检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-CQ55-C7WV-PXMQ CVE-2026-62993 | Smarty: SSRF via redirect bypass of trusted_uri using {fetch} | 中危 | Packagistsmarty/smarty | 已审查 | 2026-09-02 00:38 | 2026-09-02 00:38 |
| GHSA-RF2P-VH74-7VVH CVE-2026-69127 | Kirby: System path exposure from error messages in the REST API |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 中危 |
Packagistgetkirby/cms |
| 已审查 |
| 2026-09-02 00:37 |
| 2026-09-02 00:37 |
| GHSA-RGWJ-5XJ2-C3M3 | MySQL2: Unbounded zlib inflate in compressed MySQL protocol handler allows decompression-bomb DoS | 中危 | npmmysql2 | 已审查 | 2026-09-01 06:36 | 2026-09-02 23:28 |
| GHSA-67MX-6WF2-92XP CVE-2026-71415 | Kirby: File upload permissions are not checked during processing of chunk data | 高危 | Packagistgetkirby/cms | 已审查 | 2026-09-01 06:14 | 2026-09-01 06:14 |
| GHSA-9VX2-J98C-P72W CVE-2026-75594 | Kirby: Access to image files and limited access to JSON files outside of the site root via path traversal in the media handling | 高危 | Packagistgetkirby/cms | 已审查 | 2026-09-01 06:12 | 2026-09-01 06:12 |
| GHSA-VCC3-GHJQ-M6FR CVE-2026-45822 | decode-uri-component: Denial of service via exponential decoding of malformed percent-encoded input | 中危 | npmdecode-uri-component | 已审查 | 2026-09-01 06:10 | 2026-09-01 06:10 |
| GHSA-VF76-F5CP-9846 | Duplicate Advisory: ReDoS in nltk.tgrep via unvalidated user-supplied regular expressions 已撤回 | 高危 | PyPInltk | 已审查 | 2026-09-01 05:31 | 2026-09-02 22:49 |
| GHSA-GR94-W7QR-F4J3 CVE-2026-59724 | Socket.IO: Engine.IO WebTransport SID DoS | 高危 | npmengine.io | 已审查 | 2026-09-01 05:28 | 2026-09-01 05:28 |
| GHSA-FM3F-CH8H-QW8Q CVE-2026-81888 | @hono/oauth-providers: OAuth state check fails open on omitted state, enabling login CSRF and forced account linking | 中危 | npm@hono/oauth-providers | 已审查 | 2026-09-01 04:30 | 2026-09-01 04:30 |
| GHSA-8X3Q-JPJH-QH5C CVE-2026-81889 | elFinder: SSRF protection bypass via DNS rebinding in the `fsock_get_contents()` fallback | 高危 | Packagiststudio-42/elfinder | 已审查 | 2026-09-01 04:28 | 2026-09-01 04:28 |
| GHSA-MFQJ-CQV3-H7XW CVE-2026-15305 | TYPO3 CMS - Unrestricted File Upload in Form Framework | 中危 | Packagisttypo3/cms-form | 已审查 | 2026-09-01 03:53 | 2026-09-01 03:53 |
| GHSA-H3HJ-CMCX-XC66 | Duplicate Advisory: Nodemailer: Message-level raw option bypasses disableFileAccess/disableUrlAccess, enabling arbitrary file read and full-response SSRF in the delivered message 已撤回 | 高危 | npmnodemailer | 已审查 | 2026-08-31 17:30 | 2026-09-02 22:47 |
| GHSA-G5XC-5W98-JFVM CVE-2026-55855 | MariaDB has possible SQL injection in Buffer parameter escaping under big5/gbk/sjis/cp932/gb18030 client charsets | 中危 | npmmariadb | 已审查 | 2026-08-29 06:53 | 2026-08-29 06:53 |
| GHSA-FFG3-P8FM-MJX2 CVE-2026-55830 | RestrictedPython guard hooks can be shadowed via positional-only arguments | 高危 | PyPIRestrictedPython | 已审查 | 2026-08-29 06:51 | 2026-08-29 06:51 |
| GHSA-C857-9X2M-CVH2 CVE-2026-55860 | org.mariadb:r2dbc-mariadb vulnerable to cleartext password disclosure to a man-in-the-middle server (clear-text auth plugins not gated on a secure transport) | 中危 | Mavenorg.mariadb:r2dbc-mariadb | 已审查 | 2026-08-29 06:50 | 2026-08-29 06:50 |
| GHSA-5RQC-86VF-G8R2 CVE-2026-55859 | org.mariadb:r2dbc-mariadb has Inappropriate Encoding for Output Context and Improper Encoding or Escaping of Output | 中危 | Mavenorg.mariadb:r2dbc-mariadb | 已审查 | 2026-08-29 06:49 | 2026-08-29 06:49 |
| GHSA-XVR9-35CR-46V9 CVE-2026-55858 | org.mariadb.jdbc:mariadb-java-client has Inappropriate Encoding for Output Context | 中危 | Mavenorg.mariadb.jdbc:mariadb-java-client | 已审查 | 2026-08-29 06:47 | 2026-08-29 06:47 |
| GHSA-QXVW-FVWX-5CP7 CVE-2026-55857 | org.mariadb.jdbc:mariadb-java-client has Cleartext Transmission of Sensitive Information and Insufficiently Protected Credentials | 中危 | Mavenorg.mariadb.jdbc:mariadb-java-client | 已审查 | 2026-08-29 06:45 | 2026-08-29 06:45 |
| GHSA-G9JJ-CGMH-9F38 CVE-2026-55856 | MariaDB has cleartext password disclosure to a MITM on the initial-handshake | 中危 | Mavenorg.mariadb.jdbc:mariadb-java-client | 已审查 | 2026-08-29 06:41 | 2026-08-29 06:41 |
| GHSA-J5G3-42WP-GQM3 CVE-2026-55843 | Snipe-IT has an Improper Privilege Management issue | 高危 | Packagistsnipe/snipe-it | 已审查 | 2026-08-29 06:37 | 2026-08-29 06:37 |
| GHSA-5V29-34H8-V68R CVE-2026-55848 | MapFish Print has XXE that allows reading arbitrary files of certain types | 高危 | Mavenorg.mapfish:print.print-servlet+2 | 已审查 | 2026-08-29 06:33 | 2026-08-29 06:33 |
| GHSA-FP46-6VFW-GC9C CVE-2026-55785 | free5GC AUSF uses non-constant-time authentication comparisons and logs XRES* in 5G-AKA | 低危 | Gogithub.com/free5gc/ausf | 已审查 | 2026-08-29 06:26 | 2026-08-29 06:26 |
| GHSA-334Q-H5G3-FPXV CVE-2026-55784 | free5GC AUSF authentication contexts can be overwritten by concurrent requests for the same SUPI | 高危 | Gogithub.com/free5gc/ausf | 已审查 | 2026-08-29 06:24 | 2026-08-29 06:24 |
| GHSA-M4G4-86QC-V8W7 CVE-2026-55779 | silverstripe/versioned has XSS in archive admin restore | 中危 | Packagistsilverstripe/versioned | 已审查 | 2026-08-29 06:19 | 2026-08-29 06:19 |
| GHSA-56WQ-X3WV-3FF4 CVE-2026-55874 | SeaweedFS: Path traversal in the S3 gateway X-Amz-Copy-Source header allows cross-bucket object read | 高危 | Gogithub.com/seaweedfs/seaweedfs | 已审查 | 2026-08-29 06:17 | 2026-08-29 06:17 |