检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-JCQV-2G3V-GM88 CVE-2026-8276 | bettercap Has an Integer Coercion Error in modules/mysql_server/mysql_server.go | 低危 | Gogithub.com/bettercap/bettercap/v2 | 已审查 | 2026-05-11 14:31 | 2026-05-15 05:15 |
| GHSA-322P-RRJ6-J44G CVE-2026-8275 | bettercap Has an Integer Coercion Error in the ippReadChunkedBody Function |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 低危 |
Gogithub.com/bettercap/bettercap/v2 |
| 已审查 |
| 2026-05-11 14:31 |
| 2026-05-15 05:14 |
| GHSA-444R-2WHX-3685 CVE-2021-47935 | Sentry: Superusers can execute arbitrary commands by injecting malicious pickle-serialized objects through audit log entry data parameter | 高危 | PyPIsentry | 已审查 | 2026-05-10 23:31 | 2026-06-10 04:49 |
| GHSA-R5M4-5VWW-W9F5 CVE-2026-8212 | OSGeo gdal has a heap-based buffer overflow | 低危 | PyPIGDAL | 已审查 | 2026-05-10 08:33 | 2026-05-30 06:23 |
| GHSA-V632-2M87-7469 CVE-2026-41705 | Spring AI's MilvusVectorStore#doDelete(List) implementation is vulnerable to filter-expression injection via unsanitized document IDs | 高危 | Mavenorg.springframework.ai:spring-ai-milvus-store+1 | 已审查 | 2026-05-09 11:31 | 2026-05-14 21:10 |
| GHSA-QP7P-654G-CW7P CVE-2026-44458 | Hono has CSS Declaration Injection via Style Object Values in JSX SSR | 中危 | npmhono | 已审查 | 2026-05-09 08:46 | 2026-05-09 08:46 |
| GHSA-HM8Q-7F3Q-5F36 CVE-2026-44459 | Hono has improper validation of NumericDate claims (exp, nbf, iat) in JWT verify() | 低危 | npmhono | 已审查 | 2026-05-09 08:45 | 2026-05-15 04:35 |
| GHSA-V6WJ-C83F-V46X | @profullstack/mcp-server vulnerable to OS Command Injection in domain_lookup Module | 严重 | npm@profullstack/mcp-server | 已审查 | 2026-05-09 08:42 | 2026-05-09 08:42 |
| GHSA-J658-C2GF-X6PQ CVE-2026-44966 | Velocity.js has a Prototype Pollution vulnerability through #set path assignment | 高危 | npmvelocityjs | 已审查 | 2026-05-09 08:40 | 2026-06-09 07:35 |
| GHSA-3G76-F9XQ-8VP6 CVE-2026-6860 | Vert.x has a DoS via unbounded server-side SNI SslContext cache growth | 中危 | Mavenio.vertx:vertx-core | 已审查 | 2026-05-09 08:38 | 2026-06-03 06:07 |
| GHSA-P77W-8QQV-26RM CVE-2026-44457 | Hono's Cache Middleware ignores Vary: Authorization / Vary: Cookie leading to cross-user cache leakage | 中危 | npmhono | 已审查 | 2026-05-09 08:28 | 2026-05-15 04:35 |
| GHSA-V87V-83H2-53W7 CVE-2026-44897 | Mistune Heading ID Attribute has Injection XSS | 中危 | PyPImistune | 已审查 | 2026-05-09 08:13 | 2026-06-09 07:30 |
| GHSA-8JR5-6GVJ-RFPF CVE-2026-44895 | @yoda.digital/gitlab-mcp-server's SSE transport has no authentication and wildcard CORS, exposing all 86 GitLab tools | 高危 | npm@yoda.digital/gitlab-mcp-server | 已审查 | 2026-05-09 08:10 | 2026-06-09 07:34 |
| GHSA-97WC-2HQC-CJGR CVE-2026-44983 | smallbitvec: Integer overflow in safe API leads to heap buffer overflow | 高危 | crates.iosmallbitvec | 已审查 | 2026-05-09 08:02 | 2026-06-09 07:35 |
| GHSA-6C8G-7P36-R338 CVE-2026-44788 | SharpCompress has directory traversal via directory entries in WriteToDirectory (zip slip variant) | 中危 | NuGetSharpCompress | 已审查 | 2026-05-09 07:50 | 2026-07-22 04:10 |
| GHSA-G8R3-5HWF-QP96 CVE-2026-44900 | epa4all-client has a VAU Signature bypass | 高危 | Mavencom.oviva.telematik:epa4all-client | 已审查 | 2026-05-09 07:47 | 2026-06-09 07:34 |
| GHSA-58CW-G322-P94V CVE-2026-44896 | Mistune has XSS via unescaped figclass/figwidth in Figure directive | 中危 | PyPImistune | 已审查 | 2026-05-09 07:43 | 2026-06-09 07:34 |
| GHSA-8G87-J6Q8-G93X CVE-2026-44708 | Mistune Math Plugin has an XSS Escape Bypass | 中危 | PyPImistune | 已审查 | 2026-05-09 07:40 | 2026-06-09 07:30 |
| GHSA-HG3H-G7XC-F7VP CVE-2026-44837 | view_component: System Test Entry Point Path Check Allows Sibling Directory Escape | 中危 | RubyGemsview_component | 已审查 | 2026-05-09 07:33 | 2026-06-09 07:34 |
| GHSA-7F3R-GWC9-2995 CVE-2026-44836 | view_component: Preview Route Can Dispatch Inherited Helper Methods | 中危 | RubyGemsview_component | 已审查 | 2026-05-09 07:33 | 2026-06-09 07:34 |
| GHSA-MGHP-5CQ4-V6MG CVE-2026-44833 | Snipe-IT has an open redirect vulnerability | 中危 | Packagistsnipe/snipe-it | 已审查 | 2026-05-09 07:25 | 2026-06-09 07:30 |
| GHSA-MV93-W799-CJ2W | GitPython: Newline injection in config_writer() section parameter bypasses CVE-2026-42215 patch, enabling RCE via core.hooksPath | 高危 | PyPIGitPython | 已审查 | 2026-05-09 07:19 | 2026-05-09 07:19 |
| GHSA-G47V-RWMH-R9F8 CVE-2026-44844 | eml_parser has recursion DoS via nested message/rfc822 attachments | 中危 | PyPIeml_parser | 已审查 | 2026-05-09 07:12 | 2026-06-09 07:30 |
| GHSA-PJWX-R37V-7724 CVE-2026-44843 | LangChain vulnerable to unsafe deserialization of attacker-controlled objects through overly broad `load()` allowlists | 高危 | PyPIlangchain-core | 已审查 | 2026-05-09 07:07 | 2026-06-09 07:30 |
| GHSA-2F25-PFQ3-C7H8 CVE-2023-49316 | Phpseclib needs guardrails on large binaryfield integers | 高危 | Packagistphpseclib/phpseclib | 已审查 | 2026-05-09 07:06 | 2026-05-09 07:06 |