检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-HJPH-F4MC-WX4C | Duplicate Advisory: Mistune has a ReDoS in LINK_TITLE_RE that allows denial of service via crafted Markdown input 已撤回 | 高危 | PyPImistune | 已审查 | 2026-05-07 00:56 | 2026-05-07 03:41 |
当前筛选结果 35,190 条 · 时间按北京时间显示
| GHSA-8MP2-V27R-99XP CVE-2026-33079 |
Mistune has a ReDoS in LINK_TITLE_RE that allows denial of service via crafted Markdown input |
| 高危 |
PyPImistune |
| 已审查 |
| 2026-05-07 00:52 |
| 2026-05-07 03:35 |
| GHSA-6J7P-QJHG-9947 CVE-2026-29090 | Rucio has SQL Injection in FilterEngine PostgreSQL Query Builder via DID Search API | 严重 | PyPIrucio | 已审查 | 2026-05-07 00:44 | 2026-07-01 00:43 |
| GHSA-VJR5-C9QV-HGM3 CVE-2026-29080 | Rucio has SQL Injection in FilterEngine Oracle JSON Path via DID Search API | 严重 | PyPIrucio | 已审查 | 2026-05-07 00:42 | 2026-07-01 00:42 |
| GHSA-8F47-4RH3-X44M CVE-2026-8026 | Flowise: Bcrypt Password Hash Exposure | 中危 | npmflowise | 已审查 | 2026-05-06 23:32 | 2026-05-13 06:22 |
| GHSA-WC6P-4GWJ-JCR8 | Duplicate Advisory: Keylime has a hardcoded attestation challenge nonce that allows replay attacks 已撤回 | 中危 | PyPIkeylime | 已审查 | 2026-05-06 20:30 | 2026-06-24 11:30 |
| GHSA-JVV4-8WXX-M5R6 CVE-2026-43646 | Apache Wicket has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability | 高危 | Mavenorg.apache.wicket:wicket-parent | 已审查 | 2026-05-06 20:30 | 2026-05-11 22:21 |
| GHSA-3GMF-P6R4-Q8M6 CVE-2026-43975 | Apache Wicket has a Path Traversal issue | 中危 | Mavenorg.apache.wicket:wicket-core | 已审查 | 2026-05-06 20:30 | 2026-05-11 22:11 |
| GHSA-QPJW-P3JG-59J6 CVE-2026-40010 | Apache Wicket has a Session Fixation issue | 严重 | Mavenorg.apache.wicket:wicket-auth-roles | 已审查 | 2026-05-06 20:30 | 2026-05-11 22:25 |
| GHSA-5X9H-93GP-CHPJ CVE-2026-42509 | Apache Wicket has a Cross-site Scripting issue | 中危 | Mavenorg.apache.wicket:wicket-parent | 已审查 | 2026-05-06 20:30 | 2026-05-11 22:22 |
| GHSA-6CMP-QV2F-X97X CVE-2026-7572 | Velocidex Velociraptor has an off-by-one error | 中危 | Gowww.velocidex.com/golang/velociraptor | 已审查 | 2026-05-06 11:33 | 2026-05-12 00:24 |
| GHSA-3C93-G9G6-P5J4 CVE-2026-7573 | Velocidex Velociraptor has an authorization bypass vulnerability | 中危 | Gowww.velocidex.com/golang/velociraptor | 已审查 | 2026-05-06 11:33 | 2026-05-12 00:23 |
| GHSA-R374-RXX8-8654 CVE-2026-44405 | Paramiko rsakey.py allows the SHA-1 algorithm | 低危 | PyPIparamiko | 已审查 | 2026-05-06 08:31 | 2026-05-09 07:13 |
| GHSA-FXC7-FM93-6Q77 CVE-2026-44221 | ArcadeDB vulnerable to cross-database authorization bypass and unsecured newly-created databases | 严重 | Mavencom.arcadedb:arcadedb-server | 已审查 | 2026-05-06 06:22 | 2026-08-04 04:40 |
| GHSA-HPV8-X276-M59F CVE-2026-44222 | vLLM Vulnerable to Remote DoS via Special-Token Placeholders | 中危 | PyPIvllm | 已审查 | 2026-05-06 06:21 | 2026-07-18 00:21 |
| GHSA-XR49-F4RH-QCJF CVE-2026-43885 | AVideo Vulnerable to Exposure of Sensitive Information to an Unauthorized Actor and Missing Authorization | 高危 | Packagistwwbn/avideo | 已审查 | 2026-05-06 06:20 | 2026-05-13 22:28 |
| GHSA-7WW3-XVF5-CXWM | ciguard: Web UI is missing HTTP defence-in-depth headers | 低危 | PyPIciguard | 已审查 | 2026-05-06 06:20 | 2026-05-06 06:20 |
| GHSA-8CXW-CC62-Q28V CVE-2026-44220 | ciguard: discover_pipeline_files follows symlinks out of scan root | 低危 | PyPIciguard | 已审查 | 2026-05-06 06:19 | 2026-05-16 07:51 |
| GHSA-JRM4-4PCF-4763 CVE-2026-44218 | ciguard: Container image runs as root (no USER directive) | 低危 | PyPIciguard | 已审查 | 2026-05-06 06:18 | 2026-05-16 07:50 |
| GHSA-XW8C-RRVX-F7XQ CVE-2026-44219 | ciguard: SCA HTTP client reads response body without size cap | 中危 | PyPIciguard | 已审查 | 2026-05-06 06:17 | 2026-05-16 07:50 |
| GHSA-84HM-WFH8-C5PG CVE-2026-44217 | sse-channel: SSE Injection via unsanitized event fields | 中危 | npmsse-channel | 已审查 | 2026-05-06 06:17 | 2026-05-14 00:27 |
| GHSA-2HCH-C97C-G99X CVE-2026-43884 | AVideo has SSRF Protection Bypass via HTTP Redirect and DNS Rebinding in isSSRFSafeURL() | 高危 | Packagistwwbn/avideo | 已审查 | 2026-05-06 06:16 | 2026-05-13 22:21 |
| GHSA-958H-QP3X-Q4GJ CVE-2026-43883 | AVideo: IDOR in PayPalYPT Plugin Allows Any Authenticated User to Cancel Arbitrary PayPal Subscription Agreements | 中危 | Packagistwwbn/avideo | 已审查 | 2026-05-06 06:16 | 2026-05-13 22:20 |
| GHSA-MGGX-P7JF-JGW4 | jdbi3-freemarker Vulnerable to Improper Neutralization of Special Elements Used in FreeMarker Template Engine | 高危 | Mavenorg.jdbi:jdbi3-freemarker | 已审查 | 2026-05-06 06:15 | 2026-05-06 06:15 |
| GHSA-MWGH-92M2-WVHV CVE-2026-43882 | AVideo: Unauthenticated CRLF/ICS Injection in Scheduler downloadICS.php Allows Calendar Event Spoofing | 中危 | Packagistwwbn/avideo | 已审查 | 2026-05-06 06:14 | 2026-05-13 22:20 |