检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-8H8Q-6873-Q5FJ | Next.js Vulnerable to Denial of Service with Server Components | 高危 | npmnext | 已审查 | 2026-05-11 22:50 | 2026-05-11 22:50 |
| GHSA-RV78-F8RC-XRXH CVE-2026-23870 | Facebook React has a Denial of Service Vulnerability in React Server Components |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 高危 |
npmreact-server-dom-parcel+2 |
| 已审查 |
| 2026-05-11 22:50 |
| 2026-05-11 22:50 |
| GHSA-389R-GV7P-R3RP CVE-2026-45022 | go-git's improper parsing of specially crafted objects may lead to inconsistent interpretation compared to upstream Git | 高危 | Gogithub.com/go-git/go-git/v5+1 | 已审查 | 2026-05-11 22:48 | 2026-06-09 07:42 |
| GHSA-587R-MC96-6F2P CVE-2026-44971 | GuardDog has a blind GitHub URL rewrite in remote project scanning causes SSRF and `GH_TOKEN` exfiltration | 高危 | PyPIguarddog | 已审查 | 2026-05-11 22:45 | 2026-06-09 07:42 |
| GHSA-M5P4-GVPX-4MVR CVE-2026-44972 | GuardDog: Unsanitized human-readable scan output allows terminal escape injection from malicious package content | 中危 | PyPIguarddog | 已审查 | 2026-05-11 22:43 | 2026-06-09 07:42 |
| GHSA-Q8W6-W55C-CCV5 CVE-2026-6420 | Keylime has a hardcoded attestation challenge nonce that allows replay attacks | 中危 | PyPIkeylime | 已审查 | 2026-05-11 22:42 | 2026-05-11 22:42 |
| GHSA-Q7RR-3CGH-J5R3 CVE-2026-44902 | Prometheus exporter process crash via malformed HTTP request | 高危 | npm@opentelemetry/auto-instrumentations-node+2 | 已审查 | 2026-05-11 22:42 | 2026-06-09 07:42 |
| GHSA-G588-CJG3-6G78 | Steamworks game clients/servers using P2P authentication vulnerable to denial of service | 中危 | crates.iosteamworks | 已审查 | 2026-05-11 22:40 | 2026-05-11 22:40 |
| GHSA-HGQW-6M45-HW5F CVE-2026-44353 | Streamlink has an arbitrary local file read via file:// URI in HLS and DASH | 中危 | PyPIstreamlink | 已审查 | 2026-05-11 22:28 | 2026-06-09 07:49 |
| GHSA-W2PM-X38X-JP44 CVE-2026-44346 | Dockerfile command injection via envs[*].name in bentofile.yaml (sibling fix-bypass of CVE-2026-33744 and CVE-2026-35043) | 高危 | PyPIbentoml | 已审查 | 2026-05-11 22:27 | 2026-06-09 07:49 |
| GHSA-78F9-R8MH-4XM2 CVE-2026-44345 | BentoML Dockerfile command injection via docker.base_image (sister of pending GHSA-w2pm-x38x-jp44 / CVE-2026-33744 / CVE-2026-35043) | 高危 | PyPIbentoml | 已审查 | 2026-05-11 22:27 | 2026-06-09 07:49 |
| GHSA-HMJQ-CRXP-7RJW CVE-2026-44570 | Open WebUI has inconsistent authorization controls within memories API | 高危 | PyPIopen-webui | 已审查 | 2026-05-11 22:25 | 2026-05-19 23:57 |
| GHSA-J643-X8PV-8M67 CVE-2026-44985 | Dozzle's Cross-Site WebSocket Hijacking (CSWSH) on exec/attach endpointsbypasses authentication | 高危 | Gogithub.com/amir20/dozzle | 已审查 | 2026-05-11 22:07 | 2026-06-09 07:35 |
| GHSA-JGJ3-R8HR-9PJW CVE-2026-44571 | Open WebUI's Improper Authorization in Standard Channels Allows Message Updates with Read Permission | 中危 | PyPIopen-webui | 已审查 | 2026-05-11 22:05 | 2026-05-19 23:57 |
| GHSA-JXWR-G6R6-J3FX CVE-2026-44569 | Open WebUI's Insecure Message Access Breaks Authorization | 高危 | PyPIopen-webui | 已审查 | 2026-05-11 22:04 | 2026-05-19 23:57 |
| GHSA-J3FW-WC48-29G3 CVE-2026-44565 | Open WebUI Arbitrary File Write, Delete via Path Traversal | 高危 | PyPIopen-webui | 已审查 | 2026-05-11 22:03 | 2026-05-19 23:57 |
| GHSA-6XCP-7MPR-M7WM | Open WebUI has a CORS misconfiguration and session validation issue | 高危 | PyPIopen-webui | 已审查 | 2026-05-11 22:02 | 2026-05-11 22:02 |
| GHSA-9Q28-GHCR-C4X3 CVE-2026-44340 | PraisonAI's symlink-extraction bypass of `_safe_extractall` writes outside `dest_dir` | 高危 | PyPIPraisonAI | 已审查 | 2026-05-11 21:59 | 2026-05-11 21:59 |
| GHSA-GMJG-HV98-QGGQ CVE-2026-44339 | PraisonAI has unsafe tool resolution in `ToolExecutionMixin.execute_tool`: undeclared `__main__` callables execute | 高危 | PyPIPraisonAI+1 | 已审查 | 2026-05-11 21:59 | 2026-05-11 21:59 |
| GHSA-9MQQ-JQXF-GRVW CVE-2026-44336 | PraisonAI MCP `tools/call` path-traversal => RCE via Python `.pth` injection | 严重 | PyPIPraisonAI | 已审查 | 2026-05-11 21:58 | 2026-05-11 21:58 |
| GHSA-3643-7V76-5CJ2 CVE-2026-44337 | PraisonAI knowledge-store backends interpolate unvalidated collection names into SQL and CQL queries | 中危 | PyPIPraisonAI | 已审查 | 2026-05-11 21:57 | 2026-05-11 21:57 |
| GHSA-6RMH-7XCM-CPXJ CVE-2026-44338 | PraisonAI ships and generates a legacy API server with authentication disabled by default, allowing unauthenticated workflow execution | 高危 | PyPIPraisonAI | 已审查 | 2026-05-11 21:56 | 2026-05-11 21:56 |
| GHSA-CHWH-F6GM-R836 CVE-2026-42595 | Gotenberg: Server-Side Request Forgery via Chromium URL Endpoint with Redirect-Based Deny-List Bypass | 高危 | Gogithub.com/gotenberg/gotenberg/v8 | 已审查 | 2026-05-11 21:51 | 2026-07-21 21:57 |
| GHSA-XCCP-97WP-3GJG CVE-2026-43826 | Apache Airflow Providers OpenSearch: OpenSearch task-log handler leaks credentials embedded in the host URL | 中危 | PyPIapache-airflow-providers-opensearch | 已审查 | 2026-05-11 17:30 | 2026-06-05 22:15 |
| GHSA-G3JR-4JRM-JVQV CVE-2026-41018 | Apache Airflow Providers Elasticsearch: Elasticsearch task-log handlers leak credentials embedded in the host URL | 中危 | PyPIapache-airflow-providers-elasticsearch | 已审查 | 2026-05-11 17:30 | 2026-06-05 22:14 |