**GitHub 安全公告(GHSA)** 是針對易受攻擊的開源套件與生態(如 npm、PyPI、Maven)的權威通告,通常關聯 **CVE**。 使用搜尋框尋找 GHSA 或 CVE,依生態或嚴重度篩選,或在摘要中比對片語。
| GHSA | CVE | 嚴重度 | 類型 | 摘要 | 公開時間 |
|---|---|---|---|---|---|
| GHSA-j8qw-6jw8-r297 | CVE-2026-59943 | medium | reviewed | Dompdf: Embedded SVG images can leak existence of files and directories within the filesystem | 2026-07-22 22:52:44 UTC |
| GHSA-f5gf-2cj8-52g2 | CVE-2026-59942 | medium | reviewed | Dompdf: Denial of Service (DoS) via Resource Exhaustion using Oversized Image Bitmaps | 2026-07-22 22:51:40 UTC |
| GHSA-8hg6-c449-896m | CVE-2026-59941 | medium | reviewed | Dompdf: Uncontrolled resource consumption based on declared BMP dimensions | 2026-07-22 22:50:34 UTC |
| GHSA-cx96-42px-69fm | CVE-2026-56722 | medium | reviewed | Dompdf: Local file read due to improper file path validation in SVG images encoded as data-URI | 2026-07-22 21:30:01 UTC |
| GHSA-7x2p-4jvh-6384 | CVE-2026-55555 | low | reviewed | Dompdf: File existence oracle via font-face stylesheet declaration | 2026-07-22 21:07:07 UTC |
| GHSA-wvh6-f5jh-8gw4 | CVE-2026-55554 | low | reviewed | Dompdf: Chroot Validation Bypass | 2026-07-22 21:06:48 UTC |
| GHSA-c2w2-prh8-qm98 | CVE-2026-59882 | medium | reviewed | guzzlehttp/psr7: Host Confusion via Weak URI Host Validation | 2026-07-21 18:35:25 UTC |
| GHSA-h95v-h523-3mw8 | — | medium | reviewed | Guzzle: URI fragments disclosed in redirect Referer headers | 2026-07-20 23:28:36 UTC |
| GHSA-wm3w-8rrp-j577 | — | medium | reviewed | Guzzle: Host-only cookie scope is not preserved | 2026-07-20 23:27:49 UTC |
| GHSA-f283-ghqc-fg79 | — | medium | reviewed | Guzzle: Unbounded response cookies risk denial of service | 2026-07-20 23:27:02 UTC |
| GHSA-g446-98w2-8p5w | CVE-2026-59883 | medium | reviewed | Guzzle: Cookie Disclosure and Injection via IP-Address Domains | 2026-07-20 22:00:09 UTC |
| GHSA-gjfg-22fp-rrxx | CVE-2026-59946 | medium | reviewed | Composer: Path traversal in package bin field lets dependencies chmod arbitrary host files | 2026-07-20 21:57:40 UTC |
| GHSA-g6xq-892h-64w3 | CVE-2026-59947 | medium | reviewed | Composer: URL-embedded HTTP-Basic username leaks to verbose logs (GitHub PAT exposure) | 2026-07-20 21:55:05 UTC |
| GHSA-94pj-82f3-465w | — | medium | reviewed | Guzzle: Proxy-Authorization headers can be sent to origin servers | 2026-07-20 21:46:02 UTC |
| GHSA-499r-g7pc-vmp9 | CVE-2026-59948 | high | reviewed | Composer: Arbitrary file write outside vendor via malicious transitive package name | 2026-07-20 19:15:29 UTC |
| GHSA-cvpc-hccg-wmw4 | — | medium | reviewed | Formie: Missing authorization in administrative settings allows low-privileged CP users to modify plugin configuration | 2026-07-17 19:05:57 UTC |
| GHSA-8qw8-rq86-9pc2 | CVE-2026-27771 | high | reviewed | Gitea has insufficient permission checks for Composer package source links | 2026-07-17 19:04:37 UTC |
| GHSA-p4h7-p9rj-2pq2 | CVE-2026-55579 | critical | reviewed | Pheditor: Hardcoded default password 'admin' with no forced change enables full application compromise | 2026-07-16 20:11:23 UTC |
| GHSA-wg4w-wr5q-6vjc | CVE-2026-55578 | high | reviewed | Pheditor: Incomplete command sanitization in terminal feature allows RCE via pipe operator, backtick substitution, and newline injection | 2026-07-16 20:10:47 UTC |
| GHSA-9643-6xjp-vx57 | CVE-2026-54540 | high | reviewed | Pheditor has an authenticated terminal command whitelist bypass | 2026-07-16 20:01:05 UTC |