检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-QHR7-H655-PW6R CVE-2026-44825 | Apache Solr has hardcoded credentials in the Basic Authentication setup tool | 高危 | Mavenorg.apache.solr:solr-core | 已审查 | 2026-06-01 17:31 | 2026-07-10 04:59 |
| GHSA-MXQ5-F9C5-W4P5 CVE-2026-41084 | Apache Airflow Vulnerable to Authorization Bypass Through User-Controlled Key |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 高危 |
PyPIapache-airflow |
| 已审查 |
| 2026-06-01 17:31 |
| 2026-07-10 04:51 |
| GHSA-HG6C-8MVR-JQC9 CVE-2026-42588 | Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ have a Code Injection issue | 高危 | Mavenorg.apache.activemq:activemq-all+2 | 已审查 | 2026-06-01 17:31 | 2026-07-10 04:56 |
| GHSA-CG3X-89RC-X9MW CVE-2026-42360 | Apache Airflow vulnerable to Exposure of Sensitive Information to an Unauthorized Actor | 中危 | PyPIapache-airflow | 已审查 | 2026-06-01 17:31 | 2026-07-10 05:02 |
| GHSA-C85C-G9WV-PPH2 CVE-2026-42252 | Apache Airflow vulnerable to Improper Neutralization of Special Elements Used in a Template Engine | 严重 | PyPIapache-airflow | 已审查 | 2026-06-01 17:31 | 2026-07-10 04:52 |
| GHSA-8WM6-6FQH-PHMC CVE-2026-42253 | Apache ActiveMQ, Apache ActiveMQ Web have a Cross-site Scripting issue | 中危 | Mavenorg.apache.activemq:activemq-web+1 | 已审查 | 2026-06-01 17:31 | 2026-07-10 04:51 |
| GHSA-33G2-GX67-C2H3 CVE-2026-42358 | Apache Airflow Vulnerable to Exposure of Sensitive Information to an Unauthorized Actor | 中危 | PyPIapache-airflow | 已审查 | 2026-06-01 17:31 | 2026-07-10 04:55 |
| GHSA-2R5M-76WX-56GX CVE-2026-45360 | Apache Airflow Vulnerable to Deserialization of Untrusted Data | 高危 | PyPIapache-airflow | 已审查 | 2026-06-01 17:31 | 2026-09-02 05:04 |
| GHSA-X2X7-P37C-43CR CVE-2026-41014 | Apache Airflow has a Missing Authorization issue | 中危 | PyPIapache-airflow | 已审查 | 2026-06-01 17:31 | 2026-07-10 04:53 |
| GHSA-GPRJ-XVQ8-W53Q CVE-2026-40963 | Apache Airflow has an Improper Authorization issue | 低危 | PyPIapache-airflow | 已审查 | 2026-06-01 17:31 | 2026-07-10 04:50 |
| GHSA-95V7-H9J5-GVJR CVE-2026-41017 | Apache Airflow has a Sensitive Cookie in HTTPS Session Without 'Secure' Attribute | 中危 | PyPIapache-airflow | 已审查 | 2026-06-01 17:31 | 2026-07-10 04:53 |
| GHSA-89CJ-XRPX-J79M CVE-2026-40861 | Apache Airflow has a Link Following issue | 中危 | PyPIapache-airflow | 已审查 | 2026-06-01 17:31 | 2026-07-10 04:53 |
| GHSA-6HCW-QQR8-PJJ8 CVE-2026-40961 | Apache Airflow: Authenticated users can bypass the `is_safe_url` check | 高危 | PyPIapache-airflow | 已审查 | 2026-06-01 17:31 | 2026-07-08 07:47 |
| GHSA-698X-9W2P-7VVP CVE-2026-10517 | Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints | 中危 | Gogithub.com/quay/claircore | 已审查 | 2026-06-01 17:31 | 2026-07-08 07:47 |
| GHSA-2883-WWH7-X57V CVE-2026-45192 | Apache Airflow: Incomplete redaction allowlist exposes secrets in Connection `extra` to read-permitted users | 中危 | PyPIapache-airflow | 已审查 | 2026-06-01 17:31 | 2026-07-08 07:47 |
| GHSA-85RW-G4F4-JPRR CVE-2026-35563 | Apache Directory LDAP API lacks server certificate verification for LDAP hostnames | 高危 | Mavenorg.apache.directory.api:api-ldap-client-api | 已审查 | 2026-06-01 17:31 | 2026-07-08 07:46 |
| GHSA-PMQC-57G8-C22C CVE-2026-10224 | hermes-agent has an Uncontrolled Resource Consumption issue | 中危 | PyPIhermes-agent | 已审查 | 2026-06-01 14:30 | 2026-07-29 03:46 |
| GHSA-33QV-C5QM-799V CVE-2026-10223 | hermes-agent has an Injection issue | 低危 | PyPIhermes-agent | 已审查 | 2026-06-01 14:30 | 2026-07-29 03:57 |
| GHSA-XQ8W-9JVX-GM3V CVE-2026-10221 | hermes-agent has an Injection issue | 中危 | PyPIhermes-agent | 已审查 | 2026-06-01 14:30 | 2026-07-29 01:27 |
| GHSA-MV8X-FG99-32MF CVE-2026-10222 | hermes-agent has an Injection issue | 低危 | PyPIhermes-agent | 已审查 | 2026-06-01 14:30 | 2026-07-29 03:10 |
| GHSA-6JM8-4FHR-5W64 CVE-2026-10219 | GoClaw has a Command Injection issue | 中危 | Gogithub.com/nextlevelbuilder/goclaw | 已审查 | 2026-06-01 14:30 | 2026-07-10 04:49 |
| GHSA-R6VM-4XWG-W69H CVE-2026-10212 | AstrBot: Manipulation of astr_main_agent's session_id parameter leads to authorization bypass | 低危 | PyPIAstrBot | 已审查 | 2026-06-01 11:30 | 2026-07-08 07:47 |
| GHSA-7FG5-VC77-69FP CVE-2026-10215 | Dolibarr ERP CRM is vulnerable to Improper Authorization through its Leave Request REST API | 低危 | Packagistdolibarr/dolibarr | 已审查 | 2026-06-01 11:30 | 2026-07-08 07:43 |
| GHSA-HCHG-QM84-CJ9P CVE-2026-10177 | Aider has an SSRF vulnerability through its AWS EC2 Metadata Endpoint | 低危 | PyPIaider-chat | 已审查 | 2026-05-31 20:30 | 2026-07-08 03:39 |
| GHSA-7W7M-V5VP-W699 CVE-2026-10175 | Aider is vulnerable to Code Injection via editor_coder.run function | 低危 | PyPIaider-chat | 已审查 | 2026-05-31 17:31 | 2026-07-08 03:36 |