检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-GX64-GJ6P-PC4C CVE-2026-73415 | JupyterLab: Image viewer allows XSS when opening malicious image in new browser tab | 高危 | PyPIjupyterlab | 已审查 | 2026-07-23 07:14 | 2026-08-13 03:54 |
| GHSA-89VP-JRXV-24W8 CVE-2026-73416 | JupyterLab: PyPI extension blocklist package-name canonicalization bypass |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 中危 |
PyPIjupyterlab |
| 已审查 |
| 2026-07-23 07:14 |
| 2026-08-13 03:56 |
| GHSA-H5V5-8746-G7MM | JupyterLab PluginManager lock-rule enforcement bypass | 中危 | PyPIjupyterlab | 已审查 | 2026-07-23 07:13 | 2026-07-23 07:13 |
| GHSA-WHVH-WF3X-G77J | JupyterLab: Allowlist/blocklist check in `PyPIExtensionManager.install()` not enforced for direct callers (missing `await`) | 低危 | PyPIjupyterlab | 已审查 | 2026-07-23 07:12 | 2026-07-23 07:12 |
| GHSA-89XV-2M56-2M9X CVE-2026-64649 | Next.js: Server-Side Request Forgery in Server Actions on custom servers | 高危 | npmnext | 已审查 | 2026-07-23 07:09 | 2026-07-23 07:09 |
| GHSA-68G3-V927-F742 CVE-2026-64648 | Next.js: Cache confusion of response bodies for requests with bodies | 中危 | npmnext | 已审查 | 2026-07-23 07:08 | 2026-07-23 07:08 |
| GHSA-4633-3J49-MH5Q CVE-2026-64647 | Next.js: Cache confusion of response bodies for requests with bodies containing invalid UTF-8 byte sequences | 中危 | npmnext | 已审查 | 2026-07-23 07:06 | 2026-07-23 07:06 |
| GHSA-4C39-4CCG-62R3 CVE-2026-64646 | Next.js: Unbounded Server Action payload in Edge runtime | 中危 | npmnext | 已审查 | 2026-07-23 07:02 | 2026-07-23 07:02 |
| GHSA-P9J2-GV94-2WF4 CVE-2026-64645 | Next.js: Server-Side Request Forgery in rewrites via attacker-controlled destination hostname | 高危 | npmnext | 已审查 | 2026-07-23 07:02 | 2026-07-23 07:02 |
| GHSA-Q8WF-6R8G-63CH CVE-2026-64644 | Next.js: Denial of Service in the Image Optimization API using SVGs | 中危 | npmnext | 已审查 | 2026-07-23 07:02 | 2026-07-23 07:02 |
| GHSA-955P-X3MX-JCVP CVE-2026-64643 | Next.js: Unauthenticated disclosure of internal Server Function endpoints | 中危 | npmnext | 已审查 | 2026-07-23 07:00 | 2026-07-23 07:00 |
| GHSA-6GPP-XCG3-4W24 CVE-2026-64642 | Next.js: Middleware / Proxy bypass in App Router applications using Turbopack and single locale | 高危 | npmnext | 已审查 | 2026-07-23 06:59 | 2026-07-23 06:59 |
| GHSA-M99W-X7HQ-7VFJ CVE-2026-64641 | Next.js: Denial of Service in App Router using Server Actions | 高危 | npmnext | 已审查 | 2026-07-23 06:59 | 2026-07-23 06:59 |
| GHSA-9299-C6M4-MJHC CVE-2024-7708 | Eclipse Jetty: DoS attack triggering OutOfMemory with 100-Continue requests | 高危 | Mavenorg.eclipse.jetty:jetty-server | 已审查 | 2026-07-23 06:58 | 2026-07-23 06:58 |
| GHSA-W7X5-G22V-XQHR CVE-2026-8384 | Eclipse Jetty: Path parameter traversal | 中危 | Mavenorg.eclipse.jetty:jetty-util | 已审查 | 2026-07-23 06:57 | 2026-07-23 06:57 |
| GHSA-7P3P-8QV8-M2VH CVE-2026-6790 | Eclipse Jetty: HTTP Authority/Host mismatch | 中危 | Mavenorg.eclipse.jetty:jetty-server | 已审查 | 2026-07-23 06:56 | 2026-07-23 06:56 |
| GHSA-F4V5-65JJ-PCR2 CVE-2026-10051 | Eclipse Jetty: Cross-Request Leakage for trailers on HTTP/1.1 keep-alive connections | 中危 | Mavenorg.eclipse.jetty:jetty-server | 已审查 | 2026-07-23 06:56 | 2026-07-23 06:56 |
| GHSA-2FVJ-HGJ9-J2GR CVE-2026-10050 | Eclipse Jetty Digest Authentication: ISO-8859-1 lossy encoding allows authentication bypass via character substitution | 高危 | Mavenorg.eclipse.jetty:jetty-security+2 | 已审查 | 2026-07-23 06:55 | 2026-07-23 06:55 |
| GHSA-89GH-3PGC-V5H2 CVE-2026-65589 | n8n: Custom Header Credential Values Leaked in Plaintext into LLM Node Execution Data | 中危 | npmn8n | 已审查 | 2026-07-23 06:54 | 2026-07-23 06:54 |
| GHSA-J8QW-6JW8-R297 CVE-2026-59943 | Dompdf: Embedded SVG images can leak existence of files and directories within the filesystem | 中危 | Packagistdompdf/dompdf | 已审查 | 2026-07-23 06:52 | 2026-07-23 06:52 |
| GHSA-F5GF-2CJ8-52G2 CVE-2026-59942 | Dompdf: Denial of Service (DoS) via Resource Exhaustion using Oversized Image Bitmaps | 中危 | Packagistdompdf/dompdf | 已审查 | 2026-07-23 06:51 | 2026-07-23 06:51 |
| GHSA-8HG6-C449-896M CVE-2026-59941 | Dompdf: Uncontrolled resource consumption based on declared BMP dimensions | 中危 | Packagistdompdf/dompdf | 已审查 | 2026-07-23 06:50 | 2026-07-23 06:50 |
| GHSA-72M8-9M7M-H278 CVE-2026-59821 | LiteLLM: Custom Code Guardrails production endpoints bypass code safety checks | 低危 | PyPIlitellm | 已审查 | 2026-07-23 06:38 | 2026-07-23 06:38 |
| GHSA-7488-6R32-C95Q CVE-2026-59822 | LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback | 高危 | PyPIlitellm | 已审查 | 2026-07-23 06:38 | 2026-07-23 06:38 |
| GHSA-4G5M-C9R5-49XF CVE-2026-59819 | LiteLLM: Local file read via request-supplied OIDC file references | 低危 | PyPIlitellm | 已审查 | 2026-07-23 06:38 | 2026-07-23 06:38 |