检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-2R68-G678-7QR3 CVE-2026-49291 | mcp-memory-service: OAuth read-only clients can write and delete memories through MCP tools/call | 高危 | PyPImcp-memory-service | 已审查 | 2026-06-27 05:04 | 2026-06-27 05:04 |
| GHSA-9V98-6G37-X9G6 CVE-2026-49252 | deepstream is vulnerable to prototype pollution |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 严重 |
npm@deepstream/server |
| 已审查 |
| 2026-06-27 05:03 |
| 2026-06-27 05:03 |
| GHSA-75MW-H36V-2JV7 | Dosage Vulnerable to Stored Cross-Site Scripting (XSS) in HTML/RSS Output Handlers | 中危 | PyPIdosage | 已审查 | 2026-06-27 05:03 | 2026-07-22 03:53 |
| GHSA-6Q7J-XR26-3H2C | Scriban: ExpressionDepthLimit guard is non-enforcing — parser-recursion DoS in 6.6.0–7.2.0 (incomplete fix for GHSA-wgh7-7m3c-fx25 / GHSA-p6q4-fgr8-vx4p) | 中危 | NuGetScriban+1 | 已审查 | 2026-06-27 05:02 | 2026-07-06 21:10 |
| GHSA-Q6RR-FM2G-G5X8 | Scriban: array * int (ScriptArray<T>.TryEvaluate) bypasses LoopLimit — incomplete fix for GHSA-c875-h985-hvrc, missed sibling of GHSA-24c8-4792-22hx | 中危 | NuGetScriban+1 | 已审查 | 2026-06-27 05:01 | 2026-07-06 21:03 |
| GHSA-V2JF-442R-6MJH | nebula-mesh: Signed-poll nonce LRU is in-memory and bounded; replay survives restart + eviction | 低危 | Gogithub.com/juev/nebula-mesh | 已审查 | 2026-06-27 05:01 | 2026-06-27 05:01 |
| GHSA-Q683-8468-R6H6 | WebauthnAuthenticator leaks sensitive HTTP headers through INFO-level logs | 中危 | Packagistweb-auth/webauthn-symfony-bundle | 已审查 | 2026-06-27 05:00 | 2026-06-27 05:00 |
| GHSA-WPVJ-HJCR-H3P2 CVE-2026-48820 | CakePHP: View::element() is missing a path containment check | 中危 | Packagistcakephp/cakephp | 已审查 | 2026-06-27 05:00 | 2026-06-27 05:00 |
| GHSA-WPHV-VFRH-23Q5 CVE-2026-48990 | joserfc: b64=false RFC7797 JWS payloads bypass JWSRegistry payload-size limits during deserialization | 中危 | PyPIjoserfc | 已审查 | 2026-06-27 04:59 | 2026-06-27 04:59 |
| GHSA-3P34-W4F6-5XH2 | better-helperjs Vulnerable to Directory Traversal via String Prefix Bypass in Static Server | 高危 | npmbetter-helperjs | 已审查 | 2026-06-27 04:56 | 2026-06-27 04:56 |
| GHSA-PW9P-JVRM-F7RM CVE-2026-48979 | PHP Standard Library: HTTP/2 server-side missing content-length validation enables request smuggling | 高危 | Packagistphp-standard-library/h2+1 | 已审查 | 2026-06-27 04:55 | 2026-06-27 04:55 |
| GHSA-FHP4-PR5J-46M5 | Muhammara has a NULL pointer dereference in LZWDecode filter when DecodeParms omits EarlyChange key | 高危 | npmmuhammara | 已审查 | 2026-06-27 04:55 | 2026-06-27 04:55 |
| GHSA-J7F5-GFQM-PCX3 | Pterodactyl Panel: Client email change endpoint allows enumeration of accounts in system | 中危 | Packagistpterodactyl/panel | 已审查 | 2026-06-27 04:54 | 2026-06-27 04:54 |
| GHSA-RHQ6-9RGH-V45C | Pterodactyl Wings: Chmod operation can be used to change permissions of files outside of the server container | 中危 | Gogithub.com/pterodactyl/wings | 已审查 | 2026-06-27 04:53 | 2026-06-27 04:53 |
| GHSA-4C3C-R6P8-C863 CVE-2026-48813 | Flawfinder output manipulation via untrusted filenames and source text | 高危 | PyPIflawfinder | 已审查 | 2026-06-27 04:52 | 2026-08-12 03:22 |
| GHSA-5W7Q-77MV-V69F CVE-2026-48804 | python-socketio: Binary attachment accumulation can cause denial of service | 高危 | PyPIpython-socketio | 已审查 | 2026-06-27 04:51 | 2026-06-27 04:51 |
| GHSA-CGWC-PV48-FHJ5 CVE-2026-48802 | python-engineio has unbound thread allocation that can cause denial of service | 高危 | PyPIpython-engineio | 已审查 | 2026-06-27 04:51 | 2026-06-27 04:51 |
| GHSA-98X5-VQ43-VC5P | semantic-router exposed to compromised litellm wheel (CVE-2026-42208) via unbounded transitive pin | 严重 | PyPIsemantic-router | 已审查 | 2026-06-27 04:51 | 2026-06-27 04:51 |
| GHSA-M9GH-VJ53-GVH9 CVE-2026-48809 | python-engineio has possible denial of service due to maximum payload size sometimes not being enforced | 高危 | PyPIpython-engineio | 已审查 | 2026-06-27 04:48 | 2026-06-27 04:48 |
| GHSA-22P9-WV53-3RQ4 CVE-2026-48801 | LinkifyIt#match scan loop has quadratic algorithmic complexity | 高危 | npmlinkify-it | 已审查 | 2026-06-27 04:47 | 2026-06-27 04:47 |
| GHSA-57F6-PVX8-HWJ6 CVE-2026-48790 | turso-cli persists Turso platform JWT with world-readable (0o644) file permissions | 中危 | Gogithub.com/tursodatabase/turso-cli | 已审查 | 2026-06-27 04:44 | 2026-06-27 04:44 |
| GHSA-M8J6-RC5X-WV36 | nono-py's policy JSON accepts unknown security fields | 中危 | PyPInono-py | 已审查 | 2026-06-27 04:41 | 2026-06-27 04:41 |
| GHSA-9J7F-3R4P-PWH6 | nono-py vulnerable to authorization bypass / policy confusion | 中危 | PyPInono-py | 已审查 | 2026-06-27 04:39 | 2026-06-27 04:39 |
| GHSA-F65R-H4G3-3H9H CVE-2026-48797 | Backpropagate: backprop ui --auth and backprop ui --share do not enforce authentication | 严重 | npm@mcptoolshop/backpropagate+1 | 已审查 | 2026-06-27 04:34 | 2026-06-27 04:34 |
| GHSA-72W7-MF9G-733P | nono-py has proxy-only network fallback bypass on older Linux kernels | 中危 | PyPInono-py | 已审查 | 2026-06-27 04:33 | 2026-06-27 04:33 |