检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-533J-2V4Q-MW5H CVE-2026-55253 | LangChain MongoDB has NoSQL Operator Injection in MongoDBSaver.list() leading to cross-tenant data exposure | 高危 | PyPIlanggraph-checkpoint-mongodb+1 | 已审查 | 2026-08-21 01:29 | 2026-08-21 01:29 |
| GHSA-RRWH-6JRQ-WP5V CVE-2026-54061 |
当前筛选结果 35,190 条 · 时间按北京时间显示
Dgraph Alpha group stores can be replaced via unauthenticated external snapshot import |
| 严重 |
Gogithub.com/dgraph-io/dgraph/v25 |
| 已审查 |
| 2026-08-21 01:29 |
| 2026-08-21 01:29 |
| GHSA-89V8-RHWQ-HF77 CVE-2026-55244 | asteval has a Sandbox Escape via BaseException Subclasses | 中危 | PyPIasteval | 已审查 | 2026-08-21 01:28 | 2026-08-21 01:28 |
| GHSA-9W56-46F6-3QHX | asteval Sandbox Escape: arbitrary native memory read/write via numpy ctypes in default asteval Interpreter | 中危 | PyPIasteval | 已审查 | 2026-08-21 01:26 | 2026-08-21 01:26 |
| GHSA-QQFF-5854-PX68 CVE-2026-55149 | vouch-proxy has an Unbounded Multipart Cookie Allocation DoS | 高危 | Gogithub.com/vouch/vouch-proxy | 已审查 | 2026-08-21 01:26 | 2026-08-21 01:26 |
| GHSA-42CJ-99W8-CP2P CVE-2026-45404 | OpenTelemetry-Go: Unsynchronized baggage map can panic under concurrent access | 中危 | Gogo.opentelemetry.io/otel/bridge/opentracing | 已审查 | 2026-08-21 01:26 | 2026-08-21 01:26 |
| GHSA-J2G6-362Q-6QC6 CVE-2026-32637 | Velero vulnerable to file path traversal when extracting from backup's tarball | 中危 | Gogithub.com/vmware-tanzu/velero | 已审查 | 2026-08-21 01:26 | 2026-08-21 01:26 |
| GHSA-RGR9-R7MJ-MF6X CVE-2026-63123 | Tina: Cross-origin `POST /media/upload/*` requests can write arbitrary files into the Tina dev server media root | 中危 | npm@tinacms/cli | 已审查 | 2026-08-20 05:56 | 2026-08-22 02:31 |
| GHSA-8MQ9-5FW2-5RM4 CVE-2026-59992 | Tina: Broken Access Control: arbitrary bucket-key write/delete in `next-tinacms-s3` (and sibling production media adapters) | 中危 | npmnext-tinacms-azure+3 | 已审查 | 2026-08-20 05:56 | 2026-08-22 02:31 |
| GHSA-RXJR-6C9Q-H67X CVE-2026-63188 | logto-tunnel serves files outside --experience-path via path traversal | 高危 | npm@logto/tunnel | 已审查 | 2026-08-20 04:24 | 2026-08-20 04:24 |
| GHSA-72X6-4J93-7W86 CVE-2026-61712 | BuildKit has a possible runtime DoS via unbounded group parsing | 低危 | Gogithub.com/moby/buildkit | 已审查 | 2026-08-20 04:24 | 2026-08-20 04:24 |
| GHSA-7236-3392-C5C6 CVE-2026-61711 | BuildKit: Custom frontend could bypass Seccomp/AppArmor | 中危 | Gogithub.com/moby/buildkit | 已审查 | 2026-08-20 04:23 | 2026-08-20 04:23 |
| GHSA-HJWH-XVFW-QRWJ | SearXNG Basic Authentication Credentials Exposed Through MCP Logs and JSON-RPC Error Responses | 中危 | npmmcp-searxng | 已审查 | 2026-08-20 03:32 | 2026-08-20 03:32 |
| GHSA-VWG3-W8W3-PC79 CVE-2026-62673 | Grav: .htaccess file extension rules bypass via case variation on case-insensitive filesystems | 高危 | Packagistgetgrav/grav | 已审查 | 2026-08-20 03:32 | 2026-08-20 03:32 |
| GHSA-C8QC-WF67-342W CVE-2026-61807 | Snipe-IT: Stored DOM XSS via table selected-count IDs | 中危 | Packagistsnipe/snipe-it | 已审查 | 2026-08-20 03:32 | 2026-08-20 03:32 |
| GHSA-R9R3-G9FP-3Q4Q CVE-2026-55703 | Snipe-IT: Maintenance Record Disclosure via Missing Authorization on GET | 中危 | Packagistsnipe/snipe-it | 已审查 | 2026-08-20 03:32 | 2026-08-20 03:32 |
| GHSA-3HGV-JR5J-CG9X CVE-2026-55694 | Snipe-IT: Chained Information Disclosure and IDOR Leads to Full EULA File Takeover | 高危 | Packagistsnipe/snipe-it | 已审查 | 2026-08-20 03:32 | 2026-08-20 03:32 |
| GHSA-C6W2-J4WQ-MVWG CVE-2026-55643 | Snipe-IT: Tenant Isolation Bypass in FMCS Floater Mode | 高危 | Packagistsnipe/snipe-it | 已审查 | 2026-08-20 03:32 | 2026-09-02 23:27 |
| GHSA-WF6J-GR27-G7CH CVE-2024-45747 | GeoServer has a Server-Side Template Injection (SSTI) vulnerability in processing FreeMarker templates | 高危 | Mavenorg.geoserver:gs-main+2 | 已审查 | 2026-08-20 03:31 | 2026-08-20 03:31 |
| GHSA-WPPF-H75H-6PM6 CVE-2026-54689 | SearXNG MCP Server: Additional hardened-mode SSRF bypasses | 中危 | npmmcp-searxng | 已审查 | 2026-08-20 03:23 | 2026-08-20 03:23 |
| GHSA-Q87F-QC2R-2GW4 CVE-2026-54688 | SearXNG MCP Server is Vulnerable to SSRF in web_url_read: the internal-address guard is disabled by default (MCP_HTTP_HARDEN off) | 中危 | npmmcp-searxng | 已审查 | 2026-08-20 03:23 | 2026-08-20 03:23 |
| GHSA-P77J-G7H5-R2VW | GeoLens's authorization and cache-scope flaws disclose private dataset data and metadata to unauthorized users (fixed in 1.2.4) | 高危 | PyPIgeolens | 已审查 | 2026-08-20 03:22 | 2026-08-20 03:23 |
| GHSA-45PH-GXXR-GWGW CVE-2026-53966 | XWiki Platform Live Data Live Table Connector has privilege escalation from edit to script right through Live Data editing | 高危 | Mavenorg.xwiki.platform:xwiki-platform-livedata-livetable | 已审查 | 2026-08-20 03:18 | 2026-08-20 03:18 |
| GHSA-7M52-JW36-44R3 CVE-2026-53965 | MCP PHP SDK: client HttpTransport SSE buffer (sseBuffer .= chunk) grows unbounded when server withholds the event delimiter | 高危 | Packagistmcp/sdk | 已审查 | 2026-08-20 03:17 | 2026-08-20 03:17 |
| GHSA-W47Q-945M-Q9PC CVE-2026-53964 | Document Merge Service vulnerable to RCE via SSTI (xlsx tempaltes) | 高危 | PyPIdocument-merge-service | 已审查 | 2026-08-20 03:17 | 2026-08-20 03:17 |