检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-XHJ4-G6W8-2XJW | go-zserio has Unbounded Memory Allocation for All Platforms | 严重 | Gogithub.com/woven-planet/go-zserio | 已审查 | 2026-04-25 00:25 | 2026-04-25 00:25 |
| GHSA-CWQ5-8PVQ-J65J CVE-2026-33524 | Zserio Runtime: Integer Overflow in BitStreamReader and Unbounded Memory Allocation in Deserialization |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 高危 |
Mavenio.github.ndsev:zserio-runtime |
| 已审查 |
| 2026-04-25 00:25 |
| 2026-05-05 04:08 |
| GHSA-82J2-J2CH-GFR8 | rustls-webpki: Denial of service via panic on malformed CRL BIT STRING | 高危 | crates.iorustls-webpki | 已审查 | 2026-04-25 00:20 | 2026-04-25 00:20 |
| GHSA-4F9J-VR4P-642R CVE-2026-42239 | Budibase auth session cookies are set with httpOnly:false — any XSS can lead to full account takeover | 高危 | npm@budibase/backend-core | 已审查 | 2026-04-25 00:18 | 2026-05-11 21:29 |
| GHSA-JV9X-W4GM-HWCM CVE-2026-41498 | Kimai has Missing Object-Level Authorization in the Team API | 低危 | Packagistkimai/kimai | 已审查 | 2026-04-25 00:17 | 2026-05-12 21:27 |
| GHSA-R75F-5X8P-QVMC CVE-2026-42208 | LiteLLM has SQL Injection in Proxy API key verification | 严重 | PyPIlitellm | 已审查 | 2026-04-25 00:17 | 2026-05-12 21:27 |
| GHSA-VVF7-6RMR-M29Q CVE-2026-41492 | Dgraph: Unauthenticated Admin Token Disclosure Leading to Authentication Bypass via /debug/vars | 严重 | Gogithub.com/dgraph-io/dgraph+2 | 已审查 | 2026-04-25 00:15 | 2026-05-05 04:08 |
| GHSA-MW35-8RX3-XF9R CVE-2026-41486 | Ray: Remote Code Execution via Parquet Arrow Extension Type Deserialization | 高危 | PyPIray | 已审查 | 2026-04-25 00:15 | 2026-05-13 21:37 |
| GHSA-QC5P-3MG5-9FH8 CVE-2026-42205 | Avo: Broken Access Control Through Unauthorized Execution of Arbitrary Action Classes Across Resources | 高危 | RubyGemsavo | 已审查 | 2026-04-25 00:11 | 2026-06-09 07:17 |
| GHSA-XQMJ-J6MV-4862 CVE-2026-42203 | LiteLLM: Server-Side Template Injection in /prompts/test endpoint | 高危 | PyPIlitellm | 已审查 | 2026-04-25 00:02 | 2026-05-12 21:27 |
| GHSA-F5C8-M5VW-RMGQ CVE-2026-42202 | nova-toggle-5: Improper authorization on toggle endpoint allowed non-Nova users to modify boolean fields | 中危 | Packagistalmirhodzic/nova-toggle-5 | 已审查 | 2026-04-25 00:00 | 2026-05-13 21:37 |
| GHSA-V638-38FC-RHFV CVE-2026-6550 | AWS Encryption SDK for Python: Key commitment policy bypass via shared key cache | 中危 | PyPIaws-encryption-sdk | 已审查 | 2026-04-24 23:59 | 2026-04-24 23:59 |
| GHSA-38C5-483C-4QQP CVE-2026-42199 | Grid: Integer Overflow in Grid::expand_rows Leads to Safe-API Undefined Behavior | 中危 | crates.iogrid | 已审查 | 2026-04-24 23:57 | 2026-05-13 21:37 |
| GHSA-XFF3-5C9P-2MR4 CVE-2026-41432 | New API: Stripe Webhook Signature Bypass via Empty Secret Enables Unlimited Quota Fraud | 高危 | Gogithub.com/QuantumNous/new-api | 已审查 | 2026-04-24 23:43 | 2026-05-13 21:37 |
| GHSA-X92X-PX7W-4GX4 CVE-2026-41328 | Dgraph: Pre-Auth Full Database Exfiltration via DQL Injection in NQuad Lang Field | 严重 | Gogithub.com/dgraph-io/dgraph+2 | 已审查 | 2026-04-24 23:41 | 2026-07-08 08:34 |
| GHSA-MRXX-39G5-PH77 CVE-2026-41327 | Dgraph: Pre-Auth Full Database Exfiltration via DQL Injection in Upsert Condition Field | 严重 | Gogithub.com/dgraph-io/dgraph+2 | 已审查 | 2026-04-24 23:41 | 2026-05-05 04:08 |
| GHSA-F5V4-2WR6-HQMG CVE-2026-42189 | russh has pre-auth DoS via unbounded allocation in its keyboard-interactive auth handler | 高危 | crates.iorussh | 已审查 | 2026-04-24 23:39 | 2026-05-13 21:34 |
| GHSA-M2M6-CFF5-3W7C CVE-2026-42190 | RedwoodSDK has Same-site CSRF through lack of origin validation in its server actions | 中危 | npmrwsdk | 已审查 | 2026-04-24 23:36 | 2026-05-13 21:34 |
| GHSA-Q339-8RMV-2MHV CVE-2026-41316 | ERB has an @_init deserialization guard bypass via def_module / def_method / def_class | 高危 | RubyGemserb | 已审查 | 2026-04-24 23:36 | 2026-06-09 18:35 |
| GHSA-4RC3-7J7W-M548 CVE-2026-41311 | liquidjs has a Denial of Service via circular block reference in layout | 高危 | npmliquidjs | 已审查 | 2026-04-24 23:34 | 2026-05-13 21:38 |
| GHSA-W7RC-Q6CM-F5GM CVE-2026-40690 | Apache Airflow's asset dependency graph did not restrict nodes by the viewer's DAG read permissions | 中危 | PyPIapache-airflow | 已审查 | 2026-04-24 23:32 | 2026-05-06 02:12 |
| GHSA-P3V3-229H-MC63 CVE-2026-38743 | Apache Airflow's authenticated /ui/dags endpoint did not enforce per-DAG access control on embedded Human-in-the-Loop (HITL) and TaskInstance record | 中危 | PyPIapache-airflow | 已审查 | 2026-04-24 23:32 | 2026-05-06 02:11 |
| GHSA-QX2V-QP2M-JG93 CVE-2026-41305 | PostCSS has XSS via Unescaped </style> in its CSS Stringify Output | 中危 | npmpostcss | 已审查 | 2026-04-24 23:31 | 2026-04-24 23:31 |
| GHSA-3JVJ-V6W2-H948 CVE-2026-42180 | Lemmy has SSRF in /api/v3/post via Webmention dispatch | 中危 | crates.iolemmy_api_common | 已审查 | 2026-04-24 23:22 | 2026-05-13 21:34 |
| GHSA-H6HF-9846-XWRQ CVE-2026-42181 | Lemmy has SSRF and internal image disclosure in post link metadata via unvalidated og:image | 中危 | crates.iolemmy_api_common | 已审查 | 2026-04-24 23:21 | 2026-05-13 21:34 |