检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-8GQ3-VP5J-2GRP CVE-2026-77413 | JSONata: Arbitrary Code Execution via crafted JSONata expressions | 严重 | npmjsonata | 已审查 | 2026-08-22 04:57 | 2026-08-22 04:57 |
| GHSA-XHJ3-7XW9-VR34 CVE-2026-77354 |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 高危 |
Gogithub.com/getkin/kin-openapi |
| 已审查 |
| 2026-08-22 04:56 |
| 2026-08-22 04:56 |
| GHSA-X2RJ-828P-HX9M CVE-2026-61539 | Xinference vulnerable to remote code execution via unsafe `eval()` in Llama3 tool-call parsing | 严重 | PyPIxinference | 已审查 | 2026-08-22 04:56 | 2026-08-22 04:56 |
| GHSA-HRWP-4HH9-C8R8 CVE-2026-59989 | Phalcon Volt compiler `join` filter compile-time PHP code injection (SSTI leads to RCE) | 严重 | Packagistphalcon/cphalcon | 已审查 | 2026-08-22 04:55 | 2026-08-28 00:33 |
| GHSA-MMFR-PMJX-HW9W CVE-2026-76905 | kin-openapi openai3filter: nil-pointer panic in ConvertErrors on malformed multipart/form-data body enables unauthenticated DoS | 高危 | Gogithub.com/getkin/kin-openapi | 已审查 | 2026-08-22 04:55 | 2026-08-22 04:55 |
| GHSA-26W5-6G95-GJ28 CVE-2026-64679 | Atlantis Workspace Handling has Path Traversal that Allows Out-of-Bounds Directory Deletion/Creation | 高危 | Gogithub.com/runatlantis/atlantis | 已审查 | 2026-08-22 04:55 | 2026-08-22 04:55 |
| GHSA-CQMQ-8755-7XVH CVE-2026-63421 | Keystone vulnerable to `graphql.maxTake` bypass with negative `take` | 高危 | npm@keystone-6/core | 已审查 | 2026-08-22 04:55 | 2026-08-22 04:55 |
| GHSA-JG4P-G6XJ-4QMF CVE-2026-61824 | Defuddle vulnerable to XSS via unescaped attribute interpolation in site extractors | 高危 | npmdefuddle | 已审查 | 2026-08-22 04:54 | 2026-08-22 04:54 |
| GHSA-MQJF-5F49-2FJH CVE-2026-76904 | GeoTools has unauthenticated SQL injection in the jsonArrayContains filter function against PostGIS layers | 严重 | Mavenorg.geotools.jdbc:gt-jdbc-postgis | 已审查 | 2026-08-22 04:25 | 2026-08-22 04:26 |
| GHSA-8HGV-XC77-JMCR | Grav: Page editors can inject arbitrary script into rendered pages via the Twig sandbox's assets.addJs/addCss allowlist, escalating to super-admin | 中危 | Packagistgetgrav/grav | 已审查 | 2026-08-22 03:14 | 2026-08-22 03:14 |
| GHSA-W4MQ-XH27-6XPX CVE-2026-63466 | Unleash: Global Mustache.escape override disables HTML escaping process-wide, enabling Slack/Teams link-injection via unrestricted username | 中危 | npmunleash-server | 已审查 | 2026-08-22 03:14 | 2026-08-22 03:14 |
| GHSA-5VF6-JRQR-78FJ CVE-2026-63004 | Unleash: Addon webhook URL is dialed server-side with no internal-address filtering, enabling SSRF to internal services / cloud metadata and exfiltration of configured request headers | 中危 | npmunleash-server | 已审查 | 2026-08-22 03:14 | 2026-08-22 03:14 |
| GHSA-R5PQ-6CHH-J3XP CVE-2026-63462 | Unleash: Unauthenticated single-request DoS via OpenAPI validation error formatter | 高危 | npmunleash-server | 已审查 | 2026-08-22 03:14 | 2026-08-22 03:14 |
| GHSA-QX2G-XRX7-VFH8 CVE-2026-72818 | NLTK TweetTokenizer vulnerable to denial of service through catastrophic regex backtracking | 高危 | PyPInltk | 已审查 | 2026-08-21 08:31 | 2026-09-02 23:16 |
| GHSA-8R62-W5WH-FC5M CVE-2026-67448 | Mailpit: WebSocket origin check bypass via percent-encoded path (regression of CVE-2026-22689) | 中危 | Gogithub.com/axllent/mailpit | 已审查 | 2026-08-21 05:34 | 2026-09-03 07:40 |
| GHSA-R553-M4FV-5V97 CVE-2026-67447 | Mailpit: SMTP DATA line reader buffers over-limit input before size enforcement | 中危 | Gogithub.com/axllent/mailpit | 已审查 | 2026-08-21 05:34 | 2026-09-03 07:40 |
| GHSA-F4JP-RW7W-CCWG CVE-2026-55451 | gettext-converter: Prototype pollution in js2i18next() via crafted translation keys | 中危 | npmgettext-converter | 已审查 | 2026-08-21 04:11 | 2026-08-21 04:11 |
| GHSA-JM5P-837G-RV8G | Wagtail: Improper restriction handling on Page translation API endpoint | 中危 | PyPIwagtail | 已审查 | 2026-08-21 02:45 | 2026-08-21 02:45 |
| GHSA-X5CX-W6P2-MXF2 | Wagtail: Improper permission handling when copying snippets | 中危 | PyPIwagtail | 已审查 | 2026-08-21 02:45 | 2026-08-21 02:45 |
| GHSA-C2XX-CJMH-9Q8F | Wagtail: Improper restriction handling on descendant collections in Documents and Images API | 中危 | PyPIwagtail | 已审查 | 2026-08-21 02:45 | 2026-08-21 02:45 |
| GHSA-92HV-J533-69WC | Wagtail: Identification of documents by SHA1 hash | 低危 | PyPIwagtail | 已审查 | 2026-08-21 02:45 | 2026-08-21 02:45 |
| GHSA-HQ84-X37P-J6Q5 | Winter: Reflected XSS through the search query parameter in the backend Table widget | 中危 | Packagistwinter/wn-backend-module | 已审查 | 2026-08-21 02:45 | 2026-08-21 02:45 |
| GHSA-P2CH-C2C3-4XM5 | Winter: CSRF through AJAX handler names reachable as backend page actions | 中危 | Packagistwinter/wn-backend-module | 已审查 | 2026-08-21 02:44 | 2026-08-21 02:44 |
| GHSA-5CWR-5JXG-PCF6 | Winter: Stored XSS through cached Brand Settings and Editor Settings custom styles | 中危 | Packagistwinter/wn-backend-module | 已审查 | 2026-08-21 02:44 | 2026-08-21 02:44 |
| GHSA-FM29-4MQ3-PHG6 | Winter: ImportExportController AJAX handlers bypass granular import/export permission gate | 高危 | Packagistwinter/wn-backend-module | 已审查 | 2026-08-21 02:44 | 2026-08-22 03:10 |