检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-XCJM-WQFF-M669 CVE-2026-49219 | ImageMagick: Policy Bypass can read disallowed files via symlink | 中危 | NuGetMagick.NET-Q16-AnyCPU+16 | 已审查 | 2026-06-26 05:53 | 2026-06-26 05:53 |
当前筛选结果 35,190 条 · 时间按北京时间显示
ImageMagick: Policy Bypass in DCM decoder could result in image with invalid dimensions |
| 高危 |
NuGetMagick.NET-Q16-AnyCPU+16 |
| 已审查 |
| 2026-06-26 05:52 |
| 2026-06-26 05:52 |
| GHSA-4V89-6MGQ-6RGC CVE-2026-48994 | ImageMagick has a Heap Buffer Over-Write in MAT decoder on 32-bit systems | 中危 | NuGetMagick.NET-Q16-AnyCPU+16 | 已审查 | 2026-06-26 05:50 | 2026-06-26 05:50 |
| GHSA-H36C-3666-H489 CVE-2026-48734 | ImageMagick Vulnerable to Stack Overflow in its MVG Decoder | 中危 | NuGetMagick.NET-Q16-AnyCPU+16 | 已审查 | 2026-06-26 05:49 | 2026-06-26 05:50 |
| GHSA-5V62-8FQ6-CP9M CVE-2026-48733 | ImageMagick has an Infinite Loop in subimage-search with crafted image | 中危 | NuGetMagick.NET-Q16-AnyCPU+16 | 已审查 | 2026-06-26 05:48 | 2026-06-26 05:48 |
| GHSA-2HHQ-C99X-492R CVE-2026-48724 | ImageMagick has a Heap Buffer Underwrite in the Floyd-Steinberg depth dithering method | 中危 | NuGetMagick.NET-Q16-AnyCPU+16 | 已审查 | 2026-06-26 05:46 | 2026-06-26 05:46 |
| GHSA-92QF-FCPH-V5WR CVE-2026-48722 | nextflow auth login command has incorrect default permissions | 中危 | Mavenio.nextflow:nextflow | 已审查 | 2026-06-26 05:45 | 2026-06-26 05:45 |
| GHSA-47Q9-M4WW-924M CVE-2026-48702 | Rekor has an OOM Condition due to Unbounded gzip Decompression in Alpine APK Parsing Logic | 高危 | Gogithub.com/sigstore/rekor | 已审查 | 2026-06-26 05:33 | 2026-06-26 05:33 |
| GHSA-PJP5-FPMR-3349 CVE-2026-48529 | GitHub MCP Server: Lockdown mode singleton in HTTP server causes cross-user GraphQL client confusion | 中危 | Gogithub.com/github/github-mcp-server | 已审查 | 2026-06-26 05:32 | 2026-06-26 05:32 |
| GHSA-QHMF-XW27-6RQR CVE-2026-48517 | MessagePack-CSharp: Typeless deserialization type restrictions do not recurse into arrays or generic arguments | 中危 | NuGetMessagePack | 已审查 | 2026-06-26 05:31 | 2026-06-26 05:31 |
| GHSA-Q2H6-GHWM-5QM8 CVE-2026-48516 | MessagePack-CSharp: InterfaceLookupFormatter bypasses collision-resistant comparer settings | 中危 | NuGetMessagePack | 已审查 | 2026-06-26 05:29 | 2026-06-26 05:29 |
| GHSA-CXMJ-83GH-FP49 CVE-2026-48515 | MessagePack-CSharp: Multi-dimensional array formatters allocate from unchecked dimensions | 中危 | NuGetMessagePack | 已审查 | 2026-06-26 05:26 | 2026-06-26 05:26 |
| GHSA-W567-GJR2-HM5J CVE-2026-48514 | MessagePack-CSharp: Unity unsafe blit formatter allocates from unbounded byte length | 中危 | NuGetMessagePack | 已审查 | 2026-06-26 05:25 | 2026-06-26 05:25 |
| GHSA-WFR3-XJ75-PFWH CVE-2026-48513 | MessagePack-CSharp: DynamicUnionResolver-generated deserializers miss depth enforcement | 中危 | NuGetMessagePack | 已审查 | 2026-06-26 05:22 | 2026-06-26 05:22 |
| GHSA-CJ9G-3MJ2-G8VV CVE-2026-48512 | MessagePack-CSharp: JSON conversion APIs can recurse without consistent depth enforcement | 中危 | NuGetMessagePack | 已审查 | 2026-06-26 03:51 | 2026-06-26 03:51 |
| GHSA-2X83-8G95-XH59 CVE-2026-48511 | MessagePack-CSharp: ExpandoObject formatter can perform quadratic insertion work on untrusted maps | 中危 | NuGetMessagePack | 已审查 | 2026-06-26 03:36 | 2026-06-26 03:36 |
| GHSA-V72X-2H86-7F8M CVE-2026-48510 | MessagePack-CSharp: LZ4 decompression allocates from unbounded declared output lengths | 中危 | NuGetMessagePack | 已审查 | 2026-06-26 02:53 | 2026-06-26 02:53 |
| GHSA-2F33-PR97-265Q CVE-2026-48509 | MessagePack-CSharp: ASP.NET Core MessagePackInputFormatter defaults to TrustedData for HTTP request bodies | 中危 | NuGetMessagePack | 已审查 | 2026-06-26 02:52 | 2026-06-26 02:52 |
| GHSA-QCQW-JWXC-2HQG CVE-2026-48508 | Lemur has an authorization bypass in StrictRolePermission / AuthorityCreatorPermission | 高危 | PyPIlemur | 已审查 | 2026-06-26 02:48 | 2026-06-26 02:48 |
| GHSA-VH6J-JC39-FGGF CVE-2026-48506 | MessagePack-CSharp: MessagePackReader.Skip can recurse without enforcing maximum object graph depth | 高危 | NuGetMessagePack | 已审查 | 2026-06-26 02:46 | 2026-06-26 02:46 |
| GHSA-MC5J-F6WX-H9QH CVE-2026-48505 | Filament: Multi-factor authentication (app) recovery codes can still be used multiple times via concurrent submission | 高危 | Packagistfilament/filament | 已审查 | 2026-06-26 02:45 | 2026-06-26 02:45 |
| GHSA-W9WP-H8WV-79JX CVE-2026-48504 | opentelemetry_sdk has unbounded memory allocation in W3C Baggage propagation | 中危 | crates.ioopentelemetry_sdk | 已审查 | 2026-06-26 02:40 | 2026-06-26 02:40 |
| GHSA-382J-8MXH-C7X2 CVE-2026-48502 | MessagePack-CSharp: Denial of service vulnerabilities can swamp the CPU or crash the process with stack and heap overflows | 高危 | NuGetMessagePack | 已审查 | 2026-06-26 02:35 | 2026-06-26 02:35 |
| GHSA-G697-2XRC-GC46 CVE-2026-9291 | amazon-braket-sdk vulnerable to Insecure Deserialization via pickle.loads() | 高危 | PyPIamazon-braket-sdk | 已审查 | 2026-06-26 02:34 | 2026-06-26 02:34 |
| GHSA-W39P-VH2G-G8G5 CVE-2026-48776 | LangGraph SDK has unsafe URL path construction | 中危 | PyPIlanggraph-sdk | 已审查 | 2026-06-26 02:32 | 2026-07-21 23:03 |