检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-G35J-M5XG-VH3Q CVE-2026-57497 | webtransport-go: Memory Exhaustion Attack due to Buffering of Unknown Capsules | 中危 | Gogithub.com/quic-go/webtransport-go | 已审查 | 2026-07-25 04:49 | 2026-07-25 04:49 |
| GHSA-HQ88-5X99-X3GF CVE-2026-55502 | Cloudreve OAuth Admin.Read scope can update OneDrive storage policy credentials |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 高危 |
Gogithub.com/cloudreve/Cloudreve/v3+1 |
| 已审查 |
| 2026-07-25 04:49 |
| 2026-07-25 04:49 |
| GHSA-W8X7-H2PX-XMQ8 CVE-2026-55499 | Cloudreve: Broken Access Control in file event stream: a single-file share recipient is subscribed to the owner's parent folder and receives activity events for unshared siblings | 中危 | Gogithub.com/cloudreve/Cloudreve/v3+1 | 已审查 | 2026-07-25 04:49 | 2026-07-25 04:49 |
| GHSA-G9J2-8W95-3VWV CVE-2026-55497 | Cloudreve: Denial of Service - Image decompression / pixel bomb in thumbnail & avatar decoding crashes the server | 中危 | Gogithub.com/cloudreve/Cloudreve/v3+1 | 已审查 | 2026-07-25 04:48 | 2026-07-25 04:48 |
| GHSA-8R7F-R8HJ-R3RV CVE-2026-55496 | Cloudreve: Information Exposure in `GET /api/v4/user/search`: `SearchActive` omits the active-status predicate, leaking inactive/banned account emails | 中危 | Gogithub.com/cloudreve/Cloudreve/v3+1 | 已审查 | 2026-07-25 04:46 | 2026-07-25 04:46 |
| GHSA-49H3-CWHJ-4737 CVE-2026-55495 | Cloudreve: Path Traversal in WOPI PUT_RELATIVE Allows Arbitrary File Creation in Owner Account | 中危 | Gogithub.com/cloudreve/Cloudreve/v3+1 | 已审查 | 2026-07-25 04:41 | 2026-07-25 04:41 |
| GHSA-6V4J-43GG-VJ32 CVE-2026-55404 | yt-dlp: Downstream command injection via improper sanitization of yt-dlp --write-link output | 高危 | PyPIyt-dlp | 已审查 | 2026-07-25 04:35 | 2026-07-25 04:35 |
| GHSA-GH7P-78X6-JW6M CVE-2026-59222 | Open WebUI: /api/v1/channels/{id}/members exposes full user model including sensitive credentials | 中危 | PyPIopen-webui | 已审查 | 2026-07-25 01:04 | 2026-07-25 01:04 |
| GHSA-73X5-H92W-XC2J CVE-2026-59215 | Open WebUI: Private channel messages can be disclosed through cross-channel thread parent_id binding | 低危 | PyPIopen-webui | 已审查 | 2026-07-25 01:04 | 2026-07-25 01:04 |
| GHSA-3WP3-XXJ9-5JQQ CVE-2026-59213 | Open WebUI: Cross-user model-list exposure via static cache key in get_all_models (aiocache key= vs key_builder= misuse) | 低危 | PyPIopen-webui | 已审查 | 2026-07-25 01:03 | 2026-07-25 01:03 |
| GHSA-7R7X-GJVR-448G CVE-2026-59217 | Open WebUI: Upload `metadata.knowledge_id` bypasses the knowledge-base write-access check (read-only users can add files to KB) | 中危 | PyPIopen-webui | 已审查 | 2026-07-25 01:02 | 2026-07-25 01:02 |
