
OSV.dev · 实时热榜
- 01EEF-CVE-2026-66885 · Livebook Teams identity callback lacks state binding, allowing login CSRF
Livebook Teams identity callback lacks state binding, allowing login CSRF Affected packages: Hex/livebook、github.com/livebook-dev/livebook Attributes: Fix available、Severity - 6.8 (Medium)
最高第 1 名03:57 达到03:57 首次观测上榜05:17 观测离榜累计约1小时20分 - 02EEF-CVE-2026-68750 · Quadratic sibling re-flattening in the html_sanitize_ex traversal engine allows CPU-exhaustion denial of service
Quadratic sibling re-flattening in the html_sanitize_ex traversal engine allows CPU-exhaustion denial of service Affected packages: Hex/html_sanitize_ex、github.com/rrrene/html_sanitize_ex Attributes: Fix available、Severity - 8.2 (High)
最高第 1 名23:15 达到23:15 首次观测上榜当日结束时仍在榜累计约32分钟 - 03GHSA-279x-mwfv-vcqv · Unauthenticated Nuxt DevTools RPC allows arbitrary command execution on the developer's host
Unauthenticated Nuxt DevTools RPC allows arbitrary command execution on the developer's host Affected packages: npm/@nuxt/devtools Attributes: Fix available、Severity - 9.6 (Critical)
最高第 1 名05:33 达到05:33 首次观测上榜08:45 观测离榜累计约3小时12分 - 04GHSA-42cj-m3vj-89wv · Traefik CRD IngressRouteTCP ServersTransport Cross-Provider Namespace Bypass
Traefik CRD IngressRouteTCP ServersTransport Cross-Provider Namespace Bypass Affected packages: Go/github.com/traefik/traefik/v3 Attributes: Fix available、Severity - 5.3 (Medium)
最高第 1 名06:05 达到06:05 首次观测上榜08:45 观测离榜累计约2小时40分 - 05GHSA-7p4m-qxvv-g567 · rclone: Local Encoding Path Traversal
rclone: Local Encoding Path Traversal Affected packages: Go/github.com/rclone/rclone Attributes: Fix available、Severity - 6.9 (Medium)
最高第 1 名05:01 达到05:01 首次观测上榜06:21 观测离榜累计约1小时20分 - 06GHSA-945v-v9p3-v5xw · rclone local ` --metadata ` applies attacker-controlled mode/uid - setuid binary planted from an untrusted remote
rclone local ` --metadata ` applies attacker-controlled mode/uid - setuid binary planted from an untrusted remote Affected packages: Go/github.com/rclone/rclone Attributes: Fix available、Severity - 3.6 (Low)
最高第 1 名04:29 达到04:29 首次观测上榜05:17 观测离榜累计约48分钟 - 07GHSA-9f4c-93c8-jc8g · Electron: Sandboxed iframe can bypass the allow-popups restriction via the OpenURL navigation path
Electron: Sandboxed iframe can bypass the allow-popups restriction via the OpenURL navigation path Affected packages: npm/electron Attributes: Fix available、Severity - 7.2 (High)
最高第 1 名01:33 达到01:33 首次观测上榜03:25 观测离榜累计约1小时52分 - 08GHSA-ff2p-hmqr-hxm4 · Electron: contextBridge object copy honors prototype setters
Electron: contextBridge object copy honors prototype setters Affected packages: npm/electron Attributes: Fix available、Severity - 5.4 (Medium)
最高第 1 名01:49 达到01:49 首次观测上榜03:25 观测离榜累计约1小时36分 - 09GHSA-fqj9-69pf-6pjg · rclone ` serve restic --private-repos ` authorization bypass: ` .. ` in the URL path lets an authenticated user read, overwrite and delete other users' repositories
