检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-6C5V-HQJR-5XXP CVE-2026-79921 | amqp091-go has a Potential Memory Exhaustion/Protocol Violation via Broker-Controlled Oversized Payload | 高危 | Gogithub.com/rabbitmq/amqp091-go | 已审查 | 2026-09-04 04:15 | 2026-09-04 04:15 |
| GHSA-JXWJ-J7WR-GFRW CVE-2026-63670 |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 中危 |
npmsanitize-html |
| 已审查 |
| 2026-09-04 04:07 |
| 2026-09-04 04:07 |
| GHSA-WR5R-WQP2-X4FH CVE-2026-63669 | ApostropheCMS: Missing destination-parent authorization in page `move()` allows a low-privileged editor to move and re-rank pages inside a restricted subtree | 中危 | npmapostrophe | 已审查 | 2026-09-04 04:05 | 2026-09-04 04:05 |
| GHSA-XVG9-69GF-FJRF CVE-2026-73295 | Material for MkDocs: DOM XSS in search suggestions via query parameter | 中危 | PyPImkdocs-material | 已审查 | 2026-09-04 03:52 | 2026-09-04 03:52 |
| GHSA-P95V-992W-H6C3 CVE-2026-82404 | TOON: Prototype pollution when decoding untrusted TOON input | 高危 | npm@toon-format/toon | 已审查 | 2026-09-04 03:52 | 2026-09-04 03:52 |
| GHSA-79WM-X847-7CVG CVE-2026-73222 | Claude Code Templates: Unauthenticated OS command injection (RCE) in Claude Code Studio server (--studio) | 高危 | npmclaude-code-templates | 已审查 | 2026-09-04 03:50 | 2026-09-04 03:50 |
| GHSA-CXVF-GVFQ-36W2 CVE-2026-73293 | Semaphore UI: Manager-to-owner privilege escalation via custom-role slug collision | 高危 | Gogithub.com/semaphoreui/semaphore | 已审查 | 2026-09-04 03:23 | 2026-09-04 03:23 |
| GHSA-8CJ9-R88M-8945 CVE-2026-73292 | Semaphore UI: CSRF vulnerability on password change endpoint - No CSRF token or password confirmation | 高危 | Gogithub.com/semaphoreui/semaphore | 已审查 | 2026-09-04 03:23 | 2026-09-04 03:23 |
| GHSA-FG9P-MRXR-HVQ7 CVE-2026-62681 | Orval: RCE via OpenAPI path -> unescaped request-URL template literal (backtick breakout) | 严重 | npmorval | 已审查 | 2026-09-04 03:17 | 2026-09-04 03:17 |
| GHSA-88F2-FPV8-89Q2 CVE-2026-62682 | Orval: RCE via servers[].url -> unescaped request-URL template literal (with getBaseUrlFromSpecification) | 严重 | npmorval | 已审查 | 2026-09-04 03:06 | 2026-09-04 03:06 |
| GHSA-W727-8J6C-2RJ4 CVE-2026-72717 | Orval: Import-time RCE via schema default -> zod module-level template literal | 严重 | npmorval | 已审查 | 2026-09-04 03:03 | 2026-09-04 03:03 |
| GHSA-2H9G-J24R-H63G CVE-2026-71869 | Orval: Import-time RCE via array-items default -> zod module-level template literal | 严重 | npmorval | 已审查 | 2026-09-04 02:38 | 2026-09-04 02:38 |
| GHSA-8J6P-R8JG-MXQH CVE-2026-71871 | Orval: Import-time RCE via header-parameter default -> zod module-level template literal | 严重 | npmorval | 已审查 | 2026-09-04 02:32 | 2026-09-04 02:32 |
| GHSA-2W86-XFRC-G85R CVE-2026-71867 | Orval: RCE via schema property name -> computed-property-key injection in the MSW mock generator | 严重 | npmorval | 已审查 | 2026-09-04 02:26 | 2026-09-04 02:26 |
| GHSA-3575-W9FC-C2J6 CVE-2026-71868 | Orval: Import-time RCE via enum-typed default -> zod module-level template literal | 严重 | npmorval | 已审查 | 2026-09-04 02:20 | 2026-09-04 02:20 |
| GHSA-653Q-5476-X79G CVE-2026-71865 | Orval: Import-time RCE via query parameter name -> computed-property-key injection in the zod cli | 严重 | npmorval | 已审查 | 2026-09-04 02:18 | 2026-09-04 02:18 |
| GHSA-6437-GXHQ-PQV8 CVE-2026-71864 | Orval: Import-time RCE via header parameter name -> computed-property-key injection in the zod client | 严重 | npmorval | 已审查 | 2026-09-04 02:08 | 2026-09-04 02:08 |
| GHSA-JCVH-XF52-2CWM CVE-2026-73232 | ffuf denial of service (OOM) via HTTP response decompression bomb | 高危 | Gogithub.com/ffuf/ffuf+1 | 已审查 | 2026-09-04 02:02 | 2026-09-04 02:02 |
| GHSA-8Q3C-RJR9-XXRP CVE-2026-61625 | VictoriaMetrics vmrestore: Path traversal via crafted backup part names escapes restore root | 中危 | Gogithub.com/VictoriaMetrics/VictoriaMetrics | 已审查 | 2026-09-04 01:49 | 2026-09-04 01:49 |
| GHSA-M7FP-H3P4-HR49 CVE-2026-61556 | LiquidJS has an infinite loop vulnerability in its `strip_html` filter | 高危 | npmliquidjs | 已审查 | 2026-09-04 01:45 | 2026-09-04 01:45 |
| GHSA-H6CJ-26G5-67FV CVE-2026-75602 | OpenList: Authenticated arbitrary file write via Content-Disposition path traversal in SimpleHttp offline-download tool | 中危 | Gogithub.com/OpenListTeam/OpenList | 已审查 | 2026-09-04 01:37 | 2026-09-04 01:37 |
| GHSA-W8WF-3QVJ-6XQF | OpenClaw Feishu permission tools could ignore per-account disablement | 高危 | npm@openclaw/feishu | 已审查 | 2026-09-04 01:33 | 2026-09-04 01:33 |
| GHSA-2Q7J-2VHX-56G8 | OpenClaw Feishu tools could ignore per-account disablement | 高危 | npm@openclaw/feishu | 已审查 | 2026-09-04 01:30 | 2026-09-04 01:30 |
| GHSA-FM8W-2M5W-9J7R CVE-2026-56743 | Cilium may unexpectedly allow ingress traffic from the local namespace when a Kubernetes NetworkPolicy is configured with an ipBlock match | 中危 | Gogithub.com/cilium/cilium | 已审查 | 2026-09-04 01:17 | 2026-09-04 01:17 |
| GHSA-4MVJ-M6J5-PMF7 CVE-2026-71428 | unstructured: Server-Side Request Forgery in the URL-based partitioning | 严重 | PyPIunstructured | 已审查 | 2026-09-04 01:02 | 2026-09-04 01:02 |