检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-VF76-F5CP-9846 | Duplicate Advisory: ReDoS in nltk.tgrep via unvalidated user-supplied regular expressions 已撤回 | 高危 | PyPInltk | 已审查 | 2026-09-01 05:31 | 2026-09-02 22:49 |
当前筛选结果 998 条 · 时间按北京时间显示
Duplicate Advisory: Nodemailer: Message-level raw option bypasses disableFileAccess/disableUrlAccess, enabling arbitrary file read and full-response SSRF in the delivered message 已撤回 |
| 高危 |
npmnodemailer |
| 已审查 |
| 2026-08-31 17:30 |
| 2026-09-02 22:47 |
| GHSA-PF76-Q698-37V8 | Duplicate Advisory: Uncontrolled recursion in nltk.featstruct.FeatStructReader causes unhandled RecursionError (DoS) via deeply nested feature-structure input 已撤回 | 中危 | PyPInltk | 已审查 | 2026-08-28 02:32 | 2026-09-02 22:33 |
| GHSA-HQJ7-PHWP-C3FP | Duplicate Advisory: Model-artifact APIs bypass pathsec and touch files outside allowed roots 已撤回 | 高危 | PyPInltk | 已审查 | 2026-08-28 02:32 | 2026-09-02 22:34 |
| GHSA-4XW3-JF9X-X7MF | Duplicate Advisory: Downloader.download follows hardlinks and overwrites outside-root files 已撤回 | 中危 | PyPInltk | 已审查 | 2026-08-28 02:32 | 2026-09-02 22:35 |
| GHSA-3M7F-6HXV-6796 | Duplicate Advisory: Pl196xCorpusReader has quadratic ReDoS on malformed TEI blocks 已撤回 | 中危 | PyPInltk | 已审查 | 2026-08-28 02:32 | 2026-09-02 22:49 |
| GHSA-HQV3-XM29-P9HQ | Duplicate Advisory: Quadratic CPU Exhaustion in `XMLCorpusView._read_xml_fragment()` 已撤回 | 中危 | PyPInltk | 已审查 | 2026-08-28 02:32 | 2026-09-02 22:34 |
| GHSA-8X48-8G7J-RQXP | Duplicate Advisory: Quadratic-time DoS in PorterStemmer via long runs of 'y' 已撤回 | 高危 | PyPInltk | 已审查 | 2026-08-28 02:32 | 2026-09-02 22:36 |
| GHSA-XQQH-3W52-Q8P7 | Duplicate Advisory: Nokogiri does not check the return value from xmlC14NExecute 已撤回 | 中危 | RubyGemsnokogiri | 已审查 | 2026-08-26 02:31 | 2026-09-02 22:42 |
| GHSA-W5Q8-6JPP-4246 | Duplicate Advisory: Corpus readers follow symlinks outside trusted roots despite pathsec enforcement 已撤回 | 高危 | PyPInltk | 已审查 | 2026-08-26 02:31 | 2026-09-02 22:49 |
| GHSA-RH9X-7XJC-VWX2 | Duplicate Advisory: Nokogiri XSLT transform has a memory leak 已撤回 | 中危 | RubyGemsnokogiri | 已审查 | 2026-08-26 02:31 | 2026-09-02 22:42 |
| GHSA-RCW8-9QRW-27M2 | Duplicate Advisory: NLTK: Corpus Reader Sandbox Bypass 已撤回 | 高危 | PyPInltk | 已审查 | 2026-08-26 02:31 | 2026-09-02 22:48 |
| GHSA-5JHF-FPP7-V2PV | Duplicate Advisory: Nokogiri CSS selector tokenizer has regular expression backtracking 已撤回 | 高危 | RubyGemsnokogiri | 已审查 | 2026-08-26 02:31 | 2026-09-02 22:43 |
| GHSA-3H2G-J4WP-7QQQ | Duplicate Advisory: JVM argument injection bypass via per-call options in the NLTK Stanford wrappers (incomplete fix of CVE-2026-12841) 已撤回 | 严重 | PyPInltk | 已审查 | 2026-08-26 02:31 | 2026-09-02 04:38 |
| GHSA-VP9C-2PJM-8925 | Duplicate Advisory: Allowlisted pickle loaders still permit code execution in current source 已撤回 | 严重 | PyPInltk | 已审查 | 2026-08-25 20:31 | 2026-09-02 22:41 |
| GHSA-JX89-3QG8-P2MR | Duplicate Advisory: Entity-expansion DoS (billion laughs) via remaining raw ElementTree parses (CWE-776) 已撤回 | 高危 | PyPInltk | 已审查 | 2026-08-25 11:32 | 2026-09-02 22:39 |
| GHSA-GX65-C5HJ-VPV5 | Duplicate Advisory: [CWE-502] Unsafe Pickle Deserialization in TransitionParser Allows Remote Code Execution 已撤回 | 严重 | PyPInltk | 已审查 | 2026-08-25 11:32 | 2026-09-02 22:40 |
| GHSA-CRP9-R7RQ-C8CG | Duplicate Advisory: pathsec SSRF protection can be bypassed when a proxy is configured 已撤回 | 高危 | PyPInltk | 已审查 | 2026-08-25 11:32 | 2026-09-02 22:40 |
| GHSA-54XP-3WW7-6WJG | Duplicate Advisory: Uncontrolled search path when invoking the Graphviz 'dot' binary (CWE-426/CWE-427) 已撤回 | 高危 | PyPInltk | 已审查 | 2026-08-25 11:32 | 2026-09-02 04:25 |
| GHSA-892M-GCQ8-2468 | Duplicate Advisory: Uncontrolled recursion DoS in JustHTML() via deeply nested HTML 已撤回 | 高危 | PyPIjusthtml | 已审查 | 2026-08-23 23:33 | 2026-08-26 00:40 |
| GHSA-8H9M-22MV-QV5R | Duplicate Advisory: Symlink escape in CorpusReader allows arbitrary local file read outside the corpus root 已撤回 | 高危 | PyPInltk | 已审查 | 2026-08-22 23:31 | 2026-09-02 22:48 |
| GHSA-QQ3H-CGJ8-W3FX | Duplicate Advisory: Symlink-based sandbox bypass in FramenetCorpusReader (bypasses the fix for CVE-2026-54292) 已撤回 | 高危 | PyPInltk | 已审查 | 2026-08-22 23:31 | 2026-09-02 22:47 |
| GHSA-QG9P-XRHJ-435M | Duplicate Advisory: nltk: SSRF Fail-Open in validate_network_url() via DNS Resolution Failure 已撤回 | 中危 | PyPInltk | 已审查 | 2026-08-22 23:31 | 2026-09-02 23:38 |
| GHSA-CV2G-M8RR-888C | Duplicate Advisory: Natural Language Toolkit (NLTK) has unbounded recursion in JSONTaggedDecoder.decode_obj() may cause DoS 已撤回 | 高危 | PyPInltk | 已审查 | 2026-08-22 23:31 | 2026-09-02 23:33 |
| GHSA-8W48-H75V-CXPV | Duplicate Advisory: Security Report: StreamBackedCorpusView Bypasses pathsec.ENFORCE - Arbitrary Local File Read 已撤回 | 高危 | PyPInltk | 已审查 | 2026-08-22 23:31 | 2026-09-02 22:48 |