检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-93WV-JW9V-4972 CVE-2026-56819 | Netty: HTTP/2 decompression leaks ByteBuf reference count when the decompressor channel is already closed (Direct memory leak / OOM DoS) | 高危 | Mavenio.netty:netty-codec-http2 | 已审查 | 2026-08-01 00:51 | 2026-08-01 00:51 |
| GHSA-QVV7-CG9C-W4X3 CVE-2026-12075 |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 高危 |
PyPInltk |
| 已审查 |
| 2026-08-01 00:51 |
| 2026-08-01 00:51 |
| GHSA-FG7F-2386-8897 CVE-2026-12061 | Natural Language Toolkit (NLTK): ReDoS in NLTK ReviewsCorpusReader FEATURES regex | 高危 | PyPInltk | 已审查 | 2026-08-01 00:51 | 2026-08-01 00:51 |
| GHSA-6HM5-JGCP-P838 CVE-2026-12072 | Natural Language Toolkit (NLTK): Path Traversal in NKJPCorpusReader leads to Arbitrary File Read and bypasses the nltk.pathsec sandbox (ENFORCE=True) | 高危 | PyPInltk | 已审查 | 2026-08-01 00:50 | 2026-08-01 00:50 |
| GHSA-XH95-F55M-82FW CVE-2026-12074 | Natural Language Toolkit (NLTK) has path traversal in FramenetCorpusReader.frame() that allows arbitrary XML file read, bypassing the nltk.pathsec sandbox (ENFORCE=True) | 高危 | PyPInltk | 已审查 | 2026-08-01 00:50 | 2026-08-01 00:50 |
| GHSA-G2R8-WVMJ-JF5W CVE-2026-54753 | `nx graph` dev server permissive CORS policy | 中危 | npmnx | 已审查 | 2026-08-01 00:50 | 2026-08-01 00:50 |
| GHSA-88FW-V6X4-3F58 CVE-2026-41695 | Spring Data: Unbounded property-path cache keyed by externally-supplied path string | 高危 | Mavenorg.springframework.data:spring-data-commons | 已审查 | 2026-08-01 00:44 | 2026-08-01 00:44 |
| GHSA-22P9-R2F5-22MF CVE-2026-54706 | OnionShare follows symlinks in shared directories, allowing unintended disclosure of local files | 中危 | PyPIonionshare-cli | 已审查 | 2026-08-01 00:31 | 2026-08-01 00:31 |
| GHSA-V833-3823-CMHP CVE-2026-54707 | OnionShare Receive mode writes uploaded files even when file uploads are disabled | 中危 | PyPIonionshare-cli | 已审查 | 2026-08-01 00:27 | 2026-08-01 00:27 |
| GHSA-GHRQ-5WPP-HXX5 CVE-2026-52856 | Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service | 高危 | Gogithub.com/pterodactyl/wings | 已审查 | 2026-08-01 00:20 | 2026-08-01 00:20 |
| GHSA-PFVC-3P5H-X7H6 CVE-2026-52855 | Wings exposes node configuration secrets through egg configuration-file templating | 严重 | Gogithub.com/pterodactyl/wings | 已审查 | 2026-08-01 00:16 | 2026-08-01 00:16 |
| GHSA-Q6HH-GP44-4HCM CVE-2026-52857 | Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM | 中危 | Gogithub.com/pterodactyl/wings | 已审查 | 2026-08-01 00:10 | 2026-08-01 00:15 |
| GHSA-P7W7-4929-VPJ5 | `@dynatrace-oss/dynatrace-mcp-server` has Unauthenticated HTTP MCP Tool Invocation | 高危 | npm@dynatrace-oss/dynatrace-mcp-server | 已审查 | 2026-08-01 00:05 | 2026-08-01 00:05 |
| GHSA-XRMJ-5G4G-8987 | @dynatrace-oss/dynatrace-mcp-server has a workflow template injection via create_workflow_for_notification | 中危 | npm@dynatrace-oss/dynatrace-mcp-server | 已审查 | 2026-08-01 00:01 | 2026-08-01 00:01 |
| GHSA-PQH8-P93P-2RX7 | @dynatrace-oss/dynatrace-mcp-server has a DQL injection via parameters not documented as DQL | 中危 | npm@dynatrace-oss/dynatrace-mcp-server | 已审查 | 2026-07-31 23:56 | 2026-07-31 23:56 |
| GHSA-HJCP-JMPX-G3QM CVE-2026-64607 | Apache HttpComponents Client: Connection Leak on Content-Encoding Decode Error Leads to Pool Exhaustion DoS | 中危 | Mavenorg.apache.httpcomponents.client5:httpclient5 | 已审查 | 2026-07-31 20:30 | 2026-08-14 02:40 |
| GHSA-HF3J-86P7-MFW8 CVE-2025-4318 | AWS Amplify Studio UI Component Properties Has an Input Validation Issue | 严重 | npm@aws-amplify/codegen-ui-react | 已审查 | 2026-07-31 04:57 | 2026-07-31 04:57 |
| GHSA-XR9X-R78C-5HRM CVE-2026-66066 | Active Storage has possible arbitrary file read and remote code execution in Active Storage variant processing | 严重 | RubyGemsactivestorage | 已审查 | 2026-07-31 02:23 | 2026-07-31 02:23 |
| GHSA-4MRV-5P47-P938 CVE-2026-54522 | MessagePack::Buffer#clear Use-After-Free that Enables Cross-Buffer Disclosure | 低危 | RubyGemsmsgpack | 已审查 | 2026-07-31 00:33 | 2026-07-31 00:33 |
| GHSA-CG4G-M8JX-VJV2 CVE-2026-54722 | dssrf has an SSRF bypass with remove_at_symbol_in_string | 高危 | npmdssrf | 已审查 | 2026-07-31 00:26 | 2026-07-31 05:23 |
| GHSA-C9HR-64H3-GXPC CVE-2026-67424 | Flyto2 Core: Guarded HTTP modules follow redirects into internal space without per-hop SSRF revalidation | 高危 | PyPIflyto-core | 已审查 | 2026-07-30 22:48 | 2026-07-30 22:48 |
| GHSA-PGWH-4JJ4-QM8V CVE-2026-67428 | Flyto2 Core: Multiple HTTP-family modules fetch client-controlled URLs without the SSRF guard their siblings apply (SSRF to internal/metadata) | 高危 | PyPIflyto-core | 已审查 | 2026-07-30 22:48 | 2026-07-30 22:48 |
| GHSA-JX74-CQJV-2C67 CVE-2026-67426 | Flyto2 Core: Unauthenticated flyto-verification /run: callback_url SSRF and internal runner-secret exfiltration | 严重 | PyPIflyto-core | 已审查 | 2026-07-30 22:47 | 2026-08-10 22:59 |
| GHSA-QQ9Q-XGM3-XV9G CVE-2026-67425 | Flyto2 Core: LLM/API keys leak to an attacker-controlled base_url | 高危 | PyPIflyto-core | 已审查 | 2026-07-30 22:47 | 2026-07-30 22:47 |
| GHSA-HR7P-WG7R-HG9M CVE-2026-67427 | Flyto2 Core: ${env.VAR} interpolation reads any env secret despite env.get being denylisted | 高危 | PyPIflyto-core | 已审查 | 2026-07-30 22:47 | 2026-07-30 22:47 |