
OSV.dev · 实时热榜
- 01DEBIAN-CVE-2026-59679 · Debian:11/libxfont
Affected packages: Debian:11/libxfont、Debian:12/libxfont、Debian:13/libxfont、Debian:14/libxfont Attributes: No fix available
最高第 1 名14:05 达到14:05 首次观测上榜15:25 观测离榜累计约1小时20分 - 02DEBIAN-CVE-2026-67592 · Debian:11/qpid-proton
Affected packages: Debian:11/qpid-proton、Debian:12/qpid-proton、Debian:13/qpid-proton、Debian:14/qpid-proton Attributes: No fix available
最高第 1 名19:09 达到19:09 首次观测上榜20:45 观测离榜累计约1小时36分 - 03GHSA-3xpf-xq7r-v8c5 · Open WebUI: Same-origin XSS to account takeover via terminal file-preview iframe hardcoding allow-same-origin
Open WebUI: Same-origin XSS to account takeover via terminal file-preview iframe hardcoding allow-same-origin Affected packages: PyPI/open-webui Attributes: Fix available、Severity - 8.2 (High)
最高第 1 名04:23 达到04:23 首次观测上榜05:27 观测离榜累计约1小时4分 - 04GHSA-4wx2-7gvj-qfq3 · Ghost: Archived Offers can be Redeemed
Ghost: Archived Offers can be Redeemed Affected packages: npm/ghost Attributes: Fix available、Severity - 4.8 (Medium)
最高第 1 名05:27 达到05:27 首次观测上榜07:19 观测离榜上榜 2 次(重入 1 次)累计约1小时4分 - 05GHSA-52fh-8v99-63c2 · Flowise: Pyodide validator Unicode homoglyph bypass leads to RCE
Flowise: Pyodide validator Unicode homoglyph bypass leads to RCE Affected packages: npm/flowise、npm/flowise-components Attributes: Fix available、Severity - 9.5 (Critical)
最高第 1 名01:59 达到01:59 首次观测上榜04:07 观测离榜累计约2小时8分 - 06GHSA-6vh2-wg4h-4vwj · Flowise: Unauthenticated Property Injection into Flow Execution Context via Ungated ` overrideConfig ` Spread in Prediction API
Flowise: Unauthenticated Property Injection into Flow Execution Context via Ungated ` overrideConfig ` Spread in Prediction API Affected packages: npm/flowise Attributes: Fix available、Severity - 8.8 (High)
最高第 1 名00:07 达到00:07 首次观测上榜03:35 观测离榜累计约3小时28分 - 07GHSA-73cq-mcgh-379c · Open WebUI: Instance-wide stall via automation recurrence rules that force multi-second parsing
Open WebUI: Instance-wide stall via automation recurrence rules that force multi-second parsing Affected packages: PyPI/open-webui Attributes: Fix available、Severity - 6.5 (Medium)
最高第 1 名04:55 达到04:55 首次观测上榜05:59 观测离榜累计约1小时4分 - 08GHSA-cj62-hvv2-2q5h · Ghost: Database Backup Path Traversal
Ghost: Database Backup Path Traversal Affected packages: npm/ghost Attributes: Fix available、Severity - 5.5 (Medium)
最高第 1 名05:59 达到05:59 首次观测上榜07:19 观测离榜累计约1小时20分 - 09GHSA-g366-23fw-ggp6 · Ghost: Mobiledoc image-size fetch SSRF
Ghost: Mobiledoc image-size fetch SSRF Affected packages: npm/ghost Attributes: Fix available、Severity - 5.4 (Medium)
最高第 1 名05:43 达到05:43 首次观测上榜07:19 观测离榜累计约1小时36分 - 10GHSA-g423-grf7-98rv · Open WebUI: Users denied the image-generation permission can still generate images via chat completions
Open WebUI: Users denied the image-generation permission can still generate images via chat completions Affected packages: PyPI/open-webui Attributes: Fix available、Severity - 4.3 (Medium)
