检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-2P3Q-H3HG-JCQQ CVE-2026-47303 | Microsoft Security Advisory CVE-2026-47303 – .NET Elevation of Privilege Vulnerability | 高危 | NuGetMicrosoft.AspNetCore.Authentication.Negotiate | 已审查 | 2026-07-22 00:07 | 2026-07-22 00:07 |
| GHSA-MMJF-RQRV-855V CVE-2026-50527 |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 高危 |
NuGetSystem.Security.Cryptography.Xml |
| 已审查 |
| 2026-07-22 00:06 |
| 2026-07-22 01:30 |
| GHSA-2969-4Q4W-W5H3 CVE-2026-50650 | Microsoft Security Advisory CVE-2026-50650 – .NET Elevation of Privilege Vulnerability | 高危 | NuGetMicrosoft.WindowsDesktop.App.Runtime.win-arm64+2 | 已审查 | 2026-07-22 00:06 | 2026-07-22 00:06 |
| GHSA-8WHX-365G-H9VV CVE-2026-73491 | Loofah `allowed_uri?` does not detect `javascript:` URIs split by named whitespace character references | 低危 | RubyGemsloofah | 已审查 | 2026-07-21 23:04 | 2026-08-13 04:59 |
| GHSA-H95V-H523-3MW8 CVE-2026-67354 | Guzzle: URI fragments disclosed in redirect Referer headers | 中危 | Packagistguzzlehttp/guzzle | 已审查 | 2026-07-21 07:28 | 2026-08-04 20:53 |
| GHSA-WM3W-8RRP-J577 CVE-2026-67355 | Guzzle: Host-only cookie scope is not preserved | 中危 | Packagistguzzlehttp/guzzle | 已审查 | 2026-07-21 07:27 | 2026-08-04 20:55 |
| GHSA-F283-GHQC-FG79 CVE-2026-67353 | Guzzle: Unbounded response cookies risk denial of service | 中危 | Packagistguzzlehttp/guzzle | 已审查 | 2026-07-21 07:27 | 2026-08-04 20:58 |
| GHSA-8MV7-9C27-98VC CVE-2026-73423 | Astro: composable `astro/hono` pipeline bypasses `security.checkOrigin` when `middleware()` is absent or misordered | 中危 | npmastro | 已审查 | 2026-07-21 07:26 | 2026-08-13 04:35 |
| GHSA-X27W-589X-FRM2 CVE-2026-73424 | Astro: Unauthenticated path override in the @astrojs/vercel ISR function | 中危 | npm@astrojs/vercel | 已审查 | 2026-07-21 07:25 | 2026-08-18 01:12 |
| GHSA-HP3V-MFQW-H74C CVE-2026-73425 | @astrojs/netlify generates an overly-broad Netlify Image CDN allowlist because remotePatterns.pathname metacharacters are not escaped | 低危 | npm@astrojs/netlify | 已审查 | 2026-07-21 07:24 | 2026-08-13 23:18 |
| GHSA-V422-HMWV-36X6 CVE-2026-12590 | body-parser vulnerable to denial of service when invalid limit value silently disables size enforcement | 低危 | npmbody-parser | 已审查 | 2026-07-21 07:23 | 2026-07-21 07:23 |
| GHSA-R557-WFFQ-WVRC CVE-2026-59730 | @astrojs/node: Backslash-prefixed paths not recognized as internal by trailing-slash redirect | 低危 | npm@astrojs/node | 已审查 | 2026-07-21 07:22 | 2026-08-13 04:37 |
| GHSA-F48W-9M4C-M7F5 CVE-2026-59729 | Astro: XSS via unescaped spread attribute names in renderHTMLElement (incomplete fix for CVE-2026-54298) | 中危 | npmastro | 已审查 | 2026-07-21 07:21 | 2026-08-13 04:37 |
| GHSA-8J5Q-MFJ2-5Q9Q CVE-2026-59728 | @astrojs/rss: XML Injection via Unescaped RSS Feed Fields | 中危 | npm@astrojs/rss | 已审查 | 2026-07-21 07:21 | 2026-08-13 04:37 |
| GHSA-7PW4-F3Q4-R2P2 CVE-2026-59727 | Astro: Cross-site scripting via unescaped transition:* directive values on hydrated islands | 低危 | npmastro | 已审查 | 2026-07-21 07:21 | 2026-08-13 04:37 |
| GHSA-9HW9-CH79-4VH6 CVE-2026-59205 | Pillow: Controlled heap out-of-bounds write in Pillow `ImageCmsTransform.apply()` via output mode mismatch | 高危 | PyPIpillow | 已审查 | 2026-07-21 07:19 | 2026-07-21 07:19 |
| GHSA-VJC4-5QP5-M44J CVE-2026-59204 | Pillow JPEG2000 tiled decode retains a growing scratch buffer and can be used for denial of service | 高危 | PyPIpillow | 已审查 | 2026-07-21 07:18 | 2026-07-21 07:18 |
| GHSA-PG7V-JWJ7-P798 CVE-2026-59203 | Pillow EpsImagePlugin negative %%BeginBinary byte count causes infinite loop denial of service | 中危 | PyPIpillow | 已审查 | 2026-07-21 07:11 | 2026-07-21 07:11 |
| GHSA-JJJ6-MW9F-P565 CVE-2026-59200 | Pillow: Decompression Bomb DoS via PdfParser.PdfStream.decode() | 高危 | PyPIPillow | 已审查 | 2026-07-21 07:11 | 2026-07-21 07:11 |
| GHSA-6R8X-57C9-28J4 CVE-2026-59199 | Pillow: Heap out-of-bounds write `Image.paste()` / `Image.crop()` via signed coordinate overflow | 高危 | PyPIPillow | 已审查 | 2026-07-21 07:09 | 2026-07-21 07:09 |
| GHSA-FJ7V-R99M-22GQ CVE-2026-59198 | Pillow TGA RLE encoder can serialize up to ~57 KB of adjacent heap data into generated images | 中危 | PyPIPillow | 已审查 | 2026-07-21 07:09 | 2026-07-21 07:09 |
| GHSA-XJ96-63GP-2GMR CVE-2026-59197 | Pillow: Heap out-of-bounds write in `ImageFilter.RankFilter` via integer overflow in `ImagingExpand` | 高危 | PyPIPillow | 已审查 | 2026-07-21 07:08 | 2026-07-21 07:08 |
| GHSA-WP74-JGXH-GV4Q CVE-2026-50651 | Microsoft Security Advisory CVE-2026-50651 – .NET Denial of Service Vulnerability | 高危 | NuGetMicrosoft.NetCore.App.Runtime.linux-arm+11 | 已审查 | 2026-07-21 07:02 | 2026-07-21 07:02 |
| GHSA-74JP-VM22-8Q8X CVE-2026-50659 | Microsoft Security Advisory CVE-2026-50659 – .NET Spoofing Vulnerability | 中危 | NuGetMicrosoft.NetCore.App.Runtime.linux-arm+11 | 已审查 | 2026-07-21 07:02 | 2026-07-21 07:02 |
| GHSA-8Q5V-6PQQ-X66H CVE-2026-50525 | Microsoft Security Advisory CVE-2026-50525 – .NET Denial of Service Vulnerability | 高危 | NuGetSystem.Security.Cryptography.Xml | 已审查 | 2026-07-21 07:02 | 2026-07-22 01:23 |