检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-3X8W-4F7P-XXC2 CVE-2026-44552 | Open WebUI: Redis Cache Keys tool_servers and terminal_servers Missing Instance Prefix Enable Cross-Instance Cache Poisoning | 高危 | PyPIopen-webui | 已审查 | 2026-05-09 03:44 | 2026-05-16 07:52 |
| GHSA-45M8-CPM2-3V65 CVE-2026-44553 |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 高危 |
PyPIopen-webui |
| 已审查 |
| 2026-05-09 03:43 |
| 2026-05-16 07:52 |
| GHSA-HR43-RJMR-7WMM CVE-2026-44550 | Open WebUI's Mass Assignment via Pydantic extra='allow' Allows Creating Folders in Other Users' Accounts | 中危 | PyPIopen-webui | 已审查 | 2026-05-09 03:38 | 2026-05-16 07:52 |
| GHSA-2R4P-JPMG-48F4 CVE-2026-44551 | Open WebUI has an LDAP Empty Password Authentication Bypass | 严重 | PyPIopen-webui | 已审查 | 2026-05-09 03:38 | 2026-05-16 07:52 |
| GHSA-FMG2-F5R9-24QC CVE-2026-44737 | Grav: Stored XSS via page title (data[header][title]) in admin panel | 中危 | Packagistgetgrav/grav | 已审查 | 2026-05-09 03:38 | 2026-05-13 22:04 |
| GHSA-CFW5-68C4-FFQP CVE-2026-44680 | MikroORM has SQL injection via runtime-controlled identifiers and JSON-path keys | 高危 | npm@mikro-orm/knex+1 | 已审查 | 2026-05-09 03:17 | 2026-06-09 07:27 |
| GHSA-V39H-62P7-JPJC CVE-2026-6322 | fast-uri vulnerable to host confusion via percent-encoded authority delimiters | 高危 | npmfast-uri | 已审查 | 2026-05-09 03:13 | 2026-09-01 23:30 |
| GHSA-H9HM-M2XJ-4RQ9 CVE-2026-44499 | Zebra has Permanent Block Discovery Halt via Gossip Queue Saturation and Syncer Poisoning | 高危 | crates.iozebrad | 已审查 | 2026-05-09 03:12 | 2026-05-09 03:12 |
| GHSA-FP53-QCF8-2XX2 CVE-2026-44502 | Bunsink has an SSRF bypass in `validate_webhook_url` | 中危 | PyPIbugsink | 已审查 | 2026-05-09 03:09 | 2026-06-09 07:27 |
| GHSA-25RP-H46X-2HJM CVE-2026-44588 | SiYuan: Electron Renderer RCE via decodeURIComponent-driven tooltip XSS in aria-label sink (incomplete fix for CVE-2026-34585) | 严重 | Gogithub.com/siyuan-note/siyuan/kernel | 已审查 | 2026-05-09 03:08 | 2026-06-09 04:11 |
| GHSA-GF5M-WCRH-7928 CVE-2026-44721 | open-webui Vulnerable to Stored XSS via Model Description | 高危 | npmopen-webui | 已审查 | 2026-05-09 03:00 | 2026-05-16 07:52 |
| GHSA-MPM8-CX2P-626Q CVE-2026-43944 | Electerm users can run dangrous code through link or command line | 严重 | npmelecterm | 已审查 | 2026-05-09 02:46 | 2026-05-13 21:32 |
| GHSA-Q4P8-8J9M-8HXJ CVE-2026-43943 | Electerm Security Vulnerability: RCE via malicious SSH server filename in openFileWithEditor | 高危 | npmelecterm | 已审查 | 2026-05-09 02:43 | 2026-05-09 02:43 |
| GHSA-37J4-88RP-2F6H CVE-2026-43942 | Electerm's full process.env exposed to renderer via window.pre.env | 中危 | npmelecterm | 已审查 | 2026-05-09 02:37 | 2026-05-09 02:37 |
| GHSA-FWF6-J56G-M97C CVE-2026-43941 | Electerm has an unvalidated shell.openExternal that allows arbitrary protocol execution via terminal link click | 高危 | npmelecterm | 已审查 | 2026-05-09 02:35 | 2026-05-09 02:35 |
| GHSA-F77V-9VPC-6PJM CVE-2026-43940 | Electerm runWidget has a path traversal that leads to arbitrary code execution | 严重 | npmelecterm | 已审查 | 2026-05-09 02:34 | 2026-05-09 02:34 |
| GHSA-C62G-J346-39V5 CVE-2026-42794 | absinthe_plug Has a Cross-site Scripting vulnerability | 低危 | Hexabsinthe_plug | 已审查 | 2026-05-09 02:31 | 2026-06-09 07:12 |
| GHSA-3RF6-X59V-5JFV CVE-2026-38360 | dash-uploader has a directory traversal vulnerability | 严重 | PyPIdash-uploader | 已审查 | 2026-05-09 02:31 | 2026-09-01 06:48 |
| GHSA-PVMV-CWG8-V6C8 | Zebra v4.4.0 still accepts V5 SIGHASH_SINGLE without a corresponding output | 严重 | crates.iozebra-script+1 | 已审查 | 2026-05-09 02:27 | 2026-05-09 02:27 |
| GHSA-F2QX-66WF-WVVX CVE-2024-27355 | phpseclib guardrails needed on OID length | 高危 | Packagistphpseclib/phpseclib | 已审查 | 2026-05-09 02:24 | 2026-05-09 02:24 |
| GHSA-R8CJ-3554-33MR | justhtml introduces denial-of-service hardening | 低危 | PyPIjusthtml | 已审查 | 2026-05-09 02:19 | 2026-05-09 02:19 |
| GHSA-HFCF-V2F8-X9PC CVE-2026-44714 | bitcoinj has a ScriptExecution P2PKH/P2WPKH Verification Bypass | 高危 | Mavenorg.bitcoinj:bitcoinj-core | 已审查 | 2026-05-09 01:43 | 2026-05-16 07:49 |
| GHSA-7HGR-XVRR-XPW3 | nhost has Session Persistence After Password Change | 低危 | Gogithub.com/nhost/nhost | 已审查 | 2026-05-09 01:39 | 2026-05-09 01:39 |
| GHSA-7C37-GX6W-8VC5 CVE-2026-44310 | gitsign --verify panics on empty-certificate PKCS7 and exits 0, bypassing exit-code callers | 中危 | Gogithub.com/sigstore/gitsign | 已审查 | 2026-05-09 01:37 | 2026-05-16 07:49 |
| GHSA-Q9M2-FHV9-3JCF | `potato-annotation` has a Project-Boundary Bypass | 中危 | PyPIpotato-annotation | 已审查 | 2026-05-09 01:31 | 2026-05-09 01:31 |