
OSV.dev · 实时热榜
- 01BELL-CVE-2026-80589 · Alpaquita:23/linux-lts
Affected packages: Alpaquita:23/linux-lts、Alpaquita:25/linux-lts、Alpaquita:stream/linux-lts Attributes: Fix available、Severity - 9.8 (Critical)
最高第 1 名15:25 达到15:25 首次观测上榜19:57 观测离榜累计约4小时32分 - 02BIT-gitlab-2026-10053 · Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GitLab
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GitLab Affected packages: Bitnami/gitlab Attributes: Fix available、Severity - 8.5 (High)
最高第 1 名00:00 达到当日首次采集时已在榜00:45 观测离榜累计约46分钟 - 03DEBIAN-CVE-2025-70292 · Debian:11/u-boot
Affected packages: Debian:11/u-boot、Debian:12/u-boot、Debian:13/u-boot、Debian:14/u-boot Attributes: No fix available
最高第 1 名16:13 达到16:13 首次观测上榜23:25 观测离榜累计约7小时12分 - 04DEBIAN-CVE-2026-59944 · Debian:11/composer
Affected packages: Debian:11/composer、Debian:12/composer、Debian:13/composer、Debian:14/composer Attributes: No fix available
最高第 1 名14:05 达到14:05 首次观测上榜15:25 观测离榜累计约1小时20分 - 05DEBIAN-CVE-2026-80725 · Debian:12/linux
Affected packages: Debian:12/linux、Debian:13/linux、Debian:14/linux Attributes: Fix available
最高第 1 名18:05 达到18:05 首次观测上榜23:25 观测离榜累计约5小时20分 - 06GHSA-2vh6-hw4j-32ww · gix-packetline: reachable panic on empty side-band packet (pre-auth network DoS)
gix-packetline: reachable panic on empty side-band packet (pre-auth network DoS) Affected packages: crates.io/gix-packetline Attributes: Fix available、Severity - 6.5 (Medium)
最高第 1 名00:29 达到00:29 首次观测上榜00:45 观测离榜累计约16分钟 - 07GHSA-44v6-7fxq-vgf4 · Vikunja has an incomplete fix for CVE-2026-35595: Write-only user can detach shared project from parent hierarchy via parent_project_id=0
Vikunja has an incomplete fix for CVE-2026-35595: Write-only user can detach shared project from parent hierarchy via parent_project_id=0 Affected packages: Go/code.vikunja.io/api Attributes: Fix available、Severity - 4.3 (Medium)
最高第 1 名00:45 达到00:45 首次观测上榜02:05 观测离榜累计约1小时20分 - 08GHSA-569v-q83c-3j3g · Vikunja vulnerable to authenticated cross-tenant kanban-bucket relocation via `project_view_id` mass-assignment
Vikunja vulnerable to authenticated cross-tenant kanban-bucket relocation via `project_view_id` mass-assignment Affected packages: Go/code.vikunja.io/api Attributes: Fix available、Severity - 5.0 (Medium)
最高第 1 名01:01 达到01:01 首次观测上榜02:21 观测离榜累计约1小时20分 - 09GHSA-64f3-v33m-w89f · Incus has a project restriction bypass for custom volume copy across projects
Incus has a project restriction bypass for custom volume copy across projects Affected packages: Go/github.com/lxc/incus、Go/github.com/lxc/incus/v6、Go/github.com/lxc/incus/v7 Attributes: Fix available、Severity - 7.7 (High)
最高第 1 名03:09 达到03:09 首次观测上榜03:57 观测离榜累计约48分钟 - 10GHSA-73mf-m39p-wpm9 · Yamcs vulnerable to Remote Code Execution via instance-template argument YAML injection (createInstance)
Yamcs vulnerable to Remote Code Execution via instance-template argument YAML injection (createInstance) Affected packages: Maven/org.yamcs:yamcs-core Attributes: Fix available、Severity - 9.8 (Critical)
