
OSV.dev · 实时热榜
- 01BELL-CVE-2026-74568 · Alpaquita:stream/linux-lts
Affected packages: Alpaquita:stream/linux-lts Attributes: No fix available、Severity - 9.3 (Critical)
最高第 1 名15:23 达到15:23 首次观测上榜16:11 观测离榜累计约48分钟 - 02DEBIAN-CVE-2026-75003 · Debian:11/roundcube
Affected packages: Debian:11/roundcube、Debian:12/roundcube、Debian:13/roundcube、Debian:14/roundcube Attributes: Fix available
最高第 1 名00:11 达到00:11 首次观测上榜01:47 观测离榜累计约1小时36分 - 03ECHO-1f2a-a632-ee71 · Echo/systemd
Affected packages: Echo/systemd Attributes: No fix available
最高第 1 名18:19 达到18:19 首次观测上榜18:35 观测离榜累计约16分钟 - 04ECHO-3407-ba73-148e · Echo/thrift
Affected packages: Echo/thrift Attributes: Fix available
最高第 1 名19:55 达到19:55 首次观测上榜20:43 观测离榜累计约48分钟 - 05ECHO-4612-02ee-2b3e · Echo/binutils
Affected packages: Echo/binutils Attributes: No fix available
最高第 1 名04:59 达到04:59 首次观测上榜08:43 观测离榜累计约3小时44分 - 06ECHO-e07c-2fba-e60c · Echo/dnsmasq
Affected packages: Echo/dnsmasq Attributes: No fix available
最高第 1 名10:19 达到10:19 首次观测上榜14:35 观测离榜累计约4小时16分 - 07EEF-CVE-2026-43971 · Link Header Directive Smuggling via Unescaped target/rel/Attribute Keys in cow_link:link/1
Link Header Directive Smuggling via Unescaped target/rel/Attribute Keys in cow_link:link/1 Affected packages: Hex/cowlib、github.com/ninenines/cowlib Attributes: No fix available、Severity - 6.3 (Medium)
最高第 1 名17:15 达到17:15 首次观测上榜18:35 观测离榜累计约1小时20分 - 08GHSA-2qj4-mmr9-4v2f · Netty: Memory Exhaustion in SctpMessageCompletionHandler
Netty: Memory Exhaustion in SctpMessageCompletionHandler Affected packages: Maven/io.netty:netty-transport-sctp Attributes: Fix available、Severity - 7.5 (High)
最高第 1 名02:03 达到02:03 首次观测上榜02:35 观测离榜累计约32分钟 - 09GHSA-8394-6f8r-whxg · Terragrunt: Arbitrary File Deletion via Malicious Module Manifest
Terragrunt: Arbitrary File Deletion via Malicious Module Manifest Affected packages: Go/github.com/gruntwork-io/terragrunt Attributes: Fix available、Severity - 6.9 (Medium)
最高第 1 名00:59 达到00:59 首次观测上榜02:03 观测离榜累计约1小时4分 - 10GHSA-8c42-7qj2-3j46 · Netty Vulnerable to Cache Poisoning and Information Disclosure via CORS Vary Header Overwrite
Netty Vulnerable to Cache Poisoning and Information Disclosure via CORS Vary Header Overwrite Affected packages: Maven/io.netty:netty-codec-http Attributes: Fix available、Severity - 6.5 (Medium)
最高第 1 名02:35 达到02:35 首次观测上榜04:27 观测离榜累计约1小时52分 - 11GHSA-f2ff-p2ww-7p4p · sqlparse: Quadratic O(n²) DoS in group_comments
sqlparse: Quadratic O(n²) DoS in group_comments Affected packages: PyPI/sqlparse Attributes: Fix available、Severity - 8.7 (High)
最高第 1 名01:31 达到01:31 首次观测上榜02:35 观测离榜累计约1小时4分 - 12GHSA-fp27-88fp-2phg · Glances: REST API CORS Credentials Guard Uses Exact-Match Instead of Membership Test — Bypassed by Any Multi-Origin Allowlist Containing the Wildcard
Glances: REST API CORS Credentials Guard Uses Exact-Match Instead of Membership Test — Bypassed by Any Multi-Origin Allowlist Containing the Wildcard Affected packages: PyPI/glances Attributes: Fix available、Severity - 6.5 (Medium)
最高第 1 名01:15 达到01:15 首次观测上榜02:03 观测离榜累计约48分钟 - 13GHSA-gqch-g4w5-7qcw · MLflow: CreateModelVersion source validation does not check READ permission on referenced run_id
MLflow: CreateModelVersion source validation does not check READ permission on referenced run_id Affected packages: npm/mlflow Attributes: Fix available、Severity - 7.1 (High)
