检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-4J9M-H44M-2HV8 CVE-2026-50268 | Steeltoe: OAEP setting silently selects PKCS#1 v1.5 padding | 低危 | NuGetSteeltoe.Configuration.Encryption | 已审查 | 2026-07-03 04:32 | 2026-07-03 04:32 |
| GHSA-RXRH-4J9H-XGG9 CVE-2026-50267 | Steeltoe: TLS private keys written to /tmp with default permissions, never deleted |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 中危 |
NuGetSteeltoe.Configuration.Abstractions |
| 已审查 |
| 2026-07-03 04:32 |
| 2026-07-03 04:32 |
| GHSA-7FQC-P256-7PWJ CVE-2026-50202 | Steeltoe's static JWKS cache shared across schemes and never invalidated | 中危 | NuGetSteeltoe.Security.Authentication.CloudFoundryBase+2 | 已审查 | 2026-07-03 04:31 | 2026-07-03 04:31 |
| GHSA-227R-JM2G-7CP4 CVE-2026-50201 | Steeltoe's sensitive actuators (heapdump/env) only require Restricted permission | 中危 | NuGetSteeltoe.Management.Endpoint+1 | 已审查 | 2026-07-03 04:31 | 2026-07-03 04:31 |
| GHSA-Q62H-354G-5R85 CVE-2026-50200 | Steeltoe's env sanitizer misses connection strings — leaks embedded DB passwords | 高危 | NuGetSteeltoe.Management.Endpoint+1 | 已审查 | 2026-07-03 04:31 | 2026-07-03 04:31 |
| GHSA-J8PH-6FXJ-G533 CVE-2026-50196 | Steeltoe.Discovery.Eureka: Unrecognized DataCenterInfo.Name poisons entire registry fetch | 高危 | NuGetSteeltoe.Discovery.Eureka | 已审查 | 2026-07-03 04:30 | 2026-07-03 04:30 |
| GHSA-58F6-6RJ2-3V8R CVE-2026-50194 | Steeltoe vulnerable to management-port isolation bypass via spoofed Host header | 高危 | NuGetSteeltoe.Management.Endpoint+1 | 已审查 | 2026-07-03 04:29 | 2026-07-03 04:29 |
| GHSA-5CJR-MXJ5-WMRX CVE-2026-49289 | SimpleSAMLphp has Possible DoS via XPath Transform | 高危 | Packagistsimplesamlphp/saml2+1 | 已审查 | 2026-07-03 04:27 | 2026-08-05 20:44 |
| GHSA-63WG-WJJJ-7CP8 CVE-2026-52829 | Zebra Address Book Aborted by IPv4-Mapped Mempool Misbehavior Update | 高危 | crates.iozebra-network+1 | 已审查 | 2026-07-03 04:26 | 2026-07-03 04:26 |
| GHSA-6929-8P9F-26JX CVE-2026-49283 | SimpleSAMLphp HTTP-Artifact TLS validator confusion allows cross-IdP authentication bypass | 高危 | Packagistsimplesamlphp/saml2+1 | 已审查 | 2026-07-03 04:25 | 2026-08-05 05:23 |
| GHSA-8W6W-23MQ-H8RG CVE-2026-52817 | Linuxfabrik Monitoring Plugins: Sudoers may be able to obtain privilege escalation via /usr/bin/apt-get arguments | 高危 | PyPIlinuxfabrik-lib | 已审查 | 2026-07-03 04:23 | 2026-07-03 04:23 |
| GHSA-X4HG-HFWF-P9MW | @asymmetric-effort/nogginlessdom vulnerable to ReDoS via user-controlled regex in HTMLInputElement pattern validation | 中危 | npm@asymmetric-effort/nogginlessdom | 已审查 | 2026-07-03 04:20 | 2026-07-03 04:20 |
| GHSA-322X-V876-G883 | @asymmetric-effort/nogginlessdom's Path Traversal in matchFileSnapshot allows arbitrary file write | 高危 | npm@asymmetric-effort/nogginlessdom | 已审查 | 2026-07-03 04:19 | 2026-07-03 04:19 |
| GHSA-G6G7-PVMX-M74P CVE-2026-59800 | 9router: Missing Authorization and OS Command Injection | 严重 | npm9router | 已审查 | 2026-07-03 04:17 | 2026-07-08 02:35 |
| GHSA-GJ2H-2FPW-FHV9 | @nuxt/ui: UAuthForm / UForm SSR markup omits `method`, leaking credentials via GET if submitted before hydration | 中危 | npm@nuxt/ui | 已审查 | 2026-07-03 04:16 | 2026-08-05 05:55 |
| GHSA-86VW-MFPG-WWV9 CVE-2026-52746 | jsonata: Malicious inputs to "$toMillis" function can cause resource exhaustion | 高危 | npmjsonata | 已审查 | 2026-07-03 04:13 | 2026-08-04 04:49 |
| GHSA-65JJ-FMW8-468Q CVE-2026-52734 | zebrad has unbounded memory leak in mempool download pipeline via timeout path cancel_handles retention | 中危 | crates.iozebrad | 已审查 | 2026-07-03 04:12 | 2026-07-03 04:12 |
| GHSA-2GF8-Q9RR-JQ3H CVE-2026-52733 | zebrad has persistent on-disk corruption of Sapling/Orchard subtree roots after chain fork via pop_tip | 中危 | crates.iozebra-state+1 | 已审查 | 2026-07-03 04:11 | 2026-07-03 04:11 |
| GHSA-3W32-23WJ-RXG3 CVE-2026-50282 | Craft CMS Vulnerable to Unauthorized Deletion of Destination Folders During Forced Moves | 高危 | Packagistcraftcms/cms | 已审查 | 2026-07-03 04:03 | 2026-07-03 04:03 |
| GHSA-X5M4-G2CQ-52PQ CVE-2026-50281 | Craft CMS's mass assignment via id in newAttributes during bulk duplicate overwrites existing elements | 高危 | Packagistcraftcms/cms | 已审查 | 2026-07-03 04:03 | 2026-07-03 04:03 |
| GHSA-5HVG-W58J-545M CVE-2026-9811 | Mautic has Stored Cross-Site Scripting (XSS) in Project Option Selector | 中危 | Packagistmautic/core | 已审查 | 2026-07-03 03:49 | 2026-07-03 03:49 |
| GHSA-7H65-WHP7-RGQF CVE-2026-9809 | Mautic has Stored Cross-Site Scripting (XSS) in Projects Component | 高危 | Packagistmautic/core | 已审查 | 2026-07-03 03:49 | 2026-07-03 03:49 |
| GHSA-2JRW-C95W-H43G CVE-2026-9808 | Mautic has an Authorization Bypass in API v2 Endpoints | 高危 | Packagistmautic/core | 已审查 | 2026-07-03 03:49 | 2026-07-03 03:49 |
| GHSA-6R9H-4H75-7Q4X CVE-2026-9559 | Mautic vulnerable to Path Traversal via Campaign Import | 严重 | Packagistmautic/core | 已审查 | 2026-07-03 03:48 | 2026-07-03 03:48 |
| GHSA-9FX4-7CMJ-47VG CVE-2026-9558 | Mautic has Server-Side Template Injection (SSTI) in Theme Templates | 严重 | Packagistmautic/core | 已审查 | 2026-07-03 03:48 | 2026-07-03 03:48 |