检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-W4RC-P66M-X6QQ CVE-2026-42845 | Grav Form Plugin has an Anonymous Page Content Overwrite via Form File Upload filename Override | 高危 | Packagistgetgrav/grav-plugin-form | 已审查 | 2026-05-07 07:03 | 2026-05-13 22:04 |
| GHSA-9PHM-9P8F-HW5M CVE-2026-44372 |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 中危 |
npmnitro+1 |
| 已审查 |
| 2026-05-07 07:02 |
| 2026-06-09 09:58 |
| GHSA-5W89-W975-HF9Q CVE-2026-44373 | Nitro has a proxy scope bypass via percent-encoded path traversal in `routeRules` | 中危 | npmnitro+1 | 已审查 | 2026-05-07 07:01 | 2026-05-15 04:42 |
| GHSA-7R92-3JGR-R65Q CVE-2026-44368 | pyquorum: Timing side‑channel in mul_mod | 中危 | PyPIpyquorum | 已审查 | 2026-05-07 06:40 | 2026-05-15 04:42 |
| GHSA-2CCX-CJJH-R2J8 | MediaMTX affected by CVE-2026-27143 due to vulnerable dependency | 低危 | Gogithub.com/bluenviron/mediamtx | 已审查 | 2026-05-07 06:39 | 2026-05-07 06:39 |
| GHSA-PJV4-3C63-699F CVE-2026-42602 | opentelemetry-collector-contrib's azureauthextension Authenticate method does not validate bearer tokens, allowing auth bypass via replay | 高危 | Gogithub.com/open-telemetry/opentelemetry-collector-contrib/extension/azureauthextension | 已审查 | 2026-05-07 06:32 | 2026-05-15 04:42 |
| GHSA-J4RH-7JCR-QM69 CVE-2026-44364 | misp-modules website - Missing CSRF protection in the website home blueprint | 严重 | PyPImisp-modules | 已审查 | 2026-05-07 06:31 | 2026-05-15 04:42 |
| GHSA-FHQ3-2GF3-8F3J CVE-2026-44363 | misp-modules has nsafe remote resource fetching in expansion | 中危 | PyPImisp-modules | 已审查 | 2026-05-07 06:31 | 2026-05-15 04:42 |
| GHSA-GMVF-9V4P-V8JC CVE-2026-44351 | fast-jwt: JWT auth bypass due to empty HMAC secret accepted by async key resolver | 严重 | npmfast-jwt | 已审查 | 2026-05-07 06:26 | 2026-05-15 04:42 |
| GHSA-95Q8-X6R6-672M | Lemmy may expose private community data through community, saved, liked, and modlog API views | 中危 | crates.iolemmy_api | 已审查 | 2026-05-07 06:22 | 2026-06-09 07:39 |
| GHSA-JMXC-HHWX-GVV3 | Private Lemmy instances expose multi-community metadata without authentication | 中危 | crates.iolemmy_api | 已审查 | 2026-05-07 06:12 | 2026-06-09 07:39 |
| GHSA-Q98M-7W8C-W388 CVE-2026-44245 | Kyverno policy-reporter-ui has XSS via Stored Property Values in PropertyCard Component | 中危 | Gogithub.com/kyverno/policy-reporter-ui | 已审查 | 2026-05-07 06:11 | 2026-05-14 00:43 |
| GHSA-PWQG-Q8PG-PP6R CVE-2026-44349 | Daptin fuzzy search injects unvalidated column name into raw SQL | 高危 | Gogithub.com/daptin/daptin | 已审查 | 2026-05-07 06:10 | 2026-05-09 05:47 |
| GHSA-XCMW-GRXF-WJHJ CVE-2026-44334 | PraisonAI has unauthenticated RCE via `tool_override.py` (CVE-2026-40287 patch bypass) | 高危 | PyPIpraisonai | 已审查 | 2026-05-07 06:08 | 2026-05-12 21:33 |
| GHSA-Q9PW-VMHH-384G CVE-2026-44335 | PraisonAI has an SSRF bypass | 高危 | PyPIpraisonaiagents | 已审查 | 2026-05-07 06:08 | 2026-05-12 21:33 |
| GHSA-7MW3-79JQ-XC7F | aiograpi has dependency on vulnerable orjson 3.11.4 (CVE-2025-67221) | 低危 | PyPIaiograpi | 已审查 | 2026-05-07 06:06 | 2026-05-07 06:06 |
| GHSA-55GC-6FMC-FPX9 CVE-2026-42572 | Hatchet affected by cross-tenant information disclosure in `listTasksByDAGIds` | 中危 | Gogithub.com/hatchet-dev/hatchet | 已审查 | 2026-05-07 05:59 | 2026-05-15 04:53 |
| GHSA-V87R-6Q3F-2J67 CVE-2026-44244 | GitPython: Newline injection in config_writer().set_value() enables RCE via core.hooksPath | 高危 | PyPIGitPython | 已审查 | 2026-05-07 05:58 | 2026-05-09 05:52 |
| GHSA-PP6C-GR5W-3C5G CVE-2026-42561 | python-multipart has Denial of Service via unbounded multipart part headers | 高危 | PyPIpython-multipart | 已审查 | 2026-05-07 05:56 | 2026-05-15 04:42 |
| GHSA-89VP-X53W-74FX CVE-2026-42559 | rmcp Streamable HTTP server transport has a DNS rebinding vulnerability | 高危 | crates.iormcp | 已审查 | 2026-05-07 05:55 | 2026-05-20 04:17 |
| GHSA-V5MH-H5HX-7V92 | kube-router: GoBGP gRPC Admin Port Exposed on Node Primary IP Without Authentication, Allowing Cluster-Wide BGP Route Injection | 中危 | Gogithub.com/cloudnativelabs/kube-router | 已审查 | 2026-05-07 05:52 | 2026-05-07 05:52 |
| GHSA-2P6R-X3VV-XQM2 | rpassword affected by partial password reveal when input is interrupted | 低危 | crates.iorpassword | 已审查 | 2026-05-07 05:49 | 2026-05-07 05:49 |
| GHSA-83VM-P52W-F9PW CVE-2026-44223 | vLLM: extract_hidden_states speculative decoding crashes server on any request with penalty parameters | 中危 | PyPIvllm | 已审查 | 2026-05-07 05:45 | 2026-06-09 03:52 |
| GHSA-2H4P-VJRC-8XPQ CVE-2026-44307 | Mako vulnerable to path traversal via backslash URI on Windows in TemplateLookup | 高危 | PyPIMako | 已审查 | 2026-05-07 05:45 | 2026-05-14 00:43 |
| GHSA-MQCG-5X36-VFCG CVE-2026-42557 | JupyterLab's command linker attributes in HTML enable one-click command execution from untrusted content | 高危 | PyPIjupyterlab+1 | 已审查 | 2026-05-07 05:43 | 2026-06-09 18:59 |