检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-4J38-RW27-97GX CVE-2023-37465 | org.xwiki.contrib:discussions-server has Cross-Site Request Forgery (CSRF) issue that makes it possible to delete messages | 中危 | Mavenorg.xwiki.contrib:discussions-server | 已审查 | 2026-07-28 01:04 | 2026-07-28 01:04 |
| GHSA-HWRJ-9RR4-24XH CVE-2026-66053 |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 中危 |
PyPIthrift |
| 已审查 |
| 2026-07-27 20:31 |
| 2026-09-02 22:31 |
| GHSA-8WV5-X4W7-5GWW CVE-2026-43871 | Apache Thrift Python, Go, PHP and Java bindings have an Infinite Loop | 高危 | Goapache/thrift+3 | 已审查 | 2026-07-27 20:31 | 2026-09-02 22:31 |
| GHSA-6PJX-3PJC-MRJ8 CVE-2026-41608 | Apache Thrift Python bindings have an Improper Handling of Highly Compressed Data (Data Amplification) vulnerability | 高危 | PyPIthrift | 已审查 | 2026-07-27 20:31 | 2026-09-02 01:03 |
| GHSA-848C-C2CX-J7QX CVE-2025-71408 | NLTK vulnerable to Eval Injection via collocations CLI arguments | 高危 | PyPInltk | 已审查 | 2026-07-25 08:31 | 2026-08-13 03:30 |
| GHSA-6VCH-Q96H-7GC3 CVE-2026-73500 | etcd: `tlsListener.acceptLoop` spawns unbounded handshake goroutines with no deadline | 高危 | Gogo.etcd.io/etcd/v3 | 已审查 | 2026-07-25 06:40 | 2026-08-13 05:22 |
| GHSA-8Q49-2H5H-434X | FrontMCP: Server-Side Request Forgery (SSRF) in the OpenAPI adapter spec-change poller | 中危 | npm@frontmcp/adapters | 已审查 | 2026-07-25 06:40 | 2026-07-25 06:40 |
| GHSA-JPCW-4WR7-C3VQ CVE-2026-73502 | kin-openapi openapi3filter: unauthenticated nil-pointer panic when validating a request against a `content` parameter whose media type has no schema | 中危 | Gogithub.com/getkin/kin-openapi | 已审查 | 2026-07-25 06:39 | 2026-08-13 05:25 |
| GHSA-J6G5-3HH3-PGW8 CVE-2026-16796 | AWS Bedrock AgentCore: Improper neutralization of argument delimiters in the Python SDK install_packages() | 高危 | PyPIbedrock-agentcore | 已审查 | 2026-07-25 06:38 | 2026-07-25 06:38 |
| GHSA-XG4H-6GFC-H4M8 CVE-2026-73499 | etcd: Watch API authorization bypass via open-ended range requests | 高危 | Gogo.etcd.io/etcd/v3 | 已审查 | 2026-07-25 06:38 | 2026-08-13 05:20 |
| GHSA-JVXP-QMX7-GJPX CVE-2026-16756 | Smithy-RS: Allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service | 高危 | crates.ioaws-smithy-http-server | 已审查 | 2026-07-25 06:37 | 2026-07-25 06:37 |
| GHSA-HMJ8-5XMH-5573 CVE-2026-73568 | libp2p: yamux connection DoS via oversized data frame | 高危 | PyPIlibp2p | 已审查 | 2026-07-25 06:37 | 2026-08-14 01:43 |
| GHSA-3R53-75J5-3G7J CVE-2026-73647 | Quasar: Prototype pollution in the extend() utility | 中危 | npmquasar | 已审查 | 2026-07-25 06:36 | 2026-08-14 01:57 |
| GHSA-6XJ8-QV9J-XCJQ CVE-2026-73505 | Oh My Posh: Arbitrary command execution via template injection in the path segment | 高危 | Gogithub.com/jandedobbeleer/oh-my-posh | 已审查 | 2026-07-25 06:36 | 2026-08-13 22:22 |
| GHSA-FWJX-9P69-H25H CVE-2026-73506 | Oh My Posh: Terminal escape sequence injection via unsanitized prompt segment data | 中危 | Gogithub.com/jandedobbeleer/oh-my-posh | 已审查 | 2026-07-25 06:35 | 2026-08-13 22:23 |
| GHSA-FP43-VJ7G-PG92 | OmniFaces: Forged combined-resource IDs and related output/push boundaries | 高危 | Mavenorg.omnifaces:omnifaces | 已审查 | 2026-07-25 06:35 | 2026-07-25 06:35 |
| GHSA-GM3R-Q2WP-HW87 CVE-2026-73413 | Shescape: Quadratic-time denial of service in the flag-protection | 高危 | npmshescape | 已审查 | 2026-07-25 06:35 | 2026-08-13 03:40 |
| GHSA-Q53C-4PRM-W95Q CVE-2026-73411 | Shescape: Home-directory disclosure in assignment context on Unix with Dash | 中危 | npmshescape | 已审查 | 2026-07-25 06:34 | 2026-08-13 03:33 |
| GHSA-W4HW-QCX7-56PR CVE-2026-73414 | Shescape: Shell injection via unescaped parentheses on Windows with CMD | 严重 | npmshescape | 已审查 | 2026-07-25 06:34 | 2026-08-13 03:43 |
| GHSA-6V4M-FW66-8R4X CVE-2026-73412 | Shescape: Path disclosure on Unix with Zsh | 中危 | npmshescape | 已审查 | 2026-07-25 06:33 | 2026-08-13 03:38 |
| GHSA-29W2-FQ35-V728 CVE-2026-16584 | AWS API MCP Server Security Policy Bypass via Startup Initialization Failure | 高危 | PyPIawslabs.aws-api-mcp-server | 已审查 | 2026-07-25 06:33 | 2026-07-25 06:33 |
| GHSA-86CX-WWF4-PHQ4 CVE-2026-69160 | OpenList: Arbitrary File Read via Path Prefix Confusion in Share Creation API | 中危 | Gogithub.com/OpenListTeam/OpenList/v4 | 已审查 | 2026-07-25 06:32 | 2026-08-19 02:04 |
| GHSA-P6PH-3JX2-3337 | OpenList: Search metadata/count disclosure via Non-Separator-Aware Path Check in Bleve Search | 中危 | Gogithub.com/OpenListTeam/OpenList/v4 | 已审查 | 2026-07-25 06:32 | 2026-07-25 06:32 |
| GHSA-95CV-R8X4-VH75 CVE-2026-73509 | OpenList: Authenticated users can rename files outside their base path via batch rename `src_name` traversal | 高危 | Gogithub.com/OpenListTeam/OpenList/v4 | 已审查 | 2026-07-25 06:29 | 2026-08-13 22:31 |
| GHSA-7PPR-R889-MCF2 CVE-2026-73493 | blaze: Unbounded WebSocket message aggregation in http4s-blaze-server | 高危 | Mavenorg.http4s:http4s-blaze-server_2.12+2 | 已审查 | 2026-07-25 06:28 | 2026-08-13 05:08 |