检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-4C7Q-4928-8445 CVE-2026-35338 | chmod: --preserve-root bypassed by any path that resolves to root (e.g. /../) | 高危 | crates.iouu_chmod | 已审查 | 2026-07-07 01:41 | 2026-07-07 01:41 |
| GHSA-H9F9-H6GM-WC85 CVE-2026-55786 | flyto-core has Unauthenticated Command Execution via HTTP MCP `execute_module` |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 高危 |
PyPIflyto-core |
| 已审查 |
| 2026-07-07 01:41 |
| 2026-07-07 01:41 |
| GHSA-794R-5RP2-FPG8 CVE-2026-55787 | flyto-core has SSRF guard bypass via IPv6 transition addresses (IPv4-mapped / 6to4 / NAT64) in validate_url_ssrf | 高危 | PyPIflyto-core | 已审查 | 2026-07-07 01:30 | 2026-07-07 01:30 |
| GHSA-7JVP-HJ45-2F2M | Scriban: Template Writes to Arbitrary CLR Properties via `TypedObjectAccessor` (Mass Assignment + `private` / `init` / `internal` Setter Bypass) | 高危 | NuGetScriban | 已审查 | 2026-07-07 01:30 | 2026-07-07 01:30 |
| GHSA-JHHC-3HCP-QHM5 CVE-2026-49452 | WeasyPrint has CSS Injection via Presentational Hints | 中危 | PyPIweasyprint | 已审查 | 2026-07-07 01:29 | 2026-07-07 01:29 |
| GHSA-3FCV-JVFP-M4Q9 CVE-2026-49445 | Cilium vulnerable to sensitive information disclosure and cluster disruption via local Envoy admin socket access | 严重 | Gogithub.com/cilium/cilium | 已审查 | 2026-07-07 01:03 | 2026-07-07 01:03 |
| GHSA-XJ53-J257-HXVG CVE-2026-49439 | OpenRemote read-only asset users can write predicted datapoints | 中危 | Mavenio.openremote:openremote-manager | 已审查 | 2026-07-07 00:52 | 2026-07-07 00:52 |
| GHSA-565M-G33J-JQ96 CVE-2026-52889 | Formie Hidden field defaults vulnerable to Server-Side Template Injection | 严重 | Packagistverbb/formie | 已审查 | 2026-07-07 00:52 | 2026-07-07 00:52 |
| GHSA-55F6-PF8R-C2F4 CVE-2022-46292 | Open Babel has out-of-bounds write in MOPAC translationVectors[] (UNIT CELL TRANSLATION) | 高危 | PyPIopenbabel | 已审查 | 2026-07-07 00:41 | 2026-07-07 00:41 |
| GHSA-HH8R-75R6-QRG9 CVE-2026-49042 | Apache Camel-Langchain4j-Tools: Tool argument headers are not filtered against declared parameters | 高危 | Mavenorg.apache.camel:camel-langchain4j-agent+2 | 已审查 | 2026-07-06 20:31 | 2026-08-29 04:18 |
| GHSA-5G68-F6XG-VF2R CVE-2026-46588 | Apache Camel-CouchDB: Non-Camel-prefixed Exchange headers bypass HeaderFilterStrategy allowing operation override from untrusted input | 高危 | Mavenorg.apache.camel:camel-couchdb | 已审查 | 2026-07-06 20:31 | 2026-08-29 03:35 |
| GHSA-46JF-C9VX-HH79 CVE-2026-46587 | Apache Camel-Couchbase: Non-Camel-prefixed Exchange headers bypass HeaderFilterStrategy allowing operation override from untrusted input | 高危 | Mavenorg.apache.camel:camel-couchbase | 已审查 | 2026-07-06 20:31 | 2026-08-29 03:34 |
| GHSA-HJG2-F45W-C566 CVE-2026-56139 | Apache Camel-Undertow: The muteException consumer option defaulted to false, so a processing error returned the full Java stack trace in the HTTP response body | 中危 | Mavenorg.apache.camel:camel-undertow | 已审查 | 2026-07-06 17:30 | 2026-08-29 04:08 |
| GHSA-W2V8-8Q6C-3RHR CVE-2026-56140 | Apache Camel-AWS2-SNS: An inbound Camel-namespace filter was added to Sns2HeaderFilterStrategy | 严重 | Mavenorg.apache.camel:camel-aws2-sns | 已审查 | 2026-07-06 17:30 | 2026-08-26 22:34 |
