
OSV.dev · 实时热榜
- 01DEBIAN-CVE-2026-18938 · Debian:11/p11-kit
Affected packages: Debian:11/p11-kit、Debian:12/p11-kit、Debian:13/p11-kit、Debian:14/p11-kit Attributes: No fix available
最高第 1 名17:07 达到17:07 首次观测上榜18:43 观测离榜累计约1小时36分 - 02DEBIAN-CVE-2026-52682 · Debian:11/dnsdist
Affected packages: Debian:11/dnsdist、Debian:11/pdns、Debian:11/pdns-recursor、Debian:12/dnsdist、Debian:12/pdns、... 7 more Attributes: No fix available
最高第 1 名03:15 达到03:15 首次观测上榜04:19 观测离榜累计约1小时4分 - 03ECHO-2495-c2a6-88b6 · Echo:PyPi/pypdf
Affected packages: Echo:PyPi/pypdf Attributes: Fix available
最高第 1 名08:51 达到08:51 首次观测上榜11:15 观测离榜累计约2小时24分 - 04ECHO-7cdd-31d1-19a0 · Echo/apr-util
Affected packages: Echo/apr-util Attributes: No fix available
最高第 1 名12:51 达到12:51 首次观测上榜14:59 观测离榜累计约2小时8分 - 05EEF-CVE-2026-66838 · SQL injection via the :comment option in Postgrex.stream/4
SQL injection via the :comment option in Postgrex.stream/4 Affected packages: Hex/postgrex、github.com/elixir-ecto/postgrex Attributes: Fix available、Severity - 5.9 (Medium)
最高第 1 名20:35 达到20:35 首次观测上榜21:23 观测离榜累计约48分钟 - 06EEF-CVE-2026-68750 · Quadratic sibling re-flattening in the html_sanitize_ex traversal engine allows CPU-exhaustion denial of service
Quadratic sibling re-flattening in the html_sanitize_ex traversal engine allows CPU-exhaustion denial of service Affected packages: Hex/html_sanitize_ex、github.com/rrrene/html_sanitize_ex Attributes: Fix available、Severity - 8.2 (High)
最高第 1 名00:00 达到当日首次采集时已在榜02:11 观测离榜累计约2小时11分 - 07GHSA-3ccp-42pg-hgv6 · Traefik: Cross-user response poisoning via proxied CONNECT on Traefik's shared backend keep-alive pool
Traefik: Cross-user response poisoning via proxied CONNECT on Traefik's shared backend keep-alive pool Affected packages: Go/github.com/traefik/traefik、Go/github.com/traefik/traefik/v2、Go/github.com/traefik/traefik/v3 Attributes: Fix available、Severity - 7.0 (High)
最高第 1 名00:03 达到00:03 首次观测上榜02:11 观测离榜累计约2小时8分 - 08GHSA-3mr9-p497-58f6 · Contao crawler leaks auth credentials to external hosts
Contao crawler leaks auth credentials to external hosts Affected packages: Packagist/contao/contao、Packagist/contao/core-bundle Attributes: Fix available、Severity - 2.6 (Low)
最高第 1 名03:47 达到03:47 首次观测上榜04:51 观测离榜累计约1小时4分 - 09GHSA-5p4m-2wfm-xmqj · JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported
JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported Affected packages: npm/js-yaml Attributes: Fix available、Severity - 7.5 (High)
最高第 1 名04:35 达到04:35 首次观测上榜05:39 观测离榜累计约1小时4分 - 10GHSA-6p8f-p8j2-rqmv · Traefik: Gateway HTTPRoute backendRef filters can leak backend context across routes sharing a Service:port
Traefik: Gateway HTTPRoute backendRef filters can leak backend context across routes sharing a Service:port Affected packages: Go/github.com/traefik/traefik/v3 Attributes: Fix available、Severity - 6.3 (Medium)
