
OSV.dev · 实时热榜
- 01CLSA-2026-1787205684 · TuxCare security update for org.springframework (14 CVEs)
TuxCare security update for org.springframework (14 CVEs) Affected packages: TuxCare:Maven/org.springframework:framework-docs、TuxCare:Maven/org.springframework:spring-aop、TuxCare:Maven/org.springframework:spring-aspects、TuxCare:Maven/org.springframework:spring-beans、TuxCare:Maven/org.springframework:spring-context、... 20 more Attributes: Fix available
最高第 1 名15:06 达到15:06 首次观测上榜16:31 观测离榜累计约1小时25分 - 02DEBIAN-CVE-2026-73638 · Debian:11/libimager-perl
Affected packages: Debian:11/libimager-perl、Debian:12/libimager-perl、Debian:13/libimager-perl、Debian:14/libimager-perl Attributes: No fix available
最高第 1 名05:15 达到05:15 首次观测上榜10:35 观测离榜累计约5小时20分 - 03DEBIAN-CVE-2026-73639 · Debian:11/libimager-perl
Affected packages: Debian:11/libimager-perl、Debian:12/libimager-perl、Debian:13/libimager-perl、Debian:14/libimager-perl Attributes: No fix available
最高第 1 名04:11 达到04:11 首次观测上榜05:31 观测离榜累计约1小时20分 - 04DEBIAN-CVE-2026-75803 · Debian:11/openssl
Affected packages: Debian:11/openssl、Debian:12/openssl、Debian:13/openssl、Debian:14/openssl Attributes: No fix available
最高第 1 名22:07 达到22:07 首次观测上榜22:39 观测离榜累计约32分钟 - 05DEBIAN-CVE-2026-76956 · Debian:11/expat
Affected packages: Debian:11/expat、Debian:12/expat、Debian:13/expat、Debian:14/expat Attributes: No fix available
最高第 1 名18:07 达到18:07 首次观测上榜18:23 观测离榜累计约16分钟 - 06ECHO-1fcb-1955-3c69 · Echo/busybox
Affected packages: Echo/busybox Attributes: No fix available
最高第 1 名07:23 达到07:23 首次观测上榜10:35 观测离榜累计约3小时12分 - 07ECHO-38c1-1304-759b · Echo/expat
Affected packages: Echo/expat Attributes: No fix available
最高第 1 名15:54 达到15:54 首次观测上榜18:07 观测离榜累计约2小时13分 - 08ECHO-7a51-5ef2-da43 · Echo/expat
Affected packages: Echo/expat Attributes: No fix available
最高第 1 名21:19 达到21:19 首次观测上榜22:23 观测离榜累计约1小时4分 - 09EEF-CVE-2026-67581 · On-chain transfer proof is not single-use in mpp EVM payment method, enabling cross-challenge replay
On-chain transfer proof is not single-use in mpp EVM payment method, enabling cross-challenge replay Affected packages: Hex/mpp、github.com/zenhive/mpp Attributes: Fix available、Severity - 8.7 (High)
最高第 1 名01:31 达到01:31 首次观测上榜01:47 观测离榜累计约16分钟 - 10GHSA-hjwh-xvfw-qrwj · SearXNG Basic Authentication Credentials Exposed Through MCP Logs and JSON-RPC Error Responses
SearXNG Basic Authentication Credentials Exposed Through MCP Logs and JSON-RPC Error Responses Affected packages: npm/mcp-searxng Attributes: Fix available、Severity - 5.5 (Medium)
最高第 1 名03:55 达到03:55 首次观测上榜04:27 观测离榜累计约32分钟 - 11GHSA-jfj5-wrj9-63x4 · langgraph-api: Incomplete assistant authorization in LangGraph Server run creation
langgraph-api: Incomplete assistant authorization in LangGraph Server run creation Affected packages: PyPI/langgraph-api Attributes: Fix available、Severity - 5.9 (Medium)
最高第 1 名03:23 达到03:23 首次观测上榜03:55 观测离榜累计约32分钟 - 12GHSA-rgr9-r7mj-mf6x · Tina: Cross-origin `POST /media/upload/*` requests can write arbitrary files into the Tina dev server media root
Tina: Cross-origin `POST /media/upload/*` requests can write arbitrary files into the Tina dev server media root Affected packages: npm/@tinacms/cli Attributes: Fix available、Severity - 6.5 (Medium)
最高第 1 名06:03 达到06:03 首次观测上榜10:35 观测离榜累计约4小时32分 - 13GHSA-rxjr-6c9q-h67x · logto-tunnel serves files outside --experience-path via path traversal
logto-tunnel serves files outside --experience-path via path traversal Affected packages: npm/@logto/tunnel Attributes: Fix available、Severity - 8.7 (High)
最高第 1 名04:43 达到04:43 首次观测上榜10:35 观测离榜累计约5小时52分 - 14GHSA-wppf-h75h-6pm6 · SearXNG MCP Server: Additional hardened-mode SSRF bypasses
SearXNG MCP Server: Additional hardened-mode SSRF bypasses Affected packages: npm/mcp-searxng Attributes: Fix available、Severity - 6.3 (Medium)
最高第 1 名03:39 达到03:39 首次观测上榜04:27 观测离榜累计约48分钟 - 15JLSEC-2026-1347 · aria2c accepts a server certificate with incorrect Extended Key Usage (EKU). If the attackers...
