检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-2F9F-GQ7V-9H6M CVE-2026-43868 | Apache Thrift has a Memory Allocation with Excessive Size Value Vulnerability | 中危 | crates.iothrift | 已审查 | 2026-05-05 17:31 | 2026-07-22 04:01 |
| GHSA-445Q-VR5W-6Q77 CVE-2026-42037 | Axios: CRLF Injection in multipart/form-data body via unsanitized blob.type in formDataToStream |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 中危 |
npmaxios |
| 已审查 |
| 2026-05-05 08:40 |
| 2026-05-05 08:40 |
| GHSA-M7PR-HJQH-92CM CVE-2026-42038 | Axios: no_proxy bypass via IP alias allows SSRF | 中危 | npmaxios | 已审查 | 2026-05-05 08:40 | 2026-05-05 08:40 |
| GHSA-62HF-57XW-28J9 CVE-2026-42039 | Axios: unbounded recursion in toFormData causes DoS via deeply nested request data | 中危 | npmaxios | 已审查 | 2026-05-05 08:34 | 2026-06-08 23:54 |
| GHSA-5C9X-8GCM-MPGX CVE-2026-42034 | Axios' HTTP adapter-streamed uploads bypass maxBodyLength when maxRedirects: 0 | 中危 | npmaxios | 已审查 | 2026-05-05 08:33 | 2026-05-05 08:33 |
| GHSA-7X9R-WCGG-W86F CVE-2026-7776 | Hashicorp Boundary workers are vulnerable to a denial-of-service condition during node enrollment TLS handshakes | 高危 | Gogithub.com/hashicorp/boundary | 已审查 | 2026-05-05 08:30 | 2026-07-21 21:53 |
| GHSA-VF2M-468P-8V99 CVE-2026-42036 | Axios: HTTP adapter streamed responses bypass maxContentLength | 中危 | npmaxios | 已审查 | 2026-05-05 08:26 | 2026-05-05 08:26 |
| GHSA-PF86-5X62-JRWF CVE-2026-42033 | Axios: Prototype Pollution Gadgets - Response Tampering, Data Exfiltration, and Request Hijacking | 高危 | npmaxios | 已审查 | 2026-05-05 08:26 | 2026-05-05 08:26 |
| GHSA-6CHQ-WFR3-2HJ9 CVE-2026-42035 | Axios: Header Injection via Prototype Pollution | 高危 | npmaxios | 已审查 | 2026-05-05 08:25 | 2026-05-05 08:25 |
| GHSA-XX6V-RP6X-Q39C CVE-2026-42042 | Axios: XSRF Token Cross-Origin Leakage via Prototype Pollution Gadget in `withXSRFToken` Boolean Coercion | 中危 | npmaxios | 已审查 | 2026-05-05 08:25 | 2026-05-05 08:25 |
| GHSA-W9J2-PVGH-6H63 CVE-2026-42041 | Axios: Authentication Bypass via Prototype Pollution Gadget in `validateStatus` Merge Strategy | 中危 | npmaxios | 已审查 | 2026-05-05 08:21 | 2026-05-05 08:21 |
| GHSA-PMWG-CVHR-8VH7 CVE-2026-42043 | Axios: Incomplete Fix for CVE-2025-62718 — NO_PROXY Protection Bypassed via RFC 1122 Loopback Subnet (127.0.0.0/8) in Axios 1.15.0 | 高危 | npmaxios | 已审查 | 2026-05-05 08:20 | 2026-05-05 08:20 |
| GHSA-3W6X-2G7M-8V23 CVE-2026-42044 | Axios: Invisible JSON Response Tampering via Prototype Pollution Gadget in `parseReviver` | 中危 | npmaxios | 已审查 | 2026-05-05 08:19 | 2026-05-05 08:19 |
| GHSA-Q8QP-CVCW-X6JJ CVE-2026-42264 | Axios has prototype pollution read-side gadgets in HTTP adapter that allow credential injection and request hijacking | 高危 | npmaxios | 已审查 | 2026-05-05 08:18 | 2026-05-12 21:28 |
| GHSA-XHJH-PMCV-23JW CVE-2026-42040 | Axios: Null Byte Injection via Reverse-Encoding in AxiosURLSearchParams | 低危 | npmaxios | 已审查 | 2026-05-05 08:18 | 2026-05-05 08:18 |
| GHSA-8PQQ-224H-X875 | ogham-mcp had credentials embedded in published PyPI sdists -- Neon postgres URLs and Voyage API key | 中危 | PyPIogham-mcp | 已审查 | 2026-05-05 08:03 | 2026-05-05 08:03 |
| GHSA-G27R-R6PH-VF5R | sequoia-git has broken hard revocation handling | 低危 | crates.iosequoia-git | 已审查 | 2026-05-05 06:28 | 2026-05-05 06:28 |
| GHSA-FC86-6RV6-2JPM | webonyx/graphql-php has quadratic validation cost in OverlappingFieldsCanBeMerged via inline fragments | 高危 | Packagistwebonyx/graphql-php | 已审查 | 2026-05-05 06:22 | 2026-05-05 06:22 |
| GHSA-GXXH-8VCJ-W2MH | livewire-markdown-editor has arbitrary file upload that allows stored XSS via attachment handler | 高危 | Packagistmckenziearts/livewire-markdown-editor | 已审查 | 2026-05-05 06:11 | 2026-05-05 06:11 |
| GHSA-PG67-9WJV-MR85 CVE-2026-42313 | pyload-ng: non-admin SETTINGS users can redirect all outbound traffic through an attacker-controlled proxy via unrestricted `proxy.*` config (incomplete fix for CVE-2026-33509 / -35463 / -35464 / -35586) | 高危 | PyPIpyload-ng | 已审查 | 2026-05-05 06:08 | 2026-06-09 03:48 |
| GHSA-CCXC-X975-4HH9 CVE-2026-42312 | pyload-ng: non-admin SETTINGS users can disable outbound TLS peer verification via unrestricted `ssl_verify` config (incomplete fix for CVE-2026-33509 / -35463 / -35464 / -35586) | 中危 | PyPIpyload-ng | 已审查 | 2026-05-05 06:07 | 2026-06-09 03:48 |
| GHSA-HM49-WCQC-G2XG CVE-2026-42257 | net-imap vulnerable to command Injection via "raw" arguments to multiple commands | 中危 | RubyGemsnet-imap | 已审查 | 2026-05-05 06:04 | 2026-06-18 03:45 |
| GHSA-75XQ-5H9V-W6PX CVE-2026-42258 | net-imap vulnerable to command Injection via unvalidated Symbol inputs | 中危 | RubyGemsnet-imap | 已审查 | 2026-05-05 06:04 | 2026-07-22 20:31 |
| GHSA-87PF-FPWV-P7M7 CVE-2026-42256 | net-imap vulnerable to denial of service via high iteration count for `SCRAM-*` authentication | 中危 | RubyGemsnet-imap | 已审查 | 2026-05-05 06:03 | 2026-05-15 04:48 |
| GHSA-Q2MW-FVJ9-VVCW CVE-2026-42245 | net-imap has quadratic complexity when reading response literals | 低危 | RubyGemsnet-imap | 已审查 | 2026-05-05 06:02 | 2026-05-15 04:48 |