检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-2497-6PWJ-PWG7 CVE-2026-49288 | Statamic CMS: Missing authorization on Control Panel fieldtype endpoints allows disclosure of restricted resources | 中危 | Packagiststatamic/cms | 已审查 | 2026-06-27 06:12 | 2026-06-27 06:12 |
| GHSA-X8G9-H984-PC36 CVE-2026-49359 | PhpWeasyPrint vulnerable to SSRF and local file disclosure via the attachment option |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 中危 |
Packagistpontedilana/php-weasyprint |
| 已审查 |
| 2026-06-27 06:11 |
| 2026-06-27 06:11 |
| GHSA-5G9F-CWWG-4P8G CVE-2026-49358 | PhpWeasyPrint vulnerable to arbitrary file deletion at shutdown via public $temporaryFiles | 低危 | Packagistpontedilana/php-weasyprint | 已审查 | 2026-06-27 06:10 | 2026-06-27 06:10 |
| GHSA-2FMJ-P74R-3WJM CVE-2026-49286 | PhpWeasyPrint vulnerable to PHAR deserialization via output filename (CVE-2023-28115 case-insensitive bypass) | 高危 | Packagistpontedilana/php-weasyprint | 已审查 | 2026-06-27 06:10 | 2026-06-27 06:10 |
| GHSA-9653-RCFR-5C62 CVE-2026-47067 | Hackney vulnerable to atom-table exhaustion via unrecognized URL schemes | 高危 | Hexhackney | 已审查 | 2026-06-27 06:01 | 2026-06-27 06:01 |
| GHSA-Q8JG-FGJ4-FPHF CVE-2026-47073 | Hackney has unbounded buffer accumulation in WebSocket | 高危 | Hexhackney | 已审查 | 2026-06-27 06:00 | 2026-06-27 06:00 |
| GHSA-F9VR-G2G2-X9FG CVE-2026-47072 | Hackney has CRLF / header injection in WebSocket upgrade request | 中危 | Hexhackney | 已审查 | 2026-06-27 05:59 | 2026-06-27 05:59 |
| GHSA-J9WQ-VXXC-94WF CVE-2026-47075 | Hackney has CR/LF injection in query parameter | 中危 | Hexhackney | 已审查 | 2026-06-27 05:58 | 2026-06-27 05:58 |
| GHSA-JQ4M-Q6P2-8GWC CVE-2026-47077 | Hackney: Per-chunk timeout with unbounded body accumulation enables slow-drip OOM | 高危 | Hexhackney | 已审查 | 2026-06-27 05:57 | 2026-07-01 01:16 |
| GHSA-H73Q-4W9Q-82H4 CVE-2026-47070 | Hackney: Cross-origin Redirect Leaks Authorization, Cookie, and Request Body | 中危 | Hexhackney | 已审查 | 2026-06-27 05:56 | 2026-06-27 05:56 |
| GHSA-PJ7V-XFVX-WMJQ CVE-2026-47076 | Hackney has SSRF allowlist bypass in hackney_url:normalize/2 via percent-encoded host | 中危 | Hexhackney | 已审查 | 2026-06-27 05:54 | 2026-06-27 05:54 |
| GHSA-MP55-P8C9-RFW2 CVE-2026-47069 | Hackney has CRLF / header injection via unvalidated `domain` and `path` options | 低危 | Hexhackney | 已审查 | 2026-06-27 05:54 | 2026-06-27 05:54 |
| GHSA-GP9C-PM5M-5CXR CVE-2026-47071 | Hackney: `ssl:connect/2` post-handshake upgrade has no timeout | 高危 | Hexhackney | 已审查 | 2026-06-27 05:53 | 2026-06-27 05:53 |
| GHSA-6CP8-V795-JR2J CVE-2026-47066 | Hackney has an infinite loop on non-token byte at start of an Alt-Svc entry | 高危 | Hexhackney | 已审查 | 2026-06-27 05:53 | 2026-06-27 05:53 |
| GHSA-4HF8-5MJM-RFGQ CVE-2026-49357 | Streamable HTTP mode exposes LINE Desktop read/send tools without MCP authentication | 高危 | npmline-desktop-mcp | 已审查 | 2026-06-27 05:50 | 2026-06-27 05:50 |
| GHSA-MMJ8-WCVW-6789 CVE-2026-49262 | Aimeos Pagible CMS vulnerable to Server Side Request Forgery (SSRF) via DNS rebinding in admin proxy | 低危 | Packagistaimeos/pagible | 已审查 | 2026-06-27 05:50 | 2026-06-27 05:50 |
| GHSA-HG3W-7F8C-63HP CVE-2026-48995 | pnpm: Tarball hash of GitHub git dependencies is not stored in lockfile | 中危 | npmpnpm | 已审查 | 2026-06-27 05:49 | 2026-06-27 05:49 |
| GHSA-JQ42-7MFV-HM57 CVE-2026-5223 | Cargo crates in third party registries can override the cached source of other crates | 中危 | crates.iocargo | 已审查 | 2026-06-27 05:48 | 2026-06-27 05:48 |
| GHSA-P688-R7JV-FM6F CVE-2026-5222 | Cargo can be coerced to share credentials between registries | 低危 | crates.iocargo | 已审查 | 2026-06-27 05:47 | 2026-06-27 05:47 |
| GHSA-F5GC-QXF8-MH9G CVE-2026-49260 | php-weasyprint: shell command injection via configurable WeasyPrint binary path due to inverted is_executable() guard (mirror of KnpLabs/snappy GHSA-vpr4-p6fq-85jc) | 高危 | Packagistpontedilana/php-weasyprint | 已审查 | 2026-06-27 05:46 | 2026-06-27 05:46 |
| GHSA-C6V2-3FFM-VCMC CVE-2026-49258 | Nebula Mesh: Web UI lacks ownership checks, enabling cross-operator access to hosts and networks (read, block, delete) | 高危 | Gogithub.com/juev/nebula-mesh | 已审查 | 2026-06-27 05:29 | 2026-06-27 05:29 |
| GHSA-985R-Q3QP-299H | phpMyFAQ has an incomplete fix for GHSA-xvp4-phqj-cjr3 — editUser() and updateUserRights() lack authorization guards | 高危 | Packagistphpmyfaq/phpmyfaq+1 | 已审查 | 2026-06-27 05:23 | 2026-06-27 05:23 |
| GHSA-RP72-5V5Q-2446 | @cardano402/mcp-server missing spending limits, LAN-exposed HTTP transport, and SSRF via catalog.server.url | 低危 | npm@cardano402/mcp-server | 已审查 | 2026-06-27 05:08 | 2026-06-27 05:08 |
| GHSA-73CV-556C-W3G6 CVE-2026-49257 | mcp-pinot: Unauthenticated tool invocation via default oauth_enabled=False + host 0.0.0.0 bind | 严重 | PyPImcp-pinot-server | 已审查 | 2026-06-27 05:05 | 2026-06-27 05:05 |
| GHSA-JV46-XFWM-36J7 CVE-2026-49454 | Relyra SAML SignatureValue not cryptographically verified -> authentication bypass | 严重 | Hexrelyra | 已审查 | 2026-06-27 05:05 | 2026-06-27 05:05 |