rclone ` serve restic --private-repos ` authorization bypass: ` .. ` in the URL path lets an authenticated user read, overwrite and delete other users' repositories Affected packages: Go/github.com/rclone/rclone Attributes: Fix available、Severity - 8.8 (High)
最高第 1 名04:45 达到04:45 首次观测上榜06:21 观测离榜累计约1小时36分 - 10GHSA-m55f-7gqj-fr98 · Electron: Extension tab APIs operate across session boundaries
Electron: Extension tab APIs operate across session boundaries Affected packages: npm/electron Attributes: Fix available、Severity - 6.6 (Medium)
最高第 1 名00:13 达到00:13 首次观测上榜02:05 观测离榜累计约1小时52分 - 11GHSA-p2rr-rvmm-c5fp · Electron: Sandboxed iframes can launch external protocol handlers
Electron: Sandboxed iframes can launch external protocol handlers Affected packages: npm/electron Attributes: Fix available、Severity - 5.4 (Medium)
最高第 1 名02:05 达到02:05 首次观测上榜03:57 观测离榜累计约1小时52分 - 12GHSA-r4w5-6pfg-jxp5 · Electron: ProtocolResponse.url reuses the default session cache instead of the registering session
Electron: ProtocolResponse.url reuses the default session cache instead of the registering session Affected packages: npm/electron Attributes: Fix available、Severity - 5.9 (Medium)
最高第 1 名00:29 达到00:29 首次观测上榜02:21 观测离榜累计约1小时52分 - 13GHSA-v93f-fgjr-hjrj · Electron: window.open features string controls some window options considered privileged
Electron: window.open features string controls some window options considered privileged Affected packages: npm/electron Attributes: Fix available、Severity - 5.3 (Medium)
最高第 1 名00:45 达到00:45 首次观测上榜02:37 观测离榜累计约1小时52分 - 14GHSA-x8rc-wpg4-grpf · Electron: Cross-origin iframe can position native autofill popup
Electron: Cross-origin iframe can position native autofill popup Affected packages: npm/electron Attributes: Fix available、Severity - 3.1 (Low)
最高第 1 名00:00 达到当日首次采集时已在榜00:45 观测离榜累计约46分钟 - 15JLSEC-2026-1164 · Deno: ` fetch() ` API sandbox bypass via missing DNS resolution check
Deno: ` fetch() ` API sandbox bypass via missing DNS resolution check Affected packages: Julia/Deno_jll Attributes: Fix available、Severity - 5.2 (Medium)
最高第 1 名02:37 达到02:37 首次观测上榜04:45 观测离榜累计约2小时8分 - 16JLSEC-2026-1168 · GMP has an integer overflow with crafted inputs on 32-bit builds in ` int_raw.c ` , leading to buffer overflow
GMP has an integer overflow with crafted inputs on 32-bit builds in ` int_raw.c ` , leading to buffer overflow Affected packages: Julia/GCCBootstrap_jll、Julia/GMP_jll、Julia/LibStdCxx_jll Attributes: Fix available、Severity - 7.5 (High)
最高第 1 名05:17 达到05:17 首次观测上榜08:45 观测离榜累计约3小时28分 - 17MAL-2026-13370 · Malicious code in llm-interceptor (npm)
Malicious code in llm-interceptor (npm) Affected packages: npm/llm-interceptor Attributes: No fix available
最高第 1 名03:25 达到03:25 首次观测上榜04:45 观测离榜累计约1小时20分 - 18MAL-2026-13380 · Malicious code in uncrypt (PyPI)
Malicious code in uncrypt (PyPI) Affected packages: PyPI/uncrypt Attributes: No fix available
最高第 1 名06:53 达到06:53 首次观测上榜08:45 观测离榜累计约1小时52分 - 19MAL-2026-13386 · Malicious code in decapod-common (PyPI)
