检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-GM7F-V959-FR2G CVE-2026-41262 | Fleet DM Vulnerable to Cross-Team Policy Data Exposure via Global Policy Read Endpoint | 中危 | Gogithub.com/fleetdm/fleet/v4 | 已审查 | 2026-06-27 04:30 | 2026-06-27 04:30 |
| GHSA-JQC5-2P7Q-FQFC | Hysteria: http large header with sniff cause server DoS |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 高危 |
Gogithub.com/apernet/hysteria |
| 已审查 |
| 2026-06-27 04:19 |
| 2026-06-27 04:19 |
| GHSA-QH5X-RFWF-RVFV | Hysteria vulnerable to server crash when max_datagram_frame_size very small | 高危 | Gogithub.com/apernet/hysteria | 已审查 | 2026-06-27 03:58 | 2026-06-27 03:58 |
| GHSA-VGRC-HQ28-P3XP | Hysteria has an authenticated UDP ACL bypass that enables localhost and private-network UDP SSRF | 高危 | Gogithub.com/apernet/hysteria/core/v2 | 已审查 | 2026-06-27 03:48 | 2026-06-27 03:48 |
| GHSA-5VWR-QCHF-Q4PF | @cyclonedx/cdxgen: Maven project scanning may allow shell command injection through repository-controlled module paths | 中危 | npm@cyclonedx/cdxgen | 已审查 | 2026-06-27 03:47 | 2026-06-27 03:47 |
| GHSA-4C8J-MGM4-QQVP CVE-2026-48788 | Remark42: Cross-Site Scripting (XSS) on /api/v1/img via content-type spoofing | 高危 | Gogithub.com/umputun/remark42 | 已审查 | 2026-06-27 03:26 | 2026-06-27 03:26 |
| GHSA-CR2J-534F-MF3G CVE-2026-48785 | Apptainer has incorrect path matching for 'limit container paths' directive | 中危 | Gogithub.com/apptainer/apptainer | 已审查 | 2026-06-27 03:20 | 2026-06-27 03:20 |
| GHSA-CG7W-RG45-PC59 CVE-2026-48782 | pydantic-ai: SSRF blocklist bypass via IPv4-compatible, SIIT/IVI, and local NAT64 IPv6 addresses (incomplete fix of CVE-2026-46678) | 中危 | PyPIpydantic-ai+1 | 已审查 | 2026-06-27 03:17 | 2026-06-27 03:17 |
| GHSA-F6M5-XW2G-XC4X CVE-2026-48769 | Incus has an arbitrary file write on its client due to trusted image hash | 严重 | Gogithub.com/lxc/incus/v7/cmd/incusd | 已审查 | 2026-06-27 03:13 | 2026-06-27 03:13 |
| GHSA-JFC7-64V2-MR8C CVE-2026-48758 | @sigstore/core has DSSE payloadType type-binding failure | 中危 | npm@sigstore/core | 已审查 | 2026-06-27 03:11 | 2026-06-27 03:11 |
| GHSA-XHQX-MGH3-3H7Q CVE-2026-48756 | Incus: CreateCustomVolumeFromBackup nil-pointer dereference on volume_snapshots[*].expires_at (sibling-field variant of GHSA-r7w7) | 低危 | Gogithub.com/lxc/incus/v7/cmd/incusd | 已审查 | 2026-06-27 03:07 | 2026-06-27 03:07 |
| GHSA-V6MJ-8PF4-HHW4 CVE-2026-48755 | Incus has an argument injection in backup compression algorithm leading to AFW and ACE | 严重 | Gogithub.com/lxc/incus/v7/cmd/incusd | 已审查 | 2026-06-27 03:03 | 2026-06-27 03:03 |
