检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-QVW7-JM5C-6HQW CVE-2026-50528 | Microsoft Security Advisory CVE-2026-50528 – .NET Security Feature Bypass Vulnerability | 高危 | NuGetMicrosoft.NetCore.App.Runtime.linux-arm+11 | 已审查 | 2026-07-21 06:52 | 2026-07-21 06:52 |
当前筛选结果 35,190 条 · 时间按北京时间显示
| GHSA-23RF-6693-G89P CVE-2026-50648 |
Microsoft Security Advisory CVE-2026-50648 – .NET Denial of Service Vulnerability |
| 高危 |
NuGetSystem.Security.Cryptography.Xml |
| 已审查 |
| 2026-07-21 06:49 |
| 2026-07-22 01:31 |
| GHSA-W7CW-XP7H-6J5J CVE-2026-50524 | Microsoft Security Advisory CVE-2026-50524 – .NET Denial of Service Vulnerability | 高危 | NuGetMicrosoft.NetCore.App.Runtime.linux-arm+11 | 已审查 | 2026-07-21 06:47 | 2026-07-21 06:47 |
| GHSA-G8R8-53C2-PM3F CVE-2026-47304 | Microsoft Security Advisory CVE-2026-47304 – .NET Security Feature Bypass Vulnerability | 高危 | NuGetSystem.Security.Cryptography.Xml | 已审查 | 2026-07-21 06:44 | 2026-07-22 00:49 |
| GHSA-CVVH-RHRC-WG4Q CVE-2026-47302 | Microsoft Security Advisory CVE-2026-47302 – .NET Denial of Service Vulnerability | 高危 | NuGetMicrosoft.NetCore.App.Runtime.linux-arm+12 | 已审查 | 2026-07-21 06:42 | 2026-07-22 01:32 |
| GHSA-RP2P-6CMP-JXJ9 CVE-2026-57108 | Microsoft Security Advisory CVE-2026-57108 – .NET Denial of Service Vulnerability | 高危 | NuGetMicrosoft.NetCore.App.Runtime.linux-arm+7 | 已审查 | 2026-07-21 06:41 | 2026-07-21 06:41 |
| GHSA-GCFJ-64VW-6MP9 CVE-2026-67320 | Axios Node HTTP adapter can use an inherited proxy after interceptor config cloning | 高危 | npmaxios | 已审查 | 2026-07-21 06:40 | 2026-09-02 02:42 |
| GHSA-HCPX-6FM6-WX23 | Axios form serializer maxDepth bypass via {} metatoken | 中危 | npmaxios | 已审查 | 2026-07-21 06:38 | 2026-07-21 06:38 |
| GHSA-7Q8Q-RJ6J-MHJQ CVE-2026-67319 | Axios: Nested axios option objects can consume polluted prototype values | 中危 | npmaxios | 已审查 | 2026-07-21 06:37 | 2026-09-02 02:41 |
| GHSA-MWF2-3PR3-8698 CVE-2026-67318 | Axios: HTTP/2 streamed uploads bypass `maxBodyLength` | 中危 | npmaxios | 已审查 | 2026-07-21 06:37 | 2026-09-02 02:36 |
| GHSA-JQH4-M9W3-8HP9 CVE-2026-67317 | Axios: Fetch adapter `ReadableStream` uploads bypass `maxBodyLength` | 中危 | npmaxios | 已审查 | 2026-07-21 06:27 | 2026-09-02 02:38 |
| GHSA-MMX7-HFXF-JPPX CVE-2026-67316 | Axios: Prototype pollution gadgets can alter axios request construction | 中危 | npmaxios | 已审查 | 2026-07-21 06:25 | 2026-09-01 03:51 |
| GHSA-F4GW-2P7V-4548 CVE-2026-67315 | Axios: NO_PROXY bypass for 0.0.0.0 local addresses in axios | 中危 | npmaxios | 已审查 | 2026-07-21 06:20 | 2026-09-02 02:39 |
| GHSA-7RC3-G7H6-22M7 CVE-2026-62685 | File Browser: Colliding username normalization gives two users the same home directory | 高危 | Gogithub.com/filebrowser/filebrowser/v2 | 已审查 | 2026-07-21 06:19 | 2026-07-21 06:19 |
| GHSA-833G-CQHP-H72J CVE-2026-62684 | File Browser: Share API exposes the password hash and bypass token | 低危 | Gogithub.com/filebrowser/filebrowser/v2 | 已审查 | 2026-07-21 06:17 | 2026-07-21 06:17 |
| GHSA-83XP-526H-J3WW CVE-2026-62843 | File Browser: Archive builder turns backslash filenames into path traversal (zip-slip) | 中危 | Gogithub.com/filebrowser/filebrowser/v2 | 已审查 | 2026-07-21 06:16 | 2026-07-21 06:16 |
| GHSA-JFJ6-75FJ-8934 CVE-2026-59876 | protobufjs: Text Format string map parsing can mutate returned map object prototype | 中危 | npmprotobufjs | 已审查 | 2026-07-21 06:04 | 2026-07-21 06:04 |
| GHSA-J3F2-48V5-CCWW CVE-2026-59877 | protobufjs: Denial of Service via infinite loop in .proto option parsing | 中危 | npmprotobufjs | 已审查 | 2026-07-21 06:03 | 2026-07-21 06:03 |
| GHSA-M28W-2PQF-7QGJ CVE-2026-14631 | webpack-dev-server vulnerable to denial of service via a malformed Host or Origin header | 中危 | npmwebpack-dev-server | 已审查 | 2026-07-21 06:02 | 2026-07-21 06:02 |
| GHSA-F5VJ-F2HX-8M93 CVE-2026-14620 | webpack-dev-server vulnerable to cross-site request forgery via internal developer endpoints | 中危 | npmwebpack-dev-server | 已审查 | 2026-07-21 06:01 | 2026-07-21 06:01 |
| GHSA-G446-98W2-8P5W CVE-2026-59883 | Guzzle: Cookie Disclosure and Injection via IP-Address Domains | 中危 | Packagistguzzlehttp/guzzle | 已审查 | 2026-07-21 06:00 | 2026-07-21 06:00 |
| GHSA-VJ59-8HWV-XXMV CVE-2026-59731 | Astro: Authorization Bypass via Decode Iteration Limit and Rewrite Path Canonicalization Mismatch | 高危 | npmastro | 已审查 | 2026-07-21 05:58 | 2026-07-21 05:58 |
| GHSA-GJFG-22FP-RRXX CVE-2026-59946 | Composer: Path traversal in package bin field lets dependencies chmod arbitrary host files | 中危 | Packagistcomposer/composer | 已审查 | 2026-07-21 05:57 | 2026-07-21 05:57 |
| GHSA-G6XQ-892H-64W3 CVE-2026-59947 | Composer: URL-embedded HTTP-Basic username leaks to verbose logs (GitHub PAT exposure) | 中危 | Packagistcomposer/composer | 已审查 | 2026-07-21 05:55 | 2026-07-21 05:55 |
| GHSA-W8WR-V893-VJVP CVE-2026-59871 | node-tar: Process crash via PAX numeric path type confusion | 中危 | npmtar | 已审查 | 2026-07-21 05:53 | 2026-07-21 05:53 |