检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-G3HP-F6MG-559V CVE-2026-47122 | Sparkle's AppInstaller post-stage-1 XPC listener accepts unvalidated connections, allowing spoofed appcast item data injection | 中危 | SwiftURLgithub.com/sparkle-project/Sparkle | 已审查 | 2026-05-30 03:47 | 2026-05-30 03:47 |
| GHSA-HG88-V3CW-3QRH CVE-2026-47121 |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 中危 |
SwiftURLgithub.com/sparkle-project/Sparkle |
| 已审查 |
| 2026-05-30 03:45 |
| 2026-07-21 21:52 |
| GHSA-W5PP-99CH-QJ29 | go-git: Malformed Git object data may cause panics or resource exhaustion | 中危 | Gogithub.com/go-git/go-git/v5+1 | 已审查 | 2026-05-30 03:43 | 2026-05-30 03:43 |
| GHSA-HPV4-5H6F-WQR3 CVE-2026-46705 | russh server userauth state is not reset when authentication principal changes | 中危 | crates.iorussh | 已审查 | 2026-05-30 03:39 | 2026-06-11 22:06 |
| GHSA-WWX6-X28X-8259 CVE-2026-46702 | russh: Post-decompression SSH packet size was not bounded, allowing remote oversized compressed packets | 高危 | crates.iorussh | 已审查 | 2026-05-30 03:37 | 2026-06-11 22:06 |
| GHSA-29H4-R29X-HCHV CVE-2026-8838 | amazon-redshift-python-driver vulnerable to Remote Code Execution via eval() Injection | 严重 | PyPIredshift-connector | 已审查 | 2026-05-30 03:32 | 2026-06-03 05:41 |
| GHSA-4GG8-GXPX-9RPH | uv is vulnerable to arbitrary file write through entry point names | 中危 | crates.iouv | 已审查 | 2026-05-30 03:26 | 2026-05-30 03:26 |
| GHSA-WJJV-3MJ2-39HF CVE-2026-47255 | AgenticMail API/storage and outbound relay hardening fixes | 高危 | npm@agenticmail/api+1 | 已审查 | 2026-05-30 03:23 | 2026-05-30 03:23 |
| GHSA-8CPH-RGR4-G5VJ CVE-2026-47248 | Parse Server's GraphQL "Did you mean ...?" validation suggestions disclose schema to unauthenticated callers | 中危 | npmparse-server | 已审查 | 2026-05-30 03:18 | 2026-06-13 05:59 |
| GHSA-3PV8-6F4R-FFG2 | tar has a PAX header desynchronization issue | 中危 | crates.iotar | 已审查 | 2026-05-30 03:16 | 2026-05-30 03:16 |
| GHSA-3CV2-H65G-FGMM | astral-tokio-tar has a PAX Header Desynchronization issue | 中危 | crates.ioastral-tokio-tar | 已审查 | 2026-05-30 03:08 | 2026-05-30 03:08 |
| GHSA-XG9X-H37W-H3R3 CVE-2026-38739 | ezsystems/ezpublish-legacy has a SQL injection in dfscleanup | 高危 | Packagistezsystems/ezpublish-legacy | 已审查 | 2026-05-30 03:07 | 2026-05-30 03:07 |
| GHSA-6M57-8R3P-PQX6 CVE-2026-46690 | unbounded-spsc: Sender::send pointer-as-value transmute causes OOB read and fake-Arc drop under TX/RX race | 中危 | crates.iounbounded-spsc | 已审查 | 2026-05-30 03:05 | 2026-06-13 03:31 |
| GHSA-RF84-WR5G-M3RP | CAPM3 vulnerable to Cross-Namespace resource access | 中危 | Gogithub.com/metal3-io/cluster-api-provider-metal3 | 已审查 | 2026-05-30 03:01 | 2026-05-30 03:01 |
| GHSA-5J8P-5RRJ-8WJG CVE-2026-10108 | xiaomusic contains an unauthenticated path traversal vulnerability | 高危 | PyPIxiaomusic | 已审查 | 2026-05-30 02:31 | 2026-07-03 04:53 |
| GHSA-82M5-3PCP-HCCQ CVE-2026-10105 | agno contains a SQL injection vulnerability | 高危 | PyPIagno | 已审查 | 2026-05-30 02:31 | 2026-07-03 04:52 |
| GHSA-HX4V-668P-G2QR | Duplicate Advisory: OpenClaw: QQBot native approval buttons did not enforce configured approver identity 已撤回 | 高危 | npmopenclaw | 已审查 | 2026-05-30 02:31 | 2026-07-03 04:50 |
| GHSA-49PM-43HF-6XFQ CVE-2026-47190 | IPAM controller service account granted unnecessary full access to Secrets | 中危 | Gogithub.com/metal3-io/ip-address-manager | 已审查 | 2026-05-30 02:24 | 2026-06-13 03:31 |
| GHSA-HFC8-W5F4-3X6M | Ironic Standalone Operator's controller modifies user-owned resources without consent | 中危 | Gogithub.com/metal3-io/ironic-standalone-operator | 已审查 | 2026-05-30 02:23 | 2026-05-30 02:23 |
| GHSA-7CWM-FPFH-RRCH | Ironic Standalone Operator's prometheus metrics exporter bound to all interfaces | 中危 | Gogithub.com/metal3-io/ironic-standalone-operator | 已审查 | 2026-05-30 02:22 | 2026-05-30 02:22 |
| GHSA-9G8X-92Q2-P28F CVE-2026-47141 | NodeVM observability builtins leak host process and HTTP request data | 中危 | npmvm2 | 已审查 | 2026-05-30 02:20 | 2026-06-13 03:30 |
| GHSA-R9PM-GXMW-WV6P CVE-2026-47139 | NodeVM network builtin exclusions bypass via internal _http_client and _http_server | 高危 | npmvm2 | 已审查 | 2026-05-30 02:08 | 2026-06-13 03:30 |
| GHSA-RP36-8XQ3-R6C4 CVE-2026-47140 | NodeVM builtin denylist bypass via process and inspector/promises allows host code execution | 严重 | npmvm2 | 已审查 | 2026-05-30 01:59 | 2026-06-13 04:56 |
| GHSA-H64W-W9PR-82M4 CVE-2026-8813 | ExifReader is vulnerable to denial of service via crafted ICC `mluc` tag | 高危 | npmexifreader | 已审查 | 2026-05-30 01:58 | 2026-07-18 00:51 |
| GHSA-RR89-W3H9-M66J CVE-2026-8814 | ExifReader is vulnerable to denial of service via unbounded decompression of image metadata | 中危 | npmexifreader | 已审查 | 2026-05-30 01:52 | 2026-07-18 00:52 |