
OSV.dev · 实时热榜
- 01OESA-2026-3306 · bison security update
bison security update Affected packages: openEuler:24.03-LTS-SP3/bison Attributes: Fix available、Severity - 6.8 (Medium)
最高第 7 名11:15 达到11:15 首次观测上榜14:59 观测离榜累计约3小时44分 - 02OESA-2026-3307 · bison security update
bison security update Affected packages: openEuler:24.03-LTS-SP4/bison Attributes: Fix available、Severity - 6.8 (Medium)
最高第 6 名11:15 达到11:15 首次观测上榜14:59 观测离榜累计约3小时44分 - 03OESA-2026-3308 · librabbitmq security update
librabbitmq security update Affected packages: openEuler:20.03-LTS-SP4/librabbitmq、openEuler:22.03-LTS-SP4/librabbitmq、openEuler:24.03-LTS-SP1/librabbitmq、openEuler:24.03-LTS-SP3/librabbitmq、openEuler:24.03-LTS-SP4/librabbitmq Attributes: Fix available、Severity - 7.4 (High)
最高第 5 名11:15 达到11:15 首次观测上榜14:59 观测离榜累计约3小时44分 - 04OESA-2026-3309 · trafficserver security update
trafficserver security update Affected packages: openEuler:24.03-LTS-SP3/trafficserver Attributes: Fix available、Severity - 9.2 (Critical)
最高第 4 名11:15 达到11:15 首次观测上榜14:59 观测离榜累计约3小时44分 - 05OESA-2026-3310 · trafficserver security update
trafficserver security update Affected packages: openEuler:24.03-LTS-SP4/trafficserver Attributes: Fix available、Severity - 9.2 (Critical)
最高第 3 名11:15 达到11:15 首次观测上榜14:59 观测离榜累计约3小时44分 - 06OESA-2026-3311 · trafficserver security update
trafficserver security update Affected packages: openEuler:24.03-LTS-SP1/trafficserver Attributes: Fix available、Severity - 9.2 (Critical)
最高第 2 名11:15 达到11:15 首次观测上榜14:59 观测离榜累计约3小时44分 - 07OESA-2026-3312 · busybox security update
busybox security update Affected packages: openEuler:20.03-LTS-SP4/busybox、openEuler:22.03-LTS-SP4/busybox、openEuler:24.03-LTS-SP1/busybox、openEuler:24.03-LTS-SP3/busybox、openEuler:24.03-LTS-SP4/busybox Attributes: Fix available、Severity - 5.1 (Medium)
最高第 1 名11:15 达到11:15 首次观测上榜14:59 观测离榜累计约3小时44分 - 08GHSA-9p7c-v5x3-rfx8 · Craft CMS: Missing authorization check allows non-admin control panel users to reorder Global Sets
Craft CMS: Missing authorization check allows non-admin control panel users to reorder Global Sets Affected packages: Packagist/craftcms/cms Attributes: Fix available
最高第 1 名05:07 达到05:07 首次观测上榜08:51 观测离榜累计约3小时44分 - 09OESA-2026-3302 · kernel security update
kernel security update Affected packages: openEuler:20.03-LTS-SP4/kernel Attributes: Fix available、Severity - 9.8 (Critical)
最高第 11 名11:15 达到11:15 首次观测上榜14:43 观测离榜累计约3小时28分 - 10OESA-2026-3303 · kernel security update
kernel security update Affected packages: openEuler:22.03-LTS-SP4/kernel Attributes: Fix available、Severity - 9.8 (Critical)
最高第 10 名11:15 达到11:15 首次观测上榜14:43 观测离榜累计约3小时28分 - 11OESA-2026-3304 · bison security update
bison security update Affected packages: openEuler:22.03-LTS-SP4/bison Attributes: Fix available、Severity - 6.8 (Medium)
最高第 9 名11:15 达到11:15 首次观测上榜14:43 观测离榜累计约3小时28分 - 12OESA-2026-3305 · bison security update
bison security update Affected packages: openEuler:24.03-LTS-SP1/bison Attributes: Fix available、Severity - 6.8 (Medium)
