检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-Q6VM-XQC9-V3FF CVE-2026-50567 | Fission: Zip Slip in pkg/utils/zip.go:Unarchive allows fetcher to write outside the destination directory | 高危 | Gogithub.com/fission/fission | 已审查 | 2026-07-29 04:16 | 2026-07-29 04:16 |
| GHSA-VCHH-R53J-8MPW CVE-2026-50569 |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 中危 |
Gogithub.com/fission/fission |
| 已审查 |
| 2026-07-29 04:16 |
| 2026-07-29 04:16 |
| GHSA-QF5V-M7P4-95RP CVE-2026-50570 | Fission: Incomplete capability denylist in Environment/Function PodSpec validation allows tenant-added CAP_SYS_TIME and cross-tenant node wall-clock corruption | 高危 | Gogithub.com/fission/fission | 已审查 | 2026-07-29 04:12 | 2026-07-29 04:12 |
| GHSA-3FCR-JVGP-7F58 CVE-2026-54635 | pytonapi has a Webhook Custom Path Authentication Bypass | 高危 | PyPIpytonapi | 已审查 | 2026-07-29 01:09 | 2026-08-12 06:10 |
| GHSA-28GM-JRMW-XX93 CVE-2026-54632 | SIPSorcery: Malformed UDP packet on the RTP/ICE socket can remotely terminate a media session (DoS) | 高危 | NuGetSIPSorcery | 已审查 | 2026-07-29 01:01 | 2026-07-29 01:01 |
| GHSA-3735-5339-XFWX CVE-2026-54588 | Poweradmin has Host Header Injection in OIDC redirect_uri, SAML ACS/SLO URL, and Logout Redirect Construction. | 严重 | Packagistpoweradmin/poweradmin | 已审查 | 2026-07-29 00:40 | 2026-07-29 00:40 |
| GHSA-85RG-P3FR-XC2F CVE-2026-54609 | QTINeon has unauthenticated relay-to-host amplification via unbounded RECONNECT_REQUEST forwarding | 高危 | Mavencom.quietterminal:qti-neon+1 | 已审查 | 2026-07-29 00:36 | 2026-07-29 00:36 |
| GHSA-PP92-CRG2-GFV9 CVE-2026-54603 | OAuth2::Client#request: Protocol-relative redirect Location overrides authority, leaking bearer Authorization to attacker host | 高危 | RubyGemsoauth2 | 已审查 | 2026-07-29 00:32 | 2026-07-29 00:32 |
| GHSA-PRQ8-7WVH-44QH CVE-2026-54605 | OAuth: Cross-origin token-request redirects can expose signed request metadata | 高危 | RubyGemsoauth | 已审查 | 2026-07-29 00:27 | 2026-07-29 00:27 |
| GHSA-J7FR-3V8C-3QC3 CVE-2026-54620 | sqlite3-ruby has Use-After-Free in SQLite Aggregate Function Callbacks | 低危 | RubyGemssqlite3+1 | 已审查 | 2026-07-29 00:23 | 2026-07-29 00:23 |
| GHSA-28HH-PR2H-2W89 CVE-2026-54619 | sqlite3-ruby has Use-After-Free When Redefining SQLite Functions with Different Arity | 低危 | RubyGemssqlite3+1 | 已审查 | 2026-07-29 00:21 | 2026-07-29 00:21 |
| GHSA-G6V3-7XMC-W563 CVE-2026-54332 | GoPacket's sFlow ExtendedGatewayFlow decoder: unbounded attacker-controlled allocation (104-byte UDP datagram -> up to 16 GiB make) -> unauthenticated remote DoS | 中危 | Gogithub.com/gopacket/gopacket | 已审查 | 2026-07-29 00:17 | 2026-07-29 00:17 |
| GHSA-6R28-9PPF-4HJ5 CVE-2026-54345 | GoPacket's Diameter AVP decoder: uint32 underflow on vendor header size leads to unbounded ~4 GiB allocation (unauthenticated remote DoS) | 中危 | Gogithub.com/gopacket/gopacket | 已审查 | 2026-07-29 00:14 | 2026-07-29 00:14 |
| GHSA-HC4M-Q9JH-XW4J | nono-cli'scregistry pack verification can fail open when provenance metadata is absent | 中危 | crates.ionono-cli | 已审查 | 2026-07-28 23:51 | 2026-07-28 23:51 |
| GHSA-8R6W-3QQ5-4P4R CVE-2026-54593 | Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions | 高危 | Gogithub.com/pterodactyl/wings+1 | 已审查 | 2026-07-28 23:43 | 2026-07-28 23:43 |
| GHSA-VG6V-J97M-H5XQ | @novu/application-generic: `validateUrlSsrf` permits CGNAT (100.64.0.0/10) destinations — affects Workflow HTTP request step + Webhook filter condition | 中危 | npm@novu/application-generic | 已审查 | 2026-07-28 22:59 | 2026-07-28 22:59 |
| GHSA-XVC3-826V-XF47 CVE-2026-61609 | Pterodactyl's shared global rate-limit key on login and 2FA checkpoint enables unauthenticated panel-wide authentication lockout (DoS) | 高危 | Packagistpterodactyl/panel | 已审查 | 2026-07-28 22:57 | 2026-07-28 22:57 |
| GHSA-4R9R-4425-74P7 CVE-2026-55771 | Cedar-Java has policy injection, type confusion, and incorrect equality comparison vulnerabilities | 高危 | Mavencom.cedarpolicy:cedar-java | 已审查 | 2026-07-28 22:50 | 2026-07-28 22:50 |
| GHSA-7WPJ-VVMV-PGM8 CVE-2026-54545 | @wakaru/cli arbitrary file write during bundle unpack | 高危 | npm@wakaru/cli | 已审查 | 2026-07-28 22:44 | 2026-07-28 22:44 |
| GHSA-W4Q6-QW23-4RG7 CVE-2026-47427 | GitHub MCP Server has Nil Pointer Dereference DoS in completion/complete Handler | 高危 | Gogithub.com/github/github-mcp-server | 已审查 | 2026-07-28 22:35 | 2026-07-28 22:35 |
| GHSA-4PJ9-G833-QX53 CVE-2026-46428 | lettre has TLS hostname verification disabled when using Boring TLS backend | 严重 | crates.iolettre | 已审查 | 2026-07-28 22:29 | 2026-07-28 22:29 |
| GHSA-3PWP-G2MJ-5P3V CVE-2026-45293 | WordPress Coding Standards (WordPressCS) contains an arbitrary code execution vulnerability | 高危 | Packagistwp-coding-standards/wpcs | 已审查 | 2026-07-28 22:28 | 2026-07-28 22:28 |
| GHSA-28F5-38XR-JH2W CVE-2026-43910 | java-client Allows Network Pivot via Unvalidated directConnect Redirect in AppiumCommandExecutor | 高危 | Mavenio.appium:java-client | 已审查 | 2026-07-28 22:26 | 2026-07-28 22:26 |
| GHSA-HP74-GM6M-2QM5 | Pocket ID has a reauthentication bypass via one-time access token login — passkey step-up requirement defeated by JWT freshness check that accepts any login method | 中危 | Gogithub.com/pocket-id/pocket-id/backend | 已审查 | 2026-07-28 22:25 | 2026-07-28 22:25 |
| GHSA-W6P7-2FXX-4F44 CVE-2026-43983 | Pocket ID: OIDC refresh token flow bypasses authorization revocation, account disabling, and group restrictions | 高危 | Gogithub.com/pocket-id/pocket-id/backend | 已审查 | 2026-07-28 22:12 | 2026-07-28 22:12 |