**GitHub 安全公告(GHSA)** 是針對易受攻擊的開源套件與生態(如 npm、PyPI、Maven)的權威通告,通常關聯 **CVE**。 使用搜尋框尋找 GHSA 或 CVE,依生態或嚴重度篩選,或在摘要中比對片語。
| GHSA | CVE | 嚴重度 | 類型 | 摘要 | 公開時間 |
|---|---|---|---|---|---|
| GHSA-c8xx-jpr5-7m25 | CVE-2026-16266 | medium | unreviewed | Versions of the package mongo-object before 3.0.3 are vulnerable to Prototype Pollution via the... | 2026-07-21 06:31:18 UTC |
| GHSA-x5x7-mh5c-626x | CVE-2026-15901 | unknown | unreviewed | Use after free in Network in Google Chrome prior to 150.0.7871.128 allowed a remote attacker to... | 2026-07-21 00:30:31 UTC |
| GHSA-wwqm-cwjr-9577 | CVE-2026-15903 | unknown | unreviewed | Out of bounds read and write in V8 in Google Chrome prior to 150.0.7871.128 allowed a remote... | 2026-07-21 00:30:31 UTC |
| GHSA-m32c-p2c6-5wh9 | CVE-2026-15902 | unknown | unreviewed | Use after free in Cast in Google Chrome prior to 150.0.7871.128 allowed a remote attacker to... | 2026-07-21 00:30:31 UTC |
| GHSA-j5rv-8p72-245q | CVE-2026-15905 | unknown | unreviewed | Use after free in Aura in Google Chrome prior to 150.0.7871.128 allowed a local attacker to... | 2026-07-21 00:30:31 UTC |
| GHSA-fm68-7vm5-9rgw | CVE-2026-15900 | unknown | unreviewed | Use after free in GPU in Google Chrome on Android prior to 150.0.7871.128 allowed a remote... | 2026-07-21 00:30:31 UTC |
| GHSA-7hhh-6c82-7vf3 | CVE-2026-15904 | unknown | unreviewed | Use after free in Ozone in Google Chrome on Linux prior to 150.0.7871.128 allowed a remote... | 2026-07-21 00:30:31 UTC |
| GHSA-w672-5q29-2fg6 | CVE-2026-15899 | unknown | unreviewed | Use after free in CameraCapture in Google Chrome on Mac prior to 150.0.7871.128 allowed a remote... | 2026-07-21 00:30:30 UTC |
| GHSA-7rc3-g7h6-22m7 | CVE-2026-62685 | high | reviewed | File Browser: Colliding username normalization gives two users the same home directory | 2026-07-20 22:19:10 UTC |
| GHSA-833g-cqhp-h72j | CVE-2026-62684 | low | reviewed | File Browser: Share API exposes the password hash and bypass token | 2026-07-20 22:17:56 UTC |
| GHSA-83xp-526h-j3ww | CVE-2026-62843 | medium | reviewed | File Browser: Archive builder turns backslash filenames into path traversal (zip-slip) | 2026-07-20 22:16:09 UTC |
| GHSA-8wc8-hf36-mjh9 | CVE-2026-55668 | medium | reviewed | File Browser: ScopedFs follows a dangling symlink on write, letting a scoped user create files outside their scope | 2026-07-20 21:17:43 UTC |
| GHSA-fmm7-x4gx-8jhr | CVE-2026-55667 | high | reviewed | File Browser: Out-of-scope file deletion by a Create-only scoped user via symlink-following RemoveAll in upload failure-cleanup | 2026-07-20 21:17:24 UTC |
| GHSA-x756-g4x3-c64m | CVE-2026-54562 | medium | reviewed | Cloudreve: Non-admin remote download users can SSRF loopback/internal services and read imported responses | 2026-07-20 21:16:51 UTC |
| GHSA-vgj4-345g-jcf8 | CVE-2026-54560 | high | reviewed | Cloudreve: OAuth access tokens bypass scope enforcement due to missing client_id claim | 2026-07-20 21:15:20 UTC |
| GHSA-vv59-x63g-cp8m | CVE-2026-13724 | medium | unreviewed | Client-Side Enforcement of Server-Side Security vulnerability in Gobito Informatics Technologies... | 2026-07-20 18:32:31 UTC |
| GHSA-m7pv-37vf-wpvv | CVE-2026-57310 | medium | unreviewed | Windu CMS uses hashing algorithm based on MD5 and SHA1 with static salt to store user passwords.... | 2026-07-20 15:32:07 UTC |
| GHSA-gw59-x2xr-wwvr | CVE-2026-63761 | medium | unreviewed | SurrealDB before 3.1.0 silently substitutes the ES384 algorithm when a JWT access method is... | 2026-07-20 12:33:11 UTC |
| GHSA-mwrx-jx87-85xc | CVE-2026-16219 | low | unreviewed | A flaw has been found in Croogo CMS up to 4.0.7. This affects the function FileManager:... | 2026-07-19 09:31:35 UTC |
| GHSA-48hv-4375-2378 | CVE-2026-16216 | low | unreviewed | A weakness has been identified in geex-arts django-jet up to 1.0.8. Affected is an unknown... | 2026-07-19 06:30:25 UTC |