检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-923M-GV2P-W5QP CVE-2026-48587 | Django: has_vary_header may expose cached responses when Vary values contain whitespace | 低危 | PyPIdjango | 已审查 | 2026-06-03 23:30 | 2026-08-08 03:56 |
| GHSA-8CJM-8MP7-R2XF CVE-2026-8404 | Django: UpdateCacheMiddleware may disclose cached responses due to case-sensitive Cache-Control handling |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 低危 |
PyPIdjango |
| 已审查 |
| 2026-06-03 23:30 |
| 2026-08-08 04:03 |
| GHSA-RRC9-MX66-FFCM CVE-2026-44545 | daphne: Unauthenticated attackers can cause excessive memory consumption by sending arbitrarily large WebSocket messages/frames | 中危 | PyPIdaphne | 已审查 | 2026-06-03 23:30 | 2026-07-12 06:53 |
| GHSA-QPC8-7FXC-CM4P CVE-2026-35193 | Django: UpdateCacheMiddleware may disclose private cached responses by omitting Authorization from Vary | 低危 | PyPIdjango | 已审查 | 2026-06-03 23:30 | 2026-08-08 03:55 |
| GHSA-XHGW-QWWF-PG32 CVE-2026-10722 | ebpf-go is vulnerable to integer overflow via LoadCollectionSpecFromReader | 低危 | Gogithub.com/cilium/ebpf | 已审查 | 2026-06-03 23:30 | 2026-08-17 21:36 |
| GHSA-V3PR-HXPR-MFM8 CVE-2026-47065 | Apache MINA: Critical Deserialization Allow-list Bypass via resolveProxyClass | 严重 | Mavenorg.apache.mina:mina-core | 已审查 | 2026-06-03 20:30 | 2026-07-14 01:24 |
| GHSA-G35P-PX32-WHV6 CVE-2026-4035 | MLflow: Environment variable injection in AI Gateway secrets enables server-side credential exfiltration | 严重 | PyPImlflow | 已审查 | 2026-06-03 17:30 | 2026-07-11 03:31 |
| GHSA-R87G-78MX-3WG4 CVE-2026-10691 | DesktopCommanderMCP is vulnerable to Uncontrolled Resource Consumption | 低危 | npm@wonderwhy-er/desktop-commander | 已审查 | 2026-06-03 08:30 | 2026-07-11 01:15 |
| GHSA-647R-72HF-4VMH CVE-2026-10692 | Code Index MCP is vulnerable to Uncontrolled Resource Consumption | 低危 | PyPIcode-index-mcp | 已审查 | 2026-06-03 08:30 | 2026-07-11 01:16 |
| GHSA-5XX3-J724-WMX5 CVE-2026-10690 | DesktopCommanderMCP is vulnerable to SSRF | 低危 | npm@wonderwhy-er/desktop-commander | 已审查 | 2026-06-03 08:30 | 2026-07-11 01:15 |
| GHSA-M3V4-V5GX-7WF5 CVE-2026-47117 | OpenMed vulnerable to remote code injection through privacy-filter model loading path | 严重 | PyPIopenmed | 已审查 | 2026-06-03 02:31 | 2026-07-01 05:42 |
| GHSA-GF7Q-Q4J7-HP7C CVE-2026-5422 | Duplicate Advisory: Jupyter Server vulnerable to Path Traversal via incorrect root directory boundary check in _get_os_path() 已撤回 | 中危 | PyPIjupyter-server | 已审查 | 2026-06-02 20:31 | 2026-08-01 04:20 |
| GHSA-C2RV-HWQM-WJPG CVE-2026-46718 | Apache Calcite is Vulnerable to Use of Externally-Controlled Input to Select Classes | 中危 | Mavenorg.apache.calcite:calcite-core | 已审查 | 2026-06-02 20:31 | 2026-07-10 05:19 |
| GHSA-C635-393C-HCX2 CVE-2026-3514 | Prefect has an Authentication Middleware Bypass when URL paths are appended with 'health' or 'ready' | 高危 | PyPIprefect | 已审查 | 2026-06-02 17:36 | 2026-07-10 04:53 |
| GHSA-R5M9-WM49-959F CVE-2026-3198 | MLflow: Any authenticated user can enumerate all gateway secrets, endpoints, and model definitions | 中危 | PyPImlflow | 已审查 | 2026-06-02 14:30 | 2026-07-10 04:52 |
| GHSA-3C3G-7HWG-9QMR CVE-2026-10566 | FoundationAgents MetaGPT: Deserialization through flawed argument mapping via Message.check_instruct_content() | 低危 | PyPImetagpt | 已审查 | 2026-06-02 11:31 | 2026-07-09 21:44 |
| GHSA-M2JR-X4GQ-5RMJ CVE-2026-10300 | SGLang: Reachable Assertion via lora_path in LoRAManager enables remote Denial of Dervice | 低危 | PyPIsglang | 已审查 | 2026-06-02 08:31 | 2026-07-09 21:43 |
| GHSA-95F6-RFPG-C3W8 CVE-2026-10291 | Claw Orchestrator has inefficient regular expression complexity via validateRegex() | 中危 | npm@enderfga/claw-orchestrator | 已审查 | 2026-06-02 08:31 | 2026-07-09 21:43 |
| GHSA-434R-7C99-HWF3 CVE-2026-49138 | Nanobot contains a server-side request forgery vulnerability in the web_fetch tool | 中危 | PyPInanobot-ai | 已审查 | 2026-06-02 05:30 | 2026-07-28 00:02 |
| GHSA-X9C7-5H6G-HQ8Q CVE-2026-40989 | Spring Cloud Function Context has Uncontrolled Recursion | 中危 | Mavenorg.springframework.cloud:spring-cloud-function-context | 已审查 | 2026-06-02 05:30 | 2026-07-09 21:38 |
| GHSA-X4H3-G2X4-8GQV CVE-2026-40990 | Spring Cloud Function Context: Uncontrolled Recursion is possible while attempting to add infinite amount of functions to Function Registry | 中危 | Mavenorg.springframework.cloud:spring-cloud-function-context | 已审查 | 2026-06-02 05:30 | 2026-07-09 21:38 |
| GHSA-Q6QC-XP4Q-RJQ5 CVE-2026-10281 | Claw Orchestrator is missing authentication for the component API Endpoint | 中危 | npm@enderfga/claw-orchestrator | 已审查 | 2026-06-02 05:30 | 2026-07-09 21:38 |
| GHSA-WF93-45JW-7689 CVE-2026-8643 | pip: Path traversal in console_scripts/gui_scripts entry point names allows installing scripts outside of target directory | 中危 | PyPIpip | 已审查 | 2026-06-02 02:31 | 2026-07-10 20:31 |
| GHSA-JHQ6-GFMJ-V8FX CVE-2026-10532 | Logback vulnerable to Object Injection through HardenedObjectInputStream modules | 低危 | Mavench.qos.logback:logback-core | 已审查 | 2026-06-01 23:30 | 2026-07-16 05:52 |
| GHSA-QJWP-HRQ6-R26R CVE-2026-47191 | kas checks out SHA-like git branches as valid commits | 低危 | PyPIkas | 已审查 | 2026-06-01 22:26 | 2026-06-01 22:26 |