最高第 1 名01:33 达到01:33 首次观测上榜02:21 观测离榜累计约48分钟 - 11GHSA-73p9-6hrp-8qhr · AIIR verification and policy gates could report success without enforcing the control (fail-open)
AIIR verification and policy gates could report success without enforcing the control (fail-open) Affected packages: PyPI/aiir Attributes: Fix available、Severity - 6.9 (Medium)
最高第 1 名03:41 达到03:41 首次观测上榜04:45 观测离榜累计约1小时4分 - 12GHSA-9272-wg2r-7xmx · Yamcs has DOM XSS in Extension Routing
Yamcs has DOM XSS in Extension Routing Affected packages: Maven/org.yamcs:yamcs-core Attributes: Fix available、Severity - 4.3 (Medium)
最高第 1 名01:49 达到01:49 首次观测上榜02:21 观测离榜累计约32分钟 - 13GHSA-f97c-ph8j-8vff · Pimcore: Insufficient Permission Check on Class Definition Creation Endpoint Allows Privilege Escalation
Pimcore: Insufficient Permission Check on Class Definition Creation Endpoint Allows Privilege Escalation Affected packages: Packagist/pimcore/studio-backend-bundle Attributes: Fix available、Severity - 7.1 (High)
最高第 1 名03:25 达到03:25 首次观测上榜03:57 观测离榜累计约32分钟 - 14GHSA-fc33-6w3q-538h · Snipe-IT has an authorization bypass on print inventory page
Snipe-IT has an authorization bypass on print inventory page Affected packages: Packagist/snipe/snipe-it Attributes: Fix available、Severity - 4.3 (Medium)
最高第 1 名02:05 达到02:05 首次观测上榜02:37 观测离榜累计约32分钟 - 15GHSA-fp46-6vfw-gc9c · free5GC AUSF uses non-constant-time authentication comparisons and logs XRES* in 5G-AKA
free5GC AUSF uses non-constant-time authentication comparisons and logs XRES* in 5G-AKA Affected packages: Go/github.com/free5gc/ausf Attributes: Fix available、Severity - 3.7 (Low)
最高第 1 名06:37 达到06:37 首次观测上榜07:41 观测离榜累计约1小时4分 - 16GHSA-fwww-cp23-7f5g · Yamcs's WebSocket subscription handlers omit the privilege checks their REST siblings enforce
Yamcs's WebSocket subscription handlers omit the privilege checks their REST siblings enforce Affected packages: Maven/org.yamcs:yamcs-core Attributes: Fix available、Severity - 6.5 (Medium)
最高第 1 名01:17 达到01:17 首次观测上榜02:21 观测离榜累计约1小时4分 - 17GHSA-g5xc-5w98-jfvm · MariaDB has possible SQL injection in Buffer parameter escaping under big5/gbk/sjis/cp932/gb18030 client charsets
MariaDB has possible SQL injection in Buffer parameter escaping under big5/gbk/sjis/cp932/gb18030 client charsets Affected packages: npm/mariadb Attributes: Fix available、Severity - 6.5 (Medium)
最高第 1 名07:09 达到07:09 首次观测上榜07:41 观测离榜累计约32分钟 - 18GHSA-g9jj-cgmh-9f38 · MariaDB has cleartext password disclosure to a MITM on the initial-handshake
MariaDB has cleartext password disclosure to a MITM on the initial-handshake Affected packages: Maven/org.mariadb.jdbc:mariadb-java-client Attributes: Fix available、Severity - 5.9 (Medium)
最高第 1 名06:53 达到06:53 首次观测上榜07:41 观测离榜累计约48分钟 - 19GHSA-gqr6-r77p-c2pj · Fortigate syslog message parser can be exploited to modify or delete fields from the original message
Fortigate syslog message parser can be exploited to modify or delete fields from the original message Affected packages: Maven/org.graylog2:graylog2-server Attributes: Fix available、Severity - 7.5 (High)
最高第 1 名06:21 达到06:21 首次观测上榜07:41 观测离榜累计约1小时20分 - 20GHSA-p378-jp5r-gpgw · arc has unauthenticated cluster node admission when `cluster.shared_secret` is unset
