检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-M8RV-5G2X-5CG5 CVE-2026-15157 | undici vulnerable to CRLF Injection via blob-like body 'type' property | 中危 | npmundici | 已审查 | 2026-08-04 03:33 | 2026-08-04 03:33 |
| GHSA-JR45-8VMC-QM54 CVE-2026-14643 | undici vulnerable to cross-user information disclosure via whitespace around equals in Cache-Control directives |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 中危 |
npmundici |
| 已审查 |
| 2026-08-04 03:32 |
| 2026-08-04 03:32 |
| GHSA-V3R7-H72X-CJCM CVE-2026-16729 | undici vulnerable to cookie attribute injection via unsanitized domain and unparsed setCookie fields | 中危 | npmundici | 已审查 | 2026-08-04 03:30 | 2026-08-04 03:30 |
| GHSA-8XCM-R25X-G524 CVE-2026-16728 | undici vulnerable to downstream response desynchronization via retry interceptor | 中危 | npmundici | 已审查 | 2026-08-04 03:24 | 2026-08-04 03:24 |
| GHSA-4CWX-7WF7-3272 CVE-2026-13697 | undici vulnerable to cross-user information disclosure and parse-time crash via degenerate private cache directives | 高危 | npmundici | 已审查 | 2026-08-04 03:19 | 2026-08-04 03:24 |
| GHSA-7P8R-X3MC-P8W7 CVE-2026-18446 | fast-uri vulnerable to host confusion via backslash authority introducer | 高危 | npmfast-uri | 已审查 | 2026-08-04 03:16 | 2026-08-04 03:16 |
| GHSA-2M8V-J782-FHVR CVE-2026-69185 | Socket.IO: Zero-attachment Memory Exhaustion | 高危 | npmsocket.io-parser | 已审查 | 2026-08-04 03:09 | 2026-08-04 03:09 |
| GHSA-FXQJ-RQCC-2CMP CVE-2026-69153 | PostCSS: incomplete fix of GHSA-6g55-p6wh-862q — attacker-controlled sourceMappingURL reads arbitrary .map files when `from` is unset | 中危 | npmpostcss | 已审查 | 2026-08-04 01:11 | 2026-08-04 01:11 |
| GHSA-RGW5-RVV9-X895 CVE-2026-69152 | brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation | 高危 | npmbrace-expansion | 已审查 | 2026-08-04 00:35 | 2026-08-04 04:17 |
| GHSA-JJ27-H5HQ-8X99 CVE-2026-69151 | Angular i18n: Cross-Site Scripting (XSS) via event-handler attributes | 高危 | npm@angular/compiler+1 | 已审查 | 2026-08-04 00:23 | 2026-08-04 00:23 |
| GHSA-VPX6-8PJR-4G3V CVE-2026-69149 | Angular SSR: Missing Fallback Raw-Content Serialization Escaping leads to Cross-Site Scripting (XSS) | 高危 | npm@angular/platform-server | 已审查 | 2026-08-04 00:14 | 2026-08-04 00:14 |
| GHSA-JHPW-976M-542J CVE-2026-68945 | Angular: Cache-Key Ambiguity in HttpTransferCache Leading to Cross-Request Response Reuse and State Poisoning | 高危 | npm@angular/common | 已审查 | 2026-08-03 23:59 | 2026-08-03 23:59 |
| GHSA-M65R-RPRJ-R5RG CVE-2026-68930 | Russh: Channel-scoped server callbacks can be reached without an open channel | 中危 | crates.iorussh | 已审查 | 2026-08-03 23:35 | 2026-08-03 23:35 |
| GHSA-X7JR-GVVR-P9W7 | Duplicate Advisory: Path Traversal via unvalidated avID in RenderAttributeView/AV read endpoints : reader-reachable cross-scope attribute-view disclosure 已撤回 | 高危 | Gogithub.com/siyuan-note/siyuan/kernel | 已审查 | 2026-08-03 23:32 | 2026-09-04 04:33 |
| GHSA-PQPF-6VQV-6W92 | Duplicate Advisory: Unauthenticated SQL execution and REGEXP injection via fullTextSearchAssetContent (publish mode): reader-reachable raw SQL (method 2) and unescaped REGEXP (method 3) on read-write asset-content DB 已撤回 | 严重 | Gogithub.com/siyuan-note/siyuan | 已审查 | 2026-08-03 23:32 | 2026-09-04 05:00 |
| GHSA-P2X7-4C4P-8WH6 | Duplicate Advisory: Unauthenticated arbitrary SQL execution via searchEmbedBlock (publish mode) : reader-reachable raw statement on read-write handle, cross-notebook read/write 已撤回 | 严重 | Gogithub.com/siyuan-note/siyuan/kernel | 已审查 | 2026-08-03 23:32 | 2026-09-04 04:19 |
| GHSA-85XQ-27M5-59M9 | Duplicate Advisory: SiYuan: Full-content disclosure of publish-disabled documents via getHeading*Transaction endpoints (publish mode): reader-reachable rendered DOM with no publish-access check 已撤回 | 严重 | Gogithub.com/siyuan-note/siyuan/kernel | 已审查 | 2026-08-03 23:32 | 2026-09-04 05:17 |
| GHSA-3RFW-7FXW-6JXM | Duplicate Advisory: Cross-boundary metadata disclosure via getBlockInfo (publish mode): reader-reachable document title/root info for publish-forbidden docs; sibling getDocInfo is filtered 已撤回 | 中危 | Gogithub.com/siyuan-note/siyuan/kernel | 已审查 | 2026-08-03 23:32 | 2026-09-04 05:21 |
| GHSA-2MMH-4RF8-7XG6 | Duplicate Advisory: SiYuan: Cross-boundary content disclosure via getBacklinkDoc/getBackmentionDoc (publish mode): reader-reachable rendered DOM of publish-forbidden docs; sibling list endpoints are filtered 已撤回 | 严重 | npmsiyuan | 已审查 | 2026-08-03 23:32 | 2026-09-04 05:21 |
| GHSA-PV39-QRFQ-G8GC | Duplicate Advisory: NLTK: Missing Post-Download Integrity Verification Allows Malicious Package Injection 已撤回 | 中危 | PyPInltk | 已审查 | 2026-08-03 17:32 | 2026-09-02 04:30 |
| GHSA-XRQW-3RRV-VX5W CVE-2026-9856 | Transformers save_pretrained path traversal allows arbitrary file writes through chat template names | 高危 | PyPItransformers | 已审查 | 2026-08-03 02:30 | 2026-09-02 02:58 |
| GHSA-3Q45-2FH7-66CJ | Duplicate Advisory: better-auth has an external request basePath modification DoS 已撤回 | 严重 | npmbetter-auth | 已审查 | 2026-08-02 23:30 | 2026-09-02 02:56 |
| GHSA-M8WH-29WM-52MV CVE-2026-9335 | Keras: HDF5 links can disclose local file contents | 中危 | PyPIkeras | 已审查 | 2026-08-02 14:30 | 2026-08-08 04:35 |
| GHSA-MQQ9-GXG5-M58G | Duplicate Advisory: Guzzle: URI fragments disclosed in redirect Referer headers 已撤回 | 高危 | Packagistguzzlehttp/guzzle | 已审查 | 2026-08-01 23:30 | 2026-08-04 20:53 |
| GHSA-MJRX-74JH-7XGW | Duplicate Advisory: Guzzle: Host-only cookie scope is not preserved 已撤回 | 高危 | Packagistguzzlehttp/guzzle | 已审查 | 2026-08-01 23:30 | 2026-08-04 20:55 |