检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-6P7M-C3MW-4GMW CVE-2026-9300 | omec-project amf Vulnerable to Improper Restriction of Operations within the Bounds of a Memory Buffer | 低危 | Gogithub.com/omec-project/amf | 已审查 | 2026-05-26 21:30 | 2026-06-30 22:56 |
| GHSA-R5VF-GRCX-5VQP CVE-2026-28735 | Mattermost allows authenticated users to gain access to private repositories |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 中危 |
Gogithub.com/mattermost/mattermost-plugin-github+1 |
| 已审查 |
| 2026-05-26 21:30 |
| 2026-06-30 07:09 |
| GHSA-XJG6-5V39-V7FC CVE-2026-8340 | Concrete CMS is vulnerable to CSRF via Backend\File::approveVersion | 低危 | Packagistconcrete5/concrete5 | 已审查 | 2026-05-26 21:30 | 2026-06-30 07:04 |
| GHSA-Q9FM-MPG8-8JQM CVE-2026-8353 | Concrete CMS is vulnerable to Stored XSS via page name in the Atomik theme | 低危 | Packagistconcrete5/concrete5 | 已审查 | 2026-05-26 21:30 | 2026-06-30 07:04 |
| GHSA-JQVQ-GV67-3567 CVE-2026-8347 | Concrete CMS is vulnerable to IDOR + wrong-authorization-level in the Express association Reorder dialog | 低危 | Packagistconcrete5/concrete5 | 已审查 | 2026-05-26 21:30 | 2026-06-30 07:03 |
| GHSA-5CV4-JP36-H3MW CVE-2026-25680 | Go Net HTML parser is vulnerable to denial of service | 中危 | Gogolang.org/x/net | 已审查 | 2026-05-26 21:30 | 2026-07-02 01:58 |
| GHSA-PG32-686Q-QH6X CVE-2026-44930 | Apache CXF has an LDAP injection vulnerability | 严重 | Mavenorg.apache.cxf.services.xkms:cxf-services-xkms-x509-repo-ldap | 已审查 | 2026-05-26 21:30 | 2026-06-30 07:02 |
| GHSA-W9M8-P4CC-4QJ9 CVE-2026-5740 | Mattermost doesn't properly validate msgpack-encoded WebSocket frames before memory allocation | 高危 | Gogithub.com/mattermost/mattermost-server+1 | 已审查 | 2026-05-26 21:30 | 2026-06-30 06:52 |
| GHSA-VMM5-FJGX-2JHP CVE-2026-44618 | Apache CXF's WS-Transfer module has an insecure XML parser configuration | 中危 | Mavenorg.apache.cxf:cxf-rt-ws-transfer | 已审查 | 2026-05-26 21:30 | 2026-06-30 07:01 |
| GHSA-RMVV-8V8W-RF7X CVE-2026-4646 | Mattermost doesn't validate user-supplied input in API request handlers | 中危 | Gogithub.com/mattermost/mattermost-plugin-github+1 | 已审查 | 2026-05-26 21:30 | 2026-06-30 03:21 |
| GHSA-PG7C-462J-GRXV CVE-2026-4635 | Mattermost doesn't archive the channel before removing persistent notifications | 中危 | Gogithub.com/mattermost/mattermost-server | 已审查 | 2026-05-26 21:30 | 2026-06-27 06:48 |
| GHSA-JMVR-R5HM-FXFR CVE-2026-5308 | Mattermost doesn't enforce request body size limits on plugin HTTP endpoints | 高危 | Gogithub.com/mattermost/mattermost-plugin-github+1 | 已审查 | 2026-05-26 21:30 | 2026-06-30 06:41 |
| GHSA-FFPR-PFR4-G354 CVE-2026-3636 | Mattermost doesn't sanitize team member data when returned via API to users without elevated permissions | 中危 | Gogithub.com/mattermost/mattermost-server | 已审查 | 2026-05-26 21:30 | 2026-06-27 06:47 |
| GHSA-7PF2-9C95-W332 CVE-2026-3473 | Mattermost doesn't validate file ownership and access control | 高危 | Gogithub.com/mattermost/mattermost-server | 已审查 | 2026-05-26 21:30 | 2026-06-27 06:48 |
| GHSA-37J2-3VV8-CF24 CVE-2026-5755 | Mattermost doesn't validate the TIFF IFD offset in the image header before allocating memory | 中危 | Gogithub.com/mattermost/mattermost-server | 已审查 | 2026-05-26 21:30 | 2026-06-30 06:41 |
| GHSA-2HVC-5C6V-F533 CVE-2026-44417 | Apache CXF: Untrusted JMS configuration can lead to RCE | 高危 | Mavenorg.apache.cxf:cxf-rt-transports-jms | 已审查 | 2026-05-26 21:30 | 2026-06-30 07:00 |
| GHSA-HVV7-HFRH-7GXJ CVE-2026-47124 | Nezha Monitoring: Nezha WebSocket server stream discloses cross-tenant server telemetry to authenticated members | 中危 | Gogithub.com/nezhahq/nezha | 已审查 | 2026-05-23 08:18 | 2026-06-27 05:28 |
| GHSA-99GV-2M7H-3HH9 CVE-2026-46716 | Nezha Monitoring: RoleMember can run shell on every server (cross-tenant RCE) via POST /api/v1/cron | 严重 | Gogithub.com/nezhahq/nezha | 已审查 | 2026-05-23 08:17 | 2026-06-27 05:28 |
| GHSA-JPJH-JM2P-39HH CVE-2026-47125 | Arcane: Missing admin authorization on global variables endpoint | 高危 | Gogithub.com/getarcaneapp/arcane/backend | 已审查 | 2026-05-23 08:16 | 2026-06-09 18:30 |
| GHSA-GGXF-37HM-9WQF | instagrapi: Unsafe signup challenge path handling in instagrapi | 中危 | PyPIinstagrapi | 已审查 | 2026-05-23 08:12 | 2026-05-23 08:12 |
| GHSA-JH37-X3FV-4X72 CVE-2026-47157 | aiograpi: Unsafe signup challenge path handling | 中危 | PyPIaiograpi | 已审查 | 2026-05-23 08:11 | 2026-06-13 03:25 |
| GHSA-38M6-82C8-4XFM CVE-2026-47138 | Parse Server: Pre-authentication denial of service via client version header regex backtracking | 高危 | npmparse-server | 已审查 | 2026-05-23 08:11 | 2026-06-13 05:59 |
| GHSA-RXF6-WJH4-JFJ6 CVE-2026-47120 | Nezha Monitoring: RoleMember can fire other users' cron tasks via AlertRule.FailTriggerTasks (no ownership check) | 中危 | Gogithub.com/nezhahq/nezha | 已审查 | 2026-05-23 08:08 | 2026-06-27 05:28 |
| GHSA-W4G9-MXGG-J532 CVE-2026-46717 | Nezha Monitoring: RoleMember-reachable SSRF with full response-body reflection via POST /api/v1/notification | 高危 | Gogithub.com/nezhahq/nezha | 已审查 | 2026-05-23 08:08 | 2026-06-27 05:28 |
| GHSA-97R5-PG8X-P63P CVE-2026-46715 | Flask-Security-Too OAuth reauthentication freshness bypass via cross- user OAuth identity acceptance | 中危 | PyPIFlask-Security-Too | 已审查 | 2026-05-23 01:48 | 2026-05-23 01:48 |