检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-P5WG-G6QR-C7CG CVE-2025-50537 | Withdrawn Advisory: eslint has a Stack Overflow when serializing objects with circular references 已撤回 | 中危 | npmeslint | 已审查 | 2026-01-27 02:31 | 2026-02-04 01:43 |
当前筛选结果 998 条 · 时间按北京时间显示
| GHSA-VH96-P962-544H CVE-2026-0767 |
Withdrawn Advisory: Open WebUI/ZDI-CAN-28259 已撤回 |
| 中危 |
PyPIopen-webui |
| 已审查 |
| 2026-01-23 14:31 |
| 2026-09-03 04:48 |
| GHSA-3966-F6P6-2QR9 CVE-2026-0775 | Duplicate Advisory: npm cli Uncontrolled Search Path Element Local Privilege Escalation Vulnerability 已撤回 | 高危 | npmnpm | 已审查 | 2026-01-23 14:31 | 2026-02-07 06:28 |
| GHSA-28QQ-5F47-R5X2 | Duplicate Advisory: gemini-mcp-tool vulnerable to OS command injection and @file exfiltration via prompt quoting (CVE-2026-0755) 已撤回 | 严重 | npmgemini-mcp-tool | 已审查 | 2026-01-23 14:31 | 2026-06-19 04:44 |
| GHSA-8H3Q-9FPP-C883 | Duplicate Advisory: Wrangler affected by OS Command Injection in `wrangler pages deploy` 已撤回 | 高危 | npmwrangler | 已审查 | 2026-01-21 08:31 | 2026-01-29 11:38 |
| GHSA-XFHX-R7WW-5995 | Duplicate Advisory: Google Keras Allocates Resources Without Limits or Throttling in the HDF5 weight loading component 已撤回 | 高危 | PyPIkeras | 已审查 | 2026-01-15 23:31 | 2026-05-07 07:06 |
| GHSA-2HC9-CC65-XWJ8 | Duplicate Advisory: ComfyUI-Manager has an Unprotected Alternate Channel (CWE-420) 已撤回 | 高危 | PyPIcomfyui-manager | 已审查 | 2026-01-06 02:30 | 2026-06-23 03:58 |
| GHSA-P4F6-H8JJ-VFVF | Duplicate Advisory: Reflected XSS in go-httpbin due to unrestricted client control over Content-Type 已撤回 | 低危 | Gogithub.com/mccutchen/go-httpbin+1 | 已审查 | 2026-01-02 23:30 | 2026-01-03 04:32 |
| GHSA-46J5-6FG5-4GV3 | Duplicate Advisory: Nodemailer is vulnerable to DoS through Uncontrolled Recursion 已撤回 | 中危 | npmnodemailer | 已审查 | 2025-12-18 17:30 | 2026-02-04 01:37 |
| GHSA-H4PW-WXH7-4VJJ CVE-2024-29370 | Duplicate Advisory: python-jose denial of service via compressed JWE content 已撤回 | 中危 | PyPIpython-jose | 已审查 | 2025-12-18 02:31 | 2026-06-09 03:13 |
| GHSA-VR6P-VQ2P-6J74 | Withdrawn Advisory: LikeC4 has RCE through vulnerable React and Next.js versions 已撤回 | 严重 | npmlikec4 | 已审查 | 2025-12-16 06:00 | 2025-12-23 00:35 |
| GHSA-95FV-5GFJ-2R84 CVE-2025-64113 | Withdrawn Advisory: Emby Server API Vulnerability allowing to gain administrative access without precondition 已撤回 | 严重 | NuGetMediaBrowser.Server.Core | 已审查 | 2025-12-09 00:25 | 2025-12-30 03:43 |
| GHSA-Q3HC-J9X5-MP9M CVE-2025-65955 | Withdrawn Advisory: ImageMagick has a use-after-free/double-free risk in Options::fontFamily when clearing family 已撤回 | 中危 | NuGetMagick.NET-Q16-AnyCPU+17 | 已审查 | 2025-12-04 00:25 | 2025-12-12 04:53 |
| GHSA-644F-HRFF-MF96 | Duplicate Advisory: Authentication Bypass via Default JWT Secret in NocoBase docker-compose Deployments 已撤回 | 低危 | npm@nocobase/auth | 已审查 | 2025-12-03 02:30 | 2025-12-10 01:42 |
| GHSA-PJ86-CFQH-VQX6 CVE-2024-51999 | Withdrawn Advisory: express improperly controls modification of query properties 已撤回 | 低危 | npmexpress | 已审查 | 2025-12-02 02:59 | 2025-12-02 23:11 |
| GHSA-9G7V-8WXV-MWXP CVE-2025-12638 | Duplicate Advisory: Keras keras.utils.get_file API is vulnerable to a path traversal attack 已撤回 | 高危 | PyPIKeras | 已审查 | 2025-11-28 23:30 | 2025-12-02 08:09 |
| GHSA-93VM-MQPW-8WH3 | Duplicate Advisory: Keycloak LDAP User Federation provider enables admin-triggered untrusted Java deserialization 已撤回 | 中危 | Mavenorg.keycloak:keycloak-ldap-federation | 已审查 | 2025-11-26 02:32 | 2025-12-24 05:30 |
| GHSA-JJ37-3377-M6VV | Duplicate Advisory: Nodemailer: Email to an unintended domain can occur due to Interpretation Conflict 已撤回 | 高危 | npmnodemailer | 已审查 | 2025-11-15 05:30 | 2026-05-13 21:45 |
| GHSA-4249-GJR8-JPQ3 | Duplicate Advisory: ProsemirrorToHtml has a Cross-Site Scripting (XSS) vulnerability through unescaped HTML attribute values 已撤回 | 高危 | RubyGemsprosemirror_to_html | 已审查 | 2025-11-14 06:59 | 2026-01-24 07:00 |
| GHSA-7M9G-PMXF-M9M8 | Duplicate Advisory: Keycloak allows Binding to an Unrestricted IP Address 已撤回 | 中危 | Mavenorg.keycloak:keycloak-quarkus-server | 已审查 | 2025-11-14 02:31 | 2025-12-20 13:40 |
| GHSA-VFPF-XMWH-8M65 | Duplicate Advisory: ProsemirrorToHtml has a Cross-Site Scripting (XSS) vulnerability through unescaped HTML attribute values 已撤回 | 高危 | RubyGemsprosemirror_to_html | 已审查 | 2025-11-08 07:17 | 2025-11-10 23:37 |
| GHSA-28JP-44VH-Q42H | Duplicate Advisory: Keras keras.utils.get_file API is vulnerable to a path traversal attack 已撤回 | 高危 | PyPIkeras | 已审查 | 2025-10-31 02:31 | 2025-12-02 08:53 |
| GHSA-C6CM-5GC7-C3F4 | Duplicate Advisory: Keycloak allows access to admin path through flaw 已撤回 | 低危 | Mavenorg.keycloak:keycloak-quarkus-server | 已审查 | 2025-10-28 14:31 | 2025-12-20 13:38 |
| GHSA-3G4J-R53P-22WX | Duplicate Advisory: FlowiseAI Pre-Auth Arbitrary Code Execution 已撤回 | 严重 | npmflowise | 已审查 | 2025-10-18 02:31 | 2025-10-18 04:22 |
| GHSA-Q8G5-RW97-F55H | Duplicate Advisory: Microsoft Security Advisory CVE-2025-55247 | .NET Denial of Service Vulnerability 已撤回 | 高危 | NuGetMicrosoft.Build.Tasks.Core | 已审查 | 2025-10-15 02:30 | 2025-10-16 01:28 |