检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-RGGC-M335-3WVJ CVE-2026-53832 | OpenClaw: Same-host trusted-proxy deployments could accept local forged identity headers | 高危 | npmopenclaw | 已审查 | 2026-07-03 00:03 | 2026-08-28 23:55 |
| GHSA-V6R2-JH58-XX6W CVE-2026-53810 | OpenClaw's marketplace runtime extension metadata could point at unscanned payloads |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 高危 |
npmopenclaw |
| 已审查 |
| 2026-07-03 00:00 |
| 2026-07-03 00:00 |
| GHSA-2HFG-4FH4-QP7F CVE-2026-53812 | OpenClaw's browser act interactions could bypass private-network navigation checks | 中危 | npmopenclaw | 已审查 | 2026-07-03 00:00 | 2026-07-03 00:00 |
| GHSA-2J8V-HWGC-X698 | OpenClaw: Shell wrapper argv could change between approval and execution | 高危 | npmOpenclaw | 已审查 | 2026-07-02 23:57 | 2026-07-02 23:57 |
| GHSA-QH2F-99MV-MRCF | OpenClaw: Bundle MCP loopback could miss its exec denylist on session spawn | 中危 | npmopenclaw | 已审查 | 2026-07-02 23:42 | 2026-07-02 23:42 |
| GHSA-XWW8-GQVH-92X9 | OpenClaw: Exec approval display truncation could hide the command being approved | 高危 | npmopenclaw | 已审查 | 2026-07-02 23:40 | 2026-07-02 23:40 |
| GHSA-Q7Q8-3MGW-Q67R CVE-2026-53815 | OpenClaw: Message read actions could skip channel allowlist checks | 高危 | npmopenclaw | 已审查 | 2026-07-02 23:40 | 2026-07-02 23:40 |
| GHSA-84HP-MQVJ-3P8H CVE-2026-50027 | mcp-memory-service: Missing Authentication on Document API Endpoints Allows Unauthenticated Memory Read/Write/Delete | 严重 | PyPImcp-memory-service | 已审查 | 2026-07-02 23:26 | 2026-07-02 23:26 |
| GHSA-GCFQ-8GQF-4876 CVE-2026-45045 | GoFiber Vulnerable to X-Real-IP Spoofing via Header.Add() in BalancerForward | 中危 | Gogithub.com/gofiber/fiber/v2+1 | 已审查 | 2026-07-02 21:50 | 2026-08-05 05:52 |
| GHSA-G5VH-55HW-RXM8 CVE-2026-44332 | GoFiber Vulnerable to Username Enumeration via Timing Oracle in BasicAuth Default Authorizer | 中危 | Gogithub.com/gofiber/fiber/v3 | 已审查 | 2026-07-02 21:46 | 2026-07-02 21:46 |
| GHSA-2CM6-R77W-6G96 CVE-2026-8147 | MLflow: trace API endpoints lack proper authorization validators | 高危 | PyPImlflow | 已审查 | 2026-07-02 17:32 | 2026-08-14 02:27 |
| GHSA-9C3V-684M-579C | OpenClaw MCP SSE redirects could forward Authorization headers | 中危 | npmopenclaw | 已审查 | 2026-07-02 06:09 | 2026-07-02 06:09 |
| GHSA-6GR2-QH89-HXWM CVE-2026-50143 | Apify Model Context Protocol (MCP) server: Actor MCP path authority injection leaks Apify token | 高危 | npm@apify/actors-mcp-server | 已审查 | 2026-07-02 06:02 | 2026-07-02 06:02 |
| GHSA-J48M-H7XQ-2XPJ CVE-2026-50139 | goshs: Share-link ?token=… redemption races past download limit | 中危 | Gogoshs.de/goshs/v2 | 已审查 | 2026-07-02 05:59 | 2026-07-02 05:59 |
| GHSA-62Q6-4HV4-VJRW CVE-2026-53943 | Ghost: Cache-poisoning XSS in Ghost frontend via x-ghost-preview header | 严重 | npmghost | 已审查 | 2026-07-02 05:58 | 2026-07-02 05:58 |
| GHSA-3WHC-QVHV-XQJP CVE-2026-50138 | goshs: WebDAV listener ignores --read-only, --upload-only, and --no-delete mode flags | 高危 | Gogoshs.de/goshs/v2 | 已审查 | 2026-07-02 05:56 | 2026-07-02 05:56 |
| GHSA-VH4V-2XQ2-G5CG | ORAS Go forwards registry credentials across registry redirects | 中危 | Gooras.land/oras-go/v2 | 已审查 | 2026-07-02 05:54 | 2026-07-02 05:54 |
| GHSA-P9JG-FCR6-3MHF CVE-2026-53712 | OnGres SCRAM silent channel-binding authentication downgrade via unsupported certificate algorithms | 高危 | Mavencom.ongres.scram:scram-client+1 | 已审查 | 2026-07-02 05:51 | 2026-07-02 05:51 |
| GHSA-FXHP-MV3V-67QP CVE-2026-50163 | `oras-go` tar extraction: Hardlink entry with relative Linkname escapes extract dir via process CWD resolution | 高危 | Gooras.land/oras-go/v2 | 已审查 | 2026-07-02 05:48 | 2026-08-05 05:53 |
| GHSA-8XWF-RJM4-XVHV CVE-2026-50162 | oras-go has file store write outside workingDir via symlink traversal | 中危 | Gooras.land/oras-go/v2 | 已审查 | 2026-07-02 05:43 | 2026-07-02 05:43 |
| GHSA-JXPM-75MH-9FP7 CVE-2026-50151 | oras-go blob upload vulnerable to credential forwarding via unvalidated Location header | 高危 | Gooras.land/oras-go/v2 | 已审查 | 2026-07-02 05:35 | 2026-07-02 05:35 |
| GHSA-32H4-44JJ-C5VX CVE-2026-9795 | Keycloak has privilege escalation via improper scope mapping enforcement | 高危 | Mavenorg.keycloak:keycloak-services | 已审查 | 2026-07-02 05:20 | 2026-07-02 05:20 |
| GHSA-XF85-363P-868W CVE-2026-48978 | oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens | 低危 | Gooras.land/oras-go+1 | 已审查 | 2026-07-02 05:06 | 2026-07-02 05:06 |
| GHSA-VX8H-4PRV-G744 CVE-2026-41052 | Rancher has Privilege Escalation from Project Owner to Host | 严重 | Gogithub.com/rancher/rancher | 已审查 | 2026-07-02 04:57 | 2026-07-02 04:57 |
| GHSA-28PQ-6QXG-WG5R CVE-2026-48824 | Mailpit: Sibling-endpoint memory-exhaustion DoS via unbounded JSON body on /api/v1/messages, /api/v1/tags, and /api/v1/message/{id}/release (incomplete fix of GHSA-fpxj-m5q8-fphw) | 中危 | Gogithub.com/axllent/mailpit | 已审查 | 2026-07-02 04:56 | 2026-09-03 07:40 |