检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-X2F5-4PRF-W687 CVE-2026-54696 | Ruby json: JSON generator heap buffer overflow when streaming to an IO | 低危 | RubyGemsjson | 已审查 | 2026-07-24 03:48 | 2026-07-24 03:48 |
| GHSA-W6W4-RJH9-9R58 CVE-2026-55223 | c3p0 can, in combination with other libraries, compose to a "sink" for deserialization gadgets |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 中危 |
Mavencom.mchange:c3p0 |
| 已审查 |
| 2026-07-24 03:46 |
| 2026-07-24 03:46 |
| GHSA-WRJC-X8RR-H8H6 CVE-2026-53669 | React Router: Open redirect via backslash in <Link> and useNavigate (CVE-2025-68470 bypass) | 中危 | npmreact-router | 已审查 | 2026-07-24 03:38 | 2026-07-24 03:38 |
| GHSA-JJMJ-JMHJ-QWJ2 CVE-2026-53668 | React Router: Open redirect leading to XSS | 中危 | npmreact-router+1 | 已审查 | 2026-07-24 03:36 | 2026-07-24 03:36 |
| GHSA-H8FP-F39C-Q6MH CVE-2026-53667 | React Router: RSCErrorHandler Missing Protocol Validation (XSS) | 中危 | npmreact-router | 已审查 | 2026-07-24 03:35 | 2026-07-24 03:35 |
| GHSA-337J-9HXR-RHXG CVE-2026-53666 | React Router: Arbitrary Constructor Injection via deserializeErrors() in React Router SSR Hydration | 中危 | npmreact-router | 已审查 | 2026-07-24 03:34 | 2026-07-24 03:34 |
| GHSA-8G53-9M3C-69XG CVE-2026-53467 | ImageMagick: Information Disclosure in MNG decoder because allocated memory is left unchanged | 中危 | NuGetMagick.NET-Q16-AnyCPU+16 | 已审查 | 2026-07-24 03:33 | 2026-07-24 03:33 |
| GHSA-C96F-X56V-GQ3H CVE-2026-47219 | find-my-way: DDoS with HTTP2 | 高危 | npmfind-my-way | 已审查 | 2026-07-24 03:33 | 2026-07-24 03:33 |
| GHSA-G867-7843-WF8Q CVE-2026-59935 | pypdf: Possible infinite loop for not terminated inline images (ASCII85 and ASCIIHex filter) | 高危 | PyPIpypdf | 已审查 | 2026-07-24 00:37 | 2026-07-24 00:37 |
| GHSA-5XF7-4P34-54QR CVE-2026-59936 | pypdf: Possible infinite loop for not terminated inline images | 高危 | PyPIpypdf | 已审查 | 2026-07-24 00:36 | 2026-07-24 00:36 |
| GHSA-55H5-XMCQ-C37V CVE-2026-59937 | pypdf: Possible long runtimes for repeated malformed cross-reference entries | 中危 | PyPIpypdf | 已审查 | 2026-07-23 23:07 | 2026-07-23 23:07 |
| GHSA-5QJQ-93H5-HRGP CVE-2026-59938 | pypdf: Possible large memory usage for wrong image dimensions | 中危 | PyPIpypdf | 已审查 | 2026-07-23 23:06 | 2026-07-23 23:06 |
| GHSA-6G55-P6WH-862Q CVE-2026-45623 | PostCSS: Arbitrary file read and information disclosure via attacker-controlled sourceMappingURL in CSS comments | 高危 | npmpostcss | 已审查 | 2026-07-23 23:06 | 2026-07-23 23:06 |
| GHSA-XH5M-36R6-47M3 CVE-2026-59933 | PHPSpreadsheet: XLS/OLE sector-chain self-loop causes memory exhaustion | 高危 | Packagistphpoffice/phpspreadsheet | 已审查 | 2026-07-23 23:01 | 2026-07-23 23:01 |
| GHSA-2MRG-GJXQ-2GVR CVE-2026-59932 | PHPSpreadsheet: Gnumeric reader unbounded gzip expansion causes memory exhaustion | 高危 | Packagistphpoffice/phpspreadsheet | 已审查 | 2026-07-23 23:00 | 2026-07-23 23:00 |
| GHSA-6HQ5-7373-42RG CVE-2026-59931 | PHPSpreadsheet: SSRF bypass via HTTP redirect in WEBSERVICE() domain whitelist | 高危 | Packagistphpoffice/phpspreadsheet | 已审查 | 2026-07-23 22:55 | 2026-07-23 22:55 |
| GHSA-8FPG-XM3F-6CX3 CVE-2026-73421 | Auth.js: Configuration errors can cause existence-based auth checks to fail open (auth object populated with an error) | 严重 | npmnext-auth | 已审查 | 2026-07-23 22:52 | 2026-08-13 04:31 |
| GHSA-XMF8-CVQR-RFGJ CVE-2026-73418 | Auth.js: getToken() throws an uncaught exception on malformed Bearer authorization headers | 高危 | npm@auth/core+1 | 已审查 | 2026-07-23 22:42 | 2026-08-14 03:05 |
| GHSA-7RQJ-J65F-68WH CVE-2026-73420 | Auth.js: Email normalizer validates the address before Unicode normalization, allowing a homoglyph @ bypass | 严重 | npm@auth/core+1 | 已审查 | 2026-07-23 22:40 | 2026-08-13 04:27 |
| GHSA-X445-F3H2-J279 CVE-2026-73419 | Auth.js: OAuth state, nonce, and PKCE check cookies are not bound to the provider that created them | 中危 | npm@auth/core+1 | 已审查 | 2026-07-23 22:31 | 2026-08-14 03:05 |
| GHSA-CRF3-V9RR-V7HJ CVE-2026-16723 | fastjson has a remote code execution (RCE) vulnerability | 严重 | Mavencom.alibaba:fastjson | 已审查 | 2026-07-23 17:32 | 2026-08-08 02:18 |
| GHSA-652Q-GVQ3-74QV | n8n: Snowflake Node executeQuery Operation Allows SQL Injection via Unparameterized Expression Interpolation | 中危 | npmn8n | 已审查 | 2026-07-23 07:20 | 2026-07-23 07:20 |
| GHSA-JQWR-VX3P-R266 | n8n: PostgresTrigger Node SQL Injection Allows Authenticated Users to Execute Arbitrary SQL on Connected PostgreSQL Instances | 中危 | npmn8n | 已审查 | 2026-07-23 07:20 | 2026-07-23 07:20 |
| GHSA-9CMH-XCQM-5HQR | n8n: Cross-Tenant Module-Cache Poisoning in the JS Task Runner | 中危 | npmn8n | 已审查 | 2026-07-23 07:18 | 2026-07-23 07:18 |
| GHSA-PPPJ-HQ3G-57PJ CVE-2026-73417 | JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`) | 高危 | PyPIjupyterlab | 已审查 | 2026-07-23 07:16 | 2026-08-13 03:58 |