检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-9RJ7-RF2P-W77R | GitPython: Unguarded git option forwarding in Repo.init enables arbitrary command execution via --template clone hooks | 高危 | PyPIGitPython | 已审查 | 2026-08-07 23:36 | 2026-08-07 23:36 |
| GHSA-4GMW-GG2M-W46P | GitPython: Unguarded git read-tree option forwarding in IndexFile.from_tree/reset/merge_tree enables arbitrary file overwrite |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 高危 |
PyPIGitPython |
| 已审查 |
| 2026-08-07 23:33 |
| 2026-08-07 23:33 |
| GHSA-55Q2-FJHQ-7XH7 | DOMPurify: IN_PLACE hook removal leaves a detached subtree executable, causing XSS | 中危 | npmdompurify | 已审查 | 2026-08-07 23:30 | 2026-08-07 23:30 |
| GHSA-RJHH-76WF-8XMW CVE-2026-62996 | Smarty Security stream restriction bypass through stream: resource | 中危 | Packagistsmarty/smarty | 已审查 | 2026-08-07 23:10 | 2026-08-07 23:10 |
| GHSA-F6WF-28G6-769X CVE-2026-62992 | Smarty: Symlink path traversal out of trusted directories | 中危 | Packagistsmarty/smarty | 已审查 | 2026-08-07 23:02 | 2026-08-07 23:02 |
| GHSA-WG23-69C2-GJC8 | Craft CMS: Passkey login accepts replayed WebAuthn assertions | 严重 | Packagistcraftcms/cms | 已审查 | 2026-08-07 22:57 | 2026-08-07 22:57 |
| GHSA-957R-QF9P-67XW CVE-2026-72779 | Craft CMS: Arbitrary file read via SplFileObject in non-sandboxed template contexts | 中危 | Packagistcraftcms/cms | 已审查 | 2026-08-07 05:54 | 2026-09-02 05:03 |
| GHSA-6HR6-W5QG-QMWG CVE-2026-71554 | h2: Duplicate Host header could facilitate request smuggling | 中危 | PyPIh2 | 已审查 | 2026-08-07 05:53 | 2026-08-07 05:53 |
| GHSA-596P-6JV8-775V CVE-2026-72782 | Craft CMS: Authenticated leak of secret environment variables | 中危 | Packagistcraftcms/cms | 已审查 | 2026-08-07 05:53 | 2026-09-02 05:06 |
| GHSA-XXPX-F366-4XPQ CVE-2026-72785 | Craft CMS: Authorization bypass: view-only Categories user can modify category structure via structures/move-element | 中危 | Packagistcraftcms/cms | 已审查 | 2026-08-07 05:43 | 2026-09-02 05:18 |
| GHSA-RVMM-V933-JGXQ CVE-2026-14794 | Craft CMS: Missing authorization check allows non-admin control panel users access to user registration metrics | 中危 | Packagistcraftcms/cms | 已审查 | 2026-08-07 05:42 | 2026-09-01 03:43 |
| GHSA-7HXC-F267-H5Q7 CVE-2026-72783 | Craft CMS: Incorrect path validation could potentially lead to path traversal | 低危 | Packagistcraftcms/cms | 已审查 | 2026-08-07 05:36 | 2026-09-02 05:19 |
| GHSA-2RP4-X2J7-QMCC | Craft CMS: Stored XSS in the control panel via unescaped draft name | 中危 | Packagistcraftcms/cms | 已审查 | 2026-08-07 05:33 | 2026-08-07 05:33 |
| GHSA-HMQG-CXWW-WQHQ CVE-2026-67434 | PHP_CodeSniffer gitblame report command injection via crafted filename | 高危 | Packagistsquizlabs/php_codesniffer | 已审查 | 2026-08-07 05:31 | 2026-08-07 05:31 |
| GHSA-J4R3-HG7J-8CHG CVE-2026-71498 | node-re2: Out-of-bounds heap read in `replace`/`split` via a `Buffer` ending in a truncated multi-byte UTF-8 character → adjacent heap memory disclosed to JavaScript | 中危 | npmre2 | 已审查 | 2026-08-07 05:26 | 2026-08-07 05:26 |
| GHSA-8HCV-X26H-MCGP CVE-2026-71430 | node-re2: String.prototype.replace(re2, template) aborts the Node process (uncatchable ToLocalChecked on empty MaybeLocal) when the result exceeds V8's max string length | 中危 | npmre2 | 已审查 | 2026-08-07 05:19 | 2026-08-07 05:19 |
| GHSA-W9HM-4M3M-FXMM | ngx-extended-pdf-viewer bundles a version of pdf.js vulnerable to CVE-2026-16633 | 高危 | npmngx-extended-pdf-viewer | 已审查 | 2026-08-07 05:13 | 2026-08-07 05:13 |
| GHSA-HQ66-CQWQ-W95J CVE-2026-16633 | PDF.js: Arbitrary JavaScript execution upon opening a malicious PDF | 高危 | npmpdfjs-dist | 已审查 | 2026-08-07 05:12 | 2026-08-07 05:12 |
| GHSA-PMHH-3W7G-XQP8 CVE-2026-71497 | jsoup: Cleaner may expose markup with custom raw-text elements | 中危 | Mavenorg.jsoup:jsoup | 已审查 | 2026-08-07 05:09 | 2026-08-07 05:09 |
| GHSA-P8X7-9VFW-P7VC | Craft CMS: Arbitrary user password reset leading to administrator account takeover | 高危 | Packagistcraftcms/cms | 已审查 | 2026-08-07 05:04 | 2026-08-07 05:04 |
| GHSA-F5WM-88JV-G5HX CVE-2026-72781 | Craft CMS: Authenticated RCE through Twig sandbox escape | 高危 | Packagistcraftcms/cms | 已审查 | 2026-08-07 05:02 | 2026-09-02 05:04 |
| GHSA-9P7C-V5X3-RFX8 CVE-2026-14793 | Craft CMS: Missing authorization check allows non-admin control panel users to reorder Global Sets | 中危 | Packagistcraftcms/cms | 已审查 | 2026-08-07 04:55 | 2026-08-07 04:55 |
| GHSA-265M-7826-WJQM CVE-2026-72778 | Craft CMS: Authenticated RCE via `condition.config` JSON cleanse bypass | 高危 | Packagistcraftcms/cms | 已审查 | 2026-08-07 04:45 | 2026-09-02 05:07 |
| GHSA-MJ63-M3RC-8PPR | league/commonmark: Denial of service via deeply nested XML output | 中危 | Packagistleague/commonmark | 已审查 | 2026-08-07 04:42 | 2026-08-07 04:42 |
| GHSA-MH25-X5HQ-WRQP | league/commonmark: Denial of service via colliding heading slugs | 高危 | Packagistleague/commonmark | 已审查 | 2026-08-07 04:41 | 2026-08-07 04:41 |