检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-H6FC-48RJ-7QQH CVE-2026-43512 | Apache Tomcat - Digest authenticator will authenticate any unknown user | 严重 | Mavenorg.apache.tomcat:tomcat+2 | 已审查 | 2026-05-13 02:30 | 2026-05-19 04:38 |
| GHSA-GX5V-XP9W-J4CG |
当前筛选结果 35,190 条 · 时间按北京时间显示
Apache Tomcat: Unbounded read in WebDAV LOCK and PROPFIND handling |
| 高危 |
Mavenorg.apache.tomcat:tomcat+2 |
| 已审查 |
| 2026-05-13 02:30 |
| 2026-05-19 04:26 |
| GHSA-GPX5-7XM4-229W CVE-2026-31224 | Snorkel MultitaskClassifier.load uses an unsafe torch.load | 高危 | PyPIsnorkel | 已审查 | 2026-05-13 02:30 | 2026-05-19 04:25 |
| GHSA-FV25-8XCX-GQJC CVE-2026-42498 | Apache Tomcat - WebSocket authentication header exposure | 高危 | Mavenorg.apache.tomcat:tomcat+2 | 已审查 | 2026-05-13 02:30 | 2026-05-19 04:29 |
| GHSA-FQ92-QC8F-482V CVE-2026-31223 | Snorkel BaseLabeler.load uses an unsafe pickle.load | 高危 | PyPIsnorkel | 已审查 | 2026-05-13 02:30 | 2026-05-19 04:24 |
| GHSA-CFPG-C974-JFHQ CVE-2026-31220 | PySyft server-side arbitrary Python execution after code approval | 严重 | PyPIsyft | 已审查 | 2026-05-13 02:30 | 2026-05-19 04:24 |
| GHSA-9M89-8FRQ-C98C CVE-2026-43514 | Apache Tomcat - AJP secret compared in non-constant time | 低危 | Mavenorg.apache.tomcat:tomcat+2 | 已审查 | 2026-05-13 02:30 | 2026-05-19 22:28 |
| GHSA-94GR-W3Q5-RFQR CVE-2025-65719 | Open Source Kubectl MCP Server vulnerable to arbitrary code execution via user interaction with crafted HTML page | 严重 | npmkubectl-mcp-server | 已审查 | 2026-05-13 02:30 | 2026-06-19 04:09 |
| GHSA-78CP-F66X-QMH5 CVE-2026-31222 | Snorkel Trainer.load uses an unsafe torch.load | 高危 | PyPIsnorkel | 已审查 | 2026-05-13 02:30 | 2026-05-19 04:25 |
| GHSA-75M9-98V2-HJPM CVE-2026-31221 | PyTorch Lightning load_from_checkpoint has an insecure checkpoint deserialization | 高危 | PyPIpytorch-lightning | 已审查 | 2026-05-13 02:30 | 2026-05-19 04:24 |
| GHSA-5MP6-JRQ3-R938 CVE-2026-43513 | Apache Tomcat: LockOutRealm treats user names as case-sensitive | 高危 | Mavenorg.apache.tomcat:tomcat+2 | 已审查 | 2026-05-13 02:30 | 2026-05-19 04:31 |
| GHSA-5M62-PW8W-7W9F CVE-2026-43515 | Apache Tomcat - Security constraints not correctly applied | 严重 | Mavenorg.apache.tomcat:tomcat+2 | 已审查 | 2026-05-13 02:30 | 2026-05-19 22:34 |
| GHSA-2799-6G5R-MMC7 CVE-2026-31225 | Superduper: Remote code execution via unsafe eval in superduper query parsing | 高危 | PyPIsuperduper-framework | 已审查 | 2026-05-13 02:30 | 2026-05-19 04:26 |
| GHSA-M77W-P5JJ-XMHG CVE-2026-42074 | OpenClaude Sandbox Bypass via Model-Controlled `dangerouslyDisableSandbox` Input | 严重 | npmopenclaude | 已审查 | 2026-05-13 00:17 | 2026-06-09 18:59 |
| GHSA-C73C-X77G-854R CVE-2026-42073 | OpenClaude MCP OAuth Callback: State Check Bypass via error Param Leads to DoS | 中危 | npm@gitlawb/openclaude | 已审查 | 2026-05-12 23:34 | 2026-06-09 18:59 |
| GHSA-RHV4-8758-JX7V CVE-2026-32686 | Decimal: Unbounded exponent in `Decimal.new` enables unauthenticated DoS | 中危 | Hexdecimal | 已审查 | 2026-05-12 23:09 | 2026-08-05 20:40 |
| GHSA-X3R2-FJ3R-G5MV CVE-2026-45091 | sealed-env: TOTP secret embedded in unseal token payload (enterprise mode) | 严重 | Mavenio.github.davidalmeidac:sealed-env-core+1 | 已审查 | 2026-05-12 23:09 | 2026-05-14 00:24 |
| GHSA-2G4X-FQ3J-CGQ4 CVE-2026-45090 | Dalfox has an Unauthenticated Remote DoS via Closed-Channel Write in `ParameterAnalysis` (server mode) | 高危 | Gogithub.com/hahwul/dalfox+1 | 已审查 | 2026-05-12 23:08 | 2026-06-09 04:12 |
| GHSA-8HF9-3Q64-Q2QF CVE-2026-45089 | Dalfox Server Mode has an Unauthenticated Arbitrary File Create/Append via `output` Option | 高危 | Gogithub.com/hahwul/dalfox/v2 | 已审查 | 2026-05-12 23:08 | 2026-06-09 07:50 |
| GHSA-35WR-X7V6-9FV2 CVE-2026-45088 | Dalfox Server Mode has an Unauthenticated Arbitrary File Read with Out-of-Band Exfiltration via `custom-payload-file` | 高危 | Gogithub.com/hahwul/dalfox/v2 | 已审查 | 2026-05-12 23:08 | 2026-06-09 07:50 |
| GHSA-V25V-M36W-JP4H CVE-2026-45087 | Dalfox Server Mode Vulnerable to Unauthenticated Remote Code Execution via `found-action` | 严重 | Gogithub.com/hahwul/dalfox/v2 | 已审查 | 2026-05-12 23:07 | 2026-06-09 07:50 |
| GHSA-6R35-46G8-JCW9 CVE-2026-44295 | protobuf.js: Code injection in pbjs static output from crafted schema names | 高危 | npmprotobufjs-cli | 已审查 | 2026-05-12 23:06 | 2026-05-15 04:35 |
| GHSA-2PR8-PHX7-X9H3 CVE-2026-44294 | protobuf.js: Denial of service from crafted field names in generated code | 中危 | npmprotobufjs | 已审查 | 2026-05-12 23:06 | 2026-05-15 04:35 |
| GHSA-66FF-XGX4-VCHM CVE-2026-44293 | protobuf.js: Code injection through bytes field defaults in generated toObject code | 高危 | npmprotobufjs | 已审查 | 2026-05-12 23:06 | 2026-05-12 23:06 |
| GHSA-FX83-V9X8-X52W CVE-2026-44292 | protobuf.js: Prototype injection in generated message constructors | 中危 | npmprotobufjs | 已审查 | 2026-05-12 23:01 | 2026-05-15 04:35 |