检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-2CWR-F5HX-GG3W | Duplicate Advisory: OpenClaw: stageSandboxMedia destination symlink traversal can overwrite files outside sandbox workspace 已撤回 | 中危 | npmopenclaw | 已审查 | 2026-03-19 11:30 | 2026-03-20 00:26 |
当前筛选结果 998 条 · 时间按北京时间显示
Duplicate Advisory: Keycloak: Unauthorized access via improper validation of encrypted SAML assertions 已撤回 |
| 高危 |
Mavenorg.keycloak:keycloak-saml-adapter-core+2 |
| 已审查 |
| 2026-03-18 11:32 |
| 2026-07-03 04:42 |
| GHSA-XJJ9-2W6F-JG55 | Duplicate Advisory: OpenClaw safeBins file-existence oracle information disclosure 已撤回 | 中危 | npmopenclaw | 已审查 | 2026-03-12 20:30 | 2026-03-19 23:28 |
| GHSA-WGX8-R9VW-2W4H | Duplicate Advisory: OpenClaw: Skill env override host env injection via applySkillConfigEnvOverrides (defense-in-depth) 已撤回 | 中危 | npmopenclaw | 已审查 | 2026-03-12 20:30 | 2026-03-13 01:30 |
| GHSA-VH8F-65QG-3M8J | Duplicate Advisory: .NET Denial of Service Vulnerability 已撤回 | 高危 | NuGetMicrosoft.AspNetCore.App.Runtime.linux-arm | 已审查 | 2026-03-11 02:31 | 2026-03-12 03:53 |
| GHSA-C8GQ-RHQH-WGWM | Duplicate Advisory: .NET Denial of Service Vulnerability 已撤回 | 高危 | NuGetMicrosoft.Bcl.Memory | 已审查 | 2026-03-11 02:31 | 2026-03-12 03:54 |
| GHSA-387C-QMRW-59QV | Duplicate Advisory: Microsoft Security Advisory CVE-2026-26131 – .NET Elevation of Privilege Vulnerability 已撤回 | 高危 | NuGetMicrosoft.NetCore.App.Runtime.linux-arm+5 | 已审查 | 2026-03-11 02:31 | 2026-03-12 02:54 |
| GHSA-2RF6-9RC8-RQCH CVE-2025-15603 | Withdrawn Advisory: Open WebUI JWT Key Handler 已撤回 | 低危 | PyPIopen-webui | 已审查 | 2026-03-10 05:31 | 2026-09-03 04:49 |
| GHSA-6F6W-6J58-RQ76 CVE-2026-30916 | Withdrawn Advisory: Shescape has possible misidentification of shell due to link chains 已撤回 | 低危 | npmshescape | 已审查 | 2026-03-07 10:31 | 2026-03-21 03:53 |
| GHSA-F9V3-J2M7-4HPG | Duplicate Advisory: HTTP Request Smuggling via Premature Upgrade 已撤回 | 严重 | crates.iopingora-core | 已审查 | 2026-03-05 08:31 | 2026-03-06 04:54 |
| GHSA-2M8C-2374-465F | Duplicate Advisory: Cache poisoning via insecure-by-default cache key 已撤回 | 高危 | crates.iopingora-cache | 已审查 | 2026-03-05 08:31 | 2026-03-06 04:57 |
| GHSA-262P-VJX5-45XH | Duplicate Advisory: HTTP Request Smuggling via HTTP/1.0 and Transfer-Encoding Misparsing 已撤回 | 严重 | crates.iopingora-core | 已审查 | 2026-03-05 08:31 | 2026-03-06 04:55 |
| GHSA-FG6R-XGP8-X64R | Duplicate Advisory: Open Babel has a NULL pointer dereference in CDXML OBAtom::GetExplicitValence 已撤回 | 低危 | PyPIopenbabel | 已审查 | 2026-03-02 14:32 | 2026-07-01 02:47 |
| GHSA-7Q64-3RG2-H9PF | Duplicate Advisory: Nest has a Fastify URL Encoding Middleware Bypass 已撤回 | 高危 | npm@nestjs/platform-fastify | 已审查 | 2026-02-28 02:31 | 2026-03-02 22:34 |
| GHSA-4H76-926Q-WXXW | Duplicate Advisory: chi has an open redirect vulnerability in the RedirectSlashes middleware 已撤回 | 中危 | Gogithub.com/go-chi/chi/v5 | 已审查 | 2026-02-20 02:31 | 2026-06-18 21:01 |
| GHSA-3F56-W4G2-MX64 | Duplicate Advisory: Open Babel has NULL pointer dereference in MOL2 OBAtom::SetFormalCharge 已撤回 | 低危 | PyPIopenbabel | 已审查 | 2026-02-20 02:31 | 2026-07-01 02:46 |
| GHSA-2M54-8M6G-QF93 | Duplicate Advisory: Open Babel has an out-of-bounds read in CIF transform3d::DescribeAsString 已撤回 | 低危 | PyPIopenbabel | 已审查 | 2026-02-20 02:31 | 2026-07-01 02:46 |
| GHSA-WGM6-9RVV-3438 CVE-2026-26957 | Withdrawn Advisory: Libredesk has a SSRF Vulnerability in Webhooks 已撤回 | 中危 | Gogithub.com/abhinavxd/libredesk | 已审查 | 2026-02-18 08:56 | 2026-06-09 22:28 |
| GHSA-GFMX-QQQH-F38Q | Duplicate Advisory: Keras vulnerable to arbitrary file read in the model loading mechanism (HDF5 integration) 已撤回 | 高危 | PyPIkeras | 已审查 | 2026-02-12 08:31 | 2026-02-19 06:38 |
| GHSA-27JC-JMP8-QFW5 | Duplicate Advisory: Keylime Missing Authentication for Critical Function and Improper Authentication 已撤回 | 严重 | PyPIkeylime | 已审查 | 2026-02-07 05:30 | 2026-02-09 20:30 |
| GHSA-8X2R-V9X5-3QGH | Duplicate Advisory: Insecure Deserialization (pickle) in pdfminer.six CMap Loader — Local Privesc 已撤回 | 高危 | PyPIpdfminer.six | 已审查 | 2026-02-04 02:30 | 2026-02-05 00:49 |
| GHSA-2R8F-CF6W-X5VQ | Duplicate Advisory: FUXA contains a hard-coded credential vulnerability 已撤回 | 高危 | npmfuxa-server | 已审查 | 2026-02-04 02:30 | 2026-05-12 00:21 |
| GHSA-R2C6-8JC8-G32W | Duplicate Advisory: 1-Click RCE via Authentication Token Exfiltration From gatewayUrl 已撤回 | 高危 | npmclawdbot | 已审查 | 2026-02-02 08:30 | 2026-02-03 04:42 |
| GHSA-8RGQ-M2PM-JVMG | Duplicate Advisory: gix-date can create non-utf8 string with `TimeBuf::as_str` 已撤回 | 中危 | crates.iogix-date | 已审查 | 2026-01-27 05:30 | 2026-01-28 06:22 |
| GHSA-86RF-68F4-2CPH | Duplicate Advisory: go-viper's mapstructure May Leak Sensitive Information in Logs When Processing Malformed Data 已撤回 | 中危 | Gogithub.com/go-viper/mapstructure/v2 | 已审查 | 2026-01-27 05:30 | 2026-01-28 05:00 |