Malicious code in decapod-common (PyPI) Affected packages: PyPI/decapod-common Attributes: No fix available
最高第 1 名15:41 达到15:41 首次观测上榜16:45 观测离榜累计约1小时4分 - 20MAL-2026-13393 · Malicious code in wallet-monitor-snap (npm)
Malicious code in wallet-monitor-snap (npm) Affected packages: npm/wallet-monitor-snap Attributes: No fix available
最高第 1 名20:35 达到20:35 首次观测上榜21:55 观测离榜累计约1小时20分 - 21MAL-2026-13400 · Malicious code in agenttunnels (npm)
Malicious code in agenttunnels (npm) Affected packages: npm/agenttunnels Attributes: No fix available
最高第 1 名21:39 达到21:39 首次观测上榜22:27 观测离榜累计约48分钟 - 22MAL-2026-13419 · Malicious code in @holocronlab/botruntime-runtime (npm)
Malicious code in @holocronlab/botruntime-runtime (npm) Affected packages: npm/@holocronlab/botruntime-runtime Attributes: No fix available
最高第 1 名22:43 达到22:43 首次观测上榜23:47 观测离榜累计约1小时4分 - 23MINI-292j-93mg-c5vm · MinimOS/opensearch-3
Affected packages: MinimOS/opensearch-3、MinimOS/opensearch-3-alerting、MinimOS/opensearch-3-anomaly-detection、MinimOS/opensearch-3-crypto-kms、MinimOS/opensearch-3-discovery-ec2、... 11 more Attributes: Fix available
最高第 1 名10:05 达到10:05 首次观测上榜13:17 观测离榜累计约3小时12分 - 24MINI-2rmr-9cpg-6243 · MinimOS/portainer-ce-2.39
Affected packages: MinimOS/portainer-ce-2.39 Attributes: Fix available
最高第 1 名22:27 达到22:27 首次观测上榜22:43 观测离榜累计约16分钟 - 25MINI-5xfc-qf8m-mg3g · MinimOS/gnutar
Affected packages: MinimOS/gnutar、MinimOS/gnutar-doc、MinimOS/gnutar-rmt、MinimOS/tar Attributes: Fix available
最高第 1 名20:51 达到20:51 首次观测上榜21:55 观测离榜累计约1小时4分 - 26MINI-f632-6jhm-593p · MinimOS/py3.10-pip-base
Affected packages: MinimOS/py3.10-pip-base、MinimOS/py3.11-pip-base、MinimOS/py3.12-pip-base、MinimOS/py3.13-pip-base、MinimOS/py3.14-pip-base Attributes: Fix available
最高第 1 名21:07 达到21:07 首次观测上榜22:27 观测离榜累计约1小时20分 - 27MINI-m7hm-39h3-6jgv · MinimOS/teleport-18
Affected packages: MinimOS/teleport-18 Attributes: Fix available
最高第 1 名16:45 达到16:45 首次观测上榜17:33 观测离榜累计约48分钟 - 28RLSA-2026:50142 · Important: sg3_utils security, bug fix, and enhancement update
Important: sg3_utils security, bug fix, and enhancement update Affected packages: Rocky Linux:10/sg3_utils Attributes: Fix available、Severity - 7.6 (High)
最高第 1 名08:45 达到08:45 首次观测上榜13:17 观测离榜累计约4小时32分 - 29ROOT-OS-ALPINE-318-CVE-2026-40200 · CVE-2026-40200 in musl - Patched by Root
CVE-2026-40200 in musl - Patched by Root Affected packages: Root:Alpine:3.18/musl、Root:Alpine:3.18/rootio-musl Attributes: Fix available、Severity - 7.8 (High)
最高第 1 名15:25 达到15:25 首次观测上榜16:45 观测离榜累计约1小时20分 - 30ROOT-OS-DEBIAN-12-CVE-2004-0230 · CVE-2004-0230 in linux - Patched by Root
CVE-2004-0230 in linux - Patched by Root Affected packages: Root:Debian:12/linux、Root:Debian:12/rootio-linux Attributes: Fix available
最高第 1 名13:17 达到13:17 首次观测上榜16:45 观测离榜累计约3小时28分 - 31RUSTSEC-2026-0236 · A ` BigInt ` division panics, and two neighbouring operations answer wrongly in silence
