检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-3R68-X3XC-RXPG CVE-2026-43901 | wireshark-mcp vulnerable to arbitrary file write via export_objects when WIRESHARK_MCP_ALLOWED_DIRS is not configured | 中危 | PyPIwireshark-mcp | 已审查 | 2026-05-06 04:15 | 2026-05-13 23:20 |
| GHSA-MM2Q-QCMX-GW4W | RustFS: ListServiceAccount authorizes against wrong admin action, enabling cross-user enumeration and root service account takeover |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 高危 |
crates.iorustfs |
| 已审查 |
| 2026-05-06 04:14 |
| 2026-05-06 04:14 |
| GHSA-QJV7-627W-8QJV CVE-2026-42554 | Fiber vulnerable to XSS in AutoFormat Content Negotiation | 中危 | Gogithub.com/gofiber/fiber/v2+1 | 已审查 | 2026-05-06 04:13 | 2026-05-13 22:20 |
| GHSA-4GP8-RJRQ-CH6Q CVE-2026-43897 | link-preview-js vulnerable to IPv6 and internal loopback attacks | 高危 | npmlink-preview-js | 已审查 | 2026-05-06 04:13 | 2026-05-13 22:20 |
| GHSA-QPGQ-5G92-J5Q8 CVE-2026-42207 | Magento LTS Vulnerable to Open Redirect via Unvalidated `uenc` Parameter in `stockAction()` | 中危 | Packagistopenmage/magento-lts | 已审查 | 2026-05-06 04:11 | 2026-05-16 07:48 |
| GHSA-98QH-XJC8-98PQ CVE-2026-42198 | pgjdbc: Unbounded PBKDF2 iterations in SCRAM authentication allows CPU exhaustion DoS | 高危 | Mavenorg.postgresql:postgresql | 已审查 | 2026-05-06 04:09 | 2026-05-06 04:09 |
| GHSA-67QG-7284-2277 CVE-2026-42196 | django-s3file is vulnerable to relative path traversal | 严重 | PyPIdjango-s3file | 已审查 | 2026-05-06 04:05 | 2026-05-14 00:31 |
| GHSA-XH8F-G2QW-GCM7 CVE-2026-42600 | MinIO vulnerable to Path Traversal via msgpack Body in `ReadMultiple` Storage-REST Endpoint | 中危 | Gogithub.com/minio/minio | 已审查 | 2026-05-06 04:05 | 2026-06-09 07:26 |
| GHSA-HCJJ-CHVW-FMW9 CVE-2026-42194 | Admidio has an incomplete fix for CVE-2026-32812 (SSRF) | 中危 | Packagistadmidio/admidio | 已审查 | 2026-05-06 04:03 | 2026-05-09 04:14 |
| GHSA-XCFG-FCR5-GW9R CVE-2026-42188 | Geyser Vulnerable to Server-Side Request Forgery (SSRF) via Player Head Texture URL in Geyser | 低危 | Mavenorg.geysermc.geyser:core | 已审查 | 2026-05-06 04:03 | 2026-05-13 22:19 |
| GHSA-VV66-6RP4-WR4F CVE-2026-42186 | OpenBao's Namespace Deletion May Not Delete Data Properly | 低危 | Gogithub.com/openbao/openbao | 已审查 | 2026-05-06 04:02 | 2026-05-15 04:49 |
| GHSA-CW26-7653-2RP5 CVE-2026-43893 | exiftool-vendored vulnerable to argument injection via newline characters in tag names | 高危 | npmexiftool-vendored | 已审查 | 2026-05-06 03:53 | 2026-05-13 22:19 |
| GHSA-VH75-FWV3-PQRH CVE-2026-42175 | requests-hardened is Vulnerable to Server-Side Request Forgery | 中危 | PyPIrequests-hardened | 已审查 | 2026-05-06 03:52 | 2026-05-14 00:26 |
| GHSA-2CWR-GCF9-PVXR CVE-2026-42155 | Magento LTS has Weak API Session ID — Predictable MD5 of Time-Derived Inputs | 严重 | Packagistopenmage/magento-lts | 已审查 | 2026-05-06 03:35 | 2026-05-16 07:48 |
| GHSA-8RM2-7QQF-34QM CVE-2026-42154 | Prometheus: Remote read endpoint allows denial of service via crafted snappy payload | 高危 | Gogithub.com/prometheus/prometheus | 已审查 | 2026-05-06 03:34 | 2026-06-09 00:22 |
| GHSA-WG65-39GG-5WFJ CVE-2026-42151 | Prometheus Azure AD remote write OAuth client secret exposed via config API | 高危 | Gogithub.com/prometheus/prometheus | 已审查 | 2026-05-06 03:33 | 2026-09-01 23:30 |
| GHSA-42FC-7W97-8VRC CVE-2026-42140 | XWiki PlantUML Macro Vulnerable to Server-Side Request Forgery (SSRF) via 'server' parameter | 中危 | Mavenorg.xwiki.contrib.plantuml:macro-plantuml-macro | 已审查 | 2026-05-06 03:32 | 2026-05-06 03:32 |
| GHSA-FR8X-3VFX-F45H | gix and gitoxide: unvalidated submodule name traverses out of .git/modules and redirects state() / open() to another repository | 高危 | crates.iogitoxide+1 | 已审查 | 2026-05-06 03:27 | 2026-05-06 03:27 |
| GHSA-PG4W-G64P-QWHJ | gix and gitoxide's symlinked .gitmodules are followed and parsed from outside of the repository | 高危 | crates.iogitoxide+1 | 已审查 | 2026-05-06 03:26 | 2026-05-06 03:26 |
| GHSA-X494-MJ8G-CJ27 | gix-pack has multiple DoS vectors: unchecked indexing panics and uncapped OOM allocations from crafted pack data | 高危 | crates.iogix-pack | 已审查 | 2026-05-06 03:24 | 2026-05-06 03:24 |
| GHSA-F26G-JM89-4G65 CVE-2026-40034 | gitoxide: CommandForbiddenInModulesConfiguration Bypass in gix_submodule::File::update() Enables Arbitrary Command Execution via .gitmodules | 高危 | crates.iogix | 已审查 | 2026-05-06 03:23 | 2026-07-01 01:41 |
| GHSA-P3HW-MV63-RF9W | gix's submodule name validation bypass + trust inheritance flaw enables path traversal and credential disclosure | 高危 | crates.iogix+1 | 已审查 | 2026-05-06 03:20 | 2026-05-06 03:20 |
| GHSA-9857-6MW7-FQ2M | gix-transport: HTTP credentials leaked to redirected host in curl backend | 中危 | crates.iogix-transport | 已审查 | 2026-05-06 03:16 | 2026-05-06 03:16 |
| GHSA-MM5F-8Q57-4FC4 CVE-2026-43878 | Video: Reflected XSS in plugin/Meet/iframe.php via Unescaped user and pass Parameters in JavaScript String Literal | 中危 | Packagistwwbn/avideo | 已审查 | 2026-05-06 03:15 | 2026-05-13 22:19 |
| GHSA-JW8G-5J46-44RP CVE-2026-43877 | AVideo: CSRF in userSavePhoto.php Allows Cross-Origin Overwrite of Authenticated Users' Profile Photos with Arbitrary Content | 中危 | Packagistwwbn/avideo | 已审查 | 2026-05-06 03:13 | 2026-05-13 22:19 |