检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-MRRP-9GJM-749V CVE-2026-46592 | Apache Camel-CXF: The SOAP operation-selection headers used non-Camel-prefixed names (operationName, operationNamespace) that bypass the HTTP header filter, allowing an HTTP client to redirect the invoked SOAP operation | 高危 | Mavenorg.apache.camel:camel-cxf-rest+1 | 已审查 | 2026-07-06 17:30 | 2026-08-29 03:32 |
| GHSA-HGG5-GP4C-GPCG |
当前筛选结果 35,190 条 · 时间按北京时间显示
Apache Camel-Vertx-Websocket: The inbound consumer maps externally-supplied WebSocket query and path parameters into the Exchange without a HeaderFilterStrategy |
| 高危 |
Mavenorg.apache.camel:camel-vertx-websocket |
| 已审查 |
| 2026-07-06 17:30 |
| 2026-08-29 05:53 |
| GHSA-F7G3-2CG6-F5HJ CVE-2026-48204 | Apache Camel: camel-mongodb-gridfs producer allows GridFS operation override and NoSQL operator injection via unfiltered gridfs.* HTTP headers | 严重 | Mavenorg.apache.camel:camel-mongodb-gridfs | 已审查 | 2026-07-06 17:30 | 2026-07-25 05:08 |
| GHSA-CMC3-HR79-8MMV CVE-2026-46456 | Apache Camel-AWS2-SQS: Inbound message attributes are mapped into the Exchange without an inbound HeaderFilterStrategy, allowing a message sender to inject Camel control headers | 严重 | Mavenorg.apache.camel:camel-aws2-sqs | 已审查 | 2026-07-06 17:30 | 2026-08-29 03:25 |
| GHSA-857V-XVH8-7HJC CVE-2026-46590 | Apache Camel-PQC: The HashiCorp Vault and AWS Secrets Manager key-lifecycle managers deserialize persisted key metadata with java.io.ObjectInputStream and no ObjectInputFilter (incomplete remediation of CVE-2026-40048) | 高危 | Mavenorg.apache.camel:camel-pqc | 已审查 | 2026-07-06 17:30 | 2026-08-29 03:30 |
| GHSA-566H-V38H-3XP3 CVE-2026-46585 | Apache Camel-Lucene: The query control headers used non-Camel-prefixed names (QUERY, RETURN_LUCENE_DOCS) that bypass the HTTP header filter, allowing an HTTP client to inject the full-text search query | 高危 | Mavenorg.apache.camel:camel-lucene | 已审查 | 2026-07-06 17:30 | 2026-08-29 03:29 |
| GHSA-4H4F-V54Q-7PQ8 CVE-2026-48203 | Apache Camel-Solr: The SolrParam. and SolrField. Exchange header prefixes used non-Camel-prefixed names that bypass the HTTP header filter, allowing an HTTP client to inject Solr query parameters (server-side request forgery) and document fields | 严重 | Mavenorg.apache.camel:camel-solr | 已审查 | 2026-07-06 17:30 | 2026-08-29 05:52 |
| GHSA-29VJ-9MGP-MWP2 CVE-2026-46584 | Apache Camel-Mail: The mail producer applied attacker-supplied mail.smtp.* / mail.smtps.* message headers as JavaMail session properties | 低危 | Mavenorg.apache.camel:camel-mail | 已审查 | 2026-07-06 17:30 | 2026-08-29 03:28 |
| GHSA-XWW8-MXQW-M84W CVE-2026-43865 | Apache Camel-Hazelcast: Unsafe Java deserialization in default-configured managed Hazelcast instances enables remote code execution | 高危 | Mavenorg.apache.camel:camel-hazelcast | 已审查 | 2026-07-06 17:30 | 2026-08-27 01:54 |
| GHSA-RPV3-6645-2VQC CVE-2026-40047 | Apache Camel-Docling: Insufficient validation of custom CLI arguments enables argument injection and path traversal in DoclingProducer | 严重 | Mavenorg.apache.camel:camel-docling | 已审查 | 2026-07-06 17:30 | 2026-08-26 22:32 |
| GHSA-RP9M-HFV5-PFVR CVE-2026-46453 | Apache Camel-Elasticsearch-Rest-Client: Exchange header constants without the Camel prefix bypass inbound HTTP header filtering, allowing untrusted clients to override the Elasticsearch query and operation | 中危 | Mavenorg.apache.camel:camel-elasticsearch-rest-client | 已审查 | 2026-07-06 17:30 | 2026-08-27 02:01 |
