检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-3WHF-VGF2-9W6G | zaino-state has a Non-Finalized State Reorg — No Cycle Detection or Depth Limit | 中危 | crates.iozaino-state | 已审查 | 2026-08-01 03:49 | 2026-08-01 03:49 |
| GHSA-P849-8HWH-84J9 CVE-2026-52887 | NocoBase: SQL injection in /api/myInAppChannels:list filter to PG-superuser RCE |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 严重 |
npm@nocobase/plugin-notification-in-app-message |
| 已审查 |
| 2026-08-01 03:44 |
| 2026-08-01 03:44 |
| GHSA-98PP-VCCM-QM25 CVE-2026-53599 | Redaxo has a Mediapool isAllowedExtension bypass via multi-segment filename that leads to authenticated RCE on Apache mod_php multi-extension handlers | 高危 | Packagistredaxo/source | 已审查 | 2026-08-01 03:43 | 2026-08-01 03:43 |
| GHSA-PJXJ-PCHX-4C3M CVE-2026-53466 | ImageMagick: Heap Buffer Over-Read in XCF decoder due to integer conversion overflow | 中危 | NuGetMagick.NET-Q16-AnyCPU+16 | 已审查 | 2026-08-01 03:40 | 2026-08-01 03:40 |
| GHSA-MX5J-MP4F-G8JG CVE-2026-53510 | Savon::Model evaluates WSDL operation names as Ruby source | 高危 | RubyGemssavon | 已审查 | 2026-08-01 03:38 | 2026-08-01 03:38 |
| GHSA-45QG-252V-3F7P CVE-2026-65841 | Jodit has cross-site scripting (XSS) via <script> nested in SVG that bypasses clean-html sanitization | 中危 | npmjodit | 已审查 | 2026-08-01 03:15 | 2026-08-01 03:15 |
| GHSA-RXCW-MC6F-6HR3 CVE-2026-58263 | Jodit Editor: Mutation XSS in jodit clean-html via a MathML/style rawtext carrier | 高危 | npmjodit | 已审查 | 2026-08-01 03:12 | 2026-08-01 03:12 |
| GHSA-5957-5C94-3V7W CVE-2026-54756 | Jodit has prototype pollution via Jodit.configure() / ConfigMerge | 中危 | npmjodit | 已审查 | 2026-08-01 03:10 | 2026-08-01 03:10 |
| GHSA-J839-GQQ4-GF9J CVE-2026-62324 | Jodit has incomplete javascript: scheme normalization in sanitizeHTMLElement href check that allows link XSS | 中危 | npmjodit | 已审查 | 2026-08-01 03:08 | 2026-08-01 03:08 |
| GHSA-CJ54-HPCC-GJ6H CVE-2026-53502 | Thumbor has path traversal via post-validation URL decoding bypass in file_loader | 高危 | PyPIthumbor | 已审查 | 2026-08-01 03:03 | 2026-08-01 03:03 |
| GHSA-PHJ3-59PF-CP83 CVE-2026-53505 | Thumbor proportion filter allows unbounded post-transform resize leading to remote DoS | 高危 | PyPIthumbor | 已审查 | 2026-08-01 03:00 | 2026-08-01 03:00 |
| GHSA-5VJC-7CXW-4W6J CVE-2026-53504 | Thumbor has Regex Denial of Service (ReDoS) in `convolution` filter | 高危 | PyPIthumbor | 已审查 | 2026-08-01 02:58 | 2026-08-01 02:58 |
| GHSA-CQJP-JF4R-H5Q9 CVE-2026-53503 | Thumbor convolution filter allows divide-by-zero in C extension leading to remote DoS | 高危 | PyPIthumbor | 已审查 | 2026-08-01 02:54 | 2026-08-01 02:54 |
| GHSA-MW3H-QJXJ-6XG9 CVE-2026-53501 | Thumbor has HMAC validation bypass via multiple .replace() calls when removing URL signature | 高危 | PyPIthumbor | 已审查 | 2026-08-01 02:51 | 2026-08-01 02:51 |
| GHSA-6X26-6R6F-M537 CVE-2026-53500 | Thumbor treats ALLOWED_SOURCES string patterns as unescaped regex, allowing hostname bypass via wildcard dot | 高危 | PyPIthumbor | 已审查 | 2026-08-01 02:36 | 2026-08-01 02:36 |
| GHSA-MJ3G-7XCC-X4VH CVE-2026-54737 | @phun-ky/defaults-deep Has a Prototype Pollution issue via Unsafe Recursive Property Merging | 高危 | npm@phun-ky/defaults-deep | 已审查 | 2026-08-01 01:49 | 2026-08-01 01:49 |
| GHSA-R2V3-8GWF-7GHM CVE-2026-54725 | vault-addr annotation SSRF -- webhook makes outbound HTTP call to attacker URL during admission; vault-serviceaccount enables cluster-wide SA token theft via TokenRequest API | 严重 | Gogithub.com/bank-vaults/vault-secrets-webhook | 已审查 | 2026-08-01 01:45 | 2026-08-01 01:45 |
| GHSA-G956-2F74-RMV7 CVE-2026-55100 | hashi-vault-js has a path traversal and query parameter injection | 高危 | npmhashi-vault-js | 已审查 | 2026-08-01 01:03 | 2026-08-01 01:03 |
| GHSA-5846-7QM3-R52J CVE-2026-54729 | dssrf: any users using 1.1.1.1 DNS is impacted by SSRF | 高危 | npmdssrf | 已审查 | 2026-08-01 00:58 | 2026-08-01 00:58 |
| GHSA-JR6P-8PJJ-MFX6 CVE-2026-65835 | Capsule has an incomplete fix of CVE-2026-22872: TenantResource RawItems and Generators still allow cluster-scoped resource creation (cross-tenant privilege escalation) | 中危 | Gogithub.com/projectcapsule/capsule | 已审查 | 2026-08-01 00:53 | 2026-08-01 00:53 |
| GHSA-68CJ-MVG9-RGM2 CVE-2026-65834 | Capsule: CapsuleConfiguration NodeMetadata regex fields lack webhook validation, allowing MustCompile panic on all Node admission requests | 中危 | Gogithub.com/projectcapsule/capsule | 已审查 | 2026-08-01 00:53 | 2026-08-01 00:53 |
| GHSA-FF84-5F28-78QJ CVE-2026-67550 | re2: Out-of-bounds heap read in `exec`/`test`/`match` via attacker-influenced `lastIndex` on a non-ASCII subject → uncatchable process crash (DoS) | 中危 | npmre2 | 已审查 | 2026-08-01 00:53 | 2026-08-01 00:53 |
| GHSA-6HXR-MR5R-9836 CVE-2026-68499 | re2: Global `String.prototype.match` with an empty-matchable pattern never advances → infinite loop with unbounded native memory growth (DoS) | 中危 | npmre2 | 已审查 | 2026-08-01 00:53 | 2026-08-01 00:53 |
| GHSA-X83G-979R-F5FH CVE-2026-68501 | Sylius Mollie Plugin has unauthenticated IDOR that leaks order token and customer PII | 中危 | Packagistsylius/mollie-plugin | 已审查 | 2026-08-01 00:52 | 2026-08-01 00:52 |
| GHSA-RC52-C4HV-W89P CVE-2026-68500 | Sylius Mollie Plugin vulnerable to payment status forgery via the payment webhook | 高危 | Packagistsylius/mollie-plugin | 已审查 | 2026-08-01 00:52 | 2026-08-01 00:52 |