检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-824W-X939-6CMC CVE-2026-54457 | TensorZero Gateway: Arbitrary file read and SSRF in internal object storage endpoint | 高危 | PyPItensorzero | 已审查 | 2026-07-16 05:59 | 2026-07-16 05:59 |
| GHSA-XGCH-X3MX-CM3C CVE-2026-54452 | safeurl is Missing IPv6 CIDR Ranges in Blocklist |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 中危 |
Gogithub.com/doyensec/safeurl |
| 已审查 |
| 2026-07-16 05:58 |
| 2026-07-16 05:58 |
| GHSA-Q78P-HJ9H-5466 CVE-2026-53656 | FiftyOne App server uses wildcard CORS (Access-Control-Allow-Origin: *), enabling cross-origin reads of local server data | 中危 | PyPIfiftyone | 已审查 | 2026-07-16 05:57 | 2026-07-16 05:57 |
| GHSA-62GX-5Q78-WRVX | obsidian-local-rest-api: Authenticated path traversal via URL-encoded %2F in /vault/{path} — arbitrary host file read/write/delete | 高危 | npmobsidian-local-rest-api | 已审查 | 2026-07-16 05:56 | 2026-07-16 05:56 |
| GHSA-PPH6-VFJV-VPJW CVE-2026-54450 | ToolHive: SSRF guard misses IPv6 NAT64 ranges (64:ff9b::/96, 64:ff9b:1::/48), allowing metadata/internal access behind a NAT64 gateway | 低危 | Gogithub.com/stacklok/toolhive | 已审查 | 2026-07-16 05:51 | 2026-07-16 05:51 |
| GHSA-H738-VH6G-Q8GH | Duplicate Advisory: Command Injection in jsii-diff via npm: package argument 已撤回 | 高危 | npmjsii-diff | 已审查 | 2026-07-16 05:31 | 2026-08-08 02:15 |
| GHSA-H2WF-967X-GXVW CVE-2026-62944 | MantisBT: Stored XSS in print_all_bug_page_word.php | 高危 | Packagistmantisbt/mantisbt | 已审查 | 2026-07-16 02:56 | 2026-07-16 02:56 |
| GHSA-4VPF-W7QV-5H3Q CVE-2026-52883 | MantisBT: Injection of TIME_TRACKING and REMINDER Notes via REST and SOAP APIs | 中危 | Packagistmantisbt/mantisbt | 已审查 | 2026-07-16 02:52 | 2026-07-16 02:52 |
| GHSA-3V2J-6FW9-F57C CVE-2026-52882 | MantisBT: REST and SOAP API Issue Update Accepts Unreleased Product Versions From Updaters | 中危 | Packagistmantisbt/mantisbt | 已审查 | 2026-07-16 02:41 | 2026-07-16 02:41 |
| GHSA-VCRW-4XVV-JH49 CVE-2026-52881 | MantisBT: Reflected XSS in admin/install.php via unescaped printf | 严重 | Packagistmantisbt/mantisbt | 已审查 | 2026-07-16 02:34 | 2026-07-16 02:34 |
| GHSA-QQMF-GPG7-G8GW CVE-2026-58659 | PyTorch Lightning allows arbitrary code execution through checkpoint _instantiator hyperparameters | 高危 | PyPIlightning | 已审查 | 2026-07-16 02:31 | 2026-09-04 03:51 |
| GHSA-77X8-3V3H-HRHV CVE-2026-52847 | MantisBT: Reflected XSS in admin/install.php | 严重 | Packagistmantisbt/mantisbt | 已审查 | 2026-07-16 02:25 | 2026-07-16 02:25 |
| GHSA-RJG7-R26H-CFP2 CVE-2026-54494 | Koel: Full-read SSRF via podcast enclosure URL: isPublicHost() filter_var guard does not reject NAT64 (64:ff9b::/96) or 6to4 (2002::/16) IPv6-transition wrappers of internal IPv4 | 中危 | Packagistphanan/koel | 已审查 | 2026-07-16 02:21 | 2026-07-16 02:21 |
| GHSA-JR4P-4XJH-FWVW CVE-2026-50552 | Koel: Server-Side Request Forgery (SSRF) in radio station creation due to missing validation bail | 中危 | Packagistphanan/koel | 已审查 | 2026-07-16 02:21 | 2026-07-16 02:21 |
| GHSA-6QVR-WJMV-V8MM CVE-2026-54491 | Koel: Incomplete fix for CVE-2026-47260 — systemic SSRF in podcast & radio fetch paths | 高危 | Packagistphanan/koel | 已审查 | 2026-07-16 01:59 | 2026-07-16 01:59 |
| GHSA-RV48-QQJ5-CRXG CVE-2026-54451 | Protobuf: Unbounded recursion depth in embedded-message decoding | 高危 | Hexprotobuf | 已审查 | 2026-07-16 01:44 | 2026-07-16 01:44 |
| GHSA-3PVH-63GF-J9MW CVE-2026-54449 | LangBot: Authenticated RCE Via MCP Configuration | 高危 | PyPIlangbot | 已审查 | 2026-07-16 01:39 | 2026-07-16 01:39 |
| GHSA-WJHR-76VG-2HVC CVE-2026-54447 | garminconnect Has Insecure Permission Assignment for Garmin OAuth Token Store | 高危 | PyPIgarminconnect | 已审查 | 2026-07-16 01:33 | 2026-07-16 01:33 |
| GHSA-8Q6Q-M837-FV64 | Koel has SSRF through Authenticated Subsonic podcast feed URLs | 中危 | Packagistphanan/koel | 已审查 | 2026-07-16 01:31 | 2026-07-16 01:31 |
| GHSA-6P96-CFG5-4VHP CVE-2026-54493 | Koel: Authenticated Full-Read SSRF via Subsonic Internet Radio Stations | 高危 | Packagistphanan/koel | 已审查 | 2026-07-16 01:13 | 2026-07-16 01:13 |
| GHSA-W79M-F3JX-779V CVE-2026-54492 | Koel: Authenticated Blind SSRF via Subsonic Podcast Channel Creation | 中危 | Packagistphanan/koel | 已审查 | 2026-07-16 01:07 | 2026-07-16 01:07 |
| GHSA-M7PH-9558-MRX3 CVE-2026-49280 | MantisBT: REST API unauthorized Issue status change | 中危 | Packagistmantisbt/mantisbt | 已审查 | 2026-07-16 01:02 | 2026-07-16 01:02 |
| GHSA-V84X-QVHG-F36R CVE-2026-49273 | MantisBT: Remote Code Execution via eval() Class Hoisting in adm_config_set.php | 高危 | Packagistmantisbt/mantisbt | 已审查 | 2026-07-16 00:52 | 2026-07-16 00:52 |
| GHSA-C2XG-QJQW-2V98 CVE-2026-47156 | MantisBT: SOAP API Authentication Bypass with Privilege Escalation to Administrator | 严重 | Packagistmantisbt/mantisbt | 已审查 | 2026-07-16 00:45 | 2026-07-16 00:45 |
| GHSA-MW6P-33VW-46CC CVE-2026-47142 | MantisBT: SQL Injection via history_order Configuration Value | 高危 | Packagistmantisbt/mantisbt | 已审查 | 2026-07-16 00:38 | 2026-07-16 00:38 |