检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-3Q34-RX83-R6MQ CVE-2026-42274 | Heimdall has an authorization bypass via path normalization mismatch | 高危 | Gogithub.com/dadrus/heimdall | 已审查 | 2026-04-26 07:30 | 2026-05-12 21:29 |
| GHSA-72H4-MXFC-JX37 CVE-2026-42273 | Heimdall: Case-sensitive host matching may lead to policy bypass |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 高危 |
Gogithub.com/dadrus/heimdall |
| 已审查 |
| 2026-04-26 07:30 |
| 2026-05-12 21:28 |
| GHSA-43JV-5J4X-QV67 CVE-2026-42272 | Heimdall: Case-sensitive handling of URL-encoded slashes may lead to inconsistent path interpretation | 高危 | Gogithub.com/dadrus/heimdall | 已审查 | 2026-04-26 07:29 | 2026-05-12 21:28 |
| GHSA-V4P8-MG3P-G94G CVE-2026-42271 | LiteLLM: Authenticated command execution via MCP stdio test endpoints | 高危 | PyPIlitellm | 已审查 | 2026-04-26 07:27 | 2026-06-09 21:07 |
| GHSA-JJ45-XVQ5-RHH9 CVE-2026-6993 | Kratos has a Confused Deputy issue | 中危 | Gogithub.com/go-kratos/kratos/v2 | 已审查 | 2026-04-26 05:30 | 2026-05-06 04:24 |
| GHSA-H3RR-9WQJ-V3C6 CVE-2026-6984 | AstrBot has Incomplete Filtering of Special Elements | 低危 | PyPIAstrBot | 已审查 | 2026-04-26 02:32 | 2026-05-06 04:22 |
| GHSA-6R3X-H84W-FHXX CVE-2026-6987 | PicoClaw has an Injection issue in its Web Launcher Management Plane component | 中危 | Gogithub.com/sipeed/picoclaw | 已审查 | 2026-04-26 02:32 | 2026-05-08 00:33 |
| GHSA-FM5R-CJ7V-RJ2C CVE-2026-6982 | ShowDoc has an Injection vulnerability | 中危 | Packagistshowdoc/showdoc | 已审查 | 2026-04-25 23:33 | 2026-05-06 04:21 |
| GHSA-HFFM-XVC3-VPRC CVE-2026-6951 | simple-git is vulnerable to Remote Code Execution | 高危 | npmsimple-git | 已审查 | 2026-04-25 14:30 | 2026-05-06 04:12 |
| GHSA-8X35-HPH8-37HQ CVE-2026-41501 | electerm has Command Injection via runLinux funtion | 严重 | npmelecterm | 已审查 | 2026-04-25 04:45 | 2026-05-12 21:27 |
| GHSA-GX2M-MCC2-R4P3 CVE-2026-42150 | wlc: print_html outputs API data without HTML escaping | 中危 | PyPIwlc | 已审查 | 2026-04-25 04:43 | 2026-05-12 21:27 |
| GHSA-H829-5CG7-6HFF | gitverify has improper tag signature verification | 中危 | Gogithub.com/supply-chain-tools/gitverify | 已审查 | 2026-04-25 04:42 | 2026-04-25 04:42 |
| GHSA-39H7-PWV7-RC3X | Excalidraw vulnerable to XSS via Mermaid sequence diagram labels (KaTeX rendering) | 中危 | npm@excalidraw/excalidraw+1 | 已审查 | 2026-04-25 04:41 | 2026-04-25 04:41 |
| GHSA-FPJQ-C37H-CQCV CVE-2026-41485 | Kyverno Controller Denial of Service via forEach Mutation Panic | 高危 | Gogithub.com/kyverno/kyverno | 已审查 | 2026-04-25 04:40 | 2026-04-25 04:40 |
| GHSA-6GQR-MX34-WH8R CVE-2026-41325 | Kirby is vulnerable to authorization bypass during page, file and user creation via blueprint injection | 高危 | Packagistgetkirby/cms | 已审查 | 2026-04-25 04:39 | 2026-04-25 04:39 |
| GHSA-6X2Q-H3CR-8J2H CVE-2026-41263 | Traefik: A timing side-channel vulnerability allows for valid username enumeration via BasicAuth middleware | 中危 | Gogithub.com/traefik/traefik+2 | 已审查 | 2026-04-25 04:36 | 2026-05-07 05:24 |
| GHSA-XHJW-95FP-8VGQ CVE-2026-41174 | Traefik Kubernetes CRD allows unauthorized cross-namespace middleware binding | 中危 | Gogithub.com/traefik/traefik+2 | 已审查 | 2026-04-25 04:12 | 2026-05-07 05:24 |
| GHSA-WPQR-6V78-JR5G | Gemini CLI: Remote Code Execution via workspace trust and tool allowlisting bypasses | 严重 | GitHub Actions@google/gemini-cli+1 | 已审查 | 2026-04-25 03:30 | 2026-04-25 03:30 |
| GHSA-RRJR-V56M-WW88 CVE-2026-42241 | ParquetSharp: Possible Stack Overflow When Reading a ParquetFile with Large Decimal Type Width | 中危 | NuGetParquetSharp | 已审查 | 2026-04-25 00:39 | 2026-05-11 21:29 |
| GHSA-XVV6-P4WF-MVX7 CVE-2026-6553 | TYPO3 CMS Stores Cleartext Password in User Settings Module | 高危 | Packagisttypo3/cms-backend | 已审查 | 2026-04-25 00:39 | 2026-05-08 23:20 |
| GHSA-6JWX-7VP4-9847 CVE-2026-40912 | Traefik has an StripPrefixRegex Middleware Authorization Bypass via Path/RawPath Desync | 高危 | Gogithub.com/traefik/traefik+2 | 已审查 | 2026-04-25 00:37 | 2026-07-21 21:44 |
| GHSA-RP7V-4384-HFRP | k8sGPT has Prompt Injection through its k8sGPT-Operator | 高危 | Gogithub.com/k8sgpt-ai/k8sgpt | 已审查 | 2026-04-25 00:37 | 2026-04-25 00:37 |
| GHSA-Q5HJ-MXQH-VV77 CVE-2026-40068 | Claude Code: Trust Dialog Bypass via Git Worktree Spoofing Allows Arbitrary Code Execution | 高危 | npm@anthropic-ai/claude-code | 已审查 | 2026-04-25 00:34 | 2026-05-08 23:31 |
| GHSA-5M6W-WVH7-57VM CVE-2026-39858 | Traefik: Pre-authentication decision bypass due to forwarded alias spoofing | 高危 | Gogithub.com/traefik/traefik+2 | 已审查 | 2026-04-25 00:32 | 2026-05-07 05:24 |
| GHSA-6384-M2MW-RF54 CVE-2026-35051 | Traefik's ForwardAuth trustForwardHeader=false allows spoofed X-Forwarded-Prefix to bypass authentication | 高危 | Gogithub.com/traefik/traefik+2 | 已审查 | 2026-04-25 00:31 | 2026-05-07 05:24 |