检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-P6HG-QH38-555R CVE-2026-41181 | Traefik's errors middleware forwards Authorization and Cookie headers to separate error page service | 中危 | Gogithub.com/traefik/traefik/v2+1 | 已审查 | 2026-05-05 03:26 | 2026-05-16 07:48 |
| GHSA-62P3-HVXX-FXG4 CVE-2026-40893 |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 高危 |
Gogithub.com/gotenberg/gotenberg/v8 |
| 已审查 |
| 2026-05-05 03:21 |
| 2026-05-15 04:51 |
| GHSA-4M88-WXJ4-9QJ6 CVE-2026-40251 | Incus Vulnerable to Panic via Snapshot Bounds Check | 高危 | Gogithub.com/lxc/incus/v6/cmd/incusd | 已审查 | 2026-05-05 03:16 | 2026-05-09 03:26 |
| GHSA-C839-4QXR-J4X3 CVE-2026-40243 | Incus has an OVN TLS Verification that Accepts Peer-Supplied Roots | 低危 | Gogithub.com/lxc/incus/v6/cmd/incusd | 已审查 | 2026-05-05 03:08 | 2026-05-09 03:26 |
| GHSA-W76P-3CGP-QFCM CVE-2026-42812 | Apache Polaris has an Improper Input Validation issue | 严重 | Mavenorg.apache.polaris:polaris-runtime-service | 已审查 | 2026-05-05 02:30 | 2026-09-01 06:49 |
| GHSA-VXGG-MQX2-3W59 CVE-2026-42810 | Apache Polaris has an Improper Input Validation Issue | 严重 | Mavenorg.apache.polaris:polaris-core | 已审查 | 2026-05-05 02:30 | 2026-05-09 01:57 |
| GHSA-FC3H-C6H7-R83J CVE-2026-42811 | Apache Polaris has an Improper Input Validation issue | 严重 | Mavenorg.apache.polaris:polaris-core | 已审查 | 2026-05-05 02:30 | 2026-05-09 01:58 |
| GHSA-CX4M-2P55-RW7J CVE-2026-42027 | Apache OpenNLP ExtensionLoader Vulnerable to Arbitrary Class Instantiation via Model Manifest | 严重 | Mavenorg.apache.opennlp:opennlp-tools | 已审查 | 2026-05-05 02:30 | 2026-08-15 03:33 |
| GHSA-8GGJ-J522-H5QF CVE-2026-42809 | Apache Polaris has an Improper Input Validation Issue | 严重 | Mavenorg.apache.polaris:polaris-runtime-service | 已审查 | 2026-05-05 02:30 | 2026-05-09 01:56 |
| GHSA-659W-93R5-9J6M CVE-2026-42440 | Apache OpenNLP AbstractModelReader has an OOM Denial of Service via Unbounded Array Allocation | 高危 | Mavenorg.apache.opennlp:opennlp-tools | 已审查 | 2026-05-05 02:30 | 2026-05-09 01:54 |
| GHSA-WMVJ-F67G-QG4G CVE-2026-37461 | GoBGP has an out-of-bounds read in the ParseIP6Extended function | 高危 | Gogithub.com/osrg/gobgp/v4 | 已审查 | 2026-05-05 02:30 | 2026-05-09 01:47 |
| GHSA-4V8G-86X5-3VRC CVE-2026-40682 | Apache OpenNLP DictionaryEntryPersistor Vulnerable to XML External Entity (XXE) via Unsanitized Dictionary Parsing | 严重 | Mavenorg.apache.opennlp:opennlp-tools | 已审查 | 2026-05-05 02:30 | 2026-05-09 01:51 |
| GHSA-35XX-9XRG-GWHF CVE-2026-40563 | Apache Atlas has a Code Injection Vulnerability | 高危 | Mavenorg.apache.atlas:apache-atlas | 已审查 | 2026-05-05 02:30 | 2026-05-09 01:46 |
| GHSA-R7W7-MMXR-47R9 CVE-2026-40197 | Incus has a Nil-Pointer Dereference via Custom Volume Import | 高危 | Gogithub.com/lxc/incus/v6/cmd/incusd | 已审查 | 2026-05-05 01:45 | 2026-05-09 03:27 |
| GHSA-GC7J-G665-RXR9 CVE-2026-40195 | Incus has a Nil-Pointer Dereference Panic via Bucket Metadata | 高危 | Gogithub.com/lxc/incus/v6/cmd/incusd | 已审查 | 2026-05-05 01:40 | 2026-05-09 03:26 |
| GHSA-78FC-9688-W8XW CVE-2026-40076 | OpenMRS Module Upload Vulnerable to Path Traversal (Zip Slip) | 严重 | Mavenorg.openmrs.web:openmrs-web | 已审查 | 2026-05-05 01:39 | 2026-05-09 03:25 |
| GHSA-RC95-PCM8-65V9 CVE-2026-39852 | Quarkus has Authentication/Authorization bypasses | 高危 | Mavenio.quarkus:quarkus-vertx-http | 已审查 | 2026-05-05 01:20 | 2026-08-13 23:33 |
| GHSA-JJGJ-CX3Q-PW4W CVE-2026-40075 | OpenMRS ModuleResourcesServlet has Path Traversal that Leads to Arbitrary File Read | 高危 | Mavenorg.openmrs.web:openmrs-web | 已审查 | 2026-05-05 01:18 | 2026-05-08 23:36 |
| GHSA-8GW4-P4WQ-4HCV CVE-2026-35527 | Incus has Blind SSRF via Image Import Preflight HEAD | 中危 | Gogithub.com/lxc/incus/v6/cmd/incusd | 已审查 | 2026-05-05 00:53 | 2026-05-08 23:30 |
| GHSA-QM77-8QJP-4VCM CVE-2026-41358 | OpenClaw: Slack thread context could include messages from non-allowlisted senders | 低危 | npmopenclaw | 已审查 | 2026-05-05 00:52 | 2026-05-05 00:52 |
| GHSA-GRJ5-JJM8-H35P CVE-2026-24118 | VM2 Sandbox Breakout Through __lookupGetter__ | 严重 | npmvm2 | 已审查 | 2026-05-05 00:29 | 2026-05-08 09:25 |
| GHSA-J9RH-P96M-MHHP CVE-2026-6501 | jOpenDocument has an improper restriction of XML external entity reference vulnerability | 中危 | Mavenorg.jopendocument:jOpenDocument | 已审查 | 2026-05-04 23:31 | 2026-05-09 01:29 |
| GHSA-X8QC-FGGM-MPQG CVE-2026-7482 | Ollama contains a heap out-of-bounds read vulnerability in the GGUF model loader | 高危 | Gogithub.com/ollama/ollama | 已审查 | 2026-05-04 23:31 | 2026-05-09 01:26 |
| GHSA-W88C-9VG8-CMQ8 CVE-2026-7737 | GoBGP has Improper Restriction of Operations within the Bounds of a Memory Buffer | 中危 | Gogithub.com/osrg/gobgp | 已审查 | 2026-05-04 17:31 | 2026-05-12 00:11 |
| GHSA-HJ4W-QR9J-C4CF CVE-2026-7736 | GoBGP has an Integer Underflow Issue | 中危 | Gogithub.com/osrg/gobgp/v4 | 已审查 | 2026-05-04 17:31 | 2026-05-09 00:58 |