检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-JMV8-8J9J-RCPC CVE-2026-9557 | Mautic Focus component Vulnerable to SSRF | 中危 | Packagistmautic/core | 已审查 | 2026-07-03 03:47 | 2026-07-03 03:48 |
| GHSA-HHM7-QRV5-H4R6 CVE-2026-52739 | Zebra: Repeated Non-Finalized Shielded Transaction Aborts Zebra Before Duplicate-Nullifier Rejection |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 中危 |
crates.iozebra-state+1 |
| 已审查 |
| 2026-07-03 03:46 |
| 2026-07-03 03:46 |
| GHSA-W834-CF6P-9M9W CVE-2026-52738 | Zebra: Finalized address balance credit-first overflow on consensus-valid blocks | 中危 | crates.iozebra-state+1 | 已审查 | 2026-07-03 03:44 | 2026-07-03 03:44 |
| GHSA-GVJC-3W7C-92JX CVE-2026-52737 | Zebra has sync restart poisoning from single unauthenticated peer via above-lookahead block | 中危 | crates.iozebra-consensus+1 | 已审查 | 2026-07-03 03:44 | 2026-07-03 03:44 |
| GHSA-GF9R-M956-97QX CVE-2026-52735 | zebrad has consensus divergence via P2SH sigop undercount in pure-Rust disabled-opcode parser | 严重 | crates.iozebra-script+1 | 已审查 | 2026-07-03 03:43 | 2026-07-03 03:43 |
| GHSA-4M69-67M6-PRQP CVE-2026-52736 | Zebra has block suppression via NU5 same-header body poisoning of sent-hash cache | 高危 | crates.iozebra-state+1 | 已审查 | 2026-07-03 03:43 | 2026-07-03 03:43 |
| GHSA-H72H-PPCX-998P | Zebra has pre-handshake buffer capacity reservation based on attacker-claimed body length | 低危 | crates.iozebra-network+1 | 已审查 | 2026-07-03 03:42 | 2026-07-03 03:42 |
| GHSA-4FC2-H7JH-287C CVE-2026-52732 | zebrad has mempool transaction admission denial via single-peer inbound queue saturation | 中危 | crates.iozebrad | 已审查 | 2026-07-03 03:39 | 2026-07-03 03:39 |
| GHSA-C8W6-X74F-VMG3 | zebrad vulnerable to full node denial of service via crafted Sapling receiver in z_listunifiedreceivers | 中危 | crates.iozebra-rpc+1 | 已审查 | 2026-07-03 03:37 | 2026-07-03 03:37 |
| GHSA-F9FF-5X35-7GFW | Grackle: Fail-open authorization in the MCP tool layer lets scoped agents perform cross-task and cross-session mutations (IDOR) | 高危 | npm@grackle-ai/auth+2 | 已审查 | 2026-07-03 03:35 | 2026-07-03 03:35 |
| GHSA-443G-GWGP-49X4 | zebrad vulnerable to getblocks/getheaders locator CPU amplification via uncapped vector length | 低危 | crates.iozebra-chain+1 | 已审查 | 2026-07-03 03:34 | 2026-07-03 03:34 |
| GHSA-QV2R-V3MX-F4PF CVE-2026-52731 | zebrad has full node denial of service via non-ASCII LongPollId in getblocktemplate | 中危 | crates.iozebra-rpc+1 | 已审查 | 2026-07-03 03:28 | 2026-07-03 03:28 |
| GHSA-FCMW-WX57-9P75 CVE-2026-4776 | Mautic has SQL Injection in API Contact Filtering | 高危 | Packagistmautic/core | 已审查 | 2026-07-03 03:25 | 2026-07-03 03:25 |
| GHSA-Q4RM-M6XH-5PV7 | Froxlor customer can create MySQL databases on disallowed servers via Mysqls.add API | 中危 | Packagistfroxlor/froxlor | 已审查 | 2026-07-03 03:23 | 2026-07-03 03:23 |
| GHSA-MR9H-45P9-FG8H | Froxlor: Authenticated customers can read other customers' allowed sender aliases | 中危 | Packagistfroxlor/froxlor | 已审查 | 2026-07-03 03:23 | 2026-07-03 03:23 |
| GHSA-V5FF-XMFP-P245 CVE-2026-49255 | electerm has Command Injection in File System Operations (rmrf, mv, cp) | 高危 | npmelecterm | 已审查 | 2026-07-03 03:22 | 2026-07-03 03:22 |
| GHSA-4Q9J-6299-GXMR CVE-2026-49254 | Dragonfly Manager OAuth provider client_secret disclosure via unauthenticated GET /api/v1/oauth | 低危 | God7y.io/dragonfly/v2 | 已审查 | 2026-07-03 03:21 | 2026-07-03 03:21 |
| GHSA-38J7-23HF-9MHC CVE-2026-49253 | electerm has Path Traversal in Zmodem and Trzsz Download Filename Handling | 高危 | npmelecterm | 已审查 | 2026-07-03 03:20 | 2026-07-03 03:20 |
| GHSA-525M-7F82-2MF7 CVE-2026-49250 | @conform-to/dom parseSubmission vulnerable to CPU exhaustion when parsing many unique form fields | 高危 | npm@conform-to/dom | 已审查 | 2026-07-03 03:18 | 2026-07-03 03:18 |
| GHSA-VV65-F55V-XM6G | Grackle has command/argument injection in the git worktree executor that enables RCE on provisioned hosts via an unsanitized task branch name (shell:true) | 高危 | npm@grackle-ai/powerline+1 | 已审查 | 2026-07-03 03:16 | 2026-07-03 03:16 |
| GHSA-GG9X-QCX2-XMRH CVE-2026-49852 | joserfc: HS256/HS384/HS512 verify accepts empty/nil HMAC key (cross-language sibling of CVE-2026-45363) | 高危 | PyPIjoserfc | 已审查 | 2026-07-03 03:12 | 2026-07-03 03:12 |
| GHSA-3VCG-PV95-PQ54 CVE-2026-49245 | SFTPGo has stored XSS via inline parameter on public shares and user file download | 低危 | Gogithub.com/drakkan/sftpgo/v2 | 已审查 | 2026-07-03 03:09 | 2026-07-03 03:09 |
| GHSA-H64P-8H4R-6GFH CVE-2026-49244 | SFTPGo has path confinement bypass in public browsable share partial ZIP download | 中危 | Gogithub.com/drakkan/sftpgo/v2 | 已审查 | 2026-07-03 03:09 | 2026-07-03 03:09 |
| GHSA-93Q6-WWJH-JC6H CVE-2026-50290 | @asymmetric-effort/specifyjs: CSS expression sanitization is bypassable in renderToString | 中危 | npm@asymmetric-effort/specifyjs | 已审查 | 2026-07-03 03:08 | 2026-07-03 03:08 |
| GHSA-J5QP-P44G-2M49 | @asymmetric-effort/specifyjs: No redirect target validation in secureFetch | 中危 | npm@asymmetric-effort/specifyjs | 已审查 | 2026-07-03 03:08 | 2026-07-03 03:08 |