检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-4W5W-4FHM-Q483 CVE-2026-2705 | Open Babel has NULL pointer dereference in MOL2 OBAtom::SetFormalCharge | 低危 | PyPIopenbabel | 已审查 | 2026-07-01 02:47 | 2026-07-01 02:47 |
| GHSA-6XW4-2G22-26H8 CVE-2026-2704 | Open Babel has an out-of-bounds read in CIF transform3d::DescribeAsString |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 低危 |
PyPIopenbabel |
| 已审查 |
| 2026-07-01 02:46 |
| 2026-07-01 02:46 |
| GHSA-H8VQ-8GPG-MHCG CVE-2026-48808 | Twig: Sandbox property allowlist bypass via the `column` filter under `SourcePolicyInterface` | 中危 | Packagisttwig/twig | 已审查 | 2026-07-01 02:43 | 2026-07-01 02:43 |
| GHSA-8X9C-RMQH-456C CVE-2026-48807 | Twig: Sandbox `__toString()` policy bypass via `Traversable` in `join` and `replace` filters | 中危 | Packagisttwig/twig | 已审查 | 2026-07-01 02:43 | 2026-07-01 02:43 |
| GHSA-5V5V-WW74-355V CVE-2026-48806 | Twig: Sandbox `__toString()` policy bypass via dynamic mapping keys | 中危 | Packagisttwig/twig | 已审查 | 2026-07-01 02:42 | 2026-07-01 02:42 |
| GHSA-P42Q-9PRX-Q5WQ CVE-2026-48805 | Twig: Sandbox state regression in deprecated internal wrappers in `src/Resources/core.php` | 低危 | Packagisttwig/twig | 已审查 | 2026-07-01 02:41 | 2026-07-01 02:41 |
| GHSA-9C54-X2G4-V92J CVE-2026-49835 | Sigstore Timestamp Authority has OOM due to unbounded metric label cardinality | 中危 | Gogithub.com/sigstore/timestamp-authority+1 | 已审查 | 2026-07-01 02:40 | 2026-07-01 02:40 |
| GHSA-F5MR-Q85P-6HH6 CVE-2026-49478 | Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage | 高危 | Gogithub.com/sigstore/fulcio | 已审查 | 2026-07-01 02:38 | 2026-07-01 02:38 |
| GHSA-85JM-CWP2-MVPV CVE-2026-48796 | CefSharp.Common: `FolderSchemeHandlerFactory` path boundary check can expose files outside the configured root folder | 中危 | NuGetCefSharp.Common | 已审查 | 2026-07-01 02:36 | 2026-07-01 02:36 |
| GHSA-QCM7-3VPR-HJ5H CVE-2026-48795 | @adonisjs/bodyparser has an incomplete fix for CVE-2026-25754 | 高危 | npm@adonisjs/bodyparser | 已审查 | 2026-07-01 02:34 | 2026-07-01 02:34 |
| GHSA-389X-RGXR-8M33 CVE-2026-48592 | oban_web missing authorization check on `save-job` event handler | 中危 | Hexoban_web | 已审查 | 2026-07-01 02:33 | 2026-07-01 02:33 |
| GHSA-6XH2-93P9-VQH4 CVE-2026-48593 | oban_web: Unbounded range expansion in cron describe causes memory exhaustion | 中危 | Hexoban_web | 已审查 | 2026-07-01 02:32 | 2026-07-01 02:32 |
| GHSA-X7QQ-M748-8P2C CVE-2026-49820 | Probo has an open redirect bypass via path normalization | 中危 | Gogo.probo.inc/probo | 已审查 | 2026-07-01 02:31 | 2026-07-01 02:31 |
| GHSA-M63V-2G9W-2W6V CVE-2026-50566 | Fission: Environment Runtime.Container and Builder.Container SecurityContext bypass allows privileged pod creation | 严重 | Gogithub.com/fission/fission | 已审查 | 2026-07-01 02:20 | 2026-07-01 02:20 |
| GHSA-8WCJ-MFRC-JX5Q CVE-2026-50565 | Fission builder pods auto-mount the fission-builder ServiceAccount token in the user-supplied builder container | 中危 | Gogithub.com/fission/fission | 已审查 | 2026-07-01 02:20 | 2026-07-01 02:20 |
| GHSA-GX55-F84R-V3R7 CVE-2026-50564 | Fission Environment CRD podspec passthrough enables hostPID/hostNetwork/privileged pods, node escape | 严重 | Gogithub.com/fission/fission | 已审查 | 2026-07-01 02:19 | 2026-07-01 02:19 |
| GHSA-V455-MV2V-5G92 CVE-2026-50563 | Fission Container Executor Function PodSpec Injection Leading to Node Escape | 严重 | Gogithub.com/fission/fission | 已审查 | 2026-07-01 02:18 | 2026-07-01 02:18 |
| GHSA-WMGG-3P4H-48X7 CVE-2026-50545 | Fission Environment CRD PodSpec Injection Leading to Node Escape and Cluster Takeover | 严重 | Gogithub.com/fission/fission | 已审查 | 2026-07-01 02:18 | 2026-07-01 02:18 |
| GHSA-CVW6-GFVV-953Q CVE-2026-49824 | Fission: Cross-namespace Environment reference via unvalidated EnvironmentRef in Function admission webhook | 高危 | Gogithub.com/fission/fission | 已审查 | 2026-07-01 02:17 | 2026-07-01 02:17 |
| GHSA-3R8V-2XMJ-5C39 CVE-2026-49823 | Fission: Cross-namespace Package read via unvalidated PackageRef in Function admission webhook | 高危 | Gogithub.com/fission/fission | 已审查 | 2026-07-01 02:16 | 2026-07-01 02:16 |
| GHSA-GC3J-79F2-7VVW CVE-2026-49822 | Fission: Cross-namespace event leakage via KubernetesWatchTrigger allows persistent tenant surveillance | 高危 | Gogithub.com/fission/fission | 已审查 | 2026-07-01 02:16 | 2026-07-01 02:16 |
| GHSA-VJHC-CF4P-72Q4 CVE-2026-49821 | Fission: Cross-namespace Environment reference in Package allows build-time command execution and SA token exfiltration | 高危 | Gogithub.com/fission/fission | 已审查 | 2026-07-01 02:15 | 2026-07-01 02:15 |
| GHSA-7M8X-QG2J-4M3V | Fission: MessageQueueTrigger scaler manager materializes Secret values into Deployment envvars and accepts arbitrary user PodSpec | 高危 | Gogithub.com/fission/fission | 已审查 | 2026-07-01 02:12 | 2026-07-01 02:12 |
| GHSA-QQW8-7C2R-JXCH CVE-2026-48791 | Sigstore Java has a vulnerability with bundle verification of integratedTime | 低危 | Mavendev.sigstore:sigstore-java | 已审查 | 2026-07-01 02:10 | 2026-07-01 02:10 |
| GHSA-G4W6-VMGF-XQVX CVE-2026-49473 | @cedar-policy/authorization-for-expressjs has an authorization bypass via query string manipulation | 高危 | npm@cedar-policy/authorization-for-expressjs | 已审查 | 2026-07-01 02:09 | 2026-07-01 02:09 |