检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-JMMV-H3MP-59V8 CVE-2026-44023 | Docling Core: Unsafe remote filename resolution | 高危 | PyPIdocling-core | 已审查 | 2026-06-04 05:16 | 2026-06-04 05:16 |
| GHSA-J5XP-7M2F-49JV CVE-2026-44019 | Docling Core: Insufficient validation of image reference URIs |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 高危 |
PyPIdocling-core |
| 已审查 |
| 2026-06-04 05:15 |
| 2026-06-04 05:15 |
| GHSA-Q29V-XC37-WH5M CVE-2026-47214 | Docling: Unsafe URI and Path Handling in HTML Backend | 高危 | PyPIdocling | 已审查 | 2026-06-04 05:15 | 2026-07-21 23:04 |
| GHSA-2J5P-7P5M-CVQR CVE-2026-44022 | Docling: Potential Path Traversal via LaTeX \includegraphics and \input Commands | 中危 | PyPIdocling | 已审查 | 2026-06-04 05:14 | 2026-07-21 05:33 |
| GHSA-M88R-RG27-5XFG CVE-2026-44020 | Docling: Unsafe XML Entity Expansion in USPTO Patent Backend | 高危 | PyPIdocling | 已审查 | 2026-06-04 05:14 | 2026-08-29 02:31 |
| GHSA-R3XG-RG9J-67FV CVE-2026-44018 | Docling: Unsafe Archive Extraction and XML Parsing in METS-GBS Backend | 中危 | PyPIdocling | 已审查 | 2026-06-04 05:13 | 2026-07-21 23:04 |
| GHSA-PJ2V-GGQH-CMQ2 CVE-2026-44016 | Docling: Unsafe Playwright-based HTML Rendering | 高危 | PyPIdocling | 已审查 | 2026-06-04 05:09 | 2026-07-21 05:33 |
| GHSA-CH57-39Q2-4CRM CVE-2026-43980 | malla: Stored XSS via Meshtastic node names in multiple frontend pages | 中危 | PyPImalla | 已审查 | 2026-06-04 05:06 | 2026-06-04 05:06 |
| GHSA-8X6R-G9MW-2R78 CVE-2026-42342 | React Router vulnerable to DoS via unbounded path expansion in __manifest endpoint | 高危 | npm@remix-run/server-runtime+1 | 已审查 | 2026-06-04 05:05 | 2026-06-04 05:05 |
| GHSA-49RJ-9FVP-4H2H CVE-2026-42211 | React Router's vendored turbo-stream v2 allows arbitrary constructor invocation via TYPE_ERROR deserialization leading to Unauth RCE | 高危 | npmreact-router | 已审查 | 2026-06-04 05:03 | 2026-06-04 05:03 |
| GHSA-37M5-M4Q3-FC6X CVE-2026-41234 | Froxlor: BIND Zone File Injection via TXT Record Content | 高危 | Packagistfroxlor/froxlor | 已审查 | 2026-06-04 05:02 | 2026-06-09 19:54 |
| GHSA-VVGJ-X9JQ-8CJ9 CVE-2026-40898 | quic-go: HTTP/3 QPACK Trailer Expansion Memory Exhaustion | 中危 | Gogithub.com/quic-go/quic-go | 已审查 | 2026-06-04 04:59 | 2026-06-09 19:54 |
| GHSA-2J2X-HQR9-3H42 CVE-2026-40181 | React Router's same-origin redirect with path starting // causes open redirect via protocol-relative URL reinterpretation | 中危 | npm@remix-run/router+1 | 已审查 | 2026-06-04 04:58 | 2026-08-05 05:26 |
| GHSA-JG22-MG44-37J8 CVE-2026-34993 | AIOHTTP is Vulnerable to Deserialization of Untrusted Data | 中危 | PyPIaiohttp | 已审查 | 2026-06-04 04:56 | 2026-06-04 04:56 |
| GHSA-8646-J5J9-6R62 CVE-2026-33245 | React Router vulnerable to XSS in unstable RSC redirect handling via javascript: redirect targets | 高危 | npmreact-router | 已审查 | 2026-06-04 04:33 | 2026-06-04 04:33 |
| GHSA-F22V-GFQF-P8F3 CVE-2026-33244 | React Router has stored XSS via unescaped Location header in prerendered redirect HTML | 中危 | npmreact-router | 已审查 | 2026-06-04 04:33 | 2026-06-04 04:33 |
| GHSA-M8XX-3X29-84H8 CVE-2022-31114 | backpack/crud is vulnerable to Cross-Site Scripting (XSS) | 中危 | Packagistbackpack/crud | 已审查 | 2026-06-04 04:25 | 2026-06-04 04:31 |
| GHSA-CJQG-RQ2H-2FVJ CVE-2026-44017 | Docling: Unsafe Zip Extraction in EasyOCR Model Download | 高危 | PyPIdocling | 已审查 | 2026-06-04 04:02 | 2026-08-29 02:31 |
| GHSA-V42X-X7JP-845H CVE-2026-6657 | Duplicate Advisory: jupyter-server is vulnerable to CORS origin validation bypass when the `allow_origin_pat` configuration is used 已撤回 | 中危 | PyPIjupyter-server | 已审查 | 2026-06-04 02:33 | 2026-08-01 04:25 |
| GHSA-PW7P-7FQV-HPJ8 CVE-2026-37462 | GoBGP: Integer underflow in the BGPUpdate.DecodeFromBytes function | 高危 | Gogithub.com/osrg/gobgp/v4 | 已审查 | 2026-06-04 02:33 | 2026-07-14 01:27 |
| GHSA-C27G-Q93R-2CWF CVE-2024-52011 | launch-editor vulnerable to command injection via the crafted request on Windows | 高危 | npmlaunch-editor+1 | 已审查 | 2026-06-04 02:02 | 2026-06-04 02:02 |
| GHSA-XH68-HFP5-5X5M CVE-2026-44546 | daphne: WebSocket handshake header smuggling through autobahn splitlines() mishandling of non-standard line separators | 低危 | PyPIdaphne | 已审查 | 2026-06-03 23:30 | 2026-07-12 06:53 |
| GHSA-MM6V-Q8Q9-PGCF CVE-2026-7666 | Django fails to prevent reuse of a partially-initialized connection after a failed `STARTTLS` handshake | 低危 | PyPIdjango | 已审查 | 2026-06-03 23:30 | 2026-07-14 01:26 |
| GHSA-H7PC-VWP9-298G CVE-2026-6873 | Django: signed cookies are vulnerable to salt namespace collisions | 低危 | PyPIdjango | 已审查 | 2026-06-03 23:30 | 2026-08-08 04:04 |
| GHSA-FGCW-684Q-JJ6R CVE-2026-5241 | huggingface/transformers: Arbitrary Code Execution During Model Initialization in the LightGlue Model Loading Path | 高危 | PyPItransformers | 已审查 | 2026-06-03 23:30 | 2026-07-21 20:33 |