
OSV.dev · 实时热榜
- 01CGA-gh3g-24x2-4344 · Chainguard/gitlab-rails-ce-assets-fips-19.0
Affected packages: Chainguard/gitlab-rails-ce-assets-fips-19.0、Chainguard/gitlab-rails-ce-doc-fips-19.0、Chainguard/gitlab-rails-ce-fips-19.0 Attributes: Fix available
最高第 1 名11:35 达到11:35 首次观测上榜15:03 观测离榜累计约3小时28分 - 02DEBIAN-CVE-2026-18477 · Debian:11/tar
Affected packages: Debian:11/tar、Debian:12/tar、Debian:13/tar、Debian:14/tar Attributes: No fix available
最高第 1 名06:15 达到06:15 首次观测上榜14:15 观测离榜累计约8小时 - 03DEBIAN-CVE-2026-64563 · Debian:11/linux
Affected packages: Debian:11/linux、Debian:12/linux、Debian:13/linux、Debian:14/linux Attributes: No fix available
最高第 1 名17:11 达到17:11 首次观测上榜18:31 观测离榜累计约1小时20分 - 04ECHO-94ec-2dbe-8b73 · Echo/tar
Affected packages: Echo/tar Attributes: No fix available
最高第 1 名16:23 达到16:23 首次观测上榜18:31 观测离榜累计约2小时8分 - 05GHSA-22jq-vg5j-6vgg · ip-address: misclassification of IPv4-mapped/NAT64 IPv6 addresses can bypass SSRF and trust-boundary checks
ip-address: misclassification of IPv4-mapped/NAT64 IPv6 addresses can bypass SSRF and trust-boundary checks Affected packages: npm/ip-address Attributes: Fix available、Severity - 6.9 (Medium)
最高第 1 名04:07 达到04:07 首次观测上榜05:43 观测离榜累计约1小时36分 - 06GHSA-2m8v-j782-fhvr · Socket.IO: Zero-attachment Memory Exhaustion
Socket.IO: Zero-attachment Memory Exhaustion Affected packages: npm/socket.io-parser Attributes: Fix available、Severity - 7.5 (High)
最高第 1 名03:19 达到03:19 首次观测上榜04:07 观测离榜累计约48分钟 - 07GHSA-3f7w-8rr8-f37f · GitPython: Unguarded git option forwarding in IndexFile.checkout() and TagReference.create() enables arbitrary file overwrite and arbitrary file read
GitPython: Unguarded git option forwarding in IndexFile.checkout() and TagReference.create() enables arbitrary file overwrite and arbitrary file read Affected packages: PyPI/gitpython Attributes: Fix available、Severity - 8.1 (High)
最高第 1 名04:23 达到04:23 首次观测上榜05:43 观测离榜累计约1小时20分 - 08GHSA-8j4g-w8fx-2239 · Hono: ReDoS in CORS middleware via Access-Control-Request-Headers
Hono: ReDoS in CORS middleware via Access-Control-Request-Headers Affected packages: npm/hono Attributes: Fix available、Severity - 5.3 (Medium)
最高第 1 名04:39 达到04:39 首次观测上榜06:15 观测离榜累计约1小时36分 - 09GHSA-cq5v-8q36-5273 · AIOHTTP: Out-of-bounds heap read in C HTTP response parser error path (malformed chunked response)
AIOHTTP: Out-of-bounds heap read in C HTTP response parser error path (malformed chunked response) Affected packages: PyPI/aiohttp Attributes: Fix available、Severity - 7.1 (High)
最高第 1 名05:11 达到05:11 首次观测上榜06:15 观测离榜累计约1小时4分 - 10GHSA-fxqj-rqcc-2cmp · PostCSS: incomplete fix of GHSA-6g55-p6wh-862q — attacker-controlled sourceMappingURL reads arbitrary .map files when ` from ` is unset
PostCSS: incomplete fix of GHSA-6g55-p6wh-862q — attacker-controlled sourceMappingURL reads arbitrary .map files when ` from ` is unset Affected packages: npm/postcss Attributes: Fix available、Severity - 6.3 (Medium)
最高第 1 名01:27 达到01:27 首次观测上榜03:19 观测离榜累计约1小时52分 - 11GHSA-jhpw-976m-542j · Angular: Cache-Key Ambiguity in HttpTransferCache Leading to Cross-Request Response Reuse and State Poisoning
Angular: Cache-Key Ambiguity in HttpTransferCache Leading to Cross-Request Response Reuse and State Poisoning Affected packages: npm/@angular/common Attributes: Fix available、Severity - 8.8 (High)
最高第 1 名00:23 达到00:23 首次观测上榜03:19 观测离榜累计约2小时56分 - 12GHSA-jj27-h5hq-8x99 · Angular i18n: Cross-Site Scripting (XSS) via event-handler attributes
