检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-QC95-4862-92FH CVE-2026-45066 | Symfony has an HtmlSanitizer allowLinkHosts() / allowMediaHosts() Bypass via URL-Parser Differentials and <area> Misclassification | 中危 | Packagistsymfony/html-sanitizer+1 | 已审查 | 2026-05-28 04:13 | 2026-05-28 04:13 |
| GHSA-H5VQ-QFCG-4M6P CVE-2026-45064 |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 中危 |
Packagistsymfony/html-sanitizer+1 |
| 已审查 |
| 2026-05-28 04:04 |
| 2026-05-28 04:04 |
| GHSA-RW47-HM26-6WR7 CVE-2026-44982 | CrowdSec AppSec silently drops request body for chunked / HTTP-2 requests | 高危 | Gogithub.com/crowdsecurity/crowdsec | 已审查 | 2026-05-28 03:58 | 2026-05-28 03:58 |
| GHSA-273H-GVWR-C3QJ CVE-2026-44981 | CrowdSec LAPI: Denial of Service via Unbounded Gzip Decompression | 中危 | Gogithub.com/crowdsecurity/crowdsec | 已审查 | 2026-05-28 03:57 | 2026-06-13 04:24 |
| GHSA-CHQV-56WV-7564 CVE-2026-44726 | Deno's TLS retry copies stale upgrade hook, risking plaintext traffic | 高危 | crates.iodeno | 已审查 | 2026-05-28 03:51 | 2026-07-20 21:42 |
| GHSA-MXFR-6HCW-J9RQ CVE-2026-25879 | Langroid has Prompt to SQL Injection, Leading to RCE | 严重 | PyPIlangroid | 已审查 | 2026-05-28 03:38 | 2026-07-02 06:45 |
| GHSA-GF2Q-C269-PQGC CVE-2026-45618 | LiquidJS is Vulnerable to Remote Code Execution | 严重 | npmliquidjs | 已审查 | 2026-05-28 02:24 | 2026-05-28 02:24 |
| GHSA-R7G9-XPMJ-5FCQ CVE-2026-45617 | LiquidJS Vulnerable to ReDoS via Quadratic Backtracking in `strip_html` Filter Regex | 高危 | npmliquidjs | 已审查 | 2026-05-28 02:08 | 2026-07-10 05:06 |
| GHSA-QVJF-922G-PJ44 CVE-2026-45368 | Kirby CMS vulnerable to cross-site scripting (XSS) from links in KirbyTags and image blocks in the site frontend | 高危 | Packagistgetkirby/cms | 已审查 | 2026-05-28 01:42 | 2026-05-28 01:42 |
| GHSA-HH27-HF48-9F5Q CVE-2026-45357 | LiquidJS has a memory and render limit bypass via unbounded width padding in `date` filter (strftime) | 高危 | npmliquidjs | 已审查 | 2026-05-28 01:33 | 2026-07-10 05:06 |
| GHSA-39VQ-49QM-R2MC CVE-2026-45334 | Kirby CMS's content locks disclose IDs and emails of inaccessible users from `users.access/list` permissions | 中危 | Packagistgetkirby/cms | 已审查 | 2026-05-28 01:23 | 2026-05-28 01:23 |
| GHSA-WC7J-G8WX-M2QX CVE-2026-45260 | Pimcore: Missing Authorization in WebDAV MOVE via unchecked asset move handling | 高危 | Packagistpimcore/pimcore | 已审查 | 2026-05-28 01:17 | 2026-07-11 03:08 |
| GHSA-36FC-7WJG-MFVJ CVE-2026-45162 | Pimcore has Unsafe PHP Deserialization in Multiple Locations Without allowed_classes Restriction | 高危 | Packagistpimcore/pimcore | 已审查 | 2026-05-28 00:57 | 2026-07-11 03:07 |
| GHSA-72XP-P242-47P9 CVE-2026-45065 | Symfony has a UrlGenerator Route-Requirement Bypass via Unanchored Regex Alternation → Off-Site //host URL Injection | 中危 | Packagistsymfony/routing+1 | 已审查 | 2026-05-28 00:55 | 2026-05-28 00:55 |
| GHSA-PH86-P8F6-F9R2 CVE-2026-45063 | Symfony Vulnerable to Identity Spoofing via Unanchored DN Regex in X509Authenticator | 高危 | Packagistsymfony/security-http+1 | 已审查 | 2026-05-28 00:50 | 2026-05-28 00:50 |
| GHSA-HJ3H-R49W-34WH CVE-2026-9674 | Jenkins Multijob Plugin has a cross-site request forgery (CSRF) vulnerability | 中危 | Mavenorg.jenkins-ci.plugins:jenkins-multijob-plugin | 已审查 | 2026-05-27 23:33 | 2026-07-02 03:46 |
| GHSA-72P9-6VV6-GVQH CVE-2026-9712 | pretix vulnerable to Authorization Bypass Through User-Controlled Key | 低危 | PyPIpretix | 已审查 | 2026-05-27 23:33 | 2026-07-02 03:47 |
| GHSA-43PH-42GV-7965 CVE-2026-48927 | Jenkins buildgraph-view Plugin does not escape the build URL | 中危 | Mavenorg.jenkins-ci.plugins:buildgraph-view | 已审查 | 2026-05-27 23:33 | 2026-07-02 03:46 |
| GHSA-RF8W-7C3G-7H3G CVE-2026-48925 | Jenkins GitHub Integration Plugin has a cross-site request forgery (CSRF) vulnerability | 中危 | Mavenorg.jenkins-ci.plugins:github-integration-parent | 已审查 | 2026-05-27 23:33 | 2026-07-02 03:44 |
| GHSA-R8FJ-RFF6-F7H5 CVE-2026-48924 | Jenkins Bitbucket OAuth Plugin does not restrict the redirect URL after login | 中危 | Mavenorg.jenkins-ci.plugins:bitbucket-oauth | 已审查 | 2026-05-27 23:33 | 2026-07-02 03:43 |
| GHSA-P8JH-4P5P-2RFP CVE-2026-48926 | Jenkins Job Import Plugin does not perform a permission check in an HTTP endpoint | 中危 | Mavenorg.jenkins-ci.plugins:job-import-plugin | 已审查 | 2026-05-27 23:33 | 2026-07-02 03:45 |
| GHSA-9WM7-8QF3-9V98 CVE-2026-48923 | Jenkins AppSpider Plugin does not perform a permission check in a method implementing form validation | 中危 | Mavencom.rapid7:jenkinsci-appspider-plugin | 已审查 | 2026-05-27 23:33 | 2026-07-02 03:43 |
| GHSA-X9V8-P946-5PWC CVE-2026-48917 | Jenkins LDAP Plugin deserializes data from LDAP referrals without validation | 中危 | Mavenorg.jenkins-ci.plugins:ldap | 已审查 | 2026-05-27 23:33 | 2026-07-02 03:38 |
| GHSA-WRHR-54P6-Q97F CVE-2026-48918 | Jenkins Active Directory Plugin follows LDAP referrals by default | 中危 | Mavenorg.jenkins-ci.plugins:active-directory | 已审查 | 2026-05-27 23:33 | 2026-07-02 03:30 |
| GHSA-QJQ3-WQJ5-G37Q CVE-2026-48921 | Jenkins Pipeline: Groovy Libraries Plugin does not prohibit symbolic links in shared libraries | 高危 | Mavenio.jenkins.plugins:pipeline-groovy-lib | 已审查 | 2026-05-27 23:33 | 2026-07-02 03:26 |