检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-FJQC-HQ36-QH5P CVE-2026-48775 | LangGraph Checkpoint: Unsafe JSON deserialization in checkpoint loading | 中危 | PyPIlanggraph-checkpoint | 已审查 | 2026-06-26 02:25 | 2026-06-26 02:25 |
| GHSA-3FXJ-6JH8-HVHX | chi Has an IP Spoofing Vulnerability in `middleware.RealIP` |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 中危 |
Gogithub.com/go-chi/chi/v5/middleware |
| 已审查 |
| 2026-06-26 02:21 |
| 2026-06-26 02:21 |
| GHSA-RJR7-JGGH-PGCP | chi's RealIP Middleware allows IP spoofing via unvalidated X-Forwarded-For header | 高危 | Gogithub.com/go-chi/chi/middleware+4 | 已审查 | 2026-06-26 02:19 | 2026-06-26 02:19 |
| GHSA-9G5Q-2W5X-HMXF | chi Middleware Vulnerable to Potential IP Spoofing via `X-Forwarded-For` Header in `Request.RemoteAddr` Resolution | 高危 | Gogithub.com/go-chi/chi/middleware+4 | 已审查 | 2026-06-26 02:18 | 2026-06-26 02:18 |
| GHSA-R4V7-6WCG-GHJ5 | FileBrowser: Missing Rate Limiting on Authentication Endpoint Enables Brute Force Attacks | 中危 | Gogithub.com/gtsteffaniak/filebrowser | 已审查 | 2026-06-26 02:18 | 2026-06-26 02:18 |
| GHSA-FQ3W-P4FG-MW73 | fixurjavainstall: Previous Fuji versions can accidentally wipe `/usr/share/man/man8` | 低危 | crates.iofixurjavainstall | 已审查 | 2026-06-26 02:00 | 2026-06-26 02:00 |
| GHSA-WRR4-782V-JHWH | neotoma has tenant isolation gap in relationship query endpoints | 低危 | npmneotoma | 已审查 | 2026-06-26 01:46 | 2026-06-26 01:46 |
| GHSA-JF6W-2MVX-633J | justhtml: to_markdown() code-span blank-line breakout enables XSS | 中危 | PyPIjusthtml | 已审查 | 2026-06-26 01:35 | 2026-06-26 01:35 |
| GHSA-2933-Q333-QG83 CVE-2026-48713 | i18next-fs-backend vulnerable to prototype pollution via crafted missing-key string | 严重 | npmi18next-fs-backend | 已审查 | 2026-06-26 01:28 | 2026-06-26 01:28 |
| GHSA-F49M-VF83-692W CVE-2026-48714 | i18next-http-middleware: MissingKeyHandler does not reject keys whose segments contain prototype-polluting names | 严重 | npmi18next-http-middleware | 已审查 | 2026-06-26 01:28 | 2026-06-26 01:28 |
| GHSA-386J-6M86-78F9 CVE-2026-46560 | OpenAM: Unauthenticated Authentication Bypass via RADIUS Spoofing | 高危 | Mavenorg.openidentityplatform.openam:openam-radius | 已审查 | 2026-06-26 01:22 | 2026-06-26 01:22 |
| GHSA-CJ8F-2FHF-826R CVE-2026-46498 | OpenAM Arbitrary OAuth Token Minting via Push Registration | 高危 | Mavenorg.openidentityplatform.openam:openam-oauth2 | 已审查 | 2026-06-26 01:07 | 2026-06-26 01:07 |
| GHSA-4VP2-6Q8C-PVQ2 CVE-2026-46406 | @anthropic-ai/claude-code has an Insecure Temporary File in /copy Command that Enables Response Disclosure and Symlink-Based File Write | 中危 | npm@anthropic-ai/claude-code | 已审查 | 2026-06-26 00:53 | 2026-06-26 00:53 |
| GHSA-PP89-732F-3G8Q CVE-2026-45794 | OpenAM has Unsafe Java Deserialization via SNS | 高危 | Mavenorg.openidentityplatform.openam:openam-push-notification | 已审查 | 2026-06-26 00:30 | 2026-06-26 00:30 |
| GHSA-7X27-G8RG-X87W CVE-2026-11998 | Angular's deprecated package has a Cross-Site Scripting issue | 高危 | npmangular | 已审查 | 2026-06-25 05:30 | 2026-07-18 05:47 |
| GHSA-PRJ9-97MP-MWH2 CVE-2026-53541 | OliveTin has Unvalidated `ot_`-prefixed Arguments that Bypass Input Filtering | 中危 | Gogithub.com/OliveTin/OliveTin | 已审查 | 2026-06-25 01:43 | 2026-06-25 01:43 |
| GHSA-F637-W7P2-M7FX CVE-2026-48709 | OliveTin: ValidateArgumentType API Endpoint's Missing Authentication Allows Action and Argument Enumeration | 低危 | Gogithub.com/OliveTin/OliveTin | 已审查 | 2026-06-25 01:41 | 2026-06-25 01:41 |
| GHSA-7FQ5-7WR8-RJWJ CVE-2026-48708 | OliveTin has a Concurrent Template Parsing Race Condition which Leads to Cross-Request Command Contamination | 高危 | Gogithub.com/OliveTin/OliveTin | 已审查 | 2026-06-25 01:38 | 2026-07-21 05:32 |
| GHSA-P462-XXWX-PQF4 CVE-2026-45052 | OpenAM Pre-auth User Profile Tampering via Anonymous SOAP Authn in Liberty IDPP/Discovery Endpoints | 严重 | Mavenorg.openidentityplatform.openam:openam-federation-library | 已审查 | 2026-06-25 01:31 | 2026-06-25 01:31 |
| GHSA-6C99-87FR-6Q7R CVE-2026-45051 | OpenAM: Pre-auth RCE via Java Deserialization in WebAuthn Authenticator Storage | 严重 | Mavenorg.openidentityplatform.openam:openam-auth-webauthn | 已审查 | 2026-06-25 01:25 | 2026-06-25 01:25 |
| GHSA-PWPJ-P52H-Q484 CVE-2026-54329 | Snipe-IT API Vulnerable to Cross-Tenant Accessory Injection | 高危 | Packagistsnipe/snipe-it | 已审查 | 2026-06-24 07:12 | 2026-06-24 07:12 |
| GHSA-6MMJ-JHQJ-6C6Q CVE-2026-55542 | Snipe-IT's S3 signature image retrieval lacks authorization before temporary URL | 低危 | Packagistsnipe/snipe-it | 已审查 | 2026-06-24 07:11 | 2026-06-24 07:11 |
| GHSA-X667-R589-43M7 CVE-2026-55519 | Snipe-IT has Improper Authorization in File Deletion (IDOR) | 低危 | Packagistsnipe/snipe-it | 已审查 | 2026-06-24 07:06 | 2026-06-24 07:06 |
| GHSA-HF68-G98V-WP9G CVE-2026-55483 | Snipe-IT Vulnerable to Privilege Escalation via Missing admin Permission Check in User Creation | 中危 | Packagistsnipe/snipe-it | 已审查 | 2026-06-24 07:06 | 2026-06-24 07:06 |
| GHSA-33G4-646G-QWMM CVE-2026-55482 | Snipe-IT has Multi-Tenancy Bypass via Bulk Asset Update | 中危 | Packagistsnipe/snipe-it | 已审查 | 2026-06-24 07:03 | 2026-06-24 07:03 |