最高第 8 名11:15 达到11:15 首次观测上榜14:43 观测离榜累计约3小时28分 - 13GHSA-f5wm-88jv-g5hx · Craft CMS: Authenticated RCE through Twig sandbox escape
Craft CMS: Authenticated RCE through Twig sandbox escape Affected packages: Packagist/craftcms/cms Attributes: Fix available、Severity - 8.7 (High)
最高第 3 名05:23 达到05:23 首次观测上榜08:51 观测离榜累计约3小时28分 - 14GHSA-p8x7-9vfw-p7vc · Craft CMS: Arbitrary user password reset leading to administrator account takeover
Craft CMS: Arbitrary user password reset leading to administrator account takeover Affected packages: Packagist/craftcms/cms Attributes: Fix available
最高第 2 名05:23 达到05:23 首次观测上榜08:51 观测离榜累计约3小时28分 - 15GHSA-pmhh-3w7g-xqp8 · jsoup: Cleaner may expose markup with custom raw-text elements
jsoup: Cleaner may expose markup with custom raw-text elements Affected packages: Maven/org.jsoup:jsoup Attributes: Fix available、Severity - 4.7 (Medium)
最高第 1 名05:23 达到05:23 首次观测上榜08:51 观测离榜累计约3小时28分 - 16GHSA-62fc-8686-hfmq · Traefik: ` allowCrossNamespace=false ` bypass via ` @kubernetescrd ` TraefikService backendRef
Traefik: ` allowCrossNamespace=false ` bypass via ` @kubernetescrd ` TraefikService backendRef Affected packages: Go/github.com/traefik/traefik、Go/github.com/traefik/traefik/v2、Go/github.com/traefik/traefik/v3 Attributes: Fix available、Severity - 4.8 (Medium)
最高第 2 名00:51 达到00:51 首次观测上榜04:03 观测离榜累计约3小时12分 - 17GHSA-6p8f-p8j2-rqmv · Traefik: Gateway HTTPRoute backendRef filters can leak backend context across routes sharing a Service:port
Traefik: Gateway HTTPRoute backendRef filters can leak backend context across routes sharing a Service:port Affected packages: Go/github.com/traefik/traefik/v3 Attributes: Fix available、Severity - 6.3 (Medium)
最高第 1 名00:51 达到00:51 首次观测上榜04:03 观测离榜累计约3小时12分 - 18GHSA-8hcv-x26h-mcgp · node-re2: String.prototype.replace(re2, template) aborts the Node process (uncatchable ToLocalChecked on empty MaybeLocal) when the result exceeds V8's max string length
node-re2: String.prototype.replace(re2, template) aborts the Node process (uncatchable ToLocalChecked on empty MaybeLocal) when the result exceeds V8's max string length Affected packages: npm/re2 Attributes: Fix available、Severity - 6.2 (Medium)
最高第 2 名05:39 达到05:39 首次观测上榜08:51 观测离榜累计约3小时12分 - 19GHSA-hq66-cqwq-w95j · PDF.js: Arbitrary JavaScript execution upon opening a malicious PDF
PDF.js: Arbitrary JavaScript execution upon opening a malicious PDF Affected packages: npm/pdfjs-dist Attributes: Fix available、Severity - 8.6 (High)
最高第 4 名05:39 达到05:39 首次观测上榜08:51 观测离榜累计约3小时12分 - 20GHSA-j4r3-hg7j-8chg · node-re2: Out-of-bounds heap read in ` replace ` / ` split ` via a ` Buffer ` ending in a truncated multi-byte UTF-8 character → adjacent heap memory disclosed to JavaScript
node-re2: Out-of-bounds heap read in ` replace ` / ` split ` via a ` Buffer ` ending in a truncated multi-byte UTF-8 character → adjacent heap memory disclosed to JavaScript Affected packages: npm/re2 Attributes: Fix available、Severity - 5.1 (Medium)