最高第 1 名00:51 达到00:51 首次观测上榜04:03 观测离榜累计约3小时12分 - 11GHSA-6x64-9x62-f2gx · Mermaid allows CSS injection applying to sibling elements of the diagram
Mermaid allows CSS injection applying to sibling elements of the diagram Affected packages: npm/mermaid Attributes: Fix available、Severity - 5.3 (Medium)
最高第 1 名04:03 达到04:03 首次观测上榜04:51 观测离榜累计约48分钟 - 12GHSA-93qh-5269-9wcf · Statamic: Account takeover via OAuth email matching without email-verification check
Statamic: Account takeover via OAuth email matching without email-verification check Affected packages: Packagist/statamic/cms Attributes: Fix available、Severity - 8.1 (High)
最高第 1 名03:31 达到03:31 首次观测上榜04:35 观测离榜累计约1小时4分 - 13GHSA-957r-qf9p-67xw · Craft CMS: Arbitrary file read via SplFileObject in non-sandboxed template contexts
Craft CMS: Arbitrary file read via SplFileObject in non-sandboxed template contexts Affected packages: Packagist/craftcms/cms Attributes: Fix available、Severity - 6.9 (Medium)
最高第 1 名06:11 达到06:11 首次观测上榜08:51 观测离榜累计约2小时40分 - 14GHSA-9p7c-v5x3-rfx8 · Craft CMS: Missing authorization check allows non-admin control panel users to reorder Global Sets
Craft CMS: Missing authorization check allows non-admin control panel users to reorder Global Sets Affected packages: Packagist/craftcms/cms Attributes: Fix available
最高第 1 名05:07 达到05:07 首次观测上榜08:51 观测离榜累计约3小时44分 - 15GHSA-j4r3-hg7j-8chg · node-re2: Out-of-bounds heap read in ` replace ` / ` split ` via a ` Buffer ` ending in a truncated multi-byte UTF-8 character → adjacent heap memory disclosed to JavaScript
node-re2: Out-of-bounds heap read in ` replace ` / ` split ` via a ` Buffer ` ending in a truncated multi-byte UTF-8 character → adjacent heap memory disclosed to JavaScript Affected packages: npm/re2 Attributes: Fix available、Severity - 5.1 (Medium)
最高第 1 名05:39 达到05:39 首次观测上榜08:51 观测离榜累计约3小时12分 - 16GHSA-mj63-m3rc-8ppr · league/commonmark: Denial of service via deeply nested XML output
league/commonmark: Denial of service via deeply nested XML output Affected packages: Packagist/league/commonmark Attributes: Fix available、Severity - 5.3 (Medium)
最高第 1 名04:51 达到04:51 首次观测上榜06:11 观测离榜累计约1小时20分 - 17GHSA-pmhh-3w7g-xqp8 · jsoup: Cleaner may expose markup with custom raw-text elements
jsoup: Cleaner may expose markup with custom raw-text elements Affected packages: Maven/org.jsoup:jsoup Attributes: Fix available、Severity - 4.7 (Medium)
最高第 1 名05:23 达到05:23 首次观测上榜08:51 观测离榜累计约3小时28分 - 18GHSA-rjhh-76wf-8xmw · Smarty Security stream restriction bypass through stream: resource
Smarty Security stream restriction bypass through stream: resource Affected packages: Packagist/smarty/smarty Attributes: Fix available、Severity - 6.9 (Medium)
最高第 1 名23:15 达到23:15 首次观测上榜当日结束时仍在榜累计约32分钟 - 19GHSA-rvmm-v933-jgxq · Craft CMS: Missing authorization check allows non-admin control panel users access to user registration metrics
Craft CMS: Missing authorization check allows non-admin control panel users access to user registration metrics Affected packages: Packagist/craftcms/cms Attributes: Fix available、Severity - 5.3 (Medium)
