检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-FHGH-WQ4Q-R37X | uniget CLI: Metadata signature verification only runs when UNIGET_IGNORE_METADATA_SIGNATURE is set | 高危 | Gogitlab.com/uniget-org/cli | 已审查 | 2026-08-18 01:50 | 2026-08-18 01:50 |
| GHSA-PRG7-HCFM-MFCR CVE-2026-59893 | sqlparse: Inefficient Regex Handling of Dollar-Quoted SQL Literals Leads to ReDoS (Denial of Service) |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 高危 |
PyPIsqlparse |
| 已审查 |
| 2026-08-18 01:49 |
| 2026-08-18 01:49 |
| GHSA-PWGV-4X5Q-6M9F CVE-2026-54284 | sqlparse: TokenList.__init__ materializes O(subtree) value per group, causing CPU DoS before depth/token caps trigger | 高危 | PyPIsqlparse | 已审查 | 2026-08-18 01:49 | 2026-08-18 01:49 |
| GHSA-2JP7-WWPG-3P9W CVE-2026-55090 | Etherpad has stored XSS in HTML export via unescaped attribute-pool values | 高危 | npmep_etherpad-lite | 已审查 | 2026-08-18 01:49 | 2026-08-18 01:49 |
| GHSA-92HR-GMR6-H8CP | Etherpad addressed weak token RNG, login timing, plugin path handling, API request handling | 中危 | npmep_etherpad-lite | 已审查 | 2026-08-18 01:49 | 2026-08-18 01:49 |
| GHSA-M6JG-WR9M-CG2F CVE-2026-55062 | uniget CLI has Path Traversal in Hook Files - Directory Escape Vulnerability | 中危 | Gogitlab.com/uniget-org/cli | 已审查 | 2026-08-18 01:46 | 2026-08-18 01:46 |
| GHSA-QMCQ-XW74-W667 CVE-2026-55061 | uniget CLI has an EDITOR Command Injection | 中危 | Gogitlab.com/uniget-org/cli | 已审查 | 2026-08-18 01:46 | 2026-08-18 01:46 |
| GHSA-V836-6XW4-9CX3 | vm2 has Memory Exhaustion DoS via bufferAllocLimit Bypass | 高危 | npmvm2 | 已审查 | 2026-08-18 01:32 | 2026-08-18 01:32 |
| GHSA-M5W8-4GQ2-6F8X | vm2: NodeVM `builtin: ['*']` exposes `os` and `dns` — process-wide observability reads AND writes that hijack the host (sibling class of GHSA-9g8x-92q2-p28f) | 严重 | npmvm2 | 已审查 | 2026-08-18 01:32 | 2026-08-18 01:32 |
| GHSA-CFCW-XP6X-25GJ CVE-2026-47698 | vm2: Sandbox Breakout Using Dangerous Host Proto Mutators | 严重 | npmvm2 | 已审查 | 2026-08-18 01:32 | 2026-08-18 01:32 |
| GHSA-M283-3H24-438V CVE-2026-47686 | VM2 has Missing Error.cause Sanitization that Enables Sandbox Escape to RCE | 严重 | npmvm2 | 已审查 | 2026-08-18 01:32 | 2026-08-18 01:32 |
| GHSA-GMC2-2X9W-CGH9 CVE-2026-47683 | vm2's bufferAllocLimit cap bypassed by Buffer.concat and Buffer.from arrayLike | 高危 | npmvm2 | 已审查 | 2026-08-18 01:32 | 2026-08-18 01:32 |
| GHSA-F2FF-P2WW-7P4P CVE-2026-71491 | sqlparse: Quadratic O(n²) DoS in group_comments | 高危 | PyPIsqlparse | 已审查 | 2026-08-18 01:21 | 2026-08-18 01:21 |
| GHSA-4H34-V6R8-MMJC CVE-2026-68520 | Glances: as_dict_secure() Value-Level Bypass Leaks Credentials in URL Values via /api/4/config | 中危 | PyPIglances | 已审查 | 2026-08-18 01:20 | 2026-08-18 01:20 |
| GHSA-59FJ-M2J6-HCXH CVE-2026-68519 | Glances: `--disable-config-exec` does not cover on-alert action commands (incomplete fix of CVE-2026-53925) | 高危 | PyPIglances | 已审查 | 2026-08-18 01:20 | 2026-08-18 01:20 |
| GHSA-73WF-9VMV-5PV9 CVE-2026-62982 | Glances: Incomplete fix of CVE-2026-32608: action-template sanitizer is bypassed by nested stat values (process 'cmdline') → OS command injection | 高危 | PyPIglances | 已审查 | 2026-08-18 01:20 | 2026-08-18 01:20 |
| GHSA-3496-9G83-7V6X CVE-2026-59894 | sqlparse: Generated Python and PHP snippets allow SQL string breakout through unescaped backslashes | 中危 | PyPIsqlparse | 已审查 | 2026-08-18 01:20 | 2026-08-18 01:20 |
| GHSA-FP27-88FP-2PHG CVE-2026-68517 | Glances: REST API CORS Credentials Guard Uses Exact-Match Instead of Membership Test — Bypassed by Any Multi-Origin Allowlist Containing the Wildcard | 中危 | PyPIglances | 已审查 | 2026-08-18 01:04 | 2026-08-18 01:04 |
| GHSA-8394-6F8R-WHXG CVE-2026-45099 | Terragrunt: Arbitrary File Deletion via Malicious Module Manifest | 中危 | Gogithub.com/gruntwork-io/terragrunt | 已审查 | 2026-08-18 00:37 | 2026-08-18 00:37 |
| GHSA-QCPP-8X79-HHP3 CVE-2026-68518 | Glances has a command injection bypass of action-template sanitizer via cross-field shell-operator reconstruction | 高危 | PyPIglances | 已审查 | 2026-08-18 00:36 | 2026-08-18 00:36 |
| GHSA-J6GC-4893-QWMP CVE-2026-64865 | New API: Redis user quota cache overwrite via PUT /api/user/self allows quota bypass | 中危 | Gogithub.com/QuantumNous/new-api | 已审查 | 2026-08-18 00:36 | 2026-08-18 00:36 |
| GHSA-8R8V-XF7Q-RCPR CVE-2026-71479 | New API: Integer overflow in quota billing yields negative charges (self-crediting) | 严重 | Gogithub.com/QuantumNous/new-api | 已审查 | 2026-08-18 00:36 | 2026-08-18 00:36 |
| GHSA-P845-629J-RCJ6 CVE-2026-64866 | New API: Admin can reset passkeys for same-level or higher-privileged users | 中危 | Gogithub.com/QuantumNous/new-api | 已审查 | 2026-08-18 00:36 | 2026-08-18 00:36 |
| GHSA-V828-M3PF-VQ9Q CVE-2026-64868 | New API: Unauthenticated payment webhooks allow memory and disk DoS via unbounded body reads and full-body logging | 高危 | Gogithub.com/QuantumNous/new-api | 已审查 | 2026-08-18 00:35 | 2026-08-18 00:35 |
| GHSA-6X2C-PHFF-WX57 CVE-2026-64859 | New API: User List API Leaks Root User Access Token Leading to Privilege Escalation | 严重 | Gogithub.com/QuantumNous/new-api | 已审查 | 2026-08-18 00:35 | 2026-08-18 00:35 |