检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-W2X5-GV52-9CCV CVE-2026-54049 | Sakai Conversations has a Stored XSS Issue | 高危 | Mavenorg.sakaiproject.conversations:sakai-conversations-impl+2 | 已审查 | 2026-08-25 03:37 | 2026-08-25 03:37 |
| GHSA-XM98-3VCF-FPH7 CVE-2026-53710 |
当前筛选结果 35,190 条 · 时间按北京时间显示
mcp-contextforge-gateway has RestrictedPython sandbox bypass via getattr builtin in python_sandbox_server |
| 严重 |
PyPImcp-contextforge-gateway |
| 已审查 |
| 2026-08-25 03:20 |
| 2026-09-02 23:28 |
| GHSA-V7H8-XHH6-GFJ4 CVE-2026-78329 | Apache Camel-Undertow: the endpoint discarded the undertow-specific header filter strategy in favour of the base HTTP one, so the undertow filtering never ran on endpoint-configured routes | 严重 | Mavenorg.apache.camel:camel-undertow | 已审查 | 2026-08-25 02:31 | 2026-08-29 06:01 |
| GHSA-VVWM-3J43-7PFM CVE-2026-63621 | Apache Camel-Knative: CloudEvent extension fields received in structured content mode were mapped onto message headers without applying any header filter strategy | 中危 | Mavenorg.apache.camel:camel-knative | 已审查 | 2026-08-25 02:31 | 2026-08-29 04:30 |
| GHSA-M5R8-W65Q-8WJF CVE-2026-71300 | Apache Camel-Atmosphere-Websocket: WebSocket dispatch header injection - the producer selected its target peers through Exchange headers whose names sat outside the filtered Camel namespace | 严重 | Mavenorg.apache.camel:camel-atmosphere-websocket | 已审查 | 2026-08-25 02:31 | 2026-08-29 06:00 |
| GHSA-FPM2-M4QQ-WGHR CVE-2026-66908 | Apache Camel-platform-http-main: when JWT authentication was configured with a keystore but no issuer or audience, the iss and aud claims were never validated, so any unexpired token signed by a trusted key was accepted | 高危 | Mavenorg.apache.camel:camel-platform-http-main | 已审查 | 2026-08-25 02:31 | 2026-08-29 05:56 |
| GHSA-F78G-9385-QXQJ CVE-2026-66907 | Apache Camel-Google-Storage: the consumer appended the remote object name to the configured downloadFileName directory without constraining the result | 高危 | Mavenorg.apache.camel:camel-google-storage | 已审查 | 2026-08-25 02:31 | 2026-08-29 05:55 |
| GHSA-CX47-QXP5-MMH2 CVE-2026-59230 | Apache Camel-Mail: the MimeMultipart data format copied MIME headers onto the Camel message without a header filter strategy when unmarshalling with headersInline enabled | 中危 | Mavenorg.apache.camel:camel-mail | 已审查 | 2026-08-25 02:31 | 2026-08-29 04:19 |
| GHSA-7JWC-Q3FJ-C9PQ CVE-2026-60093 | Apache Camel-Azure-Storage-DataLake: the downloadToFile operation built the local download target from the remote path name without constraining it to the configured fileDir | 中危 | Mavenorg.apache.camel:camel-azure-storage-datalake | 已审查 | 2026-08-25 02:31 | 2026-08-29 04:29 |
| GHSA-2X37-89HJ-2J95 CVE-2026-66906 | Apache Camel-Azure-Storage-Blob: the downloadBlobToFile operation built the local download target from the remote blob name without constraining it to the configured fileDir | 严重 | Mavenorg.apache.camel:camel-azure-storage-blob | 已审查 | 2026-08-25 02:31 | 2026-08-29 05:54 |
