检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-Q2F7-M237-V562 | @hulumi/policies: GitHub OIDC trust policy bypass via AWS set-qualified condition operators | 严重 | npm@hulumi/policies | 已审查 | 2026-05-22 04:45 | 2026-05-22 04:45 |
| GHSA-4XRH-5M3M-328W | @hulumi/policies: CIS 1.16 admin policy bypass for inline and attached IAM policies |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 高危 |
npm@hulumi/policies |
| 已审查 |
| 2026-05-22 04:44 |
| 2026-05-22 04:44 |
| GHSA-G43V-9X7Q-83PQ | @hulumi/policies: HULUMI-H1 SecureBucket parent spoof bypass | 高危 | npm@hulumi/policies | 已审查 | 2026-05-22 04:43 | 2026-05-22 04:43 |
| GHSA-2FFM-HXRQ-QQMM | @hulumi/drift: Orphan reconciler accepted externally supplied execute plans | 高危 | npm@hulumi/drift | 已审查 | 2026-05-22 04:43 | 2026-05-22 04:43 |
| GHSA-GFP8-MP24-5VXG | @hulumi/baseline: CloudTrail selector tampering events were not fully detected | 中危 | npm@hulumi/baseline | 已审查 | 2026-05-22 04:43 | 2026-05-22 04:43 |
| GHSA-VR9V-27GG-QGX4 CVE-2026-46609 | Umbraco.Cms: XSS/HTML Injection in Umbraco Backoffice confirmation dialog | 中危 | NuGetUmbraco.Cms | 已审查 | 2026-05-22 04:43 | 2026-06-11 02:41 |
| GHSA-XQ32-9G7Q-7297 CVE-2026-46556 | FlaskBB: SSRF in get_image_info() via unrestricted avatar URL | 中危 | PyPIflaskbb | 已审查 | 2026-05-22 04:42 | 2026-05-22 04:42 |
| GHSA-F76X-F9VJ-92JV CVE-2026-46554 | NocoDB: Stale Auth Cache After API Token Deletion | 低危 | npmnocodb | 已审查 | 2026-05-22 04:39 | 2026-07-21 05:16 |
| GHSA-8RWR-F68V-CVW6 CVE-2026-46553 | NocoDB: Attachment Size Limit Bypass via Upload-by-URL | 低危 | npmnocodb | 已审查 | 2026-05-22 04:38 | 2026-07-21 05:16 |
| GHSA-CHQV-VRJ7-QFFP CVE-2026-46552 | NocoDB: Shared-base link access can invite arbitrary users as persistent base members | 中危 | npmnocodb | 已审查 | 2026-05-22 04:35 | 2026-07-21 05:16 |
| GHSA-99VC-2JX2-688P CVE-2026-46551 | NocoDB: Missing File Size Enforcement in Upload-by-URL Allows Denial of Service via Disk Exhaustion | 中危 | npmnocodb | 已审查 | 2026-05-22 04:35 | 2026-07-21 05:16 |
| GHSA-F74W-272X-MQCV CVE-2026-46550 | NocoDB: Refresh Token Cookie Set Without `secure` and `sameSite` Flags | 中危 | npmnocodb | 已审查 | 2026-05-22 04:35 | 2026-07-21 05:16 |
| GHSA-M5QG-RVJQ-727P CVE-2026-46549 | NocoDB: OAuth Token Scope Not Enforced at ACL Layer Allows Scope Escalation | 低危 | npmnocodb | 已审查 | 2026-05-22 04:34 | 2026-07-21 05:16 |
| GHSA-2C5X-4JGF-88MJ CVE-2026-46548 | NocoDB: SSRF Protection Bypass in Notification Webhook Plugins (Slack, Discord, Mattermost, Teams) | 中危 | npmnocodb | 已审查 | 2026-05-22 04:34 | 2026-07-21 05:16 |
| GHSA-9QGR-6VPG-9GH9 CVE-2026-46547 | NocoDB: Reflected Cross-Site Scripting via Page Leaving Redirect URL | 中危 | npmnocodb | 已审查 | 2026-05-22 04:34 | 2026-07-21 05:15 |
| GHSA-CR22-WJX7-2W6M CVE-2026-46519 | MCP Server Kubernetes: Tool Access Control Bypass via Presentation-Layer Filtering Without Execution-Layer Enforcement | 高危 | npmmcp-server-kubernetes | 已审查 | 2026-05-22 04:33 | 2026-06-13 03:26 |
| GHSA-MQCF-GQVG-RMHM CVE-2026-46668 | SpiceDB: Caveat structures with nested lists can result in improper cache reuse | 低危 | Gogithub.com/authzed/spicedb | 已审查 | 2026-05-22 04:28 | 2026-06-11 22:05 |
| GHSA-VJ64-RJF3-W3V7 CVE-2026-46654 | Plonky3 MultiField32Challenger: transcript malleability and challenge entropy loss | 高危 | crates.iop3-challenger | 已审查 | 2026-05-22 04:24 | 2026-06-11 22:05 |
| GHSA-VPR4-P6FQ-85JC CVE-2026-46643 | Snappy: Binary path is never shell-escaped due to an inverted is_executable check | 高危 | PackagistKnpLabs/knp-snappy | 已审查 | 2026-05-22 04:22 | 2026-06-11 21:30 |
| GHSA-C5FP-P67M-GQ56 CVE-2026-46683 | Snappy : SSRF and local file read via the xsl-style-sheet option | 中危 | Packagistknplabs/knp-snappy | 已审查 | 2026-05-22 04:20 | 2026-06-11 21:30 |
| GHSA-7PJR-QPVH-M339 CVE-2026-46618 | Fission builder accepts arbitrary buildcmd strings from Environment.spec.builder.command, allowing the builder pod to invoke arbitrary executables | 中危 | Gogithub.com/fission/fission | 已审查 | 2026-05-22 04:17 | 2026-06-11 02:42 |
| GHSA-85G2-PMRX-R49Q CVE-2026-46617 | Fission runtime pods automount the fission-fetcher service-account token into the user function container, granting function code namespace-wide secret / configmap read | 高危 | Gogithub.com/fission/fission | 已审查 | 2026-05-22 04:16 | 2026-07-21 21:54 |
| GHSA-3G33-6VG6-27M8 CVE-2026-46614 | Fission router exposes /fission-function/<ns>/<name> on its public listener, allowing invocation of any function without an HTTPTrigger | 严重 | Gogithub.com/fission/fission | 已审查 | 2026-05-22 04:14 | 2026-06-11 02:41 |
| GHSA-CHF8-4HV6-8PG6 CVE-2026-46612 | Fission StorageSvc /v1/archive endpoint exposes unauthenticated CRUD over all function archives | 高危 | Gogithub.com/fission/fission | 已审查 | 2026-05-22 04:07 | 2026-07-21 21:58 |
| GHSA-2QJJ-H6WP-C7H7 CVE-2026-46616 | Umbraco.Cms: Open Redirect Vulnerability in Surface Controllers | 中危 | NuGetUmbraco.Cms | 已审查 | 2026-05-22 03:58 | 2026-06-11 02:41 |