检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-CRC3-H8V6-QH57 CVE-2026-45803 | GitHub CLI: GitHub Actions log output in `gh run view` allows terminal escape sequence injection | 低危 | Gogithub.com/cli/cli+1 | 已审查 | 2026-05-20 03:37 | 2026-05-20 03:37 |
| GHSA-GX7W-56W6-G48X | Caddy: Remote Admin Authorization Bypass on PKI Endpoints via Prefix-Based Path Matching |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 中危 |
Gogithub.com/caddyserver/caddy/v2 |
| 已审查 |
| 2026-05-20 03:36 |
| 2026-05-20 03:36 |
| GHSA-WWHQ-W58M-W29C | Caddy CVE-2026-30852 Fix Bypass | 中危 | Gogithub.com/caddyserver/caddy/v2 | 已审查 | 2026-05-20 03:35 | 2026-05-20 03:35 |
| GHSA-M23H-6MWM-39M8 | Kong Ingress Controller for Kubernetes (KIC): Cross-namespace TLS Secret Exfiltration in Gateways with GatewayClass missing `konghq.com/gatewayclass-unmanaged: 'true'` annotation | 中危 | Gogithub.com/kong/kubernetes-ingress-controller+2 | 已审查 | 2026-05-20 03:30 | 2026-05-20 03:30 |
| GHSA-3278-C88V-XRH4 | Kong Ingress Controller for Kubernetes (KIC): Secret-backed plugin configurations leak through non-sensitive diagnostics endpoint | 中危 | Gogithub.com/kong/kubernetes-ingress-controller+2 | 已审查 | 2026-05-20 03:28 | 2026-06-09 04:13 |
| GHSA-RF5Q-VWXW-GMRF CVE-2026-39806 | Bandit: Unauthenticated DoS via chunked request trailers in Bandit HTTP/1 decoder | 高危 | Hexbandit | 已审查 | 2026-05-20 03:25 | 2026-06-09 04:17 |
| GHSA-9Q9Q-324X-93R2 CVE-2026-39803 | Bandit: Unauthenticated one-shot DoS via `Transfer-Encoding: chunked` | 高危 | Hexbandit | 已审查 | 2026-05-20 03:23 | 2026-06-09 04:17 |
| GHSA-FHH6-4QXV-RPQJ CVE-2026-46339 | 9router: Unauthenticated Remote Code Execution via unprotected MCP custom plugin routes | 严重 | npm9router | 已审查 | 2026-05-20 03:22 | 2026-05-20 03:22 |
| GHSA-2Q4C-3MRW-63C3 CVE-2026-45695 | Kopia: RCE via SSH ProxyCommand Injection | 严重 | Gogithub.com/kopia/kopia | 已审查 | 2026-05-20 03:18 | 2026-05-20 03:18 |
| GHSA-9WXQ-MWQW-8HHG CVE-2026-6009 | Jaspersoft Reports: Java Deserialization Vulnerability Lleads to Remote Code Execution (RCE) | 高危 | Mavennet.sf.jasperreports:jasperreports | 已审查 | 2026-05-20 02:32 | 2026-07-11 05:42 |
| GHSA-XP6R-8PCC-XV5P CVE-2026-31069 | BillaBear is Vulnerable to SQL Injection in the EventRepository | 高危 | Packagistbillabear/billabear | 已审查 | 2026-05-20 02:32 | 2026-06-05 05:38 |
| GHSA-9CFW-F3F9-7MM7 CVE-2026-31072 | APScheduler's JSONSerializer and CBORSerializer are vulnerable to Remote Code Execution (RCE) via Insecure Deserialization | 严重 | PyPIapscheduler | 已审查 | 2026-05-20 02:32 | 2026-06-05 05:36 |
| GHSA-JWP7-WG77-3W9V CVE-2026-46341 | Apify Model Context Protocol (MCP) server: Domain Allowlist Bypass in fetch-apify-docs via String Prefix Matching | 中危 | npm@apify/actors-mcp-server | 已审查 | 2026-05-20 00:34 | 2026-05-20 00:34 |
| GHSA-82RC-GXRG-V4GF CVE-2026-46426 | Budibase: Unrestricted Upload of File with Dangerous Type | 高危 | npmbudibase | 已审查 | 2026-05-20 00:31 | 2026-06-09 07:51 |
| GHSA-6VP2-6R7M-2JVX CVE-2026-46424 | Budibase: Missing Cache Invalidation on Public API Role Unassignment Allows Revoked Users to Retain Privileges for Up to 1 Hour | 中危 | npm@budibase/backend-core | 已审查 | 2026-05-20 00:30 | 2026-06-09 07:51 |
| GHSA-W4QQ-74H6-58WQ CVE-2026-46337 | AVideo: Unauthenticated Arbitrary Image Read via Path Traversal in `view/img/image404Raw.php` | 中危 | PackagistWWBN/AVideo | 已审查 | 2026-05-20 00:25 | 2026-06-09 18:28 |
| GHSA-JGGG-4JG4-V7C6 CVE-2026-45740 | protobufjs: Denial of Service via unbounded recursive JSON descriptor expansion | 中危 | npmprotobufjs | 已审查 | 2026-05-20 00:21 | 2026-05-20 00:21 |
| GHSA-FHVH-VW7H-9XF3 | libcrux-ml-dsa: Signature Verification on AVX2 Platforms Mishandles Edge Case | 高危 | crates.iolibcrux-ml-dsa | 已审查 | 2026-05-20 00:18 | 2026-05-20 00:18 |
| GHSA-HC3C-63HC-2R9F | libcrux: Potential Panic on Overlong Ciphertext Buffer | 高危 | crates.iolibcrux-chacha20poly1305 | 已审查 | 2026-05-20 00:18 | 2026-05-20 00:18 |
| GHSA-4GPH-2HHR-5MWG | Envoy AI Proxy - MCP Message Smuggling Vulnerability | 中危 | Gogithub.com/envoyproxy/ai-gateway | 已审查 | 2026-05-20 00:18 | 2026-05-20 00:18 |
| GHSA-F9F8-RM49-7JV2 CVE-2026-45793 | Github Actions issued GITHUB_TOKEN disclosure in GitHub Actions logs | 高危 | Packagistcomposer/composer | 已审查 | 2026-05-20 00:17 | 2026-07-21 03:12 |
| GHSA-3875-8GCX-7V46 CVE-2026-56348 | n8n: Credential exfiltration via Allowed HTTP Request Domains Bypass | 中危 | npmn8n | 已审查 | 2026-05-20 00:17 | 2026-07-20 21:34 |
| GHSA-2VX9-7WPG-88JQ | n8n: Legacy ExecuteWorkflow Node Bypassed File Path Restrictions | 中危 | npmn8n | 已审查 | 2026-05-19 23:55 | 2026-05-19 23:55 |
| GHSA-X97M-QP5C-W9XJ CVE-2026-45739 | Strawberry GraphQL: Default GraphiQL may expose HTTP headers in URLs | 低危 | PyPIstrawberry-graphql | 已审查 | 2026-05-19 23:55 | 2026-06-09 19:52 |
| GHSA-H98R-WV3H-FR38 CVE-2026-45738 | Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation | 高危 | Gogithub.com/argoproj/argo-cd+2 | 已审查 | 2026-05-19 23:54 | 2026-05-19 23:54 |