检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-GJRG-JJR3-56CM CVE-2026-49837 | GoBGP: BGP OPEN capability parser may read capability values outside declared CapLen boundaries | 中危 | Gogithub.com/osrg/gobgp/v4 | 已审查 | 2026-07-10 07:20 | 2026-07-10 07:20 |
| GHSA-2RMG-VRX8-9J2F CVE-2026-49836 | psd-tools vulnerable to arbitrary file write via smart-object filename |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 中危 |
PyPIpsd-tools |
| 已审查 |
| 2026-07-10 07:20 |
| 2026-07-10 07:20 |
| GHSA-9VCR-P3RJ-Q5Q6 CVE-2026-49834 | sigstore-go has a multi-log threshold bypass via single compromised log | 中危 | Gogithub.com/sigstore/sigstore-go | 已审查 | 2026-07-10 07:20 | 2026-08-01 04:17 |
| GHSA-H672-P7H7-97V9 CVE-2026-53956 | Rattler vulnerable to package cache path traversal via conda package build string | 中危 | crates.iopy_rattler+1 | 已审查 | 2026-07-10 07:20 | 2026-07-10 07:20 |
| GHSA-H5G6-XMH4-HC37 CVE-2026-55252 | OpenRun: Redirect URL validation bypass using //host paths leads to Open Redirect | 中危 | Gogithub.com/openrundev/openrun | 已审查 | 2026-07-10 07:19 | 2026-07-10 07:19 |
| GHSA-G586-CCQF-7X4R CVE-2026-48862 | mint: Unbounded streams map growth via PUSH_PROMISE without follow-up HEADERS | 高危 | Hexmint | 已审查 | 2026-07-10 07:19 | 2026-07-10 07:19 |
| GHSA-2P26-P43X-FHP8 CVE-2026-49754 | mint: Unbounded CONTINUATION/HEADERS frame accumulation (CONTINUATION flood) | 高危 | Hexmint | 已审查 | 2026-07-10 07:19 | 2026-07-10 07:19 |
| GHSA-MJQX-C6F6-7RC2 CVE-2026-49753 | mint: Content-Length header accepts non-RFC "+" sign prefix | 中危 | Hexmint | 已审查 | 2026-07-10 07:19 | 2026-07-10 07:19 |
| GHSA-2PG6-44CX-C49V CVE-2026-48861 | mint has potential CRLF injection in its HTTP request line via unvalidated `method`/`target` | 低危 | Hexmint | 已审查 | 2026-07-10 07:19 | 2026-07-10 07:19 |
| GHSA-G9XF-7F8Q-9MCJ CVE-2026-54651 | pypdf: Possible infinite loop when processing threads/articles in writer | 中危 | PyPIpypdf | 已审查 | 2026-07-10 05:09 | 2026-07-10 05:09 |
| GHSA-MR9R-H354-966R CVE-2026-53639 | Sylius: IDOR on Shop Payment Request API endpoints | 中危 | Packagistsylius/sylius | 已审查 | 2026-07-10 05:03 | 2026-07-10 05:03 |
| GHSA-6955-HRM5-C4QP CVE-2026-53638 | Sylius: Channel-based payment method restriction bypass on shop account orders API endpoint | 中危 | Packagistsylius/sylius | 已审查 | 2026-07-10 05:03 | 2026-07-10 05:03 |
| GHSA-5597-7RMH-97Q5 CVE-2026-53637 | Sylius: Cart FormComponent allows modification or deletion of an already-completed order | 中危 | Packagistsylius/sylius | 已审查 | 2026-07-10 05:03 | 2026-07-10 05:03 |
| GHSA-PX5M-H76G-P7P8 CVE-2026-52778 | YesWiki has Unsafe eval() in its Formula Calculato, Leading to Remote Code Execution & Denial of Service | 严重 | Packagistyeswiki/yeswiki | 已审查 | 2026-07-10 05:03 | 2026-07-10 05:03 |
| GHSA-9369-69WJ-7M2F CVE-2026-52777 | YesWiki Vulnerable to Authenticated PHP Object Injection in BazarImportAction via unserialize | 严重 | Packagistyeswiki/yeswiki | 已审查 | 2026-07-10 05:02 | 2026-07-10 05:02 |
| GHSA-4PF7-CC4R-G63H CVE-2026-52775 | YesWiki has Authenticated SQL Injection via ReactionManager | 高危 | Packagistyeswiki/yeswiki | 已审查 | 2026-07-10 05:02 | 2026-07-10 05:02 |
| GHSA-R5XW-GCGW-HWP5 CVE-2026-52774 | YesWiki Vulnerable to Reflected XSS via Unescaped `id` Parameter in Bazar Widget HTML Attributes | 中危 | Packagistyeswiki/yeswiki | 已审查 | 2026-07-10 05:01 | 2026-07-10 05:01 |
| GHSA-35F3-PG38-486F CVE-2026-52773 | YesWiki Vulnerable to Reflected XSS via Unescaped Archived-Revision `time` Parameter in `handlers/page/show.php` | 中危 | Packagistyeswiki/yeswiki | 已审查 | 2026-07-10 05:00 | 2026-07-10 05:00 |
| GHSA-XC7J-3G8Q-9VH4 CVE-2026-52772 | YesWiki has stored XSS in Bazar form-field templates via unescaped field.label / field.hint (|raw('html')) | 中危 | Packagistyeswiki/yeswiki | 已审查 | 2026-07-10 05:00 | 2026-07-10 05:00 |
| GHSA-8F2V-2QHJ-GFWG CVE-2026-52771 | YesWiki: Second-Order SQL Injection in Page Delete API via Unescaped Page Tag (`ApiController::deletePage`) | 高危 | Packagistyeswiki/yeswiki | 已审查 | 2026-07-10 05:00 | 2026-07-10 05:00 |
| GHSA-QG78-VMVC-FHJW CVE-2026-52770 | YesWiki: SQL Injection possible through public Bazar entry-listing APIs via numeric `query`/`queries` filters | 高危 | Packagistyeswiki/yeswiki | 已审查 | 2026-07-10 05:00 | 2026-07-10 05:00 |
| GHSA-VW42-752G-5MRP CVE-2026-52769 | YesWiki has Unauthenticated Server-Side Request Forgery via ActivityPub `Signature.keyId` | 高危 | Packagistyeswiki/yeswiki | 已审查 | 2026-07-10 04:58 | 2026-07-10 04:58 |
| GHSA-MV28-WJ57-F57G CVE-2026-52767 | YesWiki Vulnerable to Unauthenticated ActivityPub Signature-Verification Bypass via `!openssl_verify(...)` accepting `int(-1)` | 高危 | Packagistyeswiki/yeswiki | 已审查 | 2026-07-10 04:58 | 2026-07-10 04:58 |
| GHSA-6X7X-GCMF-7R8X CVE-2026-52766 | YesWiki vulnerable to unauthenticated arbitrary page deletion via `{{erasespamedcomments}}` action | 严重 | Packagistyeswiki/yeswiki | 已审查 | 2026-07-10 04:57 | 2026-07-10 04:57 |
| GHSA-89V6-J5X6-CMJ3 CVE-2026-52763 | YesWiki: SQL injection via the `recentchanges` action `period` argument leads to arbitrary DB read | 中危 | Packagistyeswiki/yeswiki | 已审查 | 2026-07-10 04:54 | 2026-07-10 04:54 |