aria2c accepts a server certificate with incorrect Extended Key Usage (EKU). If the attackers... Affected packages: Julia/Aria2_jll Attributes: Fix available、Severity - 5.3 (Medium)
最高第 1 名22:23 达到22:23 首次观测上榜当日结束时仍在榜累计约1小时36分 - 16MAL-2026-14307 · Malicious code in express-route-engine (npm)
Malicious code in express-route-engine (npm) Affected packages: npm/express-route-engine Attributes: No fix available
最高第 1 名07:07 达到07:07 首次观测上榜10:35 观测离榜累计约3小时28分 - 17MAL-2026-14315 · Malicious code in @httttt/mcp-demo (npm)
Malicious code in @httttt/mcp-demo (npm) Affected packages: npm/@httttt/mcp-demo Attributes: No fix available
最高第 1 名12:11 达到12:11 首次观测上榜16:31 观测离榜累计约4小时21分 - 18MAL-2026-14318 · Malicious code in frenchworldcupwin (npm)
Malicious code in frenchworldcupwin (npm) Affected packages: npm/frenchworldcupwin Attributes: No fix available
最高第 1 名21:51 达到21:51 首次观测上榜22:23 观测离榜累计约32分钟 - 19MINI-24v5-f78r-9mrh · MinimOS/vsphere-csi-syncer-3.6
Affected packages: MinimOS/vsphere-csi-syncer-3.6 Attributes: Fix available
最高第 1 名10:35 达到10:35 首次观测上榜16:31 观测离榜累计约5小时57分 - 20MINI-3gjg-jhpc-m385 · MinimOS/mongodb-kubernetes-operator-fips
Affected packages: MinimOS/mongodb-kubernetes-operator-fips、MinimOS/mongodb-kubernetes-operator-fips-readinessprobe、MinimOS/mongodb-kubernetes-operator-fips-version-upgrade-post-start-hook Attributes: No fix available
最高第 1 名00:59 达到00:59 首次观测上榜01:15 观测离榜累计约16分钟 - 21MINI-7rx8-q2m6-h29q · MinimOS/flipt-fips-1
Affected packages: MinimOS/flipt-fips-1 Attributes: No fix available
最高第 1 名20:31 达到20:31 首次观测上榜21:35 观测离榜累计约1小时4分 - 22MINI-87x8-mvhv-v254 · MinimOS/kubevirt-virt-controller-fips-1.6
Affected packages: MinimOS/kubevirt-virt-controller-fips-1.6 Attributes: No fix available
最高第 1 名00:27 达到00:27 首次观测上榜00:43 观测离榜累计约16分钟 - 23MINI-cgx7-3gv8-hp2g · MinimOS/redpanda-25.1-fips
Affected packages: MinimOS/redpanda-25.1-fips Attributes: No fix available
最高第 1 名01:15 达到01:15 首次观测上榜01:31 观测离榜累计约16分钟 - 24MINI-f4r5-jw8h-8qc6 · MinimOS/knative-net-kourier-fips-1.21
Affected packages: MinimOS/knative-net-kourier-fips-1.21 Attributes: No fix available
最高第 1 名00:11 达到00:11 首次观测上榜00:27 观测离榜累计约16分钟 - 25MINI-p7w2-7pqg-57f2 · MinimOS/weaviate-fips-1.36
Affected packages: MinimOS/weaviate-fips-1.36 Attributes: No fix available
最高第 1 名01:47 达到01:47 首次观测上榜03:39 观测离榜累计约1小时52分 - 26MINI-rwhc-r5fm-rcf5 · MinimOS/percona-server-8.0
Affected packages: MinimOS/percona-server-8.0、MinimOS/percona-server-8.0-client、MinimOS/percona-server-8.0-dev、MinimOS/percona-server-8.0-doc、MinimOS/percona-server-8.0-shared Attributes: No fix available
最高第 1 名04:27 达到04:27 首次观测上榜07:23 观测离榜累计约2小时56分 - 27MINI-rx8h-rv8x-vjjx · MinimOS/loki-fips-3.5
Affected packages: MinimOS/loki-fips-3.5、MinimOS/loki-fips-3.5-canary、MinimOS/loki-fips-3.5-logcli、MinimOS/loki-fips-3.5-promtail Attributes: No fix available
最高第 1 名00:43 达到00:43 首次观测上榜01:15 观测离榜累计约32分钟 - 28MINI-wj2w-rch3-95v7 · MinimOS/ingress-nginx-controller-fips-1.15
Affected packages: MinimOS/ingress-nginx-controller-fips-1.15、MinimOS/ingress-nginx-custom-error-pages-fips-1.15 Attributes: No fix available
最高第 1 名00:00 达到当日首次采集时已在榜00:11 观测离榜累计约11分钟 - 29OESA-2026-3490 · sqlite security update
