检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-WW9Q-8R59-XV46 CVE-2026-54496 | Zebra: Missing copy constraint in halo2_gadgets variable-base scalar multiplication allows under-constrained base, breaking Orchard Action circuit soundness | 严重 | crates.iohalo2_gadgets+3 | 已审查 | 2026-07-07 05:23 | 2026-07-07 05:23 |
| GHSA-2PQ5-3Q89-J7CC |
当前筛选结果 35,190 条 · 时间按北京时间显示
Langroid: Neo4jChatAgent executes LLM-generated Cypher without validation (prompt-to-Cypher injection; config-conditional RCE), mirroring the SQLChatAgent bug fixed in CVE-2026-25879 |
| 严重 |
PyPIlangroid |
| 已审查 |
| 2026-07-07 05:22 |
| 2026-07-07 05:22 |
| GHSA-VJC7-JRH9-9J86 | 9router has unauthenticated CRUD on /api/providers and Full API Key Leak via /api/usage/stats | 严重 | npm9router | 已审查 | 2026-07-07 05:22 | 2026-07-07 05:22 |
| GHSA-5WG6-JMQ2-53PW CVE-2026-55438 | Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing | 中危 | Gogithub.com/coder/coder/v2 | 已审查 | 2026-07-07 05:14 | 2026-07-07 05:14 |
| GHSA-798H-HPPH-M24J CVE-2026-55426 | Linuxfabrik Monitoring Plugins have local privilege escalation using embedded command | 高危 | PyPIlinuxfabrik-lib | 已审查 | 2026-07-07 05:13 | 2026-07-07 05:13 |
| GHSA-7QW2-F75V-62F7 CVE-2026-55437 | Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component | 中危 | Gogithub.com/coder/coder/v2 | 已审查 | 2026-07-07 05:12 | 2026-07-07 05:12 |
| GHSA-84RM-42XW-MX52 CVE-2026-55436 | Coder's AI Bridge Proxy skips TLS certificate verification in default configuration | 高危 | Gogithub.com/coder/coder/v2 | 已审查 | 2026-07-07 05:12 | 2026-07-07 05:12 |
| GHSA-WQXV-W64V-5WH6 CVE-2026-55435 | Suspended Coder users retain access to AI Bridge LLM proxy endpoints | 中危 | Gogithub.com/coder/coder/v2 | 已审查 | 2026-07-07 05:11 | 2026-07-08 06:17 |
| GHSA-F5VP-W269-392G CVE-2026-55434 | Coder vulnerable to denial of service via unbounded request body in AI Bridge provider endpoints | 中危 | Gogithub.com/coder/coder/v2 | 已审查 | 2026-07-07 05:10 | 2026-07-08 06:17 |
| GHSA-JQJ2-X4C5-JFXM CVE-2026-55433 | Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers | 中危 | Gogithub.com/coder/coder/v2 | 已审查 | 2026-07-07 05:09 | 2026-07-07 05:09 |
| GHSA-X9QQ-2QH5-8RXF CVE-2026-55432 | Coder's sub-agent app registration bypasses template port-sharing policy enforcement | 中危 | Gogithub.com/coder/coder/v2 | 已审查 | 2026-07-07 05:08 | 2026-07-07 05:08 |
| GHSA-V54H-CP2W-9X4G CVE-2026-55431 | Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps | 高危 | Gogithub.com/coder/coder/v2 | 已审查 | 2026-07-07 05:07 | 2026-07-07 05:07 |
| GHSA-2MG2-P7R7-G27F CVE-2026-55078 | Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service | 中危 | Gogithub.com/coder/coder/v2 | 已审查 | 2026-07-07 05:06 | 2026-07-07 05:06 |
| GHSA-5G4W-3VW9-478W CVE-2026-55430 | Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access | 中危 | Gogithub.com/coder/coder/v2 | 已审查 | 2026-07-07 05:05 | 2026-07-07 05:05 |
| GHSA-WRQ8-FCV5-8HVP CVE-2026-55428 | Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator | 高危 | Gogithub.com/coder/coder/v2 | 已审查 | 2026-07-07 04:58 | 2026-07-07 04:58 |
| GHSA-9RJW-3GWP-F59V CVE-2026-55429 | Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID | 高危 | Gogithub.com/coder/coder/v2 | 已审查 | 2026-07-07 04:55 | 2026-07-07 04:55 |
| GHSA-F962-QM93-MJ4C CVE-2026-55079 | Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service | 中危 | Gogithub.com/coder/coder/v2 | 已审查 | 2026-07-07 04:54 | 2026-07-07 04:54 |
| GHSA-MCQQ-FQGF-RXWM CVE-2026-55427 | Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` | 高危 | Gogithub.com/coder/coder/v2 | 已审查 | 2026-07-07 04:53 | 2026-07-07 04:53 |
| GHSA-29XF-69GQ-M9JX CVE-2026-55077 | Coder: User-admin role can reset owner account password | 高危 | Gogithub.com/coder/coder/v2 | 已审查 | 2026-07-07 04:53 | 2026-07-07 04:53 |
| GHSA-9R87-MVCW-X35F CVE-2026-55075 | Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass | 高危 | Gogithub.com/coder/coder/v2 | 已审查 | 2026-07-07 04:52 | 2026-07-07 04:52 |
| GHSA-75VM-6W67-GWVP CVE-2026-55076 | Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking | 高危 | Gogithub.com/coder/coder/v2 | 已审查 | 2026-07-07 04:50 | 2026-07-07 04:50 |
| GHSA-7V6W-C3F4-9WPQ CVE-2026-54640 | OpenRemote has an incomplete fix for CVE-2026-40882: XXE in KNXProtocol.startAssetImport() allows arbitrary file read via unprotected XMLInputFactory | 高危 | Mavenio.openremote:openremote-agent | 已审查 | 2026-07-07 04:49 | 2026-07-07 04:49 |
| GHSA-XQR9-4WVV-GVCH CVE-2026-54641 | OpenRemote has Cross-Realm User Information Disclosure in UserResourceImpl | 高危 | Mavenio.openremote:openremote-manager | 已审查 | 2026-07-07 04:47 | 2026-07-07 04:47 |
| GHSA-Q6H5-Q3Q6-F87X CVE-2026-53935 | CiliumLocalRedirectPolicy addressMatcher allows cross-namespace service traffic hijacking and can break service translation | 中危 | Gogithub.com/cilium/cilium | 已审查 | 2026-07-07 04:45 | 2026-07-07 04:45 |
| GHSA-GV83-GQW6-9J2C CVE-2026-53624 | GoFiber never set HSTS header in helmet middleware due to incorrect protocol check | 中危 | Gogithub.com/gofiber/fiber | 已审查 | 2026-07-07 04:43 | 2026-07-07 04:43 |