检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-FQ7H-9X26-6J22 CVE-2026-42876 | ExternalSecrets vulnerable to privilege escalation with secret overwriting | 中危 | Gogithub.com/external-secrets/external-secrets/apis | 已审查 | 2026-05-09 01:24 | 2026-05-13 22:19 |
| GHSA-R48C-V28R-PF6V CVE-2026-44430 | MCP Registry has an unauthenticated SSRF: HTTP namespace verification dials 6to4 / NAT64 / site-local IPv6 addresses, bypassing private-address allowlist |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 中危 |
Gogithub.com/modelcontextprotocol/registry |
| 已审查 |
| 2026-05-09 01:20 |
| 2026-05-16 07:46 |
| GHSA-RQV2-M695-F8J4 CVE-2026-44429 | MCP Registry vulnerable to stored XSS in catalogue UI via attribute-quote breakout in publisher-controlled `websiteUrl` | 中危 | Gogithub.com/modelcontextprotocol/registry | 已审查 | 2026-05-09 01:18 | 2026-05-16 07:46 |
| GHSA-Q3J6-QGPJ-74H6 CVE-2026-6321 | fast-uri vulnerable to path traversal via percent-encoded dot segments | 高危 | npmfast-uri | 已审查 | 2026-05-09 01:15 | 2026-08-20 23:33 |
| GHSA-QXHC-WX3P-2WMG CVE-2026-7768 | @fastify/accepts-serializer Vulnerable to Denial of Service via Unbounded Accept Header Cache Growth | 高危 | npm@fastify/accepts-serializer | 已审查 | 2026-05-09 01:13 | 2026-05-09 01:13 |
| GHSA-RXVX-HHPJ-Q6PX CVE-2026-44671 | ZITADEL has LDAP Filter Injection in Login Flow | 高危 | Gogithub.com/zitadel/zitadel | 已审查 | 2026-05-09 01:11 | 2026-05-16 07:47 |
| GHSA-QWFW-GGXW-577C CVE-2026-44700 | ex_webrtc client-role handshake is missing DTLS peer fingerprint validation | 高危 | Hexex_webrtc | 已审查 | 2026-05-09 01:08 | 2026-05-16 07:46 |
| GHSA-95C3-6VVW-4MRQ CVE-2026-44428 | MCP Registry's GitHub OIDC tokens are replayable across registry deployments due to shared audience | 低危 | Gogithub.com/modelcontextprotocol/registry | 已审查 | 2026-05-09 01:06 | 2026-05-16 07:47 |
| GHSA-V8VW-GW5J-W7M6 CVE-2026-44427 | MCP Registry has open redirect via protocol-relative path in trailing-slash middleware | 中危 | Gogithub.com/modelcontextprotocol/registry | 已审查 | 2026-05-09 01:02 | 2026-05-16 07:47 |
| GHSA-8G7G-HMWM-6RV2 | n8n-mcp affected by path traversal, redirect-following SSRF, and telemetry payload exposure | 高危 | npmn8n-mcp | 已审查 | 2026-05-09 01:00 | 2026-05-09 01:00 |
| GHSA-CMRH-WVQ6-WM9R CVE-2026-44694 | n8n-mcp webhook and API client paths has an authenticated SSRF | 高危 | npmn8n-mcp | 已审查 | 2026-05-09 00:59 | 2026-05-13 21:35 |
| GHSA-W9F3-QC75-QGX9 CVE-2026-44212 | PrestaShop has a stored XSS executable in customer service view | 严重 | Packagistprestashop/prestashop | 已审查 | 2026-05-09 00:54 | 2026-05-09 00:54 |
| GHSA-2H64-C999-C9R6 CVE-2026-44670 | SiYuan Affected by Stored XSS via Attribute View Name to Electron Renderer RCE | 严重 | Gogithub.com/siyuan-note/siyuan/kernel | 已审查 | 2026-05-09 00:53 | 2026-06-09 04:11 |
| GHSA-52CQ-7V8R-62C6 | gmaps-mcp's unauthenticated HTTP transport allows unlimited Google Maps API calls at operator expense | 高危 | PyPIgmaps-mcp | 已审查 | 2026-05-09 00:32 | 2026-05-09 00:32 |
| GHSA-5WM8-GMM8-39J9 CVE-2026-44665 | fast-xml-builder allows attribute values with unwanted quotes to bypass malicious or unwanted attributes | 高危 | npmfast-xml-builder | 已审查 | 2026-05-09 00:29 | 2026-05-15 04:37 |
| GHSA-45C6-75P6-83CC CVE-2026-44664 | fast-xml-builder Comment Value regex can be bypassed | 中危 | npmfast-xml-builder | 已审查 | 2026-05-09 00:27 | 2026-05-15 04:37 |
| GHSA-2CM2-M3W5-GP2F | vm2 has access to `VM2_INTERNAL_STATE_DO_NOT_USE_OR_PROGRAM_WILL_FAIL` | 中危 | npmvm2 | 已审查 | 2026-05-09 00:22 | 2026-05-09 00:22 |
| GHSA-9VG3-4RFJ-WGCM CVE-2026-44009 | vm2 has Sandbox Breakout Through Null Proto Exception | 严重 | npmvm2 | 已审查 | 2026-05-09 00:20 | 2026-05-15 04:37 |
| GHSA-9QJ6-QJGG-37QQ CVE-2026-44008 | vm2 has sandbox breakout via `neutralizeArraySpeciesBatch` | 严重 | npmvm2 | 已审查 | 2026-05-08 23:58 | 2026-05-15 04:37 |
| GHSA-JP94-3292-C3XV CVE-2026-40295 | Devise has an Open Redirect via Unvalidated `request.referrer` in Timeoutable Session Timeout Handler | 中危 | RubyGemsdevise | 已审查 | 2026-05-08 23:41 | 2026-05-30 05:44 |
| GHSA-2J9M-25XV-MP6R CVE-2026-39816 | Apache NiFi is missing the Restricted annotation with the Execute Code Required Permission | 高危 | Mavenorg.apache.nifi:nifi-other-graph-services-nar | 已审查 | 2026-05-08 23:31 | 2026-05-14 21:08 |
| GHSA-MX76-R943-RF8G CVE-2026-8149 | Bouncy Castle LTS native GCM chunking can cause bad-tag exception on decryption | 中危 | Mavenorg.bouncycastle:bcprov-lts8on | 已审查 | 2026-05-08 17:31 | 2026-07-08 05:30 |
| GHSA-RCC6-6Q2F-M2CW CVE-2023-42344 | Alkacon OpenCms allows remote unauthenticated attackers to obtain sensitive information | 高危 | Mavenorg.opencms:opencms-core | 已审查 | 2026-05-08 14:32 | 2026-05-14 21:05 |
| GHSA-PJ6P-9P8X-5MFC CVE-2023-42346 | Alkacon OpenCms is vulnerable to XXE when the <!DOCTYPE> refers to an external host | 高危 | Mavenorg.opencms:opencms-core | 已审查 | 2026-05-08 14:32 | 2026-05-14 21:05 |
| GHSA-8GPV-C454-3HFC CVE-2023-42343 | Alkacon OpenCms is vulnerable to XSS via cmis-online/type | 中危 | Mavenorg.opencms:opencms-core | 已审查 | 2026-05-08 14:32 | 2026-05-15 00:18 |