GitHub Security Advisories

GitHub Security Advisories(GHSA)は、npm・PyPI・Maven などのオープンソース向けエコシステムで影響を受けるパッケージに対する正式な注意喚起で、多くの場合 CVE とリンクされています。 検索ボックスで GHSA や CVE を探し、エコシステムや深刻度で絞り込むか、概要文にフレーズ一致させます。

表示中 141160 / 2473 アドバイザリ
GHSA CVE 深刻度 タイプ 概要 公開
GHSA-9v66-88c9-pqcg CVE-2026-14429 high unreviewed Insufficient validation of untrusted input in Skia in Google Chrome prior to 150.0.7871.46... 2026-07-02 00:31:42 UTC
GHSA-2wv3-7v49-h6mj CVE-2026-14414 medium unreviewed Insufficient validation of untrusted input in Skia in Google Chrome prior to 150.0.7871.46... 2026-07-02 00:31:42 UTC
GHSA-gm8p-g47w-pwgf CVE-2026-14412 high unreviewed Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.46... 2026-07-02 00:31:41 UTC
GHSA-8jr8-cv4x-4jmv CVE-2026-14411 critical unreviewed Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.46... 2026-07-02 00:31:41 UTC
GHSA-7fh8-qj6w-5vcc CVE-2026-14382 critical unreviewed Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.46... 2026-07-02 00:31:41 UTC
GHSA-3x3p-qx4r-hmgh CVE-2026-14401 high unreviewed Insufficient validation of untrusted input in ANGLE in Google Chrome on Android prior to 150.0... 2026-07-02 00:31:41 UTC
GHSA-whwg-vh4f-pmmf CVE-2026-49997 medium reviewed SurrealDB: Edge PERMISSIONS FOR delete bypassed when a connected node is deleted 2026-07-01 20:23:49 UTC
GHSA-fwg2-gr34-q3w8 medium reviewed SurrealDB: ES512 silently downgraded to ES384 due to jsonwebtoken crate limitation 2026-07-01 20:23:01 UTC
GHSA-c8jx-96c9-8xrp medium reviewed SurrealDB: Field-level SELECT permissions bypassed via indexed COUNT fast paths 2026-07-01 20:22:06 UTC
GHSA-wp87-mgvq-5j93 medium reviewed SurrealDB: USE NS/DB implicit creation bypasses DEFINE authorization 2026-07-01 20:21:25 UTC
GHSA-97vg-427p-8hx5 medium reviewed SurrealDB: Port-specific --deny-net rules silently bypassed on HTTP redirect 2026-07-01 20:20:40 UTC
GHSA-6wqw-vhfr-9999 medium reviewed SurrealDB: Authenticated subscribers can read records hidden by SELECT permissions via LIVE subscriptions 2026-07-01 20:20:00 UTC
GHSA-f82j-v89j-mf86 medium reviewed SurrealDB: `RELATE` overwrites existing edge records without `UPDATE` permission 2026-07-01 20:19:17 UTC
GHSA-fpxg-5xmv-922m medium reviewed SurrealDB has bypass of field-level SELECT permissions through JSON Patch `copy` and `move` with empty `from` 2026-07-01 20:18:06 UTC
GHSA-6g9v-7gq3-p2c6 medium reviewed SurrealDB: Authenticated callers can read fields hidden by field-level SELECT permissions via error messages 2026-07-01 20:16:52 UTC
GHSA-4m82-p8cx-f94j medium reviewed SurrealDB: LIVE query subscriptions survive session state changes, bypassing access controls 2026-07-01 20:16:12 UTC
GHSA-65rj-r9fh-jp2v medium reviewed SurrealDB vulnerable to pre-auth memory amplification via unbounded `/sql` WebSocket frames 2026-07-01 20:15:03 UTC
GHSA-gcwr-5mrf-fvch medium reviewed SurrealDB: Authorization Bypass in KILL Statement Allows Termination of Other Users' Live Queries 2026-07-01 20:14:20 UTC
GHSA-4v76-cw68-4vc9 medium reviewed SurrealDB: Crafting malicious LIVE queries writes to the database, resulting in DoS, without permission to the table required 2026-07-01 20:13:37 UTC
GHSA-6vg3-hgrw-p5gf medium reviewed SurrealDB has an Authorization Bypass via Composite Record-id Paths 2026-07-01 20:12:25 UTC
cvelogic Threat Intelligence