最高第 1 名05:55 达到05:55 首次观测上榜08:51 观测离榜累计约2小时56分 - 20GHSA-vp3h-ghgh-jr7g · Nx: Zip-Slip in the self-hosted remote cache
Nx: Zip-Slip in the self-hosted remote cache Affected packages: npm/@nx/azure-cache、npm/@nx/gcs-cache、npm/@nx/powerpack-azure-cache、npm/@nx/powerpack-gcs-cache、npm/@nx/powerpack-s3-cache、... 4 more Attributes: Fix available、Severity - 8.7 (High)
最高第 1 名04:19 达到04:19 首次观测上榜05:07 观测离榜累计约48分钟 - 21GHSA-x677-9fxg-v5c5 · Traefik: Incomplete fix for CVE-2026-33433 + CVE-2026-39858 cross-cohort: headerField underscore-variant identity spoofing in BasicAuth / DigestAuth / ForwardAuth
Traefik: Incomplete fix for CVE-2026-33433 + CVE-2026-39858 cross-cohort: headerField underscore-variant identity spoofing in BasicAuth / DigestAuth / ForwardAuth Affected packages: Go/github.com/traefik/traefik/v2、Go/github.com/traefik/traefik/v3 Attributes: Fix available、Severity - 7.8 (High)
最高第 1 名01:07 达到01:07 首次观测上榜04:03 观测离榜累计约2小时56分 - 22JLSEC-2026-1170 · Julia/FFMPEG_jll
Affected packages: Julia/FFMPEG_jll、Julia/FFMPEG_nogpl_jll Attributes: Fix available、Severity - 5.4 (Medium)
最高第 1 名21:39 达到21:39 首次观测上榜22:11 观测离榜累计约32分钟 - 23JLSEC-2026-1193 · Julia/libheif_jll
Affected packages: Julia/libheif_jll Attributes: Fix available、Severity - 7.1 (High)
最高第 1 名22:59 达到22:59 首次观测上榜当日结束时仍在榜累计约48分钟 - 24MAL-2026-13488 · Malicious code in idnna (PyPI)
Malicious code in idnna (PyPI) Affected packages: PyPI/idnna Attributes: No fix available
最高第 1 名16:03 达到16:03 首次观测上榜16:19 观测离榜累计约16分钟 - 25MAL-2026-13490 · Malicious code in fast-hashes (PyPI)
Malicious code in fast-hashes (PyPI) Affected packages: PyPI/fast-hashes Attributes: No fix available
最高第 1 名17:55 达到17:55 首次观测上榜18:43 观测离榜累计约48分钟 - 26MAL-2026-13605 · Malicious code in yakuza0 (npm)
Malicious code in yakuza0 (npm) Affected packages: npm/yakuza0 Attributes: No fix available
最高第 1 名21:23 达到21:23 首次观测上榜21:39 观测离榜累计约16分钟 - 27MGASA-2026-0324 · Updated python-django packages fix security vulnerabilities
Updated python-django packages fix security vulnerabilities Affected packages: Mageia:10/python-django Attributes: Fix available
最高第 1 名14:43 达到14:43 首次观测上榜16:19 观测离榜累计约1小时36分 - 28MINI-4j52-wjg6-hqfg · MinimOS/traefik-2
Affected packages: MinimOS/traefik-2 Attributes: No fix available
最高第 1 名22:27 达到22:27 首次观测上榜23:15 观测离榜累计约48分钟 - 29MINI-hw87-r378-mc2h · MinimOS/vault-k8s
Affected packages: MinimOS/vault-k8s Attributes: Fix available
最高第 1 名16:19 达到16:19 首次观测上榜16:51 观测离榜累计约32分钟 - 30MINI-vc78-8gj3-8w4r · MinimOS/elasticsearch-9.3
Affected packages: MinimOS/elasticsearch-9.3 Attributes: No fix available
最高第 1 名22:11 达到22:11 首次观测上榜22:27 观测离榜累计约16分钟 - 31OESA-2026-3312 · busybox security update
busybox security update Affected packages: openEuler:20.03-LTS-SP4/busybox、openEuler:22.03-LTS-SP4/busybox、openEuler:24.03-LTS-SP1/busybox、openEuler:24.03-LTS-SP3/busybox、openEuler:24.03-LTS-SP4/busybox Attributes: Fix available、Severity - 5.1 (Medium)
