检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-XG82-2HRV-HF64 CVE-2026-37709 | Snipe-IT has insecure permissions in file uploads | 严重 | Packagistsnipe/snipe-it | 已审查 | 2026-05-09 07:04 | 2026-05-09 07:04 |
| GHSA-RWWW-X45W-P52W CVE-2026-44330 |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 严重 |
Gogithub.com/free5gc/nef |
| 已审查 |
| 2026-05-09 07:02 |
| 2026-06-09 07:48 |
| GHSA-3258-QMV8-FRP3 CVE-2026-44329 | free5GC's SMF UPI management interface lacks auth middleware; unauthenticated topology read/write requests reach handlers | 严重 | Gogithub.com/free5gc/smf | 已审查 | 2026-05-09 07:02 | 2026-06-09 04:12 |
| GHSA-P9MG-74MG-CWWR CVE-2026-44328 | free5GC's SMF UPI DELETE /upi/v1/upNodesLinks/{ref} panics on AN-node deletion via nil UPF dereference; unauthenticated, state-mutating | 高危 | Gogithub.com/free5gc/smf | 已审查 | 2026-05-09 07:01 | 2026-06-09 07:48 |
| GHSA-CMPJ-2X3G-M7G3 CVE-2026-44327 | free5GC's NEF nnef-oam route group is unauthenticated; no-token requests reach the OAM handler | 严重 | Gogithub.com/free5gc/nef | 已审查 | 2026-05-09 06:59 | 2026-07-21 21:57 |
| GHSA-3P28-73Q7-45XP CVE-2026-44326 | free5GC's NEF 3gpp-traffic-influence API is unauthenticated; missing or forged bearer tokens can create, read, patch, and delete subscriptions | 严重 | Gogithub.com/free5gc/nef | 已审查 | 2026-05-09 06:58 | 2026-06-09 07:48 |
| GHSA-F8QV-7X5W-QR48 CVE-2026-44325 | free5GC NRF: type-confusion panic in POST /oauth2/token structured-form parser via Reflect.Set on incompatible types | 高危 | Gogithub.com/free5gc/nrf | 已审查 | 2026-05-09 06:56 | 2026-06-09 07:48 |
| GHSA-JQFC-GWJ5-3W63 CVE-2026-44324 | free5GC's UDR nudr-dr DELETE amf-subscriptions panics on missing UE state via nil interface type assertion (single authenticated request) | 中危 | Gogithub.com/free5gc/udr | 已审查 | 2026-05-09 06:52 | 2026-06-09 07:48 |
| GHSA-4RQF-GRM6-VF75 CVE-2026-44323 | free5GC's UDR nudr-dr DELETE amf-subscriptions panics on missing subsId when UE state exists (nil pointer dereference) | 中危 | Gogithub.com/free5gc/udr | 已审查 | 2026-05-09 06:52 | 2026-06-09 07:48 |
| GHSA-J59F-X285-69JX CVE-2026-44322 | free5GC's NEF 3gpp-pfd-management PATCH applications/{appId} panics on UDR access failure due to nil ProblemDetails dereference | 高危 | Gogithub.com/free5gc/nef | 已审查 | 2026-05-09 06:50 | 2026-06-09 07:47 |
| GHSA-44QJ-CGHF-9P97 CVE-2026-44321 | free5GC's SMF UPI POST /upi/v1/upNodesLinks exits the SMF process on overlapping UE pools (unauthenticated, reachable Fatalf) | 高危 | Gogithub.com/free5gc/smf | 已审查 | 2026-05-09 06:47 | 2026-06-09 07:47 |
| GHSA-WQFH-GQ79-J8MF CVE-2026-44320 | free5GC's NEF nnef-callback route group is unauthenticated; forged callback requests are accepted into the processing path | 高危 | Gogithub.com/free5gc/nef | 已审查 | 2026-05-09 06:46 | 2026-06-09 07:47 |
