检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-2XP4-QHR4-XQM2 | Duplicate Advisory: OpenClaw: HTTP operator endpoints lack browser-origin validation in trusted-proxy mode 已撤回 | 低危 | npmopenclaw | 已审查 | 2026-04-24 08:31 | 2026-05-05 05:55 |
当前筛选结果 35,190 条 · 时间按北京时间显示
Duplicate Advisory: OpenClaw: LINE webhook handler lacks shared pre-auth concurrency budget before signature verification 已撤回 |
| 中危 |
npmopenclaw |
| 已审查 |
| 2026-04-24 08:31 |
| 2026-05-05 05:55 |
| GHSA-Q2PW-XX38-P64J CVE-2026-29051 | melange has Path Traversal via .PKGINFO in --persist-lint-results | 低危 | Gochainguard.dev/melange | 已审查 | 2026-04-24 05:54 | 2026-04-28 00:35 |
| GHSA-98F2-W9H9-7FP9 CVE-2026-29050 | melange has Path Traversal When Resolving External Pipelines via Unvalidated pipeline[].uses | 中危 | Gochainguard.dev/melange | 已审查 | 2026-04-24 05:53 | 2026-04-28 00:34 |
| GHSA-88GM-J2WX-58H6 CVE-2026-41321 | Cloudflare has SSRF via redirect following through its image-binding-transform endpoint (incomplete fix for GHSA-qpr4) | 低危 | npm@astrojs/cloudflare | 已审查 | 2026-04-24 05:52 | 2026-04-28 00:42 |
| GHSA-8H25-Q488-4HXW CVE-2026-41900 | OpenLearnX has Critical Remote Code Execution Through Python Sandbox Escape via Code Execution Environment | 高危 | npmopenlearnx | 已审查 | 2026-04-24 05:46 | 2026-05-11 21:49 |
| GHSA-28XM-PRXC-5866 CVE-2026-41173 | OpenTelemetry.Sampler.AWS & OpenTelemetry.Resources.AWS have unbounded HTTP response body reads | 中危 | NuGetOpenTelemetry.Resources.AWS+1 | 已审查 | 2026-04-24 05:44 | 2026-04-24 05:44 |
| GHSA-G94R-2VXG-569J CVE-2026-40894 | OpenTelemetry dotnet: Excessive memory allocation when parsing OpenTelemetry propagation headers | 中危 | NuGetOpenTelemetry.Api+1 | 已审查 | 2026-04-24 05:43 | 2026-04-24 05:43 |
| GHSA-MR8R-92FQ-PJ8P CVE-2026-40891 | OpenTelemetry dotnet: Unbounded `grpc-status-details-bin` parsing in OTLP/gRPC retry handling | 中危 | NuGetOpenTelemetry.Exporter.OpenTelemetryProtocol | 已审查 | 2026-04-24 05:40 | 2026-04-24 05:40 |
| GHSA-5JV8-H7QH-RF5P CVE-2026-40886 | Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows Controller | 高危 | Gogithub.com/argoproj/argo-workflows/v3+1 | 已审查 | 2026-04-24 05:39 | 2026-04-24 05:39 |
| GHSA-Q834-8QMM-V933 CVE-2026-40182 | OpenTelemetry dotnet: OTLP exporter reads unbounded HTTP response bodies | 中危 | NuGetOpenTelemetry.Exporter.OpenTelemetryProtocol | 已审查 | 2026-04-24 05:26 | 2026-04-24 05:26 |
| GHSA-W942-J9R6-HR6R CVE-2026-40099 | Kirby's page creation API bypasses the changeStatus permission check via unfiltered isDraft parameter | 中危 | Packagistgetkirby/cms | 已审查 | 2026-04-24 05:24 | 2026-04-28 00:35 |
| GHSA-M8MH-X359-VM8M CVE-2026-39973 | Apktool: Path Traversal to Arbitrary File Write | 高危 | Mavenorg.apktool:apktool-lib | 已审查 | 2026-04-24 05:24 | 2026-04-24 05:24 |
| GHSA-JCJW-58RV-C452 CVE-2026-34587 | Kirby has Server-Side Template Injection (SSTI) via double template resolution in option rendering | 高危 | Packagistgetkirby/cms | 已审查 | 2026-04-24 05:24 | 2026-05-05 23:43 |
| GHSA-PRP4-2F49-FCGP CVE-2026-33318 | Actual has Privilege Escalation via 'change-password' Endpoint on OpenID-Migrated Servers | 高危 | npm@actual-app/sync-server | 已审查 | 2026-04-24 05:23 | 2026-04-28 00:35 |
| GHSA-PJCQ-XVWQ-HHPJ CVE-2026-32952 | go-ntlmssp NTLM challenges can panic on malformed payloads | 中危 | Gogithub.com/Azure/go-ntlmssp | 已审查 | 2026-04-24 05:21 | 2026-04-28 00:35 |
| GHSA-9WFJ-C55W-J9QR CVE-2026-32870 | Kirby has XML injection in its XML creator toolkit | 中危 | Packagistgetkirby/cms | 已审查 | 2026-04-24 05:21 | 2026-04-28 00:35 |
| GHSA-C2JG-5CP7-6WC7 CVE-2025-62373 | Pipecat: Remote Code Execution by Pickle Deserialization Through LivekitFrameSerializer | 严重 | PyPIpipecat-ai | 已审查 | 2026-04-24 05:15 | 2026-04-24 05:15 |
| GHSA-QGX9-6PX9-7P75 | Duplicate Advisory: OpenClaw: Assistant media route missed scope enforcement for trusted-proxy authorization 已撤回 | 低危 | npmopenclaw | 已审查 | 2026-04-24 02:33 | 2026-05-05 05:04 |
| GHSA-PQHX-W72W-M393 CVE-2026-39087 | ntfy.sh allows a remote attacker to execute arbitrary code via the parseActions function | 严重 | Goheckel.io/ntfy/v2 | 已审查 | 2026-04-24 02:33 | 2026-05-09 00:32 |
| GHSA-9MV3-2CWR-P262 CVE-2026-40372 | Microsoft Security Advisory CVE-2026-40372 – ASP.NET Core Elevation of Privilege | 严重 | NuGetMicrosoft.AspNetCore.DataProtection | 已审查 | 2026-04-23 22:55 | 2026-04-25 03:59 |
| GHSA-C57F-MM3J-27Q9 CVE-2026-41322 | Astro: Cache Poisoning due to incorrect error handling when if-match header is malformed | 中危 | npm@astrojs/node | 已审查 | 2026-04-23 22:36 | 2026-04-28 00:42 |
| GHSA-PFM2-2MHG-8WPX CVE-2026-41495 | n8n-MCP Logs Sensitive Request Data on Unauthorized /mcp Requests | 中危 | npmn8n-mcp | 已审查 | 2026-04-23 22:31 | 2026-05-13 21:33 |
| GHSA-RHF7-WVW3-VJVM CVE-2026-42091 | goshs has Cross-Origin Arbitrary File Write via Missing CSRF on PUT and Wildcard CORS | 中危 | Gogithub.com/patrickhener/goshs+1 | 已审查 | 2026-04-23 22:28 | 2026-05-05 04:11 |
| GHSA-2WVH-87G2-89HR | OpenC3 COSMOS: Permissions Bypass Provides User Access to Unassigned Administrative Actions via Script Runner Tool | 严重 | RubyGemsopenc3 | 已审查 | 2026-04-23 22:17 | 2026-04-23 22:17 |