检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-22J2-JP4F-7GWX CVE-2026-46536 | 无摘要 | 未知 | —— | 未审查 | 2026-08-21 05:31 | 2026-08-21 05:31 |
| GHSA-F4JP-RW7W-CCWG CVE-2026-55451 | gettext-converter: Prototype pollution in js2i18next() via crafted translation keys |
当前筛选结果 366,391 条 · 时间按北京时间显示
| 中危 |
npmgettext-converter |
| 已审查 |
| 2026-08-21 04:11 |
| 2026-08-21 04:11 |
| GHSA-JM5P-837G-RV8G | Wagtail: Improper restriction handling on Page translation API endpoint | 中危 | PyPIwagtail | 已审查 | 2026-08-21 02:45 | 2026-08-21 02:45 |
| GHSA-X5CX-W6P2-MXF2 | Wagtail: Improper permission handling when copying snippets | 中危 | PyPIwagtail | 已审查 | 2026-08-21 02:45 | 2026-08-21 02:45 |
| GHSA-C2XX-CJMH-9Q8F | Wagtail: Improper restriction handling on descendant collections in Documents and Images API | 中危 | PyPIwagtail | 已审查 | 2026-08-21 02:45 | 2026-08-21 02:45 |
| GHSA-92HV-J533-69WC | Wagtail: Identification of documents by SHA1 hash | 低危 | PyPIwagtail | 已审查 | 2026-08-21 02:45 | 2026-08-21 02:45 |
| GHSA-HQ84-X37P-J6Q5 | Winter: Reflected XSS through the search query parameter in the backend Table widget | 中危 | Packagistwinter/wn-backend-module | 已审查 | 2026-08-21 02:45 | 2026-08-21 02:45 |
| GHSA-P2CH-C2C3-4XM5 | Winter: CSRF through AJAX handler names reachable as backend page actions | 中危 | Packagistwinter/wn-backend-module | 已审查 | 2026-08-21 02:44 | 2026-08-21 02:44 |
| GHSA-5CWR-5JXG-PCF6 | Winter: Stored XSS through cached Brand Settings and Editor Settings custom styles | 中危 | Packagistwinter/wn-backend-module | 已审查 | 2026-08-21 02:44 | 2026-08-21 02:44 |
| GHSA-FM29-4MQ3-PHG6 | Winter: ImportExportController AJAX handlers bypass granular import/export permission gate | 高危 | Packagistwinter/wn-backend-module | 已审查 | 2026-08-21 02:44 | 2026-08-22 03:10 |
| GHSA-MPMW-F6H6-3G26 | Winter: My Account preview exposes another backend user's profile by record ID | 中危 | Packagistwinter/wn-backend-module | 已审查 | 2026-08-21 02:44 | 2026-08-21 02:44 |
| GHSA-7MPF-4465-7FC2 | Winter: Stored XSS through Backend List widget image columns | 低危 | Packagistwinter/wn-backend-module | 已审查 | 2026-08-21 02:44 | 2026-08-21 02:44 |
| GHSA-RXHG-VCWW-2MPW | Fleet: ORDER BY column injection on activity list endpoints | 低危 | Gogithub.com/fleetdm/fleet/v4 | 已审查 | 2026-08-21 02:44 | 2026-08-21 02:44 |
| GHSA-Q9C5-PP7M-FM2G | Fleet: Unauthenticated download of in-house iOS app binaries via predictable URLs | 中危 | Gogithub.com/fleetdm/fleet/v4 | 已审查 | 2026-08-21 02:44 | 2026-08-21 02:44 |
| GHSA-8CFW-PCWH-V63W | Winter: Authenticated Twig sandbox escape in CMS SecurityPolicy (bypass of CVE-2024-54149) | 高危 | Packagistwinter/wn-system-module | 已审查 | 2026-08-21 02:44 | 2026-08-21 02:44 |
| GHSA-2223-F22X-24CQ | Winter: Local File Inclusion through =include directives in JavaScript asset compilation | 中危 | Packagistwinter/wn-system-module | 已审查 | 2026-08-21 02:44 | 2026-08-21 02:44 |
| GHSA-4899-MPCH-38P3 CVE-2026-63202 | netty-incubator-codec-ohttp BinaryHttpParser: Unauthenticated CPU-exhaustion DoS via infinite loop in field-section decoding | 高危 | Mavenio.netty.incubator:netty-incubator-codec-bhttp | 已审查 | 2026-08-21 02:43 | 2026-08-21 02:43 |
| GHSA-58FP-MCX6-7QF9 CVE-2026-63179 | Winter: Local File Inclusion through @import directives in LESS compilation of backend customizable stylesheets and theme assets | 中危 | Packagistwinter/wn-backend-module | 已审查 | 2026-08-21 02:43 | 2026-08-21 02:43 |
| GHSA-HMQ9-67W8-J5PW CVE-2026-61827 | netty-incubator-codec-ohttp: BinaryHttpParser should enforce limits for variable lengths fields | 高危 | Mavenio.netty.incubator:netty-incubator-codec-bhttp | 已审查 | 2026-08-21 02:43 | 2026-08-21 02:43 |
| GHSA-8CFX-WX3Q-MH5Q CVE-2026-63124 | netty-incubator-codec-ohttp: Binary HTTP parser infinite loop on known-length field section boundary | 高危 | Mavenio.netty.incubator:netty-incubator-codec-bhttp | 已审查 | 2026-08-21 02:43 | 2026-08-21 02:43 |
| GHSA-PGRF-4654-3GQ8 CVE-2026-61799 | netty-incubator-codec-ohttp: Binary HTTP parser unchecked varint length overflow causes decoder crash | 中危 | Mavenio.netty.incubator:netty-incubator-codec-bhttp | 已审查 | 2026-08-21 02:43 | 2026-08-21 02:43 |
| GHSA-2MC4-J865-9Q4R CVE-2026-61798 | netty-incubator-codec-ohttp: BoringSSL HPKE private key bytes exposed through toString() and exception messages | 高危 | Mavenio.netty.incubator:netty-incubator-codec-ohttp-hpke-classes-boringssl | 已审查 | 2026-08-21 02:43 | 2026-08-21 02:43 |
| GHSA-8QJ2-C6Q4-F399 CVE-2026-61663 | django CMS: Missing authorization in `render_object_structure` discloses non-PageContent placeholder structure to low-privileged staff | 中危 | PyPIdjango-cms | 已审查 | 2026-08-21 02:42 | 2026-08-21 02:42 |
| GHSA-6X92-6VX4-5FWR CVE-2026-63003 | django CMS: Broken access control in page *Duplicate* allows reading the content of any page (cross-site / restriction bypass) | 中危 | PyPIdjango-cms | 已审查 | 2026-08-21 02:42 | 2026-08-21 02:42 |
| GHSA-HVQ6-2R72-P2X7 CVE-2026-75526 | django CMS: Stored XSS in edit-mode plugin exception rendering | 中危 | PyPIdjango-cms | 已审查 | 2026-08-21 02:42 | 2026-08-21 02:42 |