arc has unauthenticated cluster node admission when `cluster.shared_secret` is unset Affected packages: Go/github.com/basekick-labs/arc Attributes: Fix available、Severity - 6.9 (Medium)
最高第 1 名04:45 达到04:45 首次观测上榜07:09 观测离榜累计约2小时24分 - 21GHSA-q79r-r9xg-r863 · Graylog Server: System Catalog titles endpoint can be used to retrieve values of protected database fields
Graylog Server: System Catalog titles endpoint can be used to retrieve values of protected database fields Affected packages: Maven/org.graylog2:graylog2-server Attributes: Fix available、Severity - 5.0 (Medium)
最高第 1 名02:21 达到02:21 首次观测上榜03:09 观测离榜累计约48分钟 - 22GHSA-w98g-5w9p-p3rc · Bifrost's SSRF deny-list is incomplete: isPublicIP permits CGNAT, IPv6 6to4/NAT64, and site-local in FetchAndEncodeURL
Bifrost's SSRF deny-list is incomplete: isPublicIP permits CGNAT, IPv6 6to4/NAT64, and site-local in FetchAndEncodeURL Affected packages: Go/github.com/maximhq/bifrost/core Attributes: Fix available、Severity - 8.7 (High)
最高第 1 名02:37 达到02:37 首次观测上榜03:25 观测离榜累计约48分钟 - 23GHSA-wjmf-p669-5m5p · Protego has exponential backtracking ReDoS in robots.txt URL wildcard matching
Protego has exponential backtracking ReDoS in robots.txt URL wildcard matching Affected packages: PyPI/protego Attributes: Fix available、Severity - 7.1 (High)
最高第 1 名02:53 达到02:53 首次观测上榜03:57 观测离榜累计约1小时4分 - 24MAL-2026-15519 · Malicious code in qbo-ui-services (npm)
Malicious code in qbo-ui-services (npm) Affected packages: npm/qbo-ui-services Attributes: No fix available
最高第 1 名07:41 达到07:41 首次观测上榜07:57 观测离榜累计约16分钟 - 25MAL-2026-15544 · Malicious code in sentrykit (npm)
Malicious code in sentrykit (npm) Affected packages: npm/sentrykit Attributes: No fix available
最高第 1 名07:57 达到07:57 首次观测上榜10:37 观测离榜累计约2小时40分 - 26MAL-2026-15549 · Malicious code in ckeditor5-ckbox (npm)
Malicious code in ckeditor5-ckbox (npm) Affected packages: npm/ckeditor5-ckbox Attributes: No fix available
最高第 1 名10:37 达到10:37 首次观测上榜11:41 观测离榜累计约1小时4分 - 27MAL-2026-15566 · Malicious code in flask-header-guard (PyPI)
Malicious code in flask-header-guard (PyPI) Affected packages: PyPI/flask-header-guard Attributes: No fix available
最高第 1 名19:57 达到19:57 首次观测上榜23:41 观测离榜累计约3小时44分 - 28MINI-676g-m4jh-p2xh · MinimOS/plural-agent-harness
Affected packages: MinimOS/plural-agent-harness Attributes: Fix available
最高第 1 名17:49 达到17:49 首次观测上榜23:25 观测离榜累计约5小时36分 - 29MINI-695x-6c52-56wg · MinimOS/pluralsh-deployment-operator
Affected packages: MinimOS/pluralsh-deployment-operator Attributes: Fix available
最高第 1 名08:45 达到08:45 首次观测上榜10:37 观测离榜累计约1小时52分 - 30MINI-83px-p94x-qpj8 · MinimOS/cert-manager-cainjector-fips-1.17
Affected packages: MinimOS/cert-manager-cainjector-fips-1.17、MinimOS/cert-manager-controller-fips-1.17、MinimOS/cert-manager-fips-1.17、MinimOS/cert-manager-startupapicheck-fips-1.17、MinimOS/cert-manager-webhook-fips-1.17 Attributes: No fix available
最高第 1 名23:41 达到23:41 首次观测上榜当日结束时仍在榜累计约16分钟 - 31MINI-c566-jxgh-x5v8 · MinimOS/coredns-fips-1.13
Affected packages: MinimOS/coredns-fips-1.13、MinimOS/kuma-coredns-fips-1.13 Attributes: No fix available