| GHSA-RCVM-6R79-CF4R CVE-2026-55993 | Apache Camel-Atmosphere-Websocket: The inbound consumer maps externally-supplied WebSocket query parameters into the Exchange without a HeaderFilterStrategy | 高危 | Mavenorg.apache.camel:camel-atmosphere-websocket | 已审查 | 2026-07-06 17:30 | 2026-08-29 04:10 |
| GHSA-QVC3-6Q9X-95PJ CVE-2026-53913 | Apache Camel: KeycloakSecurityPolicy has Improper Authentication, Missing Authentication for Critical Function and Failing Open Vulnerabilities | 严重 | Mavenorg.apache.camel:camel-keycloak | 已审查 | 2026-07-06 17:30 | 2026-07-25 00:47 |
| GHSA-PW9Q-PQ7C-RFQW CVE-2026-55994 | Apache Camel-Iggy: The inbound consumer maps externally-supplied Iggy message user-headers into the Exchange without a HeaderFilterStrategy | 高危 | Mavenorg.apache.camel:camel-iggy | 已审查 | 2026-07-06 17:30 | 2026-08-29 04:09 |
| GHSA-MM84-QVJH-HCJ7 CVE-2026-49098 | Apache Camel-Kafka: The kafka.OVERRIDE_TOPIC (and other kafka.*) Exchange header constants used non-Camel-prefixed names that bypass the upstream HTTP header filter | 中危 | Mavenorg.apache.camel:camel-kafka | 已审查 | 2026-07-06 17:30 | 2026-08-29 04:14 |
| GHSA-HCM8-X79P-WX2W CVE-2026-48205 | Apache Camel DNS Has Improper Input Validation, Leading to Server-Side Request Forgery (SSRF) | 严重 | Mavenorg.apache.camel:camel-dns | 已审查 | 2026-07-06 17:30 | 2026-07-25 05:07 |
| GHSA-GCC7-C8MP-34QX CVE-2026-49099 | Apache Camel-Salesforce: Non-Camel-prefixed Exchange header constants bypass the HTTP header filter | 中危 | Mavenorg.apache.camel:camel-salesforce | 已审查 | 2026-07-06 17:30 | 2026-08-29 04:12 |
| GHSA-64GV-6CQ2-45JR CVE-2026-48206 | Apache Camel-JIRA: A set of non-Camel-prefixed Exchange header constants bypass the HTTP header filter | 中危 | Mavenorg.apache.camel:camel-jira | 已审查 | 2026-07-06 17:30 | 2026-08-29 03:33 |
| GHSA-583R-F84W-33G7 CVE-2026-49086 | Apache Camel-Dapr: The Dapr Pub/Sub consumer copied the inbound CloudEvent's pub/sub-name and topic into producer-direction routing headers | 中危 | Mavenorg.apache.camel:camel-dapr | 已审查 | 2026-07-06 17:30 | 2026-08-29 04:15 |
| GHSA-463M-2HR2-Q2J7 CVE-2026-49097 | Apache Camel-IRC: The irc.sendTo (and other irc.*) Exchange header constants used non-Camel-prefixed names that bypass the HTTP header filter | 中危 | Mavenorg.apache.camel:camel-irc | 已审查 | 2026-07-06 17:30 | 2026-08-29 04:13 |
| GHSA-42Q5-XW42-XF9G CVE-2026-49365 | Apache Camel-Netty-HTTP: The muteException consumer option defaulted to false, so a processing error returned the full Java stack trace in the HTTP response body | 中危 | Mavenorg.apache.camel:camel-netty-http | 已审查 | 2026-07-06 17:30 | 2026-08-29 04:12 |
| GHSA-Q86M-QJPM-VQCW CVE-2026-46591 | Apache Camel-Neo4j: JSON property names from the CamelNeo4jMatchProperties header are interpolated into the Cypher WHERE clause without validation, allowing Cypher injection (incomplete remediation of CVE-2025-66169) | 高危 | Mavenorg.apache.camel:camel-neo4j | 已审查 | 2026-07-06 17:30 | 2026-08-29 03:31 |