检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-M6QJ-3MPP-57V8 CVE-2026-9087 | Keycloak: Insufficient verification proof scoping enables identity provider account linking attack and account compromise | 中危 | Mavenorg.keycloak:keycloak-services | 已审查 | 2026-05-21 02:31 | 2026-06-26 17:30 |
| GHSA-FVHG-P4HF-79X3 CVE-2026-30691 | @cyntler/react-doc-viewer's TXTRenderer fails to sanitize file content and explicitly casts raw data as a ReactNode |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 中危 |
npm@cyntler/react-doc-viewer |
| 已审查 |
| 2026-05-21 02:31 |
| 2026-06-11 21:28 |
| GHSA-W9XH-5F39-VQ89 CVE-2026-35675 | phpMyFAQ: Missing Password Reset Token Allows Account Takeover via Username/Email Enumeration | 高危 | Packagistphpmyfaq/phpmyfaq+1 | 已审查 | 2026-05-20 23:46 | 2026-05-28 22:20 |
| GHSA-GP95-J463-VV28 CVE-2026-35672 | phpMyFAQ: Default Empty API Token Authentication Bypass | 高危 | Packagistphpmyfaq/phpmyfaq+1 | 已审查 | 2026-05-20 23:46 | 2026-06-09 08:05 |
| GHSA-XVP4-PHQJ-CJR3 CVE-2026-35671 | phpMyFAQ: IDOR Account Takeover | 高危 | Packagistphpmyfaq/phpmyfaq+1 | 已审查 | 2026-05-20 23:46 | 2026-05-28 22:19 |
| GHSA-9QV9-8XV6-5P35 CVE-2026-35676 | phpMyFAQ: Unauthenticated Password Reset Endpoint Allows User Enumeration and Forced Password Change Without Token Validation | 高危 | Packagistphpmyfaq/phpmyfaq+1 | 已审查 | 2026-05-20 23:45 | 2026-05-28 22:23 |
| GHSA-C2C9-MFW7-P8HW CVE-2026-56268 | Flowise: Cross-Workspace Chatflow Disclosure via chatflows/apikey Endpoint Returns All Unprotected Chatflows | 中危 | npmflowise | 已审查 | 2026-05-20 23:45 | 2026-07-20 21:35 |
| GHSA-59FH-9F3P-7M39 | Flowise: Mass Assignment in PUT /api/v1/user Allows Authenticated Users to Override Password Hash and Bypass Password Change Verification | 中危 | npmflowise | 已审查 | 2026-05-20 23:44 | 2026-05-20 23:44 |
| GHSA-M837-XVXR-VQWG | Flowise: Hardcoded CORS wildcard on TTS endpoint enables cross-origin credential abuse from any webpage | 中危 | npmflowise | 已审查 | 2026-05-20 23:38 | 2026-05-20 23:38 |
| GHSA-MW8F-W6P8-XRF4 | wger: cross-tenant account deletion / deactivation / activation by gym.manage_gym + gym=None | 高危 | PyPIwger | 已审查 | 2026-05-20 23:37 | 2026-05-20 23:37 |
| GHSA-PXH5-6RRC-8RJV | OpenTofu: Excessive resource usage in "tofu init" when installing dependencies from attacker-controlled server | 低危 | Gogithub.com/opentofu/opentofu | 已审查 | 2026-05-20 23:35 | 2026-05-20 23:35 |
| GHSA-468C-VQ7P-GH64 CVE-2026-8468 | Plug: Unbounded buffer accumulation in multipart header parsing causes denial of service | 高危 | Hexplug | 已审查 | 2026-05-20 23:35 | 2026-05-20 23:35 |
| GHSA-HW27-4V2Q-5QFF CVE-2026-46431 | Algernon: Auto-refresh SSE event server sets Access-Control-Allow-Origin: * | 中危 | Gogithub.com/xyproto/algernon | 已审查 | 2026-05-20 23:34 | 2026-06-09 07:27 |
| GHSA-GJ84-924C-48FX CVE-2026-46430 | Algernon: Auto-refresh SSE event server binds to all interfaces by default on Linux/macOS | 中危 | Gogithub.com/xyproto/algernon | 已审查 | 2026-05-20 23:33 | 2026-05-20 23:33 |
| GHSA-PVW4-CVR4-97P8 CVE-2026-46421 | Supply chain compromise via malicious package versions (@cap-js/sqlite, @cap-js/postgres, @cap-js/db-service) | 严重 | npm@cap-js/db-service+2 | 已审查 | 2026-05-20 23:33 | 2026-05-20 23:33 |
| GHSA-5WXR-W449-57CM | Setup PHP: GitHub tokens configured by setup-php may be exposed through pinned affected Composer versions | 中危 | GitHub Actionsshivammathur/setup-php | 已审查 | 2026-05-20 23:32 | 2026-05-20 23:32 |
| GHSA-PQWM-Q9PV-PH8R CVE-2026-46420 | Setup PHP: Command Injection in Repository-Derived PHP Version Resolution | 中危 | GitHub Actionsshivammathur/setup-php | 已审查 | 2026-05-20 23:31 | 2026-05-20 23:31 |
| GHSA-7WX4-6VFF-V64P CVE-2026-45804 | Diffusers: TOCTOU Trust Remote Code Bypass | 高危 | PyPIdiffusers | 已审查 | 2026-05-20 23:31 | 2026-07-21 03:07 |
| GHSA-FVVM-949W-QJ4W CVE-2026-45792 | RTK improperly trusts project-local filter configuration, allowing silent tampering of command output shown to LLM | 中危 | crates.iortk | 已审查 | 2026-05-20 23:30 | 2026-07-21 05:12 |
| GHSA-XMJC-63PR-2MPG CVE-2026-6366 | Drupal core allows Object Injection | 中危 | Packagistdrupal/core | 已审查 | 2026-05-20 08:31 | 2026-06-06 02:18 |
| GHSA-PW6F-3999-XP7G CVE-2026-6367 | Drupal core allows Cross-Site Scripting (XSS) | 中危 | Packagistdrupal/core | 已审查 | 2026-05-20 08:31 | 2026-06-06 02:22 |
| GHSA-F3CJ-MJQM-FHVJ CVE-2026-6365 | Drupal core is Vulnerable to Cross-Site Scripting | 中危 | Packagistdrupal/core | 已审查 | 2026-05-20 08:31 | 2026-06-06 02:26 |
| GHSA-G9QC-QF28-HHQX CVE-2026-42526 | Apache Airflow Amazon provider: Prevent unauthorized access to team-scoped secrets in AWS Secrets Manager and SSM Parameter Store backends | 中危 | PyPIapache-airflow-providers-amazon | 已审查 | 2026-05-20 05:32 | 2026-06-06 00:37 |
| GHSA-524W-VQ63-2XHF CVE-2026-27173 | Apache Airflow CNCF Kubernetes provider: JWT Token Exposure in KubernetesExecutor Command-Line Arguments | 高危 | PyPIapache-airflow-providers-cncf-kubernetes | 已审查 | 2026-05-20 05:32 | 2026-06-06 00:37 |
| GHSA-RFH7-FXQC-Q52V CVE-2026-46417 | @angular/platform-server: SSRF via Hostname Hijacking | 高危 | npm@angular/platform-server | 已审查 | 2026-05-20 04:29 | 2026-07-16 06:04 |