检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-PM4M-PH32-GHV5 CVE-2026-73643 | js-yaml: Exponential parsing time in flow collections leads to denial of service | 高危 | npmjs-yaml | 已审查 | 2026-07-25 00:47 | 2026-08-14 01:47 |
| GHSA-G9HV-X236-4QP3 CVE-2026-73429 | Russh: client wrong-length X25519 `clone_from_slice` panic (pre-auth DoS) |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 中危 |
crates.iorussh |
| 已审查 |
| 2026-07-25 00:47 |
| 2026-08-13 04:53 |
| GHSA-CQJC-RMPQ-XPRQ CVE-2026-73489 | Russh: Post-auth remote panic via pty-req with more than 130 terminal-mode records | 中危 | crates.iorussh | 已审查 | 2026-07-25 00:46 | 2026-08-13 04:56 |
| GHSA-5XVQ-CP9X-6P6R CVE-2026-73430 | Russh: Pre-auth remote panic via all-zero Curve25519 peer public value (encode_mpint OOB) | 中危 | crates.iorussh | 已审查 | 2026-07-25 00:45 | 2026-08-13 04:55 |
| GHSA-QWWW-VCR4-C8H2 | React Router: RSC Mode CSRF Bypass Allows Action Execution Before 400 Response | 高危 | npmreact-router | 已审查 | 2026-07-25 00:44 | 2026-08-08 02:16 |
| GHSA-464C-974J-9XM6 | AWS CDK CodeBuild S3 Log Encryption Boolean Inversion | 低危 | Go@aws-cdk/aws-codebuild+8 | 已审查 | 2026-07-25 00:44 | 2026-07-25 00:44 |
| GHSA-8PVW-JCV7-9CMJ CVE-2026-7120 | @fastify/static vulnerable to Authorization Bypass via Non-Canonical URL Paths | 中危 | npm@fastify/static | 已审查 | 2026-07-25 00:43 | 2026-07-25 00:43 |
| GHSA-83W8-P2F5-377R CVE-2026-15074 | @fastify/static vulnerable to route guard bypass via path traversal | 高危 | npm@fastify/static | 已审查 | 2026-07-25 00:43 | 2026-07-25 00:43 |
| GHSA-R9MR-M37C-5FR3 | GitPython: Unsafe git option guard bypass via single-character kwarg value token smuggling enables arbitrary command execution | 高危 | PyPIGitPython | 已审查 | 2026-07-25 00:42 | 2026-07-25 00:42 |
| GHSA-6P8H-3WGX-97GF | GitPython: Incomplete unsafe_git_clone_options denylist omits --template enabling arbitrary command execution via clone hooks | 高危 | PyPIGitPython | 已审查 | 2026-07-25 00:42 | 2026-07-25 00:42 |
| GHSA-FJR4-X663-MWXC | GitPython: Arbitrary file overwrite via git diff --output argument injection in Diffable.diff (key- and value-controlled) | 高危 | PyPIGitPython | 已审查 | 2026-07-25 00:41 | 2026-07-25 00:41 |
| GHSA-R292-9MHP-454M CVE-2026-73566 | node-tar: Uncontrolled recursion in mapHas/filesFilter allows uncatchable stack-overflow DoS via crafted long-path tar with member selection | 高危 | npmtar | 已审查 | 2026-07-25 00:26 | 2026-08-22 03:08 |
| GHSA-R28C-9Q8G-F849 CVE-2026-73646 | PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosure | 高危 | npmpostcss | 已审查 | 2026-07-25 00:24 | 2026-08-14 01:55 |
| GHSA-W28W-GP39-M4P6 | Prompty: Server-Side Template Injection to Remote Code Execution in the @prompty/core Nunjucks Renderer | 严重 | npm@prompty/core | 已审查 | 2026-07-25 00:23 | 2026-07-25 00:23 |
| GHSA-664H-WQGQ-64GW CVE-2026-73562 | Mongoose: Prototype pollution in mongoose update casting via __proto__-prefixed dotted path (Schema._getSchema/path getter) | 中危 | npmmongoose | 已审查 | 2026-07-25 00:22 | 2026-08-14 01:27 |
| GHSA-3RP5-JJMW-4WV2 | GitPython: git-config section-name injection enables arbitrary config directives (core.sshCommand RCE) | 高危 | PyPIgitpython | 已审查 | 2026-07-25 00:22 | 2026-07-25 00:22 |
| GHSA-7GFH-X38P-PRH3 CVE-2026-73649 | Velocity.js: Remote Code Execution via property-read to Function constructor (bypass of GHSA-j658-c2gf-x6pq fix) | 严重 | npmvelocityjs | 已审查 | 2026-07-25 00:21 | 2026-08-14 02:05 |
| GHSA-38HQ-7X33-PHP4 CVE-2026-73563 | @backstage/plugin-auth-backend: Unauthenticated OAuth account takeover via `redirect_uri` allowlist bypass | 中危 | npm@backstage/plugin-auth-backend | 已审查 | 2026-07-25 00:20 | 2026-08-14 01:32 |
| GHSA-H22J-F9XW-XJJM CVE-2026-62946 | ImageMagick: Integer Overflow in JNX decoder causes heap buffer over-write when processing extremly large files on 32-bit builds | 中危 | NuGetMagick.NET-Q16-AnyCPU+5 | 已审查 | 2026-07-25 00:20 | 2026-07-25 00:20 |
| GHSA-422R-8C97-XCG4 CVE-2026-62363 | ImageMagick: Heap Buffer Over-Write in fx operation | 中危 | NuGetMagick.NET-Q16-AnyCPU+16 | 已审查 | 2026-07-25 00:20 | 2026-07-25 00:20 |
| GHSA-F5M7-CQGW-8HM7 CVE-2026-62343 | ImageMagick: Heap Buffer Over-Write in morphology operation when an invalid kernel is provided | 中危 | NuGetMagick.NET-Q16-AnyCPU+16 | 已审查 | 2026-07-25 00:19 | 2026-07-25 00:19 |
| GHSA-9XWG-3R6F-JCX2 CVE-2026-61632 | PyMdown Extensions: Path traversal in the b64 extension lets <img src> read files outside base_path | 中危 | PyPIpymdown-extensions | 已审查 | 2026-07-25 00:18 | 2026-07-25 00:18 |
| GHSA-53G2-MVCC-Q9X3 CVE-2026-73428 | Trix: Stored XSS via HTMLParser attribute injection on paste | 中危 | npmaction_text-trix+1 | 已审查 | 2026-07-25 00:18 | 2026-08-13 04:52 |
| GHSA-P5RM-JG5C-8C77 CVE-2026-73851 | Microsoft Kiota: Path traversal in generated plugin manifest static_template.file reference (percent-encoding bypass) | 中危 | NuGetMicrosoft.OpenApi.Kiota | 已审查 | 2026-07-25 00:14 | 2026-08-17 23:11 |
| GHSA-5QJJ-4XWW-7PHC CVE-2026-59952 | Valibot: record() issue paths can make flatten() throw for inherited Object property names | 中危 | npmvalibot | 已审查 | 2026-07-25 00:14 | 2026-07-25 00:14 |