检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-XQHV-CHQM-FHCC CVE-2026-53649 | Joro: Unauthenticated Cross-Origin Plugin Upload Leads to RCE | 严重 | Gogithub.com/BishopFox/joro | 已审查 | 2026-07-09 04:27 | 2026-07-09 04:27 |
| GHSA-Q95X-7G78-RCCV | OneRingBuf has a Use After Free Vulnerability |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 中危 |
crates.iooneringbuf |
| 已审查 |
| 2026-07-09 04:26 |
| 2026-07-09 04:26 |
| GHSA-9QM4-RH6W-PQ5X CVE-2026-49833 | DSpace: Path Traversal is possible through LDN message generation | 中危 | Mavenorg.dspace:dspace-api | 已审查 | 2026-07-09 04:26 | 2026-07-09 04:26 |
| GHSA-C827-PW3M-67W7 CVE-2026-49830 | DSpace: ORE resource URI does not validate scheme for non-web resources | 中危 | Mavenorg.dspace:dspace-api | 已审查 | 2026-07-09 04:25 | 2026-07-09 04:25 |
| GHSA-V66X-68F2-PXF5 CVE-2026-49831 | DSpace has a possible Path Traversal Vulnerability in its Curation Task Reporter output path | 中危 | Mavenorg.dspace:dspace-api | 已审查 | 2026-07-09 04:25 | 2026-07-09 04:25 |
| GHSA-9X82-RM84-C6X7 CVE-2026-49832 | DSpace has possible Remote Code Execution (RCE) through Velocity Templates used by LDN | 高危 | Mavenorg.dspace:dspace-api | 已审查 | 2026-07-09 04:25 | 2026-07-09 04:25 |
| GHSA-MXWC-WH95-PW4G | Trapster Community: Unauthenticated malformed DNS compression pointers crash per-packet honeypot handler | 中危 | PyPItrapster | 已审查 | 2026-07-09 04:24 | 2026-07-09 04:24 |
| GHSA-VMWX-M75V-QVCH CVE-2026-53634 | Sharp Missing Authorization Check in Quick Creation Command Endpoints | 中危 | Packagistcode16/sharp | 已审查 | 2026-07-09 04:24 | 2026-07-09 04:24 |
| GHSA-V5PX-423J-PF7P CVE-2026-52831 | Nuclio: Unsanitized cron trigger event headers/body injected into CronJob shell command leads to persistent RCE | 严重 | Gogithub.com/nuclio/nuclio | 已审查 | 2026-07-09 04:24 | 2026-07-09 04:24 |
| GHSA-35RM-7J9C-2F7M CVE-2026-53600 | async-tar PAX extension-header desync enables tar entry/content smuggling | 中危 | crates.ioasync-tar | 已审查 | 2026-07-09 04:24 | 2026-07-09 04:24 |
| GHSA-659F-RGP5-W4WF CVE-2026-50197 | Skipper: opaAuthorizeRequestWithBody filter bypasses OPA policy on Transfer-Encoding — chunked / HTTP/2 requests | 高危 | Gogithub.com/zalando/skipper | 已审查 | 2026-07-09 04:23 | 2026-07-09 04:23 |
| GHSA-4JHM-JV67-739F CVE-2026-49825 | `lxml_html_clean.Cleaner` does not strip `javascript:` URLs from namespaced URL attributes | 高危 | PyPIlxml_html_clean | 已审查 | 2026-07-09 04:23 | 2026-07-09 04:23 |
| GHSA-2QP2-6FRJ-P9PQ | Duplicate Advisory: MySQL v1 Node executeQuery Operation Allows SQL Injection via Unparameterized Expression Interpolation 已撤回 | 中危 | npmn8n | 已审查 | 2026-07-08 23:32 | 2026-07-23 06:21 |
| GHSA-GQCV-RFJ6-R29G | Duplicate Advisory: Improper Authorization Allows Authenticated Users to Assign Workflows to Folders in Other Projects 已撤回 | 中危 | npmn8n | 已审查 | 2026-07-08 23:32 | 2026-07-23 06:24 |
| GHSA-VMFC-9982-2M45 CVE-2026-50127 | Weblate SSRF: outbound URL guard misses some private ranges | 中危 | PyPIweblate | 已审查 | 2026-07-08 07:46 | 2026-07-08 07:46 |
| GHSA-2JCC-MXV7-P3F9 CVE-2026-53508 | oasdiff does not enforce --allow-external-refs=false on the git-revision load path (SSRF / local file read) | 中危 | Gogithub.com/oasdiff/oasdiff | 已审查 | 2026-07-08 07:45 | 2026-07-08 07:45 |
| GHSA-6W3M-4HHP-775Q CVE-2026-53572 | KEDA has PostgreSQL connection string parameter injection via incomplete whitespace escaping | 中危 | Gogithub.com/kedacore/keda/v2 | 已审查 | 2026-07-08 07:44 | 2026-07-08 07:44 |
| GHSA-F66Q-9RF6-8795 | Flask-Security-Too: WebAuthn reauthentication freshness bypass via cross-user assertion | 中危 | PyPIFlask-Security-Too | 已审查 | 2026-07-08 07:43 | 2026-07-08 07:43 |
| GHSA-4G5X-HCWM-82JW CVE-2026-53553 | Goploy: Arbitrary File Read via Path Traversal in /deploy/fileDiff allows Remote Server Compromise | 高危 | Gogithub.com/zhenorzz/goploy | 已审查 | 2026-07-08 07:42 | 2026-07-08 07:42 |
| GHSA-26RH-24RG-J3VV CVE-2026-53552 | Goploy: Cross-namespace IDOR and RCE via body-supplied row id in project and project_file handlers | 严重 | Gogithub.com/zhenorzz/goploy | 已审查 | 2026-07-08 07:42 | 2026-07-08 07:42 |
| GHSA-Q855-8RH5-JFGQ | ha-mcp: Add-on settings and policy routes are reachable without authentication at the bare root path | 中危 | PyPIha-mcp | 已审查 | 2026-07-08 07:41 | 2026-07-08 07:41 |
| GHSA-CWV4-H3J5-W3CF | rama has Stored XSS in ServeDir HTML directory listing via unescaped file names and URI path | 低危 | crates.iorama | 已审查 | 2026-07-08 07:41 | 2026-07-08 07:41 |
| GHSA-V3Q9-HJ7J-63HQ CVE-2026-53533 | aiosmtplib vulnerable to SMTP command injection via CR/LF in sender/recipient address | 中危 | PyPIaiosmtplib | 已审查 | 2026-07-08 07:40 | 2026-07-08 07:40 |
| GHSA-GVHC-WV3V-7PF8 CVE-2026-53487 | Kite has an authenticated cluster RBAC bypass in /api/v1/overview | 中危 | Gogithub.com/zxh326/kite | 已审查 | 2026-07-08 07:40 | 2026-07-08 07:40 |
| GHSA-GQ4G-FPC9-VJFQ | Webauthn: SimpleFakeCredentialGenerator with an empty secret produces predictable fake credentials, weakening username enumeration protection | 低危 | Packagistweb-auth/webauthn-lib | 已审查 | 2026-07-08 07:39 | 2026-07-08 07:40 |