检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-FCRP-7GC2-93G7 CVE-2026-53718 | Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass | 中危 | Gogithub.com/envoyproxy/gateway | 已审查 | 2026-07-17 03:14 | 2026-07-17 03:14 |
| GHSA-V95X-XHQ5-4929 CVE-2026-50166 | kumactl connects to control plane without verifying TLS certificate when no CA is configured |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 中危 |
Gogithub.com/kumahq/kuma+1 |
| 已审查 |
| 2026-07-17 03:12 |
| 2026-07-17 03:12 |
| GHSA-5CC2-282F-JJQ2 CVE-2026-15925 | Snowflake Connector for Python improperly verifies TLS hostnames | 严重 | PyPIsnowflake-connector-python | 已审查 | 2026-07-16 17:32 | 2026-09-01 06:35 |
| GHSA-PR64-JMMF-JP54 CVE-2026-58196 | ToolHive: SSRF in remote MCP server authentication discovery (host-side, bypasses container isolation) | 低危 | Gogithub.com/stacklok/toolhive | 已审查 | 2026-07-16 07:41 | 2026-07-16 07:41 |
| GHSA-XG43-5579-QW6V | adawolfa/isdoc: Uncontrolled resource consumption (decompression bomb) when reading untrusted ISDOCX or PDF files | 中危 | Packagistadawolfa/isdoc | 已审查 | 2026-07-16 07:30 | 2026-07-16 07:30 |
| GHSA-6F5R-5672-72J7 CVE-2026-54504 | @andrea9293/mcp-documentation-server: Web UI API binds to all interfaces without authentication by default | 高危 | npm@andrea9293/mcp-documentation-server | 已审查 | 2026-07-16 07:26 | 2026-07-16 07:26 |
| GHSA-5XPP-75JX-M839 CVE-2026-50289 | systeminformation: OS command injection in networkInterfaces() via interfaces(5) source-directive path on Linux | 高危 | npmsysteminformation | 已审查 | 2026-07-16 07:09 | 2026-07-16 07:09 |
| GHSA-GGW3-5987-RX77 CVE-2026-50285 | Pomerium Pre-Auth Memory Exhaustion via Unbounded zstd Decompression in HPKE Callback | 高危 | Gogithub.com/pomerium/pomerium | 已审查 | 2026-07-16 07:08 | 2026-07-16 07:08 |
| GHSA-P5F6-RCCC-JV98 CVE-2026-50276 | dd-trace-rb: Improper parsing of W3C baggage headers may lead to DoS | 高危 | RubyGemsdatadog | 已审查 | 2026-07-16 07:07 | 2026-07-16 07:07 |
| GHSA-74J5-XF3V-CRQ8 CVE-2026-50274 | dd-trace-go: Improper parsing of W3C baggage headers may lead to DoS | 高危 | Gogithub.com/DataDog/dd-trace-go+1 | 已审查 | 2026-07-16 07:05 | 2026-07-16 07:05 |
| GHSA-38WR-VPC7-2MP4 CVE-2026-50273 | dd-trace-dotnet: Improper parsing of W3C baggage headers may lead to DoS | 高危 | NuGetDatadog.Trace+1 | 已审查 | 2026-07-16 06:59 | 2026-07-16 06:59 |
| GHSA-WXQQ-GCQ8-C443 CVE-2026-50272 | dd-trace-js: Improper parsing of W3C baggage headers may lead to DoS | 高危 | npmdd-trace | 已审查 | 2026-07-16 06:58 | 2026-07-16 06:58 |
| GHSA-MW54-J2V2-42HR CVE-2026-50271 | dd-trace-py: Improper parsing of W3C baggage headers may lead to DoS | 高危 | PyPIddtrace | 已审查 | 2026-07-16 06:55 | 2026-07-16 06:55 |
| GHSA-74XJ-WH4W-VQXC CVE-2026-50270 | dd-trace-java: Improper parsing of W3C baggage headers may lead to DoS | 高危 | Mavencom.datadoghq:dd-java-agent | 已审查 | 2026-07-16 06:53 | 2026-07-16 06:53 |
| GHSA-9H85-G7W3-RH49 CVE-2026-54497 | ViewComponent: Reused Component Instances Retain Stale Render Context | 中危 | RubyGemsview_component | 已审查 | 2026-07-16 06:51 | 2026-07-16 06:51 |
| GHSA-97JW-64CJ-JC58 CVE-2026-54498 | ViewComponent: around_render HTML-Safety Bypass | 高危 | RubyGemsview_component | 已审查 | 2026-07-16 06:51 | 2026-07-16 06:51 |
| GHSA-398H-7F66-3H4P CVE-2026-54495 | open-feature-operator: Cross-namespace FeatureFlagSource and InProcessConfiguration resolution exposes spec contents on multi-tenant clusters | 中危 | Gogithub.com/open-feature/open-feature-operator | 已审查 | 2026-07-16 06:44 | 2026-07-16 06:44 |
| GHSA-R3HX-X5RH-P9VV | django-haystack: Remote Code Execution via `eval()` in Elasticsearch Result Deserialization | 高危 | PyPIdjango-haystack | 已审查 | 2026-07-16 06:42 | 2026-07-16 06:42 |
| GHSA-7GCF-G7XR-8HXJ | serde_with: KeyValueMap serialization panics on empty sequence or map entries | 中危 | crates.ioserde_with | 已审查 | 2026-07-16 06:41 | 2026-08-31 22:18 |
| GHSA-MP7J-QC5W-4988 CVE-2026-54490 | websocket-driver: Resource limit bypass via message compression | 中危 | npmwebsocket-driver | 已审查 | 2026-07-16 06:08 | 2026-07-16 06:08 |
| GHSA-XV26-6W52-CPH6 CVE-2026-54466 | websocket-driver: Message corruption via abuse of protocol length headers | 严重 | npmwebsocket-driver | 已审查 | 2026-07-16 06:07 | 2026-07-16 06:07 |
| GHSA-8J3G-F24P-4MPW CVE-2026-54465 | websocket-driver: Memory exhaustion in HTTP header parser | 中危 | RubyGemswebsocket-driver | 已审查 | 2026-07-16 06:05 | 2026-08-18 00:15 |
| GHSA-33PH-FCCM-39PJ CVE-2026-54464 | websocket-driver: Resource limit bypass via message compression | 中危 | RubyGemswebsocket-driver | 已审查 | 2026-07-16 06:03 | 2026-08-18 00:15 |
| GHSA-GHHP-3QVG-889P CVE-2026-54463 | websocket-driver: Memory exhaustion via abuse of protocol length headers | 中危 | RubyGemswebsocket-driver | 已审查 | 2026-07-16 06:01 | 2026-08-18 00:15 |
| GHSA-F5PF-Q7C7-M3VV CVE-2026-54254 | Pixeldrain API key shared with unverified thirdparty sites | 中危 | PyPIcyberdrop-dl-patched | 已审查 | 2026-07-16 06:00 | 2026-07-16 06:00 |