最高第 1 名11:15 达到11:15 首次观测上榜14:59 观测离榜累计约3小时44分 - 32RHSA-2026:51436 · Red Hat Security Advisory: postfix security update
Red Hat Security Advisory: postfix security update Affected packages: Red Hat:enterprise_linux_eus:10.0/postfix Attributes: Fix available、Severity - 7.5 (High)
最高第 1 名18:43 达到18:43 首次观测上榜20:35 观测离榜累计约1小时52分 - 33ROOT-APP-PYPI-CVE-2023-44271 · CVE-2023-44271 in pillow - Patched by Root
CVE-2023-44271 in pillow - Patched by Root Affected packages: Root:PyPI/pillow、Root:PyPI/rootio-pillow Attributes: Fix available
最高第 1 名16:51 达到16:51 首次观测上榜18:43 观测离榜累计约1小时52分 - 34RXSA-2026:51035 · Moderate: kernel security, bug fix, and enhancement update
Moderate: kernel security, bug fix, and enhancement update Affected packages: Rocky Linux:9/kernel Attributes: Fix available、Severity - 7.1 (High)
最高第 1 名02:27 达到02:27 首次观测上榜04:19 观测离榜累计约1小时52分 - 35DEBIAN-CVE-2026-61477 · Debian:11/libvirt
Affected packages: Debian:11/libvirt、Debian:12/libvirt、Debian:13/libvirt、Debian:14/libvirt Attributes: No fix available
最高第 2 名05:07 达到05:07 首次观测上榜06:11 观测离榜累计约1小时4分 - 36DEBIAN-CVE-2026-64638 · Debian:11/wordpress
Affected packages: Debian:11/wordpress、Debian:12/wordpress、Debian:13/wordpress、Debian:14/wordpress Attributes: No fix available
最高第 2 名17:07 达到17:07 首次观测上榜18:43 观测离榜累计约1小时36分 - 37ECHO-0e0b-03fe-eb59 · Echo/apr-util
Affected packages: Echo/apr-util Attributes: No fix available
最高第 2 名12:51 达到12:51 首次观测上榜14:59 观测离榜累计约2小时8分 - 38ECHO-28b6-f469-c293 · Echo:PyPi/pypdf
Affected packages: Echo:PyPi/pypdf Attributes: Fix available
最高第 2 名08:51 达到08:51 首次观测上榜11:15 观测离榜累计约2小时24分 - 39EEF-CVE-2026-68749 · Quadratic regex backtracking in the html_sanitize_ex CSS scrubber allows CPU-exhaustion denial of service
Quadratic regex backtracking in the html_sanitize_ex CSS scrubber allows CPU-exhaustion denial of service Affected packages: Hex/html_sanitize_ex、github.com/rrrene/html_sanitize_ex Attributes: Fix available、Severity - 8.2 (High)
最高第 2 名00:00 达到当日首次采集时已在榜02:11 观测离榜累计约2小时11分 - 40GHSA-225x-3jhx-wh4q · Statamic: Missing authorization on Control Panel endpoint allows disclosure of user existence
Statamic: Missing authorization on Control Panel endpoint allows disclosure of user existence Affected packages: Packagist/statamic/cms Attributes: Fix available、Severity - 4.3 (Medium)
最高第 2 名03:31 达到03:31 首次观测上榜04:35 观测离榜累计约1小时4分 - 41GHSA-3rrr-jr9j-h3q3 · Mermaid Architecture diagrams are vulnerable to prototype pollution
Mermaid Architecture diagrams are vulnerable to prototype pollution Affected packages: npm/mermaid Attributes: Fix available、Severity - 6.5 (Medium)
最高第 2 名04:03 达到04:03 首次观测上榜04:51 观测离榜累计约48分钟 - 42GHSA-62fc-8686-hfmq · Traefik: ` allowCrossNamespace=false ` bypass via ` @kubernetescrd ` TraefikService backendRef
