检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-4W5H-HX6R-28Q7 CVE-2026-53531 | ratex-parser has unbounded parser recursion that leads to stack overflow (process abort) | 中危 | crates.ioratex-parser | 已审查 | 2026-07-08 07:39 | 2026-07-08 07:39 |
| GHSA-4HGP-59H5-GVRJ CVE-2026-53530 | ratex-parser panics on `\verb` with a multibyte delimiter (UTF-8 byte-boundary slice) |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 高危 |
crates.ioratex-parser |
| 已审查 |
| 2026-07-08 07:39 |
| 2026-07-08 07:39 |
| GHSA-49F7-WHX5-4256 CVE-2026-58473 | Cognee allows non-superusers to overwrite global LLM configuration | 严重 | PyPIcognee | 已审查 | 2026-07-08 05:31 | 2026-09-04 04:10 |
| GHSA-J8V8-G9CX-5QF4 | @better-auth/scim: Account/provider takeover via missing owner binding on non-org SCIM providers | 高危 | npm@better-auth/scim | 已审查 | 2026-07-08 04:57 | 2026-07-08 04:57 |
| GHSA-2VG6-77G8-24MP | Better Auth: Stale sessions persist after user deletion across admin, anonymous, and SCIM flows | 低危 | npm@better-auth/scim+1 | 已审查 | 2026-07-08 04:56 | 2026-07-08 04:56 |
| GHSA-7W99-5WM4-3G79 CVE-2026-53518 | @better-auth/oauth-provider's OAuth authorization-code grant allows concurrent redemption when two token requests race the find-then-delete primitive | 高危 | npm@better-auth/oauth-provider+1 | 已审查 | 2026-07-08 04:56 | 2026-07-21 03:24 |
| GHSA-5RR4-8452-HF4V CVE-2026-53513 | @better-auth/sso provider registration has server-side request forgery via unvalidated OIDC endpoints | 严重 | npm@better-auth/sso | 已审查 | 2026-07-08 04:56 | 2026-07-21 03:24 |
| GHSA-392P-2Q2V-4372 CVE-2026-53517 | Better Auth: OAuth refresh-token rotation forks the token family on concurrent redemption | 高危 | npm@better-auth/oauth-provider+1 | 已审查 | 2026-07-08 04:55 | 2026-07-21 03:24 |
| GHSA-9H47-PQCX-HJR4 | Better Auth has insecure cryptographic defaults in oidcProvider: alg=none advertised and plain PKCE accepted by default | 高危 | npmbetter-auth | 已审查 | 2026-07-08 04:55 | 2026-07-08 04:55 |
| GHSA-86J7-9J95-VPQJ | Better Auth has stored XSS in the auth-server origin via javascript: redirect_uri in oidc-provider and mcp | 高危 | npmbetter-auth | 已审查 | 2026-07-08 04:55 | 2026-07-08 04:55 |
| GHSA-G38M-R43W-P2Q7 CVE-2026-53516 | Better Auth has an account takeover issue via OAuth auto-link to unverified pre-registered email | 高危 | npmbetter-auth | 已审查 | 2026-07-08 04:55 | 2026-07-21 03:23 |
| GHSA-FMH4-WCC4-5JM3 CVE-2026-53514 | Better Auth vulnerable to unauthorized invitation acceptance via unverified email match in organization plugin | 高危 | npmbetter-auth | 已审查 | 2026-07-08 04:54 | 2026-07-21 03:24 |
| GHSA-P2FR-6HMX-4528 | @better-auth/oauth-provider may provide access tokens for unauthorized audiences via unbound resource indicators | 中危 | npm@better-auth/oauth-provider | 已审查 | 2026-07-08 04:54 | 2026-07-08 04:54 |
| GHSA-PW9M-5JXM-XR6H CVE-2026-53512 | Better Auth: OAuth refresh-token replay via missing client authentication on oidc-provider and mcp plugins | 严重 | npmbetter-auth | 已审查 | 2026-07-08 04:11 | 2026-07-21 03:24 |
| GHSA-7856-G3GV-9WQ8 | netfoil: Attacker controlled data written to logs | 低危 | Gogithub.com/tinfoil-factory/netfoil | 已审查 | 2026-07-08 04:04 | 2026-07-08 04:04 |
| GHSA-3G4Q-2F67-2GVH | netfoil has a resource leak in LRU cache | 低危 | Gogithub.com/tinfoil-factory/netfoil | 已审查 | 2026-07-08 04:04 | 2026-07-08 04:04 |
| GHSA-59QP-CFJ3-RP64 | netfoil has a domain name filter bypass via multiple questions | 中危 | Gogithub.com/tinfoil-factory/netfoil | 已审查 | 2026-07-08 04:03 | 2026-07-08 04:03 |
| GHSA-FQF6-GXHH-2XHW | uutils coreutils: cp/install/mv/ln --suffix alone does not enable backup mode (silent data loss vs GNU) | 高危 | crates.iouucore | 已审查 | 2026-07-08 03:36 | 2026-07-08 03:36 |
| GHSA-G84H-J7JJ-X32P CVE-2026-53509 | @aborruso/ckan-mcp-server: SSRF via base_url allows access to internal networks (Potential fix bypass of CVE-2026-33060) | 中危 | npm@aborruso/ckan-mcp-server | 已审查 | 2026-07-08 03:35 | 2026-07-08 03:35 |
| GHSA-JGX9-JR5X-MVPV CVE-2026-34225 | Open WebUI has Blind Server Side Request Forgery in its Image Edit Functionality | 中危 | PyPIopen-webui | 已审查 | 2026-07-08 00:51 | 2026-07-08 00:51 |
| GHSA-VJM7-M4XH-7WRC CVE-2026-26193 | Open WebUI vulnerable to Stored XSS via iFrame embeds in response messages | 高危 | PyPIopen-webui | 已审查 | 2026-07-08 00:51 | 2026-07-08 00:51 |
| GHSA-XC8P-9RR6-97R2 CVE-2026-26192 | Open WebUI vulnerable to Stored XSS via iFrame in citations model | 高危 | PyPIopen-webui | 已审查 | 2026-07-08 00:51 | 2026-07-08 00:51 |
| GHSA-9F4F-JV96-8766 CVE-2025-46719 | Open WebUI vulnerable to stored XSS via unescaped markdown token in MarkdownTokens.svelte leading to full account takeover and RCE via functions | 高危 | PyPIopen-webui | 已审查 | 2026-07-08 00:50 | 2026-07-08 00:50 |
| GHSA-8GH5-QQH8-HQ3X CVE-2025-46571 | Open WebUI allows limited stored XSS vila uploaded html file | 中危 | PyPIopen-webui | 已审查 | 2026-07-08 00:50 | 2026-07-08 00:50 |
| GHSA-CRHF-3PFG-W68W CVE-2026-53877 | Django: GDALRaster may over-read heap memory when constructed from bytes | 中危 | PyPIdjango | 已审查 | 2026-07-07 23:32 | 2026-08-08 04:01 |