检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-63CW-R7XF-JMWR CVE-2026-32936 | CoreDNS DoH GET oversized dns= query parameter causes pre-validation CPU and memory amplification | 高危 | Gogithub.com/coredns/coredns | 已审查 | 2026-04-29 06:43 | 2026-06-13 03:25 |
| GHSA-2WPX-QPW2-G5H5 CVE-2026-32934 |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 高危 |
Gogithub.com/coredns/coredns |
| 已审查 |
| 2026-04-29 06:40 |
| 2026-05-08 23:27 |
| GHSA-PP79-HQV6-VMC3 CVE-2026-32699 | FacturaScripts has Insecure Parameter Handling: Unauthorized Modification of Immutable 'nick' Field | 中危 | Packagistfacturascripts/facturascripts | 已审查 | 2026-04-29 06:39 | 2026-05-08 02:46 |
| GHSA-35HP-HQMV-8QG8 CVE-2026-30246 | Fiber's cache middleware default key generator ignores query string, causing response mix-up across distinct query parameters | 中危 | Gogithub.com/gofiber/fiber/v3 | 已审查 | 2026-04-29 06:28 | 2026-05-08 21:42 |
| GHSA-JQP3-QRGH-4846 CVE-2026-24178 | NVIDIA NVFlare Dashboard: Authorization bypass through user-controlled key via user management and authentication system | 严重 | PyPInvflare | 已审查 | 2026-04-29 05:36 | 2026-06-10 04:32 |
| GHSA-QPV2-RWC8-C993 CVE-2026-38651 | Netmaker does not verify JWT signatures for host tokens | 严重 | Gogithub.com/gravitl/netmaker | 已审查 | 2026-04-29 02:30 | 2026-05-05 22:45 |
| GHSA-4G9C-3X4P-MFPP CVE-2026-40968 | Spring gRPC SecurityContext leaks across requests upon authorization failure | 中危 | Mavenorg.springframework.grpc:spring-grpc | 已审查 | 2026-04-28 23:30 | 2026-05-07 03:59 |
| GHSA-37W2-Q6VH-45V6 CVE-2026-40969 | Spring gRPC AuthenticationException messages are reflected to remote client | 低危 | Mavenorg.springframework.grpc:spring-grpc | 已审查 | 2026-04-28 23:30 | 2026-05-07 04:00 |
| GHSA-WF45-Q9CH-Q8GH CVE-2026-41602 | Apache Thrift TFramedTransport Go language implementation has an Integer Overflow or Wraparound vulnerability | 高危 | Gogithub.com/apache/thrift | 已审查 | 2026-04-28 20:31 | 2026-05-07 03:57 |
| GHSA-R67J-R569-JRWP CVE-2026-41636 | Apache Thrift Node.js bindings vulnerable to Uncontrolled Recursion | 高危 | npmthrift | 已审查 | 2026-04-28 20:31 | 2026-05-07 03:56 |
| GHSA-V6X6-PJXW-3PV2 CVE-2026-40966 | Spring AI's VectorStoreChatMemoryAdvisor conversation scoping can lead to cross-tenant memory exfiltration | 中危 | Mavenorg.springframework.ai:spring-ai-advisors-vector-store | 已审查 | 2026-04-28 17:34 | 2026-07-18 04:49 |
| GHSA-R5HP-3CGJ-J6XV CVE-2026-40979 | Spring AI's ONNX model cache defaults to world-writable predictable /tmp directory | 中危 | Mavenorg.springframework.ai:spring-ai-transformers | 已审查 | 2026-04-28 17:34 | 2026-05-07 03:52 |
| GHSA-63C8-M9M2-CVR3 CVE-2026-40978 | Spring AI has SQL Injection in CosmosDBVectorStore.doDelete() | 高危 | Mavenorg.springframework.ai:spring-ai-azure-cosmos-db-store | 已审查 | 2026-04-28 17:34 | 2026-05-07 03:54 |
| GHSA-26GG-9GV2-V27J CVE-2026-40980 | Spring AI Vulnerable to OOM by attacker-controlled PDF | 中危 | Mavenorg.springframework.ai:spring-ai-pdf-document-reader | 已审查 | 2026-04-28 17:34 | 2026-05-07 03:51 |
| GHSA-QC4J-QJQX-VR58 CVE-2026-40967 | Spring AI has a VectorStore FilterExpression Converter injection | 高危 | Mavenorg.springframework.ai:spring-ai-vector-store | 已审查 | 2026-04-28 17:34 | 2026-05-07 03:51 |
| GHSA-WQPV-C3PP-3M58 CVE-2026-42510 | OpenStack Ironic is Vulnerable to Inclusion of Functionality from Untrusted Control Sphere | 中危 | PyPIironic | 已审查 | 2026-04-28 14:30 | 2026-07-09 01:41 |
| GHSA-R2JQ-4H3X-RFJ6 CVE-2026-7223 | BigSweetPotatoStudio HyperChat has a Server-Side Request Forgery issue | 中危 | npm@dadigua/hyperchat | 已审查 | 2026-04-28 14:30 | 2026-05-07 03:44 |
| GHSA-VC5J-42HH-J3MR CVE-2026-7212 | notes-mcp has a Path Traversal issue | 中危 | PyPInotes-mcp | 已审查 | 2026-04-28 11:31 | 2026-05-07 03:17 |
| GHSA-4J28-22QP-RJCF CVE-2026-7206 | sqlite-mcp has an Injection issue | 中危 | PyPIsqlite-mcp | 已审查 | 2026-04-28 11:31 | 2026-05-07 03:18 |
| GHSA-WWPQ-F5C3-7HVX CVE-2026-40973 | Spring Boot accepts predictable temp directory without ownership verification | 高危 | Mavenorg.springframework.boot:spring-boot | 已审查 | 2026-04-28 08:31 | 2026-05-07 03:00 |
| GHSA-QP56-GP47-JWJ3 | Duplicate Advisory: OpenClaw: Feishu extension resolveUploadInput bypasses file-system sandbox and allows arbitrary file reads via upload_image 已撤回 | 中危 | npmopenclaw | 已审查 | 2026-04-28 08:31 | 2026-05-07 05:50 |
| GHSA-MQVW-JFMH-93QQ CVE-2026-40974 | Spring Boot's Cassandra SSL auto-configuration disables TLS hostname verification | 中危 | Mavenorg.springframework.boot:spring-boot-cassandra | 已审查 | 2026-04-28 08:31 | 2026-05-07 03:01 |
| GHSA-M4X9-HX6X-2C43 CVE-2026-40975 | Spring Boot's random value property source uses a weak PRNG unsuitable for secrets | 中危 | Mavenorg.springframework.boot:spring-boot-cassandra | 已审查 | 2026-04-28 08:31 | 2026-05-07 02:54 |
| GHSA-F5FM-9JMP-C88R | Duplicate Advisory: OpenClaw: Trailing-dot localhost CDP hosts could bypass remote loopback protections 已撤回 | 中危 | npmopenclaw | 已审查 | 2026-04-28 08:31 | 2026-05-07 03:03 |
| GHSA-8V8J-3HXP-93WR CVE-2026-40976 | Spring Boot's default security filter chain has no authorization rule with Actuator but without Health | 严重 | Mavenorg.springframework.boot:spring-boot | 已审查 | 2026-04-28 08:31 | 2026-05-07 02:54 |