| GHSA-R9CC-J7WR-P329 CVE-2026-46454 | Apache Camel-Cometd: Inbound Bayeux message headers are mapped into the Exchange without a HeaderFilterStrategy, allowing unauthenticated clients to inject Camel control headers | 严重 | Mavenorg.apache.camel:camel-cometd | 已审查 | 2026-07-06 17:30 | 2026-08-27 02:03 |
| GHSA-MQWC-6QWC-V9GQ CVE-2026-46455 | Apache Camel-Keycloak: The access-token validity window is not verified because the IS_ACTIVE check is missing from the TokenVerifier, allowing expired tokens to be accepted | 严重 | Mavenorg.apache.camel:camel-keycloak | 已审查 | 2026-07-06 17:30 | 2026-08-29 03:24 |
| GHSA-F755-XP6R-8Q84 CVE-2026-43866 | Apache Camel JMS deserialization filter bypass | 高危 | Mavenorg.apache.camel:camel-activemq+5 | 已审查 | 2026-07-06 17:30 | 2026-08-27 01:59 |
| GHSA-8H6P-JVHF-9HCR CVE-2026-42527 | Apache Camel: Permissive default ObjectInputFilter pattern admits java.net.** and enables DNS-based information disclosure | 高危 | Mavenorg.apache.camel:camel-amqp+11 | 已审查 | 2026-07-06 17:30 | 2026-08-26 23:12 |
| GHSA-7V55-Q9X3-83CJ CVE-2026-46457 | Apache Camel-NATS: Inbound NATS message headers are mapped into the Exchange without a configured HeaderFilterStrategy, allowing a client that can publish to the subject to inject Camel control headers | 高危 | Mavenorg.apache.camel:camel-nats | 已审查 | 2026-07-06 17:30 | 2026-08-29 03:26 |
| GHSA-7CMX-QJH8-7V3V CVE-2026-43867 | Apache Camel-PQC: The AWS Secrets Manager key-lifecycle manager deserializes persisted key metadata with java.io.ObjectInputStream and no ObjectInputFilter | 严重 | Mavenorg.apache.camel:camel-pqc | 已审查 | 2026-07-06 17:30 | 2026-08-27 01:52 |
| GHSA-6QW3-4796-5984 CVE-2026-40859 | Apache Camel-Vertx-Http and Camel-Netty-Http: Unsafe Java deserialization of HTTP response bodies via a raw ObjectInputStream when transferException is enabled | 高危 | Mavenorg.apache.camel:camel-netty-http+1 | 已审查 | 2026-07-06 17:30 | 2026-08-26 23:17 |
| GHSA-RQJW-R5G4-X8QM | Duplicate Advisory: Craft CMS: Missing authorization check allows non-admin control panel users to reorder Global Sets 已撤回 | 中危 | Packagistcraftcms/cms | 已审查 | 2026-07-06 14:31 | 2026-08-07 04:55 |
| GHSA-RMJ4-M9CP-MP9V | Duplicate Advisory: Craft CMS: Missing authorization check allows non-admin control panel users access to user registration metrics 已撤回 | 中危 | Packagistcraftcms/cms | 已审查 | 2026-07-06 14:31 | 2026-09-01 03:42 |
| GHSA-VHQ7-FWWH-7HJF CVE-2026-27780 | Gitea pre-receive hook scanner errors allow branch-protection bypass | 严重 | Gocode.gitea.io/gitea | 已审查 | 2026-07-04 05:31 | 2026-09-02 02:55 |
| GHSA-V8F2-2GHQ-9WHV CVE-2026-27779 | Gitea forwarded-proto validation allows canonical URL spoofing | 高危 | Gocode.gitea.io/gitea | 已审查 | 2026-07-04 05:31 | 2026-09-02 01:23 |
| GHSA-7JVX-G65V-R899 CVE-2026-28705 | Gitea release asset dumps permit path traversal through crafted names | 中危 | Gocode.gitea.io/gitea | 已审查 | 2026-07-04 05:31 | 2026-09-02 01:23 |
| GHSA-X92V-F5GC-R34V CVE-2026-27660 | Gitea draft releases and attachments are exposed without write permission | 高危 | Gocode.gitea.io/gitea | 已审查 | 2026-07-04 05:31 | 2026-09-02 02:55 |
| GHSA-RC56-RJ3F-XGGF CVE-2026-26292 | Gitea LFS mirror operations bypass migration HTTP transport protections | 严重 | Gocode.gitea.io/gitea | 已审查 | 2026-07-04 05:31 | 2026-09-02 01:21 |