检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-HP26-Q66V-Q2W7 CVE-2026-46441 | FlowiseAI has Mass Assignment in Assistant Update Endpoint that Allows Cross-Workspace Resource Reassignment | 高危 | npmflowise | 已审查 | 2026-05-14 22:57 | 2026-06-09 21:10 |
| GHSA-M99R-2HXC-CP3Q | Flowise has an MCP Security Bypass that Enables RCE |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 高危 |
npmflowise+1 |
| 已审查 |
| 2026-05-14 22:57 |
| 2026-05-16 07:47 |
| GHSA-PHP6-83FG-GW3G CVE-2026-46440 | FlowiseAI Exposes Basic Auth Credentials via API | 高危 | npmflowise | 已审查 | 2026-05-14 22:54 | 2026-06-09 21:10 |
| GHSA-5WXP-QJGQ-FX6M CVE-2026-42863 | FlowiseAI has Mass Assignment in Chatflow Update Endpoint that Allows Cross-Workspace AgentFlow Reassignment | 高危 | npmflowise | 已审查 | 2026-05-14 22:54 | 2026-06-09 21:10 |
| GHSA-X5V6-PJ28-CWWM CVE-2026-42862 | FlowiseAI has Mass Assignment in Tool Update Endpoint that Allows Cross-Workspace Resource Reassignment | 高危 | npmflowise | 已审查 | 2026-05-14 22:52 | 2026-06-09 21:09 |
| GHSA-6FW7-3Q8R-M5VJ CVE-2026-42861 | FlowiseAI has Mass Assignment in Variable Update Endpoint that Allows Cross-Workspace Resource Reassignment | 高危 | npmflowise | 已审查 | 2026-05-14 22:52 | 2026-06-09 21:09 |
| GHSA-MXMP-WR3W-RVQX CVE-2026-46356 | Fleet: IP spoofing allows bypassing API rate limiting | 中危 | Gogithub.com/fleetdm/fleet/v4 | 已审查 | 2026-05-14 21:18 | 2026-05-16 07:45 |
| GHSA-Q58J-G3F4-H26H CVE-2026-41249 | CoreShop Vulnerable to Remote Code Execution (RCE) via Insecure `pull_request_target` Configuration | 高危 | Packagistcoreshop/core-shop | 已审查 | 2026-05-14 21:18 | 2026-06-09 19:55 |
| GHSA-RJG2-95X7-8QMX CVE-2026-27886 | Strapi may leak sensitive data via relational filtering due to lack of query sanitization | 严重 | npm@strapi/strapi | 已审查 | 2026-05-14 21:17 | 2026-05-16 07:44 |
| GHSA-9VCR-G537-3W5V CVE-2026-26191 | Fleet vulnerable to OS command injection in software packages | 中危 | Gogithub.com/fleetdm/fleet/v4 | 已审查 | 2026-05-14 21:17 | 2026-05-16 07:45 |
| GHSA-X67P-9M2R-FXQV CVE-2026-26062 | Fleet server may terminate unexpectedly when handling certain gRPC requests | 高危 | Gogithub.com/fleetdm/fleet/v4 | 已审查 | 2026-05-14 21:17 | 2026-05-16 07:45 |
| GHSA-FFG9-J72F-J6XM CVE-2026-24899 | Fleet Windows MDM Azure AD JWT Authentication Bypass | 高危 | Gogithub.com/fleetdm/fleet/v4 | 已审查 | 2026-05-14 21:13 | 2026-06-09 07:26 |
| GHSA-J8H8-75H3-JG53 CVE-2026-24000 | Fleet has a rate limiting bypass via untrusted client IP headers | 中危 | Gogithub.com/fleetdm/fleet/v4 | 已审查 | 2026-05-14 21:13 | 2026-05-16 07:44 |
| GHSA-2RC4-7JC6-QFFH CVE-2026-23998 | Fleet has a Windows MDM management endpoint authentication bypass | 高危 | Gogithub.com/fleetdm/fleet/v4 | 已审查 | 2026-05-14 21:13 | 2026-06-09 07:36 |
| GHSA-PCW7-5633-82VV CVE-2026-22707 | Strapi Upload Plugin MIME Validation Bypass via Content API | 中危 | npm@strapi/upload | 已审查 | 2026-05-14 21:12 | 2026-05-16 07:44 |
| GHSA-WMMV-VVG5-993Q CVE-2026-8178 | Amazon Redshift Vulnerable to Remote Code Execution via Unsafe Class Loading | 严重 | Mavencom.amazon.redshift:redshift-jdbc42 | 已审查 | 2026-05-14 21:09 | 2026-05-14 21:09 |
| GHSA-9MHV-8H52-Q7Q2 CVE-2026-43967 | Absinthe: Quadratic fragment-name uniqueness check | 高危 | Hexabsinthe | 已审查 | 2026-05-14 21:08 | 2026-05-14 21:08 |
| GHSA-QF4G-9FQQ-MMM7 CVE-2026-42793 | Absinthe: Unbounded atom creation from parsed directive name | 高危 | Hexabsinthe | 已审查 | 2026-05-14 21:08 | 2026-05-14 21:08 |
| GHSA-337M-MW94-2V6G CVE-2026-45205 | Apache Commons Configuration: StackOverflowError for YAML input with cycles | 中危 | Mavenorg.apache.commons:commons-configuration2 | 已审查 | 2026-05-14 20:30 | 2026-05-20 23:36 |
| GHSA-4G73-W726-53H3 CVE-2026-44919 | OpenStack Ironic: Pre-Validation Checksum Calculation allows Denial of Service (DoS) via Infinite Block Devices | 中危 | PyPIironic | 已审查 | 2026-05-14 11:32 | 2026-06-09 04:07 |
| GHSA-WFHV-MJ62-F5XH CVE-2026-33381 | Grafana: Users can generate Service Account tokens after permissions removal | 中危 | Gogithub.com/grafana/grafana | 已审查 | 2026-05-14 05:32 | 2026-06-18 21:05 |
| GHSA-JFC2-Q6QH-G5X8 CVE-2026-8466 | Cowboy: Unbounded buffer accumulation in multipart header parsing causes denial of service in cowboy | 高危 | Hexcowboy | 已审查 | 2026-05-14 05:32 | 2026-05-20 04:12 |
| GHSA-GXCP-JJXH-RWP4 CVE-2026-33380 | Grafana: SQL Expressions Read File From Disk | 中危 | Gogithub.com/grafana/grafana | 已审查 | 2026-05-14 05:32 | 2026-06-18 21:05 |
| GHSA-84F2-RP86-235P CVE-2026-43970 | cowlib: Decompression Bomb in cow_spdy:inflate/2 Allows Memory Exhaustion via Crafted SPDY Frame | 高危 | Hexcowlib | 已审查 | 2026-05-14 05:32 | 2026-05-20 04:12 |
| GHSA-HVP3-26WX-G2W4 CVE-2026-22706 | Strapi: Password Reset Does Not Revoke Existing Refresh Sessions | 低危 | npm@strapi/admin+1 | 已审查 | 2026-05-14 04:02 | 2026-05-16 07:44 |