检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-W26R-FWG8-RCP3 CVE-2026-63641 | MagicMirror Socket.IO module namespaces bypass configured IP whitelist and allow unauthenticated server-side actions | 低危 | npmmagicmirror | 已审查 | 2026-08-19 01:26 | 2026-08-19 01:26 |
| GHSA-5XWG-CFVJ-GFF5 CVE-2026-61634 | RabbitMQ Java client accepts broker frames larger than the negotiated AMQP frame_max |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 低危 |
Mavencom.rabbitmq:amqp-client |
| 已审查 |
| 2026-08-19 00:36 |
| 2026-08-19 00:36 |
| GHSA-5M9F-RPHJ-C435 CVE-2026-63336 | RabbitMQ Java client: TrustEverythingTrustManager used by default in useSslProtocol() enables MITM | 中危 | Mavencom.rabbitmq:amqp-client | 已审查 | 2026-08-19 00:32 | 2026-08-19 00:32 |
| GHSA-QX7J-JV8M-FPPR CVE-2026-63335 | RabbitMQ Java client malformed body frame triggers raw command assembler exception | 中危 | Mavencom.rabbitmq:amqp-client | 已审查 | 2026-08-19 00:32 | 2026-08-19 00:32 |
| GHSA-6G32-PXV4-2WFJ CVE-2026-63337 | RabbitMQ Java client: Unvalidated Class.forName in JSON-RPC ProcedureDescription enables arbitrary class loading | 高危 | Mavencom.rabbitmq:amqp-client | 已审查 | 2026-08-19 00:32 | 2026-08-19 00:32 |
| GHSA-68MJ-5WR7-6FGG CVE-2026-69219 | RabbitMQ Java client ValueReader: Oversized LongString/bytes length triggers OOM via unchecked allocation | 高危 | Mavencom.rabbitmq:amqp-client | 已审查 | 2026-08-19 00:32 | 2026-08-19 00:32 |
| GHSA-93J5-89VC-PPH4 CVE-2026-69220 | RabbitMQ Java client ValueReader: Unbounded recursive table/array nesting causes StackOverflowError DoS | 高危 | Mavencom.rabbitmq:amqp-client | 已审查 | 2026-08-19 00:32 | 2026-08-19 00:32 |
| GHSA-8RC5-4FR6-64PW CVE-2026-63328 | Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write | 中危 | Gogithub.com/aquasecurity/trivy | 已审查 | 2026-08-19 00:32 | 2026-08-19 00:32 |
| GHSA-34PM-923J-7WF8 CVE-2026-55839 | Kestra vulnerable to stored XSS via custom Markdown [[link]] attribute injection | 高危 | Mavenio.kestra:kestra | 已审查 | 2026-08-19 00:31 | 2026-08-19 00:31 |
| GHSA-2MF3-MR2R-R4VF | @rhinostone/swig: arbitrary local file read via include/extends path traversal | 高危 | npm@rhinostone/swig+4 | 已审查 | 2026-08-19 00:31 | 2026-08-19 00:31 |
| GHSA-X5PQ-M9P8-F4VX CVE-2026-70657 | Copyparty vulnerable to file/dirkey confusion | 中危 | PyPIcopyparty | 已审查 | 2026-08-18 23:02 | 2026-08-18 23:02 |
| GHSA-GQCH-G4W5-7QCW CVE-2026-69148 | MLflow: CreateModelVersion source validation does not check READ permission on referenced run_id | 高危 | npmmlflow | 已审查 | 2026-08-18 05:59 | 2026-08-18 05:59 |
| GHSA-3P64-6GVH-82V5 CVE-2026-69146 | MLflow: LogInputs endpoint bypasses per-run UPDATE authorization in basic-auth | 中危 | npmmlflow | 已审查 | 2026-08-18 05:59 | 2026-08-18 05:59 |
| GHSA-7GWP-5PFP-969J CVE-2026-64849 | MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding) | 严重 | PyPImlflow | 已审查 | 2026-08-18 05:58 | 2026-08-18 05:58 |
| GHSA-8G4W-4FFG-8VGX CVE-2026-56677 | 9Router: Authenticated Server-Side Request Forgery (SSRF) via OIDC Provider Test Endpoint | 高危 | npm9router | 已审查 | 2026-08-18 05:58 | 2026-08-18 05:58 |
| GHSA-P28P-J94Q-PG32 CVE-2026-54148 | http4k: `DigestAuthProvider.verify` did not bind to request URI | 高危 | Mavenorg.http4k:http4k-security-digest | 已审查 | 2026-08-18 05:57 | 2026-08-18 05:57 |
| GHSA-VXXM-WWQH-MH47 CVE-2026-54147 | http4k: `DigestAuthProvider.verify` ignored configured algorithm and did not bind to request URI | 中危 | Mavenorg.http4k:http4k-security-digest | 已审查 | 2026-08-18 05:56 | 2026-08-18 05:57 |
| GHSA-8QF9-62X2-82PP CVE-2026-53766 | chrome-devtools-mcp: validatePath() does not canonicalize symlinks before enforcing roots | 中危 | npmchrome-devtools-mcp | 已审查 | 2026-08-18 05:56 | 2026-08-18 05:56 |
| GHSA-MPWR-8VM7-H73F | package pkcs12: Authentication bypass in Decode functions | 中危 | Gosoftware.sslmate.com/src/go-pkcs12 | 已审查 | 2026-08-18 05:56 | 2026-08-18 05:56 |
| GHSA-GC95-3VW8-VG43 CVE-2026-53752 | docx4j: Stack Overflow via Cyclic `w:basedOn` Style Chain leads to Denial of Service | 高危 | Mavenorg.docx4j:docx4j-core | 已审查 | 2026-08-18 05:55 | 2026-08-18 05:55 |
| GHSA-G4W2-6H2R-3M3W CVE-2026-53659 | http4k: Unbounded gzip decompression in `ServerFilters.GZip` / `RequestFilters.GunZip` allowed memory-exhaustion DoS | 高危 | Mavenorg.http4k:http4k-core | 已审查 | 2026-08-18 05:52 | 2026-08-18 05:58 |
| GHSA-J659-8XH6-5PQ5 | atomic-agents-stack: Parallel helper/delegate batch reserves $0 for models absent from the pricing table, bypassing the cost-cap fan-out guard | 高危 | PyPIatomic-agents-stack | 已审查 | 2026-08-18 05:50 | 2026-08-18 05:50 |
| GHSA-XHCR-CQFR-M3HV | atomic-agents-stack: HTTP MCP catalog accepts cleartext http and spawns catalog-supplied commands (MITM to RCE) | 高危 | PyPIatomic-agents-stack | 已审查 | 2026-08-18 05:49 | 2026-08-18 05:49 |
| GHSA-8C42-7QJ2-3J46 CVE-2026-59903 | Netty Vulnerable to Cache Poisoning and Information Disclosure via CORS Vary Header Overwrite | 中危 | Mavenio.netty:netty-codec-http | 已审查 | 2026-08-18 02:24 | 2026-08-18 02:24 |
| GHSA-2QJ4-MMR9-4V2F CVE-2026-59902 | Netty: Memory Exhaustion in SctpMessageCompletionHandler | 高危 | Mavenio.netty:netty-transport-sctp | 已审查 | 2026-08-18 01:50 | 2026-08-18 01:50 |