最高第 1 名04:07 达到04:07 首次观测上榜05:27 观测离榜累计约1小时20分 - 11GHSA-gmmw-qg98-6j6p · Flowise: Broken Access Control in Stripe Subscription Endpoints Allows Cross-Tenant Billing Manipulation
Flowise: Broken Access Control in Stripe Subscription Endpoints Allows Cross-Tenant Billing Manipulation Affected packages: npm/flowise Attributes: Fix available、Severity - 8.3 (High)
最高第 1 名03:35 达到03:35 首次观测上榜04:55 观测离榜累计约1小时20分 - 12GHSA-jx35-x7fj-vgpr · Ghost Content API filter bypass reveals private fields
Ghost Content API filter bypass reveals private fields Affected packages: npm/ghost Attributes: Fix available、Severity - 5.3 (Medium)
最高第 1 名22:53 达到22:53 首次观测上榜23:57 观测离榜累计约1小时4分 - 13GHSA-p5w8-m249-4r4v · Flowise: ` DELETE /api/v1/chatflows/:id ` does not validate resource type, allowing ` agentflows:delete ` and ` chatflows:delete ` to delete each other’s flow type
Flowise: ` DELETE /api/v1/chatflows/:id ` does not validate resource type, allowing ` agentflows:delete ` and ` chatflows:delete ` to delete each other’s flow type Affected packages: npm/flowise Attributes: Fix available、Severity - 7.1 (High)
最高第 1 名01:11 达到01:11 首次观测上榜03:51 观测离榜累计约2小时40分 - 14GHSA-pfmc-3mgc-p6fp · Electron: Off-screen rendering trusts GPU-supplied geometry over shared-memory size
Electron: Off-screen rendering trusts GPU-supplied geometry over shared-memory size Affected packages: npm/electron Attributes: Fix available、Severity - 3.9 (Low)
最高第 1 名23:41 达到23:41 首次观测上榜当日结束时仍在榜累计约16分钟 - 15GHSA-pwxh-7358-jq2x · Open WebUI: Stored XSS via unescaped KaTeX render-error fallback in rendered messages
Open WebUI: Stored XSS via unescaped KaTeX render-error fallback in rendered messages Affected packages: PyPI/open-webui Attributes: Fix available、Severity - 8.7 (High)
最高第 1 名05:11 达到05:11 首次观测上榜06:15 观测离榜累计约1小时4分 - 16GHSA-vmv7-4m6c-3cg5 · Flowise: CSV Agent Remote Code Execution via Pyodide Code Injection — Root Shell Verified
Flowise: CSV Agent Remote Code Execution via Pyodide Code Injection — Root Shell Verified Affected packages: npm/flowise、npm/flowise-components Attributes: Fix available、Severity - 9.2 (Critical)
最高第 1 名00:00 达到当日首次采集时已在榜02:15 观测离榜累计约2小时16分 - 17GHSA-w2rx-84hp-gg95 · Open WebUI: SSRF into internal services via unvalidated sub-resource requests in the Playwright web loader
Open WebUI: SSRF into internal services via unvalidated sub-resource requests in the Playwright web loader Affected packages: PyPI/open-webui Attributes: Fix available、Severity - 7.7 (High)
最高第 1 名03:51 达到03:51 首次观测上榜04:55 观测离榜累计约1小时4分 - 18GHSA-wch5-xp77-fxg4 · Flowise: Cross-Workspace OAuth2 Credential Metadata Leak
Flowise: Cross-Workspace OAuth2 Credential Metadata Leak Affected packages: npm/flowise Attributes: Fix available、Severity - 7.6 (High)
最高第 1 名02:15 达到02:15 首次观测上榜04:07 观测离榜累计约1小时52分 - 19GHSA-x3hf-7cj6-3r4m · Flowise RCE via SQLite Record Manager Node
