检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-M6VC-F87M-CC2H CVE-2026-44476 | Doorkeeper Openid Connect: Dynamic Client Registration feature creates public clients with client_secret | 中危 | RubyGemsdoorkeeper-openid_connect | 已审查 | 2026-06-04 22:37 | 2026-06-09 19:57 |
| GHSA-FH3H-VG37-CC95 CVE-2026-44889 | WebOb: Location header normalization during redirect leads to open redirect - again |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 中危 |
PyPIwebob |
| 已审查 |
| 2026-06-04 22:33 |
| 2026-07-19 01:27 |
| GHSA-HFXV-24RG-XRQF CVE-2026-44496 | Axios: Regular Expression Denial of Service (ReDoS) via Cookie Name Injection | 高危 | npmaxios | 已审查 | 2026-06-04 22:24 | 2026-06-04 22:24 |
| GHSA-777C-7FJR-54VF CVE-2026-44488 | Allocation of Resources Without Limits or Throttling in Axios | 高危 | npmaxios | 已审查 | 2026-06-04 22:21 | 2026-06-13 03:24 |
| GHSA-P92Q-9VQR-4J8V CVE-2026-44487 | Axios: Proxy-Authorization Credential Leak to Origin Server Across HTTP-to-HTTPS Redirect in Axios Node.js HTTP Adapter | 高危 | npmaxios | 已审查 | 2026-06-04 22:19 | 2026-06-13 03:24 |
| GHSA-J5F8-GRM9-P9FC CVE-2026-44486 | Axios: Proxy-Authorization header leaks to redirect target when proxy is re-evaluated to direct connection | 高危 | npmaxios | 已审查 | 2026-06-04 22:15 | 2026-06-13 03:24 |
| GHSA-86QP-5C8J-P5MR CVE-2026-48710 | Starlette has missing Host header validation that poisons request.url.path, bypassing path-based security checks | 中危 | PyPIstarlette | 已审查 | 2026-06-04 21:15 | 2026-08-29 02:30 |
| GHSA-VQWP-45WM-R9R5 CVE-2026-10804 | Streamlit @st.cache_data hash collision via fixed sampling seed and PIL P-mode palette omission | 低危 | PyPIstreamlit | 已审查 | 2026-06-04 20:30 | 2026-07-16 05:49 |
| GHSA-5QMP-P3C4-72QJ CVE-2026-10803 | MLflow: Deterministic sampling in dataset digest enables predictable collisions | 低危 | PyPImlflow | 已审查 | 2026-06-04 20:30 | 2026-07-16 01:51 |
| GHSA-45JQ-C8XM-JFW9 CVE-2026-10802 | Keystone: GraphQL API Endpoint Lacks Query Depth Limits | 低危 | npm@keystone-6/core | 已审查 | 2026-06-04 20:30 | 2026-07-15 04:53 |
| GHSA-PRFW-69R3-WQXF CVE-2026-10801 | ms-swift: Image Cache Hash Collision via Missing Dimension Metadata | 低危 | PyPIms-swift | 已审查 | 2026-06-04 20:30 | 2026-07-15 04:47 |
| GHSA-9V62-QX4C-44X5 CVE-2026-48681 | OpenStack Ironic allows file overwrite via directory traversal during deployment with a crafted ISO image | 中危 | PyPIironic | 已审查 | 2026-06-04 14:30 | 2026-07-15 03:50 |
| GHSA-9HFW-W3F4-C4P8 CVE-2026-41283 | OpenStack Mistral allows Arbitrary Remote Code Execution when the API is exposed | 严重 | PyPImistral | 已审查 | 2026-06-04 14:30 | 2026-07-15 03:45 |
| GHSA-JRH2-F5JC-XPGR CVE-2026-46447 | OpenStack Ironic allows Boot Script Injection | 中危 | PyPIironic | 已审查 | 2026-06-04 08:30 | 2026-07-15 03:35 |
| GHSA-JRCC-J37M-V8FG CVE-2026-10775 | SGLang is Vulnerable to DoS via the data_hash Function | 低危 | PyPIsglang | 已审查 | 2026-06-04 08:30 | 2026-08-18 05:52 |
| GHSA-6655-8PH2-63J3 CVE-2026-10783 | Gradio: Audio cache key ignores metadata when saving numpy audio outputs | 低危 | PyPIgradio | 已审查 | 2026-06-04 08:30 | 2026-07-15 03:38 |
| GHSA-F9RX-7WF7-JR36 CVE-2026-52793 | Froxlor's API Authentication bypasses 2FA Authentication | 高危 | Packagistfroxlor/froxlor | 已审查 | 2026-06-04 05:41 | 2026-06-09 21:07 |
| GHSA-6VR3-7WCX-V5G5 CVE-2026-49143 | browserstack-runner vulnerable to Remote Code Execution via vm sandbox escape in _log HTTP handler | 高危 | npmbrowserstack-runner | 已审查 | 2026-06-04 05:39 | 2026-06-04 05:39 |
| GHSA-8RPW-6CQH-2V9H CVE-2026-49144 | browserstack-runner has an unauthenticated arbitrary file read via path traversal in HTTP server | 高危 | npmbrowserstack-runner | 已审查 | 2026-06-04 05:38 | 2026-06-04 05:38 |
| GHSA-CFW7-6C5V-2WJQ CVE-2026-44182 | Jupyter Enterprise Gateway: Kubernetes Manifest Injection in Jinja2 Template Rendering | 严重 | PyPIjupyter_enterprise_gateway | 已审查 | 2026-06-04 05:37 | 2026-06-04 05:37 |
| GHSA-F49J-V924-FX9W CVE-2026-44181 | Jupyter Enterprise Gateway: Jinja2 Template Server Side Template Injection resulting in Remote Code Execution | 严重 | PyPIjupyter_enterprise_gateway | 已审查 | 2026-06-04 05:36 | 2026-06-04 05:36 |
| GHSA-HG6J-4RV6-33PG CVE-2026-47265 | AIOHTTP is vulnerable to cross-origin redirect with per-request cookies | 中危 | PyPIaiohttp | 已审查 | 2026-06-04 05:34 | 2026-06-04 05:34 |
| GHSA-PHX2-3W66-H4PW CVE-2026-10766 | mlrun: DataFrame hash collisions can cause dataset artifact path conflicts and silent data corruption | 低危 | PyPImlrun | 已审查 | 2026-06-04 05:30 | 2026-07-15 02:49 |
| GHSA-52PR-7VMF-2W7X CVE-2026-7888 | Concrete CMS is vulnerable to PHP Object Injection via unserialize() calls in the Workflow, Form block, and File/Set components | 高危 | Packagistconcrete5/concrete5 | 已审查 | 2026-06-04 05:30 | 2026-07-15 02:27 |
| GHSA-CHQ7-94J8-CJ28 CVE-2026-44180 | Jupyter Enterprise Gateway: ContainerProcessProxy._enforce_prohibited_ids Bypass | 严重 | PyPIjupyter_enterprise_gateway | 已审查 | 2026-06-04 05:30 | 2026-06-04 05:30 |