全部/科技/实时热榜

OSV.dev · 实时热榜

HISTORY2026年8月31日202 不同热搜
08/0309/01 有历史数据
DAILY UNIQUE TOPICS202 个热搜
  1. 01
    BIT-keycloak-2026-18573 · Keycloak-services: keycloak-services: client access-type policy condition bypass during client update

    Keycloak-services: keycloak-services: client access-type policy condition bypass during client update Affected packages: Bitnami/keycloak Attributes: Fix available、Severity - 6.5 (Medium)

    最高第 123:24 达到23:24 首次观测上榜当日结束时仍在榜累计约20分钟
  2. 02
    BIT-python-2026-15310 · zipfile: bzip2/LZMA/Zstandard members decompress without a max_length bound, defeating chunked-read memory limits

    zipfile: bzip2/LZMA/Zstandard members decompress without a max_length bound, defeating chunked-read memory limits Affected packages: Bitnami/python Attributes: No fix available、Severity - 2.1 (Low)

    最高第 119:24 达到19:24 首次观测上榜20:44 观测离榜累计约1小时20分
  3. 03
    BIT-tomcat-2026-73180 · Apache Tomcat: Authenticated WebSocket session survives end of HTTP session

    Apache Tomcat: Authenticated WebSocket session survives end of HTTP session Affected packages: Bitnami/tomcat Attributes: Fix available、Severity - 6.8 (Medium)

    最高第 117:00 达到17:00 首次观测上榜18:20 观测离榜累计约1小时20分
  4. 04
    DEBIAN-CVE-2026-19873 · Debian:11/libhtml-formfu-perl

    Affected packages: Debian:11/libhtml-formfu-perl、Debian:12/libhtml-formfu-perl、Debian:13/libhtml-formfu-perl、Debian:14/libhtml-formfu-perl Attributes: No fix available

    最高第 120:12 达到20:12 首次观测上榜21:32 观测离榜累计约1小时20分
  5. 05
    DEBIAN-CVE-2026-82623 · Debian:13/open62541

    Affected packages: Debian:13/open62541、Debian:14/open62541 Attributes: No fix available

    最高第 119:08 达到19:08 首次观测上榜20:44 观测离榜累计约1小时36分
  6. 06
    ECHO-0030-65ec-f55d · Echo/keycloak-25

    Affected packages: Echo/keycloak-25 Attributes: Fix available

    最高第 101:32 达到01:32 首次观测上榜05:00 观测离榜累计约3小时28分
  7. 07
    EEF-CVE-2026-75760 · AshAi vectorize change leaks raw embedding-provider errors, including credentials, in a user-facing error

    AshAi vectorize change leaks raw embedding-provider errors, including credentials, in a user-facing error Affected packages: Hex/ash_ai、github.com/ash-project/ash_ai Attributes: Fix available、Severity - 7.1 (High)

    最高第 109:16 达到09:16 首次观测上榜10:52 观测离榜累计约1小时36分
  8. 08
    EEF-CVE-2026-78693 · Incomplete redaction re-attaches the original error path in AshGraphql, leaking internal field names

    Incomplete redaction re-attaches the original error path in AshGraphql, leaking internal field names Affected packages: Hex/ash_graphql、github.com/ash-project/ash_graphql Attributes: Fix available、Severity - 6.9 (Medium)

    最高第 102:36 达到02:36 首次观测上榜05:00 观测离榜累计约2小时24分
  9. 09
    EEF-CVE-2026-78699 · rename_tenant returns :ok on a failed rename, enabling cross-tenant access in AshPostgres

    rename_tenant returns :ok on a failed rename, enabling cross-tenant access in AshPostgres Affected packages: Hex/ash_postgres、github.com/ash-project/ash_postgres Attributes: Fix available、Severity - 7.2 (High)

    最高第 100:00 达到当日首次采集时已在榜01:32 观测离榜累计约1小时33分
  10. 10
    EEF-CVE-2026-81315 · MCP DNS-rebinding origin check in AshAi is bypassed by a spoofed X-Forwarded-Proto header

    MCP DNS-rebinding origin check in AshAi is bypassed by a spoofed X-Forwarded-Proto header Affected packages: Hex/ash_ai、github.com/ash-project/ash_ai Attributes: Fix available、Severity - 7.4 (High)