Angular i18n: Cross-Site Scripting (XSS) via event-handler attributes Affected packages: npm/@angular/compiler、npm/@angular/core Attributes: Fix available、Severity - 7.6 (High)
最高第 1 名00:39 达到00:39 首次观测上榜03:19 观测离榜累计约2小时40分 - 13GHSA-m2h6-j472-rp4c · python-cryptography verifier accepts wildcard DNS names allowing escape from permittedSubtrees
python-cryptography verifier accepts wildcard DNS names allowing escape from permittedSubtrees Affected packages: PyPI/cryptography Attributes: Fix available、Severity - 6.9 (Medium)
最高第 1 名05:43 达到05:43 首次观测上榜14:31 观测离榜上榜 2 次(重入 1 次)累计约4小时48分 - 14GHSA-m65r-rprj-r5rg · Russh: Channel-scoped server callbacks can be reached without an open channel
Russh: Channel-scoped server callbacks can be reached without an open channel Affected packages: crates.io/russh Attributes: Fix available、Severity - 6.5 (Medium)
最高第 1 名00:07 达到00:07 首次观测上榜03:03 观测离榜累计约2小时56分 - 15GHSA-m8rv-5g2x-5cg5 · undici vulnerable to CRLF Injection via blob-like body 'type' property
undici vulnerable to CRLF Injection via blob-like body 'type' property Affected packages: npm/undici Attributes: Fix available、Severity - 4.2 (Medium)
最高第 1 名03:51 达到03:51 首次观测上榜04:07 观测离榜累计约16分钟 - 16GHSA-mq44-7p77-q5h7 · AIOHTTP: WebSocket client accepts compressed frames without negotiated permessage-deflate
AIOHTTP: WebSocket client accepts compressed frames without negotiated permessage-deflate Affected packages: PyPI/aiohttp Attributes: Fix available、Severity - 6.9 (Medium)
最高第 1 名04:55 达到04:55 首次观测上榜06:15 观测离榜累计约1小时20分 - 17GHSA-r745-8hwv-h473 · Flowise: Unauthenticated OAuth2 Refresh Enables Non-Blind SSRF and Secret Exfiltration
Flowise: Unauthenticated OAuth2 Refresh Enables Non-Blind SSRF and Secret Exfiltration Affected packages: npm/flowise Attributes: Fix available、Severity - 8.5 (High)
最高第 1 名22:31 达到22:31 首次观测上榜22:47 观测离榜累计约16分钟 - 18GHSA-rgw5-rvv9-x895 · brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation
brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation Affected packages: npm/brace-expansion Attributes: Fix available、Severity - 7.5 (High)
最高第 1 名00:55 达到00:55 首次观测上榜03:19 观测离榜累计约2小时24分 - 19GHSA-v5mv-p594-2x33 · Guzzle: Noncanonical host can bypass host-based checks
Guzzle: Noncanonical host can bypass host-based checks Affected packages: Packagist/guzzlehttp/guzzle Attributes: Fix available、Severity - 7.2 (High)
最高第 1 名05:27 达到05:27 首次观测上榜06:15 观测离榜累计约48分钟 - 20GHSA-vmv7-4m6c-3cg5 · Flowise: CSV Agent Remote Code Execution via Pyodide Code Injection — Root Shell Verified
Flowise: CSV Agent Remote Code Execution via Pyodide Code Injection — Root Shell Verified Affected packages: npm/flowise、npm/flowise-components Attributes: Fix available、Severity - 9.2 (Critical)
最高第 1 名23:51 达到23:51 首次观测上榜当日结束时仍在榜累计约0分钟 - 21GHSA-wp74-f5hh-5f3r · Flowise: Missing authorization on ` /api/v1/files ` allows low-privileged API keys to list and delete files across workspaces within the same organization
Flowise: Missing authorization on ` /api/v1/files ` allows low-privileged API keys to list and delete files across workspaces within the same organization Affected packages: npm/flowise Attributes: Fix available、Severity - 7.2 (High)
最高第 1 名23:03 达到23:03 首次观测上榜23:35 观测离榜累计约32分钟 - 22JLSEC-2026-1157 · nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1.1 Upgrade request that also carries a...
nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1.1 Upgrade request that also carries a... Affected packages: Julia/nghttp2_jll Attributes: Fix available、Severity - 6.3 (Medium)
最高第 1 名03:35 达到03:35 首次观测上榜04:07 观测离榜累计约32分钟 - 23JLSEC-2026-1162 · Julia/HDF5_jll
Affected packages: Julia/HDF5_jll Attributes: Fix available、Severity - 5.9 (Medium)
最高第 1 名21:43 达到21:43 首次观测上榜22:15 观测离榜累计约32分钟 - 24MAL-2026-11515 · Malicious code in @zzzgenesis00/bip39-generator (npm)
Malicious code in @zzzgenesis00/bip39-generator (npm) Affected packages: npm/@zzzgenesis00/bip39-generator Attributes: No fix available
最高第 1 名13:43 达到13:43 首次观测上榜15:03 观测离榜累计约1小时20分 - 25MAL-2026-11518 · Malicious code in exnesss (npm)
Malicious code in exnesss (npm) Affected packages: npm/exnesss Attributes: No fix available
最高第 1 名17:59 达到17:59 首次观测上榜18:31 观测离榜累计约32分钟 - 26MGASA-2026-0313 · Updated corosync and libqb packages fix security vulnerabilities
Updated corosync and libqb packages fix security vulnerabilities Affected packages: Mageia:10/corosync、Mageia:10/libqb、Mageia:9/corosync、Mageia:9/libqb Attributes: Fix available
最高第 1 名03:03 达到03:03 首次观测上榜03:19 观测离榜累计约16分钟 - 27MINI-2r5h-c9j4-cp8g · MinimOS/ko-fips
Affected packages: MinimOS/ko-fips Attributes: Fix available
最高第 1 名23:35 达到23:35 首次观测上榜当日结束时仍在榜累计约16分钟 - 28MINI-4c4j-7r87-2gqm · MinimOS/apache-iceberg-sink-connector
Affected packages: MinimOS/apache-iceberg-sink-connector Attributes: No fix available
最高第 1 名00:00 达到当日首次采集时已在榜03:03 观测离榜累计约3小时4分 - 29MINI-5qmq-733j-gh5p · MinimOS/uptime-kuma-2.5
Affected packages: MinimOS/uptime-kuma-2.5 Attributes: No fix available
最高第 1 名01:11 达到01:11 首次观测上榜03:19 观测离榜累计约2小时8分 - 30MINI-5x48-m84g-r2rq · MinimOS/gitlab-rails-19.1
Affected packages: MinimOS/gitlab-rails-19.1 Attributes: No fix available
最高第 1 名22:47 达到22:47 首次观测上榜23:03 观测离榜累计约16分钟 - 31MINI-5xhf-388v-457v · MinimOS/tw
Affected packages: MinimOS/tw Attributes: No fix available
最高第 1 名19:19 达到19:19 首次观测上榜20:07 观测离榜累计约48分钟 - 32MINI-6c4p-j525-45g7 · MinimOS/calico-whisker-3.32
Affected packages: MinimOS/calico-whisker-3.32 Attributes: Fix available
最高第 1 名19:51 达到19:51 首次观测上榜20:07 观测离榜累计约16分钟 - 33MINI-7568-cxgx-gc2q · MinimOS/k3s-fips-1.34
Affected packages: MinimOS/k3s-fips-1.34 Attributes: No fix available
最高第 1 名21:27 达到21:27 首次观测上榜21:43 观测离榜累计约16分钟 - 34MINI-9c69-frh7-2296 · MinimOS/gitlab-rails-19.1
Affected packages: MinimOS/gitlab-rails-19.1 Attributes: Fix available
最高第 1 名23:19 达到23:19 首次观测上榜23:35 观测离榜累计约16分钟 - 35MINI-cqjq-525q-2xrf · MinimOS/tailscale-fips
Affected packages: MinimOS/tailscale-fips Attributes: Fix available
最高第 1 名10:15 达到10:15 首次观测上榜15:03 观测离榜累计约4小时48分 - 36MINI-cqqc-w94p-v732 · MinimOS/k3s-1.34
Affected packages: MinimOS/k3s-1.34 Attributes: Fix available
最高第 1 名20:55 达到20:55 首次观测上榜21:11 观测离榜累计约16分钟 - 37MINI-j2c8-gxmw-fjjm · MinimOS/linkerd2-cli-fips
Affected packages: MinimOS/linkerd2-cli-fips Attributes: No fix available
最高第 1 名19:03 达到19:03 首次观测上榜20:07 观测离榜累计约1小时4分 - 38MINI-pvw5-m2v3-492g · MinimOS/docker-scout-1.23
Affected packages: MinimOS/docker-scout-1.23 Attributes: No fix available
最高第 1 名20:23 达到20:23 首次观测上榜20:55 观测离榜累计约32分钟 - 39MINI-qg32-v54g-jjc7 · MinimOS/rancher-agent-fips-2.12
Affected packages: MinimOS/rancher-agent-fips-2.12 Attributes: No fix available
