检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-FQ3V-XJJX-95RC CVE-2026-44568 | Open WebUI has Stored XSS in Pending User Overlay via Incorrect DOMPurify Application Order | 中危 | PyPIopen-webui | 已审查 | 2026-05-09 06:21 | 2026-05-16 07:53 |
| GHSA-M9G3-3G99-MHPX CVE-2026-44214 | eventsource-encoder vulnerable to SSE event injection via unsanitized `event` and `id` fields |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 中危 |
npmeventsource-encoder |
| 已审查 |
| 2026-05-09 04:49 |
| 2026-06-09 07:29 |
| GHSA-WFR5-454P-MJC2 CVE-2026-44213 | OpenTelemetry.Exporter.Instana bypasses TLS certificate validation when a proxy is configured | 中危 | NuGetOpenTelemetry.Exporter.Instana | 已审查 | 2026-05-09 04:48 | 2026-06-09 07:34 |
| GHSA-8WXP-XXP2-RCGX CVE-2026-44247 | Volcano's webhook server vulnerable to OOM due to unbounded HTTP request body size | 中危 | Govolcano.sh/volcano | 已审查 | 2026-05-09 04:44 | 2026-06-09 07:54 |
| GHSA-5C57-RQJX-35G2 CVE-2026-44211 | Cline Kanban Server has a Cross-Origin WebSocket Hijacking Vulnerability | 严重 | npmcline | 已审查 | 2026-05-09 04:43 | 2026-06-09 18:50 |
| GHSA-GPHH-9Q3H-JGPP CVE-2026-44209 | banks has Critical Remote Code Execution (RCE) via Jinja2 SSTI | 高危 | PyPIbanks | 已审查 | 2026-05-09 04:36 | 2026-06-09 07:29 |
| GHSA-FV7C-FP4J-7GWP CVE-2026-44728 | @babel/plugin-transform-modules-systemjs generates arbitrary code when compiling malicious input | 高危 | npm@babel/plugin-transform-modules-systemjs | 已审查 | 2026-05-09 04:34 | 2026-06-09 07:28 |
| GHSA-628H-Q48J-JR6Q CVE-2026-32689 | Phoenix: Long-poll NDJSON body splitting causes large memory allocation | 高危 | Hexphoenix | 已审查 | 2026-05-09 04:24 | 2026-05-09 04:24 |
| GHSA-67RV-MG8Q-5PF3 CVE-2026-44200 | Wagtail has improper permission handling when copying pages | 中危 | PyPIwagtail | 已审查 | 2026-05-09 04:23 | 2026-06-09 03:56 |
| GHSA-P5GM-92H4-6PV6 CVE-2026-44201 | Wagtail has improper restriction handling on Documents and Images API | 中危 | PyPIwagtail | 已审查 | 2026-05-09 04:21 | 2026-06-09 03:55 |
| GHSA-PWM3-7FV4-G6XX CVE-2026-44199 | Wagtail has improper permission handling when deleting form submissions | 中危 | PyPIwagtail | 已审查 | 2026-05-09 04:20 | 2026-06-09 03:55 |
| GHSA-C4MR-889M-VGF6 CVE-2026-44198 | Wagtail has improper permission handling when viewing page history | 中危 | PyPIwagtail | 已审查 | 2026-05-09 04:19 | 2026-06-09 03:55 |
| GHSA-C6WJ-9VCJ-75PJ CVE-2026-44197 | Wagtail has improper permission handling when comparing revisions | 中危 | PyPIwagtail | 已审查 | 2026-05-09 04:17 | 2026-06-09 03:53 |
| GHSA-QHH4-458H-XWH2 | @cyclonedx/cdxgen: Docker registry auth substring match forwards credentials to a different registry | 中危 | npm@cyclonedx/cdxgen | 已审查 | 2026-05-09 04:06 | 2026-05-09 04:06 |
| GHSA-H36F-RQPX-J5WX CVE-2026-44560 | Open WebUI has Unauthorized File and Knowledge Base Content Access via RAG Vector Search | 中危 | PyPIopen-webui | 已审查 | 2026-05-09 04:03 | 2026-05-16 07:53 |
| GHSA-HMGR-67HW-J2CQ CVE-2026-44561 | Open WebUI: Deactivated Channel Members Retain Full Access to Group/DM Channels | 中危 | PyPIopen-webui | 已审查 | 2026-05-09 04:01 | 2026-05-16 07:53 |
| GHSA-VRFH-RJ4Q-RMHR CVE-2026-44564 | Read-Only Open WebUI Users Can Modify Collaborative Documents via Socket.IO | 中危 | PyPIopen-webui | 已审查 | 2026-05-09 04:00 | 2026-06-09 19:52 |
| GHSA-RCVP-6FGW-C7FH CVE-2026-44563 | Open WebUI's Ollama Model Access Control Bypass via /api/generate, /api/embed, /api/embeddings, and /api/show | 中危 | PyPIopen-webui | 已审查 | 2026-05-09 03:52 | 2026-05-16 07:53 |
| GHSA-MQQ6-CQCX-38VG CVE-2026-44562 | Open WebUI's Model Import Overwrites Any Model Without Ownership Check | 中危 | PyPIopen-webui | 已审查 | 2026-05-09 03:52 | 2026-05-16 07:53 |
| GHSA-C7WP-3QH5-55PV CVE-2026-44559 | Open WebUI Missing Access Check on Channel Members Endpoint for Standard Channels | 中危 | PyPIopen-webui | 已审查 | 2026-05-09 03:51 | 2026-05-16 07:53 |
| GHSA-6C2X-GCP3-GP73 CVE-2026-44557 | Open WebUI vulnerable to Global Knowledge Base Enumeration via knowledge-bases Meta-Collection | 中危 | PyPIopen-webui | 已审查 | 2026-05-09 03:51 | 2026-05-16 07:52 |
| GHSA-7R82-QHG4-6WVJ CVE-2026-44554 | Open WebUI has Knowledge Base Destruction and RAG Poisoning via Unauthorized Collection Overwrite | 高危 | PyPIopen-webui | 已审查 | 2026-05-09 03:51 | 2026-05-16 07:52 |
| GHSA-7RJH-PX4V-5W55 CVE-2026-44558 | Open WebUI's Channel Access Grants Bypass filter_allowed_access_grants | 中危 | PyPIopen-webui | 已审查 | 2026-05-09 03:50 | 2026-05-16 07:52 |
| GHSA-HP5M-24VP-VQ2Q CVE-2026-44556 | Open WebUI's responses passthrough endpoint lacks access control authorization | 高危 | PyPIopen-webui | 已审查 | 2026-05-09 03:45 | 2026-05-16 07:52 |
| GHSA-9VVH-QMJX-P4Q8 CVE-2026-44555 | Open WebUI's Base Model Routing Bypasses Access Control via Model Chaining | 高危 | PyPIopen-webui | 已审查 | 2026-05-09 03:45 | 2026-05-16 07:52 |