检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-3FVR-2JW6-CRQ4 | Duplicate Advisory: Guzzle: Unbounded response cookies risk denial of service 已撤回 | 中危 | Packagistguzzlehttp/guzzle | 已审查 | 2026-08-01 23:30 | 2026-08-04 20:58 |
当前筛选结果 35,190 条 · 时间按北京时间显示
Duplicate Advisory: Guzzle: Proxy-Authorization headers can be sent to origin servers 已撤回 |
| 中危 |
Packagistguzzlehttp/guzzle |
| 已审查 |
| 2026-08-01 23:30 |
| 2026-08-04 20:49 |
| GHSA-9WX3-P993-35VP | Duplicate Advisory: Axios: Nested axios option objects can consume polluted prototype values 已撤回 | 中危 | npmaxios | 已审查 | 2026-08-01 23:30 | 2026-09-02 02:41 |
| GHSA-68JP-44VC-2X5H | Duplicate Advisory: Axios Node HTTP adapter can use an inherited proxy after interceptor config cloning 已撤回 | 高危 | npmaxios | 已审查 | 2026-08-01 23:30 | 2026-09-02 02:42 |
| GHSA-FQJ3-H9PC-443H | Duplicate Advisory: Axios: HTTP/2 streamed uploads bypass `maxBodyLength` 已撤回 | 中危 | npmaxios | 已审查 | 2026-08-01 23:30 | 2026-09-02 02:35 |
| GHSA-FQ2J-3J99-RX65 | Duplicate Advisory: Axios: Excessive recursion in formDataToJSON can cause denial of service 已撤回 | 中危 | npmaxios | 已审查 | 2026-08-01 23:30 | 2026-09-02 02:40 |
| GHSA-F2R5-PQH9-R8F8 | Duplicate Advisory: Axios: Prototype pollution gadgets can alter axios request construction 已撤回 | 中危 | npmaxios | 已审查 | 2026-08-01 23:30 | 2026-09-01 03:51 |
| GHSA-7QF5-7PPR-87V8 | Duplicate Advisory: Kubernetes Ingress NGINX RewriteTarget Path Traversal Allows Route-Level Authentication Bypass 已撤回 | 高危 | Gogithub.com/traefik/traefik/v3 | 已审查 | 2026-08-01 23:30 | 2026-08-07 00:45 |
| GHSA-6HQM-HM2V-3P2P | Duplicate Advisory: Axios: NO_PROXY bypass for 0.0.0.0 local addresses in axios 已撤回 | 中危 | npmaxios | 已审查 | 2026-08-01 23:30 | 2026-09-02 02:38 |
| GHSA-4WW2-RJH2-XPV9 | Duplicate Advisory: Axios: Deep formToJSON Key Recursion Can Cause Denial of Service 已撤回 | 中危 | npmaxios | 已审查 | 2026-08-01 23:30 | 2026-09-01 04:02 |
| GHSA-39J5-W47M-2GMV | Duplicate Advisory: Axios: Fetch adapter `ReadableStream` uploads bypass `maxBodyLength` 已撤回 | 中危 | npmaxios | 已审查 | 2026-08-01 23:30 | 2026-09-02 02:37 |
| GHSA-38GX-CFQF-F652 | Duplicate Advisory: Axios: Prototype pollution auth subfields can inject Basic auth 已撤回 | 中危 | npmaxios | 已审查 | 2026-08-01 23:30 | 2026-08-08 01:51 |
| GHSA-VVP7-H4FJ-M28W CVE-2026-54910 | FileBrowser Quantum's path traversal issue in subtitle handler allows any authenticated user to read arbitrary files | 高危 | Gogithub.com/gtsteffaniak/filebrowser/backend | 已审查 | 2026-08-01 06:35 | 2026-08-01 06:35 |
| GHSA-G65V-27R3-5P6M CVE-2016-1000305 | guard-livereload has a directory traversal vulnerability | 中危 | RubyGemsguard-livereload | 已审查 | 2026-08-01 06:33 | 2026-08-01 06:33 |
| GHSA-C5PX-58J2-7FQP CVE-2026-54785 | gemini-bridge vulnerable to arbitrary local file read via consult_gemini_with_files inline mode | 中危 | PyPIgemini-bridge | 已审查 | 2026-08-01 06:31 | 2026-08-01 06:31 |
| GHSA-JHH7-832H-F8HV CVE-2026-54768 | WPGraphQL has deprecated `user` field on SendPasswordResetEmailPayload that leaks user existence + profile (defeats explicit anti-enumeration design) | 中危 | Packagistwp-graphql/wp-graphql | 已审查 | 2026-08-01 06:24 | 2026-08-01 06:24 |
| GHSA-PJP7-Q6WP-97QX CVE-2026-53573 | core-geonetwork has an Open Redirect Bypass | 中危 | Mavenorg.geonetwork-opensource:geonetwork | 已审查 | 2026-08-01 06:16 | 2026-08-01 06:16 |
| GHSA-WG4G-WM44-CH5J CVE-2026-54908 | Pion DTLS vulnerable to denial of service via panic while parsing a crafted ECDHE_PSK ServerKeyExchange message | 中危 | Gogithub.com/pion/dtls/v3 | 已审查 | 2026-08-01 06:06 | 2026-08-01 06:06 |
| GHSA-34RH-WP3J-6CXC CVE-2026-54909 | Pion STUN vulnerable to remote denial of service via panic while parsing a malformed XOR-MAPPED-ADDRESS attribute | 中危 | Gogithub.com/pion/stun+2 | 已审查 | 2026-08-01 06:03 | 2026-08-01 06:03 |
| GHSA-WQQC-JJCQ-VFXM CVE-2026-54787 | sigstore-go fails to check signature timestamps against a signing key's validity period | 低危 | Gogithub.com/sigstore/sigstore-go | 已审查 | 2026-08-01 05:58 | 2026-08-01 05:58 |
| GHSA-WF43-FPP3-CF65 CVE-2026-53608 | @apostrophecms/seo Vulnerable to Stored XSS via Unsanitized Google Analytics / GTM ID Injected into Script Tag | 高危 | npm@apostrophecms/seo | 已审查 | 2026-08-01 05:53 | 2026-08-01 05:53 |
| GHSA-34PJ-2622-JVXQ CVE-2026-53607 | @apostrophecms/file pretty-URL Vulnerable to Unauthenticated SSRF via Host header | 低危 | npmapostrophe | 已审查 | 2026-08-01 05:51 | 2026-08-01 05:51 |
| GHSA-6H5J-32CF-4253 CVE-2026-53609 | Apostrophe has Server-Side Prototype Pollution in apos.util.set via patch operators that leads to process-wide authorization bypass | 严重 | npmapostrophe | 已审查 | 2026-08-01 05:49 | 2026-08-01 05:49 |
| GHSA-VCCV-CMXP-4J9H CVE-2026-53606 | sanitize-html has incomplete URI scheme validation in that allows javascript: URIs through action, formaction, data, poster, and background attributes | 中危 | npmsanitize-html | 已审查 | 2026-08-01 05:43 | 2026-08-01 05:43 |
| GHSA-QJ55-47FP-P62J CVE-2026-53551 | free5GC AUSF: null byte injection in supiOrSuci causes HTTP 500 internal service failure | 中危 | Gogithub.com/free5gc/ausf+1 | 已审查 | 2026-08-01 04:13 | 2026-08-01 04:13 |