检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-MPMW-F6H6-3G26 | Winter: My Account preview exposes another backend user's profile by record ID | 中危 | Packagistwinter/wn-backend-module | 已审查 | 2026-08-21 02:44 | 2026-08-21 02:44 |
| GHSA-7MPF-4465-7FC2 | Winter: Stored XSS through Backend List widget image columns |
当前筛选结果 35,190 条 · 时间按北京时间显示
Packagistwinter/wn-backend-module |
| 已审查 |
| 2026-08-21 02:44 |
| 2026-08-21 02:44 |
| GHSA-RXHG-VCWW-2MPW | Fleet: ORDER BY column injection on activity list endpoints | 低危 | Gogithub.com/fleetdm/fleet/v4 | 已审查 | 2026-08-21 02:44 | 2026-08-21 02:44 |
| GHSA-Q9C5-PP7M-FM2G | Fleet: Unauthenticated download of in-house iOS app binaries via predictable URLs | 中危 | Gogithub.com/fleetdm/fleet/v4 | 已审查 | 2026-08-21 02:44 | 2026-08-21 02:44 |
| GHSA-8CFW-PCWH-V63W | Winter: Authenticated Twig sandbox escape in CMS SecurityPolicy (bypass of CVE-2024-54149) | 高危 | Packagistwinter/wn-system-module | 已审查 | 2026-08-21 02:44 | 2026-08-21 02:44 |
| GHSA-2223-F22X-24CQ | Winter: Local File Inclusion through =include directives in JavaScript asset compilation | 中危 | Packagistwinter/wn-system-module | 已审查 | 2026-08-21 02:44 | 2026-08-21 02:44 |
| GHSA-4899-MPCH-38P3 CVE-2026-63202 | netty-incubator-codec-ohttp BinaryHttpParser: Unauthenticated CPU-exhaustion DoS via infinite loop in field-section decoding | 高危 | Mavenio.netty.incubator:netty-incubator-codec-bhttp | 已审查 | 2026-08-21 02:43 | 2026-08-21 02:43 |
| GHSA-58FP-MCX6-7QF9 CVE-2026-63179 | Winter: Local File Inclusion through @import directives in LESS compilation of backend customizable stylesheets and theme assets | 中危 | Packagistwinter/wn-backend-module | 已审查 | 2026-08-21 02:43 | 2026-08-21 02:43 |
| GHSA-HMQ9-67W8-J5PW CVE-2026-61827 | netty-incubator-codec-ohttp: BinaryHttpParser should enforce limits for variable lengths fields | 高危 | Mavenio.netty.incubator:netty-incubator-codec-bhttp | 已审查 | 2026-08-21 02:43 | 2026-08-21 02:43 |
| GHSA-8CFX-WX3Q-MH5Q CVE-2026-63124 | netty-incubator-codec-ohttp: Binary HTTP parser infinite loop on known-length field section boundary | 高危 | Mavenio.netty.incubator:netty-incubator-codec-bhttp | 已审查 | 2026-08-21 02:43 | 2026-08-21 02:43 |
| GHSA-PGRF-4654-3GQ8 CVE-2026-61799 | netty-incubator-codec-ohttp: Binary HTTP parser unchecked varint length overflow causes decoder crash | 中危 | Mavenio.netty.incubator:netty-incubator-codec-bhttp | 已审查 | 2026-08-21 02:43 | 2026-08-21 02:43 |
| GHSA-2MC4-J865-9Q4R CVE-2026-61798 | netty-incubator-codec-ohttp: BoringSSL HPKE private key bytes exposed through toString() and exception messages | 高危 | Mavenio.netty.incubator:netty-incubator-codec-ohttp-hpke-classes-boringssl | 已审查 | 2026-08-21 02:43 | 2026-08-21 02:43 |
| GHSA-8QJ2-C6Q4-F399 CVE-2026-61663 | django CMS: Missing authorization in `render_object_structure` discloses non-PageContent placeholder structure to low-privileged staff | 中危 | PyPIdjango-cms | 已审查 | 2026-08-21 02:42 | 2026-08-21 02:42 |
| GHSA-6X92-6VX4-5FWR CVE-2026-63003 | django CMS: Broken access control in page *Duplicate* allows reading the content of any page (cross-site / restriction bypass) | 中危 | PyPIdjango-cms | 已审查 | 2026-08-21 02:42 | 2026-08-21 02:42 |
| GHSA-HVQ6-2R72-P2X7 CVE-2026-75526 | django CMS: Stored XSS in edit-mode plugin exception rendering | 中危 | PyPIdjango-cms | 已审查 | 2026-08-21 02:42 | 2026-08-21 02:42 |
| GHSA-42VX-43VC-X6PR CVE-2026-57570 | Laravel Backpack CRUD: HasMany/MorphMany relation fields allow cross-tenant record re-parenting (IDOR) via attachManyRelation | 中危 | Packagistbackpack/crud | 已审查 | 2026-08-21 02:42 | 2026-08-21 02:42 |
| GHSA-3VRH-M9W7-V94F CVE-2026-55468 | Wagtail: Improper restriction handling on Pages admin API | 中危 | PyPIwagtail | 已审查 | 2026-08-21 02:42 | 2026-08-21 02:42 |
| GHSA-GHVF-QF6H-G8X5 | NocoBase: Arbitrary File Write chained with Local file Inclusion leads to Remote code execution | 高危 | npm@nocobase/server | 已审查 | 2026-08-21 02:42 | 2026-08-21 02:42 |
| GHSA-VGXM-H9GX-H9W7 CVE-2026-54624 | django CMS: Structure endpoint bypasses page-view permission | 中危 | PyPIdjango-cms | 已审查 | 2026-08-21 02:42 | 2026-08-21 02:42 |
| GHSA-4XFR-4P46-GC6P CVE-2026-54622 | django CMS: Clipboard copy IDOR discloses unauthorized plugin content | 中危 | PyPIdjango-cms | 已审查 | 2026-08-21 02:42 | 2026-08-21 02:42 |
| GHSA-23M2-MGHX-VQMF CVE-2026-54263 | Wagtail: Reflected XSS in dynamic image URL generator view | 高危 | PyPIwagtail | 已审查 | 2026-08-21 02:40 | 2026-08-21 02:40 |
| GHSA-8634-MR4J-R72C CVE-2026-54262 | Wagtail: Pages translations can be created without page permissions when using simple_translation | 中危 | PyPIwagtail | 已审查 | 2026-08-21 02:40 | 2026-08-21 02:40 |
| GHSA-R6P4-GRQ7-XM4M CVE-2026-54261 | Wagtail: Improper permission handling in image preview | 中危 | PyPIwagtail | 已审查 | 2026-08-21 02:40 | 2026-08-21 02:40 |
| GHSA-F2P5-J6FG-5CXF CVE-2026-54260 | Wagtail: Denial of service via unbounded filter specs in the image preview | 中危 | PyPIwagtail | 已审查 | 2026-08-21 02:40 | 2026-08-21 02:40 |
| GHSA-H54R-XQ46-QWQM CVE-2026-54259 | Wagtail: Improper restriction handling on Documents and Images chosen endpoints | 中危 | PyPIwagtail | 已审查 | 2026-08-21 02:40 | 2026-08-21 02:40 |