检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-3H23-RRPC-3P87 CVE-2026-46415 | Caddy Defender trusted proxy client IP bypass | 高危 | Gopkg.jsn.cam/caddy-defender | 已审查 | 2026-05-20 04:29 | 2026-05-20 04:29 |
| GHSA-6XWP-CP5H-Q856 CVE-2026-46412 | Malicious code in @beproduct/nestjs-auth (0.1.2 through 0.1.19) — Mini Shai-Hulud worm |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 严重 |
npm@beproduct/nestjs-auth |
| 已审查 |
| 2026-05-20 04:28 |
| 2026-05-20 04:28 |
| GHSA-3JMG-P96M-M328 CVE-2026-46410 | FileBrowser Quantum: unauthenticated user share share info | 高危 | Gogithub.com/gtsteffaniak/filebrowser+1 | 已审查 | 2026-05-20 04:14 | 2026-05-20 04:14 |
| GHSA-7HGR-7H44-33W2 | CamoFox MCP: Unauthenticated HTTP MCP browser-control surface | 高危 | npmcamofox-mcp | 已审查 | 2026-05-20 04:13 | 2026-05-20 04:13 |
| GHSA-73JC-5MRQ-PRW7 CVE-2026-46374 | SQLFluff: Uncontrolled Resource Consumption in SQLFluff Parser | 高危 | PyPIsqlfluff | 已审查 | 2026-05-20 04:10 | 2026-07-07 06:53 |
| GHSA-WMHF-FQC8-VXHH CVE-2026-46373 | SQLFluff: Recursive Stack Overflow in Parser | 高危 | PyPIsqlfluff | 已审查 | 2026-05-20 04:10 | 2026-07-07 06:53 |
| GHSA-QG89-QWWH-5F3J CVE-2026-46372 | SillyTavern: SSRF in SearXNG Search Proxy via Unvalidated baseUrl | 高危 | npmsillytavern | 已审查 | 2026-05-20 04:09 | 2026-06-09 18:32 |
| GHSA-M6XR-FVFG-5G64 CVE-2026-46378 | Dasel: Denial of service in dasel selector lexer due to infinite loop on unterminated regex literal | 高危 | Gogithub.com/tomwright/dasel/v3 | 已审查 | 2026-05-20 04:09 | 2026-05-20 04:09 |
| GHSA-M5J3-4634-C2VQ CVE-2026-46377 | Dasel: Index-out-of-range panic in dasel selector lexer on trailing backslash in quoted string | 高危 | Gogithub.com/tomwright/dasel/v3 | 已审查 | 2026-05-20 04:08 | 2026-05-20 04:08 |
| GHSA-32MQ-HPPH-XFVR CVE-2026-45783 | @libp2p/kad-dht: Unvalidated PUT_VALUE records allow unbounded disk exhaustion on DHT server nodes | 高危 | npm@libp2p/kad-dht | 已审查 | 2026-05-20 04:07 | 2026-06-11 21:30 |
| GHSA-6X44-W3XG-HQQF CVE-2026-46354 | Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft | 严重 | Gogithub.com/coder/coder+1 | 已审查 | 2026-05-20 04:04 | 2026-05-20 04:04 |
| GHSA-G8WJ-3CR3-6W7V CVE-2026-46342 | Nuxt: `__nuxt_island` endpoint does not bind responses to request props, enabling shared-cache poisoning | 低危 | npm@nuxt/nitro-server+1 | 已审查 | 2026-05-20 04:03 | 2026-07-09 01:35 |
| GHSA-62Q4-447F-WV8H CVE-2026-46338 | Regression in pymdownx.snippets reintroduces sibling-prefix path traversal bypass despite restrict_base_path | 中危 | PyPIpymdown-extensions | 已审查 | 2026-05-20 04:00 | 2026-05-20 04:00 |
| GHSA-22QR-RP27-J9WM CVE-2026-45805 | PenPot MCP REPL server binds to 0.0.0.0 with unauthenticated /execute endpoint — RCE | 高危 | npm@penpot/mcp | 已审查 | 2026-05-20 03:57 | 2026-05-20 03:57 |
| GHSA-2MGW-7Q6P-8GRG CVE-2026-45802 | FPDI: Memory Exhaustion and Endless Loop in FPDI leads to Denial of Service | 中危 | Packagistsetasign/fpdi | 已审查 | 2026-05-20 03:56 | 2026-06-13 03:27 |
| GHSA-7XPR-HC2W-34M9 CVE-2026-45799 | Wire: skipGroup() missing negative-length check allows 10-byte payload to crash any Wire-decoding service | 高危 | Mavencom.squareup.wire:wire-runtime+1 | 已审查 | 2026-05-20 03:54 | 2026-08-05 22:55 |
| GHSA-686C-7VGV-V3FX CVE-2026-45796 | Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint | 中危 | Gogithub.com/coder/coder+1 | 已审查 | 2026-05-20 03:53 | 2026-05-20 03:53 |
| GHSA-9R33-XHW8-4QQP CVE-2026-46357 | HAX CMS: Denial of Service using Malicious Import Request | 中危 | npm@haxtheweb/haxcms-nodejs | 已审查 | 2026-05-20 03:51 | 2026-06-09 19:57 |
| GHSA-5QWM-7PVP-W988 CVE-2026-45785 | OpenMcdf: Uncatchable infinite loop in DirectoryTree.TryGetDirectoryEntry on crafted CFB directory cycle | 中危 | NuGetOpenMcdf | 已审查 | 2026-05-20 03:50 | 2026-05-20 03:50 |
| GHSA-PHQJ-4MHP-Q6MQ CVE-2026-45784 | rust-openssl: Potential out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers | 中危 | crates.ioopenssl | 已审查 | 2026-05-20 03:50 | 2026-05-20 03:50 |
| GHSA-HCF7-66RW-9F5R CVE-2026-45773 | Turbo: Login callback CSRF/session fixation | 中危 | npmturbo | 已审查 | 2026-05-20 03:49 | 2026-06-29 23:30 |
| GHSA-3QCW-2RHX-2726 CVE-2026-45772 | Turbo: Unexpected local code execution during Yarn Berry detection | 低危 | npm@turbo/codemod+2 | 已审查 | 2026-05-20 03:46 | 2026-05-20 03:46 |
| GHSA-G53W-W6MJ-HRPP | MCP Gateway: Authority-injection and JWT/session bypass via the unauthenticated router hair-pin "router-key" / "mcp-init-host" path | 严重 | Gogithub.com/Kuadrant/mcp-gateway | 已审查 | 2026-05-20 03:42 | 2026-07-21 22:42 |
| GHSA-M9P2-FXP5-V3FP | Diesel: Command injection in Diesel's implementation of `COPY FROM`/`COPY TO` | 中危 | crates.iodiesel | 已审查 | 2026-05-20 03:42 | 2026-05-20 03:42 |
| GHSA-Q8X8-JRHJ-FH9P | Diesel: Possible unaligned data access for implementations of `SqliteAggregate` | 中危 | crates.iodiesel | 已审查 | 2026-05-20 03:39 | 2026-05-20 03:39 |