A ` BigInt ` division panics, and two neighbouring operations answer wrongly in silence Affected packages: crates.io/viperjs Attributes: Fix available、Severity - 7.5 (High)
最高第 1 名17:17 达到17:17 首次观测上榜21:39 观测离榜累计约4小时22分 - 32DEBIAN-CVE-2026-64589 · Debian:13/linux
Affected packages: Debian:13/linux、Debian:14/linux Attributes: Fix available
最高第 2 名18:05 达到18:05 首次观测上榜18:59 观测离榜累计约54分钟 - 33EEF-CVE-2026-66298 · JS-view sandboxed output can synthesize keyboard events to trigger unconfirmed global shortcuts
JS-view sandboxed output can synthesize keyboard events to trigger unconfirmed global shortcuts Affected packages: Hex/livebook、github.com/livebook-dev/livebook Attributes: Fix available、Severity - 8.6 (High)
最高第 2 名03:57 达到03:57 首次观测上榜05:01 观测离榜累计约1小时4分 - 34EEF-CVE-2026-68749 · Quadratic regex backtracking in the html_sanitize_ex CSS scrubber allows CPU-exhaustion denial of service
Quadratic regex backtracking in the html_sanitize_ex CSS scrubber allows CPU-exhaustion denial of service Affected packages: Hex/html_sanitize_ex、github.com/rrrene/html_sanitize_ex Attributes: Fix available、Severity - 8.2 (High)
最高第 2 名23:15 达到23:15 首次观测上榜当日结束时仍在榜累计约32分钟 - 35GHSA-2m8m-jhrm-w6j2 · rclone: PowerShell Smart-Quote Filename Injection Enables SFTP Server-Side Command Execution
rclone: PowerShell Smart-Quote Filename Injection Enables SFTP Server-Side Command Execution Affected packages: Go/github.com/rclone/rclone Attributes: Fix available、Severity - 8.0 (High)
最高第 2 名04:45 达到04:45 首次观测上榜06:21 观测离榜累计约1小时36分 - 36GHSA-48hr-524c-v5w3 · Nuxt: Unauthorized Component Instantiation via Server Island Props
Nuxt: Unauthorized Component Instantiation via Server Island Props Affected packages: npm/nuxt Attributes: Fix available、Severity - 4.8 (Medium)
最高第 2 名05:33 达到05:33 首次观测上榜08:45 观测离榜累计约3小时12分 - 37GHSA-4f78-qhmw-8j8m · Electron: DevTools JavaScript Injection via Unsanitized Dock State Parameter
Electron: DevTools JavaScript Injection via Unsanitized Dock State Parameter Affected packages: npm/electron Attributes: Fix available、Severity - 5.7 (Medium)
最高第 2 名01:49 达到01:49 首次观测上榜03:25 观测离榜累计约1小时36分 - 38GHSA-4vr5-p2gc-h23p · rclone archive extract allows S3 destination prefix escape via crafted archive paths
rclone archive extract allows S3 destination prefix escape via crafted archive paths Affected packages: Go/github.com/rclone/rclone Attributes: Fix available、Severity - 5.0 (Medium)
最高第 2 名05:01 达到05:01 首次观测上榜06:21 观测离榜累计约1小时20分 - 39GHSA-5c9j-mhmv-5xgx · Electron: shell.openPath path validation bypass via embedded null byte
Electron: shell.openPath path validation bypass via embedded null byte Affected packages: npm/electron Attributes: Fix available、Severity - 6.0 (Medium)
最高第 2 名00:13 达到00:13 首次观测上榜01:49 观测离榜累计约1小时36分 - 40GHSA-9pf5-hg6p-4pwp · Electron: Permission Check Handler Receives Main Frame Origin Instead of Requesting Iframe Origin
