检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-HHX9-57XQ-R5RW CVE-2026-48819 | @hey-api/openapi-ts's `buildClientParams` template: prototype chain substitution via unknown `$<slot>___proto__` key | 中危 | npm@hey-api/openapi-ts | 已审查 | 2026-07-02 04:55 | 2026-07-02 04:55 |
| GHSA-4J6X-2764-M8GH CVE-2026-41053 | Rancher has over-inclusive team membership expansion in GitHub App authentication provider |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 高危 |
Gogithub.com/rancher/rancher |
| 已审查 |
| 2026-07-02 04:51 |
| 2026-07-02 04:51 |
| GHSA-XR65-5CPM-G36X CVE-2026-44935 | Rancher Fleet vulnerable to cross namespace secret disclosure via unvalidated `valuesFrom` references in Helm Deployer | 严重 | Gogithub.com/rancher/fleet | 已审查 | 2026-07-02 04:45 | 2026-07-02 04:45 |
| GHSA-HX4V-CXPF-VH8M CVE-2026-44936 | Rancher Fleet has SSRF in Bundle Reader via Unvalidated Helm Repository URL in fleet.yaml | 中危 | Gogithub.com/rancher/fleet | 已审查 | 2026-07-02 04:45 | 2026-07-02 04:45 |
| GHSA-MHC6-2GFQ-XX62 CVE-2026-44939 | Rancher vulnerable to command injection through unsanitized YAML parameter | 严重 | Gogithub.com/rancher/rancher | 已审查 | 2026-07-02 04:44 | 2026-07-02 04:44 |
| GHSA-JMF4-M7J9-G72R CVE-2026-44937 | Rancher Fleet has Unauthenticated Webhook: Regex Injection via Unsanitized Repository URL Components | 高危 | Gogithub.com/rancher/fleet | 已审查 | 2026-07-02 04:44 | 2026-07-02 04:44 |
| GHSA-864G-863M-VCVQ CVE-2026-44938 | Fleet has PSS Bypass through addLabelsFromOptions in Fleet Agent | 高危 | Gogithub.com/rancher/fleet | 已审查 | 2026-07-02 04:35 | 2026-07-02 04:35 |
| GHSA-2R8V-P65X-3663 CVE-2026-49457 | QUIC has Broken TLS verification | 严重 | Hexquic | 已审查 | 2026-07-02 04:32 | 2026-07-02 04:32 |
| GHSA-J6HM-V3X2-QV6J | land.oras:oras-java-sdk: Symlink-based path traversal in ArchiveUtils.untar / unzip allows arbitrary file write outside extraction directory | 低危 | Mavenland.oras:oras-java-sdk | 已审查 | 2026-07-02 04:31 | 2026-07-02 04:31 |
| GHSA-G6VG-WJ8F-48CJ CVE-2026-49998 | Centrifugo's dynamic JWKS key cache keyed only by `kid` allows cross-issuer JWT authentication bypass | 高危 | Gogithub.com/centrifugal/centrifugo+4 | 已审查 | 2026-07-02 04:28 | 2026-07-02 04:28 |
| GHSA-WHWG-VH4F-PMMF CVE-2026-49997 | SurrealDB: Edge PERMISSIONS FOR delete bypassed when a connected node is deleted | 中危 | crates.iosurrealdb | 已审查 | 2026-07-02 04:23 | 2026-07-21 03:08 |
| GHSA-FWG2-GR34-Q3W8 | SurrealDB: ES512 silently downgraded to ES384 due to jsonwebtoken crate limitation | 中危 | crates.iosurrealdb | 已审查 | 2026-07-02 04:23 | 2026-07-02 04:23 |
| GHSA-C8JX-96C9-8XRP | SurrealDB: Field-level SELECT permissions bypassed via indexed COUNT fast paths | 中危 | crates.iosurrealdb | 已审查 | 2026-07-02 04:22 | 2026-07-02 04:22 |
| GHSA-WP87-MGVQ-5J93 | SurrealDB: USE NS/DB implicit creation bypasses DEFINE authorization | 中危 | crates.iosurrealdb | 已审查 | 2026-07-02 04:21 | 2026-07-02 04:21 |
| GHSA-97VG-427P-8HX5 | SurrealDB: Port-specific --deny-net rules silently bypassed on HTTP redirect | 中危 | crates.iosurrealdb | 已审查 | 2026-07-02 04:20 | 2026-07-02 04:20 |
| GHSA-6WQW-VHFR-9999 | SurrealDB: Authenticated subscribers can read records hidden by SELECT permissions via LIVE subscriptions | 中危 | crates.iosurrealdb | 已审查 | 2026-07-02 04:20 | 2026-07-02 04:20 |
| GHSA-F82J-V89J-MF86 | SurrealDB: `RELATE` overwrites existing edge records without `UPDATE` permission | 中危 | crates.iosurrealdb | 已审查 | 2026-07-02 04:19 | 2026-07-02 04:19 |
| GHSA-FPXG-5XMV-922M | SurrealDB has bypass of field-level SELECT permissions through JSON Patch `copy` and `move` with empty `from` | 中危 | crates.iosurrealdb | 已审查 | 2026-07-02 04:18 | 2026-07-02 04:18 |
| GHSA-6G9V-7GQ3-P2C6 | SurrealDB: Authenticated callers can read fields hidden by field-level SELECT permissions via error messages | 中危 | crates.iosurrealdb | 已审查 | 2026-07-02 04:16 | 2026-07-02 04:16 |
| GHSA-4M82-P8CX-F94J | SurrealDB: LIVE query subscriptions survive session state changes, bypassing access controls | 中危 | crates.iosurrealdb | 已审查 | 2026-07-02 04:16 | 2026-07-02 04:16 |
| GHSA-65RJ-R9FH-JP2V | SurrealDB vulnerable to pre-auth memory amplification via unbounded `/sql` WebSocket frames | 中危 | crates.iosurrealdb | 已审查 | 2026-07-02 04:15 | 2026-07-02 04:15 |
| GHSA-GCWR-5MRF-FVCH | SurrealDB: Authorization Bypass in KILL Statement Allows Termination of Other Users' Live Queries | 中危 | crates.iosurrealdb | 已审查 | 2026-07-02 04:14 | 2026-07-02 04:14 |
| GHSA-4V76-CW68-4VC9 | SurrealDB: Crafting malicious LIVE queries writes to the database, resulting in DoS, without permission to the table required | 中危 | crates.iosurrealdb | 已审查 | 2026-07-02 04:13 | 2026-07-02 04:13 |
| GHSA-6VG3-HGRW-P5GF | SurrealDB has an Authorization Bypass via Composite Record-id Paths | 中危 | crates.iosurrealdb | 已审查 | 2026-07-02 04:12 | 2026-07-02 04:12 |
| GHSA-VJJX-RFW4-RMFC | SurrealDB: Graph traversal bypasses table SELECT permissions | 中危 | crates.iosurrealdb | 已审查 | 2026-07-02 04:10 | 2026-07-02 04:10 |