    最高第 109:00 达到09:00 首次观测上榜10:52 观测离榜累计约1小时52分
  11. 11
    EEF-CVE-2026-81322 · Cloaked plaintext leaks through a non-sensitive action argument in AshCloak

    Cloaked plaintext leaks through a non-sensitive action argument in AshCloak Affected packages: Hex/ash_cloak、github.com/ash-project/ash_cloak Attributes: Fix available、Severity - 2.1 (Low)

    最高第 102:20 达到02:20 首次观测上榜05:00 观测离榜累计约2小时40分
  12. 12
    EEF-CVE-2026-81852 · AshAdmin ships a hardcoded CSP nonce, allowing nonce-based CSP bypass

    AshAdmin ships a hardcoded CSP nonce, allowing nonce-based CSP bypass Affected packages: Hex/ash_admin、github.com/ash-project/ash_admin Attributes: Fix available、Severity - 2.1 (Low)

    最高第 110:36 达到10:36 首次观测上榜14:52 观测离榜累计约4小时16分
  13. 13
    EEF-CVE-2026-82673 · Path traversal in AshAdmin file uploads via unsanitized client filename

    Path traversal in AshAdmin file uploads via unsanitized client filename Affected packages: Hex/ash_admin、github.com/ash-project/ash_admin Attributes: Fix available、Severity - 8.3 (High)

    最高第 110:52 达到10:52 首次观测上榜16:12 观测离榜累计约5小时20分
  14. 14
    EEF-CVE-2026-82725 · AshPhoenix FilterForm allows filtering across non-public relationships, disclosing private related data

    AshPhoenix FilterForm allows filtering across non-public relationships, disclosing private related data Affected packages: Hex/ash_phoenix、github.com/ash-project/ash_phoenix Attributes: Fix available、Severity - 2.3 (Low)

    最高第 111:24 达到11:24 首次观测上榜17:00 观测离榜累计约5小时36分
  15. 15
    MAL-2026-15588 · Malicious code in tronlinker (PyPI)

    Malicious code in tronlinker (PyPI) Affected packages: PyPI/tronlinker Attributes: No fix available

    最高第 106:36 达到06:36 首次观测上榜10:52 观测离榜累计约4小时16分
  16. 16
    MAL-2026-15603 · Malicious code in pyservercheck (PyPI)

    Malicious code in pyservercheck (PyPI) Affected packages: PyPI/pyservercheck Attributes: No fix available

    最高第 113:32 达到13:32 首次观测上榜17:00 观测离榜累计约3小时28分
  17. 17
    MINI-phfw-96xm-7673 · MinimOS/argocd-3.5

    Affected packages: MinimOS/argocd-3.5、MinimOS/argocd-3.5-compat Attributes: Fix available

    最高第 104:44 达到04:44 首次观测上榜05:00 观测离榜累计约16分钟
  18. 18
    MINI-xq4r-f6jg-86x6 · MinimOS/weaviate-1.39

    Affected packages: MinimOS/weaviate-1.39 Attributes: Fix available

    最高第 105:00 达到05:00 首次观测上榜10:52 观测离榜累计约5小时52分
  19. 19
    RHSA-2026:61313 · Red Hat Security Advisory: rhc security update

    Red Hat Security Advisory: rhc security update Affected packages: Red Hat:enterprise_linux_eus:10.0/rhc、Red Hat:enterprise_linux_eus:10.0/rhc-debuginfo、Red Hat:enterprise_linux_eus:10.0/rhc-debugsource Attributes: Fix available、Severity - 8.8 (High)

    最高第 118:20 达到18:20 首次观测上榜19:40 观测离榜累计约1小时20分
  20. 20
    RLSA-2026:61240 · Moderate: pipewire security update

    Moderate: pipewire security update Affected packages: Rocky Linux:9/pipewire Attributes: Fix available、Severity - 6.5 (Medium)

    最高第 120:44 达到20:44 首次观测上榜21:32 观测离榜累计约48分钟
  21. 21
    ROOT-APP-MAVEN-AIKIDO-2026-61483 · AIKIDO-2026-61483 in spring-security-oauth2-jose - Patched by Root

