GitHub Security Advisories(GHSA)は、npm・PyPI・Maven などのオープンソース向けエコシステムで影響を受けるパッケージに対する正式な注意喚起で、多くの場合 CVE とリンクされています。 検索ボックスで GHSA や CVE を探し、エコシステムや深刻度で絞り込むか、概要文にフレーズ一致させます。
| GHSA | CVE | 深刻度 | タイプ | 概要 | 公開 |
|---|---|---|---|---|---|
| GHSA-35rm-7j9c-2f7m | CVE-2026-53600 | medium | reviewed | async-tar PAX extension-header desync enables tar entry/content smuggling | 2026-07-08 20:24:12 UTC |
| GHSA-qhhg-cg26-g7r4 | CVE-2026-15063 | medium | unreviewed | A flaw was found in the gorch service template, which is part of the trustyai-service-operator.... | 2026-07-08 18:31:35 UTC |
| GHSA-569j-6vhh-8mc3 | CVE-2026-15044 | medium | unreviewed | A flaw was found in the TrustyAI Service Operator. When deploying services like gorch or... | 2026-07-08 15:32:02 UTC |
| GHSA-x6hw-8x39-wcwp | CVE-2026-57258 | medium | unreviewed | The PRC file header parsing logic trusts the constructed file structure description information,... | 2026-07-08 09:31:52 UTC |
| GHSA-cwv4-h3j5-w3cf | — | low | reviewed | rama has Stored XSS in ServeDir HTML directory listing via unescaped file names and URI path | 2026-07-07 23:41:12 UTC |
| GHSA-4w5h-hx6r-28q7 | CVE-2026-53531 | medium | reviewed | ratex-parser has unbounded parser recursion that leads to stack overflow (process abort) | 2026-07-07 23:39:30 UTC |
| GHSA-4hgp-59h5-gvrj | CVE-2026-53530 | high | reviewed | ratex-parser panics on `\verb` with a multibyte delimiter (UTF-8 byte-boundary slice) | 2026-07-07 23:39:12 UTC |
| GHSA-fqf6-gxhh-2xhw | — | high | reviewed | uutils coreutils: cp/install/mv/ln --suffix alone does not enable backup mode (silent data loss vs GNU) | 2026-07-07 19:36:17 UTC |
| GHSA-pmfc-4wjj-gmhx | CVE-2026-35381 | low | reviewed | cut: -s ignored in -z -d '' newline-delimiter mode | 2026-07-06 21:54:29 UTC |
| GHSA-r9hw-mj3w-phcq | CVE-2026-35361 | low | reviewed | mknod: Device nodes created mislabeled on SELinux, with broken cleanup (remove_dir on a node) | 2026-07-06 21:54:05 UTC |
| GHSA-pmf6-rcx4-v53v | CVE-2026-35341 | high | reviewed | mkfifo: permissions of an existing file are changed after FIFO creation fails | 2026-07-06 21:53:34 UTC |
| GHSA-ww9q-8r59-xv46 | CVE-2026-54496 | critical | reviewed | Zebra: Missing copy constraint in halo2_gadgets variable-base scalar multiplication allows under-constrained base, breaking Orchard Action circuit soundness | 2026-07-06 21:23:41 UTC |
| GHSA-5g4w-3vw9-478w | CVE-2026-55430 | medium | reviewed | Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access | 2026-07-06 21:05:31 UTC |
| GHSA-p7h3-7q52-72w8 | CVE-2026-35366 | medium | reviewed | printenv: environment variables with invalid UTF-8 are silently skipped (evades inspection) | 2026-07-06 20:25:42 UTC |
| GHSA-w6xc-g9qj-vp32 | CVE-2026-35362 | low | reviewed | uucore: safe_traversal TOCTOU protection only enabled on Linux | 2026-07-06 20:25:15 UTC |
| GHSA-h444-6j9x-p8vh | CVE-2026-35365 | medium | reviewed | mv: symlinks expanded during cross-device move (resource exhaustion / data duplication) | 2026-07-06 20:24:53 UTC |
| GHSA-8vrf-r662-2w2v | CVE-2026-35358 | medium | reviewed | cp: -R reads device nodes as streams, destroying device semantics | 2026-07-06 20:21:18 UTC |
| GHSA-89p7-7cq3-hhr2 | CVE-2026-35363 | medium | reviewed | rm: 'rm -rf ./' (and ./// variants) silently deletes current directory contents, bypassing dot protection | 2026-07-06 20:20:56 UTC |
| GHSA-3wfc-mgpm-9rq6 | CVE-2026-35347 | medium | reviewed | comm: FIFO/pipe inputs are drained before comparison (data loss / hang) | 2026-07-06 20:17:59 UTC |
| GHSA-47c7-qrm7-mqw7 | CVE-2026-35370 | medium | reviewed | id: groups= computed from real GID instead of effective GID | 2026-07-06 20:16:46 UTC |