检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-C8H8-VQ34-9FW2 CVE-2026-47694 | WWBN AVideo: Stored XSS via unescaped Gallery category description | 中危 | PackagistWWBN/AVideo | 已审查 | 2026-06-05 02:46 | 2026-06-05 02:48 |
| GHSA-XF4V-W5X5-PV79 | Spree: CSV Formula Injection in Customer Export |
当前筛选结果 35,190 条 · 时间按北京时间显示
RubyGemsspree |
| 已审查 |
| 2026-06-05 02:46 |
| 2026-06-05 02:46 |
| GHSA-WC3V-3457-C8CM CVE-2026-8462 | OpenMeter: SQL injection through meter creation | 中危 | Gogithub.com/openmeterio/openmeter | 已审查 | 2026-06-05 02:39 | 2026-06-05 02:39 |
| GHSA-QMC5-GV6V-8P22 CVE-2026-50266 | OpenStack Neutron: Neutron port RBAC policy bypass allows project managers to set trusted device owners on shared networks | 低危 | PyPIneutron | 已审查 | 2026-06-05 02:30 | 2026-07-16 06:40 |
| GHSA-8F39-V287-78JF CVE-2026-50076 | Apache Fory Java SDK Has Deserialization of Untrusted Data in the Java replace-resolve path | 严重 | Mavenorg.apache.fory:fory-core | 已审查 | 2026-06-05 02:30 | 2026-07-16 06:32 |
| GHSA-JH6H-V6MP-H22V CVE-2026-10814 | milvus: RBAC grantee-id uses truncated MD5 (64-bit), enabling privilege-binding collisions and cross-role privilege forgery | 低危 | Gogithub.com/milvus-io/milvus | 已审查 | 2026-06-05 02:30 | 2026-07-16 06:09 |
| GHSA-76QH-XR7Q-H39M CVE-2026-44393 | OpenStack oslo.messaging does not verify RabbitMQ broker hostname during TLS handshake | 高危 | PyPIoslo.messaging | 已审查 | 2026-06-05 02:30 | 2026-07-16 06:30 |
| GHSA-3HH9-752G-5G22 CVE-2026-10813 | LMCache: 16-bit multimodal hash collision can poison KV cache entries | 低危 | PyPIlmcache | 已审查 | 2026-06-05 02:30 | 2026-07-16 06:10 |
| GHSA-2GCR-MFCQ-WCC3 CVE-2026-47676 | Hono: app.mount() strips mount prefix using undecoded path, causing incorrect routing for percent-encoded paths | 中危 | npmhono | 已审查 | 2026-06-05 02:01 | 2026-06-05 02:01 |
| GHSA-XRHX-7G5J-RCJ5 CVE-2026-47674 | Hono: IP Restriction bypasses static deny rules for non-canonical IPv6 | 中危 | npmhono | 已审查 | 2026-06-05 02:00 | 2026-06-05 02:00 |
| GHSA-3HRH-PFW6-9M5X CVE-2026-47675 | Hono: Cookie helper does not sanitize sameSite and priority, allowing Set-Cookie injection | 中危 | npmhono | 已审查 | 2026-06-05 01:59 | 2026-06-05 01:59 |
| GHSA-F577-QRJJ-4474 CVE-2026-47673 | Hono: JWT middleware accepts any Authorization scheme, not only Bearer | 中危 | npmhono | 已审查 | 2026-06-05 01:52 | 2026-06-05 01:52 |
| GHSA-C82X-F4XR-QV33 CVE-2026-47672 | epa4all-client: Unauthenticated REST API for Patient Record Writes | 中危 | Mavencom.oviva.telematik:epa4all-rest-service | 已审查 | 2026-06-05 01:49 | 2026-06-05 01:49 |
| GHSA-64CJ-QVX5-M4F3 CVE-2026-47671 | Nhost CLI local configserver allows cross-origin unauthenticated read/write access to local development configuration and secrets | 中危 | Gogithub.com/nhost/nhost | 已审查 | 2026-06-05 01:43 | 2026-06-05 01:43 |
| GHSA-74M6-4HJP-7226 | Klever-Go P2P MultiDataInterceptor leaks global throttler slots on malformed compressed batches (DoS) | 高危 | Gogithub.com/klever-io/klever-go | 已审查 | 2026-06-05 01:40 | 2026-06-05 01:40 |
| GHSA-WQCR-7RF3-F64M CVE-2026-47215 | Singluarity: Incorrect path matching for 'limit container paths' directive | 中危 | Gogithub.com/sylabs/singularity+1 | 已审查 | 2026-06-05 01:38 | 2026-06-05 01:38 |
| GHSA-4VQC-WPWG-VH7J CVE-2026-47192 | kas's late signature validation may allow unnoticed repository manipulations | 低危 | PyPIkas | 已审查 | 2026-06-05 01:36 | 2026-06-05 01:36 |
| GHSA-XFQJ-4CR9-9GR5 CVE-2026-10812 | GPTCache: File and image cache keys collide because BufferedReader.peek() only reads the buffered prefix | 低危 | PyPIgptcache | 已审查 | 2026-06-04 23:30 | 2026-07-16 02:55 |
| GHSA-RXV8-25V2-QMQ8 CVE-2026-34077 | React Router vulnerable to Denial of Service via reflected user input in single-fetch | 高危 | npmreact-router+1 | 已审查 | 2026-06-04 23:23 | 2026-06-04 23:23 |
| GHSA-M8XG-8XG9-MXHM CVE-2026-45730 | Nuclio: Missing authorization on project write paths allows any authenticated user to modify or delete any project | 高危 | Gogithub.com/nuclio/nuclio | 已审查 | 2026-06-04 23:05 | 2026-06-04 23:05 |
| GHSA-CQ3F-VC6P-68FH CVE-2026-45337 | Better Auth: Device authorization approve and deny accept any authenticated session while the user code is pending | 高危 | npmbetter-auth | 已审查 | 2026-06-04 22:55 | 2026-06-09 19:58 |
| GHSA-H97M-27FX-42RX CVE-2026-45057 | matrix-sdk-ui: Incomplete edit validation | 中危 | crates.iomatrix-sdk-ui | 已审查 | 2026-06-04 22:50 | 2026-06-04 22:50 |
| GHSA-WFQ4-36M3-9G42 CVE-2026-45056 | Matrix Rust SDK: Sender-binding gaps in to-device and room-key attribution | 中危 | crates.iomatrix-sdk-crypto | 已审查 | 2026-06-04 22:47 | 2026-06-04 22:47 |
| GHSA-FR49-MHGJ-CRFC CVE-2026-47707 | Strawberry GraphQL's Bypass of MaxAliasesLimiter via Fragment Spreads leading to GraphQL Alias Amplification | 中危 | PyPIstrawberry-graphql | 已审查 | 2026-06-04 22:39 | 2026-06-09 19:53 |
| GHSA-QFWV-87QJ-98XQ CVE-2026-47706 | Strawberry GraphQL has a Circular Fragment Reference DOS | 中危 | PyPIstrawberry-graphql | 已审查 | 2026-06-04 22:38 | 2026-06-09 19:53 |