Traefik: ` allowCrossNamespace=false ` bypass via ` @kubernetescrd ` TraefikService backendRef Affected packages: Go/github.com/traefik/traefik、Go/github.com/traefik/traefik/v2、Go/github.com/traefik/traefik/v3 Attributes: Fix available、Severity - 4.8 (Medium)
最高第 2 名00:51 达到00:51 首次观测上榜04:03 观测离榜累计约3小时12分 - 43GHSA-6hr6-w5qg-qmwg · h2: Duplicate Host header could facilitate request smuggling
h2: Duplicate Host header could facilitate request smuggling Affected packages: PyPI/h2 Attributes: Fix available、Severity - 5.3 (Medium)
最高第 2 名06:11 达到06:11 首次观测上榜08:51 观测离榜累计约2小时40分 - 44GHSA-7hxc-f267-h5q7 · Craft CMS: Incorrect path validation could potentially lead to path traversal
Craft CMS: Incorrect path validation could potentially lead to path traversal Affected packages: Packagist/craftcms/cms Attributes: Fix available、Severity - 2.1 (Low)
最高第 2 名05:55 达到05:55 首次观测上榜08:51 观测离榜累计约2小时56分 - 45GHSA-8hcv-x26h-mcgp · node-re2: String.prototype.replace(re2, template) aborts the Node process (uncatchable ToLocalChecked on empty MaybeLocal) when the result exceeds V8's max string length
node-re2: String.prototype.replace(re2, template) aborts the Node process (uncatchable ToLocalChecked on empty MaybeLocal) when the result exceeds V8's max string length Affected packages: npm/re2 Attributes: Fix available、Severity - 6.2 (Medium)
最高第 2 名05:39 达到05:39 首次观测上榜08:51 观测离榜累计约3小时12分 - 46GHSA-cxjq-mrr5-89rv · Traefik: Authentication Bypass via Path Traversal in ReplacePathRegex Middleware
Traefik: Authentication Bypass via Path Traversal in ReplacePathRegex Middleware Affected packages: Go/github.com/traefik/traefik、Go/github.com/traefik/traefik/v2、Go/github.com/traefik/traefik/v3 Attributes: Fix available、Severity - 9.1 (Critical)
最高第 2 名01:07 达到01:07 首次观测上榜04:03 观测离榜累计约2小时56分 - 47GHSA-f6wf-28g6-769x · Smarty: Symlink path traversal out of trusted directories
Smarty: Symlink path traversal out of trusted directories Affected packages: Packagist/smarty/smarty Attributes: Fix available、Severity - 6.9 (Medium)
最高第 2 名23:15 达到23:15 首次观测上榜当日结束时仍在榜累计约32分钟 - 48GHSA-mh25-x5hq-wrqp · league/commonmark: Denial of service via colliding heading slugs
league/commonmark: Denial of service via colliding heading slugs Affected packages: Packagist/league/commonmark Attributes: Fix available、Severity - 7.5 (High)
最高第 2 名04:51 达到04:51 首次观测上榜06:11 观测离榜累计约1小时20分 - 49GHSA-p8x7-9vfw-p7vc · Craft CMS: Arbitrary user password reset leading to administrator account takeover
Craft CMS: Arbitrary user password reset leading to administrator account takeover Affected packages: Packagist/craftcms/cms Attributes: Fix available
最高第 2 名05:23 达到05:23 首次观测上榜08:51 观测离榜累计约3小时28分 - 50GHSA-rhh3-jpg6-66xh · Mermaid radar diagrams are vulnerable to DoS
Mermaid radar diagrams are vulnerable to DoS Affected packages: npm/mermaid Attributes: Fix available、Severity - 5.3 (Medium)
最高第 2 名04:19 达到04:19 首次观测上榜04:51 观测离榜累计约32分钟


































































