最高第 1 名23:57 达到23:57 首次观测上榜当日结束时仍在榜累计约0分钟 - 32MINI-gpr6-w34p-hwwh · MinimOS/argocd-image-updater-fips-0
Affected packages: MinimOS/argocd-image-updater-fips-0 Attributes: No fix available
最高第 1 名23:25 达到23:25 首次观测上榜23:41 观测离榜累计约16分钟 - 33MINI-hx7v-m3r6-6mc9 · MinimOS/miniconda3
Affected packages: MinimOS/miniconda3 Attributes: Fix available
最高第 1 名11:41 达到11:41 首次观测上榜15:25 观测离榜累计约3小时44分 - 34MINI-whpr-9m6v-jq5h · MinimOS/litellm-1.82
Affected packages: MinimOS/litellm-1.82 Attributes: No fix available
最高第 1 名03:57 达到03:57 首次观测上榜06:37 观测离榜累计约2小时40分 - 35RHSA-2026:57986 · Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update
Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update Affected packages: Red Hat:hummingbird:1/ruby3.3、Red Hat:hummingbird:1/ruby3.3-default-gems Attributes: Fix available、Severity - 3.7 (Low)
最高第 1 名18:37 达到18:37 首次观测上榜23:41 观测离榜累计约5小时4分 - 36BELL-CVE-2026-80587 · Alpaquita:23/linux-lts
Affected packages: Alpaquita:23/linux-lts、Alpaquita:25/linux-lts、Alpaquita:stream/linux-lts Attributes: Fix available、Severity - 9.8 (Critical)
最高第 2 名15:25 达到15:25 首次观测上榜18:37 观测离榜累计约3小时12分 - 37BIT-tomcat-2026-65637 · Apache Tomcat: HTTP/2 no-authority bypass of strict SNI validation - CVE-2026-32990 fix incomplete
Apache Tomcat: HTTP/2 no-authority bypass of strict SNI validation - CVE-2026-32990 fix incomplete Affected packages: Bitnami/tomcat Attributes: Fix available、Severity - 9.8 (Critical)
最高第 2 名00:00 达到当日首次采集时已在榜00:45 观测离榜累计约46分钟 - 38DEBIAN-CVE-2025-70291 · Debian:11/u-boot
Affected packages: Debian:11/u-boot、Debian:12/u-boot、Debian:13/u-boot、Debian:14/u-boot Attributes: No fix available
最高第 2 名16:13 达到16:13 首次观测上榜23:25 观测离榜累计约7小时12分 - 39GHSA-298f-872v-2rcx · ORAS CLI: Cyclic Referrer Graph Can Cause Unbounded Recursion and Resource Consumption
ORAS CLI: Cyclic Referrer Graph Can Cause Unbounded Recursion and Resource Consumption Affected packages: Go/oras.land/oras Attributes: Fix available、Severity - 2.0 (Low)
最高第 2 名02:37 达到02:37 首次观测上榜03:25 观测离榜累计约48分钟 - 40GHSA-2q2q-jr9g-v9rf · Weblate has IDOR in GroupViewSet that allows authenticated project manager to gain unauthorized read access to any private project
Weblate has IDOR in GroupViewSet that allows authenticated project manager to gain unauthorized read access to any private project Affected packages: PyPI/weblate Attributes: Fix available、Severity - 8.1 (High)
最高第 2 名03:09 达到03:09 首次观测上榜03:57 观测离榜累计约48分钟 - 41GHSA-334q-h5g3-fpxv · free5GC AUSF authentication contexts can be overwritten by concurrent requests for the same SUPI
free5GC AUSF authentication contexts can be overwritten by concurrent requests for the same SUPI Affected packages: Go/github.com/free5gc/ausf Attributes: No fix available、Severity - 7.5 (High)
最高第 2 名06:37 达到06:37 首次观测上榜07:41 观测离榜累计约1小时4分 - 42GHSA-575r-357h-fhch · Snipe-IT vulnerable to cross-company asset maintenance re-parenting via API update
Snipe-IT vulnerable to cross-company asset maintenance re-parenting via API update Affected packages: Packagist/snipe/snipe-it Attributes: Fix available、Severity - 7.7 (High)
