检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-2PMR-289P-44R3 CVE-2026-42592 | Gotenberg's DNS rebinding bypasses SSRF validation on Chromium URL conversion routes | 中危 | Gogithub.com/gotenberg/gotenberg/v8 | 已审查 | 2026-05-07 08:57 | 2026-06-09 04:10 |
| GHSA-RM4C-XJ6X-49MW CVE-2026-42591 | Gotenberg has a Server-Side Request Forgery (SSRF) Issue |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 高危 |
Gogithub.com/gotenberg/gotenberg/v8 |
| 已审查 |
| 2026-05-07 08:57 |
| 2026-05-15 04:52 |
| GHSA-7V3R-M9C8-R855 CVE-2026-42590 | Gotenberg's ExifTool group-prefix syntax bypasses dangerous-tag blocklist | 高危 | Gogithub.com/gotenberg/gotenberg/v8 | 已审查 | 2026-05-07 08:55 | 2026-07-21 21:51 |
| GHSA-RQGH-GXV4-6657 CVE-2026-42589 | Gotenberg has Unauthenticated RCE via ExifTool Metadata Key Injection | 严重 | Gogithub.com/gotenberg/gotenberg/v8 | 已审查 | 2026-05-07 08:55 | 2026-05-15 04:52 |
| GHSA-W37P-236H-PFX3 CVE-2026-44484 | Compromise of PyTorch Lightning PyPi Package Versions | 严重 | PyPIpytorch-lightning | 已审查 | 2026-05-07 08:52 | 2026-06-09 07:12 |
| GHSA-F6HV-JMP6-3VWV CVE-2026-42587 | Netty: HttpContentDecompressor maxAllocation bypass when Content-Encoding set to br/zstd/snappy leads to decompression bomb DoS | 高危 | Mavenio.netty:netty-codec-http+1 | 已审查 | 2026-05-07 08:46 | 2026-05-15 04:41 |
| GHSA-RGRR-P7GP-5XJ7 CVE-2026-42586 | Netty Redis Codec Encoder has a CRLF Injection Issue | 中危 | Mavenio.netty:netty-codec-redis | 已审查 | 2026-05-07 08:24 | 2026-05-15 04:41 |
| GHSA-38F8-5428-X5CV CVE-2026-42585 | Netty vulnerable to HTTP Request Smuggling due to malformed Transfer-Encoding | 中危 | Mavenio.netty:netty-codec-http | 已审查 | 2026-05-07 08:22 | 2026-05-15 04:41 |
| GHSA-57RV-R2G8-2CJ3 CVE-2026-42584 | Netty has HttpClientCodec response desynchronization | 高危 | Mavenio.netty:netty-codec-http | 已审查 | 2026-05-07 08:21 | 2026-05-15 04:41 |
| GHSA-MJ4R-2HFC-F8P6 CVE-2026-42583 | Netty Lz4FrameDecoder is vulnerable to resource exhaustion | 高危 | Mavenio.netty:netty-codec+1 | 已审查 | 2026-05-07 08:20 | 2026-05-15 04:41 |
| GHSA-2C5C-CHWR-9HQW CVE-2026-42582 | Netty HTTP/3 QPACK literal unbounded allocation | 高危 | Mavenio.netty:netty-codec-http3 | 已审查 | 2026-05-07 08:19 | 2026-07-01 06:27 |
| GHSA-XXQH-MFJM-7MV9 CVE-2026-42581 | Netty HTTP/1.0 TE+CL Coexistence Bypasses Smuggling Sanitization | 中危 | Mavenio.netty:netty-codec-http | 已审查 | 2026-05-07 08:18 | 2026-05-15 04:41 |
| GHSA-M4CV-J2PX-7723 CVE-2026-42580 | Netty vulnerable to HTTP Request Smuggling due to incorrect chunk size parsing | 中危 | Mavenio.netty:netty-codec-http | 已审查 | 2026-05-07 08:13 | 2026-05-15 04:41 |
| GHSA-CM33-6792-R9FM CVE-2026-42579 | Netty has a DNS Codec Input Validation Bypass (Encoder + Decoder) | 高危 | Mavenio.netty:netty-codec-dns | 已审查 | 2026-05-07 08:12 | 2026-05-15 04:40 |
| GHSA-45Q3-82M4-75JR CVE-2026-42578 | Netty has HTTP Header Injection via HttpProxyHandler Disabled Validation (Incomplete Fix CVE-2025-67735) | 低危 | Mavenio.netty:netty-handler-proxy | 已审查 | 2026-05-07 08:11 | 2026-05-15 04:40 |
| GHSA-X5HG-X4GV-J98M | OpenSearch has ineffective TLS certificate hostname verification | 低危 | Mavenorg.opensearch.plugin:opensearch-security | 已审查 | 2026-05-07 08:09 | 2026-05-07 08:09 |
| GHSA-P8XM-42R7-89XG CVE-2026-44216 | wasmtime has a panic when allocating a table exceeding the size of the host's address space | 中危 | crates.iowasmtime | 已审查 | 2026-05-07 08:08 | 2026-05-15 04:49 |
| GHSA-X83W-23JP-G6PW | OpenSearch Security plugin: DLS not applied on documents linked by has_child or has_parent relation | 中危 | Mavenorg.opensearch.plugin:opensearch-security | 已审查 | 2026-05-07 08:08 | 2026-05-07 08:08 |
| GHSA-22VX-2X23-98W6 | OpenSearch vulnerable to improper authorization for Rollover Requests | 低危 | Mavenorg.opensearch.plugin:opensearch-security | 已审查 | 2026-05-07 08:08 | 2026-05-07 08:08 |
| GHSA-83X9-VC3C-HGHC | OpenSearch has a bypass of REST Layer Authorization Using Malformed Paths | 低危 | Mavenorg.opensearch.plugin:opensearch-security | 已审查 | 2026-05-07 08:07 | 2026-05-07 08:07 |
| GHSA-R4W4-WV68-QV85 CVE-2026-44308 | Spring Cloud AWS missing SNS message signature verification allows spoofing of HTTP/HTTPS endpoint notifications | 中危 | Mavenio.awspring.cloud:spring-cloud-aws-sns | 已审查 | 2026-05-07 08:06 | 2026-05-15 04:49 |
| GHSA-PGF8-2HGJ-GRQG CVE-2026-44479 | Vercel: Non-interactive mode includes CLI arguments in suggested command output | 中危 | npmvercel | 已审查 | 2026-05-07 08:05 | 2026-05-15 04:32 |
| GHSA-5CMV-3RC4-7279 CVE-2026-44264 | Weblate vulnerable to XSS via crafted Markdown | 中危 | PyPIweblate | 已审查 | 2026-05-07 08:04 | 2026-05-09 05:47 |
| GHSA-GCG5-86JR-F7JG CVE-2026-44263 | Weblate Vulnerable to Private Translation Enumeration via Screenshot API | 中危 | PyPIweblate | 已审查 | 2026-05-07 08:03 | 2026-05-09 05:47 |
| GHSA-FF9Q-RM55-Q7QR | diesel-async may expose uninitialized padding bytes for MySQL temporal columns | 低危 | crates.iodiesel-async | 已审查 | 2026-05-07 08:02 | 2026-05-07 08:02 |