检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-7FXV-8WR2-MFC4 CVE-2026-44543 | Local Path Provisioner Vulnerable to HelperPod Template Injection | 高危 | Gogithub.com/rancher/local-path-provisioner | 已审查 | 2026-05-12 00:15 | 2026-06-09 10:00 |
| GHSA-3G8H-86W9-WVMQ CVE-2026-44572 |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 低危 |
npmnext |
| 已审查 |
| 2026-05-12 00:12 |
| 2026-05-15 04:35 |
| GHSA-C3GJ-Q88F-7HQJ CVE-2026-44521 | elFinder MySQL has a SQL Injection in its Volume Driver (elFinderVolumeMySQL) | 高危 | Packagiststudio-42/elfinder | 已审查 | 2026-05-12 00:11 | 2026-06-09 07:49 |
| GHSA-3JH5-RR2Q-XFV7 CVE-2026-44516 | Valtimo has sensitive data exposure through HTTP request/response logging in LoggingRestClientCustomizer | 高危 | Mavencom.ritense.valtimo:web | 已审查 | 2026-05-12 00:11 | 2026-05-15 04:54 |
| GHSA-MHWJ-73QX-JQXM | @theecryptochad/merge-guard has Prototype Pollution in its deepMerge() function | 高危 | npm@theecryptochad/merge-guard | 已审查 | 2026-05-12 00:10 | 2026-05-12 00:10 |
| GHSA-C567-44RC-M5HQ CVE-2026-44483 | @rvf/set-get has a prototype pollution issue that's reachable via @rvf/core preprocessFormData (HTTP form data) | 高危 | npm@rvf/set-get | 已审查 | 2026-05-12 00:09 | 2026-06-09 07:49 |
| GHSA-423P-G724-FR39 CVE-2026-44477 | CloudNativePG's metrics exporter allows privilege escalation to PostgreSQL superuser and OS RCE | 严重 | Gogithub.com/cloudnative-pg/cloudnative-pg | 已审查 | 2026-05-11 23:59 | 2026-06-09 10:00 |
| GHSA-FFHC-5MCF-PF4Q CVE-2026-44581 | Next.js vulnerable to cross-site scripting in App Router applications using CSP nonces | 中危 | npmnext | 已审查 | 2026-05-11 23:57 | 2026-05-15 04:38 |
| GHSA-VFV6-92FF-J949 CVE-2026-44582 | Next.js vulnerable to cache poisoning via collisions in React Server Component cache-busting | 低危 | npmnext | 已审查 | 2026-05-11 23:56 | 2026-05-15 04:38 |
| GHSA-GX5P-JG67-6X7H CVE-2026-44580 | Next.js has cross-site scripting in beforeInteractive scripts with untrusted input | 中危 | npmnext | 已审查 | 2026-05-11 23:56 | 2026-05-15 04:38 |
| GHSA-MG66-MRH9-M8JX CVE-2026-44579 | Next.js vulnerable to Denial of Service via connection exhaustion in applications using Cache Components | 高危 | npmnext | 已审查 | 2026-05-11 23:56 | 2026-05-15 04:38 |
| GHSA-H64F-5H5J-JQJH CVE-2026-44577 | Next.js has a Denial of Service in the Image Optimization API | 中危 | npmnext | 已审查 | 2026-05-11 23:56 | 2026-05-15 04:38 |
| GHSA-C4J6-FC7J-M34R CVE-2026-44578 | Next.js vulnerable to server-side request forgery in applications using WebSocket upgrades | 高危 | npmnext | 已审查 | 2026-05-11 23:55 | 2026-05-15 04:38 |
| GHSA-WFC6-R584-VFW7 CVE-2026-44576 | Next.js vulnerable to cache poisoning in React Server Component responses | 中危 | npmnext | 已审查 | 2026-05-11 23:54 | 2026-05-15 04:38 |
| GHSA-267C-6GRR-H53F CVE-2026-44575 | Next.js has a Middleware / Proxy bypass in App Router applications via segment-prefetch routes | 高危 | npmnext | 已审查 | 2026-05-11 23:54 | 2026-05-15 04:38 |
| GHSA-492V-C6PP-MQQV CVE-2026-44574 | Next.js has a Middleware / Proxy bypass through dynamic route parameter injection | 高危 | npmnext | 已审查 | 2026-05-11 23:54 | 2026-05-15 04:38 |
| GHSA-36QX-FR4F-26G5 CVE-2026-44573 | Next.js has a Middleware / Proxy bypass in Pages Router applications using i18n | 高危 | npmnext | 已审查 | 2026-05-11 23:53 | 2026-05-15 04:37 |
| GHSA-MC29-HMX6-856Q CVE-2026-44474 | Ella Core has handover failures during concurrent Security Mode Command | 低危 | Gogithub.com/ellanetworks/core | 已审查 | 2026-05-11 23:29 | 2026-06-09 07:48 |
| GHSA-PWFH-MQP3-PQWJ CVE-2026-44475 | Ella Core has a UE Security Capability bypass on NGAP PathSwitchRequest | 中危 | Gogithub.com/ellanetworks/core | 已审查 | 2026-05-11 23:29 | 2026-06-09 07:48 |
| GHSA-QFXW-V8QX-VJ3V CVE-2026-44473 | Ella Core Vulnerable to UE Downlink Redirection via Forged PDUSessionResourceSetupResponse | 高危 | Gogithub.com/ellanetworks/core | 已审查 | 2026-05-11 23:18 | 2026-06-09 07:48 |
| GHSA-8P4X-WR7X-3788 CVE-2026-45017 | python-liquid: Absolute paths escape filesystem loader search path | 高危 | PyPIpython-liquid | 已审查 | 2026-05-11 22:57 | 2026-06-09 10:00 |
| GHSA-88Q9-CMP2-C2VQ | oxidize-pdf: NaN/inf bypass in colour content-stream emission causes PDF rejection (DoS) | 中危 | crates.iooxidize-pdf+1 | 已审查 | 2026-05-11 22:53 | 2026-05-11 22:53 |
| GHSA-MF9V-MFXR-J63J CVE-2026-44432 | urllib3: Decompression-bomb safeguards bypassed in parts of the streaming API | 高危 | PyPIurllib3 | 已审查 | 2026-05-11 22:51 | 2026-06-09 03:52 |
| GHSA-QCCP-GFCP-XXVC CVE-2026-44431 | urllib3: Sensitive headers forwarded across origins in proxied low-level redirects | 高危 | PyPIurllib3 | 已审查 | 2026-05-11 22:51 | 2026-05-15 04:35 |
| GHSA-W94C-4VHP-22GX | @vitejs/plugin-rsc has a Denial of Service Vulnerability in React Server Components | 高危 | npm@vitejs/plugin-rsc | 已审查 | 2026-05-11 22:50 | 2026-05-11 22:50 |