检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-W757-XVVV-VGFW CVE-2026-63397 | Genql: inject arbitrary JavaScript or TypeScript via a GraphQL schema | 高危 | npm@genql/cli | 已审查 | 2026-07-17 05:30 | 2026-08-14 02:29 |
| GHSA-X8MG-6R4P-87PF | ArcadeDB has cross-database IDOR: /ts/*, /batch/*, Prometheus and Grafana handlers bypass authorization |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 高危 |
Mavencom.arcadedb:arcadedb-server |
| 已审查 |
| 2026-07-17 04:20 |
| 2026-07-17 04:20 |
| GHSA-VWJC-V7X7-CM6G | ArcadeDB: Scripting authorization gate (GHSA-48qw-824m-86pr) bypassed via SQL DEFINE FUNCTION ... LANGUAGE js | 高危 | Mavencom.arcadedb:arcadedb-engine | 已审查 | 2026-07-17 04:17 | 2026-07-17 04:17 |
| GHSA-X9F9-R4M8-9XC2 | ArcadeDB: Trigger scripts run with java.lang.* allowed, enabling OS command execution (RCE) | 高危 | Mavencom.arcadedb:arcadedb-engine | 已审查 | 2026-07-17 04:15 | 2026-07-17 04:15 |
| GHSA-VJ7Q-GJH5-988W CVE-2026-59950 | MCP Python SDK: WebSocket server transport does not support Host/Origin validation | 高危 | PyPImcp | 已审查 | 2026-07-17 04:14 | 2026-07-17 04:14 |
| GHSA-48QW-824M-86PR | ArcadeDB: Privilege escalation via reader role in /api/v1/command JS scripting language — arbitrary host file read | 高危 | Mavencom.arcadedb:arcadedb-server | 已审查 | 2026-07-17 04:13 | 2026-07-17 04:13 |
| GHSA-P4H7-P9RJ-2PQ2 CVE-2026-55579 | Pheditor: Hardcoded default password 'admin' with no forced change enables full application compromise | 严重 | Packagistpheditor/pheditor | 已审查 | 2026-07-17 04:11 | 2026-07-17 04:11 |
| GHSA-WG4W-WR5Q-6VJC CVE-2026-55578 | Pheditor: Incomplete command sanitization in terminal feature allows RCE via pipe operator, backtick substitution, and newline injection | 高危 | Packagistpheditor/pheditor | 已审查 | 2026-07-17 04:10 | 2026-07-17 04:10 |
| GHSA-WVMP-6R4V-J6CV CVE-2026-52724 | kuma-dp connects to control plane without verifying TLS certificate when no CA is configured | 中危 | Gogithub.com/kumahq/kuma+1 | 已审查 | 2026-07-17 04:09 | 2026-07-17 04:09 |
| GHSA-VG6X-6PG9-6QWG CVE-2026-54076 | ArcadeDB: Read-only users can mutate database schema (incomplete fix of CVE-2026-44221) | 高危 | Mavencom.arcadedb:arcadedb-engine | 已审查 | 2026-07-17 04:08 | 2026-07-17 04:08 |
| GHSA-8W86-M9H8-HVQG CVE-2026-54077 | ArcadeDB: IMPORT DATABASE allows SSRF and arbitrary local file read by authenticated users | 高危 | Mavencom.arcadedb:arcadedb-engine | 已审查 | 2026-07-17 04:05 | 2026-07-17 04:05 |
| GHSA-5RG2-XV9J-GV5P CVE-2026-54542 | nimiq-primitives: Out-of-bounds panic in KeyNibbles::Add from oversized child suffix in a deserialized proof | 低危 | crates.ionimiq-primitives | 已审查 | 2026-07-17 04:03 | 2026-07-17 04:03 |
| GHSA-46WQ-28CX-MHW4 CVE-2026-54541 | nimiq-primitives: Panic in TrieProof::verify via child_index unwrap on equal-length keys | 低危 | crates.ionimiq-primitives | 已审查 | 2026-07-17 04:03 | 2026-07-17 04:03 |
| GHSA-9643-6XJP-VX57 CVE-2026-54540 | Pheditor has an authenticated terminal command whitelist bypass | 高危 | Packagistpheditor/pheditor | 已审查 | 2026-07-17 04:01 | 2026-07-17 04:01 |
| GHSA-JPW9-PFVF-9F58 CVE-2026-52869 | MCP Python SDK: HTTP transports serve session requests without verifying the authenticated principal | 高危 | PyPImcp | 已审查 | 2026-07-17 03:58 | 2026-07-17 03:58 |
| GHSA-HVRP-RF83-W775 CVE-2026-52870 | MCP Python SDK: Experimental task handlers allow any client to access and cancel other clients' tasks | 高危 | PyPImcp | 已审查 | 2026-07-17 03:56 | 2026-07-17 03:56 |
| GHSA-WPCJ-RMV4-86QG CVE-2026-52832 | Nuclio: Unauthenticated path traversal in spec.handler allows arbitrary file write in Dashboard container | 中危 | Gogithub.com/nuclio/nuclio | 已审查 | 2026-07-17 03:47 | 2026-07-17 03:47 |
| GHSA-3V79-M2CG-89WW CVE-2026-52833 | Nuclio: Unsanitized runtimeAttributes.repositories injected into Groovy build.gradle leads to build-time RCE | 高危 | Gogithub.com/nuclio/nuclio | 已审查 | 2026-07-17 03:40 | 2026-07-17 03:40 |
| GHSA-22XC-XG2R-9J7V CVE-2026-53714 | Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode | 高危 | Gogithub.com/envoyproxy/gateway | 已审查 | 2026-07-17 03:32 | 2026-07-17 03:32 |
| GHSA-GGXF-9F6J-W742 | Diesel has possible use after free when deserializing a SQLite database via `SqliteConnection::deserialize_readonly_database` | 中危 | crates.iodiesel | 已审查 | 2026-07-17 03:25 | 2026-07-17 03:25 |
| GHSA-WCRF-9VRR-854F CVE-2026-53713 | Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure | 严重 | Gogithub.com/envoyproxy/gateway | 已审查 | 2026-07-17 03:23 | 2026-07-17 03:23 |
| GHSA-8FV2-88GG-HM7Q CVE-2026-53715 | Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock | 中危 | Gogithub.com/envoyproxy/gateway | 已审查 | 2026-07-17 03:21 | 2026-07-17 03:21 |
| GHSA-H7PQ-86H8-RP5X CVE-2026-53717 | Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header | 中危 | Gogithub.com/envoyproxy/gateway | 已审查 | 2026-07-17 03:20 | 2026-07-17 03:20 |
| GHSA-M2V6-2JMH-4C68 CVE-2026-53719 | Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization | 中危 | Gogithub.com/envoyproxy/gateway | 已审查 | 2026-07-17 03:19 | 2026-07-17 03:19 |
| GHSA-CXPQ-8V7Q-CG56 CVE-2026-53716 | Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit | 中危 | Gogithub.com/envoyproxy/gateway | 已审查 | 2026-07-17 03:18 | 2026-07-17 03:18 |