    AIKIDO-2026-61483 in spring-security-oauth2-jose - Patched by Root Affected packages: Root:Maven/io.root.spring-security-oauth2-jose、Root:Maven/spring-security-oauth2-jose Attributes: Fix available

    最高第 122:20 达到22:20 首次观测上榜23:24 观测离榜累计约1小时4分
  22. 22
    ROOT-APP-NPM-CVE-2026-23745 · CVE-2026-23745 in tar - Patched by Root

    CVE-2026-23745 in tar - Patched by Root Affected packages: Root:npm/@rootio/tar、Root:npm/tar Attributes: Fix available、Severity - 6.1 (Medium)

    最高第 117:16 达到17:16 首次观测上榜18:20 观测离榜累计约1小时4分
  23. 23
    ROOT-OS-ALPINE-318-CVE-2025-29087 · CVE-2025-29087 in sqlite - Patched by Root

    CVE-2025-29087 in sqlite - Patched by Root Affected packages: Root:Alpine:3.18/rootio-sqlite、Root:Alpine:3.18/sqlite Attributes: Fix available、Severity - 7.5 (High)

    最高第 114:52 达到14:52 首次观测上榜17:16 观测离榜累计约2小时24分
  24. 24
    ROOT-OS-ALPINE-320-CVE-2026-1642 · CVE-2026-1642 in nginx - Patched by Root

    CVE-2026-1642 in nginx - Patched by Root Affected packages: Root:Alpine:3.20/nginx、Root:Alpine:3.20/rootio-nginx Attributes: Fix available

    最高第 119:40 达到19:40 首次观测上榜21:32 观测离榜累计约1小时52分
  25. 25
    ROOT-OS-DEBIAN-12-CVE-2026-63382 · CVE-2026-63382 in libevent - Patched by Root

    CVE-2026-63382 in libevent - Patched by Root Affected packages: Root:Debian:12/libevent、Root:Debian:12/rootio-libevent Attributes: Fix available

    最高第 121:32 达到21:32 首次观测上榜22:20 观测离榜累计约48分钟
  26. 26
    BIT-keycloak-2026-18572 · Keycloak-services: keycloak-services: uma claim token can override authorization time-policy evaluation attributes

    Keycloak-services: keycloak-services: uma claim token can override authorization time-policy evaluation attributes Affected packages: Bitnami/keycloak Attributes: Fix available、Severity - 6.5 (Medium)

    最高第 223:24 达到23:24 首次观测上榜当日结束时仍在榜累计约20分钟
  27. 27
    BIT-python-min-2026-15310 · zipfile: bzip2/LZMA/Zstandard members decompress without a max_length bound, defeating chunked-read memory limits

    zipfile: bzip2/LZMA/Zstandard members decompress without a max_length bound, defeating chunked-read memory limits Affected packages: Bitnami/python-min Attributes: No fix available、Severity - 2.1 (Low)

    最高第 219:24 达到19:24 首次观测上榜20:44 观测离榜累计约1小时20分
  28. 28
    BIT-tomcat-2026-68763 · Apache Tomcat: DoS via allocation leak in HTTP/2 backlog tracking when a stream is reset

    Apache Tomcat: DoS via allocation leak in HTTP/2 backlog tracking when a stream is reset Affected packages: Bitnami/tomcat Attributes: Fix available、Severity - 7.5 (High)

    最高第 217:00 达到17:00 首次观测上榜18:20 观测离榜累计约1小时20分
  29. 29
    ECHO-12de-2dca-d7dc · Echo/keycloak-25

    Affected packages: Echo/keycloak-25 Attributes: Fix available

    最高第 201:32 达到01:32 首次观测上榜05:00 观测离榜累计约3小时28分
  30. 30
    EEF-CVE-2026-77956 · EEx template evaluation of prompt content in AshAi enables remote code execution

    EEx template evaluation of prompt content in AshAi enables remote code execution Affected packages: Hex/ash_ai、github.com/ash-project/ash_ai Attributes: Fix available、Severity - 10.0 (Critical)

    最高第 209:00 达到09:00 首次观测上榜10:52 观测离榜累计约1小时52分
  31. 31
    EEF-CVE-2026-80223 · Cross-tenant subscription disclosure in AshGraphql authorizes notifications in memory without a tenant-scoped read

