检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-6P8F-P8J2-RQMV CVE-2026-54765 | Traefik: Gateway HTTPRoute backendRef filters can leak backend context across routes sharing a Service:port | 中危 | Gogithub.com/traefik/traefik/v3 | 已审查 | 2026-08-07 00:40 | 2026-08-07 00:40 |
| GHSA-62FC-8686-HFMQ CVE-2026-71325 | Traefik: `allowCrossNamespace=false` bypass via `@kubernetescrd` TraefikService backendRef |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 中危 |
Gogithub.com/traefik/traefik+2 |
| 已审查 |
| 2026-08-07 00:38 |
| 2026-08-07 00:38 |
| GHSA-3Q9R-P662-5J8M CVE-2026-54764 | Traefik: ForwardAuth middleware leaks X-Forwarded-Port spoofing via untrusted X-Forwarded-Proto when trustForwardHeader=false | 中危 | Gogithub.com/traefik/traefik+2 | 已审查 | 2026-08-07 00:38 | 2026-08-07 00:38 |
| GHSA-FGJJ-PX3W-67XX CVE-2026-71327 | Traefik: Gateway API route identity collision allows cross-namespace backend hijacking | 高危 | Gogithub.com/traefik/traefik/v3 | 已审查 | 2026-08-07 00:38 | 2026-08-07 00:38 |
| GHSA-6765-C87H-8MRF CVE-2026-71326 | Traefik: BasicAuth singleflight key collision allows authenticated identity spoofing | 低危 | Gogithub.com/traefik/traefik/v3 | 已审查 | 2026-08-07 00:34 | 2026-08-07 00:34 |
| GHSA-3CCP-42PG-HGV6 CVE-2026-71324 | Traefik: Cross-user response poisoning via proxied CONNECT on Traefik's shared backend keep-alive pool | 高危 | Gogithub.com/traefik/traefik+2 | 已审查 | 2026-08-06 23:56 | 2026-08-06 23:56 |
| GHSA-42CJ-M3VJ-89WV CVE-2026-65602 | Traefik CRD IngressRouteTCP ServersTransport Cross-Provider Namespace Bypass | 中危 | Gogithub.com/traefik/traefik/v3 | 已审查 | 2026-08-06 05:53 | 2026-08-06 05:53 |
| GHSA-QQ9Q-X9W4-CHHJ CVE-2026-65601 | Traefik Gateway API HTTPRoute BackendRef ExtensionRef Namespace Confusion | 中危 | GoTraefik | 已审查 | 2026-08-06 05:49 | 2026-08-06 05:49 |
| GHSA-9PGF-384G-P7MV CVE-2026-71321 | Nuxt: Unauthenticated CPU exhaustion parsing and hashing the Nuxt island endpoint body before hash validation | 高危 | npmnuxt | 已审查 | 2026-08-06 05:43 | 2026-08-06 05:43 |
| GHSA-9473-5F9J-94WQ CVE-2026-71320 | Nuxt: Server-Side Remote Code Execution via Runtime Template Injection in Nuxt Server Island Props | 高危 | npmnuxt | 已审查 | 2026-08-06 05:29 | 2026-08-06 05:29 |
| GHSA-279X-MWFV-VCQV CVE-2026-71319 | Unauthenticated Nuxt DevTools RPC allows arbitrary command execution on the developer's host | 严重 | npm@nuxt/devtools | 已审查 | 2026-08-06 05:27 | 2026-08-06 05:27 |
| GHSA-48HR-524C-V5W3 CVE-2026-71318 | Nuxt: Unauthorized Component Instantiation via Server Island Props | 中危 | npmnuxt | 已审查 | 2026-08-06 05:21 | 2026-08-06 05:21 |
| GHSA-WM8W-6QJM-CV43 CVE-2026-71316 | Nuxt runtime payload cache discloses another user's SSR data across users and to unauthenticated clients | 高危 | npmnuxt | 已审查 | 2026-08-06 05:14 | 2026-08-06 05:14 |
| GHSA-HXVH-4H3W-PRP9 CVE-2026-71315 | Nuxt route rules silently dropped for mixed-case paths, bypassing appMiddleware auth gates (incomplete fix for CVE-2026-53721) | 高危 | npmnuxt | 已审查 | 2026-08-06 05:05 | 2026-08-06 05:05 |
| GHSA-HXCR-HM88-MPQ6 CVE-2026-71314 | Nuxt: Unauthenticated out-of-memory crash via unbounded v-for expansion in island rendering | 高危 | npmnuxt | 已审查 | 2026-08-06 04:59 | 2026-08-06 04:59 |
| GHSA-7P4M-QXVV-G567 CVE-2026-71313 | rclone: Local Encoding Path Traversal | 中危 | Gogithub.com/rclone/rclone | 已审查 | 2026-08-06 04:48 | 2026-08-06 04:48 |
| GHSA-4VR5-P2GC-H23P CVE-2026-59732 | rclone archive extract allows S3 destination prefix escape via crafted archive paths | 中危 | Gogithub.com/rclone/rclone | 已审查 | 2026-08-06 04:43 | 2026-08-06 04:43 |
| GHSA-GX4C-2HQX-CW2R | rclone: S3 backend does not strip X-Amz-Security-Token on a same-host HTTPS->HTTP redirect | 低危 | Gogithub.com/rclone/rclone | 已审查 | 2026-08-06 04:43 | 2026-08-06 04:43 |
| GHSA-FQJ9-69PF-6PJG CVE-2026-59733 | rclone `serve restic --private-repos` authorization bypass: `..` in the URL path lets an authenticated user read, overwrite and delete other users' repositories | 高危 | Gogithub.com/rclone/rclone | 已审查 | 2026-08-06 04:41 | 2026-08-06 04:41 |
| GHSA-2M8M-JHRM-W6J2 CVE-2026-71312 | rclone: PowerShell Smart-Quote Filename Injection Enables SFTP Server-Side Command Execution | 高危 | Gogithub.com/rclone/rclone | 已审查 | 2026-08-06 04:37 | 2026-08-06 04:37 |
| GHSA-H4MF-4V27-HGGJ | rclone: WebDAV Credentials Survive a Same-Host HTTPS-to-HTTP Redirect | 中危 | Gogithub.com/rclone/rclone | 已审查 | 2026-08-06 04:36 | 2026-08-06 04:36 |
| GHSA-8C48-Q9WJ-3W37 CVE-2026-71311 | rclone: FTP Command Arguments Permit CRLF Injection When Custom Encoding Preserves Newlines | 中危 | Gogithub.com/rclone/rclone | 已审查 | 2026-08-06 04:33 | 2026-08-06 04:33 |
| GHSA-8MXV-9XHP-86H4 | rclone: S3 Redirect Sanitization Omits IBM IAM Bearer Tokens and SSE-C Keys | 中危 | Gogithub.com/rclone/rclone | 已审查 | 2026-08-06 04:27 | 2026-08-06 04:27 |
| GHSA-8V25-V8P6-QF7V | rclone: Path traversal in serve s3 allows reading and overwriting root-level files | 中危 | Gogithub.com/rclone/rclone | 已审查 | 2026-08-06 04:27 | 2026-08-06 04:27 |
| GHSA-3X6R-WXXG-53VV | rclone: Infinite Scale TUS Creation Transport Error Causes a Nil-Response Panic | 中危 | Gogithub.com/rclone/rclone | 已审查 | 2026-08-06 04:26 | 2026-08-06 04:26 |