Flowise RCE via SQLite Record Manager Node Affected packages: npm/flowise、npm/flowise-components Attributes: Fix available、Severity - 9.4 (Critical)
最高第 1 名00:23 达到00:23 首次观测上榜03:35 观测离榜累计约3小时12分 - 20GHSA-x8rc-wpg4-grpf · Electron: Cross-origin iframe can position native autofill popup
Electron: Cross-origin iframe can position native autofill popup Affected packages: npm/electron Attributes: Fix available、Severity - 3.1 (Low)
最高第 1 名23:57 达到23:57 首次观测上榜当日结束时仍在榜累计约0分钟 - 21GHSA-xc48-889x-5qmw · Flowise: CVE-2025-8943 Patch Bypass: npm_config_yes bypasses MCP environment variable blocklist (Unauthenticated RCE)
Flowise: CVE-2025-8943 Patch Bypass: npm_config_yes bypasses MCP environment variable blocklist (Unauthenticated RCE) Affected packages: npm/flowise、npm/flowise-components Attributes: Fix available、Severity - 8.7 (High)
最高第 1 名01:27 达到01:27 首次观测上榜03:51 观测离榜累计约2小时24分 - 22GHSA-xm43-3m56-w3wf · Ghost: Paid gift memberships obtainable at minimal cost via the donations feature
Ghost: Paid gift memberships obtainable at minimal cost via the donations feature Affected packages: npm/ghost Attributes: Fix available、Severity - 5.3 (Medium)
最高第 1 名06:15 达到06:15 首次观测上榜07:19 观测离榜累计约1小时4分 - 23MAL-2026-11530 · Malicious code in @zzzgenesis00/etherjs (npm)
Malicious code in @zzzgenesis00/etherjs (npm) Affected packages: npm/@zzzgenesis00/etherjs Attributes: No fix available
最高第 1 名07:19 达到07:19 首次观测上榜08:55 观测离榜累计约1小时36分 - 24MAL-2026-12038 · Malicious code in bigops-customer (npm)
Malicious code in bigops-customer (npm) Affected packages: npm/bigops-customer Attributes: No fix available
最高第 1 名09:59 达到09:59 首次观测上榜10:15 观测离榜累计约16分钟 - 25MAL-2026-12056 · Malicious code in @zzzgenesis00/mnemonic-to-key (npm)
Malicious code in @zzzgenesis00/mnemonic-to-key (npm) Affected packages: npm/@zzzgenesis00/mnemonic-to-key Attributes: No fix available
最高第 1 名11:25 达到11:25 首次观测上榜15:25 观测离榜累计约4小时 - 26MAL-2026-12104 · Malicious code in @wethenorth12/test-fresh (npm)
Malicious code in @wethenorth12/test-fresh (npm) Affected packages: npm/@wethenorth12/test-fresh Attributes: No fix available
最高第 1 名15:25 达到15:25 首次观测上榜16:45 观测离榜累计约1小时20分 - 27MAL-2026-12225 · Malicious code in time-utils-helper (npm)
Malicious code in time-utils-helper (npm) Affected packages: npm/time-utils-helper Attributes: No fix available
最高第 1 名18:21 达到18:21 首次观测上榜18:53 观测离榜累计约32分钟 - 28MAL-2026-12310 · Malicious code in statist-browser-typed-client-sme.platform.web.teasers (npm)
Malicious code in statist-browser-typed-client-sme.platform.web.teasers (npm) Affected packages: npm/statist-browser-typed-client-sme.platform.web.teasers Attributes: No fix available
最高第 1 名20:45 达到20:45 首次观测上榜21:49 观测离榜累计约1小时4分 - 29MAL-2026-12484 · Malicious code in trailserver (npm)
Malicious code in trailserver (npm) Affected packages: npm/trailserver Attributes: No fix available
最高第 1 名21:49 达到21:49 首次观测上榜22:37 观测离榜累计约48分钟 - 30MAL-2026-12515 · Malicious code in bpm-foundation-test-jest (npm)