sqlite security update Affected packages: openEuler:20.03-LTS-SP4/sqlite、openEuler:22.03-LTS-SP4/sqlite、openEuler:24.03-LTS-SP1/sqlite、openEuler:24.03-LTS-SP3/sqlite、openEuler:24.03-LTS-SP4/sqlite Attributes: Fix available、Severity - 6.1 (Medium)
最高第 1 名18:23 达到18:23 首次观测上榜18:55 观测离榜累计约32分钟 - 30RHSA-2026:57417 · Red Hat Security Advisory: yelp security update
Red Hat Security Advisory: yelp security update Affected packages: Red Hat:rhel_els:7/yelp、Red Hat:rhel_els:7/yelp-debuginfo、Red Hat:rhel_els:7/yelp-devel、Red Hat:rhel_els:7/yelp-libs Attributes: Fix available、Severity - 7.1 (High)
最高第 1 名18:55 达到18:55 首次观测上榜20:47 观测离榜累计约1小时52分 - 31RLSA-2026:55787 · Moderate: java-21-openjdk security update
Moderate: java-21-openjdk security update Affected packages: Rocky Linux:8/java-21-openjdk Attributes: Fix available、Severity - 6.8 (Medium)
最高第 1 名14:34 达到14:34 首次观测上榜16:31 观测离榜累计约1小时57分 - 32RLSA-2026:56936 · Important: mysql:8.4 security, bug fix, and enhancement update
Important: mysql:8.4 security, bug fix, and enhancement update Affected packages: Rocky Linux:8/mecab、Rocky Linux:8/mecab-ipadic Attributes: Fix available、Severity - 8.4 (High)
最高第 1 名02:35 达到02:35 首次观测上榜03:39 观测离榜累计约1小时4分 - 33RLSA-2026:56973 · Important: mysql:8.4 security, bug fix, and enhancement update
Important: mysql:8.4 security, bug fix, and enhancement update Affected packages: Rocky Linux:9/mecab、Rocky Linux:9/mecab-ipadic、Rocky Linux:9/perl-DBD-MySQL、Rocky Linux:9/rapidjson Attributes: Fix available、Severity - 8.4 (High)
最高第 1 名08:42 达到08:42 首次观测上榜10:35 观测离榜累计约1小时52分 - 34ROOT-OS-DEBIAN-11-CVE-2023-34152 · CVE-2023-34152 in imagemagick - Patched by Root
CVE-2023-34152 in imagemagick - Patched by Root Affected packages: Root:Debian:11/imagemagick、Root:Debian:11/rootio-imagemagick Attributes: Fix available、Severity - 9.8 (Critical)
最高第 1 名23:27 达到23:27 首次观测上榜当日结束时仍在榜累计约32分钟 - 35ROOT-OS-DEBIAN-11-CVE-2025-30258 · CVE-2025-30258 in gnupg2 - Patched by Root
CVE-2025-30258 in gnupg2 - Patched by Root Affected packages: Root:Debian:11/gnupg2、Root:Debian:11/rootio-gnupg2 Attributes: Fix available、Severity - 4.7 (Medium)
最高第 1 名21:35 达到21:35 首次观测上榜22:23 观测离榜累计约48分钟 - 36ROOT-OS-UBUNTU-2404-CVE-2021-31879 · CVE-2021-31879 in wget - Patched by Root
CVE-2021-31879 in wget - Patched by Root Affected packages: Root:Ubuntu:24.04/rootio-wget、Root:Ubuntu:24.04/wget Attributes: Fix available
最高第 1 名16:31 达到16:31 首次观测上榜18:23 观测离榜累计约1小时52分 - 37DEBIAN-CVE-2026-54330 · Debian:11/ceph
Affected packages: Debian:11/ceph、Debian:12/ceph、Debian:13/ceph、Debian:14/ceph Attributes: No fix available
最高第 2 名18:07 达到18:07 首次观测上榜18:23 观测离榜累计约16分钟 - 38ECHO-8a36-8d53-bf0c · Echo/expat
Affected packages: Echo/expat Attributes: No fix available
最高第 2 名21:19 达到21:19 首次观测上榜22:23 观测离榜累计约1小时4分 - 39EEF-CVE-2026-73541 · Tempo fee sponsorship in mpp bounds each transaction but not aggregate exposure, allowing concurrent sponsor-wallet drain
Tempo fee sponsorship in mpp bounds each transaction but not aggregate exposure, allowing concurrent sponsor-wallet drain Affected packages: Hex/mpp、github.com/zenhive/mpp Attributes: Fix available、Severity - 8.3 (High)
