检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-2HFH-9H53-QC24 CVE-2026-42403 | Apache Neethi does not properly detect circular references in policy definitions. | 高危 | Mavenorg.apache.neethi:neethi | 已审查 | 2026-05-01 17:30 | 2026-05-07 10:39 |
| GHSA-85X2-R8XV-WW8C CVE-2026-42137 | Kirby CMS's `pages.access/list` and `files.access/list` permissions are not consistently checked in the Panel and REST API |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 高危 |
Packagistgetkirby/cms |
| 已审查 |
| 2026-05-01 05:03 |
| 2026-05-01 05:03 |
| GHSA-MQQ7-WXX5-MP8H | ps_checkout allows unauthorized method invocation through unvalidated parameter | 低危 | Packagistprestashop/ps_checkout | 已审查 | 2026-05-01 04:59 | 2026-05-01 04:59 |
| GHSA-RH99-WC69-C255 | Contras Affected by CopyFile Policy Subversion via Symlinks | 高危 | Gogithub.com/edgelesssys/contrast | 已审查 | 2026-05-01 04:57 | 2026-05-01 04:57 |
| GHSA-CXX3-HR75-4Q96 CVE-2026-42461 | Arcane Vulnerable to Unauthenticated Disclosure of Custom Compose Template Content (incl. `.env` secrets) | 高危 | Gogithub.com/getarcaneapp/arcane/backend | 已审查 | 2026-05-01 04:55 | 2026-05-13 21:38 |
| GHSA-F6QQ-3M3H-4G42 CVE-2026-42560 | auth: Patreon provider assigns the same local user ID to every authenticated Patreon account, enabling cross‑user impersonation | 严重 | Gogithub.com/go-pkgz/auth+1 | 已审查 | 2026-05-01 04:47 | 2026-05-13 21:41 |
| GHSA-RCMW-7MC7-3RJ7 CVE-2026-42354 | Sentry's improper authentication on SAML SSO process allows user identity linking | 严重 | PyPIsentry | 已审查 | 2026-05-01 04:44 | 2026-05-13 21:38 |
| GHSA-4625-4J76-FWW9 CVE-2026-42191 | OpenTelemetry's disk retry default temp path enables local blob injection via OTLP Exporter | 中危 | NuGetOpenTelemetry.Exporter.OpenTelemetryProtocol | 已审查 | 2026-05-01 02:34 | 2026-05-14 00:27 |
| GHSA-FQCW-2XHJ-P63G CVE-2026-36766 | Shopizer is vulnerable to Cross-site Scripting | 中危 | Mavencom.shopizer:shopizer | 已审查 | 2026-05-01 02:30 | 2026-05-07 09:20 |
| GHSA-F5W4-7CCJ-5M75 CVE-2026-36767 | Shopizer has a path traversal issue | 严重 | Mavencom.shopizer:shopizer | 已审查 | 2026-05-01 02:30 | 2026-05-07 09:19 |
| GHSA-32PX-CCFX-CXQ3 CVE-2026-36340 | Krayin CRM allows a remote attacker to execute arbitrary code via compose email function | 高危 | Packagistkrayin/laravel-crm | 已审查 | 2026-05-01 02:30 | 2026-05-07 09:16 |
| GHSA-28XX-PPPM-VQFF | ydb-go-sdk's transactions are not committed using the `options.WithCommit()` option on last call `table.Transaction.Execute` in transaction | 低危 | Gogithub.com/ydb-platform/ydb-go-sdk/v3 | 已审查 | 2026-05-01 02:21 | 2026-06-09 04:10 |
| GHSA-W24R-5266-9C3C CVE-2026-42349 | Clerk has an authorization bypass when combining organization, billing, or reverification checks | 高危 | npm@clerk/astro+16 | 已审查 | 2026-05-01 02:20 | 2026-06-09 18:49 |
| GHSA-56C3-VFP2-5QQJ CVE-2026-42449 | n8n-mcp's IPv4-mapped IPv6 addresses bypass SSRF protection in validateUrlSync(), enabling full SSRF for SDK embedders | 高危 | npmn8n-mcp | 已审查 | 2026-05-01 02:12 | 2026-05-11 21:29 |
| GHSA-83HF-93M4-RGWQ | Hickory DNS's Record Cache Accepts AUTHORITY-Section NS from Sibling Zone via Parent-Pool Zone-Context Elevation | 高危 | crates.iohickory-recursor | 已审查 | 2026-05-01 02:10 | 2026-05-01 02:10 |
| GHSA-CG4X-64P3-X59H CVE-2026-42032 | CKAN has Unauthenticated Authorization Bypass in `datastore_search_sql` | 中危 | PyPIckan | 已审查 | 2026-05-01 01:34 | 2026-05-15 04:39 |
| GHSA-CWCX-382V-8M9G CVE-2026-41654 | Weblate Vulnerable to Authenticated SSRF via Project Backup Import bypassing validate_repo_url | 中危 | PyPIweblate | 已审查 | 2026-05-01 01:28 | 2026-05-09 05:47 |
| GHSA-6J8J-4QP3-36P2 CVE-2026-41519 | Weblate Doesn't Invalidate API Token on Password Change | 中危 | PyPIweblate | 已审查 | 2026-05-01 01:28 | 2026-05-09 05:47 |
| GHSA-Q7R4-HC83-HF2Q CVE-2026-40281 | Gotenberg has ExifTool stdin argument injection via metadata value newlines (bypass of key sanitization fix) | 严重 | Gogithub.com/gotenberg/gotenberg/v8 | 已审查 | 2026-05-01 01:27 | 2026-05-09 03:26 |
| GHSA-RCH3-82JR-F9W9 CVE-2026-40171 | Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS | 高危 | npm@jupyter-notebook/help-extension+3 | 已审查 | 2026-05-01 01:25 | 2026-05-09 03:26 |
| GHSA-5VH4-RGV7-P9G4 CVE-2026-39383 | Gotenberg Vulnerable to Unauthenticated SSRF via Unfiltered Webhook URL | 中危 | Gogithub.com/gotenberg/gotenberg/v8 | 已审查 | 2026-05-01 01:24 | 2026-05-08 23:31 |
| GHSA-5Q7P-7JGV-WW56 CVE-2026-40280 | Gotenberg has case-insensitive URL scheme that bypasses webhook and downloadFrom deny-list SSRF protection | 高危 | Gogithub.com/gotenberg/gotenberg/v8 | 已审查 | 2026-05-01 01:19 | 2026-05-08 23:31 |
| GHSA-HM32-HFMW-RHVG CVE-2026-7500 | Keycloak has a Forced Browsing issue | 中危 | Mavenorg.keycloak:keycloak-services | 已审查 | 2026-04-30 23:30 | 2026-06-26 17:30 |
| GHSA-X8MH-94WC-33GV CVE-2026-41016 | apache-airflow-providers-smtp: No certificate validation on SMTP STARTTLS connections in SMTP provider | 中危 | PyPIapache-airflow-providers-smtp | 已审查 | 2026-04-30 20:33 | 2026-05-22 21:04 |
| GHSA-QP2C-XQV6-PHH6 CVE-2025-13030 | django-mdeditor is Missing Authentication for Critical Function | 低危 | PyPIdjango-mdeditor | 已审查 | 2026-04-30 14:30 | 2026-05-07 07:41 |