Malicious code in bpm-foundation-test-jest (npm) Affected packages: npm/bpm-foundation-test-jest Attributes: No fix available
最高第 1 名22:37 达到22:37 首次观测上榜23:57 观测离榜累计约1小时20分 - 31MGASA-2026-0321 · Updated acl attr packages fix security vulnerabilities
Updated acl attr packages fix security vulnerabilities Affected packages: Mageia:10/acl、Mageia:10/attr、Mageia:9/acl、Mageia:9/attr Attributes: Fix available
最高第 1 名01:43 达到01:43 首次观测上榜04:07 观测离榜累计约2小时24分 - 32MINI-239w-wv4f-px8c · MinimOS/datahub-frontend-react-fips
Affected packages: MinimOS/datahub-frontend-react-fips Attributes: Fix available
最高第 1 名10:15 达到10:15 首次观测上榜11:25 观测离榜累计约1小时10分 - 33MINI-4r5r-6rgc-vvr5 · MinimOS/rancher-machine
Affected packages: MinimOS/rancher-machine Attributes: No fix available
最高第 1 名17:01 达到17:01 首次观测上榜17:33 观测离榜累计约32分钟 - 34MINI-4xf7-5cpv-mf2v · MinimOS/calico-3.29-apiserver-compat-fips
Affected packages: MinimOS/calico-3.29-apiserver-compat-fips、MinimOS/calico-3.29-apiserver-fips、MinimOS/calico-3.29-app-policy-fips、MinimOS/calico-3.29-calicoctl-fips、MinimOS/calico-3.29-cni-compat-fips、... 10 more Attributes: No fix available
最高第 1 名22:21 达到22:21 首次观测上榜22:37 观测离榜累计约16分钟 - 35MINI-54gr-qf55-g8qm · MinimOS/strimzi-kafka-operator-1.0-kafka-thirdparty-libs-cc
Affected packages: MinimOS/strimzi-kafka-operator-1.0-kafka-thirdparty-libs-cc Attributes: No fix available
最高第 1 名17:33 达到17:33 首次观测上榜18:21 观测离榜累计约48分钟 - 36MINI-6q24-jvh2-3jpg · MinimOS/tomcat-fips-11.0
Affected packages: MinimOS/tomcat-fips-11.0 Attributes: Fix available
最高第 1 名17:17 达到17:17 首次观测上榜18:21 观测离榜累计约1小时4分 - 37MINI-cgfv-j7p6-r7jc · MinimOS/rancher-fleet-agent-fips-0.12
Affected packages: MinimOS/rancher-fleet-agent-fips-0.12 Attributes: Fix available
最高第 1 名16:45 达到16:45 首次观测上榜17:01 观测离榜累计约16分钟 - 38MINI-f764-5hrx-hg8v · MinimOS/glibc-2.39
Affected packages: MinimOS/glibc-2.39、MinimOS/glibc-2.39-dev、MinimOS/glibc-2.39-iconv、MinimOS/glibc-2.39-ld-linux、MinimOS/glibc-2.39-libc-bin、... 11 more Attributes: Fix available
最高第 1 名20:13 达到20:13 首次观测上榜20:45 观测离榜累计约32分钟 - 39MINI-wq49-jx89-j4r7 · MinimOS/strimzi-kafka-operator-fips-1.0-cluster-operator
Affected packages: MinimOS/strimzi-kafka-operator-fips-1.0-cluster-operator Attributes: No fix available
最高第 1 名19:25 达到19:25 首次观测上榜20:45 观测离榜累计约1小时20分 - 40RHSA-2026:9098 · Red Hat Security Advisory: skopeo security update
Red Hat Security Advisory: skopeo security update Affected packages: Red Hat:rhel_eus:9.6::appstream/skopeo、Red Hat:rhel_eus:9.6::appstream/skopeo-debuginfo、Red Hat:rhel_eus:9.6::appstream/skopeo-debugsource、Red Hat:rhel_eus:9.6::appstream/skopeo-tests Attributes: Fix available、Severity - 7.5 (High)
最高第 1 名18:53 达到18:53 首次观测上榜20:45 观测离榜累计约1小时52分 - 41RXSA-2026:49857 · Moderate: kernel security, bug fix, and enhancement update
Moderate: kernel security, bug fix, and enhancement update Affected packages: Rocky Linux:8/kernel Attributes: Fix available、Severity - 5.8 (Medium)