| GHSA-RXRQ-FV76-26PR CVE-2026-44319 | free5GC's NEF crashes via logger.Fatal on PFD notification delivery failure (attacker-controlled notifyUri) | 高危 | Gogithub.com/free5gc/nef | 已审查 | 2026-05-09 06:44 | 2026-06-09 07:47 |
| GHSA-27PH-8Q4F-H7M7 CVE-2026-44318 | free5GC's BSF concurrent PUT /nbsf-management/v1/subscriptions/{subId} crashes the BSF process via concurrent map read/write on Subscriptions | 中危 | Gogithub.com/free5gc/bsf | 已审查 | 2026-05-09 06:41 | 2026-06-09 04:11 |
| GHSA-WWQH-7JM5-GJ7W CVE-2026-44317 | free5GC's PCF npcf-policyauthorization POST /app-sessions panics on suppFeat=1 with missing AfRoutReq via nil pointer dereference | 中危 | Gogithub.com/free5gc/pcf | 已审查 | 2026-05-09 06:40 | 2026-06-09 07:47 |
| GHSA-WR8J-6CHW-GM6P CVE-2026-44316 | free5GC's PCF npcf-smpolicycontrol POST /sm-policies panics on downstream UDR/OpenAPI 404 via nil pointer dereference | 高危 | Gogithub.com/free5gc/pcf | 已审查 | 2026-05-09 06:39 | 2026-06-09 07:47 |
| GHSA-5F62-53R8-QRQF CVE-2026-44315 | free5GC's NEF 3gpp-pfd-management API is unauthenticated; forged bearer tokens can create, read, and delete PFD transactions | 严重 | Gogithub.com/free5gc/nef | 已审查 | 2026-05-09 06:39 | 2026-06-09 07:47 |
| GHSA-7RMH-48MX-2VWC CVE-2026-44309 | gitsign verify accepts signatures over go-git-normalized bytes, enabling trust confusion on malformed commits | 中危 | Gogithub.com/sigstore/gitsign | 已审查 | 2026-05-09 06:38 | 2026-05-16 07:49 |
| GHSA-9PGH-J74G-QJ6M CVE-2026-44566 | Open WebUI Vulnerable to Arbitrary File Upload and Path Traversal | 高危 | PyPIopen-webui | 已审查 | 2026-05-09 06:38 | 2026-05-19 23:57 |
| GHSA-4VG5-RP28-GVJF CVE-2026-44567 | Open WebUI has Improper Authorization Control | 高危 | PyPIopen-webui | 已审查 | 2026-05-09 06:34 | 2026-05-19 23:57 |
| GHSA-JWF8-PV5P-VHMC CVE-2026-44549 | Open WebUI has stored XSS in Excel file preview | 高危 | PyPIopen-webui | 已审查 | 2026-05-09 06:26 | 2026-05-19 23:57 |
| GHSA-HQ28-CRG7-95PR CVE-2026-44832 | Snipe-IT has Privilege Escalation via API Permissions Assignment | 高危 | Packagistsnipe/snipe-it | 已审查 | 2026-05-09 06:24 | 2026-07-02 22:48 |
| GHSA-PMWQ-PJRM-6P5R | in-toto-golang and in-toto-python have inconsistent negation behavior | 中危 | Gogithub.com/in-toto/in-toto-golang | 已审查 | 2026-05-09 06:24 | 2026-05-09 06:24 |
| GHSA-R42M-953Q-6VJX CVE-2026-44831 | Snipe-IT has Stored XSS via Component Checkout Notes (v8.4.0) | 中危 | Packagistsnipe/snipe-it | 已审查 | 2026-05-09 06:23 | 2026-06-09 07:29 |
| GHSA-H5FH-7HWR-97MW CVE-2026-44298 | Kimai has an arbitrary file read in its invoice PDF renderer (admin) | 中危 | Packagistkimai/kimai | 已审查 | 2026-05-09 06:22 | 2026-05-09 06:22 |