**GitHub 安全公告(GHSA)** 是針對易受攻擊的開源套件與生態(如 npm、PyPI、Maven)的權威通告,通常關聯 **CVE**。 使用搜尋框尋找 GHSA 或 CVE,依生態或嚴重度篩選,或在摘要中比對片語。
| GHSA | CVE | 嚴重度 | 類型 | 摘要 | 公開時間 |
|---|---|---|---|---|---|
| GHSA-wm9c-mg5f-4mpg | CVE-2026-2395 | critical | unreviewed | Improper neutralization of special elements used in an SQL command ('SQL injection')... | 2026-07-22 15:31:26 UTC |
| GHSA-qhh7-j7w3-xfxq | CVE-2026-11605 | high | unreviewed | The issue is a resource exhaustion vulnerability associated with DNSSEC validation. BIND always... | 2026-07-22 15:31:26 UTC |
| GHSA-jh99-mm75-xrmv | CVE-2026-62145 | high | unreviewed | A vulnerability in Check Point Gaia Portal allows an authenticated attacker with read-only Gaia... | 2026-07-22 15:31:26 UTC |
| GHSA-g5c7-92qw-5486 | CVE-2026-11622 | high | unreviewed | A DNSSEC validating resolver that is under a random subdomain attack against a DNSSEC-signed zone... | 2026-07-22 15:31:26 UTC |
| GHSA-cq66-h8mj-77hh | CVE-2026-11721 | high | unreviewed | It is possible for an attacker's zone to respond to a query with an RRSIG that has a smaller... | 2026-07-22 15:31:26 UTC |
| GHSA-cc7q-gqfw-hrm4 | CVE-2026-12617 | high | unreviewed | The issue is unexpected program termination based on ordering and/or specific content in... | 2026-07-22 15:31:26 UTC |
| GHSA-8p39-mp4q-99c8 | CVE-2026-11331 | high | unreviewed | An attacker who knows (or guesses) that a resolver uses RPZ with wildcard CNAME policies can... | 2026-07-22 15:31:26 UTC |
| GHSA-89q8-qc36-7m58 | CVE-2026-13204 | high | unreviewed | If a provably insecure domain is covered by both an NSEC and NSEC3 record at the parent, and... | 2026-07-22 15:31:26 UTC |
| GHSA-4fw4-hmvf-4www | CVE-2026-10723 | medium | unreviewed | BIND may accept incorrect child-zone NSEC3 records as valid, which could allow an attacker to... | 2026-07-22 15:31:26 UTC |
| GHSA-49wx-869f-rxhj | CVE-2026-14985 | unknown | unreviewed | The Analog Way Picturall Quad Compact Mark II version 3.5.8, contains a local privilege... | 2026-07-22 15:31:26 UTC |
| GHSA-42qr-f5rc-vfw9 | CVE-2026-10822 | medium | unreviewed | If BIND encounters a particular invalid data structure in a DNS record, it will accept the... | 2026-07-22 15:31:26 UTC |
| GHSA-36gp-wrgh-j78w | CVE-2026-13321 | high | unreviewed | The BIND resolver accepts validly-signed NSEC records where the "Next Domain Name" field points... | 2026-07-22 15:31:26 UTC |
| GHSA-x9gf-4mqv-47hw | CVE-2026-56444 | medium | unreviewed | In NLnet Labs Unbound 1.20.0 up to and including 1.25.1, when Unbound is configured with 'serve... | 2026-07-22 15:31:25 UTC |
| GHSA-qg2m-c9gf-4qvp | CVE-2026-62144 | critical | unreviewed | An authentication bypass vulnerability in Check Point Security Management and Multi-Domain... | 2026-07-22 15:31:25 UTC |
| GHSA-j6hj-wvx2-8wqp | CVE-2026-55991 | medium | unreviewed | In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, a remote unauthenticated client can... | 2026-07-22 15:31:25 UTC |
| GHSA-hpr4-88jh-4pvx | CVE-2026-55990 | medium | unreviewed | In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, when the 'dnscrypt:' clause lists more ... | 2026-07-22 15:31:25 UTC |
| GHSA-g479-fg97-pf5w | CVE-2026-55973 | high | unreviewed | In NLnet Labs Unbound 1.23.0 up to and including 1.25.1, when 'dns-error-reporting: yes' is set,... | 2026-07-22 15:31:25 UTC |
| GHSA-9vcf-h83p-jghm | CVE-2026-55717 | medium | unreviewed | In NLnet Labs Unbound 1.10.0 up to and including 1.25.1, when 'serve-expired: yes' is set... | 2026-07-22 15:31:25 UTC |
| GHSA-9pwr-gcwm-8wj5 | CVE-2026-53910 | low | unreviewed | diff3 tool from GNU diffutils is vulnerable to a heap‑based buffer overflow due to multiple... | 2026-07-22 15:31:25 UTC |
| GHSA-2845-97v4-7wm3 | CVE-2026-56416 | medium | unreviewed | In NLnet Labs Unbound up to and including version 1.25.1, when the validator builds the canonical... | 2026-07-22 15:31:25 UTC |