| GHSA-892M-GCQ8-2468 | Duplicate Advisory: Uncontrolled recursion DoS in JustHTML() via deeply nested HTML 已撤回 | 高危 | PyPIjusthtml | 已审查 | 2026-08-23 23:33 | 2026-08-26 00:40 |
| GHSA-8H9M-22MV-QV5R | Duplicate Advisory: Symlink escape in CorpusReader allows arbitrary local file read outside the corpus root 已撤回 | 高危 | PyPInltk | 已审查 | 2026-08-22 23:31 | 2026-09-02 22:48 |
| GHSA-QQ3H-CGJ8-W3FX | Duplicate Advisory: Symlink-based sandbox bypass in FramenetCorpusReader (bypasses the fix for CVE-2026-54292) 已撤回 | 高危 | PyPInltk | 已审查 | 2026-08-22 23:31 | 2026-09-02 22:47 |
| GHSA-QG9P-XRHJ-435M | Duplicate Advisory: nltk: SSRF Fail-Open in validate_network_url() via DNS Resolution Failure 已撤回 | 中危 | PyPInltk | 已审查 | 2026-08-22 23:31 | 2026-09-02 23:38 |
| GHSA-CV2G-M8RR-888C | Duplicate Advisory: Natural Language Toolkit (NLTK) has unbounded recursion in JSONTaggedDecoder.decode_obj() may cause DoS 已撤回 | 高危 | PyPInltk | 已审查 | 2026-08-22 23:31 | 2026-09-02 23:33 |
| GHSA-CV22-G7MW-8V73 CVE-2026-71514 | NLTK CrubadanCorpusReader path traversal allows arbitrary file disclosure | 低危 | PyPInltk | 已审查 | 2026-08-22 23:31 | 2026-09-02 23:32 |
| GHSA-8W48-H75V-CXPV | Duplicate Advisory: Security Report: StreamBackedCorpusView Bypasses pathsec.ENFORCE - Arbitrary Local File Read 已撤回 | 高危 | PyPInltk | 已审查 | 2026-08-22 23:31 | 2026-09-02 22:48 |
| GHSA-8VH5-MGJJ-W6HG | Duplicate Advisory: [CWE-1188] Default ENFORCE=False Disables All pathsec Security Controls 已撤回 | 高危 | PyPInltk | 已审查 | 2026-08-22 23:31 | 2026-09-02 23:40 |
| GHSA-79PH-W9M5-4V5M | Duplicate Advisory: FileSystemPathPointer.open() sandbox check is dead code — arbitrary file read via file:// protocol 已撤回 | 高危 | PyPInltk | 已审查 | 2026-08-22 23:31 | 2026-09-02 22:47 |
| GHSA-5GH2-94QG-QPPQ CVE-2026-71513 | NLTK AllowlistUnpickler dotted-name validation bypass allows remote code execution | 高危 | PyPInltk | 已审查 | 2026-08-22 23:31 | 2026-09-02 23:18 |
| GHSA-343M-9FQQ-97C7 | Duplicate Advisory: NLTK: Symlink-based arbitrary file read in IPIPANCorpusReader, bypasses nltk.pathsec entirely 已撤回 | 中危 | PyPInltk | 已审查 | 2026-08-22 23:31 | 2026-09-02 22:47 |
| GHSA-66MM-25PP-RFFF CVE-2026-77415 | JSONata vulnerable to Arbitrary Code Execution via crafted JSONata expressions | 严重 | npmjsonata | 已审查 | 2026-08-22 05:04 | 2026-08-22 05:04 |
| GHSA-2943-5XFG-GQ5F CVE-2026-77414 | JSONata vulnerable to Arbitrary Code Execution via crafted JSONata expressions | 严重 | npmjsonata | 已审查 | 2026-08-22 04:58 | 2026-08-22 04:58 |
| GHSA-2CP2-2R3C-7P7R CVE-2026-68508 | Hydra: hydra.utils.instantiate with untrusted config can lead to code execution | 高危 | PyPIhydra-core | 已审查 | 2026-08-22 04:57 | 2026-08-22 04:57 |
| GHSA-5H77-88J3-R659 CVE-2026-63135 | YOURLS has stored XSS in referrer statistics chart via crafted Referer header | 高危 | Packagistyourls/yourls | 已审查 | 2026-08-22 04:57 | 2026-08-22 04:57 |