| GHSA-74H3-CXQ7-VC5Q CVE-2026-59216 | Open WebUI: Cross-user code-interpreter and tool execution via unvalidated Socket.IO event-caller session_id | 高危 | PyPIopen-webui | 已审查 | 2026-07-25 01:01 | 2026-07-25 01:01 |
| GHSA-X2FF-V5V8-M75M CVE-2026-59714 | Open WebUI: Cross-channel message overwrite via chat completion API (single-model and multimodel message_ids) | 高危 | PyPIopen-webui | 已审查 | 2026-07-25 01:01 | 2026-07-25 01:01 |
| GHSA-855V-HQ7W-JMJW CVE-2026-59219 | Open WebUI: Realtime endpoints accept Redis-revoked JWTs after signout/backchannel logout | 高危 | PyPIopen-webui | 已审查 | 2026-07-25 01:00 | 2026-07-25 01:00 |
| GHSA-GMFW-G93R-VG53 CVE-2026-59715 | Open WebUI: Unauthenticated WebSocket Access to Collaborative Document Handlers (ydoc:awareness:update, ydoc:document:leave) | 低危 | PyPIopen-webui | 已审查 | 2026-07-25 00:59 | 2026-07-25 00:59 |
| GHSA-RQJ7-6WRP-6G2G CVE-2026-59227 | Open WebUI: POST /api/v1/images/edit bypasses the global image-edit switch and the per-user image-generation permission | 中危 | PyPIopen-webui | 已审查 | 2026-07-25 00:58 | 2026-07-25 00:58 |
| GHSA-FFPJ-XV5C-P3GW CVE-2026-59220 | Open WebUI: ReDoS in skill-mention regexes causes whole-instance DoS on default config | 中危 | PyPIopen-webui | 已审查 | 2026-07-25 00:55 | 2026-07-25 00:55 |
| GHSA-MVX4-532P-XFM9 CVE-2026-59226 | Open WebUI: Scheduled automations continue after pending-user deactivation and stored model ACL revocation | 低危 | PyPIopen-webui | 已审查 | 2026-07-25 00:55 | 2026-07-25 00:55 |
| GHSA-7RW5-9F7Q-XJ36 CVE-2026-59218 | Open WebUI: Account enumeration via observable login timing discrepancy | 中危 | PyPIopen-webui | 已审查 | 2026-07-25 00:55 | 2026-07-25 00:55 |
| GHSA-4R2P-27MH-5M22 CVE-2026-59214 | Open WebUI: Stored web worker XSS via Pyodide | 高危 | PyPIopen-webui | 已审查 | 2026-07-25 00:54 | 2026-07-25 00:54 |
| GHSA-7835-87Q9-RGVV CVE-2026-55607 | Claude Code: Sandbox Escape via Git Worktree Path Confusion Allows Unsandboxed Code Execution | 高危 | npm@anthropic-ai/claude-code | 已审查 | 2026-07-25 00:54 | 2026-07-25 00:54 |
| GHSA-V74W-7MR3-4QG3 CVE-2026-73507 | Netty: Denial of Service in XmlFrameDecoder via CPU Exhaustion | 高危 | Mavenio.netty:netty-codec-xml | 已审查 | 2026-07-25 00:53 | 2026-08-13 22:25 |
| GHSA-MFG7-5GFP-C4W3 CVE-2026-73508 | Netty: Memory Leak in DNS Record Decoder via Malformed Domain Names | 中危 | Mavenio.netty:netty-codec-dns | 已审查 | 2026-07-25 00:52 | 2026-08-13 22:27 |
| GHSA-R277-6W6Q-XMQW | kin-openapi: ValidationHandler.Load() Fail-Open Authentication Bypass via NoopAuthenticationFunc Default | 严重 | Gogithub.com/getkin/kin-openapi | 已审查 | 2026-07-25 00:52 | 2026-07-25 00:52 |
| GHSA-GCJH-H69Q-9W9G | cel-go: JSON Private Fields Exposed via NativeTypes and ParseStructTag | 中危 | Gogithub.com/google/cel-go | 已审查 | 2026-07-25 00:48 | 2026-07-25 00:48 |