最高第 1 名20:07 达到20:07 首次观测上榜20:23 观测离榜累计约16分钟 - 40MINI-rpcj-pgx6-gm49 · MinimOS/k3s-1.35
Affected packages: MinimOS/k3s-1.35 Attributes: Fix available
最高第 1 名21:11 达到21:11 首次观测上榜21:43 观测离榜累计约32分钟 - 41MINI-w6pv-24r4-6mfm · MinimOS/gitlab-elasticsearch-indexer
Affected packages: MinimOS/gitlab-elasticsearch-indexer、MinimOS/gitlab-elasticsearch-indexer-compat Attributes: Fix available
最高第 1 名22:15 达到22:15 首次观测上榜22:31 观测离榜累计约16分钟 - 42RHSA-2026:49851 · Red Hat Security Advisory: kernel-rt security, bug fix, and enhancement update
Red Hat Security Advisory: kernel-rt security, bug fix, and enhancement update Affected packages: Red Hat:enterprise_linux:8::nfv/kernel-rt、Red Hat:enterprise_linux:8::nfv/kernel-rt-core、Red Hat:enterprise_linux:8::nfv/kernel-rt-debug、Red Hat:enterprise_linux:8::nfv/kernel-rt-debug-core、Red Hat:enterprise_linux:8::nfv/kernel-rt-debug-debuginfo、... 23 more Attributes: Fix available、Severity - 5.8 (Medium)
最高第 1 名18:31 达到18:31 首次观测上榜19:19 观测离榜累计约48分钟 - 43RHSA-2026:49910 · Red Hat Security Advisory: systemd security, bug fix, and enhancement update
Red Hat Security Advisory: systemd security, bug fix, and enhancement update Affected packages: Red Hat:rhel_eus:9.6::appstream/systemd-boot-unsigned、Red Hat:rhel_eus:9.6::appstream/systemd-boot-unsigned-debuginfo、Red Hat:rhel_eus:9.6::appstream/systemd-container-debuginfo、Red Hat:rhel_eus:9.6::appstream/systemd-debuginfo、Red Hat:rhel_eus:9.6::appstream/systemd-debugsource、... 32 more Attributes: Fix available、Severity - 7.8 (High)
最高第 1 名18:47 达到18:47 首次观测上榜20:07 观测离榜累计约1小时20分 - 44RLSA-2023:2771 · Moderate: unbound security and bug fix update
Moderate: unbound security and bug fix update Affected packages: Rocky Linux:8/unbound Attributes: Fix available、Severity - 7.5 (High)
最高第 1 名14:31 达到14:31 首次观测上榜18:31 观测离榜累计约4小时 - 45RLSA-2026:49508 · Important: gstreamer1-plugins-good security update
Important: gstreamer1-plugins-good security update Affected packages: Rocky Linux:10/gstreamer1-plugins-good Attributes: Fix available、Severity - 7.8 (High)
最高第 1 名20:39 达到20:39 首次观测上榜20:55 观测离榜累计约16分钟 - 46CGA-4p4g-gwq9-x2fx · Chainguard/gitlab-rails-ce-assets-fips-19.0
Affected packages: Chainguard/gitlab-rails-ce-assets-fips-19.0、Chainguard/gitlab-rails-ce-doc-fips-19.0、Chainguard/gitlab-rails-ce-fips-19.0 Attributes: Fix available
最高第 2 名11:35 达到11:35 首次观测上榜15:03 观测离榜累计约3小时28分 - 47DEBIAN-CVE-2026-18508 · Debian:11/tar
Affected packages: Debian:11/tar、Debian:12/tar、Debian:13/tar、Debian:14/tar Attributes: No fix available
最高第 2 名06:15 达到06:15 首次观测上榜13:43 观测离榜累计约7小时28分 - 48DEBIAN-CVE-2026-64561 · Debian:11/linux
Affected packages: Debian:11/linux、Debian:12/linux、Debian:13/linux、Debian:14/linux Attributes: No fix available
最高第 2 名17:11 达到17:11 首次观测上榜18:31 观测离榜累计约1小时20分 - 49ECHO-b8d2-238f-d46b · Echo/tar
Affected packages: Echo/tar Attributes: No fix available
最高第 2 名16:23 达到16:23 首次观测上榜18:31 观测离榜累计约2小时8分 - 50GHSA-2364-jh4q-m9vm · Flowise: IDOR vulnerability exists at the GET /api/v1/organization/customer-default-source endpoint
Flowise: IDOR vulnerability exists at the GET /api/v1/organization/customer-default-source endpoint Affected packages: npm/flowise Attributes: Fix available、Severity - 6.0 (Medium)
最高第 2 名22:31 达到22:31 首次观测上榜22:47 观测离榜累计约16分钟


































































