最高第 1 名06:03 达到06:03 首次观测上榜10:19 观测离榜累计约4小时16分 - 14GHSA-v836-6xw4-9cx3 · vm2 has Memory Exhaustion DoS via bufferAllocLimit Bypass
vm2 has Memory Exhaustion DoS via bufferAllocLimit Bypass Affected packages: npm/vm2 Attributes: Fix available、Severity - 7.5 (High)
最高第 1 名01:47 达到01:47 首次观测上榜02:35 观测离榜累计约48分钟 - 15GHSA-x5pq-m9p8-f4vx · Copyparty vulnerable to file/dirkey confusion
Copyparty vulnerable to file/dirkey confusion Affected packages: PyPI/copyparty Attributes: Fix available、Severity - 4.3 (Medium)
最高第 1 名23:23 达到23:23 首次观测上榜当日结束时仍在榜累计约32分钟 - 16GO-2026-6097 · Cloudreve: Path Traversal in WOPI PUT_RELATIVE Allows Arbitrary File Creation in Owner Account in github.com/cloudreve/Cloudreve
Cloudreve: Path Traversal in WOPI PUT_RELATIVE Allows Arbitrary File Creation in Owner Account in github.com/cloudreve/Cloudreve Affected packages: Go/github.com/cloudreve/Cloudreve、Go/github.com/cloudreve/Cloudreve/v3、Go/github.com/cloudreve/Cloudreve/v4 Attributes: Fix available
最高第 1 名23:07 达到23:07 首次观测上榜当日结束时仍在榜累计约48分钟 - 17GO-2026-6153 · Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Affected packages: Go/github.com/apache/answer Attributes: Fix available
最高第 1 名22:51 达到22:51 首次观测上榜23:07 观测离榜累计约16分钟 - 18JLSEC-2026-1344 · TOCTOU in GNU tar allows unauthorized file modification by a local attacker
TOCTOU in GNU tar allows unauthorized file modification by a local attacker Affected packages: Julia/Tar_jll Attributes: No fix available、Severity - 4.4 (Medium)
最高第 1 名08:27 达到08:27 首次观测上榜10:19 观测离榜累计约1小时52分 - 19MAL-2026-14117 · Malicious code in bcc-design (npm)
Malicious code in bcc-design (npm) Affected packages: npm/bcc-design Attributes: No fix available
最高第 1 名13:15 达到13:15 首次观测上榜14:35 观测离榜累计约1小时20分 - 20MAL-2026-14119 · Malicious code in bcc-design-icons (npm)
Malicious code in bcc-design-icons (npm) Affected packages: npm/bcc-design-icons Attributes: No fix available
最高第 1 名13:47 达到13:47 首次观测上榜14:35 观测离榜累计约48分钟 - 21MINI-3797-4chw-7mcj · MinimOS/paketo-buildpacks-dotnet-core-sdk-1.6.36
Affected packages: MinimOS/paketo-buildpacks-dotnet-core-sdk-1.6.36 Attributes: Fix available
最高第 1 名19:07 达到19:07 首次观测上榜19:23 观测离榜累计约16分钟 - 22MINI-3c2g-r424-xff6 · MinimOS/paketo-buildpacks-clojure-tools
Affected packages: MinimOS/paketo-buildpacks-clojure-tools Attributes: No fix available
最高第 1 名04:27 达到04:27 首次观测上榜04:43 观测离榜累计约16分钟 - 23MINI-3g2r-m98j-r8f3 · MinimOS/paketo-buildpacks-yarn-start
Affected packages: MinimOS/paketo-buildpacks-yarn-start Attributes: No fix available
最高第 1 名04:43 达到04:43 首次观测上榜08:27 观测离榜累计约3小时44分 - 24MINI-4mq4-p743-4qv8 · MinimOS/gitlab-runner-18.6
Affected packages: MinimOS/gitlab-runner-18.6、MinimOS/gitlab-runner-helper-18.6 Attributes: No fix available
最高第 1 名22:19 达到22:19 首次观测上榜22:35 观测离榜累计约16分钟 - 25MINI-4q9r-75jr-v9m5 · MinimOS/paketo-buildpacks-yarn-2.4.0
Affected packages: MinimOS/paketo-buildpacks-yarn-2.4.0 Attributes: Fix available
最高第 1 名19:23 达到19:23 首次观测上榜20:11 观测离榜累计约48分钟 - 26MINI-7j6q-29j2-4397 · MinimOS/registration-operator
Affected packages: MinimOS/registration-operator Attributes: Fix available
最高第 1 名16:11 达到16:11 首次观测上榜18:35 观测离榜累计约2小时24分 - 27MINI-9fqc-r248-9q6c · MinimOS/velero
Affected packages: MinimOS/velero Attributes: Fix available
最高第 1 名20:11 达到20:11 首次观测上榜22:19 观测离榜累计约2小时8分 - 28MINI-c6gc-j6ch-w5hv · MinimOS/neo4j-4.4
