检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-6FXP-P9MG-Q64W CVE-2025-54363 | Withdrawn Advisory: Microsoft Knack ReDoS Vulnerability in the Introspection Module 已撤回 | 低危 | PyPIknack | 已审查 | 2025-08-20 11:30 | 2025-08-30 04:14 |
当前筛选结果 998 条 · 时间按北京时间显示
| GHSA-XQRQ-4MGF-FF32 CVE-2025-50817 |
Withdrawn Advisory: Python-Future Module Arbitrary Code Execution via Unintended Import of test.py 已撤回 |
| 高危 |
PyPIfuture |
| 已审查 |
| 2025-08-15 02:31 |
| 2025-10-07 04:33 |
| GHSA-Q4XX-MC3Q-23X8 | Duplicate Advisory: Flowise vulnerable to RCE via Dynamic function constructor injection 已撤回 | 严重 | npmflowise | 已审查 | 2025-08-14 20:30 | 2025-10-04 05:50 |
| GHSA-PWQ7-2GVJ-VG9V | Duplicate Advisory: Keras safe mode bypass vulnerability 已撤回 | 高危 | PyPIkeras | 已审查 | 2025-08-11 17:30 | 2025-08-13 03:24 |
| GHSA-VH9X-PHQ6-FX54 | Duplicate Advisory: Denial of service via malicious preflight requests in github.com/rs/cors 已撤回 | 低危 | Gogithub.com/rs/cors | 已审查 | 2025-08-07 05:31 | 2025-08-07 06:09 |
| GHSA-QJ5R-2R5P-PHC7 | Duplicate Advisory: Keycloak-services SMTP Inject Vulnerability 已撤回 | 中危 | Mavenorg.keycloak:keycloak-services | 已审查 | 2025-08-07 02:31 | 2025-09-18 04:23 |
| GHSA-522R-9946-FW43 | Duplicate Advisory: CIRCL-Fourq: Missing and wrong validation can lead to incorrect results 已撤回 | 低危 | Gogithub.com/cloudflare/circl | 已审查 | 2025-08-06 17:30 | 2025-08-07 01:39 |
| GHSA-C2FV-2FMJ-9XRX | Duplicate Advisory: ssrfcheck has Incomplete IP Address Deny List that leads to Server-Side Request Forgery Vulnerability 已撤回 | 高危 | npmssrfcheck | 已审查 | 2025-07-28 14:30 | 2026-05-06 04:25 |
| GHSA-RFX3-FFRP-6875 | Duplicate Advisory: sequoia-openpgp vulnerable to out-of-bounds array access leading to panic 已撤回 | 低危 | crates.iosequoia-openpgp | 已审查 | 2025-07-28 11:31 | 2025-07-28 23:55 |
| GHSA-Q5H2-XQ96-6GMC | Duplicate Advisory: buffered-reader vulnerable to out-of-bounds array access leading to panic 已撤回 | 低危 | crates.iobuffered-reader | 已审查 | 2025-07-28 11:31 | 2025-07-28 23:59 |
| GHSA-GW89-822V-8V8G | Duplicate Advisory: `openssl` `X509VerifyParamRef::set_host` buffer over-read 已撤回 | 中危 | crates.ioopenssl | 已审查 | 2025-07-28 11:31 | 2025-07-28 23:54 |
| GHSA-G693-V3JR-8HCR | Duplicate Advisory: `ed25519-dalek` Double Public Key Signing Function Oracle Attack 已撤回 | 中危 | crates.ioed25519-dalek | 已审查 | 2025-07-28 11:31 | 2025-07-28 23:53 |
| GHSA-5C5J-JMHX-Q2GR | Duplicate Advisory: gix-transport code execution vulnerability 已撤回 | 中危 | crates.iogix-transport | 已审查 | 2025-07-28 11:31 | 2025-07-28 23:37 |
| GHSA-624C-2H52-GF7F | Duplicate Advisory: Remotely exploitable denial of service in Rosenpass 已撤回 | 中危 | crates.iorosenpass | 已审查 | 2025-07-28 08:30 | 2025-07-28 23:08 |
| GHSA-97F8-H76H-F297 | Duplicate Advisory: Unauthenticated Nonce Increment in snow 已撤回 | 低危 | crates.iosnow | 已审查 | 2025-07-28 08:30 | 2025-07-28 23:56 |
| GHSA-286M-6PG9-V42V | Duplicate Advisory: Multiple issues involving quote API in shlex 已撤回 | 低危 | crates.ioshlex | 已审查 | 2025-07-28 08:30 | 2025-07-28 23:57 |
| GHSA-P444-P2RM-HVRW | Duplicate Advisory: transpose: Buffer overflow due to integer overflow 已撤回 | 中危 | crates.iotranspose | 已审查 | 2025-07-28 05:32 | 2025-07-28 23:53 |
| GHSA-J87P-GJR6-M4PV | Duplicate Advisory: serde-json-wasm stack overflow during recursive JSON parsing 已撤回 | 低危 | crates.ioserde-json-wasm | 已审查 | 2025-07-28 05:32 | 2025-07-28 23:54 |
| GHSA-RM83-PXJX-PR5J | Duplicate Advisory: CosmWasm affected by arithmetic overflows 已撤回 | 低危 | crates.iocosmwasm-std | 已审查 | 2025-07-28 05:32 | 2025-07-28 23:52 |
| GHSA-G97W-MW7G-V3JV | Duplicate Advisory: Low severity (DoS) vulnerability in sequoia-openpgp 已撤回 | 低危 | crates.iosequoia-openpgp | 已审查 | 2025-07-28 05:32 | 2025-07-28 23:36 |
| GHSA-4HFF-HH47-7788 | Duplicate Advisory: curve25519-dalek has timing variability in `curve25519-dalek`'s `Scalar29::sub`/`Scalar52::sub` 已撤回 | 低危 | crates.iocurve25519-dalek | 已审查 | 2025-07-28 05:32 | 2025-07-28 23:46 |
| GHSA-49JM-G4M8-X53P CVE-2025-45406 | Withdrawn Advisory: CodeIgniter4 Cross-Site Scripting Vulnerability in debugbar_time Parameter 已撤回 | 中危 | Packagistcodeigniter4/framework | 已审查 | 2025-07-26 02:30 | 2025-07-29 22:30 |
| GHSA-CMM8-GW4M-26CW CVE-2025-43712 | Withdrawn Advisory: JHipster allows privilege escalation via a modified authorities parameter 已撤回 | 低危 | npmgenerator-jhipster | 已审查 | 2025-07-25 23:30 | 2025-08-05 04:26 |
| GHSA-MVW6-62QV-VMQF | Duplicate Advisory: Koa Open Redirect via Referrer Header (User-Controlled) 已撤回 | 低危 | npmkoa | 已审查 | 2025-07-25 14:30 | 2025-07-30 03:06 |
| GHSA-RM8P-CX58-HCVX CVE-2025-54371 | Withdrawn Advisory: Axios has Transitive Critical Vulnerability via form-data 已撤回 | 高危 | npmaxios | 已审查 | 2025-07-24 00:49 | 2025-07-24 21:35 |