检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-P2GW-F3RV-82MW CVE-2026-48919 | Jenkins Active Directory Plugin deserializes data from LDAP referrals without validation | 中危 | Mavenorg.jenkins-ci.plugins:active-directory | 已审查 | 2026-05-27 23:33 | 2026-07-02 03:39 |
| GHSA-MQ58-M26G-46GP CVE-2026-48920 | Jenkins Email Extension Plugin: Attackers able to control email content may specify `file:` URLs for images to read arbitrary files from Jenkins controller filesystem |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 高危 |
Mavenorg.jenkins-ci.plugins:email-ext |
| 已审查 |
| 2026-05-27 23:33 |
| 2026-07-02 03:42 |
| GHSA-FXXF-W25W-MCX2 CVE-2026-48922 | Jenkins Credentials Binding Plugin does not properly sanitize file names for file and zip file credentials | 高危 | Mavenorg.jenkins-ci.plugins:credentials-binding | 已审查 | 2026-05-27 23:33 | 2026-07-02 03:41 |
| GHSA-FMJP-MW89-C6H6 CVE-2026-48916 | Jenkins LDAP Plugin follows LDAP referrals | 中危 | Mavenorg.jenkins-ci.plugins:ldap | 已审查 | 2026-05-27 23:33 | 2026-07-02 03:37 |
| GHSA-7HP7-4P35-3CX2 CVE-2026-48545 | Gradio contains a cookie injection vulnerability | 高危 | PyPIgradio | 已审查 | 2026-05-27 23:33 | 2026-07-02 03:33 |
| GHSA-28GH-Q3GW-PVX8 CVE-2026-48544 | Taipy contains a path traversal vulnerability | 高危 | PyPItaipy | 已审查 | 2026-05-27 23:33 | 2026-07-02 03:29 |
| GHSA-RR5Q-3XWR-F323 CVE-2026-9704 | Keycloak Vulnerable to Improper Validation of Specified Quantity in Input | 中危 | Mavenorg.keycloak:keycloak-server-spi-private+1 | 已审查 | 2026-05-27 23:33 | 2026-07-02 03:09 |
| GHSA-CV2P-68F4-F4PW CVE-2026-36045 | picoclaw is vulnerable to OS command injection via the ExecTool component | 高危 | Gogithub.com/sipeed/picoclaw | 已审查 | 2026-05-27 23:33 | 2026-07-02 03:06 |
| GHSA-WCVJ-VPVW-9RR5 CVE-2026-9689 | Keycloak Services has Improper Validation of Consistency within Input | 中危 | Mavenorg.keycloak:keycloak-services | 已审查 | 2026-05-27 20:31 | 2026-08-06 02:31 |
| GHSA-WPHC-7CM7-8MF7 CVE-2026-49014 | GDAL: scanForGeometryContainers in the netCDF driver allows code execution via a stack-based buffer overflow | 高危 | PyPIgdal | 已审查 | 2026-05-27 11:30 | 2026-07-02 02:07 |
| GHSA-G7JQ-J257-RWW2 CVE-2026-49017 | OpenStack Swift: s3api middleware enters an infinite loop when processing a truncated aws-chunked PUT request body | 高危 | PyPIswift | 已审查 | 2026-05-27 11:30 | 2026-07-02 02:04 |
| GHSA-VHJM-W67Q-G75C CVE-2026-44979 | @hapi/wreck leaks sensitive `Proxy-Authorization` header across cross-hostname redirects | 中危 | npm@hapi/wreck | 已审查 | 2026-05-27 08:38 | 2026-05-27 08:38 |
| GHSA-36HH-X5P5-JGC8 CVE-2026-44974 | @hapi/content header parser has a parameter smuggling issue that allows upload-filter bypass via duplicate parameters | 高危 | npm@hapi/content | 已审查 | 2026-05-27 08:37 | 2026-05-27 08:37 |
| GHSA-H4PH-CRVJ-9H92 CVE-2026-44741 | Pimcore Admin Classic Bundle Vulnerable to SQL Injection in Translation Grid Date Filter via Unsanitized Property Parameter | 高危 | Packagistpimcore/admin-ui-classic-bundle | 已审查 | 2026-05-27 08:35 | 2026-07-11 03:07 |
| GHSA-3234-GXC3-PQ6F CVE-2026-44739 | Pimcore Vulnerable to SQL Injection in Custom Reports Column Configuration | 高危 | Packagistpimcore/pimcore | 已审查 | 2026-05-27 08:35 | 2026-07-11 03:07 |
| GHSA-PH9P-34F9-6G65 CVE-2026-44705 | tmp has Path Traversal via unsanitized prefix/postfix that enables directory escape | 高危 | npmtmp | 已审查 | 2026-05-27 08:34 | 2026-06-13 03:25 |
| GHSA-9X9P-QF8F-MVJG CVE-2026-44646 | LiquidJS's `{% render %}` tag silently bypasses per-render `ownPropertyOnly:true` via `Context.spawn()` | 中危 | npmliquidjs | 已审查 | 2026-05-27 08:28 | 2026-07-10 05:06 |
| GHSA-8XX9-69P8-7JP3 CVE-2026-44645 | LiquidJS has a renderLimit DoS guard bypass via empty `{% for %}` body | 中危 | npmliquidjs | 已审查 | 2026-05-27 08:11 | 2026-07-10 05:06 |
| GHSA-2QV6-9WX5-CWV4 CVE-2026-44644 | LiquidJS's strip_html filter bypass via newline characters in HTML tags enables XSS | 中危 | npmliquidjs | 已审查 | 2026-05-27 08:09 | 2026-07-10 05:06 |
| GHSA-524G-X36V-9WM6 CVE-2026-44632 | Yamcs Vulnerable to Server-Side Code Injection (RCE) via Janino Expression Engine in `JavaExprAlgorithmExecutionFactory` | 严重 | Mavenorg.yamcs:yamcs-core | 已审查 | 2026-05-27 08:05 | 2026-05-27 08:05 |
| GHSA-W5R6-MCGQ-7PQ4 CVE-2026-44596 | Yamcs has No Rate Limiting on Authentication Endpoint | 中危 | Mavenorg.yamcs:yamcs-core | 已审查 | 2026-05-27 08:04 | 2026-05-27 08:04 |
| GHSA-P2RJ-MRMC-9W29 CVE-2026-44595 | Yamcs vulnerable to unauthorized user enumeration via IAM API endpoints | 中危 | Mavenorg.yamcs:yamcs-core | 已审查 | 2026-05-27 08:03 | 2026-05-27 08:03 |
| GHSA-7G26-2QGJ-CHFG CVE-2026-44587 | CarrierWave has a denylisted_content_type bypass via Unescaped Regex Metacharacters | 中危 | RubyGemscarrierwave | 已审查 | 2026-05-27 08:03 | 2026-07-09 01:39 |
| GHSA-RR59-XXVX-96QR CVE-2026-44210 | Kata Containers have VM Escape via virtiofsd Argument Injection through Default-Enabled Pod Annotations | 中危 | Gogithub.com/kata-containers/kata-containers | 已审查 | 2026-05-27 07:57 | 2026-07-28 09:48 |
| GHSA-9HX7-C53C-V6X8 CVE-2026-44177 | Kirby CMS has pre-authentication path traversal and PHP file inclusion during user lookup | 高危 | Packagistgetkirby/cms | 已审查 | 2026-05-27 07:56 | 2026-05-27 07:56 |