检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-X4MJ-7F9G-29H4 CVE-2026-41246 | Contour has Lua code injection via Cookie Path Rewrite Policy | 高危 | Gogithub.com/projectcontour/contour | 已审查 | 2026-04-24 23:19 | 2026-07-02 06:20 |
| GHSA-W3W2-MPP5-92GM CVE-2026-40466 | Apache ActiveMQ Vulnerable to Improper Input Validation and Code Injection |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 高危 |
Mavenorg.apache.activemq:activemq-all+2 |
| 已审查 |
| 2026-04-24 20:30 |
| 2026-05-05 08:09 |
| GHSA-MR6M-XJ7V-3CV3 CVE-2026-41044 | Apache ActiveMQ Vulnerable to Code Injection | 高危 | Mavenorg.apache.activemq:activemq-all+2 | 已审查 | 2026-04-24 20:30 | 2026-05-05 08:13 |
| GHSA-F786-9C63-8XR8 CVE-2025-62233 | Apache DolphinScheduler RPC module has a Deserialization of Untrusted Data vulnerability | 中危 | Mavenorg.apache.dolphinscheduler:dolphinscheduler+1 | 已审查 | 2026-04-24 20:30 | 2026-05-05 08:06 |
| GHSA-72MV-WWVM-VGP5 CVE-2026-23902 | Apache DolphinScheduler has an Incorrect Authorization Vulnerability | 高危 | Mavenorg.apache.dolphinscheduler:dolphinscheduler | 已审查 | 2026-04-24 20:30 | 2026-05-05 08:16 |
| GHSA-2JP3-2923-9H52 CVE-2026-41043 | Apache ActiveMQ Vulnerable to Cross-site Scripting | 中危 | Mavenorg.apache.activemq:activemq-all+2 | 已审查 | 2026-04-24 20:30 | 2026-05-05 08:12 |
| GHSA-P4R4-XVRQ-GVMC CVE-2026-21728 | Grafana Tempo has an Uncontrolled Resource Consumption issue | 高危 | Gogithub.com/grafana/tempo | 已审查 | 2026-04-24 17:30 | 2026-05-05 08:24 |
| GHSA-WWC3-C577-533M | Duplicate Advisory: OpenClaw: Gateway `device.token.rotate` does not terminate active WebSocket sessions after credential rotation 已撤回 | 低危 | npmopenclaw | 已审查 | 2026-04-24 08:31 | 2026-05-05 05:59 |
| GHSA-M958-864J-XQ5W | Duplicate Advisory: OpenClaw: Telnyx Webhook Replay Detection Bypass via Base64 Signature Re-encoding 已撤回 | 中危 | npmopenclaw | 已审查 | 2026-04-24 08:31 | 2026-05-05 05:59 |
| GHSA-M563-373Q-885C | Duplicate Advisory: OpenClaw: OpenShell `mirror` mode can convert untrusted sandbox files into explicitly enabled workspace hooks and execute them on the host during gateway startup 已撤回 | 中危 | npmopenclaw | 已审查 | 2026-04-24 08:31 | 2026-05-05 06:00 |
| GHSA-7HRG-5W46-5R2X | Duplicate Advisory: OpenClaw: Slack thread context could include messages from non-allowlisted senders 已撤回 | 低危 | npmopenclaw | 已审查 | 2026-04-24 08:31 | 2026-05-05 00:51 |
| GHSA-6477-WVJJ-47V6 | Duplicate Advisory: OpenClaw: Zalo replay dedupe keys could suppress messages across chats or senders 已撤回 | 中危 | npmopenclaw | 已审查 | 2026-04-24 08:31 | 2026-05-08 00:44 |
| GHSA-394X-274P-MQC6 | Duplicate Advisory: OpenClaw: Gateway operator.write Can Reach Admin-Class Telegram Config and Cron Persistence via send 已撤回 | 高危 | npmopenclaw | 已审查 | 2026-04-24 08:31 | 2026-05-07 06:41 |
| GHSA-WCM7-94WG-H74H | Duplicate Advisory: OpenClaw host-env blocklist missing `GIT_TEMPLATE_DIR` and `AWS_CONFIG_FILE` allows code execution via env override 已撤回 | 中危 | npmopenclaw | 已审查 | 2026-04-24 08:31 | 2026-05-05 05:54 |
| GHSA-W9F5-8Q83-QWPX | Duplicate Advisory: OpenClaw: Fake DeviceToken Bypasses Shared Auth Rate Limiting 已撤回 | 中危 | npmopenclaw | 已审查 | 2026-04-24 08:31 | 2026-05-05 06:00 |
| GHSA-V3C2-39FM-JQ4H | Duplicate Advisory: OpenClaw: Gateway `operator.write` can reach admin-only persisted `verboseLevel` via `chat.send` `/verbose` 已撤回 | 中危 | npmopenclaw | 已审查 | 2026-04-24 08:31 | 2026-05-07 07:04 |
| GHSA-R7P2-R9G4-4XPH | Duplicate Advisory: OpenClaw: Gateway hello snapshots exposed host config and state paths to non-admin clients 已撤回 | 中危 | npmopenclaw | 已审查 | 2026-04-24 08:31 | 2026-05-05 05:55 |
| GHSA-QGP3-3RJ7-QQQ4 | Duplicate Advisory: OpenClaw: Discord Slash Commands Bypass Group DM Channel Allowlist 已撤回 | 低危 | npmopenclaw | 已审查 | 2026-04-24 08:31 | 2026-05-05 05:58 |
| GHSA-PR66-WHQJ-RQ5P | Duplicate Advisory: OpenClaw: Discord Component Interaction Misclassifies Group DM as Direct Message 已撤回 | 低危 | npmopenclaw | 已审查 | 2026-04-24 08:31 | 2026-05-05 05:48 |
| GHSA-MF69-R24Q-GHHR | Duplicate Advisory: OpenClaw: Pairing pending-request caps were enforced per channel instead of per account 已撤回 | 中危 | npmopenclaw | 已审查 | 2026-04-24 08:31 | 2026-05-05 05:59 |
| GHSA-JX3C-247H-CXWP | Duplicate Advisory: OpenClaw: Workspace `.env` can override the bundled hooks root and load attacker hook code 已撤回 | 高危 | npmopenclaw | 已审查 | 2026-04-24 08:31 | 2026-05-05 05:54 |
| GHSA-GV2F-Q4WP-FVH5 | Duplicate Advisory: OpenClaw: CLI Remote Onboarding Persists Unauthenticated Discovery Endpoint and Exfiltrates Gateway Credentials 已撤回 | 高危 | npmopenclaw | 已审查 | 2026-04-24 08:31 | 2026-05-07 07:04 |
| GHSA-FJM8-MGC9-MF65 | Duplicate Advisory: OpenClaw Has a Gateway Control Interface Information Disclosure Vulnerability 已撤回 | 中危 | npmopenclaw | 已审查 | 2026-04-24 08:31 | 2026-05-05 05:52 |
| GHSA-CW28-63X4-37C3 | Duplicate Advisory: OpenClaw: Voice-call Plivo replay mutates in-process callback origin before replay rejection 已撤回 | 中危 | npmopenclaw | 已审查 | 2026-04-24 08:31 | 2026-05-05 05:55 |
| GHSA-7VQ9-42CC-33J4 | Duplicate Advisory: OpenClaw: Device-Paired Node Skips Node Scope Gate → Host RCE.md 已撤回 | 高危 | npmopenclaw | 已审查 | 2026-04-24 08:31 | 2026-05-05 05:59 |