检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-JFM3-95JQ-Q3RF | league/commonmark: Denial of service via duplicate footnote definitions | 高危 | Packagistleague/commonmark | 已审查 | 2026-08-07 04:40 | 2026-08-07 04:42 |
| GHSA-G2GP-3WWQ-F4PH | league/commonmark: Denial of service via adjacent inline attribute blocks |
当前筛选结果 35,190 条 · 时间按北京时间显示
Packagistleague/commonmark |
| 已审查 |
| 2026-08-07 04:39 |
| 2026-08-07 04:39 |
| GHSA-2Q4P-G7HV-5RGV CVE-2026-71488 | league/commonmark: Quadratic-time denial of service when parsing crafted Markdown | 高危 | Packagistleague/commonmark | 已审查 | 2026-08-07 04:37 | 2026-08-07 04:37 |
| GHSA-29PJ-957V-52MC CVE-2026-71478 | league/commonmark: AttributesExtension href/src unsafe-link filter bypass via embedded control bytes | 中危 | Packagistleague/commonmark | 已审查 | 2026-08-07 04:30 | 2026-08-07 04:30 |
| GHSA-5P4M-2WFM-XMQJ | JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported | 高危 | npmjs-yaml | 已审查 | 2026-08-07 04:27 | 2026-08-07 04:27 |
| GHSA-W3CP-G2PF-65WH CVE-2026-54717 | Silverstripe: XSS in breadcrumbs in page list view | 中危 | Packagistsilverstripe/cms | 已审查 | 2026-08-07 04:27 | 2026-08-07 04:27 |
| GHSA-HQVF-45JJ-MCCQ CVE-2026-18654 | AWS CLI: Disabled SSH host key verification in Amazon AWS CLI EMR helper commands | 中危 | PyPIawscli | 已审查 | 2026-08-07 04:15 | 2026-08-07 04:15 |
| GHSA-VP3H-GHGH-JR7G CVE-2026-71476 | Nx: Zip-Slip in the self-hosted remote cache | 高危 | npm@nx/azure-cache+8 | 已审查 | 2026-08-07 04:10 | 2026-08-07 04:10 |
| GHSA-RHH3-JPG6-66XH CVE-2026-71439 | Mermaid radar diagrams are vulnerable to DoS | 中危 | npmmermaid | 已审查 | 2026-08-07 04:01 | 2026-08-07 04:01 |
| GHSA-C4C3-PG64-4M4V CVE-2026-71438 | Mermaid configuration APIs allow prototype pollution | 低危 | npmmermaid | 已审查 | 2026-08-07 03:59 | 2026-08-07 03:59 |
| GHSA-6X64-9X62-F2GX CVE-2026-50159 | Mermaid allows CSS injection applying to sibling elements of the diagram | 中危 | npmmermaid | 已审查 | 2026-08-07 03:55 | 2026-08-07 03:55 |
| GHSA-3RRR-JR9J-H3Q3 CVE-2026-71437 | Mermaid Architecture diagrams are vulnerable to prototype pollution | 中危 | npmmermaid | 已审查 | 2026-08-07 03:51 | 2026-08-07 03:51 |
| GHSA-GRM4-WM43-9JH5 CVE-2026-55825 | Contao: Possible path traversal in job download URIs | 低危 | Packagistcontao/contao+1 | 已审查 | 2026-08-07 03:49 | 2026-08-07 03:49 |
| GHSA-2V8P-3F2J-5MP7 CVE-2026-71436 | Mermaid XY Charts are vulnerable to an infinite loop DoS | 中危 | npmmermaid | 已审查 | 2026-08-07 03:49 | 2026-08-07 03:49 |
| GHSA-3MR9-P497-58F6 CVE-2026-55824 | Contao crawler leaks auth credentials to external hosts | 低危 | Packagistcontao/contao+1 | 已审查 | 2026-08-07 03:43 | 2026-08-07 03:43 |
| GHSA-VX89-P3J7-8XQC CVE-2026-71435 | Statamic: Stored Cross-Site Scripting in Automagic Form Notification Email Template | 中危 | Packagiststatamic/cms | 已审查 | 2026-08-07 03:37 | 2026-08-07 03:37 |
| GHSA-QHR7-V3XP-VW9M CVE-2026-71434 | Statamic: Missing file upload validation on frontend forms allows uploading disallowed file types | 中危 | Packagiststatamic/cms | 已审查 | 2026-08-07 03:35 | 2026-08-07 03:35 |
| GHSA-QH8C-7588-QFRV CVE-2026-64662 | Statamic: Missing authorization on navigation endpoint allows disclosure of restricted entries | 中危 | Packagiststatamic/cms | 已审查 | 2026-08-07 03:30 | 2026-08-07 03:30 |
| GHSA-J2VP-F2PV-5RJ4 CVE-2026-64663 | Statamic: Unsafe method invocation via Antlers template resolution allows data destruction | 中危 | Packagiststatamic/cms | 已审查 | 2026-08-07 03:28 | 2026-08-07 03:28 |
| GHSA-93QH-5269-9WCF CVE-2026-64665 | Statamic: Account takeover via OAuth email matching without email-verification check | 高危 | Packagiststatamic/cms | 已审查 | 2026-08-07 03:25 | 2026-08-07 03:25 |
| GHSA-225X-3JHX-WH4Q CVE-2026-64664 | Statamic: Missing authorization on Control Panel endpoint allows disclosure of user existence | 中危 | Packagiststatamic/cms | 已审查 | 2026-08-07 03:22 | 2026-08-07 03:22 |
| GHSA-47PJ-3JCM-6WHG CVE-2026-71433 | LangGraph: Namespace prefix matching crosses segment boundaries in Postgres and SQLite stores | 中危 | PyPIlanggraph-checkpoint-postgres+1 | 已审查 | 2026-08-07 03:03 | 2026-08-07 03:03 |
| GHSA-X677-9FXG-V5C5 CVE-2026-54763 | Traefik: Incomplete fix for CVE-2026-33433 + CVE-2026-39858 cross-cohort: headerField underscore-variant identity spoofing in BasicAuth / DigestAuth / ForwardAuth | 高危 | Gogithub.com/traefik/traefik/v2+1 | 已审查 | 2026-08-07 00:53 | 2026-08-07 00:53 |
| GHSA-CXJQ-MRR5-89RV CVE-2026-65600 | Traefik: Authentication Bypass via Path Traversal in ReplacePathRegex Middleware | 严重 | Gogithub.com/traefik/traefik+2 | 已审查 | 2026-08-07 00:51 | 2026-08-07 00:51 |
| GHSA-8RXV-JG7P-WVG3 CVE-2026-67309 | Traefik: Kubernetes Ingress NGINX RewriteTarget Path Traversal Allows Route-Level Authentication Bypass | 高危 | Gogithub.com/traefik/traefik/v3 | 已审查 | 2026-08-07 00:45 | 2026-08-07 00:45 |