检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-23HP-3JRH-7FPW CVE-2026-59873 | node-tar: Decompression/parse DoS via unlimited input | 严重 | npmtar | 已审查 | 2026-07-21 05:52 | 2026-07-21 05:52 |
| GHSA-8X88-C5MF-7J5W CVE-2026-59874 | node-tar: Negative tar entry size causes infinite loop in archive replace |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 高危 |
npmtar |
| 已审查 |
| 2026-07-21 05:51 |
| 2026-07-21 05:51 |
| GHSA-GVWX-54WH-QM9J CVE-2026-59875 | node-tar: Uncaught Exception DoS via NUL byte in PAX path/linkpath records | 中危 | npmtar | 已审查 | 2026-07-21 05:51 | 2026-07-21 05:51 |
| GHSA-R635-G3XR-VW7X CVE-2026-59725 | Socket.IO: Engine.IO Polling Transport Connection Exhaustion | 高危 | npmengine.io | 已审查 | 2026-07-21 05:49 | 2026-07-21 05:49 |
| GHSA-395F-4HP3-45GV CVE-2026-13311 | shell-quote: Quadratic-complexity Denial of Service in `parse()` (CWE-407) | 高危 | npmshell-quote | 已审查 | 2026-07-21 05:49 | 2026-07-21 05:49 |
| GHSA-C6W9-5G5J-JH2P CVE-2026-61836 | Directus: Authorization-dependent response served from unsegmented cache key | 高危 | npmdirectus | 已审查 | 2026-07-21 05:48 | 2026-07-21 05:48 |
| GHSA-J5H6-VQC3-PHQH CVE-2026-61835 | Directus: SSRF Protection Bypass via 0.0.0.0 in File Import | 高危 | npmdirectus | 已审查 | 2026-07-21 05:47 | 2026-07-21 05:47 |
| GHSA-F4VV-55C2-5789 CVE-2026-61740 | LightRAG is Vulnerable to Authentication Bypass: hardcoded DEFAULT_TOKEN_SECRET and public /auth-status defeat LIGHTRAG_API_KEY protection | 严重 | PyPIlightrag-hku | 已审查 | 2026-07-21 05:46 | 2026-07-21 05:46 |
| GHSA-94PJ-82F3-465W CVE-2026-67339 | Guzzle: Proxy-Authorization headers can be sent to origin servers | 中危 | Packagistguzzlehttp/guzzle | 已审查 | 2026-07-21 05:46 | 2026-08-04 20:49 |
| GHSA-6X6H-QQR7-855W CVE-2026-61736 | LightRAG: CORS Wildcard + Credentials Enables Any-Origin Credentialed Requests | 严重 | PyPIlightrag-hku | 已审查 | 2026-07-21 05:45 | 2026-07-21 05:45 |
| GHSA-QFRW-5RXM-MHH2 CVE-2026-59929 | Mistune renderers/html.safe_url: HARMFUL_PROTOCOLS list misses legacy and chained schemes that historically chain to `javascript:` execution | 中危 | PyPImistune | 已审查 | 2026-07-21 05:35 | 2026-07-21 05:35 |
| GHSA-2HM2-HC3V-44H9 CVE-2026-59930 | Mistune toc / TableOfContents directive: heading IDs use predictable `toc_N` numbering with no slugification, allowing collision with attacker-controlled `id="toc_N"` content | 中危 | PyPImistune | 已审查 | 2026-07-21 05:35 | 2026-07-21 05:35 |
| GHSA-R4RV-85JG-W4MF CVE-2026-59924 | Mistune: Arbitrary File Read via Include directive path traversal | 中危 | PyPImistune | 已审查 | 2026-07-21 05:34 | 2026-07-21 05:34 |
| GHSA-C8J7-8CV4-2XMQ CVE-2026-59922 | Mistune plugins/formatting: quadratic-time parsing on long runs of `~~x~~`, `==x==`, and `^^x^^` markers (strikethrough / mark / insert) | 高危 | PyPImistune | 已审查 | 2026-07-21 05:34 | 2026-07-21 05:34 |
| GHSA-G97X-GVCM-X72H CVE-2026-59926 | Mistune: XSS via unescaped class option in Admonition directive | 中危 | PyPImistune | 已审查 | 2026-07-21 05:34 | 2026-07-21 05:34 |
| GHSA-8C25-4J27-2RV3 CVE-2026-59923 | Mistune: XSS via percent-encoded javascript URI bypass in safe_url() | 中危 | PyPImistune | 已审查 | 2026-07-21 05:32 | 2026-07-21 05:32 |
| GHSA-4J32-57V6-6G45 CVE-2026-59925 | Mistune inline_parser: quadratic-time parsing on long runs of `**x**` and `***x***` emphasis pairs | 高危 | PyPImistune | 已审查 | 2026-07-21 05:32 | 2026-07-21 05:32 |
| GHSA-8MPJ-M6QM-5QR8 CVE-2026-59927 | Mistune directives/include: mutual `.. include::` recursion crashes the renderer with `RecursionError`, denial of service via two attacker-controlled markdown files | 中危 | PyPImistune | 已审查 | 2026-07-21 05:24 | 2026-07-21 05:24 |
| GHSA-FFQ3-XPV3-J92Q CVE-2026-59928 | Mistune block_parser: quadratic-time parsing on long lists of repeated reference-link definitions | 高危 | PyPImistune | 已审查 | 2026-07-21 05:24 | 2026-07-21 05:24 |
| GHSA-G796-FGMG-93MV CVE-2026-59868 | js-yaml: YAML merge-key chains can force quadratic CPU consumption in js-yaml | 中危 | npmjs-yaml | 已审查 | 2026-07-21 05:19 | 2026-07-21 05:19 |
| GHSA-52CP-R559-CP3M CVE-2026-59869 | js-yaml: YAML merge-key chains can force quadratic CPU consumption | 高危 | npmjs-yaml | 已审查 | 2026-07-21 05:19 | 2026-07-21 05:19 |
| GHSA-724G-MXRG-4QVM CVE-2026-59870 | js-yaml: Quadratic-complexity (O(n^2)) DoS via !!omap tag in YAML11_SCHEMA | 中危 | npmjs-yaml | 已审查 | 2026-07-21 05:18 | 2026-07-21 05:18 |
| GHSA-8WC8-HF36-MJH9 CVE-2026-55668 | File Browser: ScopedFs follows a dangling symlink on write, letting a scoped user create files outside their scope | 中危 | Gogithub.com/filebrowser/filebrowser/v2 | 已审查 | 2026-07-21 05:17 | 2026-07-21 05:17 |
| GHSA-FMM7-X4GX-8JHR CVE-2026-55667 | File Browser: Out-of-scope file deletion by a Create-only scoped user via symlink-following RemoveAll in upload failure-cleanup | 高危 | Gogithub.com/filebrowser/filebrowser/v2 | 已审查 | 2026-07-21 05:17 | 2026-07-21 05:17 |
| GHSA-X756-G4X3-C64M CVE-2026-54562 | Cloudreve: Non-admin remote download users can SSRF loopback/internal services and read imported responses | 中危 | Gogithub.com/cloudreve/Cloudreve/v3+1 | 已审查 | 2026-07-21 05:16 | 2026-07-21 05:16 |