Affected packages: MinimOS/neo4j-4.4 Attributes: No fix available
最高第 1 名22:35 达到22:35 首次观测上榜23:07 观测离榜累计约32分钟 - 29MINI-qpp6-8c43-jp42 · MinimOS/trino-fips-480
Affected packages: MinimOS/trino-fips-480 Attributes: Fix available
最高第 1 名19:39 达到19:39 首次观测上榜20:11 观测离榜累计约32分钟 - 30MINI-r5jg-xwjm-x367 · MinimOS/metrics-server
Affected packages: MinimOS/metrics-server Attributes: No fix available
最高第 1 名20:59 达到20:59 首次观测上榜22:19 观测离榜累计约1小时20分 - 31RHSA-2026:55930 · Red Hat Security Advisory: mod_http2 security update
Red Hat Security Advisory: mod_http2 security update Affected packages: Red Hat:rhel_e4s:9.2::appstream/mod_http2 Attributes: Fix available、Severity - 7.5 (High)
最高第 1 名18:35 达到18:35 首次观测上榜19:23 观测离榜累计约48分钟 - 32RLSA-2026:55541 · Important: nodejs22 security update
Important: nodejs22 security update Affected packages: Rocky Linux:10/nodejs22 Attributes: Fix available、Severity - 8.6 (High)
最高第 1 名20:43 达到20:43 首次观测上榜22:19 观测离榜累计约1小时36分 - 33RLSA-2026:55740 · Important: pcp security update
Important: pcp security update Affected packages: Rocky Linux:9/pcp Attributes: Fix available、Severity - 8.8 (High)
最高第 1 名14:35 达到14:35 首次观测上榜15:23 观测离榜累计约48分钟 - 34ROOT-APP-MAVEN-CVE-2026-22735 · CVE-2026-22735 in org.springframework:spring-webflux - Patched by Root
CVE-2026-22735 in org.springframework:spring-webflux - Patched by Root Affected packages: Root:Maven/io.root.org.springframework:spring-webflux、Root:Maven/io.root.org.springframework:spring-webmvc、Root:Maven/org.springframework:spring-webflux、Root:Maven/org.springframework:spring-webmvc Attributes: Fix available、Severity - 2.6 (Low)
最高第 1 名00:00 达到当日首次采集时已在榜00:59 观测离榜累计约1小时 - 35ROOT-APP-NPM-CVE-2026-32621 · CVE-2026-32621 in @apollo/federation-internals - Patched by Root
CVE-2026-32621 in @apollo/federation-internals - Patched by Root Affected packages: Root:npm/@apollo/federation-internals、Root:npm/@apollo/gateway、Root:npm/@apollo/query-planner、Root:npm/@rootio/apollo__federation-internals、Root:npm/@rootio/apollo__gateway、... 1 more Attributes: Fix available
最高第 1 名16:59 达到16:59 首次观测上榜18:35 观测离榜累计约1小时36分 - 36BELL-CVE-2026-74569 · Alpaquita:23/linux-lts
Affected packages: Alpaquita:23/linux-lts、Alpaquita:25/linux-lts、Alpaquita:stream/linux-lts Attributes: Fix available、Severity - 9.8 (Critical)
最高第 2 名15:23 达到15:23 首次观测上榜16:11 观测离榜累计约48分钟 - 37DEBIAN-CVE-2026-75006 · Debian:11/roundcube
Affected packages: Debian:11/roundcube、Debian:12/roundcube、Debian:13/roundcube、Debian:14/roundcube Attributes: Fix available
最高第 2 名00:11 达到00:11 首次观测上榜01:47 观测离榜累计约1小时36分 - 38ECHO-8af2-71e7-4b82 · Echo/thrift
Affected packages: Echo/thrift Attributes: Fix available
最高第 2 名19:55 达到19:55 首次观测上榜20:43 观测离榜累计约48分钟 - 39ECHO-9f82-dc11-1360 · Echo/systemd
Affected packages: Echo/systemd Attributes: No fix available
最高第 2 名04:59 达到04:59 首次观测上榜08:43 观测离榜累计约3小时44分 - 40ECHO-b98e-b63c-2d5f · Echo/python3.13
Affected packages: Echo/python3.13 Attributes: No fix available
最高第 2 名18:19 达到18:19 首次观测上榜18:35 观测离榜累计约16分钟 - 41GHSA-3p64-6gvh-82v5 · MLflow: LogInputs endpoint bypasses per-run UPDATE authorization in basic-auth
MLflow: LogInputs endpoint bypasses per-run UPDATE authorization in basic-auth Affected packages: npm/mlflow Attributes: Fix available、Severity - 6.5 (Medium)