最高第 2 名02:21 达到02:21 首次观测上榜03:09 观测离榜累计约48分钟 - 43GHSA-5pg6-m483-7vrg · Vikunja has cross-tenant IDOR in kanban move-task endpoint via unauthorized body task_id
Vikunja has cross-tenant IDOR in kanban move-task endpoint via unauthorized body task_id Affected packages: Go/code.vikunja.io/api Attributes: Fix available、Severity - 7.1 (High)
最高第 2 名01:01 达到01:01 首次观测上榜02:05 观测离榜累计约1小时4分 - 44GHSA-79cw-hfcc-7mw9 · Pimcore: SQL Injection via Column Name in DateFilter allows authenticated user to extract arbitrary database data including admin password hashes
Pimcore: SQL Injection via Column Name in DateFilter allows authenticated user to extract arbitrary database data including admin password hashes Affected packages: Packagist/pimcore/studio-backend-bundle Attributes: Fix available、Severity - 7.7 (High)
最高第 2 名03:25 达到03:25 首次观测上榜03:57 观测离榜累计约32分钟 - 45GHSA-8x7x-83cf-c3pg · Hatchet allows cross-tenant write/DoS to other tenants' workers via Dispatcher gRPC UpsertWorkerLabels and Unsubscribe
Hatchet allows cross-tenant write/DoS to other tenants' workers via Dispatcher gRPC UpsertWorkerLabels and Unsubscribe Affected packages: Go/github.com/hatchet-dev/hatchet Attributes: Fix available、Severity - 6.4 (Medium)
最高第 2 名00:29 达到00:29 首次观测上榜00:45 观测离榜累计约16分钟 - 46GHSA-962x-ccwf-8x6p · Yamcs Core API has Multiple Missing Function Level Access Control vulnerabilities
Yamcs Core API has Multiple Missing Function Level Access Control vulnerabilities Affected packages: Maven/org.yamcs:yamcs-core Attributes: Fix available、Severity - 8.8 (High)
最高第 2 名01:17 达到01:17 首次观测上榜02:21 观测离榜累计约1小时4分 - 47GHSA-9jg3-g3wh-w9pj · Yamcs has Unauthenticated Directory Traversal
Yamcs has Unauthenticated Directory Traversal Affected packages: Maven/org.yamcs:yamcs-core Attributes: Fix available、Severity - 7.5 (High)
最高第 2 名01:33 达到01:33 首次观测上榜02:21 观测离榜累计约48分钟 - 48GHSA-c64q-hj4j-375f · Yamcs vulnerable to authenticated remote code execution via unescaped StreamSQL `LIKE` pattern compiled by Janino (`LikeExpression`)
Yamcs vulnerable to authenticated remote code execution via unescaped StreamSQL `LIKE` pattern compiled by Janino (`LikeExpression`) Affected packages: Maven/org.yamcs:yamcs-core Attributes: Fix available、Severity - 9.9 (Critical)
最高第 2 名01:49 达到01:49 首次观测上榜02:21 观测离榜累计约32分钟 - 49GHSA-f27p-pw2p-9pr4 · Vikunja has a project duplication bypasses write-permission check on the target parent project
Vikunja has a project duplication bypasses write-permission check on the target parent project Affected packages: Go/code.vikunja.io/api Attributes: Fix available、Severity - 5.3 (Medium)
最高第 2 名00:45 达到00:45 首次观测上榜02:05 观测离榜累计约1小时20分 - 50GHSA-ffg3-p8fm-mjx2 · RestrictedPython guard hooks can be shadowed via positional-only arguments
RestrictedPython guard hooks can be shadowed via positional-only arguments Affected packages: PyPI/restrictedpython Attributes: Fix available、Severity - 8.3 (High)
最高第 2 名07:09 达到07:09 首次观测上榜07:41 观测离榜累计约32分钟


































































































