检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-W7CG-WHH7-XP28 CVE-2026-54070 | SiYuan: Stored XSS in Bazaar marketplace via package README event handlers | 高危 | Gogithub.com/siyuan-note/siyuan/kernel | 已审查 | 2026-07-11 03:27 | 2026-07-11 03:27 |
| GHSA-XQP3-JQ6G-X3QM CVE-2026-54089 |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 严重 |
Gogithub.com/filebrowser/filebrowser/v2 |
| 已审查 |
| 2026-07-11 03:27 |
| 2026-07-11 03:27 |
| GHSA-HVR9-72V2-FFF3 CVE-2026-54069 | SiYuan: Unauthenticated Admin API Access via Blanket chrome-extension:// Origin Allowlist | 严重 | Gogithub.com/siyuan-note/siyuan/kernel | 已审查 | 2026-07-11 03:26 | 2026-07-11 03:27 |
| GHSA-GCM7-57GF-953C CVE-2026-54068 | SiYuan: Unauthenticated SQLite Data Exfiltration via Template Injection in /api/icon/getDynamicIcon | 中危 | Gogithub.com/siyuan-note/siyuan/kernel | 已审查 | 2026-07-11 03:26 | 2026-07-11 03:26 |
| GHSA-9MQM-QCWF-5QHG | CredSweeper: Recursive archive size-limit bypass in deep scanner allows crafted compressed inputs to exhaust resources | 中危 | PyPIcredsweeper | 已审查 | 2026-07-11 03:25 | 2026-07-11 03:25 |
| GHSA-H69G-9HX6-F3V4 CVE-2026-54063 | Excelize: Unbounded Row Index Allocation in Worksheet Parser (checkSheet OOM/Panic DoS) | 高危 | Gogithub.com/xuri/excelize/v2 | 已审查 | 2026-07-11 03:25 | 2026-07-11 03:25 |
| GHSA-H29V-HJ44-Q8CV CVE-2026-54072 | Authorizer: Unvalidated redirect_uri in /authorize leaks OAuth2 tokens to attacker-controlled URL | 严重 | Gogithub.com/authorizerdev/authorizer | 已审查 | 2026-07-11 03:25 | 2026-07-11 03:25 |
| GHSA-MVJR-VV3C-W4QV CVE-2026-54067 | SiYuan: Stored XSS to RCE via CSS-snippet <style> breakout in renderSnippet() | 严重 | Gogithub.com/siyuan-note/siyuan/kernel | 已审查 | 2026-07-11 03:25 | 2026-07-11 03:25 |
| GHSA-P4M3-MGMM-C664 CVE-2026-54066 | SiYuan: Path Traversal via Double URL Encoding in /assets/*path (publish mode arbitrary file─read), Incomplete fix of CVE-2026-41894 | 高危 | Gogithub.com/siyuan-note/siyuan/kernel | 已审查 | 2026-07-11 03:25 | 2026-07-11 03:25 |
| GHSA-XCPC-8H2W-3J85 CVE-2026-39244 | adm-zip: Crafted ZIP file triggers 4GB memory allocation | 高危 | npmadm-zip | 已审查 | 2026-07-11 02:32 | 2026-07-18 05:50 |
| GHSA-489G-7RXV-6C8Q | MCP Atlassian: DNS-rebinding TOCTOU bypass of the SSRF fix (CVE-2026-27826) | 中危 | PyPImcp-atlassian | 已审查 | 2026-07-11 02:01 | 2026-07-11 02:01 |
| GHSA-JXJ7-G6GM-49J7 CVE-2026-49977 | tarteaucitron: data-cookie attribute can be used to delete arbitrary cookies | 中危 | npmtarteaucitronjs | 已审查 | 2026-07-11 00:05 | 2026-07-11 00:05 |
| GHSA-CWC9-CP4J-MCVV CVE-2026-49866 | libp2p: CPU DoS via oversized IHAVE and IWANT control message arrays | 高危 | npm@libp2p/gossipsub | 已审查 | 2026-07-11 00:04 | 2026-07-11 00:04 |
| GHSA-PJ8J-P4G4-4VW8 CVE-2026-49865 | Kimai has Server-Side Request Forgery in Invoice PDF Rendering via Markdown Image URLs | 中危 | Packagistkimai/kimai | 已审查 | 2026-07-11 00:04 | 2026-07-11 00:04 |
| GHSA-2VWW-6P9H-5G8J | Duplicate Advisory: Authenticated Users Can Exhaust Temporary Disk Storage via Data-Table File Uploads 已撤回 | 中危 | npmn8n | 已审查 | 2026-07-10 23:31 | 2026-07-23 06:25 |
| GHSA-4VJ7-5MJ6-JM8M CVE-2026-5078 | morgan vulnerable to Log Forging via unneutralized control characters in :remote-user | 中危 | npmmorgan | 已审查 | 2026-07-10 22:32 | 2026-07-10 22:32 |
| GHSA-PJHX-3C3W-9V23 CVE-2026-49858 | API Platform Core vulnerable to cross-user attribute leak in JSON:API and HAL item normalizers due to missing isCacheKeySafe gate | 中危 | Packagistapi-platform/core+2 | 已审查 | 2026-07-10 22:32 | 2026-07-10 22:32 |
| GHSA-JWP9-9V96-94MX CVE-2026-39243 | decompress allows arbitrary hardlink creation during archive extraction | 中危 | npmdecompress | 已审查 | 2026-07-10 08:31 | 2026-08-13 22:18 |
| GHSA-28JH-G32X-V9V4 CVE-2026-48598 | Tesla vulnerable to multipart part smuggling via unescaped `content-disposition` values | 低危 | Hextesla | 已审查 | 2026-07-10 08:04 | 2026-07-10 08:04 |
| GHSA-H74C-Q9J7-MPCM CVE-2026-48597 | Tesla vulnerable to atom exhaustion via untrusted URL scheme | 高危 | Hextesla | 已审查 | 2026-07-10 08:03 | 2026-07-10 08:03 |
| GHSA-9M9W-GXF7-RH8M CVE-2026-48595 | Tesla: Authorization header leaks on cross-origin redirect via case-sensitive filtering | 高危 | Hextesla | 已审查 | 2026-07-10 08:03 | 2026-07-10 08:03 |
| GHSA-MC85-72GR-VM9F CVE-2026-48594 | Tesla has decompression bomb on response body | 高危 | Hextesla | 已审查 | 2026-07-10 08:03 | 2026-07-10 08:03 |
| GHSA-Q7JX-V53G-848W CVE-2026-48596 | Tesla has CRLF injection in request `Content-Type` header via `add_content_type_param` | 低危 | Hextesla | 已审查 | 2026-07-10 08:03 | 2026-07-10 08:03 |
| GHSA-QCQ2-496W-V96P CVE-2026-49851 | Mistune: Potential DoS via quadratic-time parsing in parse_link_text | 高危 | PyPImistune | 已审查 | 2026-07-10 07:52 | 2026-07-10 07:52 |
| GHSA-FRRJ-87JH-2772 CVE-2026-49838 | GoBGP confederation validation panics on empty AS_PATH attribute | 中危 | Gogithub.com/osrg/gobgp/v4 | 已审查 | 2026-07-10 07:21 | 2026-07-10 07:21 |