检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-WPQM-4GWX-W843 CVE-2026-44598 | Apache Shiro Vulnerable to Open Redirect, Server-Side Request Forgery | 中危 | Mavenorg.apache.shiro:shiro-jakarta-ee | 已审查 | 2026-05-26 21:30 | 2026-07-01 01:29 |
| GHSA-FCVM-3CPJ-F9QX CVE-2026-43827 | Apache Shiro has a session fixation vulnerability |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 中危 |
Mavenorg.apache.shiro:shiro-core |
| 已审查 |
| 2026-05-26 21:30 |
| 2026-07-01 01:26 |
| GHSA-C6R4-QJMW-CVJ2 CVE-2026-43828 | Apache Shiro sends sensitive cookies in HTTPS session without 'Secure' attribute | 中危 | Mavenorg.apache.shiro:shiro-web | 已审查 | 2026-05-26 21:30 | 2026-07-01 01:27 |
| GHSA-7PQ2-FHX9-X464 CVE-2026-48589 | Apache Shiro’s Jakarta EE module used the HTTP Referer header in certain cases to issue redirect after a user login | 低危 | Mavenorg.apache.shiro:shiro-jakarta-ee | 已审查 | 2026-05-26 21:30 | 2026-07-11 05:42 |
| GHSA-4R4V-3JC5-HRG9 CVE-2026-9497 | TCC-TRANSACTION has an Improper Input Validation vulnerability | 低危 | Mavenorg.mengyun:tcc-transaction | 已审查 | 2026-05-26 21:30 | 2026-07-01 01:37 |
| GHSA-VR35-JM2F-8WG2 CVE-2026-42797 | Apache Syncope Vulnerable to Exposure of Sensitive Information Through Data Queries | 中危 | Mavenorg.apache.syncope.core:syncope-core-provisioning-api | 已审查 | 2026-05-26 21:30 | 2026-07-01 01:19 |
| GHSA-GQ7G-VG2Q-JVQ3 CVE-2026-42782 | Apache Syncope has an Improper Isolation or Compartmentalization vulnerability | 高危 | Mavenorg.apache.syncope.core:syncope-core-spring | 已审查 | 2026-05-26 21:30 | 2026-07-01 01:18 |
| GHSA-76V6-F83Q-PXVH | Duplicate Advisory: Hackney has an Allocation of Resources Without Limits or Throttling vulnerabilit 已撤回 | 高危 | Hexhackney | 已审查 | 2026-05-26 21:30 | 2026-07-01 01:15 |
| GHSA-G283-W6FP-C4FC CVE-2026-46745 | Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability | 中危 | PyPIapache-airflow-providers-fab | 已审查 | 2026-05-26 21:30 | 2026-07-01 00:59 |
| GHSA-G9V5-GJWF-9RWX CVE-2026-45361 | Apache Airflow providers-google's `ComputeEngineSSHHook` disables SSH host-key verification by default | 高危 | PyPIapache-airflow-providers-google | 已审查 | 2026-05-26 21:30 | 2026-07-01 00:53 |
| GHSA-FGMJ-FM8M-JVVX CVE-2026-45249 | Apache ECharts has a cross-site scripting (XSS) vulnerability | 中危 | npmecharts | 已审查 | 2026-05-26 21:30 | 2026-07-01 00:55 |
| GHSA-5GMF-X7HG-97WF CVE-2026-4915 | Mattermost doesn't filter nil elements from outgoing webhook attachment payloads before processing | 中危 | Gogithub.com/mattermost/mattermost-server+1 | 已审查 | 2026-05-26 21:30 | 2026-07-01 00:58 |
| GHSA-CC4M-MP48-X7QG CVE-2026-41863 | Spring AI's support for Anthropic's Skills API used LLM-influenced filenames unsanitized in Path.resolve before writing files to disk | 中危 | Mavenorg.springframework.ai:spring-ai-anthropic | 已审查 | 2026-05-26 21:30 | 2026-07-01 00:50 |
| GHSA-8C7Q-86FQ-VVMH CVE-2026-2651 | MLflow allows unauthorized access to multipart upload endpoints when the `--serve-artifacts` mode is enabled | 严重 | PyPImlflow | 已审查 | 2026-05-26 21:30 | 2026-07-01 00:48 |
| GHSA-29PF-2H5F-8G72 CVE-2026-4372 | HuggingFace transformers vulnerable to remote code execution | 高危 | PyPItransformers | 已审查 | 2026-05-26 21:30 | 2026-07-02 02:00 |
| GHSA-WM96-9GFH-VVGQ CVE-2026-9368 | hermes-agent has a sandbox issue | 中危 | PyPIhermes-agent | 已审查 | 2026-05-26 21:30 | 2026-06-30 23:37 |
| GHSA-JGJ7-C8VJ-W563 CVE-2026-9370 | jasypt-spring-boot Uses a One-Way Hash without a Salt | 低危 | Mavencom.github.ulisesbocchio:jasypt-spring-boot+1 | 已审查 | 2026-05-26 21:30 | 2026-07-01 00:30 |
| GHSA-CV5C-MH6J-WVP9 CVE-2026-9369 | hermes-agent has an Incorrect Comparison | 低危 | PyPIhermes-agent | 已审查 | 2026-05-26 21:30 | 2026-07-01 01:22 |
| GHSA-PGP4-XR4J-H5CG CVE-2026-9366 | hermes-agent has an Injection issue | 中危 | PyPIhermes-agent | 已审查 | 2026-05-26 21:30 | 2026-06-30 23:34 |
| GHSA-W9M9-85WC-3X92 CVE-2026-9358 | postcss-selector-parser allows denial of service through uncontrolled AST recursion | 低危 | npmpostcss-selector-parser | 已审查 | 2026-05-26 21:30 | 2026-09-01 23:45 |
| GHSA-238W-F66P-W349 CVE-2026-9353 | hermes-agent has an Injection issue | 中危 | PyPIhermes-agent | 已审查 | 2026-05-26 21:30 | 2026-06-30 23:25 |
| GHSA-CW25-2P92-7F75 CVE-2026-3515 | Prefect has an Argument Injection issue | 高危 | PyPIprefect | 已审查 | 2026-05-26 21:30 | 2026-06-30 23:12 |
| GHSA-HXMH-2XC4-C894 CVE-2018-25357 | Dolibarr ERP CRM contains a remote code evaluation vulnerability | 严重 | Packagistdolibarr/dolibarr | 已审查 | 2026-05-26 21:30 | 2026-07-01 01:50 |
| GHSA-QM7Q-RCM2-3FRC CVE-2026-9301 | omec-project amf Vulnerable to Improper Restriction of Operations within the Bounds of a Memory Buffer | 低危 | Gogithub.com/omec-project/amf | 已审查 | 2026-05-26 21:30 | 2026-06-30 22:57 |
| GHSA-M9R6-R5C3-JW4J CVE-2026-9299 | omec-project amf Vulnerable to Improper Restriction of Operations within the Bounds of a Memory Buffer | 低危 | Gogithub.com/omec-project/amf | 已审查 | 2026-05-26 21:30 | 2026-06-30 22:58 |