检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-QM72-8PRH-G92X CVE-2026-25782 | Gitea tracked-time deletion is not scoped to the requested issue | 中危 | Gocode.gitea.io/gitea | 已审查 | 2026-07-04 05:31 | 2026-09-02 01:22 |
| GHSA-M5CH-PPFX-XV3V CVE-2026-26247 | Gitea OAuth2 PKCE S256 verifier bypass |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 严重 |
Gocode.gitea.io/gitea |
| 已审查 |
| 2026-07-04 05:31 |
| 2026-09-02 01:23 |
| GHSA-H9C5-X7G8-4Q7F CVE-2026-26307 | Gitea git grep searches allow server resource exhaustion | 高危 | Gocode.gitea.io/gitea | 已审查 | 2026-07-04 05:31 | 2026-09-02 01:21 |
| GHSA-H697-89CP-24Q8 CVE-2026-25718 | Gitea template repository generation follows unsafe filesystem paths | 严重 | Gocode.gitea.io/gitea | 已审查 | 2026-07-04 05:31 | 2026-09-02 01:19 |
| GHSA-FHQ3-P242-2QPF CVE-2026-20909 | Gitea exposes tracked time entries without repository authorization | 中危 | Gocode.gitea.io/gitea | 已审查 | 2026-07-04 05:31 | 2026-09-02 01:17 |
| GHSA-922F-HFWP-P56F CVE-2026-22547 | Gitea repository creation accepts insufficiently validated fields | 严重 | Gocode.gitea.io/gitea | 已审查 | 2026-07-04 05:31 | 2026-09-02 01:19 |
| GHSA-5V69-G2M3-3HQ3 CVE-2026-26232 | Gitea OAuth2 authorization codes can be reused after expiry | 严重 | Gocode.gitea.io/gitea | 已审查 | 2026-07-04 05:31 | 2026-09-02 01:23 |
| GHSA-4C8F-3M6H-M56R CVE-2026-27657 | Gitea primary email ownership bypass allows cross-user email changes | 高危 | Gocode.gitea.io/gitea | 已审查 | 2026-07-04 05:31 | 2026-09-02 01:21 |
| GHSA-47RQ-XP99-92MX CVE-2026-24690 | Gitea pull request branch permission checks allow unauthorized updates and rebases | 高危 | Gocode.gitea.io/gitea | 已审查 | 2026-07-04 05:31 | 2026-09-02 01:20 |
| GHSA-37W2-86G3-H4QH CVE-2026-25712 | Gitea organization permission APIs expose hidden membership and private organization data | 高危 | Gocode.gitea.io/gitea | 已审查 | 2026-07-04 05:31 | 2026-09-02 01:22 |
| GHSA-5GWJ-M78Q-7PQ3 CVE-2026-12481 | Keras: Lambda deserialization can bypass safe mode and execute code | 高危 | PyPIkeras | 已审查 | 2026-07-04 05:31 | 2026-08-08 04:30 |
| GHSA-RH62-J648-G5QC CVE-2026-49360 | Recce server has unauthenticated SQL execution that allows local file read/write through DuckDB | 高危 | PyPIrecce | 已审查 | 2026-07-03 05:14 | 2026-07-03 05:14 |
| GHSA-6G2F-W7G3-77VF CVE-2026-49353 | 9router has an Incomplete Fix: Local-Only Access Gate Bypass in 9router via Host Header SpoofING | 高危 | npm9router | 已审查 | 2026-07-03 05:13 | 2026-07-03 05:13 |
| GHSA-Q675-QJ96-32M9 CVE-2026-46599 | golang.org/x/image/tiff has excessive resource consumption in PackBits decompression | 高危 | Gogolang.org/x/image | 已审查 | 2026-07-03 05:01 | 2026-07-03 05:01 |
| GHSA-JPHH-M39H-6GWX CVE-2026-49352 | 9router's Hardcoded Default fallback JWT Secret Allows Authentication Bypass | 严重 | npm9router | 已审查 | 2026-07-03 04:56 | 2026-07-03 04:56 |
| GHSA-V8RP-6XCV-FWGH CVE-2026-49292 | Kiwi TCMS's /init-db/ page renders and responds to requests after first use | 低危 | PyPIkiwitcms | 已审查 | 2026-07-03 04:55 | 2026-07-03 04:55 |
| GHSA-5G75-477J-2C2F CVE-2026-54617 | LaunchServer FileServerHandler has an unauthenticated path traversal issue | 严重 | Mavenpro.gravit.launcher:launchserver-api | 已审查 | 2026-07-03 04:49 | 2026-07-03 04:49 |
| GHSA-Q8R6-XJ3F-WRRM CVE-2026-49284 | SimpleSAMLphp SP accepts a response from an unexpected IdP when unsigned `Response/InResponseTo` is combined with a signed assertion lacking `SubjectConfirmationData/InResponseTo` | 高危 | Packagistsimplesamlphp/simplesamlphp | 已审查 | 2026-07-03 04:47 | 2026-07-03 04:47 |
| GHSA-MM6C-5J6X-HQ8M CVE-2026-52792 | Algernon vulnerable to server-side script source disclosure on Windows via NTFS filename | 高危 | Gogithub.com/xyproto/algernon | 已审查 | 2026-07-03 04:46 | 2026-07-03 04:46 |
| GHSA-5PMV-RX8R-WMV5 CVE-2026-52834 | jxl-grid on 32-bit platforms has an out-of-bounds writes due to integer overflow | 高危 | crates.iojxl-grid | 已审查 | 2026-07-03 04:45 | 2026-07-03 04:45 |
| GHSA-66M8-C62J-H6V5 | jxl-oxide: `FrameBuffer::new` creates out-of-bounds slices on overflow | 中危 | crates.iojxl-oxide | 已审查 | 2026-07-03 04:45 | 2026-07-03 04:45 |
| GHSA-2V8P-FQPX-2Q3W | jxl-oxide: integer subtraction overflow panic in cluster_from_table via crafted JXL input (DoS) | 中危 | crates.iojxl-modular | 已审查 | 2026-07-03 04:44 | 2026-07-03 04:44 |
| GHSA-J5MC-P8QG-39J7 | Kimai Favorite Timesheet Add and Remove Endpoints Allows Cross-User Bookmark Manipulation | 低危 | Packagistkimai/kimai | 已审查 | 2026-07-03 04:44 | 2026-07-03 04:44 |
| GHSA-794G-X443-36F7 CVE-2026-2092 | Keycloak: Unauthorized access via improper validation of encrypted SAML assertions | 高危 | Mavenorg.keycloak:keycloak-services | 已审查 | 2026-07-03 04:42 | 2026-07-03 04:42 |
| GHSA-RXW2-PC8J-VXWM CVE-2026-52830 | fast-mcp-telegram: Bearer token path traversal bypasses reserved Telegram session protection | 严重 | PyPIfast-mcp-telegram | 已审查 | 2026-07-03 04:38 | 2026-08-14 00:57 |