    Cross-tenant subscription disclosure in AshGraphql authorizes notifications in memory without a tenant-scoped read Affected packages: Hex/ash_graphql、github.com/ash-project/ash_graphql Attributes: Fix available、Severity - 7.1 (High)

    最高第 202:36 达到02:36 首次观测上榜05:00 观测离榜累计约2小时24分
  32. 32
    EEF-CVE-2026-81319 · Unsafe deserialization of decrypted terms enables node DoS in AshCloak

    Unsafe deserialization of decrypted terms enables node DoS in AshCloak Affected packages: Hex/ash_cloak、github.com/ash-project/ash_cloak Attributes: Fix available、Severity - 5.9 (Medium)

    最高第 202:20 达到02:20 首次观测上榜05:00 观测离榜累计约2小时40分
  33. 33
    EEF-CVE-2026-81853 · AshAdmin composite primary key decoding accepts arbitrary fields, enabling a secret-attribute oracle

    AshAdmin composite primary key decoding accepts arbitrary fields, enabling a secret-attribute oracle Affected packages: Hex/ash_admin、github.com/ash-project/ash_admin Attributes: Fix available、Severity - 2.3 (Low)

    最高第 210:52 达到10:52 首次观测上榜16:12 观测离榜累计约5小时20分
  34. 34
    EEF-CVE-2026-82580 · AshAi echoes raw tool exception messages into the conversation, disclosing internal details

    AshAi echoes raw tool exception messages into the conversation, disclosing internal details Affected packages: Hex/ash_ai、github.com/ash-project/ash_ai Attributes: Fix available、Severity - 5.3 (Medium)

    最高第 209:16 达到09:16 首次观测上榜10:52 观测离榜累计约1小时36分
  35. 35
    EEF-CVE-2026-82681 · Query-parameter injection in AshAdmin row-action links via unencoded string primary keys

    Query-parameter injection in AshAdmin row-action links via unencoded string primary keys Affected packages: Hex/ash_admin、github.com/ash-project/ash_admin Attributes: Fix available、Severity - 2.0 (Low)

    最高第 210:36 达到10:36 首次观测上榜14:52 观测离榜累计约4小时16分
  36. 36
    EEF-CVE-2026-82724 · Broken access control in AshPhoenix SubdomainHook via a nil tenant in handle_subdomain

    Broken access control in AshPhoenix SubdomainHook via a nil tenant in handle_subdomain Affected packages: Hex/ash_phoenix、github.com/ash-project/ash_phoenix Attributes: Fix available、Severity - 7.6 (High)

    最高第 211:24 达到11:24 首次观测上榜17:00 观测离榜累计约5小时36分
  37. 37
    MINI-2p7v-w6j4-569m · MinimOS/vela-core-1.10

    Affected packages: MinimOS/vela-core-1.10 Attributes: Fix available

    最高第 205:00 达到05:00 首次观测上榜10:52 观测离榜累计约5小时52分
  38. 38
    MINI-9c4q-8wfr-435f · MinimOS/amazon-cloudwatch-agent

    Affected packages: MinimOS/amazon-cloudwatch-agent Attributes: Fix available

    最高第 204:44 达到04:44 首次观测上榜05:00 观测离榜累计约16分钟
  39. 39
    MINI-m826-28qr-7wcw · MinimOS/weaviate-fips-1.38

    Affected packages: MinimOS/weaviate-fips-1.38 Attributes: Fix available

    最高第 200:00 达到当日首次采集时已在榜01:32 观测离榜累计约1小时33分
  40. 40
    RHSA-2026:61261 · Red Hat Security Advisory: sg3_utils security, bug fix, and enhancement update

    Red Hat Security Advisory: sg3_utils security, bug fix, and enhancement update Affected packages: Red Hat:rhel_e4s:9.2::baseos/sg3_utils、Red Hat:rhel_e4s:9.2::baseos/sg3_utils-debuginfo、Red Hat:rhel_e4s:9.2::baseos/sg3_utils-debugsource、Red Hat:rhel_e4s:9.2::baseos/sg3_utils-libs、Red Hat:rhel_e4s:9.2::baseos/sg3_utils-libs-debuginfo Attributes: Fix available、Severity - 7.6 (High)