Electron: Permission Check Handler Receives Main Frame Origin Instead of Requesting Iframe Origin Affected packages: npm/electron Attributes: Fix available、Severity - 5.9 (Medium)
最高第 2 名00:00 达到当日首次采集时已在榜00:45 观测离榜累计约46分钟 - 41GHSA-f2r8-jv7c-xqmp · Electron: DevTools embedder handler executes arbitrary files via shell open
Electron: DevTools embedder handler executes arbitrary files via shell open Affected packages: npm/electron Attributes: Fix available、Severity - 6.9 (Medium)
最高第 2 名02:05 达到02:05 首次观测上榜03:41 观测离榜累计约1小时36分 - 42GHSA-gwfq-86j8-7qhv · rclone: Verbose Stack Trace Disclosure in RC API Error Responses
rclone: Verbose Stack Trace Disclosure in RC API Error Responses Affected packages: Go/github.com/rclone/rclone Attributes: Fix available、Severity - 2.7 (Low)
最高第 2 名04:29 达到04:29 首次观测上榜05:17 观测离榜累计约48分钟 - 43GHSA-qq9q-x9w4-chhj · Traefik Gateway API HTTPRoute BackendRef ExtensionRef Namespace Confusion
Traefik Gateway API HTTPRoute BackendRef ExtensionRef Namespace Confusion Affected packages: Go/Traefik Attributes: Fix available、Severity - 5.3 (Medium)
最高第 2 名06:05 达到06:05 首次观测上榜08:45 观测离榜累计约2小时40分 - 44GHSA-v64r-4m7r-3mvq · Electron: HTTP redirect followed into local file loader
Electron: HTTP redirect followed into local file loader Affected packages: npm/electron Attributes: Fix available、Severity - 5.9 (Medium)
最高第 2 名00:29 达到00:29 首次观测上榜02:21 观测离榜累计约1小时52分 - 45JLSEC-2026-1165 · Deno: WebSocket API sandbox bypass via missing post-DNS check
Deno: WebSocket API sandbox bypass via missing post-DNS check Affected packages: Julia/Deno_jll Attributes: Fix available、Severity - 5.2 (Medium)
最高第 2 名02:37 达到02:37 首次观测上榜04:45 观测离榜累计约2小时8分 - 46JLSEC-2026-1169 · 7-Zip for Windows fails to preserve the Mark-of-the-Web when extracting a crafted RAR5 archive
7-Zip for Windows fails to preserve the Mark-of-the-Web when extracting a crafted RAR5 archive Affected packages: Julia/p7zip_jll Attributes: No fix available、Severity - 4.8 (Medium)
最高第 2 名05:17 达到05:17 首次观测上榜08:45 观测离榜累计约3小时28分 - 47MAL-2026-13369 · Malicious code in kepler (npm)
Malicious code in kepler (npm) Affected packages: npm/kepler Attributes: No fix available
最高第 2 名03:25 达到03:25 首次观测上榜04:45 观测离榜累计约1小时20分 - 48MAL-2026-13392 · Malicious code in golaaa (npm)
Malicious code in golaaa (npm) Affected packages: npm/golaaa Attributes: No fix available
最高第 2 名20:35 达到20:35 首次观测上榜21:55 观测离榜累计约1小时20分 - 49MAL-2026-13394 · Malicious code in @activepieces/piece-google-bigquery (npm)
Malicious code in @activepieces/piece-google-bigquery (npm) Affected packages: npm/@activepieces/piece-google-bigquery Attributes: No fix available
最高第 2 名21:39 达到21:39 首次观测上榜22:27 观测离榜累计约48分钟 - 50MAL-2026-13420 · Malicious code in @innocarpe/deepseek-build (npm)
Malicious code in @innocarpe/deepseek-build (npm) Affected packages: npm/@innocarpe/deepseek-build Attributes: No fix available
最高第 2 名22:43 达到22:43 首次观测上榜23:47 观测离榜累计约1小时4分


































































