最高第 2 名01:31 达到01:31 首次观测上榜01:47 观测离榜累计约16分钟 - 40GHSA-2c9q-c2q9-qgqv · langgraph-api: Relative webhook targets in LangGraph Server can reach in-process routes without authentication
langgraph-api: Relative webhook targets in LangGraph Server can reach in-process routes without authentication Affected packages: PyPI/langgraph-api Attributes: Fix available、Severity - 5.9 (Medium)
最高第 2 名03:23 达到03:23 首次观测上榜03:39 观测离榜累计约16分钟 - 41GHSA-72x6-4j93-7w86 · BuildKit has a possible runtime DoS via unbounded group parsing
BuildKit has a possible runtime DoS via unbounded group parsing Affected packages: Go/github.com/moby/buildkit Attributes: Fix available、Severity - 2.3 (Low)
最高第 2 名04:43 达到04:43 首次观测上榜10:35 观测离榜累计约5小时52分 - 42GHSA-8mq9-5fw2-5rm4 · Tina: Broken Access Control: arbitrary bucket-key write/delete in `next-tinacms-s3` (and sibling production media adapters)
Tina: Broken Access Control: arbitrary bucket-key write/delete in `next-tinacms-s3` (and sibling production media adapters) Affected packages: npm/next-tinacms-azure、npm/next-tinacms-cloudinary、npm/next-tinacms-dos、npm/next-tinacms-s3 Attributes: Fix available、Severity - 5.4 (Medium)
最高第 2 名06:03 达到06:03 首次观测上榜10:35 观测离榜累计约4小时32分 - 43GHSA-q87f-qc2r-2gw4 · SearXNG MCP Server is Vulnerable to SSRF in web_url_read: the internal-address guard is disabled by default (MCP_HTTP_HARDEN off)
SearXNG MCP Server is Vulnerable to SSRF in web_url_read: the internal-address guard is disabled by default (MCP_HTTP_HARDEN off) Affected packages: npm/mcp-searxng Attributes: Fix available、Severity - 6.5 (Medium)
最高第 2 名03:39 达到03:39 首次观测上榜04:27 观测离榜累计约48分钟 - 44GHSA-vwg3-w8w3-pc79 · Grav: .htaccess file extension rules bypass via case variation on case-insensitive filesystems
Grav: .htaccess file extension rules bypass via case variation on case-insensitive filesystems Affected packages: Packagist/getgrav/grav Attributes: Fix available、Severity - 8.2 (High)
最高第 2 名03:55 达到03:55 首次观测上榜04:27 观测离榜累计约32分钟 - 45MAL-2026-14303 · Malicious code in x6842179305 (npm)
Malicious code in x6842179305 (npm) Affected packages: npm/x6842179305 Attributes: No fix available
最高第 2 名02:35 达到02:35 首次观测上榜03:39 观测离榜累计约1小时4分 - 46MAL-2026-14306 · Malicious code in rc4-secure (PyPI)
Malicious code in rc4-secure (PyPI) Affected packages: PyPI/rc4-secure Attributes: No fix available
最高第 2 名05:31 达到05:31 首次观测上榜10:35 观测离榜累计约5小时4分 - 47MAL-2026-14308 · Malicious code in libasync (PyPI)
Malicious code in libasync (PyPI) Affected packages: PyPI/libasync Attributes: No fix available
最高第 2 名07:23 达到07:23 首次观测上榜10:35 观测离榜累计约3小时12分 - 48MAL-2026-14316 · Malicious code in expect-dotenv (npm)
Malicious code in expect-dotenv (npm) Affected packages: npm/expect-dotenv Attributes: No fix available
最高第 2 名12:11 达到12:11 首次观测上榜16:31 观测离榜累计约4小时21分 - 49MAL-2026-14319 · Malicious code in test-flow-1 (npm)
Malicious code in test-flow-1 (npm) Affected packages: npm/test-flow-1 Attributes: No fix available
最高第 2 名21:51 达到21:51 首次观测上榜22:23 观测离榜累计约32分钟 - 50MINI-2c52-936r-3x88 · MinimOS/prometheus-node-exporter-fips-1.9
Affected packages: MinimOS/prometheus-node-exporter-fips-1.9 Attributes: No fix available
最高第 2 名01:15 达到01:15 首次观测上榜01:31 观测离榜累计约16分钟


































































