最高第 2 名06:03 达到06:03 首次观测上榜10:19 观测离榜累计约4小时16分 - 42GHSA-4h34-v6r8-mmjc · Glances: as_dict_secure() Value-Level Bypass Leaks Credentials in URL Values via /api/4/config
Glances: as_dict_secure() Value-Level Bypass Leaks Credentials in URL Values via /api/4/config Affected packages: PyPI/glances Attributes: Fix available、Severity - 5.3 (Medium)
最高第 2 名01:31 达到01:31 首次观测上榜02:35 观测离榜累计约1小时4分 - 43GHSA-fhgh-wq4q-r37x · uniget CLI: Metadata signature verification only runs when UNIGET_IGNORE_METADATA_SIGNATURE is set
uniget CLI: Metadata signature verification only runs when UNIGET_IGNORE_METADATA_SIGNATURE is set Affected packages: Go/gitlab.com/uniget-org/cli Attributes: Fix available、Severity - 7.8 (High)
最高第 2 名02:03 达到02:03 首次观测上榜02:35 观测离榜累计约32分钟 - 44GHSA-m5w8-4gq2-6f8x · vm2: NodeVM `builtin: ['*']` exposes `os` and `dns` — process-wide observability reads AND writes that hijack the host (sibling class of GHSA-9g8x-92q2-p28f)
vm2: NodeVM `builtin: ['*']` exposes `os` and `dns` — process-wide observability reads AND writes that hijack the host (sibling class of GHSA-9g8x-92q2-p28f) Affected packages: npm/vm2 Attributes: Fix available、Severity - 10.0 (Critical)
最高第 2 名01:47 达到01:47 首次观测上榜02:35 观测离榜累计约48分钟 - 45GHSA-qcpp-8x79-hhp3 · Glances has a command injection bypass of action-template sanitizer via cross-field shell-operator reconstruction
Glances has a command injection bypass of action-template sanitizer via cross-field shell-operator reconstruction Affected packages: PyPI/glances Attributes: Fix available、Severity - 8.8 (High)
最高第 2 名00:59 达到00:59 首次观测上榜02:03 观测离榜累计约1小时4分 - 46GO-2026-6098 · Cloudreve: Information Exposure in `GET /api/v4/user/search`: `SearchActive` omits the active-status predicate, leaking inactive/banned account emails in github.com/cloudreve/Cloudreve
Cloudreve: Information Exposure in `GET /api/v4/user/search`: `SearchActive` omits the active-status predicate, leaking inactive/banned account emails in github.com/cloudreve/Cloudreve Affected packages: Go/github.com/cloudreve/Cloudreve、Go/github.com/cloudreve/Cloudreve/v3、Go/github.com/cloudreve/Cloudreve/v4 Attributes: Fix available
最高第 2 名23:07 达到23:07 首次观测上榜当日结束时仍在榜累计约48分钟 - 47GO-2026-6205 · Traefik: Gateway HTTPRoute backendRef filters can leak backend context across routes sharing a Service:port in github.com/traefik/traefik
Traefik: Gateway HTTPRoute backendRef filters can leak backend context across routes sharing a Service:port in github.com/traefik/traefik Affected packages: Go/github.com/traefik/traefik、Go/github.com/traefik/traefik/v2、Go/github.com/traefik/traefik/v3 Attributes: Fix available
最高第 2 名22:51 达到22:51 首次观测上榜23:07 观测离榜累计约16分钟 - 48MAL-2026-14118 · Malicious code in core-tailwindcss-utility (npm)
Malicious code in core-tailwindcss-utility (npm) Affected packages: npm/core-tailwindcss-utility Attributes: No fix available
最高第 2 名13:15 达到13:15 首次观测上榜14:35 观测离榜累计约1小时20分 - 49MAL-2026-14124 · Malicious code in alphazone (npm)
Malicious code in alphazone (npm) Affected packages: npm/alphazone Attributes: No fix available
最高第 2 名23:55 达到23:55 首次观测上榜当日结束时仍在榜累计约0分钟 - 50MINI-3vp8-px7c-x2j2 · MinimOS/paketo-buildpacks-yarn-start
Affected packages: MinimOS/paketo-buildpacks-yarn-start Attributes: No fix available
最高第 2 名04:43 达到04:43 首次观测上榜07:07 观测离榜累计约2小时24分


































































































