—— |
| 未审查 |
| 2026-09-02 23:34 |
| 2026-09-03 05:32 |
| GHSA-499Q-GX9F-WXHQ CVE-2026-76782 | 无摘要 | 高危 | —— | 未审查 | 2026-09-02 23:34 | 2026-09-03 05:32 |
| GHSA-3WF5-7HJW-48CG CVE-2026-81158 | 无摘要 | 中危 | —— | 未审查 | 2026-09-02 23:34 | 2026-09-03 05:32 |
| GHSA-3RH4-FV5F-H684 CVE-2026-76755 | 无摘要 | 中危 | —— | 未审查 | 2026-09-02 23:34 | 2026-09-03 05:32 |
| GHSA-3M67-GRCR-C75V CVE-2026-76759 | 无摘要 | 高危 | —— | 未审查 | 2026-09-02 23:34 | 2026-09-03 05:32 |
| GHSA-HCFP-75MM-JGGH CVE-2026-16647 | 无摘要 | 未知 | —— | 未审查 | 2026-09-02 23:34 | 2026-09-02 23:34 |
| GHSA-H52G-F94F-R87H CVE-2026-18986 | 无摘要 | 中危 | —— | 未审查 | 2026-09-02 23:34 | 2026-09-02 23:34 |
| GHSA-6GMQ-8VP8-GCM6 CVE-2026-83610 | xmldom: XML fragment injection via invalid EntityReference.nodeName during requireWellFormed serialization | 中危 | npm@xmldom/xmldom+1 | 已审查 | 2026-09-02 23:18 | 2026-09-02 23:18 |
| GHSA-6M44-FPC8-C3RQ CVE-2026-76098 | Mistune: Denial of Service — RecursionError via Excessive Emphasis Markers in Markdown | 高危 | PyPImistune | 已审查 | 2026-09-02 23:14 | 2026-09-02 23:14 |
| GHSA-3M5P-2C4R-XXW2 CVE-2026-16732 | fastify vulnerable to X-Forwarded-* spoofing under trustProxy hop-count | 中危 | npmfastify | 已审查 | 2026-09-02 23:14 | 2026-09-02 23:14 |
| GHSA-W2QP-RPH6-63G4 CVE-2026-18504 | fastify vulnerable to schema validation bypass via root primitive coercion mismatch | 中危 | npmfastify | 已审查 | 2026-09-02 23:13 | 2026-09-02 23:13 |
| GHSA-VMG4-6GFG-83QX CVE-2026-71553 | ApostropheCMS: 2nd-order prototype pollution via PATCH leading to single-request persistent DoS | 高危 | npmapostrophe | 已审查 | 2026-09-02 23:12 | 2026-09-02 23:12 |
| GHSA-PP4X-CCXQ-6R33 CVE-2026-82396 | Sulu: Stored XSS via media download inline-disposition override | 中危 | Packagistsulu/sulu | 已审查 | 2026-09-02 23:10 | 2026-09-02 23:10 |
| GHSA-65CV-W493-7VHQ CVE-2026-82394 | Sulu: Fix authorization bypass when creating preview links | 中危 | Packagistsulu/sulu | 已审查 | 2026-09-02 23:09 | 2026-09-02 23:09 |
| GHSA-H6CX-GJXX-V25C CVE-2026-82395 | Sulu: Media move/update authorization bypass (IDOR) | 中危 | Packagistsulu/sulu | 已审查 | 2026-09-02 22:57 | 2026-09-02 22:57 |
| GHSA-79QF-VQGC-7XX3 CVE-2026-63667 | ApostropheCMS: Arbitrary file read via import-export attachment-name path traversal | 中危 | npm@apostrophecms/import-export | 已审查 | 2026-09-02 22:55 | 2026-09-02 22:55 |
| GHSA-6J4C-MGQR-QV76 CVE-2026-75592 | Kirby: Access to image files outside of the site root via path traversal in the media handling | 中危 | Packagistgetkirby/cms | 已审查 | 2026-09-02 22:55 | 2026-09-02 22:55 |
| GHSA-CXQ5-97V7-87J8 CVE-2026-62680 | Orval: Generation-time SSRF + remote/local file inclusion via unrestricted $ref | 高危 | npmorval | 已审查 | 2026-09-02 22:54 | 2026-09-02 22:54 |
| GHSA-P4CG-3328-RVFG CVE-2026-72716 | Orval: Import-time RCE via query-parameter default -> zod module-level template literal | 严重 | npmorval | 已审查 | 2026-09-02 22:53 | 2026-09-02 22:53 |
| GHSA-6MR6-JVCR-2F25 CVE-2026-71866 | Orval: Import-time RCE via schema property name -> computed-property-key injection in the zod client | 严重 | npmorval | 已审查 | 2026-09-02 22:52 | 2026-09-02 22:52 |
| GHSA-83X6-42HR-JC76 CVE-2026-73845 | CKAN MCP Server: MQA server allowlist bypass via unanchored regex (`isValidMqaServer`) | 中危 | npm@aborruso/ckan-mcp-server | 已审查 | 2026-09-02 22:52 | 2026-09-02 22:52 |
| GHSA-2V6V-25FM-P4FG CVE-2026-72920 | SeaweedFS: Unauthenticated filer IAM gRPC service grants S3 administrative control | 严重 | Gogithub.com/seaweedfs/seaweedfs | 已审查 | 2026-09-02 22:51 | 2026-09-02 22:51 |
| GHSA-FJ2P-QJ2F-74V5 CVE-2026-64850 | Grav: Remote code execution via unrestricted callable in Blueprint::dynamicData() | 高危 | Packagistgetgrav/grav | 已审查 | 2026-09-02 22:51 | 2026-09-02 22:51 |
| GHSA-37F3-6P89-6QR9 CVE-2026-62672 | Grav: Authenticated ReDoS via regex_replace in Twig Sandbox | 中危 | Packagistgetgrav/grav | 已审查 | 2026-09-02 22:50 | 2026-09-02 22:50 |