检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-9WHX-C884-C68Q CVE-2026-42048 | Langflow Knowledge Bases API is Vulnerable to Path Traversal | 严重 | PyPIlangflow | 已审查 | 2026-05-06 02:28 | 2026-05-14 00:26 |
| GHSA-G485-8J3V-P6X8 | @tdurieux/anonymous_github Vulnerable to XSS via Unsanitized GitHub Repository Content Rendering in Anonymous GitHub Origin |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 高危 |
npm@tdurieux/anonymous_github |
| 已审查 |
| 2026-05-06 02:28 |
| 2026-05-06 02:28 |
| GHSA-V8H7-RR48-VMMV CVE-2026-41417 | Netty: Start-Line Injection in DefaultHttpRequest.setUri() Allows HTTP Request Smuggling and RTSP Request Injection | 中危 | Mavenio.netty:netty-codec-http | 已审查 | 2026-05-06 02:27 | 2026-05-09 03:32 |
| GHSA-FQVV-JVHR-G5JC CVE-2026-42864 | FireFighter has unauthenticated SSRF in its Raid jira_bot endpoint that allows IAM credential theft | 严重 | PyPIfirefighter-incident | 已审查 | 2026-05-06 02:21 | 2026-05-13 22:18 |
| GHSA-2JF5-6WWV-VHXX CVE-2026-42047 | Inngest TypeScript SDK exposes environment variables via serve() handler on unhandled HTTP methods | 高危 | npminngest | 已审查 | 2026-05-06 02:13 | 2026-05-11 21:29 |
| GHSA-M68R-V472-JGQ9 CVE-2026-40864 | JupyterHub has cross-origin form POSTs bypass XSRF (CWE-352) | 中危 | PyPIjupyterhub | 已审查 | 2026-05-06 02:10 | 2026-06-09 07:20 |
| GHSA-H5X4-M2QF-R4F2 | Diesel's SQLite backend has possible UTF-8 corruption | 高危 | crates.iodiesel | 已审查 | 2026-05-06 02:08 | 2026-05-06 02:08 |
| GHSA-XQ4X-622M-Q8FQ CVE-2026-42045 | LobeHub has a Cross-Site Scripting issue that escalates to Remote Code Execution | 中危 | npm@lobehub/lobehub | 已审查 | 2026-05-06 02:04 | 2026-05-14 00:25 |
| GHSA-4V9X-CQC5-J645 CVE-2026-25660 | Codechecker has an authentication bypass for certain API calls | 严重 | PyPIcodechecker | 已审查 | 2026-05-06 01:58 | 2026-05-06 01:58 |
| GHSA-64CV-VXPR-J6VC CVE-2026-42860 | edx-enterprise has SSRF via SAML metadata URL in sync_provider_data endpoint | 高危 | PyPIedx-enterprise | 已审查 | 2026-05-06 01:51 | 2026-06-06 08:27 |
| GHSA-FJ4G-2P96-Q6M3 CVE-2026-42856 | Network-AI missing authentication on MCP HTTP endpoint, which allows unauthenticated privileged tool calls | 高危 | npmnetwork-ai | 已审查 | 2026-05-06 01:25 | 2026-05-13 22:17 |
| GHSA-R7CG-QJJM-XHQQ | webonyx/graphql-php has unbounded recursion in parser that causes stack overflow on crafted nested input | 高危 | Packagistwebonyx/graphql-php | 已审查 | 2026-05-06 01:24 | 2026-05-06 01:24 |
| GHSA-H5FQ-653G-GXRM | ots has a negative expire override that can bypass its secret retention policy | 中危 | Gogithub.com/Luzifer/ots | 已审查 | 2026-05-06 01:20 | 2026-07-21 22:49 |
| GHSA-9HMG-827W-9RHJ CVE-2026-41164 | nuts-node has JWT type confusion in v1 access token introspection that allows VP replay as access token | 中危 | Gogithub.com/nuts-foundation/nuts-node | 已审查 | 2026-05-06 01:15 | 2026-06-09 07:28 |
| GHSA-5MRQ-X3X5-8V8F CVE-2026-40934 | Jupyter Server's Authentication Cookies Remain Valid After Password Reset and Server Restart | 高危 | PyPIjupyter-server | 已审查 | 2026-05-06 01:03 | 2026-06-06 08:27 |
| GHSA-24QX-W28J-9M6P CVE-2026-40110 | Jupyter Server has a CORS Origin Validation Bypass via `re.match()` in `allow_origin_pat` | 高危 | PyPIjupyter-server | 已审查 | 2026-05-06 00:54 | 2026-08-01 04:27 |
| GHSA-5789-5FC7-67V3 CVE-2026-35397 | Jupyter Server: Path Traversal via incorrect startswith() root directory check allows access to sibling directories | 高危 | PyPIjupyter-server | 已审查 | 2026-05-06 00:49 | 2026-08-29 02:30 |
| GHSA-FFH4-J6H5-PG66 CVE-2026-26956 | VM2 Has a WASM Sandbox Escape | 严重 | npmvm2 | 已审查 | 2026-05-06 00:44 | 2026-06-08 23:38 |
| GHSA-55HX-C926-FR95 CVE-2026-26332 | VM2 Has a Sandbox Escape Issue via SuppressedError | 严重 | npmvm2 | 已审查 | 2026-05-06 00:33 | 2026-05-06 00:33 |
| GHSA-V37H-5MFM-C47C CVE-2026-24781 | VM2 Has Sandbox Breakout Through Inspect Function | 严重 | npmvm2 | 已审查 | 2026-05-06 00:33 | 2026-05-06 00:33 |
| GHSA-QH7Q-6QM3-653W CVE-2025-61669 | Jupyter Server has an open redirection vulnerability in `next` query parameter | 中危 | PyPIjupyter-server | 已审查 | 2026-05-06 00:32 | 2026-06-06 01:55 |
| GHSA-QVJJ-29QF-HP7P CVE-2026-24120 | VM2 Has Sandbox Breakout Through Promise Species | 严重 | npmvm2 | 已审查 | 2026-05-06 00:23 | 2026-05-06 00:23 |
| GHSA-35MW-5VVR-VRXC CVE-2026-43570 | OpenClaw contains a symlink traversal vulnerability | 中危 | npmopenclaw | 已审查 | 2026-05-05 20:31 | 2026-05-09 04:04 |
| GHSA-7PWC-H2J2-RJGJ CVE-2026-43869 | Apache Thrift has an Improper Validation of Certificate with Host Mismatch Vulnerability | 高危 | Mavenorg.apache.thrift:libthrift | 已审查 | 2026-05-05 17:31 | 2026-06-03 06:10 |
| GHSA-526F-JXPJ-JMG2 CVE-2026-43870 | Apache Thrift vulnerable to Path Traversal, HTTP Request/Response Splitting, Uncontrolled Resource Consumption | 高危 | npmthrift | 已审查 | 2026-05-05 17:31 | 2026-05-09 03:24 |