检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-7MQQ-4V55-88GH CVE-2026-54244 | Statamic CMS's incorrect authorization lets view-only users submit Live Preview content reserved for editors | 低危 | Packagiststatamic/cms | 已审查 | 2026-06-27 07:10 | 2026-06-27 07:10 |
| GHSA-9RC6-8CJV-RCVX CVE-2026-53523 | Nezha Monitoring: OAuth2 Redirect URL — Host Header Injection |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 中危 |
Gogithub.com/nezhahq/nezha |
| 已审查 |
| 2026-06-27 07:05 |
| 2026-06-27 07:05 |
| GHSA-JG62-J5H6-8MPQ CVE-2026-53522 | Nezha Monitoring: Unbounded WebSocket Streams — Resource Exhaustion DoS | 中危 | Gogithub.com/nezhahq/nezha | 已审查 | 2026-06-27 07:04 | 2026-06-27 07:04 |
| GHSA-H77M-QRJ7-JXCW CVE-2026-54243 | Statamic Vulnerable to CSV formula injection in form submission exports | 中危 | Packagiststatamic/cms | 已审查 | 2026-06-27 07:03 | 2026-06-27 07:03 |
| GHSA-V5C4-WCPJ-X73M CVE-2026-54242 | Statamic Vulnerable to Server-Side Request Forgery via Glide (DNS rebinding) | 中危 | Packagiststatamic/cms | 已审查 | 2026-06-27 07:03 | 2026-06-27 07:03 |
| GHSA-5C25-7VPJ-9MQH CVE-2026-53519 | Nezha Monitoring: Pre-auth path traversal via /dashboard.. prefix confusion leaks jwt_secret_key | 严重 | Gogithub.com/nezhahq/nezha | 已审查 | 2026-06-27 07:03 | 2026-06-27 07:03 |
| GHSA-39G2-8X68-PMX8 CVE-2026-53521 | Nezha Monitoring: Stored future DDNS profile ID allows unauthorized use of another user's DDNS profile context | 中危 | Gogithub.com/nezhahq/nezha | 已审查 | 2026-06-27 07:02 | 2026-06-27 07:02 |
| GHSA-X6FG-52VR-HJ4W CVE-2026-53520 | Nezha Monitoring: Authenticated users can claim the dashboard Host through NAT and preempt all dashboard routing | 中危 | Gogithub.com/nezhahq/nezha | 已审查 | 2026-06-27 07:00 | 2026-06-27 07:00 |
| GHSA-RXHJ-4M44-96R4 CVE-2026-50015 | pnpm Vulnerable to Arbitrary File Write/Delete via Malicious Patch File (Path Traversal) | 高危 | npmpnpm | 已审查 | 2026-06-27 06:59 | 2026-06-27 06:59 |
| GHSA-CJHR-43R9-CFMW CVE-2026-50017 | pnpm binds unscoped user-level npm auth credentials to a repository-selected registry | 中危 | npmpnpm | 已审查 | 2026-06-27 06:59 | 2026-06-27 06:59 |
| GHSA-HWX4-2J3J-G496 CVE-2026-50016 | pnpm: Transitive dependency alias path traversal allows project path override via symlink replacement | 高危 | npmpnpm | 已审查 | 2026-06-27 06:55 | 2026-06-27 06:55 |
| GHSA-P4XF-RF54-RJ3X CVE-2026-50014 | pnpm: Git Fetch Argument Injection via Lockfile resolution.commit | 中危 | npmpnpm | 已审查 | 2026-06-27 06:53 | 2026-06-27 06:53 |
| GHSA-Q6J5-FJX5-2MC3 CVE-2026-50021 | pnpm Has an Integrity Check Bypass via Missing Lockfile Integrity Field | 中危 | npmpnpm | 已审查 | 2026-06-27 06:53 | 2026-06-27 06:53 |
| GHSA-54HH-G5MX-JQCP CVE-2026-50573 | pnpm: Unsafe default behavior breaks integrity check | 中危 | npmpnpm | 已审查 | 2026-06-27 06:52 | 2026-06-27 06:52 |
| GHSA-8JGF-23Q5-X7XX CVE-2026-47074 | ex_aws_sns: Trusted-attacker `SigningCertURL` permits complete SNS signature bypass | 高危 | Hexex_aws_sns | 已审查 | 2026-06-27 06:50 | 2026-07-01 01:16 |
| GHSA-M34P-749J-X6M6 CVE-2026-50029 | js-toml has silent type confusion via falsy-primitive duplicate-key bypass | 中危 | npmjs-toml | 已审查 | 2026-06-27 06:49 | 2026-07-22 01:23 |
| GHSA-QVQC-4C52-X6QP CVE-2026-49349 | regclient may leak authentication credentials to external blob stores | 中危 | Gogithub.com/regclient/regclient | 已审查 | 2026-06-27 06:43 | 2026-06-27 06:43 |
| GHSA-J748-H363-WQJ8 CVE-2026-48794 | Authelia has an Edge Case Access Control Rule Mismatch | 低危 | Gogithub.com/authelia/authelia/v4 | 已审查 | 2026-06-27 06:32 | 2026-06-27 06:32 |
| GHSA-Q6XX-5VR8-P898 | Nezha vulnerable to cross-tenant terminal/file-manager session hijack via WebSocket stream UUID without ownership check | 严重 | Gogithub.com/nezhahq/nezha | 已审查 | 2026-06-27 06:31 | 2026-06-27 06:31 |
| GHSA-WCR3-9X4C-F5GJ | Blnk has an API key authorization bypass in owner and scope enforcement | 高危 | Gogithub.com/blnkfinance/blnk | 已审查 | 2026-06-27 06:31 | 2026-06-27 06:31 |
| GHSA-PXCC-8665-PHX8 CVE-2026-49342 | YARD static cache reads raw traversal paths before router sanitization | 中危 | RubyGemsyard | 已审查 | 2026-06-27 06:29 | 2026-06-27 06:29 |
| GHSA-396Q-4VC8-28X9 CVE-2026-49336 | @microsoft/kiota-http-fetchlibrary: Bearer token and Cookie leak across origin on redirect due to case-mismatched scrub in fetchRequestAdapter | 中危 | npm@microsoft/kiota-http-fetchlibrary | 已审查 | 2026-06-27 06:23 | 2026-06-27 06:23 |
| GHSA-WP3C-266W-4QFQ CVE-2026-49293 | js-toml vulnerable to CPU exhaustion via O(n^2) BigInt construction on radix-prefixed integer literals | 高危 | npmjs-toml | 已审查 | 2026-06-27 06:21 | 2026-06-27 06:21 |
| GHSA-7VFX-4246-JCFH | SolidInvoice: IDOR in LiveComponent allows same-company cross-user access to API tokens and notification transport settings | 高危 | Packagistsolidinvoice/solidinvoice | 已审查 | 2026-06-27 06:20 | 2026-06-27 06:20 |
| GHSA-M92M-R54R-X8R2 CVE-2026-49287 | Statamic CMS's unsafe method invocation via collection sorting allows data destruction | 高危 | Packagiststatamic/cms | 已审查 | 2026-06-27 06:15 | 2026-06-27 06:15 |