检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-RG3G-4RW9-GQRP CVE-2026-45737 | Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations | 中危 | Gogithub.com/argoproj/argo-cd/v3 | 已审查 | 2026-05-19 23:54 | 2026-05-19 23:54 |
| GHSA-FPXJ-M5Q8-FPHW CVE-2026-45713 | Mailpit: Unauthenticated remote memory-exhaustion DoS via unlimited SMTP DATA and /api/v1/send body sizes |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 高危 |
Gogithub.com/axllent/mailpit |
| 已审查 |
| 2026-05-19 23:54 |
| 2026-09-03 07:39 |
| GHSA-W4VJ-R5PG-3722 CVE-2026-45712 | Mailpit: Concurrent map read & write in proxy CSS rewriter - remote unauth crash (fatal error: concurrent map read and map write) | 中危 | Gogithub.com/axllent/mailpit | 已审查 | 2026-05-19 23:53 | 2026-09-03 07:39 |
| GHSA-QX5X-85P8-VG4J CVE-2026-45711 | Mailpit: Path traversal & arbitrary file write in mailpit dump --http via attacker-controlled message IDs | 中危 | Gogithub.com/axllent/mailpit | 已审查 | 2026-05-19 23:53 | 2026-09-03 07:39 |
| GHSA-J3FJ-QPPJ-FMMC CVE-2026-45709 | Mailpit has an incomplete fix for GHSA-6jxm: HTML check still permits SSRF to private/loopback/IMDS via missing IP-filter dialer | 中危 | Gogithub.com/axllent/mailpit | 已审查 | 2026-05-19 23:52 | 2026-09-03 07:39 |
| GHSA-X5W9-XH9R-MVFC CVE-2026-45692 | Caddy: Remote Admin Authorization Bypass in `/config` API via Array Index Normalization | 中危 | Gogithub.com/caddyserver/caddy/v2 | 已审查 | 2026-05-19 23:51 | 2026-07-20 21:43 |
| GHSA-6M52-M754-PW2G CVE-2026-45670 | Nuxt: Dev server exposes built source over LAN to malicious sites (incomplete fix for GHSA-4gf7-ff8x-hq99) | 中危 | npm@nuxt/rspack-builder+1 | 已审查 | 2026-05-19 23:51 | 2026-07-09 01:35 |
| GHSA-FX6J-W5W5-H468 CVE-2026-45669 | Nuxt: Reflected XSS in `navigateTo()` external redirect | 中危 | npmnuxt | 已审查 | 2026-05-19 23:49 | 2026-07-09 01:35 |
| GHSA-XM96-GFJX-JCRC | ORAS Java: Path traversal in pullArtifact via attacker-controlled org.opencontainers.image.title annotation | 高危 | Mavenland.oras:oras-java-sdk | 已审查 | 2026-05-19 23:47 | 2026-05-19 23:47 |
| GHSA-HV85-774V-26FG | auth-fetch-mcp: SSRF and disk exfiltration via unvalidated auth_fetch and download_media URLs | 高危 | npmauth-fetch-mcp | 已审查 | 2026-05-19 23:47 | 2026-05-19 23:47 |
| GHSA-XMPW-2VMM-P4P6 CVE-2026-45758 | Malicious code in guardrails-ai 0.10.1 (supply chain compromise) | 严重 | PyPIguardrails-ai | 已审查 | 2026-05-19 23:40 | 2026-06-09 21:13 |
| GHSA-WG5X-3G47-V38R CVE-2026-45581 | fabric-chaincode-java: TLS Private Key Password Disclosed in INFO Startup Logs in Chaincode-as-a-Service Mode | 中危 | Mavenorg.hyperledger.fabric-chaincode-java:fabric-chaincode-shim | 已审查 | 2026-05-19 23:40 | 2026-06-09 21:12 |
| GHSA-2V5F-5R6W-P67R CVE-2026-45781 | MCP Registry: OCI validator skips ownership check on upstream rate limits | 低危 | Gogithub.com/modelcontextprotocol/registry | 已审查 | 2026-05-19 23:39 | 2026-05-19 23:39 |
| GHSA-C656-JCX2-7PQJ CVE-2026-45576 | zrok copy writes attacker-controlled WebDAV paths outside the destination root | 高危 | Gogithub.com/openziti/zrok+1 | 已审查 | 2026-05-19 23:38 | 2026-05-19 23:38 |
| GHSA-CRHJ-59GH-8X96 CVE-2026-45571 | go-git: Crafted repositories may modify main and submodule .git directories | 中危 | Gogithub.com/go-git/go-git+2 | 已审查 | 2026-05-19 23:38 | 2026-06-09 07:43 |
| GHSA-RG3P-P27C-2F39 CVE-2025-70950 | gohttp is vulnerable to directory traversal via a crafted request | 高危 | Gogithub.com/itang/gohttp | 已审查 | 2026-05-19 23:31 | 2026-06-05 03:00 |
| GHSA-FHHQ-H4HG-549X CVE-2025-51427 | ModelScope is vulnerable to arbitrary code injection via a crafted module | 高危 | PyPImodelscope | 已审查 | 2026-05-19 23:31 | 2026-06-05 02:52 |
| GHSA-96V6-HQ43-X9H4 CVE-2026-2586 | GlassFish's Administration Console is Vulnerable to RCE | 严重 | Mavenorg.glassfish.jsftemplating:jsftemplating+1 | 已审查 | 2026-05-19 23:31 | 2026-06-05 03:10 |
| GHSA-29WV-CV7P-XJC2 CVE-2026-2587 | GlassFish's gadget handler is vulnerable to RCE | 严重 | Mavenorg.glassfish.jsftemplating:jsftemplating+1 | 已审查 | 2026-05-19 23:31 | 2026-06-05 03:21 |
| GHSA-8364-HFQJ-PWM6 CVE-2026-47323 | Camel-CXF and Camel-Knative Message Header are Vulnerable to Injection via Missing Inbound Filtering | 严重 | Mavenorg.apache.camel:camel-cxf-rest | 已审查 | 2026-05-19 23:31 | 2026-06-05 02:49 |
| GHSA-M7CR-M3PV-HGRP CVE-2026-45570 | go-git: Improper single-quote escaping in go-git SSH transport | 低危 | Gogithub.com/go-git/go-git+2 | 已审查 | 2026-05-19 23:21 | 2026-06-09 07:42 |
| GHSA-JH67-HWQW-M5R7 CVE-2026-45568 | rok Python ProxyShare can be used as an SSRF proxy through absolute URL paths | 严重 | PyPIzrok | 已审查 | 2026-05-19 23:16 | 2026-05-19 23:16 |
| GHSA-X3X5-7H4H-GWXG CVE-2026-46511 | HAXcms: Mass Token Exfiltration and Cross-Tenant Hijack | 高危 | npm@haxtheweb/haxcms-nodejs | 已审查 | 2026-05-19 22:47 | 2026-06-09 19:56 |
| GHSA-JH3H-RPXG-FR36 CVE-2026-46396 | Stored XSS via <iframe> in HAX CMS allows access to sensitive client-side data and account takeover | 高危 | npm@haxtheweb/haxcms-nodejs+2 | 已审查 | 2026-05-19 22:46 | 2026-06-09 19:56 |
| GHSA-6C8G-9HFH-PQ5H CVE-2026-46395 | HAXcms: Private Key Disclosure via Broken HMAC Implementation | 严重 | npm@haxtheweb/haxcms-nodejs | 已审查 | 2026-05-19 22:44 | 2026-06-09 19:56 |