检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-6QC3-V8FV-FV9J CVE-2026-28672 | Apache Ranger has a Command Injection vulnerability | 严重 | Mavenorg.apache.ranger:ranger | 已审查 | 2026-08-10 20:31 | 2026-09-02 22:31 |
| GHSA-74M6-M3XX-3VMJ CVE-2026-12570 |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 中危 |
PyPIkeras |
| 已审查 |
| 2026-08-10 17:31 |
| 2026-09-02 04:22 |
| GHSA-FP3F-MC75-235C CVE-2026-71870 | pypdf: Possible large memory usage for large /ToUnicode streams | 中危 | PyPIpypdf | 已审查 | 2026-08-08 03:29 | 2026-08-08 03:29 |
| GHSA-FWG2-594C-JP42 CVE-2026-71852 | pypdf: Possible long runtimes/large memory usage for large CID font width ranges | 中危 | PyPIpypdf | 已审查 | 2026-08-08 02:54 | 2026-08-08 02:54 |
| GHSA-RG76-677X-56Q9 CVE-2026-71851 | crypto-js: Insufficient Entropy in Cryptographic Secret Generation via Vulnerable CryptoJS Dependency Chain | 严重 | npmcrypto-js | 已审查 | 2026-08-08 02:48 | 2026-08-08 02:48 |
| GHSA-F23P-VX2J-J53R CVE-2026-71850 | Hono: `memo()` retains SSR output across requests, leading to cross-user data disclosure | 中危 | npmhono | 已审查 | 2026-08-08 02:42 | 2026-08-08 02:42 |
| GHSA-79QM-7RJ5-M7R9 CVE-2026-71849 | Hono: Proxy Helper does not remove response headers listed in the `Connection` header | 低危 | npmhono | 已审查 | 2026-08-08 02:38 | 2026-08-08 02:38 |
| GHSA-54FX-42GC-7VW4 CVE-2026-71848 | Hono: Algorithmic Complexity DoS in Language Middleware | 中危 | npmhono | 已审查 | 2026-08-08 02:36 | 2026-08-08 02:36 |
| GHSA-9HJ4-R449-HFVC CVE-2026-71847 | Ruby JSON: JSON::ResumableParser#partial_value dereferences a freed input buffer and crashes on truncated duplicate-key streams | 低危 | RubyGemsjson | 已审查 | 2026-08-08 02:33 | 2026-08-08 02:33 |
| GHSA-GM37-52C6-37MW CVE-2026-67422 | pymdown-extensions: exponential-backtracking ReDoS in caret, tilde, betterem, and magiclink inline processors | 高危 | PyPIpymdown-extensions | 已审查 | 2026-08-08 02:26 | 2026-08-08 02:26 |
| GHSA-MMJ4-63M4-R6H5 CVE-2026-63223 | CodeIgniter: Uploaded file extension validation bypass in `is_image` and `mime_in` rules | 严重 | Packagistcodeigniter4/framework | 已审查 | 2026-08-08 02:24 | 2026-08-08 02:24 |
| GHSA-HHMC-Q9HP-R662 CVE-2026-63222 | CodeIgniter: Path traversal in UploadedFile::move() when using client-provided filenames | 高危 | Packagistcodeigniter4/framework | 已审查 | 2026-08-08 02:23 | 2026-08-08 02:23 |
| GHSA-C9W5-RWH3-7PM9 CVE-2026-63221 | CodeIgniter: SQL injection in Query Builder deleteBatch() when used with where() conditions | 严重 | Packagistcodeigniter4/framework | 已审查 | 2026-08-08 02:22 | 2026-08-08 02:22 |
| GHSA-7WMF-PW8J-MC78 CVE-2026-63220 | CodeIgniter: Spoofable forwarded HTTPS headers in IncomingRequest::isSecure() | 中危 | Packagistcodeigniter4/framework | 已审查 | 2026-08-08 02:21 | 2026-08-08 02:21 |
| GHSA-WCX4-WPFV-MC5C CVE-2026-15895 | jsii-diff: Command Injection via npm: package argument | 高危 | npmjsii-diff | 已审查 | 2026-08-08 02:15 | 2026-08-08 02:15 |
| GHSA-P9JM-Q85P-7MCP CVE-2026-56818 | Netty: RedisArrayAggregator max-elements failure leaves retained partial aggregate state | 中危 | Mavenio.netty:netty-codec-redis | 已审查 | 2026-08-08 01:16 | 2026-08-08 01:16 |
| GHSA-9RJG-X2P2-H68H CVE-2026-54164 | API Platform Core: Relation IRIs are not type-checked: a related resource can be denormalised as the wrong resource type (type confusion) | 中危 | Packagistapi-platform/core | 已审查 | 2026-08-08 00:54 | 2026-08-08 00:54 |
| GHSA-29G2-3RMR-QM68 CVE-2026-66062 | SvelteKit: ReDoS (O(n^2)) in content negotiation — unauthenticated DoS via the Accept header | 中危 | npm@sveltejs/kit | 已审查 | 2026-08-08 00:50 | 2026-08-08 00:50 |
| GHSA-7C4V-FWGW-9RF7 CVE-2026-72744 | Nuxt dev server discloses project root and workspace UUID via the Chrome DevTools workspace endpoint | 中危 | npmnuxt | 已审查 | 2026-08-08 00:45 | 2026-08-13 22:18 |
| GHSA-QGQ7-7HM3-Q39J CVE-2026-71557 | go-git: Malicious reference names may modify files outside the reference storage | 中危 | Gogithub.com/go-git/go-git/v5+1 | 已审查 | 2026-08-08 00:41 | 2026-08-08 00:41 |
| GHSA-HC8V-WWC9-VGXM CVE-2026-71556 | go-git: Worktree operations may follow symlinks | 高危 | Gogithub.com/go-git/go-git/v5+1 | 已审查 | 2026-08-08 00:38 | 2026-08-08 00:38 |
| GHSA-WVPP-8HX9-P66J | GitPython: Unsafe git option guard bypass via split_single_char_options=False short-option token smuggling enables command execution | 高危 | PyPIGitPython | 已审查 | 2026-08-07 23:49 | 2026-08-07 23:49 |
| GHSA-JM78-9FVV-MHGR | GitPython: git-config OPTION-name injection via =/#/whitespace bypasses name validator, enabling forged core.sshCommand/hooksPath (RCE) | 高危 | PyPIGitPython | 已审查 | 2026-08-07 23:46 | 2026-08-07 23:46 |
| GHSA-HMQ2-W58F-27JC | GitPython: Arbitrary Git Repository Creation Outside the Working Tree via Unvalidated .gitmodules Submodule Name in GitPython | 高危 | PyPIGitPython | 已审查 | 2026-08-07 23:45 | 2026-08-07 23:45 |
| GHSA-HH9P-6WH2-4MFC | GitPython: Arbitrary file read via --pathspec-from-file in IndexFile.remove() and Head.checkout() | 中危 | PyPIGitPython | 已审查 | 2026-08-07 23:43 | 2026-08-07 23:43 |