检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-VJ5C-M527-MPFF CVE-2026-54639 | Style Dictionary - Prototype Pollution in convertTokenData utility function | 高危 | npmstyle-dictionary | 已审查 | 2026-07-29 06:23 | 2026-07-29 06:23 |
| GHSA-FH2F-XFXC-Q9CC CVE-2026-54650 | openhole-server vulnerable to path traversal via URL-decoded request path |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 高危 |
Gogithub.com/bablilayoub/openhole |
| 已审查 |
| 2026-07-29 06:20 |
| 2026-07-29 06:20 |
| GHSA-6WCC-39RP-HH9P CVE-2026-54658 | @hypequery/clickhouse has SQL Injection in parameter escaping that allows arbitrary SQL execution | 严重 | npm@hypequery/clickhouse | 已审查 | 2026-07-29 06:19 | 2026-08-05 04:34 |
| GHSA-WHMM-QJ9R-WVR2 CVE-2026-54638 | td has pre-auth denial of service via unbounded memory allocation in proto.UnencryptedMessage.Decode | 高危 | Gogithub.com/gotd/td | 已审查 | 2026-07-29 06:15 | 2026-07-29 06:15 |
| GHSA-WG2Q-39H6-66X9 CVE-2026-66063 | goshs has a Path Traversal issue | 中危 | Gogithub.com/patrickhener/goshs+3 | 已审查 | 2026-07-29 06:08 | 2026-07-29 06:10 |
| GHSA-HQ33-8JGP-8QQ3 CVE-2026-64863 | goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite | 严重 | Gogithub.com/patrickhener/goshs+3 | 已审查 | 2026-07-29 06:03 | 2026-07-29 06:03 |
| GHSA-RMXW-PQ4X-3FVH CVE-2026-54719 | goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx) | 高危 | Gogithub.com/patrickhener/goshs+3 | 已审查 | 2026-07-29 05:59 | 2026-07-29 05:59 |
| GHSA-RJRW-MJQ6-HPMM CVE-2026-62325 | goshs SFTP authentication bypass via empty password (incomplete fix of CVE-2026-40884) | 严重 | Gogithub.com/patrickhener/goshs/v2+1 | 已审查 | 2026-07-29 05:56 | 2026-07-29 05:56 |
| GHSA-WJV6-JCFJ-MF9R CVE-2026-54654 | `datamodel-code-generator` vulnerable to code injection via unescaped carriage return in `--extra-template-data` `comment` field | 高危 | PyPIdatamodel-code-generator | 已审查 | 2026-07-29 05:50 | 2026-07-29 05:50 |
| GHSA-8359-H9FX-J6V9 CVE-2026-55389 | datamodel-code-generator vulnerable to arbitrary local file read via JSON-Schema `$ref` (`file://` and `../` traversal), bypassing `--no-allow-remote-refs` | 高危 | PyPIdatamodel-code-generator | 已审查 | 2026-07-29 05:49 | 2026-07-29 05:49 |
| GHSA-386Q-5HP3-95M9 CVE-2026-54653 | `datamodel-code-generator` vulnerable to code injection in via attacker-controlled `default_factory` schema field | 高危 | PyPIdatamodel-code-generator | 已审查 | 2026-07-29 05:48 | 2026-07-29 05:48 |
| GHSA-VX7X-VCC2-C44G CVE-2026-55391 | datamodel-code-generator vulnerable to SSRF protection bypass via DNS rebinding | 高危 | PyPIdatamodel-code-generator | 已审查 | 2026-07-29 05:45 | 2026-07-29 05:45 |
| GHSA-8M8R-38JM-F355 CVE-2026-54656 | `datamodel-code-generator` vulnerable to code execution on import via unescaped `validators` entries in --extra-template-data | 高危 | PyPIdatamodel-code-generator | 已审查 | 2026-07-29 05:44 | 2026-07-29 05:44 |
| GHSA-954P-556P-R752 CVE-2026-54690 | datamodel-code-generator vulnerable to SSRF via JSON-Schema `$ref` to HTTP URL (silent by default) | 高危 | PyPIdatamodel-code-generator | 已审查 | 2026-07-29 05:42 | 2026-07-29 05:42 |
| GHSA-5578-W22F-PFX9 CVE-2026-55415 | datamodel-code-generator vulnerable to code injection via `x-python-import` / `customTypePath` in generated import statements | 高危 | PyPIdatamodel-code-generator | 已审查 | 2026-07-29 05:40 | 2026-07-29 05:40 |
| GHSA-J884-Q54Q-MMX3 CVE-2026-54621 | `datamodel-code-generator` vulnerable to code injection via unescaped carriage return in GraphQL Union description | 高危 | PyPIdatamodel-code-generator | 已审查 | 2026-07-29 05:35 | 2026-07-29 05:35 |
| GHSA-M34R-V34R-RF9Q CVE-2026-54655 | `datamodel-code-generator` vulnerable to code execution on import via `x-python-type` JSON-Schema extension in datamodel-code-generator | 高危 | PyPIdatamodel-code-generator | 已审查 | 2026-07-29 05:33 | 2026-07-29 05:33 |
| GHSA-R5VV-FF45-PRP2 CVE-2026-55403 | datamodel-code-generator: Authorization / request headers leaked to cross-origin redirect target when fetching remote schemas | 低危 | PyPIdatamodel-code-generator | 已审查 | 2026-07-29 05:32 | 2026-07-29 05:32 |
| GHSA-RFR2-MQ9M-X2QX CVE-2026-54691 | datamodel-code-generator vulnerable to SSRF via --url: no host/IP validation, follows redirects | 高危 | PyPIdatamodel-code-generator | 已审查 | 2026-07-29 05:30 | 2026-07-29 05:30 |
| GHSA-442Q-2J6P-642G CVE-2026-55390 | datamodel-code-generator vulnerable to arbitrary local file read via XSD `schemaLocation` (`xs:include`/`xs:import`) path traversal, with no remote-ref gate | 高危 | PyPIdatamodel-code-generator | 已审查 | 2026-07-29 05:26 | 2026-07-29 05:26 |
| GHSA-6588-8GV4-XFGH CVE-2026-32203 | Microsoft Security Advisory CVE-2026-32203 – .NET and Visual Studio Denial of Service Vulnerability | 高危 | NuGetSystem.Security.Cryptography.Xml | 已审查 | 2026-07-29 05:02 | 2026-07-29 05:02 |
| GHSA-V8VM-CQH8-Q87Q CVE-2026-52888 | NocoBase: Sensitive Data Exposure via SQL Blacklist Bypass | 中危 | npm@nocobase/plugin-collection-sql | 已审查 | 2026-07-29 04:53 | 2026-07-29 04:53 |
| GHSA-2RX5-2G7J-2659 CVE-2026-49446 | Cosmos-Server has an authentication bypass via forward-auth header smuggling on Constellation tunnel | 中危 | Gogithub.com/azukaar/cosmos-server | 已审查 | 2026-07-29 04:44 | 2026-07-29 04:44 |
| GHSA-5FQM-CC34-FCF5 CVE-2026-49447 | Cosmos-Server's constellation public-devices endpoint accepts arbitrary bearer tokens | 中危 | Gogithub.com/azukaar/cosmos-server | 已审查 | 2026-07-29 04:32 | 2026-07-29 04:32 |
| GHSA-R5JH-Q2MW-GCX4 CVE-2026-50568 | Fission: SanitizeFilePath lexical HasPrefix bypass permits sibling-directory escape | 低危 | Gogithub.com/fission/fission | 已审查 | 2026-07-29 04:18 | 2026-07-29 04:18 |