    最高第 218:20 达到18:20 首次观测上榜19:40 观测离榜累计约1小时20分
  41. 41
    RLSA-2026:61247 · Moderate: libxml2 security update

    Moderate: libxml2 security update Affected packages: Rocky Linux:9/libxml2 Attributes: Fix available、Severity - 5.9 (Medium)

    最高第 220:44 达到20:44 首次观测上榜21:32 观测离榜累计约48分钟
  42. 42
    ROOT-APP-NPM-CVE-2024-43414 · CVE-2024-43414 in @apollo/gateway - Patched by Root

    CVE-2024-43414 in @apollo/gateway - Patched by Root Affected packages: Root:npm/@apollo/gateway、Root:npm/@apollo/query-planner、Root:npm/@rootio/apollo__gateway、Root:npm/@rootio/apollo__query-planner Attributes: Fix available

    最高第 222:20 达到22:20 首次观测上榜23:24 观测离榜累计约1小时4分
  43. 43
    ROOT-APP-NPM-CVE-2026-23950 · CVE-2026-23950 in tar - Patched by Root

    CVE-2026-23950 in tar - Patched by Root Affected packages: Root:npm/@rootio/tar、Root:npm/tar Attributes: Fix available、Severity - 8.8 (High)

    最高第 217:16 达到17:16 首次观测上榜18:20 观测离榜累计约1小时4分
  44. 44
    ROOT-OS-ALPINE-318-CVE-2026-11824 · CVE-2026-11824 in sqlite - Patched by Root

    CVE-2026-11824 in sqlite - Patched by Root Affected packages: Root:Alpine:3.18/rootio-sqlite、Root:Alpine:3.18/sqlite Attributes: Fix available

    最高第 214:52 达到14:52 首次观测上榜17:16 观测离榜累计约2小时24分
  45. 45
    ROOT-OS-ALPINE-320-CVE-2026-27651 · CVE-2026-27651 in nginx - Patched by Root

    CVE-2026-27651 in nginx - Patched by Root Affected packages: Root:Alpine:3.20/nginx、Root:Alpine:3.20/rootio-nginx Attributes: Fix available

    最高第 219:40 达到19:40 首次观测上榜21:32 观测离榜累计约1小时52分
  46. 46
    ROOT-OS-DEBIAN-12-CVE-2026-63383 · CVE-2026-63383 in libevent - Patched by Root

    CVE-2026-63383 in libevent - Patched by Root Affected packages: Root:Debian:12/libevent、Root:Debian:12/rootio-libevent Attributes: Fix available

    最高第 221:32 达到21:32 首次观测上榜22:20 观测离榜累计约48分钟
  47. 47
    BIT-keycloak-2026-18571 · Keycloak-services: keycloak-services: fgap v2 group assignment bypass during user creation

    Keycloak-services: keycloak-services: fgap v2 group assignment bypass during user creation Affected packages: Bitnami/keycloak Attributes: Fix available、Severity - 7.2 (High)

    最高第 323:24 达到23:24 首次观测上榜当日结束时仍在榜累计约20分钟
  48. 48
    BIT-kibana-2026-78581 · Authorization Bypass Through User-Controlled Key in Kibana Leading to Unauthorized Data Modification in Kibana

    Authorization Bypass Through User-Controlled Key in Kibana Leading to Unauthorized Data Modification in Kibana Affected packages: Bitnami/kibana Attributes: Fix available、Severity - 4.2 (Medium)

    最高第 316:12 达到16:12 首次观测上榜17:16 观测离榜累计约1小时4分
  49. 49
    BIT-tomcat-2026-68569 · Apache Tomcat: Principal lookup can fail open in some cases

    Apache Tomcat: Principal lookup can fail open in some cases Affected packages: Bitnami/tomcat Attributes: Fix available、Severity - 8.1 (High)

    最高第 317:00 达到17:00 首次观测上榜18:20 观测离榜累计约1小时20分
  50. 50
    ECHO-1814-da4f-7983 · Echo/keycloak-25

    Affected packages: Echo/keycloak-25 Attributes: Fix available

    最高第 301:32 达到01:32 首次观测上榜05:00 观测离榜累计约3小时28分