**GitHub 安全公告(GHSA)** 是針對易受攻擊的開源套件與生態(如 npm、PyPI、Maven)的權威通告,通常關聯 **CVE**。 使用搜尋框尋找 GHSA 或 CVE,依生態或嚴重度篩選,或在摘要中比對片語。
| GHSA | CVE | 嚴重度 | 類型 | 摘要 | 公開時間 |
|---|---|---|---|---|---|
| GHSA-395f-4hp3-45gv | CVE-2026-13311 | high | reviewed | shell-quote: Quadratic-complexity Denial of Service in `parse()` (CWE-407) | 2026-07-20 21:49:34 UTC |
| GHSA-c6w9-5g5j-jh2p | CVE-2026-61836 | high | reviewed | Directus: Authorization-dependent response served from unsegmented cache key | 2026-07-20 21:48:15 UTC |
| GHSA-j5h6-vqc3-phqh | CVE-2026-61835 | high | reviewed | Directus: SSRF Protection Bypass via 0.0.0.0 in File Import | 2026-07-20 21:47:17 UTC |
| GHSA-f4vv-55c2-5789 | CVE-2026-61740 | critical | reviewed | LightRAG is Vulnerable to Authentication Bypass: hardcoded DEFAULT_TOKEN_SECRET and public /auth-status defeat LIGHTRAG_API_KEY protection | 2026-07-20 21:46:37 UTC |
| GHSA-94pj-82f3-465w | — | medium | reviewed | Guzzle: Proxy-Authorization headers can be sent to origin servers | 2026-07-20 21:46:02 UTC |
| GHSA-6x6h-qqr7-855w | CVE-2026-61736 | critical | reviewed | LightRAG: CORS Wildcard + Credentials Enables Any-Origin Credentialed Requests | 2026-07-20 21:45:25 UTC |
| GHSA-qfrw-5rxm-mhh2 | CVE-2026-59929 | medium | reviewed | Mistune renderers/html.safe_url: HARMFUL_PROTOCOLS list misses legacy and chained schemes that historically chain to `javascript:` execution | 2026-07-20 21:35:30 UTC |
| GHSA-2hm2-hc3v-44h9 | CVE-2026-59930 | medium | reviewed | Mistune toc / TableOfContents directive: heading IDs use predictable `toc_N` numbering with no slugification, allowing collision with attacker-controlled `id="toc_N"` content | 2026-07-20 21:35:11 UTC |
| GHSA-r4rv-85jg-w4mf | CVE-2026-59924 | medium | reviewed | Mistune: Arbitrary File Read via Include directive path traversal | 2026-07-20 21:34:53 UTC |
| GHSA-c8j7-8cv4-2xmq | CVE-2026-59922 | high | reviewed | Mistune plugins/formatting: quadratic-time parsing on long runs of `~~x~~`, `==x==`, and `^^x^^` markers (strikethrough / mark / insert) | 2026-07-20 21:34:37 UTC |
| GHSA-g97x-gvcm-x72h | CVE-2026-59926 | medium | reviewed | Mistune: XSS via unescaped class option in Admonition directive | 2026-07-20 21:34:14 UTC |
| GHSA-8c25-4j27-2rv3 | CVE-2026-59923 | medium | reviewed | Mistune: XSS via percent-encoded javascript URI bypass in safe_url() | 2026-07-20 21:32:49 UTC |
| GHSA-4j32-57v6-6g45 | CVE-2026-59925 | high | reviewed | Mistune inline_parser: quadratic-time parsing on long runs of `**x**` and `***x***` emphasis pairs | 2026-07-20 21:32:40 UTC |
| GHSA-q57w-g8m3-937c | CVE-2026-56623 | high | unreviewed | Path traversal on Windows in Apache MINA SSHD component sshd-git. Apache MINA SSHD is a Java... | 2026-07-20 21:31:51 UTC |
| GHSA-j262-jh5j-p4fw | CVE-2026-56624 | high | unreviewed | Improper certificate validation in Apache MINA SSHD (server-side). Apache MINA SSHD is a Java... | 2026-07-20 21:31:51 UTC |
| GHSA-7229-w5mh-32hm | CVE-2026-58624 | medium | unreviewed | Improper input validation in sshd-git in Apache MINA SSHD. Apache MINA SSHD is a Java library for... | 2026-07-20 21:31:51 UTC |
| GHSA-2vf2-jm4x-2gj4 | CVE-2026-56452 | high | unreviewed | Path traversal in the sshd-scp component of Apache MINA SSHD. Apache MINA SSHD is a Java library... | 2026-07-20 21:31:51 UTC |
| GHSA-qg8p-5h9q-qwf4 | CVE-2024-51313 | unknown | unreviewed | The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_42EA38 function... | 2026-07-20 21:31:50 UTC |
| GHSA-q7qg-rc6j-fpwp | CVE-2026-64619 | high | unreviewed | FileCodeBox before 2.4 contains a rate-limit bypass vulnerability in the IPRateLimit class that... | 2026-07-20 21:31:50 UTC |
| GHSA-m3gj-74x3-vc94 | CVE-2026-64194 | unknown | unreviewed | Net::DNS versions through 1.55 for Perl allow Denial of Service via deep DNS compression pointer... | 2026-07-20 21:31:50 UTC |