检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-F88M-G3JW-G9CJ | sharp inherited vulnerabilities in libvips: CVE-2026-33327, CVE-2026-33328, CVE-2026-35590, CVE-2026-35591 | 高危 | npmsharp | 已审查 | 2026-07-22 06:07 | 2026-07-22 06:07 |
| GHSA-8R6M-32JQ-JX6Q CVE-2026-73569 | fast-xml-parser: Repeated DOCTYPE declarations reset entity expansion limits |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 高危 |
npmfast-xml-parser |
| 已审查 |
| 2026-07-22 06:06 |
| 2026-08-14 01:45 |
| GHSA-RWJ8-PGH3-R573 | GitPython: Environment-variable exfiltration via os.path.expandvars() on Repo.clone_from() URL | 高危 | PyPIgitpython | 已审查 | 2026-07-22 06:06 | 2026-07-22 06:06 |
| GHSA-CJ75-F6XR-R4G7 CVE-2026-73648 | Rails HTML Sanitizers: Possible XSS vulnerability with certain configurations | 中危 | RubyGemsrails-html-sanitizer | 已审查 | 2026-07-22 06:05 | 2026-08-14 02:00 |
| GHSA-9MQV-5HH9-4CGG CVE-2026-73565 | Node.js Adapter for Hono: Unauthenticated memory-leak DoS via aborted WebSocket handshake | 中危 | npm@hono/node-server | 已审查 | 2026-07-22 06:04 | 2026-08-14 01:37 |
| GHSA-HRXH-6V49-42GF | gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities | 高危 | Gogoogle.golang.org/grpc | 已审查 | 2026-07-22 06:03 | 2026-07-22 06:03 |
| GHSA-5QHF-9PHG-95M2 | Loofah `allowed_uri?` does not detect `javascript:` URIs split by numeric character references without semicolons | 低危 | RubyGemsloofah | 已审查 | 2026-07-22 06:03 | 2026-07-22 06:03 |
| GHSA-9WJQ-CP2P-HRGF CVE-2026-73490 | Loofah: SVG `href` attribute bypasses local-reference restriction | 中危 | RubyGemsloofah | 已审查 | 2026-07-22 06:01 | 2026-08-13 04:58 |
| GHSA-5GVW-P9QM-JGWH CVE-2026-59889 | jackson-databind: @JsonView bypassed for @JsonUnwrapped container properties on deserialization | 中危 | Mavencom.fasterxml.jackson.core:jackson-databind+1 | 已审查 | 2026-07-22 06:00 | 2026-08-04 04:51 |
| GHSA-2RP8-MM9Q-FP49 CVE-2026-73651 | TypeORM: migration:generate template-literal code injection | 中危 | npmtypeorm | 已审查 | 2026-07-22 05:59 | 2026-08-14 02:11 |
| GHSA-R7WM-3CXJ-WFF9 | jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq) | 高危 | Mavencom.fasterxml.jackson.core:jackson-core+1 | 已审查 | 2026-07-22 05:58 | 2026-08-04 04:30 |
| GHSA-GX3V-Q759-G323 CVE-2026-20779 | Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface | 高危 | Gocode.gitea.io/gitea | 已审查 | 2026-07-22 05:57 | 2026-07-22 05:57 |
| GHSA-FQ2P-5P22-8G6J CVE-2026-58429 | Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints | 中危 | Gocode.gitea.io/gitea | 已审查 | 2026-07-22 05:56 | 2026-07-22 05:56 |
| GHSA-2WM4-VWP6-V7XC CVE-2026-59765 | Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata | 中危 | Gocode.gitea.io/gitea | 已审查 | 2026-07-22 05:55 | 2026-07-22 05:55 |
| GHSA-3R5C-2XXX-H872 CVE-2026-58511 | Gitea: Webhook Authorization Header Returned in Plaintext via API | 低危 | Gocode.gitea.io/gitea | 已审查 | 2026-07-22 05:52 | 2026-07-22 05:52 |
| GHSA-FRPW-3H2Q-4JJ6 CVE-2026-57897 | Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs | 中危 | Gocode.gitea.io/gitea | 已审查 | 2026-07-22 05:52 | 2026-07-22 05:52 |
| GHSA-Q423-49RW-G9MH CVE-2026-58510 | Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private | 中危 | Gocode.gitea.io/gitea | 已审查 | 2026-07-22 05:51 | 2026-07-22 05:51 |
| GHSA-H56G-4QW7-2MXG CVE-2026-58431 | Gitea: Public-only API token restriction is not enforced on team API routes | 中危 | Gogitea.dev | 已审查 | 2026-07-22 05:50 | 2026-07-22 05:50 |
| GHSA-PRR9-9MP4-5GP2 CVE-2026-58427 | Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 | 中危 | Gogitea.dev | 已审查 | 2026-07-22 05:49 | 2026-07-22 05:49 |
| GHSA-G9G6-QHRC-P3QC CVE-2026-58422 | Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts | 高危 | Gocode.gitea.io/gitea | 已审查 | 2026-07-22 05:48 | 2026-07-22 05:48 |
| GHSA-44QC-PGVP-WX7V CVE-2026-58419 | Gitea: Notification API leaks private issue metadata after access revocation | 高危 | Gocode.gitea.io/gitea | 已审查 | 2026-07-22 05:48 | 2026-07-22 05:48 |
| GHSA-V73X-HX65-6PF4 CVE-2026-25038 | Gitea: Unauthorized Access to Labels of Private Organizations | 高危 | Gocode.gitea.io/gitea | 已审查 | 2026-07-22 05:46 | 2026-07-22 05:46 |
| GHSA-649P-MMHF-85C7 CVE-2026-27775 | Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write | 高危 | Gocode.gitea.io/gitea | 已审查 | 2026-07-22 05:43 | 2026-07-22 05:43 |
| GHSA-WRF9-R3H7-7X5V CVE-2026-24451 | Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private | 高危 | Gocode.gitea.io/gitea | 已审查 | 2026-07-22 05:42 | 2026-07-22 05:42 |
| GHSA-2FCR-JFVC-VGG2 CVE-2026-58314 | Gitea: Two SSRF findings | 高危 | Gocode.gitea.io/gitea | 已审查 | 2026-07-22 05:16 | 2026-07-22 05:16 |