检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-8HG8-63C5-GWMX CVE-2026-44007 | vm2 NodeVM `nesting: true` bypasses `require: false` allowing sandbox escape and arbitrary OS command execution | 严重 | npmvm2 | 已审查 | 2026-05-07 13:13 | 2026-05-15 04:37 |
| GHSA-CP6G-6699-WX9C CVE-2026-43998 |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 高危 |
npmvm2 |
| 已审查 |
| 2026-05-07 12:33 |
| 2026-05-15 04:36 |
| GHSA-WP5R-2GW5-M7Q7 CVE-2026-44003 | vm2's Transformer Fast-Path Bypass Exposes Internal State Variable | 中危 | npmvm2 | 已审查 | 2026-05-07 12:32 | 2026-05-15 04:36 |
| GHSA-V27G-JCQJ-V8RW CVE-2026-44002 | vm2 is Vulnerable to Host File Path Disclosure via Stack Trace Information Leak | 中危 | npmvm2 | 已审查 | 2026-05-07 12:30 | 2026-05-15 04:36 |
| GHSA-MPF8-4HX2-7CJG CVE-2026-44000 | vm2 Host Promise Resolution Preserves Object Identity Across Sandbox Boundary | 中危 | npmvm2 | 已审查 | 2026-05-07 12:29 | 2026-05-15 04:36 |
| GHSA-6785-PVV7-MVG7 CVE-2026-44004 | vm2 Sandbox Access to Host Buffer.alloc Allows timeout Bypass Resulting in Memory Exhaustion | 高危 | npmvm2 | 已审查 | 2026-05-07 12:26 | 2026-05-15 04:36 |
| GHSA-HW58-P9XV-2MJH CVE-2026-44001 | vm2 has a Sandbox Escape via Promise Constructor Unhandled Rejection (Process Crash DoS) | 高危 | npmvm2 | 已审查 | 2026-05-07 12:10 | 2026-05-15 04:36 |
| GHSA-947F-4V7F-X2V8 CVE-2026-43999 | vm2 has a NodeVM builtin allowlist bypass via `module` builtin's `Module._load` that allows sandbox escape | 严重 | npmvm2 | 已审查 | 2026-05-07 12:08 | 2026-05-15 04:36 |
| GHSA-VWRP-X96C-MHWQ CVE-2026-44005 | vm2: Mutable Proxies for Host Intrinsic Prototypes Allows Sandbox Escape | 严重 | npmvm2 | 已审查 | 2026-05-07 12:07 | 2026-05-15 04:36 |
| GHSA-47X8-96VW-5WG6 CVE-2026-43997 | vm2 Access to Host Object Enables Sandbox Escape | 严重 | npmvm2 | 已审查 | 2026-05-07 12:00 | 2026-05-15 04:36 |
| GHSA-QCP4-V2JJ-FJX8 CVE-2026-44006 | vm2 has a Sandbox Escape Vulnerability | 严重 | npmvm2 | 已审查 | 2026-05-07 11:54 | 2026-05-15 04:36 |
| GHSA-Q6V9-R226-V65F CVE-2026-42788 | Bandit HTTP/2 Frame Size Limit Bypass via Late Buffer Check Enables Memory Exhaustion | 中危 | Hexbandit | 已审查 | 2026-05-07 11:52 | 2026-05-07 11:52 |
| GHSA-375F-4R2H-F99J CVE-2026-39807 | Bandit trusts client-supplied URI scheme on plaintext connections | 中危 | Hexbandit | 已审查 | 2026-05-07 11:47 | 2026-05-07 11:47 |
| GHSA-C67R-GC9J-2QF7 CVE-2026-39805 | Bandit is vulnerable to CL.CL request smuggling via unrejected duplicate `Content-Length` header | 中危 | Hexbandit | 已审查 | 2026-05-07 11:46 | 2026-05-07 11:46 |
| GHSA-PF94-94M9-536P CVE-2026-42786 | Bandit Buffers Unbounded WebSocket Continuation Frames, Allowing Unauthenticated Memory Exhaustion | 高危 | Hexbandit | 已审查 | 2026-05-07 11:43 | 2026-05-07 11:43 |
| GHSA-FRH3-6PV6-RC8J CVE-2026-39804 | Bandit's unbounded WebSocket inflate causes BEAM OOM with a single frame | 高危 | Hexbandit | 已审查 | 2026-05-07 11:36 | 2026-05-07 11:36 |
| GHSA-VXVC-CG7J-RWQJ CVE-2026-44544 | gittuf's policy can be rolled back to prior valid versions | 中危 | Gogithub.com/gittuf/gittuf | 已审查 | 2026-05-07 11:34 | 2026-05-15 04:54 |
| GHSA-MMPX-JH39-WRV6 | FileBrowser Vulnerable to Stored XSS via SVG File in Public Share (Missing CSP Header) | 中危 | Gogithub.com/gtsteffaniak/filebrowser | 已审查 | 2026-05-07 11:29 | 2026-05-07 11:29 |
| GHSA-FWJ3-42WH-8673 CVE-2026-44542 | FileBrowser Public Share DELETE API Path Traversal Allows Unauthenticated Arbitrary File Deletion | 严重 | Gogithub.com/gtsteffaniak/filebrowser | 已审查 | 2026-05-07 11:28 | 2026-05-15 04:54 |
| GHSA-X35M-3GP4-4FH5 CVE-2026-44283 | etcd RBAC bypass allows unauthorized data access via PrevKv/lease attachment in nested transaction Put requests | 低危 | Gogo.etcd.io/etcd+1 | 已审查 | 2026-05-07 11:21 | 2026-05-15 04:54 |
| GHSA-FQPH-J6V6-JVGX CVE-2026-44520 | docling-graph has SSRF via Missing Internal IP Validation in URLInputHandler | 中危 | PyPIdocling-graph | 已审查 | 2026-05-07 11:15 | 2026-05-15 04:54 |
| GHSA-W5P8-4JCX-2J6R | imageproc: integer overflow in kernel size check leads to out-of-bounds read | 中危 | crates.ioimageproc | 已审查 | 2026-05-07 11:13 | 2026-05-07 11:13 |
| GHSA-QG8R-F7X3-25F7 | imageproc: Out-of-bounds read via NaN coordinates in bilinear/bicubic sampling | 中危 | crates.ioimageproc | 已审查 | 2026-05-07 11:10 | 2026-05-07 11:10 |
| GHSA-5QV7-J6W5-FR4M | imageproc has fragile bounds check when sampling from image | 中危 | crates.ioimageproc | 已审查 | 2026-05-07 11:03 | 2026-05-07 11:03 |
| GHSA-VWX9-7QCF-GG7F CVE-2026-44426 | ShellHub has cross-tenant IDOR in `GET /api/namespaces/:tenant` via API Key bypasses membership check | 中危 | Gogithub.com/shellhub-io/shellhub | 已审查 | 2026-05-07 11:02 | 2026-05-15 04:43 |