最高第 1 名08:39 达到08:39 首次观测上榜09:59 观测离榜累计约1小时20分 - 42RXSA-2026:49870 · Low: kernel security, bug fix, and enhancement update
Low: kernel security, bug fix, and enhancement update Affected packages: Rocky Linux:9/kernel Attributes: Fix available、Severity - 5.5 (Medium)
最高第 1 名02:31 达到02:31 首次观测上榜04:23 观测离榜累计约1小时52分 - 43DEBIAN-CVE-2026-44950 · Debian:11/libxfont
Affected packages: Debian:11/libxfont、Debian:12/libxfont、Debian:13/libxfont、Debian:14/libxfont Attributes: No fix available
最高第 2 名14:05 达到14:05 首次观测上榜15:25 观测离榜累计约1小时20分 - 44DEBIAN-CVE-2026-67591 · Debian:11/qpid-proton
Affected packages: Debian:11/qpid-proton、Debian:12/qpid-proton、Debian:13/qpid-proton、Debian:14/qpid-proton Attributes: No fix available
最高第 2 名19:09 达到19:09 首次观测上榜20:45 观测离榜累计约1小时36分 - 45GHSA-3r7g-q6cg-q2vx · Open WebUI: Tool source code disclosed to read-only users via the tool list and get endpoints
Open WebUI: Tool source code disclosed to read-only users via the tool list and get endpoints Affected packages: PyPI/open-webui Attributes: Fix available、Severity - 6.5 (Medium)
最高第 2 名05:11 达到05:11 首次观测上榜05:59 观测离榜累计约48分钟 - 46GHSA-8gj2-2cvc-6xx7 · Flowise: Unauthenticated Credential Abuse via Text-to-Speech Endpoint Allows Unauthorized Use of Private Chatflow TTS Credentials
Flowise: Unauthenticated Credential Abuse via Text-to-Speech Endpoint Allows Unauthorized Use of Private Chatflow TTS Credentials Affected packages: npm/flowise Attributes: Fix available、Severity - 6.3 (Medium)
最高第 2 名03:35 达到03:35 首次观测上榜04:23 观测离榜累计约48分钟 - 47GHSA-8x5v-cpv7-8jjp · Open WebUI: Any authenticated user can reach internal services and cloud metadata via NAT64-encoded URLs
Open WebUI: Any authenticated user can reach internal services and cloud metadata via NAT64-encoded URLs Affected packages: PyPI/open-webui Attributes: Fix available、Severity - 7.1 (High)
最高第 2 名04:23 达到04:23 首次观测上榜05:27 观测离榜累计约1小时4分 - 48GHSA-944x-pm95-3jpr · Ghost: File Upload Content-Type Spoofing
Ghost: File Upload Content-Type Spoofing Affected packages: npm/ghost Attributes: Fix available、Severity - 5.4 (Medium)
最高第 2 名05:27 达到05:27 首次观测上榜06:15 观测离榜累计约48分钟 - 49GHSA-9pf5-hg6p-4pwp · Electron: Permission Check Handler Receives Main Frame Origin Instead of Requesting Iframe Origin
Electron: Permission Check Handler Receives Main Frame Origin Instead of Requesting Iframe Origin Affected packages: npm/electron Attributes: Fix available、Severity - 5.9 (Medium)
最高第 2 名23:57 达到23:57 首次观测上榜当日结束时仍在榜累计约0分钟 - 50GHSA-c6xh-wv4j-ppv5 · Flowise: SSRF Protection Bypass via IPv4-Mapped IPv6 Addresses
Flowise: SSRF Protection Bypass via IPv4-Mapped IPv6 Addresses Affected packages: npm/flowise Attributes: Fix available、Severity - 7.6 (High)
最高第 2 名00:07 达到00:07 首次观测上榜03:35 观测离榜累计约3小时28分


































































































