检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-8PF2-VJ79-4WXG | Duplicate Advisory: OpenClaw: MSTeams thread history bypasses sender allowlist via Graph API 已撤回 | 中危 | npmopenclaw | 已审查 | 2026-04-28 08:31 | 2026-05-07 03:12 |
当前筛选结果 35,190 条 · 时间按北京时间显示
Duplicate Advisory: OpenClaw: Host exec environment sanitization misses package, registry, Docker, compiler, and TLS override variables 已撤回 |
| 高危 |
npmopenclaw |
| 已审查 |
| 2026-04-28 08:31 |
| 2026-05-07 03:11 |
| GHSA-5799-3XG7-RFRV | Duplicate Advisory: OpenClaw: SSH sandbox tar upload follows symlinks, enabling arbitrary file write on remote host 已撤回 | 高危 | npmopenclaw | 已审查 | 2026-04-28 08:31 | 2026-05-07 03:11 |
| GHSA-5368-6H4H-GR29 CVE-2026-40977 | Spring Boot's PID file write follows symlinks at predictable default path | 中危 | Mavenorg.springframework.boot:spring-boot-cassandra | 已审查 | 2026-04-28 08:31 | 2026-05-07 03:05 |
| GHSA-WFR3-HF93-QGG3 CVE-2026-7159 | mkdocs-mcp-plugin has a Path Traversal issue | 中危 | PyPImkdocs-mcp-plugin | 已审查 | 2026-04-28 08:31 | 2026-05-07 03:02 |
| GHSA-9VC8-QPPQ-WVXC CVE-2026-40971 | Spring Boot's RabbitMQ auto-configuration doesn't perform hostname verification when connecting to the RabbitMQ broker | 中危 | Mavenorg.springframework.boot:spring-boot-rabbitmq | 已审查 | 2026-04-28 08:31 | 2026-05-07 03:02 |
| GHSA-56V8-86GJ-66JP CVE-2026-40972 | Spring Boot DevTools remote secret comparison is vulnerable to timing attacks | 高危 | Mavenorg.springframework.boot:spring-boot-devtools | 已审查 | 2026-04-28 08:31 | 2026-05-07 03:02 |
| GHSA-H7XC-4MV8-59FJ CVE-2026-7158 | mcp-url-downloader has a Server-Side Request Forgery issue | 中危 | PyPImcp-url-downloader | 已审查 | 2026-04-28 05:31 | 2026-05-07 02:39 |
| GHSA-7GXW-Q9J5-MRJ4 CVE-2026-5362 | Pimcore has an authenticated Cross-site Scripting issue | 中危 | Packagistpimcore/pimcore | 已审查 | 2026-04-28 05:31 | 2026-05-07 02:40 |
| GHSA-VMH7-9C7H-2PGG CVE-2026-7150 | auto-favicon has a Server-Side Request Forgery issue | 低危 | PyPIauto-favicon | 已审查 | 2026-04-28 05:31 | 2026-05-07 02:29 |
| GHSA-Q882-JC55-6343 CVE-2026-7149 | kaggle-mcp has a Path Traversal issue | 中危 | PyPIkaggle-mcp | 已审查 | 2026-04-28 05:31 | 2026-05-07 02:36 |
| GHSA-C96X-RPM4-349P CVE-2026-40970 | Spring Boot's Elasticsearch auto-configuration doesn't perform hostname verification when connecting to the Elasticsearch server. | 中危 | Mavenorg.springframework.boot:spring-boot-elasticsearch | 已审查 | 2026-04-28 05:31 | 2026-05-07 02:38 |
| GHSA-C8G3-X47W-8Q7P | Duplicate Advisory: Pimcore admin users can trigger SQL Injection 已撤回 | 高危 | Packagistpimcore/pimcore | 已审查 | 2026-04-28 05:31 | 2026-05-29 04:47 |
| GHSA-X368-4G9H-FVV4 CVE-2026-7141 | vLLM makes Use of Uninitialized Resource | 低危 | PyPIvllm | 已审查 | 2026-04-28 02:32 | 2026-05-07 01:31 |
| GHSA-W65C-CMXJ-QRHM CVE-2026-7142 | Wooey has an Incorrect Privilege Assignment issue | 低危 | PyPIwooey | 已审查 | 2026-04-28 02:32 | 2026-05-07 01:26 |
| GHSA-JP4C-XJXW-MGF9 CVE-2026-6357 | pip Vulnerable to Inclusion of Functionality from Untrusted Control Sphere | 中危 | PyPIpip | 已审查 | 2026-04-27 23:30 | 2026-05-06 06:05 |
| GHSA-J2Q8-XX3Q-8FQH CVE-2026-41081 | Apache Storm's Improper Handling of TLS Client Authentication Failure Leads to Anonymous Principal Assignment | 中危 | Mavenorg.apache.storm:storm-client | 已审查 | 2026-04-27 23:30 | 2026-05-06 06:06 |
| GHSA-82FM-WPC2-5PMP CVE-2026-40557 | Apache Storm Prometheus Reporter vulnerable to Improper Certificate Validation via Global SSL Context Downgrade | 中危 | Mavenorg.apache.storm:storm-metrics-prometheus | 已审查 | 2026-04-27 23:30 | 2026-05-06 06:05 |
| GHSA-F2WH-GRMH-R6JM CVE-2026-41409 | Apache MINA Vulnerable to Deserialization of Untrusted Data (CVE-2024-52046 Incomplete Fix) | 严重 | Mavenorg.apache.mina:mina-core | 已审查 | 2026-04-27 20:30 | 2026-05-06 05:38 |
| GHSA-695C-X5GC-94GJ CVE-2026-33453 | Apache camel-coap allows header injection that can lead to remote code execution | 严重 | Mavenorg.apache.camel:camel-coap | 已审查 | 2026-04-27 20:30 | 2026-05-05 22:45 |
| GHSA-5RC6-9QFP-8VWG CVE-2026-27172 | Apache Camel-Consul component vulnerable to Deserialization of Untrusted Data | 中危 | Mavenorg.apache.camel:camel-consul | 已审查 | 2026-04-27 20:30 | 2026-05-06 05:43 |
| GHSA-4XWX-HVV7-7PRJ CVE-2026-40858 | Apache Camel-Infinispan Component Vulnerable to Deserialization of Untrusted Data | 高危 | Mavenorg.apache.camel:camel-infinispan | 已审查 | 2026-04-27 20:30 | 2026-05-06 05:44 |
| GHSA-2VQF-X7G4-7C2G CVE-2026-33454 | Apache Camel's Camel-Mail component is vulnerable to Camel message header injection | 严重 | Mavenorg.apache.camel:camel-mail | 已审查 | 2026-04-27 20:30 | 2026-05-06 05:43 |
| GHSA-27VM-5VPJ-RP5G CVE-2026-40022 | Apache Camel Vulnerable to Authentication Bypass Using an Alternate Path or Channel | 高危 | Mavenorg.apache.camel:camel-platform-http-main | 已审查 | 2026-04-27 20:30 | 2026-05-06 05:38 |
| GHSA-VPR3-2659-RW55 CVE-2026-40473 | Camel-MINA Vulnerable to Deserialization of Untrusted Data | 高危 | Mavenorg.apache.camel:camel-mina | 已审查 | 2026-04-27 17:34 | 2026-05-06 05:19 |