检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-42VX-43VC-X6PR CVE-2026-57570 | Laravel Backpack CRUD: HasMany/MorphMany relation fields allow cross-tenant record re-parenting (IDOR) via attachManyRelation | 中危 | Packagistbackpack/crud | 已审查 | 2026-08-21 02:42 | 2026-08-21 02:42 |
| GHSA-3VRH-M9W7-V94F CVE-2026-55468 | Wagtail: Improper restriction handling on Pages admin API |
当前筛选结果 366,391 条 · 时间按北京时间显示
| 中危 |
PyPIwagtail |
| 已审查 |
| 2026-08-21 02:42 |
| 2026-08-21 02:42 |
| GHSA-GHVF-QF6H-G8X5 | NocoBase: Arbitrary File Write chained with Local file Inclusion leads to Remote code execution | 高危 | npm@nocobase/server | 已审查 | 2026-08-21 02:42 | 2026-08-21 02:42 |
| GHSA-VGXM-H9GX-H9W7 CVE-2026-54624 | django CMS: Structure endpoint bypasses page-view permission | 中危 | PyPIdjango-cms | 已审查 | 2026-08-21 02:42 | 2026-08-21 02:42 |
| GHSA-4XFR-4P46-GC6P CVE-2026-54622 | django CMS: Clipboard copy IDOR discloses unauthorized plugin content | 中危 | PyPIdjango-cms | 已审查 | 2026-08-21 02:42 | 2026-08-21 02:42 |
| GHSA-23M2-MGHX-VQMF CVE-2026-54263 | Wagtail: Reflected XSS in dynamic image URL generator view | 高危 | PyPIwagtail | 已审查 | 2026-08-21 02:40 | 2026-08-21 02:40 |
| GHSA-8634-MR4J-R72C CVE-2026-54262 | Wagtail: Pages translations can be created without page permissions when using simple_translation | 中危 | PyPIwagtail | 已审查 | 2026-08-21 02:40 | 2026-08-21 02:40 |
| GHSA-R6P4-GRQ7-XM4M CVE-2026-54261 | Wagtail: Improper permission handling in image preview | 中危 | PyPIwagtail | 已审查 | 2026-08-21 02:40 | 2026-08-21 02:40 |
| GHSA-F2P5-J6FG-5CXF CVE-2026-54260 | Wagtail: Denial of service via unbounded filter specs in the image preview | 中危 | PyPIwagtail | 已审查 | 2026-08-21 02:40 | 2026-08-21 02:40 |
| GHSA-H54R-XQ46-QWQM CVE-2026-54259 | Wagtail: Improper restriction handling on Documents and Images chosen endpoints | 中危 | PyPIwagtail | 已审查 | 2026-08-21 02:40 | 2026-08-21 02:40 |
| GHSA-3277-H8G9-QJ5F CVE-2026-54256 | Winter: Authenticated IDOR in backend FileUpload widget allows cross-user access to attachment metadata | 中危 | Packagistwinter/wn-backend-module | 已审查 | 2026-08-21 02:39 | 2026-08-21 02:39 |
| GHSA-VMR9-J6WF-PMH2 CVE-2026-54251 | netty-incubator-codec-ohttp: [OHttpServerCodec] Native Direct-Memory Leak on AEAD Decryption Failure Leads to Gateway Denial of Service | 高危 | Mavenio.netty.incubator:netty-incubator-codec-ohttp | 已审查 | 2026-08-21 02:39 | 2026-08-21 02:39 |
| GHSA-7Q96-F8XW-JV5J CVE-2026-54245 | Fleet: SQL injection in Okta conditional access endpoint allows host-controlled compromise of the Fleet database | 高危 | Gogithub.com/fleetdm/fleet | 已审查 | 2026-08-21 02:39 | 2026-08-21 02:39 |
| GHSA-MRC5-3MM3-45C5 CVE-2026-54182 | Laravel Backpack CRUD: OS command injection in Stats::makeCurlRequest via attacker-controlled Host header (pre-auth) | 高危 | Packagistbackpack/crud | 已审查 | 2026-08-21 02:38 | 2026-08-21 02:38 |
| GHSA-MMG4-322V-6JVC CVE-2026-54181 | Laravel Backpack CRUD: Stored XSS in the color column — the `@if($column['escaped'])` branches are inverted | 中危 | Packagistbackpack/crud | 已审查 | 2026-08-21 02:38 | 2026-08-21 02:38 |
| GHSA-VGMV-8XJC-6RCH CVE-2026-54180 | Laravel Backpack CRUD: CRUD panel query scopes are not enforced on Update, Delete, and Reorder (cross-tenant IDOR) | 高危 | Packagistbackpack/crud | 已审查 | 2026-08-21 02:38 | 2026-08-21 02:38 |
| GHSA-8HW4-7QJR-3WXG CVE-2026-54179 | Laravel Backpack CRUD: SingleBase64Image accepts any base64 payload behind a `data:image` prefix — SVG-with-script lands on the public disk | 中危 | Packagistbackpack/crud | 已审查 | 2026-08-21 02:38 | 2026-08-21 02:38 |
| GHSA-8XJM-WQRP-2F25 CVE-2026-54178 | Laravel Backpack CRUD: Arbitrary file deletion via attacker-controlled clear_<attr>[] in HasUploadFields::uploadMultipleFilesToDisk | 高危 | Packagistbackpack/crud | 已审查 | 2026-08-21 02:38 | 2026-08-21 02:38 |
| GHSA-8Q2W-PV9P-MJVC CVE-2026-54177 | Laravel Backpack CRUD: HasUploadFields keeps the attacker-supplied file extension — public-disk uploads of `shell.php` reach the webserver | 中危 | Packagistbackpack/crud | 已审查 | 2026-08-21 02:38 | 2026-08-21 02:38 |
| GHSA-9FW9-8C49-QCH8 CVE-2026-54176 | Laravel Backpack CRUD: MyAccountController allows changing the login email without a current-password check | 中危 | Packagistbackpack/crud | 已审查 | 2026-08-21 02:38 | 2026-08-21 02:38 |
| GHSA-XPV2-HRFC-HW62 CVE-2026-54175 | Laravel Backpack CRUD: Unverified password change in MyAccountController via mass assignment | 高危 | Packagistbackpack/crud | 已审查 | 2026-08-21 02:38 | 2026-08-21 02:38 |
| GHSA-V667-GC2R-2XM7 CVE-2026-55445 | Qinglong has an incomplete fix for CVE-2026-3965: Improper Authentication | 严重 | npm@whyour/qinglong | 已审查 | 2026-08-21 02:36 | 2026-08-21 02:36 |
| GHSA-6F2P-296R-CC28 CVE-2026-54168 | Tekton Pipelines-as-Code: Unscoped GitHub App installation token allows unauthorized access to private repositories via remote task resolution | 中危 | Gogithub.com/openshift-pipelines/pipelines-as-code | 已审查 | 2026-08-21 02:36 | 2026-08-21 02:36 |
| GHSA-F5F4-3HH4-F54M CVE-2026-54167 | Pipelines-as-Code GitHub App token request can be redirected via untrusted Enterprise Host header | 高危 | Gogithub.com/openshift-pipelines/pipelines-as-code | 已审查 | 2026-08-21 02:36 | 2026-08-21 02:36 |
| GHSA-22W5-2FXG-VRWX | OpenTofu has high CPU usage when using K8S remote state backend or when parsing specifically crafted TLS certificates from untrusted or compromised servers | 低危 | Gogithub.com/opentofu/opentofu | 已审查 | 2026-08-21 02:36 | 2026-08-21 02:36 |