检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-6PJF-3R9X-M592 CVE-2026-41888 | Distribution's tag deletion bypasses `storage.delete.enabled` configuration | 中危 | Gogithub.com/distribution/distribution+1 | 已审查 | 2026-05-05 04:48 | 2026-07-21 21:45 |
| GHSA-X3H8-JRGH-P8JX | OpenClaw's exec allowlist analysis rejects shell expansion in unquoted heredocs |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 中危 |
npmopenclaw |
| 已审查 |
| 2026-05-05 04:23 |
| 2026-05-13 21:45 |
| GHSA-R6XH-PQHR-V4XH CVE-2026-44118 | OpenClaw: MCP loopback owner context is derived from server-issued bearer tokens | 高危 | npmopenclaw | 已审查 | 2026-05-05 04:22 | 2026-05-12 21:37 |
| GHSA-55CF-XX38-4P9P CVE-2026-45003 | OpenClaw: Workspace dotenv files cannot override connector endpoint hosts | 中危 | npmopenclaw | 已审查 | 2026-05-05 04:22 | 2026-05-19 23:56 |
| GHSA-Q3JJ-46PQ-826R CVE-2026-44997 | OpenClaw's ACP child sessions inherit subagent security envelope constraints | 中危 | npmopenclaw | 已审查 | 2026-05-05 04:21 | 2026-05-19 23:56 |
| GHSA-2HH7-C75G-QJ2R CVE-2026-44116 | OpenClaw validates Zalo outbound photo URLs through the SSRF guard | 中危 | npmopenclaw | 已审查 | 2026-05-05 04:21 | 2026-05-12 21:36 |
| GHSA-PWV6-VV43-88GR CVE-2026-42311 | Pillow has an OOB Write with Invalid PSD Tile Extents (Integer Overflow) | 高危 | PyPIpillow | 已审查 | 2026-05-05 04:20 | 2026-05-13 21:41 |
| GHSA-R73J-PQJ5-W3X7 CVE-2026-42310 | Pillow has a PDF Parsing Trailer Infinite Loop (DoS) | 中危 | PyPIpillow | 已审查 | 2026-05-05 04:19 | 2026-05-13 21:41 |
| GHSA-WJX4-4JCJ-G98J CVE-2026-42308 | Pillow has an integer overflow when processing fonts | 中危 | PyPIpillow | 已审查 | 2026-05-05 04:18 | 2026-06-09 07:40 |
| GHSA-5XMW-VC9V-4WF2 CVE-2026-42309 | Pillow has a heap buffer overflow with nested list coordinates | 中危 | PyPIpillow | 已审查 | 2026-05-05 04:18 | 2026-05-13 21:39 |
| GHSA-R35X-V8P8-XVHW CVE-2026-42301 | pyp2spec is Vulnerable to Code Injection | 高危 | PyPIpyp2spec | 已审查 | 2026-05-05 04:14 | 2026-05-13 21:39 |
| GHSA-7VF8-2CR6-54MF CVE-2026-42295 | Argo vulnerable to exposure of artifact repository credentials | 高危 | Gogithub.com/argoproj/argo-workflows/v4 | 已审查 | 2026-05-05 04:12 | 2026-07-21 21:51 |
| GHSA-3775-99MW-8RP4 CVE-2026-42296 | Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure | 高危 | Gogithub.com/argoproj/argo-workflows/v3+1 | 已审查 | 2026-05-05 04:11 | 2026-05-13 21:39 |
| GHSA-JCC8-G2Q4-9FXQ CVE-2026-42294 | Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor | 高危 | Gogithub.com/argoproj/argo-workflows/v3+1 | 已审查 | 2026-05-05 04:11 | 2026-07-21 22:54 |
| GHSA-P4GQ-3VXJ-F4JQ CVE-2026-42183 | Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) | 低危 | Gogithub.com/argoproj/argo-workflows/v4 | 已审查 | 2026-05-05 04:01 | 2026-05-13 21:39 |
| GHSA-XCHC-CQWG-G76Q CVE-2026-42297 | Argo has Missing Authorization in its Sync ConfigMap Provider | 高危 | Gogithub.com/argoproj/argo-workflows/v4 | 已审查 | 2026-05-05 04:00 | 2026-05-13 21:39 |
| GHSA-X68M-C7JF-2572 CVE-2026-42051 | Kirby CMS's system API endpoint leaks installed version and license data to authenticated users | 中危 | Packagistgetkirby/cms | 已审查 | 2026-05-05 03:59 | 2026-05-13 21:38 |
| GHSA-39CP-6679-8XV2 CVE-2026-42174 | Kirby CMS doesn't gate user avatar creation, replacement and deletion with user update permissions | 中危 | Packagistgetkirby/cms | 已审查 | 2026-05-05 03:58 | 2026-05-13 21:38 |
| GHSA-2H7V-4372-F6X2 CVE-2026-42069 | Kirby CMS's read access to site, user and role information is not gated by permissions | 高危 | Packagistgetkirby/cms | 已审查 | 2026-05-05 03:50 | 2026-05-13 21:38 |
| GHSA-98VH-X9CX-9CFP CVE-2026-41685 | Incus is affected by unbounded binary import disk exhaustion | 中危 | Gogithub.com/lxc/incus/v6/cmd/incusd | 已审查 | 2026-05-05 03:46 | 2026-05-09 05:47 |
| GHSA-X5R6-JR56-89PV CVE-2026-41684 | Incus has Nil Dereferences on Restore via Malformed YAML | 中危 | Gogithub.com/lxc/incus/v6/cmd/incusd | 已审查 | 2026-05-05 03:45 | 2026-05-09 05:47 |
| GHSA-67WX-R9XR-X75X CVE-2026-41648 | Incus has Unbounded YAML Metadata Decode via Parsing | 中危 | Gogithub.com/lxc/incus/v6/cmd/incusd | 已审查 | 2026-05-05 03:44 | 2026-05-09 05:47 |
| GHSA-FWJ8-62R8-8P8M CVE-2026-41647 | Incus has Nil-Pointer Dereference via S3 Bucket Import | 中危 | Gogithub.com/lxc/incus/v6/cmd/incusd | 已审查 | 2026-05-05 03:38 | 2026-05-09 05:47 |
| GHSA-Q49M-57VM-C8CC CVE-2026-41326 | Kata Container has CopyFile Policy Subversion via Symlinks | 高危 | Gogithub.com/kata-containers/kata-containers | 已审查 | 2026-05-05 03:32 | 2026-05-15 04:49 |
| GHSA-XJ4F-8JJG-VX4Q CVE-2026-41258 | OpenMRS has Stored Velocity SSTI to RCE via ConceptReferenceRange | 严重 | Mavenorg.openmrs.api:openmrs-api | 已审查 | 2026-05-05 03:31 | 2026-05-16 07:48 |