检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-Q5F4-99JV-PGG5 CVE-2026-42231 | n8n has Prototype Pollution in XML Webhook Body Parser that Leads to RCE | 严重 | npmn8n | 已审查 | 2026-04-30 05:25 | 2026-05-08 09:31 |
| GHSA-537J-GQPC-P7FQ CVE-2026-42235 |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 高危 |
npmn8n |
| 已审查 |
| 2026-04-30 05:23 |
| 2026-05-08 09:31 |
| GHSA-R4V6-9FQC-W5JR CVE-2026-42226 | n8n's Credential Authorization Bypass in dynamic-node-parameters Allows Foreign API Key Replay | 高危 | npmn8n | 已审查 | 2026-04-30 05:22 | 2026-05-08 09:31 |
| GHSA-44V6-JHGM-P3M4 CVE-2026-42234 | n8n has a Python Task Runner Sandbox Escape Vulnerability | 高危 | npmn8n | 已审查 | 2026-04-30 05:21 | 2026-05-08 09:31 |
| GHSA-756Q-GQ9H-FP22 CVE-2026-42227 | n8n has Public API Variables IDOR that Allows Cross-Project Secret Disclosure | 中危 | npmn8n | 已审查 | 2026-04-30 05:21 | 2026-05-08 09:31 |
| GHSA-49M9-PGWW-9VQ6 CVE-2026-42236 | n8n Vulnerable to Unauthenticated Denial of Service via MCP Client Registration | 高危 | npmn8n | 已审查 | 2026-04-30 05:19 | 2026-05-08 09:31 |
| GHSA-F77H-J2V7-G6MW CVE-2026-42228 | n8n Vulnerable to Hijacking of Unauthenticated Chat Execution | 中危 | npmn8n | 已审查 | 2026-04-30 05:17 | 2026-05-08 09:31 |
| GHSA-MP4J-H6GH-F6MP CVE-2026-42229 | n8n has SQL Injection in SeaTable Node | 中危 | npmn8n | 已审查 | 2026-04-30 05:10 | 2026-05-08 09:30 |
| GHSA-F6X8-65Q6-J9M9 CVE-2026-42230 | n8n has Open Redirect in MCP OAuth Consent Flow | 中危 | npmn8n | 已审查 | 2026-04-30 05:10 | 2026-05-08 09:30 |
| GHSA-R6JC-MPQW-M755 CVE-2026-42233 | n8n has SQL Injection in Oracle Database Node via Limit Field | 中危 | npmn8n | 已审查 | 2026-04-30 05:08 | 2026-05-08 09:30 |
| GHSA-HP3C-VFPM-Q4F7 CVE-2026-42237 | n8n has SQL Injection in Snowflake and MySQL Nodes | 中危 | npmn8n | 已审查 | 2026-04-30 05:03 | 2026-05-08 09:30 |
| GHSA-55WF-5M3Q-6JJF CVE-2026-42224 | ipl/web is vulnerable to reflected XSS by malformed search requests | 高危 | Packagistipl/web | 已审查 | 2026-04-30 05:01 | 2026-06-09 18:44 |
| GHSA-H8CJ-HPMG-636V | appsmith has SQL Injection in FilterDataService via Unsafe DROP TABLE Execution | 高危 | Mavencom.appsmith:interfaces | 已审查 | 2026-04-30 04:59 | 2026-04-30 04:59 |
| GHSA-WR32-99HH-6F35 CVE-2026-44015 | Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal Services | 高危 | Gogithub.com/0xJacky/Nginx-UI | 已审查 | 2026-04-30 04:54 | 2026-05-14 00:31 |
| GHSA-3GX8-Q682-38MX CVE-2026-42206 | OpenID Connect nonce generated but never validated — ID token replay attack | 中危 | Packagistroadiz/openid | 已审查 | 2026-04-30 04:51 | 2026-05-13 21:38 |
| GHSA-8RXH-R2P6-7F2Q CVE-2026-41643 | GoBGP has Remote Denial of Service (Panic) in UpdatePathAttrs4ByteAs via Malformed BGP UPDATE | 高危 | Gogithub.com/osrg/gobgp/v4 | 已审查 | 2026-04-30 04:44 | 2026-05-09 04:42 |
| GHSA-7235-89M6-F4PX CVE-2026-41642 | GoBGP has Remote Denial of Service (Panic) via Malformed Well-known Path Attribute | 高危 | Gogithub.com/osrg/gobgp/v4 | 已审查 | 2026-04-30 04:43 | 2026-05-09 04:42 |
| GHSA-FW49-9XQ4-GMX6 CVE-2026-41587 | CI4MS has Unrestricted PHP File Upload via Theme Installation that Leads to Authenticated Remote Code Execution | 高危 | Packagistci4-cms-erp/ci4ms | 已审查 | 2026-04-30 04:42 | 2026-05-09 03:55 |
| GHSA-PRF8-CF2X-RHX7 CVE-2026-41586 | fabric-sdk-java has ObjectInputStream.readObject() without ObjectInputFilter, which allows Java deserialization RCE | 严重 | Mavenorg.hyperledger.fabric-sdk-java:fabric-sdk-java | 已审查 | 2026-04-30 04:41 | 2026-05-21 06:56 |
| GHSA-MCVF-JXCW-VJ73 CVE-2026-41255 | CKAN has CSRF exemption primed by anonymous requests | 中危 | PyPIckan | 已审查 | 2026-04-30 04:36 | 2026-05-15 04:39 |
| GHSA-MPFM-FPGX-647Q CVE-2026-41132 | CKAN has no certificate validation on STMP connection | 中危 | PyPIckan | 已审查 | 2026-04-30 04:33 | 2026-05-15 04:39 |
| GHSA-7C6M-4442-2X6M CVE-2026-40902 | PhpSpreadsheet has CPU Denial of Service via Unbounded Row Number in XLSX Row Dimensions | 高危 | Packagistphpoffice/phpspreadsheet | 已审查 | 2026-04-30 04:24 | 2026-05-14 00:31 |
| GHSA-84WQ-86V6-X5J6 CVE-2026-40863 | PhpSpreadsheet has CPU Denial of Service via Unbounded Row Index in SpreadsheetML XML Reader | 高危 | Packagistphpoffice/phpspreadsheet | 已审查 | 2026-04-30 04:23 | 2026-05-14 00:31 |
| GHSA-Q4Q6-R8WH-5CGH CVE-2026-34084 | PhpSpreadsheet has SSRF/RCE in IOFactory::load when $filename is user controlled | 严重 | Packagistphpoffice/phpspreadsheet | 已审查 | 2026-04-30 04:22 | 2026-05-08 23:29 |
| GHSA-55M9-299J-53C7 CVE-2026-41484 | OneCollector exporter reads unbounded HTTP response bodies | 中危 | NuGetOpenTelemetry.Exporter.OneCollector | 已审查 | 2026-04-30 04:17 | 2026-05-09 03:32 |