检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-R95X-QFJJ-FJJ2 CVE-2026-44681 | Authlib OIDC Implicit/Hybrid Authorization Vulnerable to Open Redirect | 中危 | PyPIauthlib | 已审查 | 2026-05-13 09:36 | 2026-06-09 07:53 |
| GHSA-Q7M6-WPVF-MVWX CVE-2026-44672 | Mapfish Print: Remote Code Injection (RCE) in Dynamic table |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 严重 |
Mavenorg.mapfish.print:print-lib+1 |
| 已审查 |
| 2026-05-13 09:35 |
| 2026-06-09 10:00 |
| GHSA-C38F-WX89-P2XG CVE-2026-44660 | UltraJSON has a Memory Leak in ujson.dump() on Write Failure | 高危 | PyPIujson | 已审查 | 2026-05-13 06:25 | 2026-06-09 07:53 |
| GHSA-CCFQ-2454-F5XW CVE-2026-44652 | SillyTavern has a SSRF vulnerability in the CORS proxy middleware | 中危 | npmsillytavern | 已审查 | 2026-05-13 06:24 | 2026-06-09 18:32 |
| GHSA-XC4X-2452-5GC9 CVE-2026-44651 | SillyTavern has a reflected XSS vulnerability in the CORS proxy middleware | 中危 | npmsillytavern | 已审查 | 2026-05-13 06:23 | 2026-06-09 18:32 |
| GHSA-886Q-F44J-H6WH CVE-2026-44650 | SillyTavern has a Path Traversal issue | 严重 | npmsillytavern | 已审查 | 2026-05-13 06:23 | 2026-05-13 06:23 |
| GHSA-GXX6-H3G6-VWJH CVE-2026-44649 | SillyTavern has Authentication Bypass via SSO Header Injection | 严重 | npmsillytavern | 已审查 | 2026-05-13 06:23 | 2026-06-09 18:32 |
| GHSA-WMM3-H9QJ-P5V6 CVE-2026-44648 | SillyTavern: Existing sessions are not invalidated after password change, allowing session reuse and account takeover | 高危 | npmsillytavern | 已审查 | 2026-05-13 06:23 | 2026-06-09 18:32 |
| GHSA-RG65-45M7-HQ57 CVE-2026-44594 | esm.sh: Path Traversal via package.json browser field allows reading arbitrary server files | 高危 | Gogithub.com/esm-dev/esm.sh | 已审查 | 2026-05-13 06:22 | 2026-06-09 10:00 |
| GHSA-3636-H3VX-6465 CVE-2026-44593 | esm.sh: Legacy Route Path Traversal Can Lead to RCE | 高危 | Gogithub.com/esm-dev/esm.sh | 已审查 | 2026-05-13 06:22 | 2026-06-09 09:59 |
| GHSA-WQWC-X3RC-2XW6 CVE-2026-8052 | HashiCorp Nomad’s exec2 task driver vulnerable to a symlink attack | 中危 | Gogithub.com/hashicorp/nomad-driver-exec2 | 已审查 | 2026-05-13 05:31 | 2026-05-19 23:39 |
| GHSA-HX53-77QJ-8663 CVE-2026-7474 | HashiCorp Nomad vulnerable to a path traversal | 高危 | Gogithub.com/hashicorp/nomad | 已审查 | 2026-05-13 05:31 | 2026-05-19 23:39 |
| GHSA-3934-423W-4JQ3 CVE-2026-6959 | HashiCorp Nomad vulnerable to symlink attack | 中危 | Gogithub.com/hashicorp/nomad | 已审查 | 2026-05-13 05:31 | 2026-05-19 23:39 |
| GHSA-97JF-46M3-8953 CVE-2026-33117 | Security feature bypass vulnerability in Azure Key Vault Keys library for Java | 严重 | Mavencom.azure:azure-security-keyvault-keys | 已审查 | 2026-05-13 02:30 | 2026-06-03 06:18 |
| GHSA-XP5Q-5Q7G-Q26R CVE-2026-31238 | Ludwig framework is vulnerable to insecure deserialization in its model serving component | 严重 | PyPIludwig | 已审查 | 2026-05-13 02:30 | 2026-05-28 06:17 |
| GHSA-WCR3-GM9F-F87Q CVE-2026-31237 | Ludwig framework is vulnerable to insecure deserialization through its predict() method. | 严重 | PyPIludwig | 已审查 | 2026-05-13 02:30 | 2026-05-28 06:19 |
| GHSA-PQ2F-X424-6FJM CVE-2026-31239 | mamba language model framework vulnerable to insecure deserialization when loading pre-trained models from HuggingFace Hub | 严重 | PyPImamba-ssm | 已审查 | 2026-05-13 02:30 | 2026-05-28 06:09 |
| GHSA-JFV9-68M5-GJJR CVE-2026-31240 | mem0 server lacks authentication and authorization controls for its memory management API endpoints | 高危 | PyPImem0ai | 已审查 | 2026-05-13 02:30 | 2026-05-29 03:13 |
| GHSA-GQ6F-QWV9-RF4J CVE-2026-31241 | mem0 server lacks authentication and authorization controls for its memory deletion API endpoint | 中危 | PyPImem0ai | 已审查 | 2026-05-13 02:30 | 2026-05-28 06:46 |
| GHSA-G82G-J283-HJ97 CVE-2026-31235 | imgaug contains an insecure deserialization vulnerability in BackgroundAugmenter class within multicore.py module | 严重 | PyPIimgaug | 已审查 | 2026-05-13 02:30 | 2026-05-28 06:25 |
| GHSA-G76P-4VG5-F4QH CVE-2026-31236 | llm CLI tool contains a code injection vulnerability via `--functions` command-line argument | 严重 | PyPIllm | 已审查 | 2026-05-13 02:30 | 2026-05-28 06:22 |
| GHSA-CGX8-QGVR-F7VF CVE-2026-31245 | mem0 server lacks authentication and authorization controls for its memory creation API endpoint | 中危 | PyPImem0ai | 已审查 | 2026-05-13 02:30 | 2026-05-28 06:46 |
| GHSA-R6HF-G5X6-7PV9 CVE-2026-31233 | Guardrails AI contains a code injection vulnerability in its Hub package installation mechanism | 严重 | PyPIguardrails-ai | 已审查 | 2026-05-13 02:30 | 2026-05-28 06:03 |
| GHSA-MF8F-X4R3-JM8C CVE-2026-31234 | Horovod contains an insecure deserialization vulnerability in its KVStore HTTP server component | 严重 | PyPIhorovod | 已审查 | 2026-05-13 02:30 | 2026-05-28 05:45 |
| GHSA-R29C-68GH-XP6X CVE-2026-41293 | Apache Tomcat - HTTP/2 request headers not validated | 严重 | Mavenorg.apache.tomcat:tomcat+2 | 已审查 | 2026-05-13 02:30 | 2026-09-01 05:04 |