| GHSA-4XG6-52MH-FPW8 CVE-2026-48754 | Incus: Nil-pointer dereference in createDependentVolumesFromBackup on disk.{Volume,VolumeSnapshots,Pool} | 低危 | Gogithub.com/lxc/incus/v7/cmd/incusd | 已审查 | 2026-06-27 02:52 | 2026-06-27 02:52 |
| GHSA-CCJC-4QC3-JXQC CVE-2026-48753 | Incus has an arbitrary file write via path traversal in S3 multipart upload | 严重 | Gogithub.com/lxc/incus/v7/cmd/incusd | 已审查 | 2026-06-27 02:47 | 2026-06-27 02:47 |
| GHSA-VXP5-584Q-C479 CVE-2026-48752 | Incus has arbitrary file read+write on host via templates/ symlink in malicious image | 严重 | Gogithub.com/lxc/incus/v7/cmd/incusd | 已审查 | 2026-06-27 02:46 | 2026-06-27 02:46 |
| GHSA-JMR9-QJV8-65GV CVE-2026-56876 | extract-zip unvalidated symlink path traversal | 高危 | npmextract-zip | 已审查 | 2026-06-27 02:34 | 2026-08-13 03:22 |
| GHSA-48Q5-W887-33WV CVE-2026-48751 | Incus has a restricted project bypass leading to arbitrary command execution | 严重 | Gogithub.com/lxc/incus/v7/cmd/incusd | 已审查 | 2026-06-27 02:33 | 2026-06-27 02:33 |
| GHSA-73HR-M85F-64V9 CVE-2026-48750 | Incus has an arbitrary file write on host via `exec-output` symlink in crafted image | 严重 | Gogithub.com/lxc/incus/v7/cmd/incusd | 已审查 | 2026-06-27 02:32 | 2026-06-27 02:32 |
| GHSA-2Q3F-Q5PQ-G8WV CVE-2026-48749 | Incus has an arbitrary file read+write on host via rootfs/ symlink in malicious image | 严重 | Gogithub.com/lxc/incus/v7/cmd/incusd | 已审查 | 2026-06-27 02:31 | 2026-06-27 02:31 |
| GHSA-P9RQ-Q46C-G4X6 CVE-2026-53463 | ImageMagick has Null Pointer Dereference caused by the distort operation when passing incorrect arguments | 中危 | NuGetMagick.NET-Q16-AnyCPU+16 | 已审查 | 2026-06-27 01:51 | 2026-06-27 01:51 |
| GHSA-GF57-4MP6-M85X CVE-2026-46623 | OpenAM Account Takeover via Unverified Password Change in OAuth2 Module | 高危 | Mavenorg.openidentityplatform.openam:openam-auth-oauth2 | 已审查 | 2026-06-27 01:33 | 2026-06-27 01:33 |
| GHSA-XQ73-FVMR-JVMM CVE-2026-46619 | OpenAM Authentication Bypass via MSISDN LDAP Injection | 高危 | Mavenorg.openidentityplatform.openam:openam-auth-msisdn | 已审查 | 2026-06-27 01:32 | 2026-06-27 01:32 |
| GHSA-2JC5-XHX8-QJ6H CVE-2026-44163 | fluent-plugin-opentelemetry Has Denial of Service (DoS) via Large Payloads and Decompression Bombs in `in_opentelemetry` | 中危 | RubyGemsfluent-plugin-opentelemetry | 已审查 | 2026-06-27 01:22 | 2026-06-27 01:22 |
| GHSA-XV9W-7V6Q-HPJH CVE-2026-44162 | fluent-plugin-s3 Vulnerable to Denial of Service (DoS) via Decompression Bomb in `in_s3` | 低危 | RubyGemsfluent-plugin-s3 | 已审查 | 2026-06-27 01:02 | 2026-06-27 01:02 |
| GHSA-72F5-RR8C-R6GR CVE-2026-44161 | Fluentd is Vulnerable to Server-Side Request Forgery (SSRF) via Placeholder Expansion in `out_http` | 高危 | RubyGemsfluentd | 已审查 | 2026-06-27 00:36 | 2026-06-27 00:36 |