检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-98FX-66CF-FC7C | SurrealDB: Scraping a TABLE with no available PERMISSIONS to current auth level | 中危 | crates.iosurrealdb | 已审查 | 2026-07-02 04:06 | 2026-07-02 04:06 |
| GHSA-Q8QP-67F9-WR3F | SurrealDB vulnerable to Denial of Service due to nested types annotations |
当前筛选结果 35,190 条 · 时间按北京时间显示
crates.iosurrealdb |
| 已审查 |
| 2026-07-02 04:05 |
| 2026-07-02 04:05 |
| GHSA-WJJJ-24CX-F28G | SurrealDB has unauthenticated remote DoS via malformed RPC `use` call | 高危 | crates.iosurrealdb | 已审查 | 2026-07-02 04:04 | 2026-07-02 04:04 |
| GHSA-Q729-696Q-G9PQ | SurrealDB has Denial of Service in JSON parser due to nested objects | 高危 | crates.iosurrealdb | 已审查 | 2026-07-02 04:03 | 2026-07-02 04:03 |
| GHSA-4VGR-H27G-CF9P | SurrealDB: HTTP RPC Session Race Condition Allows Privilege Escalation | 高危 | crates.iosurrealdb | 已审查 | 2026-07-02 04:02 | 2026-07-02 04:02 |
| GHSA-5QFP-32CF-69JH | SurrealDB: HTTP /rpc `sessions` method leaks attached session UUIDs, enabling full session hijack by anonymous callers | 高危 | crates.iosurrealdb | 已审查 | 2026-07-02 04:00 | 2026-07-02 04:00 |
| GHSA-52V5-JR5W-GJXR CVE-2026-48815 | sigstore's `certificateOIDs` verification constraints are silently dropped and never enforced | 高危 | npmsigstore | 已审查 | 2026-07-02 03:58 | 2026-07-02 03:58 |
| GHSA-XGJW-PM74-86Q4 CVE-2026-48816 | sigstore-js has Insufficient Verification of Data Authenticity | 中危 | npm@sigstore/verify | 已审查 | 2026-07-02 03:57 | 2026-07-02 03:57 |
| GHSA-2XV8-GJWH-FV8P CVE-2026-49989 | CrateDB's Blob HTTP handler bypasses authorization | 低危 | Mavenio.crate:crate | 已审查 | 2026-07-02 03:55 | 2026-07-02 03:55 |
| GHSA-M492-GV72-XVXJ | Kimai Password Reset Link Remains Valid After Password Change | 低危 | Packagistkimai/kimai | 已审查 | 2026-07-02 03:49 | 2026-07-02 03:49 |
| GHSA-HWPP-H97W-2H3J CVE-2026-49988 | repomix: attach_packed_output can bypass file-read secret scanning for supported local files | 中危 | npmrepomix | 已审查 | 2026-07-02 03:01 | 2026-07-02 03:01 |
| GHSA-8W27-C4VC-88Q9 CVE-2026-49826 | Concourse login flow has an open redirect issue | 低危 | Gogithub.com/concourse/concourse | 已审查 | 2026-07-02 03:01 | 2026-07-02 03:01 |
| GHSA-9MM9-RQHJ-J5MX CVE-2026-49987 | repomix Vulnerable to Command Injection (RCE) via `--remote-branch` Argument Injection | 高危 | npmrepomix | 已审查 | 2026-07-02 03:00 | 2026-07-02 03:00 |
| GHSA-MJGF-XJ26-9QF9 | pay-rails/pay: non-constant-time HMAC comparison in Paddle Billing webhook signature verifier | 高危 | RubyGemspay | 已审查 | 2026-07-02 02:57 | 2026-07-02 02:57 |
| GHSA-529H-VH3J-85HQ CVE-2026-49981 | Twig: Sandbox filter, tag and function allow-list bypass when sandbox state changes between renders for a cached `Template` | 高危 | Packagisttwig/twig | 已审查 | 2026-07-02 02:55 | 2026-07-02 02:55 |
| GHSA-3CCM-4QQ2-5WRP | Constrata's coordinator transit engine `ciphertextContainer.UnmarshalJSON` panics on attacker-controlled short ciphertexts | 中危 | Gogithub.com/edgelesssys/contrast | 已审查 | 2026-07-02 02:47 | 2026-07-02 02:47 |
| GHSA-6C87-G9PW-78FX | Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries | 低危 | Gogithub.com/edgelesssys/contrast | 已审查 | 2026-07-02 02:43 | 2026-07-02 02:43 |
| GHSA-GVPP-V77H-5W8G CVE-2026-49986 | Cortex has Untrusted Project Bootstrap Code Execution via `CLAUDE_PROJECT_DIR` | 高危 | PyPIneuro-cortex-memory | 已审查 | 2026-07-02 02:41 | 2026-07-02 02:41 |
| GHSA-HWMC-R6MF-JH83 | Schema.org has cross-site scripting (XSS) via script break-out in toScript() output | 低危 | Packagistspatie/schema-org | 已审查 | 2026-07-02 02:32 | 2026-07-02 02:33 |
| GHSA-V3JC-474W-2WM6 CVE-2026-54428 | Apache HttpComponents Core: HPackDecoder Unlimited Header List Size Before SETTINGS ACK | 高危 | Mavenorg.apache.httpcomponents.core5:httpcore5-h2 | 已审查 | 2026-07-02 02:31 | 2026-08-14 02:27 |
| GHSA-HF6X-8P5F-CGMF CVE-2026-54399 | Apache HttpComponents Core HTTP/1 header parsing can cause memory-exhaustion denial of service | 高危 | Mavenorg.apache.httpcomponents.core5:httpcore5 | 已审查 | 2026-07-02 02:31 | 2026-08-13 03:24 |
| GHSA-26C4-7VV6-867J CVE-2026-12480 | Keras: HDF5 virtual datasets can disclose local files | 中危 | PyPIkeras | 已审查 | 2026-07-02 02:31 | 2026-08-08 04:28 |
| GHSA-P26J-H7WJ-R568 CVE-2026-49864 | wetty vulnerable to DOM XSS via file-download filename | 高危 | npmwetty | 已审查 | 2026-07-02 02:19 | 2026-07-02 02:19 |
| GHSA-2WWR-9X6F-88GP | EasyAdminBundle has path traversal and reflected XSS in Flag and Icon Twig components | 中危 | Packagisteasycorp/easyadmin-bundle | 已审查 | 2026-07-02 02:18 | 2026-07-02 02:18 |
| GHSA-PVRJ-8CG3-J5F8 CVE-2026-49857 | auth-fetch-mcp has SSRF Protection Bypass via IPv4-mapped IPv6 Loopback | 高危 | npmauth-fetch-mcp | 已审查 | 2026-07-02 02:16 | 2026-07-02 02:16 |