检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-M44R-7C5H-M6MJ CVE-2026-53728 | Medplum: Improper Validation of Redirect URI in External Auth Callback allows Authorization Code Leakage | 高危 | npm@medplum/core | 已审查 | 2026-08-17 21:36 | 2026-08-17 21:36 |
| GHSA-2QVG-QR73-MQXP CVE-2026-55158 | conflibot vulnerable to command injection via crafted pull request branch names under pull_request_target |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 严重 |
GitHub Actionswktk/conflibot |
| 已审查 |
| 2026-08-17 21:35 |
| 2026-08-17 21:35 |
| GHSA-GGR8-5VV4-36MX CVE-2026-40345 | DeepmergeTS has stack exhaustion when merging recursive object graphs | 高危 | npmdeepmerge-ts | 已审查 | 2026-08-17 21:32 | 2026-08-17 21:32 |
| GHSA-9Q54-F358-3FQF CVE-2026-10740 | s2n-quic has excessive memory allocation | 中危 | crates.ios2n-quic | 已审查 | 2026-08-15 05:44 | 2026-08-15 05:44 |
| GHSA-76PC-MQXP-3RQ5 CVE-2026-55156 | Token Optimizer MCP: Unauthenticated Path Traversal in Dashboard Session Log API Endpoints | 中危 | npm@ooples/token-optimizer-mcp | 已审查 | 2026-08-15 05:43 | 2026-08-15 05:43 |
| GHSA-49MQ-FC6Q-3H46 CVE-2026-55157 | Token Optimizer MCP: OS command injection in smart_user via username in get-user-info | 高危 | npm@ooples/token-optimizer-mcp | 已审查 | 2026-08-15 05:42 | 2026-08-15 05:42 |
| GHSA-9HGC-G3W5-67CM CVE-2026-53708 | ContextForge: DNS TOCTOU race condition causes SSRF protection bypass (`/admin/gateways/test`) | 中危 | PyPImcp-contextforge-gateway | 已审查 | 2026-08-15 03:49 | 2026-08-15 03:49 |
| GHSA-8RW6-P7M8-63JP | SurrealDB: Array element-level (field.*) SELECT permissions leak denied elements to record users | 中危 | crates.iosurrealdb | 已审查 | 2026-08-15 03:40 | 2026-08-15 03:40 |
| GHSA-H84G-69H7-MW6V CVE-2026-55153 | mchange-commons-java contains elements susceptible to abuse via JNDI injection and "deserialization gadgets" | 高危 | Mavencom.mchange:mchange-commons-java | 已审查 | 2026-08-15 03:29 | 2026-08-15 03:29 |
| GHSA-FPMH-VX4H-XC33 CVE-2026-53660 | OpenAM Insecure SSO Cookie Initialization | 高危 | Mavenorg.openidentityplatform.openam:openam-core | 已审查 | 2026-08-15 03:25 | 2026-08-15 03:25 |
| GHSA-XGHW-P77P-3R7X CVE-2026-53658 | Fabric CA Developer's Guide: LDAP Injection via Unescaped Username in GetUser Filter | 中危 | Gogithub.com/hyperledger/fabric-ca | 已审查 | 2026-08-15 03:24 | 2026-08-15 03:24 |
| GHSA-2J9V-P4XJ-CJW2 CVE-2026-53657 | Lima: An arbitrary user in a QEMU VM could gain the root privilege in the VM via the guest agent socket | 高危 | Gogithub.com/lima-vm/lima/v2 | 已审查 | 2026-08-15 03:24 | 2026-08-15 03:24 |
| GHSA-4X9G-VW65-VVF9 CVE-2026-53653 | Grav: Unauthenticated denial of service via unbounded image derivative dimensions | 高危 | Packagistgetgrav/grav | 已审查 | 2026-08-15 03:23 | 2026-08-15 03:23 |
| GHSA-5FPJ-28RV-84R7 CVE-2026-35219 | Budibase: SSRF in Automation Steps - Webhook, Zapier, N8N, Slack, Discord Bypass IP Blacklist | 高危 | npm@budibase/server | 已审查 | 2026-08-15 03:18 | 2026-08-15 03:18 |
| GHSA-29RF-F4VV-PVQ6 CVE-2026-35511 | Authorizer: Zero-click account takeover via OAuth identity linking to unverified email accounts | 高危 | Gogithub.com/authorizerdev/authorizer | 已审查 | 2026-08-14 23:36 | 2026-08-14 23:36 |
| GHSA-WW86-C2QF-W8FW | Duplicate Advisory: Missing authorization on refreshBacklink allows anonymous readers to trigger persistent server-side writes and unauthenticated resource amplification (publish mode) 已撤回 | 中危 | Gogithub.com/siyuan-note/siyuan/kernel | 已审查 | 2026-08-14 20:31 | 2026-09-04 06:22 |
| GHSA-Q6G5-M978-C6V9 | Duplicate Advisory: Publish-boundary bypass via WebSocket broadcast: anonymous readers receive a live unfiltered feed of all edits including protected/forbidden documents (publish mode) 已撤回 | 严重 | Gogithub.com/siyuan-note/siyuan/kernel | 已审查 | 2026-08-14 20:31 | 2026-09-04 06:30 |
| GHSA-P8CP-78HP-WMQ8 | Duplicate Advisory: SQL injection in backlink/mention search via unescaped stored and client input (publish mode): first-order (client keyword) and second-order (stored document title) breakout on read-write handle 已撤回 | 严重 | Gogithub.com/siyuan-note/siyuan/kernel | 已审查 | 2026-08-14 20:31 | 2026-09-04 06:24 |
| GHSA-P28V-F755-9QRG CVE-2026-73654 | Trigger.dev: Prototype pollution via run metadata operations → process-wide cross-tenant DoS | 高危 | npm@trigger.dev/core | 已审查 | 2026-08-14 04:54 | 2026-08-14 04:54 |
| GHSA-M42H-3232-VPV3 CVE-2026-12243 | nltk: Arbitrary File Read via Path Traversal in nltk.data.load() through Percent-Encoded Sequences | 高危 | PyPInltk | 已审查 | 2026-08-14 04:45 | 2026-08-14 04:45 |
| GHSA-87X5-VMC3-756J CVE-2026-73559 | vLLM: Completion prompt lists fan out into unbounded engine requests | 中危 | PyPIvllm | 已审查 | 2026-08-14 02:40 | 2026-08-14 02:40 |
| GHSA-RM43-82J9-R4MJ | atomic-agents-stack: Dashboard HTTP server path traversal allows arbitrary file read | 高危 | PyPIatomic-agents-stack | 已审查 | 2026-08-13 22:17 | 2026-08-13 22:17 |
| GHSA-H7P7-W5GC-XJ3W CVE-2026-54249 | Pydantic AI: Unvalidated UploadedFile references in UI adapters allow server-side file access using the application's credentials | 中危 | PyPIpydantic-ai+1 | 已审查 | 2026-08-13 22:16 | 2026-08-13 22:16 |
| GHSA-48P8-G2FX-3WWM CVE-2026-54526 | Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) | 高危 | Gogithub.com/argoproj/argo-workflows+2 | 已审查 | 2026-08-13 22:16 | 2026-08-13 22:16 |
| GHSA-5PQ8-3FFP-7W5M CVE-2026-55102 | hashi-vault-js: Vault token and secret values exposed in thrown errors | 中危 | npmhashi-vault-js | 已审查 | 2026-08-13 22:14 | 2026-08-13 22:14 |