检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-4MJR-XMP4-GH2G CVE-2026-82417 | qs: Denial of Service via Attacker Controlled isBuffer | 中危 | npmqs | 已审查 | 2026-09-02 22:45 | 2026-09-02 22:45 |
| GHSA-CP6Q-959Q-F8RH | Tiptap: mergeAttributes() turns an own __proto__ key into inherited executable DOM attributes |
当前筛选结果 35,190 条 · 时间按北京时间显示
npm@tiptap/core |
| 已审查 |
| 2026-09-02 22:44 |
| 2026-09-02 22:44 |
| GHSA-G2FM-8HR4-J82H CVE-2026-81892 | EasyAdmin custom-action dispatcher bypasses access_control on other routes | 高危 | Packagisteasycorp/easyadmin-bundle | 已审查 | 2026-09-02 22:39 | 2026-09-02 22:39 |
| GHSA-G3HC-697W-WM82 CVE-2026-81887 | Livewire DOM-based cross-site scripting during client-side state handling | 中危 | Packagistlivewire/livewire | 已审查 | 2026-09-02 22:38 | 2026-09-02 22:38 |
| GHSA-MPF4-983Q-P7J4 CVE-2026-82397 | Tornado: Urlencoded body parsing omits max_num_fields, so one request can stall the event loop | 高危 | PyPItornado | 已审查 | 2026-09-02 22:38 | 2026-09-02 22:38 |
| GHSA-X8WG-4XGC-VR54 CVE-2026-71492 | Banks: Path traversal in `DirectoryPromptRegistry.set()` allows arbitrary file write outside the registry root | 中危 | PyPIbanks | 已审查 | 2026-09-02 22:38 | 2026-09-02 22:38 |
| GHSA-FC8X-2RWW-XW9M CVE-2026-82398 | pypdf: Inefficient handling of non-whitespace inputs in read_until_whitespace | 中危 | PyPIpypdf | 已审查 | 2026-09-02 22:38 | 2026-09-02 22:38 |
| GHSA-GXMJ-R5RF-GGWQ CVE-2026-81891 | elFinder: ZIP extraction bypasses uploadDeny MIME filter allowing PHP file upload (RCE) | 高危 | PackagistStudio-42/elFinder | 已审查 | 2026-09-02 22:37 | 2026-09-03 04:21 |
| GHSA-9HJF-W35W-6VX2 CVE-2026-81890 | elFinder: CSRF in netmount allows forced FTP mounts and server-side FTP connections | 中危 | Packagiststudio-42/elfinder | 已审查 | 2026-09-02 22:37 | 2026-09-02 22:37 |
| GHSA-C59Q-G84Q-2GJ5 CVE-2026-82392 | pnpm: Virtual store linker path traversal via unvalidated depPath name in lockfileToDepGraph | 高危 | npmpnpm | 已审查 | 2026-09-02 22:37 | 2026-09-02 22:37 |
| GHSA-VQ4V-J7R6-JQ4M CVE-2026-82393 | pnpm: A tarball dependency's manifest `name` escapes node_modules → arbitrary file write/overwrite on install | 高危 | npmpnpm | 已审查 | 2026-09-02 22:36 | 2026-09-02 22:36 |
| GHSA-WW6M-CW3F-Q94G CVE-2026-81722 | NLTK: Quadratic-time DoS in PorterStemmer via long runs of 'y' | 中危 | PyPInltk | 已审查 | 2026-09-02 22:36 | 2026-09-02 22:36 |
| GHSA-F794-5JV7-7672 CVE-2026-81727 | NLTK: Downloader.download follows hardlinks and overwrites outside-root files | 中危 | PyPInltk | 已审查 | 2026-09-02 22:35 | 2026-09-02 22:35 |
| GHSA-8MGP-746C-J5XP CVE-2026-81726 | NLTK: Model-artifact APIs bypass pathsec and touch files outside allowed roots | 高危 | PyPInltk | 已审查 | 2026-09-02 22:35 | 2026-09-02 22:35 |
| GHSA-VP2X-QP44-57V7 CVE-2026-81723 | NLTK: Quadratic CPU Exhaustion in `XMLCorpusView._read_xml_fragment()` | 中危 | PyPInltk | 已审查 | 2026-09-02 22:34 | 2026-09-02 22:34 |
| GHSA-FF5C-CP5C-9WJF CVE-2026-12876 | NLTK: Uncontrolled resource consumption in RecursiveDescentParser via ambiguous or left-recursive grammars | 中危 | PyPInltk | 已审查 | 2026-09-02 22:33 | 2026-09-02 22:33 |
| GHSA-CW6X-M8JW-QMRH CVE-2026-81724 | NLTK: Uncontrolled recursion in nltk.featstruct.FeatStructReader causes unhandled RecursionError (DoS) via deeply nested feature-structure input | 中危 | PyPInltk | 已审查 | 2026-09-02 22:33 | 2026-09-02 22:33 |
| GHSA-CVHV-G4RQ-3HMW | ImageMagick: Memory Leak when providing invalid options to the cli | 低危 | NuGetMagick.NET-Q16-AnyCPU+16 | 已审查 | 2026-09-02 22:27 | 2026-09-02 22:27 |
| GHSA-P498-V437-472G | humanfs: Recursive copy follows symlinked files and copies data from outside the source tree | 中危 | npm@humanfs/node | 已审查 | 2026-09-02 22:27 | 2026-09-02 22:27 |
| GHSA-QXC2-J82W-R537 CVE-2026-73231 | Faker: helpers.fake exploitable into arbritary code execution | 高危 | npm@faker-js/faker | 已审查 | 2026-09-02 22:20 | 2026-09-02 22:20 |
| GHSA-275H-V5H9-VR82 CVE-2026-59832 | Siyuan: Authenticated path traversal in /snippets/ static handler (serveSnippets) leaks conf/conf.json secrets and siyuan.db | 高危 | Gogithub.com/siyuan-note/siyuan/kernel | 已审查 | 2026-09-02 22:17 | 2026-09-02 22:17 |
| GHSA-H89Q-4J2H-7H88 CVE-2026-59834 | SiYuan: SQL Query in Block Search Exposes Hidden Published Document Content | 高危 | Gogithub.com/siyuan-note/siyuan/kernel | 已审查 | 2026-09-02 22:16 | 2026-09-02 22:16 |
| GHSA-VP52-PCJ8-J9QC CVE-2026-84304 | gRPC-Go: Heap Memory Exhaustion (OOM) via HTTP/2 DATA Frame Fragmentation | 高危 | Gogoogle.golang.org/grpc | 已审查 | 2026-09-02 05:32 | 2026-09-02 05:32 |
| GHSA-68JX-F42C-7599 CVE-2026-19418 | TYPO3 CMS - Broken Access Control in Backend and Install Tool | 高危 | Packagisttypo3/cms-backend+1 | 已审查 | 2026-09-02 05:31 | 2026-09-02 05:31 |
| GHSA-R3J6-GPJW-QFJR CVE-2026-84306 | Filament: Multi-factor authentication (app) codes can still be used after a newer code has been used | 中危 | Packagistfilament/filament | 已审查 | 2026-09-02 05:29 | 2026-09-02 05:29 |