检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-FJQ3-FFVR-VM46 CVE-2026-45683 | OpenTelemetry eBPF Instrumentation: Java TLS ioctl kprobe allows kernel memory disclosure | 低危 | Gogo.opentelemetry.io/obi | 已审查 | 2026-05-19 04:12 | 2026-06-09 18:58 |
| GHSA-R6C9-G6Q5-QRF9 CVE-2026-45681 | OpenTelemetry eBPF Instrumentation: CPU-mismatch fallback uses 256-byte buffer with 8KB size |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 中危 |
Gogo.opentelemetry.io/obi |
| 已审查 |
| 2026-05-19 04:11 |
| 2026-06-09 18:58 |
| GHSA-89C6-VPCJ-7VJ4 CVE-2026-45680 | OpenTelemetry eBPF Instrumentation: Unbounded BPF internal metrics replay can exhaust CPU | 中危 | Gogo.opentelemetry.io/obi | 已审查 | 2026-05-19 04:11 | 2026-06-09 18:58 |
| GHSA-8X9C-MQXV-Q2PP CVE-2026-35433 | Microsoft Security Advisory CVE-2026-35433 – .NET Elevation of Privilege Vulnerability | 高危 | NuGetMicrosoft.WindowsDesktop.App.Runtime.win-arm64+2 | 已审查 | 2026-05-19 03:20 | 2026-07-09 01:41 |
| GHSA-9V76-4QCC-FRGH CVE-2026-42899 | Microsoft Security Advisory CVE-2026-42899 – ASP.NET Core Denial of Service Vulnerability | 高危 | NuGetMicrosoft.AspNetCore.App.Runtime.linux-arm+11 | 已审查 | 2026-05-19 03:10 | 2026-05-19 03:10 |
| GHSA-RG75-Q538-X34V CVE-2026-32175 | Microsoft Security Advisory CVE-2026-32175 – .NET Core Tampering Vulnerability | 高危 | NuGetMicrosoft.NetCore.App.Runtime.win-arm+3 | 已审查 | 2026-05-19 03:08 | 2026-05-19 03:08 |
| GHSA-58QX-3VCG-4XPX CVE-2026-45736 | ws: Uninitialized memory disclosure | 中危 | npmws | 已审查 | 2026-05-19 03:02 | 2026-05-19 03:02 |
| GHSA-3MJV-375J-6H92 CVE-2026-45731 | AVideo: Authenticated Arbitrary File Read in view/update.php | 中危 | PackagistWWBN/AVideo | 已审查 | 2026-05-19 03:01 | 2026-06-09 18:28 |
| GHSA-F4J7-R4Q5-QW2C CVE-2026-45829 | ChromaDB Python project has a pre-authentication code injection vulnerability | 严重 | PyPIchromadb | 已审查 | 2026-05-19 02:31 | 2026-05-30 03:15 |
| GHSA-QR28-P3WR-MXQ3 CVE-2025-57282 | ngrok is Vulnerable to Command Injection | 高危 | npmngrok | 已审查 | 2026-05-19 02:31 | 2026-05-30 03:10 |
| GHSA-PGVV-Q3WF-MM9M CVE-2026-45678 | OpenTelemetry eBPF Instrumentation: Postgres BIND parsing can panic on malformed payloads | 高危 | Gogo.opentelemetry.io/obi | 已审查 | 2026-05-19 01:56 | 2026-06-09 18:58 |
| GHSA-8RRQ-WCG8-CV5Q CVE-2026-45679 | OpenTelemetry eBPF Instrumentation: Redis error text is exported in span status messages | 中危 | Gogo.opentelemetry.io/obi | 已审查 | 2026-05-19 01:56 | 2026-06-09 18:57 |
| GHSA-WP73-MWGF-4JQ9 CVE-2026-45676 | OpenTelemetry eBPF Instrumentation: Unsafe fastelf parsing allows malformed ELF to crash agent | 中危 | Gogo.opentelemetry.io/obi | 已审查 | 2026-05-19 01:56 | 2026-06-09 18:57 |
| GHSA-JGG6-4RPR-WFH7 | Broken dropper in @mistralai/mistralai, @mistralai/mistralai-azure, @mistralai/mistralai-gcp | 低危 | npm@mistralai/mistralai+2 | 已审查 | 2026-05-19 01:55 | 2026-05-19 01:55 |
| GHSA-WX9M-WX4F-4CMG | Malicious dropper in mistralai 2.4.6 PyPI package | 严重 | PyPImistralai | 已审查 | 2026-05-19 01:55 | 2026-05-19 01:55 |
| GHSA-CWPJ-H54C-XJPX CVE-2026-45031 | ImageMagick: Policy Bypass in PSD decoder | 中危 | NuGetMagick.NET-Q16-AnyCPU+17 | 已审查 | 2026-05-19 01:53 | 2026-06-11 21:30 |
| GHSA-R73H-97W8-M54H CVE-2026-32687 | Postgrex: Channel-name SQL injection in `Postgrex.Notifications.listen/3` | 高危 | Hexpostgrex | 已审查 | 2026-05-19 01:53 | 2026-05-19 01:53 |
| GHSA-RG2X-37C3-W2RH CVE-2026-42306 | Docker: Race condition in docker cp allows bind mount redirection to host path | 高危 | Gogithub.com/docker/docker+2 | 已审查 | 2026-05-19 01:53 | 2026-06-13 05:59 |
| GHSA-VP62-88P7-QQF5 CVE-2026-41568 | Docker: Race condition in docker cp allows creation of arbitrary empty files on the host via symlink swap | 中危 | Gogithub.com/docker/docker+2 | 已审查 | 2026-05-19 01:52 | 2026-06-13 05:59 |
| GHSA-MF33-GV72-W2H5 CVE-2026-45727 | CloakBrowser: Unauthenticated path traversal via fingerprint parameter in cloakserve leads to arbitrary directory deletion | 高危 | PyPIcloakbrowser | 已审查 | 2026-05-19 01:50 | 2026-06-09 18:50 |
| GHSA-CR6R-HMJ8-PR7R CVE-2026-45358 | ImageMagick: Out-of-Bounds Read of a single byte in meta encoder | 中危 | NuGetMagick.NET-Q16-AnyCPU+17 | 已审查 | 2026-05-19 01:48 | 2026-06-11 21:30 |
| GHSA-VHRH-72HQ-W8M7 CVE-2026-45359 | ImageMagick: Out-of-Bounds Read in connected components when the user supplies an invalid keep-top define | 中危 | NuGetMagick.NET-Q16-AnyCPU+17 | 已审查 | 2026-05-19 01:48 | 2026-06-11 21:30 |
| GHSA-363W-HVWH-W7M6 CVE-2026-45719 | Budibase: CouchDB Reduce Injection via Unsanitized Calculation Parameter in V1 Views API | 中危 | npm@budibase/server | 已审查 | 2026-05-19 01:47 | 2026-06-09 07:51 |
| GHSA-X86F-5XW2-FM2R CVE-2026-41567 | Docker: `PUT /containers/{id}/archive` executes container binary on the host | 高危 | Gogithub.com/docker/docker+2 | 已审查 | 2026-05-19 01:47 | 2026-06-09 19:55 |
| GHSA-3263-V5V9-XQ8Q CVE-2026-45718 | Budibase: Row Action Trigger Bypasses View Row Filter Security Boundary Allowing Action on Out-of-Scope Rows | 中危 | npmbudibase | 已审查 | 2026-05-19 01:44 | 2026-06-09 07:51 |