检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-46Q4-43PH-C6FR CVE-2026-73495 | blaze: Chunked-body trailer fields promoted into Request.headers in blaze-server (front-end header-sanitization bypass) | 高危 | Mavenorg.http4s:blaze-http_2.12+2 | 已审查 | 2026-07-25 06:26 | 2026-08-13 05:12 |
| GHSA-MHVJ-JHPQ-885V CVE-2026-73494 |
当前筛选结果 35,190 条 · 时间按北京时间显示
blaze: Multiple HTTP/1.1 request-smuggling primitives in blaze's Java wire parser |
| 高危 |
Mavenorg.http4s:blaze-http_2.13+2 |
| 已审查 |
| 2026-07-25 06:26 |
| 2026-08-13 05:12 |
| GHSA-CMWH-G2H8-C222 | Poweradmin: OIDC `sub` collation bypass in Poweradmin leading to account takeover | 高危 | Packagistpoweradmin/poweradmin | 已审查 | 2026-07-25 05:56 | 2026-07-25 05:56 |
| GHSA-RM67-G9CH-VXFF | Poweradmin: Broken access control (IDOR): any zone owner can modify DNS records in zones they do not own | 高危 | Packagistpoweradmin/poweradmin | 已审查 | 2026-07-25 05:55 | 2026-07-25 05:55 |
| GHSA-H4HF-V6W5-897X | Poweradmin: API user-update endpoint leads to a non-admin reset any user's password and take over the superuser account | 高危 | Packagistpoweradmin/poweradmin | 已审查 | 2026-07-25 05:54 | 2026-07-25 05:54 |
| GHSA-F25V-X6VR-962G | Pheditor: Authentication Bypass in Forced Password-Change Flow via Unverified Current Password | 严重 | Packagistpheditor/pheditor | 已审查 | 2026-07-25 05:54 | 2026-07-25 05:54 |
| GHSA-MH99-V99M-4GVG CVE-2026-14257 | brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash | 高危 | npmbrace-expansion | 已审查 | 2026-07-25 05:53 | 2026-08-01 03:37 |
| GHSA-Q3G2-M552-3R9C CVE-2026-64785 | swift-nio-http2: Missing CR/LF/NUL validation in header values | 中危 | SwiftURLswift-nio-http2 | 已审查 | 2026-07-25 05:52 | 2026-07-25 05:52 |
| GHSA-VH45-F885-3848 CVE-2026-73567 | sm-crypto: Predictable SM2 key generation in Node.js: default RNG uses Math.random + wall clock | 严重 | npmsm-crypto | 已审查 | 2026-07-25 05:50 | 2026-08-14 01:41 |
| GHSA-V6W6-358X-2433 | Cloudreve Admin.Read OAuth tokens can trigger server-side node test requests | 中危 | Gogithub.com/cloudreve/Cloudreve/v3+1 | 已审查 | 2026-07-25 05:50 | 2026-07-25 05:50 |
| GHSA-47W6-GWP4-W6VC CVE-2026-73652 | vantage6: Algorithm developer can edit another developer's algorithm that is pending / under review | 高危 | PyPIvantage6 | 已审查 | 2026-07-25 05:49 | 2026-08-14 02:16 |
| GHSA-2625-RW7M-5Q5X | Hubuum client library (Rust): Sensitive data may be exposed through default diagnostics | 低危 | crates.iohubuum_client | 已审查 | 2026-07-25 05:49 | 2026-07-25 05:49 |
| GHSA-QQC3-94QV-7FW3 | Hubuum client library (Rust): Configured custom transports may be bypassed, exposing credentials and network traffic | 中危 | crates.iohubuum_client | 已审查 | 2026-07-25 05:49 | 2026-07-25 05:49 |
| GHSA-F45Q-W629-WR25 | Hubuum client library (Rust): Authenticated requests may escape the configured base path through redirects | 中危 | crates.iohubuum_client | 已审查 | 2026-07-25 05:48 | 2026-07-25 05:48 |
| GHSA-26GQ-P25F-99CP CVE-2026-73564 | frp: Unauthenticated Remote Denial of Service in the frp SSH Tunnel Gateway via Integer Overflow | 高危 | Gogithub.com/fatedier/frp | 已审查 | 2026-07-25 05:48 | 2026-08-14 01:35 |
| GHSA-G5VV-Q72C-7J78 CVE-2026-73561 | @anephenix/hub: Unauthenticated WebSocket RPC Waiter Resource Exhaustion | 高危 | npm@anephenix/hub | 已审查 | 2026-07-25 05:47 | 2026-08-14 01:24 |
| GHSA-C534-2W9C-X7FM | Kite Kubernetes proxy path traversal allows authenticated users to bypass RBAC and read cluster-wide resources | 中危 | Gogithub.com/zxh326/kite | 已审查 | 2026-07-25 05:47 | 2026-07-25 05:47 |
| GHSA-P279-2CQP-84JG CVE-2026-73644 | OpenDJ SASL PLAIN authzid bypassing the proxy ACI scope check | 严重 | Mavenorg.openidentityplatform.opendj:opendj-server-legacy | 已审查 | 2026-07-25 05:46 | 2026-08-14 01:52 |
| GHSA-68R5-9HPG-7QW9 | OpenDJ unauthenticated SSRF, local file read and unbounded-read DoS in the DSMLv2 gateway | 严重 | Mavenorg.openidentityplatform.opendj:opendj-dsml-servlet | 已审查 | 2026-07-25 05:46 | 2026-07-25 05:46 |
| GHSA-G3HQ-HPHG-8FHH | Pheditor: Terminal command-allowlist bypass via argument injection leads to RCE — surviving vector after the metacharacter-sanitization fixes | 高危 | Packagistpheditor/pheditor | 已审查 | 2026-07-25 05:45 | 2026-07-25 05:45 |
| GHSA-94P4-4CQ8-9G67 | GitPython: Environment-variable exfiltration via Repo.create_remote() / Remote.add() URL (incomplete fix of GHSA-rwj8-pgh3-r573) | 高危 | PyPIGitPython | 已审查 | 2026-07-25 05:45 | 2026-07-25 05:45 |
| GHSA-HFHX-W8P8-4HC7 CVE-2026-73307 | Budibase: SSRF via bare fetch() in uploadUrl during AI table generation | 中危 | npm@budibase/server | 已审查 | 2026-07-25 05:44 | 2026-08-13 02:59 |
| GHSA-V42F-V8XC-J435 CVE-2026-73410 | Budibase: SSRF via DNS rebinding in the REST datasource integration | 高危 | npm@budibase/server | 已审查 | 2026-07-25 05:44 | 2026-08-13 03:22 |
| GHSA-PMPG-2MXQ-6XWR | Budibase: NoSQL injection in MongoDB integration: collection dump, $where JS exec, cross-collection pivot, arbitrary update/delete | 高危 | npm@budibase/server | 已审查 | 2026-07-25 05:43 | 2026-07-25 05:43 |
| GHSA-CR7P-CR3Q-H5CM CVE-2026-73306 | Budibase: Account Enumeration via Login Lockout Response Differential | 中危 | npm@budibase/server | 已审查 | 2026-07-25 05:43 | 2026-08-13 02:56 |