检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-J9CW-HWQF-85W7 CVE-2026-44160 | Fluentd is Vulnerable to Denial of Service (DoS) via Gzip Decompression Bomb in `in_http` and `in_forward` | 高危 | RubyGemsfluentd | 已审查 | 2026-06-27 00:35 | 2026-06-27 00:35 |
| GHSA-PR7J-96CJ-549H CVE-2026-44025 | Fluentd is Vulnerable to Exposure of Sensitive Information via Monitor Agent API |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 高危 |
RubyGemsfluentd |
| 已审查 |
| 2026-06-27 00:32 |
| 2026-06-27 00:32 |
| GHSA-44HJ-4M45-FRJ3 CVE-2026-44024 | Fluentd is Vulnerable to Remote Code Execution (RCE) via Arbitrary File Write in `${tag}` Placeholder | 严重 | RubyGemsfluentd | 已审查 | 2026-06-27 00:32 | 2026-06-27 00:32 |
| GHSA-PX7Q-GGQJ-HCF2 CVE-2026-53462 | ImageMagick has a Use-After-Free when allocation in CheckPrimitiveExtent fails | 中危 | NuGetMagick.NET-Q16-AnyCPU+16 | 已审查 | 2026-06-27 00:21 | 2026-06-27 00:21 |
| GHSA-R937-WJX7-W2JP CVE-2026-53914 | JetBrains Kotlin: Unsafe Deserialization in Kotlin Build Cache Enables Code Execution | 中危 | Mavenorg.jetbrains.kotlin:kotlin-gradle-plugin | 已审查 | 2026-06-26 23:32 | 2026-08-13 03:25 |
| GHSA-X527-X647-Q7GG CVE-2026-46595 | golang.org/x/crypto: Invoking VerifiedPublicKeyCallback permissions skip enforcement | 严重 | Gogolang.org/x/crypto | 已审查 | 2026-06-26 06:23 | 2026-07-17 23:32 |
| GHSA-5CGQ-3RG8-M6CV CVE-2026-42508 | golang.org/x/crypto vulnerable to auth bypass via unenforced @revoked status | 严重 | Gogolang.org/x/crypto | 已审查 | 2026-06-26 06:22 | 2026-07-17 23:32 |
| GHSA-RM3J-F69W-WQMQ CVE-2026-39834 | golang.org/x/crypto vulnerable to infinite loop on large channel writes | 严重 | Gogolang.org/x/crypto | 已审查 | 2026-06-26 06:21 | 2026-07-07 23:26 |
| GHSA-89GR-R52H-F8RX CVE-2026-39831 | golang.org/x/crypto: FIDO/U2F security key physical presence check can be bypassed | 严重 | Gogolang.org/x/crypto | 已审查 | 2026-06-26 06:21 | 2026-07-07 23:25 |
| GHSA-W879-237Q-WC7R CVE-2026-39829 | golang.org/x/crypto: Invoking pathological RSA/DSA parameters may cause DoS | 高危 | Gogolang.org/x/crypto | 已审查 | 2026-06-26 06:18 | 2026-07-20 20:32 |
| GHSA-VGWF-H737-FF37 CVE-2026-39830 | golang.org/x/crypto: Invoking client can cause server deadlock on unexpected responses | 严重 | Gogolang.org/x/crypto | 已审查 | 2026-06-26 06:18 | 2026-08-31 23:34 |
| GHSA-QPW4-5X99-6VJP CVE-2026-39827 | golang.org/x/crypto: Invoking memory leak when rejecting channels can lead to DoS | 中危 | Gogolang.org/x/crypto | 已审查 | 2026-06-26 06:15 | 2026-07-07 23:24 |
| GHSA-78MQ-XCR3-XM33 CVE-2026-39835 | golang.org/x/crypto is vulnerable to invoking server panic during CheckHostKey/Authenticate flow | 中危 | Gogolang.org/x/crypto | 已审查 | 2026-06-26 06:15 | 2026-09-02 23:34 |
| GHSA-45GG-VH54-H5M9 CVE-2026-39828 | golang.org/x/crypto vulnerable to invoking bypass of certificate restrictions | 中危 | Gogolang.org/x/crypto | 已审查 | 2026-06-26 06:14 | 2026-07-20 20:32 |
| GHSA-Q4H4-GMJ2-QVW2 CVE-2026-46597 | golang.org/x/crypto: Invoking byte arithmetic causes underflow and panic | 高危 | Gogolang.org/x/crypto | 已审查 | 2026-06-26 06:14 | 2026-07-07 23:22 |
| GHSA-F5WC-C3C7-36MC CVE-2026-39832 | golang.org/x/crypto doesn't drop invoking agent constraints when forwarding keys | 严重 | Gogolang.org/x/crypto | 已审查 | 2026-06-26 06:14 | 2026-08-11 23:31 |
| GHSA-JPPX-RXG9-JMRX CVE-2026-39833 | golang.org/x/crypto doesn't enforce invoking key constraints | 严重 | Gogolang.org/x/crypto | 已审查 | 2026-06-26 06:13 | 2026-07-07 23:27 |
| GHSA-9M57-25V3-79X9 CVE-2026-46598 | golang.org/x/crypto: Invoking pathological inputs can lead to client panic | 中危 | Gogolang.org/x/crypto | 已审查 | 2026-06-26 06:12 | 2026-07-07 23:28 |
| GHSA-V2WP-FRMC-5Q3V CVE-2026-55166 | Lemur: ACME SSRF + creator-equality IDOR lead to AWS IAM/PKI compromise | 严重 | PyPIlemur | 已审查 | 2026-06-26 06:07 | 2026-06-26 06:07 |
| GHSA-R9GP-7F88-9R54 CVE-2026-55165 | Lemur: JWT verifier honors attacker-supplied alg, enabling ATO | 中危 | PyPIlemur | 已审查 | 2026-06-26 06:05 | 2026-06-26 06:05 |
| GHSA-Q437-G7FV-2JVV CVE-2026-55164 | Lemur user-update path stores plaintext passwords | 中危 | PyPIlemur | 已审查 | 2026-06-26 06:02 | 2026-06-26 06:02 |
| GHSA-X3VF-MGXJ-7785 CVE-2026-55163 | Lemur Privilege Escalation: Non-admin role members can rewrite role membership via PUT /api/1/roles/<id> | 中危 | PyPIlemur | 已审查 | 2026-06-26 06:01 | 2026-06-26 06:01 |
| GHSA-54VG-PFH7-JQ95 CVE-2026-55162 | Lemur: Crafted CRL/OCSP URLs in uploaded certificates lead to post-authentication SSRF | 中危 | PyPIlemur | 已审查 | 2026-06-26 05:58 | 2026-06-26 05:58 |
| GHSA-G22Q-F7GC-5JHR CVE-2026-53461 | ImageMagick has out-of-bounds write in ICON decoder due to incorrect loop | 高危 | NuGetMagick.NET-Q16-AnyCPU+16 | 已审查 | 2026-06-26 05:54 | 2026-06-26 05:54 |
| GHSA-Q62C-H75R-2XHC CVE-2026-53460 | ImageMagick: Policy Bypass can Trigger an Out-of-Memory condition | 高危 | NuGetMagick.NET-Q16-AnyCPU+16 | 已审查 | 2026-06-26 05:54 | 2026-06-26 05:54 |