检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-2956-977X-2W3R CVE-2026-67429 | Flyto2 Core: Arbitrary file write via image.download (and other file-writing modules) | 严重 | PyPIflyto-core | 已审查 | 2026-07-30 22:46 | 2026-07-30 22:46 |
| GHSA-4JC5-G844-4X33 CVE-2026-67435 |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 中危 |
PyPIlinuxfabrik-lib |
| 已审查 |
| 2026-07-30 22:46 |
| 2026-07-30 22:46 |
| GHSA-5P9G-J988-PCWV CVE-2026-67431 | MCP Ruby SDK: Ruby SSE Session Poisoning | 高危 | RubyGemsmcp | 已审查 | 2026-07-30 22:44 | 2026-07-30 22:44 |
| GHSA-H669-8M4G-R2HC CVE-2026-67432 | MCP Ruby SDK: Unbounded JSON-RPC request body causes uncontrolled memory allocation in StreamableHTTPTransport | 高危 | RubyGemsmcp | 已审查 | 2026-07-30 22:44 | 2026-07-30 22:44 |
| GHSA-52JP-GJ8W-J6XH CVE-2026-67430 | MCP Ruby SDK: Unbounded session retention in StreamableHTTPTransport allows memory exhaustion via initialize flood | 中危 | RubyGemsmcp | 已审查 | 2026-07-30 22:43 | 2026-07-30 22:43 |
| GHSA-7683-3W9X-CH42 CVE-2026-63119 | MCP Ruby SDK: Unbounded line buffer in stdio transports leads to memory exhaustion (DoS) | 中危 | RubyGemsmcp | 已审查 | 2026-07-30 22:41 | 2026-07-30 22:41 |
| GHSA-RJR6-RCGV-9M7M CVE-2026-63118 | MCP Ruby SDK: Streamable HTTP transport lacks DNS-rebinding (Host/Origin) protection | 中危 | RubyGemsmcp | 已审查 | 2026-07-30 22:41 | 2026-07-30 22:41 |
| GHSA-XC5W-4V5W-7X65 CVE-2026-67438 | OliveTin OS Command Injection via Custom regex: Argument Type Bypassing Shell Safety Check | 中危 | Gogithub.com/OliveTin/OliveTin | 已审查 | 2026-07-30 22:31 | 2026-07-30 22:31 |
| GHSA-JM28-2WCR-QF3H CVE-2026-67439 | OliveTin: StartActionAndWait Endpoints Bypass `logs` Permission and Return Action Output | 中危 | Gogithub.com/OliveTin/OliveTin | 已审查 | 2026-07-30 22:25 | 2026-07-30 22:25 |
| GHSA-XPXJ-F2FM-RQCH CVE-2026-67437 | OliveTin: Unauthenticated DoS via OAuth2 State Memory Exhaustion (Unbounded Map Growth) | 高危 | Gogithub.com/OliveTin/OliveTin | 已审查 | 2026-07-30 22:24 | 2026-07-30 22:24 |
| GHSA-QWM4-QH6W-59XR CVE-2026-13346 | pip would incorrectly handle doubly-encoded package URLs from indexes | 中危 | PyPIpip | 已审查 | 2026-07-30 05:30 | 2026-09-02 02:57 |
| GHSA-FM7P-GW32-828P CVE-2026-54705 | mathlive's Lack of Escaping of HTML allows for XSS | 中危 | npmmathlive | 已审查 | 2026-07-30 01:21 | 2026-07-30 01:21 |
| GHSA-RWQX-FVQH-6WM4 CVE-2026-54704 | OpenTelemetry Java Instrumentation: JDBC Auto-Instrumentation Logging Clear-Text Passwords | 中危 | Mavenio.opentelemetry.javaagent:opentelemetry-javaagent | 已审查 | 2026-07-30 01:18 | 2026-07-30 01:18 |
| GHSA-FQ3F-M5QM-99F5 CVE-2026-54712 | OpenTelemetry Javaagent RMI context propagation allows resource exhaustion | 中危 | Mavenio.opentelemetry.javaagent:opentelemetry-javaagent | 已审查 | 2026-07-30 01:16 | 2026-07-30 01:16 |
| GHSA-PMWX-RM49-XV39 | ActiveRecord::Tenanted::Storage::DiskService#path_for has a possible path traversal | 低危 | RubyGemsactiverecord-tenanted | 已审查 | 2026-07-30 01:06 | 2026-07-30 01:06 |
| GHSA-XVG2-CGV6-6H7V | netfoil: Incorrect block responses could lead to localhost traffic | 高危 | Gogithub.com/tinfoil-factory/netfoil | 已审查 | 2026-07-30 01:03 | 2026-07-30 01:03 |
| GHSA-MJQF-28PH-426H CVE-2026-54680 | Logging operator has Fluentd configuration injection that allows remote code execution | 严重 | Gogithub.com/kube-logging/logging-operator | 已审查 | 2026-07-30 01:01 | 2026-07-30 01:01 |
| GHSA-JQ8W-8Q2F-FFM9 CVE-2026-54693 | ZITADEL Users Can Self-Verify Email/Phone via API | 高危 | Gogithub.com/zitadel/zitadel | 已审查 | 2026-07-30 00:54 | 2026-07-30 00:54 |
| GHSA-7H3G-4W2F-FJ2F CVE-2026-54727 | proot-distro has a Container Isolation Bypass via Crafted Restore Archive | 高危 | PyPIproot-distro | 已审查 | 2026-07-30 00:42 | 2026-07-30 00:42 |
| GHSA-9XQ3-3FQG-4VG7 CVE-2026-54574 | `proot-distro install` has a Symlink Escape (Arbitrary Host File Write) via Malicious Tar Archive | 高危 | PyPIproot-distro | 已审查 | 2026-07-30 00:32 | 2026-07-30 00:32 |
| GHSA-996F-334J-67G7 CVE-2026-52838 | Easy!Appointments disable_booking_message rendered as raw HTML on public booking page — Stored XSS | 低危 | Packagistalextselegidis/easyappointments | 已审查 | 2026-07-30 00:30 | 2026-07-30 00:30 |
| GHSA-8HM4-R66F-29WR CVE-2026-52841 | Easy!Appointments: Authorization bypass in Google OAuth provider binding lets any backend user rebind a peer provider's Google sync | 低危 | Packagistalextselegidis/easyappointments | 已审查 | 2026-07-30 00:29 | 2026-07-30 00:29 |
| GHSA-XGR6-PQJV-3PF8 CVE-2026-52837 | Easy!Appointments has unauthenticated customer PII disclosure on booking reschedule page | 中危 | Packagistalextselegidis/easyappointments | 已审查 | 2026-07-30 00:28 | 2026-07-30 00:28 |
| GHSA-W8XC-8G92-V77H CVE-2026-52839 | Easy!Appointments appointments/store and appointments/update allow cross-provider appointment injection — Authorization Bypass | 低危 | Packagistalextselegidis/easyappointments | 已审查 | 2026-07-30 00:26 | 2026-07-30 00:26 |
| GHSA-PM5P-7W5H-JM5Q CVE-2026-52840 | Easy!Appointments has server-side request forgery in CalDAV connection test that exposes the deployment's internal network | 低危 | Packagistalextselegidis/easyappointments | 已审查 | 2026-07-30 00:24 | 2026-07-30 00:24 |