检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-897W-FCG9-F6XJ CVE-2026-42305 | Dulwich has an arbitrary file write via NTFS-hostile tree entries on Windows | 高危 | PyPIdulwich | 已审查 | 2026-05-29 06:28 | 2026-06-11 22:05 |
| GHSA-WHQR-FGM5-X77Q CVE-2026-44394 | OpenStack Keystone's federated token rescoping mechanism doesn't propagate the original token's expiry to the newly issued token |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 中危 |
PyPIkeystone |
| 已审查 |
| 2026-05-29 05:32 |
| 2026-07-03 01:44 |
| GHSA-Q623-F4J4-P4XJ CVE-2026-43000 | OpenStack Keystone has an Incorrect Authorization issue | 中危 | PyPIkeystone | 已审查 | 2026-05-29 05:32 | 2026-07-03 01:44 |
| GHSA-8F8M-WRVR-WCVF CVE-2026-42998 | OpenStack Keystone doesn't verify that the user supplied in the authentication request matches the owner of the application credential | 中危 | PyPIkeystone | 已审查 | 2026-05-29 05:32 | 2026-07-03 01:43 |
| GHSA-2R23-2G6V-2M5F CVE-2026-42999 | OpenStack Keystone has an Authorization Bypass | 中危 | PyPIkeystone | 已审查 | 2026-05-29 05:32 | 2026-07-03 01:44 |
| GHSA-R2F4-FF2P-XC64 CVE-2026-5394 | Pimcore Platform - SQL Injection in DataObject composite index handling during class definition import/save | 高危 | Packagistpimcore/pimcore | 已审查 | 2026-05-29 04:47 | 2026-07-11 03:08 |
| GHSA-R9G5-7Q8J-958C CVE-2026-47718 | FUXA provides guest and invalid-token access to protected read APIs in secure mode | 中危 | npmfuxa-server | 已审查 | 2026-05-29 04:33 | 2026-05-29 04:33 |
| GHSA-X6P3-76F2-XXVH CVE-2026-47144 | Shamefile has an arbitrary file read via shamefile.yaml in shame next | 中危 | crates.ioshamefile | 已审查 | 2026-05-29 04:02 | 2026-07-21 05:48 |
| GHSA-27VP-2MMC-VMH3 CVE-2026-47128 | nono: Sandbox escape on Linux via D-Bus: `systemd-run --user` | 中危 | crates.ionono-cli | 已审查 | 2026-05-29 03:55 | 2026-05-29 03:55 |
| GHSA-2XF4-CG6J-VHGQ CVE-2026-46644 | symfony/polyfill-intl-idn: xn-- labels with ASCII-only Punycode payloads are treated as equivalent to their decoded form | 低危 | Packagistsymfony/polyfill+1 | 已审查 | 2026-05-29 03:52 | 2026-05-29 03:52 |
| GHSA-G23J-2VWM-5C25 CVE-2026-46526 | local-deep-research has an SSRF bypass in `safe_get` | 中危 | PyPIlocal-deep-research | 已审查 | 2026-05-29 03:18 | 2026-06-09 18:23 |
| GHSA-GG2G-P7XC-QQMM CVE-2026-46439 | compliance-trestle Vulnerable to Remote Code Execution via Recursive Server-Side Template Injection (SSTI) | 高危 | PyPIcompliance-trestle | 已审查 | 2026-05-29 03:01 | 2026-05-29 03:01 |
| GHSA-7J6W-VVW2-5F9C CVE-2026-46405 | OpenBao's Kerberos Auth Method Accumulates Unaccessible Tokens | 中危 | Gogithub.com/openbao/openbao | 已审查 | 2026-05-29 02:55 | 2026-05-29 02:55 |
| GHSA-RGQ2-93GJ-FFXG CVE-2026-9096 | Casdoor doesn't enforce SAML assertion time bounds | 高危 | Gogithub.com/casdoor/casdoor | 已审查 | 2026-05-29 02:30 | 2026-07-03 02:37 |
| GHSA-MFVP-7P3V-X9MH CVE-2026-9098 | Casdoor SAML callback handler accepts any well-formed SAMLResponse sent to /api/acs without verifying that it corresponds to an AuthnRequest | 严重 | Gogithub.com/casdoor/casdoor | 已审查 | 2026-05-29 02:30 | 2026-07-03 02:37 |
| GHSA-GV4M-V8C8-HR3G CVE-2026-9091 | Casdoor allows users to bypass configured MFA requirements | 中危 | Gogithub.com/casdoor/casdoor | 已审查 | 2026-05-29 02:30 | 2026-07-03 02:36 |
| GHSA-FWGQ-J9R9-QJGR CVE-2026-9090 | Casdoor has an authentication bypass | 严重 | Gogithub.com/casdoor/casdoor | 已审查 | 2026-05-29 02:30 | 2026-07-03 02:36 |
| GHSA-C9W5-QP6M-M395 CVE-2026-9094 | Casdoor: GetTokenExchangeToken bypass through lack of cross-organization JWT signature check | 严重 | Gogithub.com/casdoor/casdoor | 已审查 | 2026-05-29 02:30 | 2026-07-10 07:32 |
| GHSA-9P7W-W5Q6-MXJ3 CVE-2026-41184 | Calico Inserts Sensitive Information into Log File | 中危 | Gogithub.com/projectcalico/calico | 已审查 | 2026-05-29 02:30 | 2026-07-03 02:01 |
| GHSA-3W4H-G9F5-J84P CVE-2026-9093 | Casdoor does not validate the AudienceRestriction element in SAML assertions | 严重 | Gogithub.com/casdoor/casdoor | 已审查 | 2026-05-29 02:30 | 2026-07-03 02:37 |
| GHSA-3M4Q-GGCJ-J6M4 CVE-2026-6720 | Calico Inserts Sensitive Information into Log File | 高危 | Gogithub.com/projectcalico/calicoctl/v3 | 已审查 | 2026-05-29 02:30 | 2026-07-03 02:07 |
| GHSA-339W-3HQM-9PJC CVE-2026-9097 | Casdoor doesn't verify that a JWT used for token exchange is still active | 严重 | Gogithub.com/casdoor/casdoor | 已审查 | 2026-05-29 02:30 | 2026-07-03 02:37 |
| GHSA-M67G-87RX-V42C CVE-2026-41185 | Calico Inserts Sensitive Information into Log File | 中危 | Gogithub.com/projectcalico/calico | 已审查 | 2026-05-29 02:30 | 2026-07-03 01:30 |
| GHSA-W76H-Q7C6-JPJP CVE-2026-46380 | compliance-trestle Vulnerable to SSRF in Remote Fetching Subsystem | 中危 | PyPIcompliance-trestle | 已审查 | 2026-05-29 02:27 | 2026-05-29 02:27 |
| GHSA-Q537-QHJ4-WCJX CVE-2026-44730 | OpenCTI: Privilege escalation via graphQL API is abusable by organization admins, due to incorrect ACL on userEdit relationAdd | 高危 | PyPIpycti | 已审查 | 2026-05-29 02:08 | 2026-05-29 02:08 |