检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-75PX-5XX7-5XC7 CVE-2026-44291 | protobuf.js: Code generation gadget after prototype pollution | 高危 | npmprotobufjs | 已审查 | 2026-05-12 23:01 | 2026-05-15 04:35 |
| GHSA-JVWF-75H9-CWGG CVE-2026-44290 | protobuf.js: Process-wide denial of service through unsafe option paths |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 高危 |
npmprotobufjs |
| 已审查 |
| 2026-05-12 23:01 |
| 2026-05-15 04:35 |
| GHSA-685M-2W69-288Q CVE-2026-44289 | protobuf.js: Denial of service through unbounded protobuf recursion | 高危 | npmprotobufjs | 已审查 | 2026-05-12 23:01 | 2026-05-15 04:35 |
| GHSA-Q6X5-8V7M-XCRF CVE-2026-44288 | protobufjs has overlong UTF-8 decoding | 中危 | npm@protobufjs/utf8+1 | 已审查 | 2026-05-12 23:00 | 2026-05-15 04:35 |
| GHSA-F84P-CVGM-XGJJ CVE-2026-42290 | protobuf.js is Vulnerable to OS Command Injection in the CLI | 高危 | npmprotobufjs-cli | 已审查 | 2026-05-12 22:59 | 2026-05-15 04:31 |
| GHSA-Q62F-H9X2-GCQC CVE-2026-41712 | Spring AI: ChatMemory DEFAULT_CONVERSATION_ID causes unintended cross-user data leakage | 高危 | Mavenorg.springframework.ai:spring-ai-advisors-vector-store+2 | 已审查 | 2026-05-12 20:32 | 2026-05-19 01:54 |
| GHSA-5852-PHMH-8FHR CVE-2026-41713 | Spring AI: Prompt Injection via Memory Poisoning in PromptChatMemoryAdvisor | 高危 | Mavenorg.springframework.ai:spring-ai-client-chat | 已审查 | 2026-05-12 20:32 | 2026-05-19 01:54 |
| GHSA-3H63-FX68-X5FM CVE-2026-8349 | omec-project amf crashes when processing malformed LocationReports | 低危 | Gogithub.com/omec-project/amf | 已审查 | 2026-05-12 08:31 | 2026-05-19 01:13 |
| GHSA-G7CV-RXG3-HMPX CVE-2026-45321 | Malware in @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys | 严重 | npm@tanstack/arktype-adapter+41 | 已审查 | 2026-05-12 08:12 | 2026-06-09 07:53 |
| GHSA-CH88-C67Q-65R9 CVE-2026-8319 | aiwaves-cn agents is vulnerable to resource consumption in the recall_relevant_memories_to_working_memory function | 中危 | PyPIai-agents | 已审查 | 2026-05-12 05:31 | 2026-05-19 00:52 |
| GHSA-42H5-H8QH-VV9V CVE-2026-2614 | MLflow allows an unauthenticated remote attacker to read arbitrary files from the server's filesystem | 高危 | PyPImlflow | 已审查 | 2026-05-12 05:31 | 2026-05-19 00:49 |
| GHSA-32P9-57CR-4X65 CVE-2026-7790 | cowlib cow_http_te module: Uncontrolled Resource Consumption vulnerability allows Excessive Allocation | 高危 | Hexcowlib | 已审查 | 2026-05-12 05:31 | 2026-05-19 00:49 |
| GHSA-QP7V-GJGG-4MJ6 CVE-2026-45222 | @steipete/summarize allows local attackers to read bearer tokens and API credentials stored in ~/.summarize/daemon.json | 中危 | npm@steipete/summarize | 已审查 | 2026-05-12 05:31 | 2026-05-19 00:47 |
| GHSA-HV23-4QP7-8C8R CVE-2026-43968 | ninenines cowlib: Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability allows SSE event splitting and injection via unvalidated field values | 中危 | Hexcowlib | 已审查 | 2026-05-12 05:31 | 2026-06-09 04:16 |
| GHSA-G2WM-735Q-3F56 CVE-2026-43969 | cowlib: Cookie Request Header Injection via Unvalidated Encoder in cow_cookie:cookie/1 | 低危 | Hexcowlib | 已审查 | 2026-05-12 05:31 | 2026-06-09 04:17 |
| GHSA-3CJV-H753-QF7H CVE-2026-45224 | Crabbox contains a path traversal vulnerability in the Islo provider's workspace path resolution | 中危 | Gogithub.com/openclaw/crabbox | 已审查 | 2026-05-12 05:31 | 2026-05-19 00:48 |
| GHSA-F3JG-756W-GM35 CVE-2026-45046 | Gryph Agents Payload Filter Fails to Strip Tool Payload for Sensitive Content | 中危 | Gogithub.com/safedep/gryph | 已审查 | 2026-05-12 05:20 | 2026-06-09 07:53 |
| GHSA-P6FR-RXQ7-XCG8 CVE-2026-44657 | MantisBT Vulnerable to Stored XSS in File Download | 高危 | Packagistmantisbt/mantisbt | 已审查 | 2026-05-12 03:40 | 2026-06-09 18:24 |
| GHSA-7MQJ-8GJ2-CG59 CVE-2026-44655 | MantisBT has Stored XSS on Move Attachments Admin Page | 高危 | Packagistmantisbt/mantisbt | 已审查 | 2026-05-12 03:40 | 2026-06-09 18:23 |
| GHSA-PV5W-4P9Q-P3V2 CVE-2026-44635 | Kysely: JSON-path traversal injection via unsanitized path-leg metacharacters in `JSONPathBuilder.key()` / `.at()` | 高危 | npmkysely | 已审查 | 2026-05-12 03:40 | 2026-06-09 07:53 |
| GHSA-FJ2M-QVH9-JQ4Q CVE-2026-43979 | local-deep-research is Vulnerable to HTML Injection via Unescaped User Input in PDF Export (`pdf_service.py:_markdown_to_html`) | 中危 | PyPIlocal-deep-research | 已审查 | 2026-05-12 03:40 | 2026-06-09 18:22 |
| GHSA-G8F2-4F4F-5JQW CVE-2026-43898 | SandboxJS has a sandbox escape via Function.caller leakage of internal call op | 严重 | npm@nyariv/sandboxjs | 已审查 | 2026-05-12 03:40 | 2026-06-09 10:00 |
| GHSA-PW5X-2MF9-3XC8 CVE-2026-42071 | MantisBT has a Private Bugnote Attachment Content Leak via REST API | 高危 | Packagistmantisbt/mantisbt | 已审查 | 2026-05-12 03:39 | 2026-06-09 18:23 |
| GHSA-PQ86-J2C2-47F6 CVE-2026-42070 | MantisBT: Authorization Bypass in Bugnote Editing via Issue Update API | 中危 | Packagistmantisbt/mantisbt | 已审查 | 2026-05-12 03:39 | 2026-06-09 18:23 |
| GHSA-J7V9-F46R-2RP4 CVE-2026-41897 | MantisBT is Vulnerable to Reflected XSS in Rendering Dynamic Custom Textarea Field | 中危 | Packagistmantisbt/mantisbt | 已审查 | 2026-05-12 03:39 | 2026-06-09 18:23 |