低危 | Packagisttwig/twig | 已审查 | 2026-06-06 05:46 | 2026-06-06 05:47 |
| GHSA-5X67-J5XG-C5GJ CVE-2026-53954 | Bugsink: DOS using large numbers of event tags | 中危 | PyPIbugsink | 已审查 | 2026-06-06 05:45 | 2026-06-13 03:24 |