检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-Q2QQ-HMJ6-3WPP | hickory-proto vulnerable to CPU exhaustion during message encoding due to O(n²) name compression | 中危 | crates.iohickory-proto | 已审查 | 2026-05-07 10:59 | 2026-05-07 10:59 |
| GHSA-3V94-MW7P-V465 | hickory-proto: NSEC3 closest-encloser proof validation enters unbounded loop on cross-zone responses |
当前筛选结果 35,190 条 · 时间按北京时间显示
crates.iohickory-net+1 |
| 已审查 |
| 2026-05-07 10:59 |
| 2026-05-07 10:59 |
| GHSA-258C-965C-P3HC | Daptin's Session Management Vulnerability Leads to Insufficient Session Expiration After Password Change | 中危 | Gogithub.com/daptin/daptin | 已审查 | 2026-05-07 10:57 | 2026-05-07 10:57 |
| GHSA-M38G-VWW2-MVGX | Talos Linux has a local privilege escalation from untrusted workloads | 高危 | Gogithub.com/siderolabs/talos | 已审查 | 2026-05-07 10:38 | 2026-06-09 07:43 |
| GHSA-V8J7-HP7C-738F CVE-2026-44514 | Kubetail has a Cross-Site WebSocket Hijacking issue that allows attacker to read Kubernetes logs from authenticated users | 中危 | Gogithub.com/kubetail-org/kubetail/modules/cli+1 | 已审查 | 2026-05-07 10:34 | 2026-05-15 04:54 |
| GHSA-J7W6-VPVQ-J3GM CVE-2026-44827 | Diffusers has a `trust_remote_code` bypass via `custom_pipeline` and local custom components 已撤回 | 高危 | PyPIdiffusers | 已审查 | 2026-05-07 10:24 | 2026-06-06 01:53 |
| GHSA-4CX3-3C38-J9VV CVE-2026-44511 | katalyst-koi: Session cookies can be replayed after user logout | 高危 | RubyGemskatalyst-koi | 已审查 | 2026-05-07 10:13 | 2026-05-30 05:45 |
| GHSA-585V-HCGF-JHFR CVE-2026-42459 | Free5GC UDM has Improper Input Validation and Generation of Error Messages Containing Sensitive Information | 高危 | Gogithub.com/free5gc/udm | 已审查 | 2026-05-07 10:09 | 2026-06-09 07:46 |
| GHSA-W239-58X2-Q8P5 CVE-2026-42328 | go-ipld-prime's DAG-CBOR and DAG-JSON decoders have unbounded recursion depth | 中危 | Gogithub.com/ipld/go-ipld-prime | 已审查 | 2026-05-07 10:07 | 2026-06-09 07:47 |
| GHSA-FF6C-W6QF-7XQC CVE-2026-44312 | CSS Parser: Improper Certificate Validation allows MITM injection of remote CSS content | 中危 | RubyGemscss_parser | 已审查 | 2026-05-07 10:06 | 2026-06-09 07:18 |
| GHSA-6RGM-GR97-X3J5 CVE-2026-42083 | Free5GC PCF: Missing authentication middleware in Npcf_SMPolicyControl allows access to SM policy handlers and disclosure of subscriber SUPI | 高危 | Gogithub.com/free5gc/pcf | 已审查 | 2026-05-07 09:58 | 2026-06-09 07:46 |
| GHSA-3V3M-WC6V-X4X3 CVE-2026-42880 | ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction | 严重 | Gogithub.com/argoproj/argo-cd/v3 | 已审查 | 2026-05-07 09:56 | 2026-05-11 21:30 |
| GHSA-VRRX-58H3-PRMH CVE-2026-42082 | Free5GC AMF has Missing Concurrent NAS SMC Validation During NGAP Handover | 低危 | Gogithub.com/free5gc/amf | 已审查 | 2026-05-07 09:56 | 2026-06-09 07:46 |
| GHSA-FPF5-4JW8-67X8 | rust-zserio has Unbounded Memory Allocation | 高危 | crates.iorust-zserio | 已审查 | 2026-05-07 09:54 | 2026-05-07 09:54 |
| GHSA-77X9-RF64-92GV CVE-2026-42081 | Free5GC AMF Bypasses UE Security Capabilities on NGAP PathSwitchRequest | 中危 | Gogithub.com/free5gc/amf | 已审查 | 2026-05-07 09:53 | 2026-06-09 07:46 |
| GHSA-M98R-6667-4WQ7 CVE-2026-44504 | Aegra has cross-user run injection in /threads/{thread_id}/runs (IDOR) | 高危 | PyPIaegra-api | 已审查 | 2026-05-07 09:49 | 2026-05-15 04:53 |
| GHSA-7J59-V9QR-6FQ9 CVE-2026-44503 | Kiota abstractions RedirectHandler leaks Cookie/Proxy-Authorization headers on cross-host redirect | 高危 | Gocom.microsoft.kiota:microsoft-kiota-abstractions+4 | 已审查 | 2026-05-07 09:49 | 2026-07-21 21:52 |
| GHSA-39G5-644C-QWCG | container: pf Rule Injection via Domain Name Argument in `container system dns create --localhost` Command | 低危 | SwiftURLgithub.com/apple/container | 已审查 | 2026-05-07 09:43 | 2026-05-07 09:43 |
| GHSA-765J-QFRP-HM3J CVE-2026-41050 | Fleet: Helm impersonation bypass of `RESTClientGetter` retains `cluster-admin` during template rendering | 严重 | Gogithub.com/rancher/fleet | 已审查 | 2026-05-07 09:26 | 2026-05-15 04:31 |
| GHSA-5V3H-X4WF-5C35 CVE-2026-25705 | Rancher Extensions have arbitrary file access via path traversal | 高危 | Gogithub.com/rancher/rancher | 已审查 | 2026-05-07 09:23 | 2026-05-15 04:31 |
| GHSA-FC67-C4HG-Q653 | Amazon ECS Container Agent (Windows) is vulnerable to Information Disclosure | 高危 | Gogithub.com/aws/amazon-ecs-agent | 已审查 | 2026-05-07 09:22 | 2026-05-07 09:22 |
| GHSA-G924-CJX7-2RJW CVE-2026-42597 | Gotenberg allows Chromium URL conversion routes to read arbitrary files under /tmp via file:// scheme | 中危 | Gogithub.com/gotenberg/gotenberg/v7+1 | 已审查 | 2026-05-07 09:15 | 2026-07-21 22:34 |
| GHSA-4VMC-GM8V-M35H CVE-2026-42596 | Gotenberg vulnerable to unauthenticated SSRF via default deny-list bypass in downloadFrom and webhook | 严重 | Gogithub.com/gotenberg/gotenberg/v8 | 已审查 | 2026-05-07 09:15 | 2026-05-15 04:52 |
| GHSA-R33J-C622-R6QP CVE-2026-42594 | Gotenberg has an unauthenticated denial of service via echo.Context pool reuse in webhook async goroutine | 高危 | Gogithub.com/gotenberg/gotenberg/v8 | 已审查 | 2026-05-07 09:00 | 2026-05-15 04:52 |
| GHSA-3CV5-Q585-H563 CVE-2026-42593 | Gotenberg has arbitrary PDF read via stampExpression and watermarkExpression in merge, split, and convert routes | 中危 | Gogithub.com/gotenberg/gotenberg/v8 | 已审查 | 2026-05-07 08:59 | 2026-05-15 04:52 |