检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-P63J-VCC4-9VMV CVE-2026-73653 | @vitest/browser: Browser Mode provider commands bypass the file-access permission gate | 严重 | npm@vitest/browser | 已审查 | 2026-07-22 03:36 | 2026-08-14 02:19 |
| GHSA-PF56-329R-95RW CVE-2026-59891 |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 严重 |
npm@sigstore/oci |
| 已审查 |
| 2026-07-22 03:34 |
| 2026-07-22 03:34 |
| GHSA-3PJW-73GF-8QR5 CVE-2026-59888 | jackson-databind: @JsonIgnore on a Record property is bypassed with a PropertyNamingStrategy | 中危 | Mavencom.fasterxml.jackson.core:jackson-databind+1 | 已审查 | 2026-07-22 03:33 | 2026-07-22 03:33 |
| GHSA-82F7-87HM-852X CVE-2026-57894 | Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration | 高危 | Gocode.gitea.io/gitea | 已审查 | 2026-07-22 03:17 | 2026-07-22 03:17 |
| GHSA-HM4W-WWCW-MR6R CVE-2026-59886 | pyasn1: Uncontrolled resource consumption when converting decoded REAL values | 高危 | PyPIpyasn1 | 已审查 | 2026-07-22 03:11 | 2026-07-22 03:11 |
| GHSA-8PPF-4F7H-5PPJ CVE-2026-59885 | pyasn1: Quadratic complexity in OBJECT IDENTIFIER and RELATIVE-OID processing allows denial of service | 高危 | PyPIpyasn1 | 已审查 | 2026-07-22 03:11 | 2026-07-22 03:11 |
| GHSA-M4P7-R5RC-7G4J CVE-2026-59884 | pyasn1 BER/CER/DER decoder denial of service via unbounded long-form tag IDs | 高危 | PyPIpyasn1 | 已审查 | 2026-07-22 03:10 | 2026-08-01 05:55 |
| GHSA-H35F-9H28-MQ5C CVE-2026-59890 | setuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization collision (NFC/NFD) on macOS APFS/HFS+ | 中危 | PyPIsetuptools | 已审查 | 2026-07-22 03:09 | 2026-07-22 03:09 |
| GHSA-45RX-2JWX-CXFR CVE-2026-59892 | OpenTelemetry JavaScript: Denial of service in `JaegerPropagator` via unhandled exception on a malformed header | 高危 | npm@opentelemetry/propagator-jaeger | 已审查 | 2026-07-22 03:07 | 2026-07-22 03:07 |
| GHSA-V245-V573-V5VM CVE-2026-59887 | linkify-it: Quadratic-complexity DoS via the `mailto:` validator scan-loop on attacker text | 高危 | npmlinkify-it | 已审查 | 2026-07-22 03:06 | 2026-07-22 03:06 |
| GHSA-VCRF-J523-4MRF CVE-2026-13760 | aws-cdk-lib: OS Command Injection in NodejsFunction Docker Bundling | 高危 | npmaws-cdk-lib | 已审查 | 2026-07-22 03:04 | 2026-07-22 03:04 |
| GHSA-4C8G-83QW-93J6 CVE-2026-13676 | fast-uri vulnerable to host confusion via failed IDN canonicalization | 高危 | npmfast-uri | 已审查 | 2026-07-22 03:03 | 2026-08-31 23:34 |
| GHSA-XVCM-6775-5M9R CVE-2026-59880 | Immutable: Hash-collision algorithmic complexity denial of service in Immutable.Map/Set | 高危 | npmimmutable | 已审查 | 2026-07-22 03:02 | 2026-09-04 00:38 |
| GHSA-V56Q-MH7H-F735 CVE-2026-59879 | Immutable.js `List` 32-bit trie overflow → unrecoverable DoS | 高危 | npmimmutable | 已审查 | 2026-07-22 02:36 | 2026-07-22 02:36 |
| GHSA-C2W2-PRH8-QM98 CVE-2026-59882 | guzzlehttp/psr7: Host Confusion via Weak URI Host Validation | 中危 | Packagistguzzlehttp/psr7 | 已审查 | 2026-07-22 02:35 | 2026-07-22 02:35 |
| GHSA-2X63-GW47-W4MM CVE-2026-61666 | websocket-driver-ruby: Denial of service via malformed Host header | 高危 | RubyGemswebsocket-driver | 已审查 | 2026-07-22 02:34 | 2026-07-22 02:34 |
| GHSA-HVRM-45R6-MJFJ CVE-2026-59896 | hono/jsx does not isolate context per request, leading to cross-request data disclosure | 中危 | npmhono | 已审查 | 2026-07-22 02:34 | 2026-07-22 02:34 |
| GHSA-W62V-XXXG-MG59 CVE-2026-59895 | Hono: Server-Side XSS via JSX Escaping Bypass in cx() Utility | 中危 | npmhono | 已审查 | 2026-07-22 02:33 | 2026-07-22 02:33 |
| GHSA-5HXG-R395-FQXX CVE-2026-64825 | Home Assistant Core vulnerable to Path Traversal via backup upload during onboarding | 严重 | PyPIhomeassistant | 已审查 | 2026-07-22 02:31 | 2026-08-14 02:37 |
| GHSA-XGM2-5F3F-MVVC CVE-2026-59897 | Hono: API Gateway v1 adapter can drop a distinct repeated request header value during de-duplication | 中危 | npmhono | 已审查 | 2026-07-22 02:18 | 2026-07-22 02:18 |
| GHSA-FRVP-7C67-39W9 | Node.js Adapter for Hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`) | 中危 | npm@hono/node-server | 已审查 | 2026-07-22 02:17 | 2026-08-13 02:26 |
| GHSA-J92G-9F8W-J867 CVE-2026-54291 | PostgreSQL JDBC Driver: Silent channel-binding authentication downgrade via unsupported certificate algorithms | 高危 | Mavenorg.postgresql:postgresql | 已审查 | 2026-07-22 01:47 | 2026-07-22 01:47 |
| GHSA-J8GR-8FP3-5Q5H CVE-2026-56170 | Microsoft Security Advisory CVE-2026-56170 – .NET Denial of Service Vulnerability | 高危 | NuGetMicrosoft.AspNetCore.App.Runtime.linux-arm+11 | 已审查 | 2026-07-22 00:15 | 2026-07-22 00:15 |
| GHSA-55JH-FWMH-39M4 CVE-2026-50526 | Microsoft Security Advisory CVE-2026-50526 – .NET Tampering Vulnerability | 高危 | NuGetMicrosoft.NET.Build.Containers | 已审查 | 2026-07-22 00:14 | 2026-07-22 00:14 |
| GHSA-8PRM-248R-H957 CVE-2026-47300 | Microsoft Security Advisory CVE-2026-47300 – .NET Elevation of Privilege Vulnerability | 高危 | NuGetMicrosoft.AspNetCore.Authentication.Negotiate | 已审查 | 2026-07-22 00:13 | 2026-07-22 00:13 |