检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-VCGP-9326-PQCP CVE-2026-42246 | net-imap vulnerable to STARTTLS stripping via invalid response timing | 高危 | RubyGemsnet-imap | 已审查 | 2026-05-05 06:01 | 2026-05-15 04:48 |
| GHSA-G38R-8GMR-GHRF | `mysten-metrics` was removed from crates.io for malicious code |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 严重 |
crates.iomysten-metrics |
| 已审查 |
| 2026-05-05 05:43 |
| 2026-05-05 05:43 |
| GHSA-QPRH-M6P3-HWXC | `sui-execution-cut` was removed from crates.io for malicious code | 严重 | crates.iosui-execution-cut | 已审查 | 2026-05-05 05:42 | 2026-05-05 05:42 |
| GHSA-V4GP-HF5J-4566 CVE-2025-67796 | IKUS Rdiffweb allows an attacker with any valid or stolen access token to act as other users | 高危 | PyPIrdiffweb | 已审查 | 2026-05-05 05:30 | 2026-05-09 02:52 |
| GHSA-RM34-FG4M-39MW CVE-2026-38751 | OpenSTAManager contains an arbitrary file upload vulnerability in its module update functionality | 高危 | Packagistdevcode-it/openstamanager | 已审查 | 2026-05-05 05:30 | 2026-05-09 02:48 |
| GHSA-3H23-7824-PJ8R CVE-2026-42601 | ArchiveBox Vulnerable to RCE via unvalidated per-crawl config overrides in AddView | 严重 | PyPIarchivebox | 已审查 | 2026-05-05 05:30 | 2026-07-07 21:05 |
| GHSA-HCWR-PQ9G-RQ3M CVE-2026-42575 | apko doesn't verify downloaded apk packages against APKINDEX checksum (package substitution possible) | 高危 | Gochainguard.dev/apko | 已审查 | 2026-05-05 05:27 | 2026-05-13 21:42 |
| GHSA-QQ3R-W4HJ-GJP6 CVE-2026-42574 | apko dirFS has a symlink-following path traversal that allows multiple entry points to escape the build root | 高危 | Gochainguard.dev/apko | 已审查 | 2026-05-05 05:26 | 2026-05-13 21:42 |
| GHSA-M7HM-VM4X-28JF CVE-2026-42576 | apko `DiscoverKeys` has a panic on non-rsa jwks key that causes crash during key discovery | 中危 | Gochainguard.dev/apko | 已审查 | 2026-05-05 05:25 | 2026-05-13 21:42 |
| GHSA-RPFR-X88X-XWCW CVE-2026-42571 | Pelican Web UI Affected by a Privilege Escalation Attack | 严重 | Gogithub.com/pelicanplatform/pelican | 已审查 | 2026-05-05 05:24 | 2026-05-13 21:42 |
| GHSA-FV26-4939-62FH CVE-2026-42569 | phpVMS has an /importer authorization bypass causing full database wipe | 严重 | Packagistnabeel/phpvms | 已审查 | 2026-05-05 05:20 | 2026-05-13 21:42 |
| GHSA-Q4PH-8X8G-95F8 | AzuraCast Vulnerable to Liquidsoap Code Injection via Incomplete cleanUpString-to-toRawString Migration in Remote Relay Password Field | 高危 | Packagistazuracast/azuracast | 已审查 | 2026-05-05 05:19 | 2026-05-05 05:19 |
| GHSA-QFF7-Q5FM-8P76 | AzuraCast has Missing Permissions Check on Media File Download, Allowing Cross-Station Data Exfiltration | 中危 | Packagistazuracast/azuracast | 已审查 | 2026-05-05 05:19 | 2026-05-05 05:19 |
| GHSA-4FM3-GGG2-C6QX | AzuraCast's Missing RequireInternalConnection on Liquidsoap API Allows Low-Privilege Metadata Injection and Broadcast Disruption | 中危 | Packagistazuracast/azuracast | 已审查 | 2026-05-05 05:18 | 2026-05-05 05:18 |
| GHSA-GV7R-3MR9-H5X8 CVE-2026-42606 | AzuraCast has Password Reset Poisoning via Untrusted X-Forwarded-Host Header that Leads to Account Takeover and 2FA Bypass | 高危 | Packagistazuracast/azuracast | 已审查 | 2026-05-05 05:17 | 2026-05-13 21:42 |
| GHSA-VP2F-CQQP-478J CVE-2026-42605 | AzuraCast has Path Traversal in `currentDirectory` Parameter that Enables Remote Code Execution via Media Upload | 高危 | Packagistazuracast/azuracast | 已审查 | 2026-05-05 05:16 | 2026-05-13 21:42 |
| GHSA-FR8F-RWJX-F32V CVE-2026-42333 | quarkus-openapi-generator has overly broad path-parameter matching that sends authentication headers to unintended operations | 中危 | Mavenio.quarkiverse.openapi.generator:quarkus-openapi-generator | 已审查 | 2026-05-05 05:15 | 2026-05-13 21:41 |
| GHSA-C9PH-GXWW-7744 CVE-2026-41901 | Sandboxed Thymeleaf expressions vulnerable to improper recognition of unauthorized syntax patterns | 严重 | Mavenorg.thymeleaf:thymeleaf+2 | 已审查 | 2026-05-05 05:15 | 2026-05-14 00:43 |
| GHSA-93RG-2XM5-2P9V | OpenClaw's Gateway Control UI bootstrap config required Gateway auth | 中危 | npmopenclaw | 已审查 | 2026-05-05 05:14 | 2026-05-05 05:14 |
| GHSA-5H3G-6XHH-RG6P CVE-2026-44113 | OpenClaw: OpenShell FS bridge reads pin and verify the opened file before returning bytes | 中危 | npmopenclaw | 已审查 | 2026-05-05 05:07 | 2026-05-12 21:36 |
| GHSA-WPPJ-C6MR-83JJ CVE-2026-44112 | OpenClaw: OpenShell FS bridge writes stay pinned to the sandbox mount root | 中危 | npmopenclaw | 已审查 | 2026-05-05 04:57 | 2026-05-12 21:36 |
| GHSA-V7CP-2CX9-X793 CVE-2026-41895 | changedetection.io project has an XXE vulnerability | 高危 | PyPIchangedetection.io | 已审查 | 2026-05-05 04:56 | 2026-06-05 22:31 |
| GHSA-VMFM-CH9H-5C7G CVE-2026-41893 | Signal K Server's WebSocket Login Endpoint Lacks Rate Limiting (Credential Brute-Force) | 高危 | npmsignalk-server | 已审查 | 2026-05-05 04:52 | 2026-05-13 21:41 |
| GHSA-5HFV-C864-QCQ9 CVE-2026-41891 | CI4MS has a Deactivated User Session Bypass (active=0) | 中危 | Packagistci4-cms-erp/ci4ms | 已审查 | 2026-05-05 04:50 | 2026-05-09 04:14 |
| GHSA-VGRF-PR28-VF98 CVE-2026-41890 | CI4MS Vulnerable to Arbitrary Database Table Drop via Theme deleteProcess | 中危 | Packagistci4-cms-erp/ci4ms | 已审查 | 2026-05-05 04:50 | 2026-05-09 04:14 |