最高第 1 名05:39 达到05:39 首次观测上榜08:51 观测离榜累计约3小时12分 - 21GHSA-w9hm-4m3m-fxmm · ngx-extended-pdf-viewer bundles a version of pdf.js vulnerable to CVE-2026-16633
ngx-extended-pdf-viewer bundles a version of pdf.js vulnerable to CVE-2026-16633 Affected packages: npm/ngx-extended-pdf-viewer Attributes: Fix available、Severity - 8.6 (High)
最高第 3 名05:39 达到05:39 首次观测上榜08:51 观测离榜累计约3小时12分 - 22GHSA-2rp4-x2j7-qmcc · Craft CMS: Stored XSS in the control panel via unescaped draft name
Craft CMS: Stored XSS in the control panel via unescaped draft name Affected packages: Packagist/craftcms/cms Attributes: Fix available、Severity - 5.1 (Medium)
最高第 3 名05:55 达到05:55 首次观测上榜08:51 观测离榜累计约2小时56分 - 23GHSA-3q9r-p662-5j8m · Traefik: ForwardAuth middleware leaks X-Forwarded-Port spoofing via untrusted X-Forwarded-Proto when trustForwardHeader=false
Traefik: ForwardAuth middleware leaks X-Forwarded-Port spoofing via untrusted X-Forwarded-Proto when trustForwardHeader=false Affected packages: Go/github.com/traefik/traefik、Go/github.com/traefik/traefik/v2、Go/github.com/traefik/traefik/v3 Attributes: Fix available、Severity - 6.9 (Medium)
最高第 3 名00:51 达到00:51 首次观测上榜03:47 观测离榜累计约2小时56分 - 24GHSA-6765-c87h-8mrf · Traefik: BasicAuth singleflight key collision allows authenticated identity spoofing
Traefik: BasicAuth singleflight key collision allows authenticated identity spoofing Affected packages: Go/github.com/traefik/traefik/v3 Attributes: Fix available、Severity - 2.1 (Low)
最高第 5 名00:51 达到00:51 首次观测上榜03:47 观测离榜累计约2小时56分 - 25GHSA-7hxc-f267-h5q7 · Craft CMS: Incorrect path validation could potentially lead to path traversal
Craft CMS: Incorrect path validation could potentially lead to path traversal Affected packages: Packagist/craftcms/cms Attributes: Fix available、Severity - 2.1 (Low)
最高第 2 名05:55 达到05:55 首次观测上榜08:51 观测离榜累计约2小时56分 - 26GHSA-8rxv-jg7p-wvg3 · Traefik: Kubernetes Ingress NGINX RewriteTarget Path Traversal Allows Route-Level Authentication Bypass
Traefik: Kubernetes Ingress NGINX RewriteTarget Path Traversal Allows Route-Level Authentication Bypass Affected packages: Go/github.com/traefik/traefik/v3 Attributes: Fix available、Severity - 7.8 (High)
最高第 3 名01:07 达到01:07 首次观测上榜04:03 观测离榜累计约2小时56分 - 27GHSA-cxjq-mrr5-89rv · Traefik: Authentication Bypass via Path Traversal in ReplacePathRegex Middleware
Traefik: Authentication Bypass via Path Traversal in ReplacePathRegex Middleware Affected packages: Go/github.com/traefik/traefik、Go/github.com/traefik/traefik/v2、Go/github.com/traefik/traefik/v3 Attributes: Fix available、Severity - 9.1 (Critical)
最高第 2 名01:07 达到01:07 首次观测上榜04:03 观测离榜累计约2小时56分 - 28GHSA-fgjj-px3w-67xx · Traefik: Gateway API route identity collision allows cross-namespace backend hijacking
Traefik: Gateway API route identity collision allows cross-namespace backend hijacking Affected packages: Go/github.com/traefik/traefik/v3 Attributes: Fix available、Severity - 8.2 (High)
最高第 4 名00:51 达到00:51 首次观测上榜03:47 观测离榜累计约2小时56分 - 29GHSA-hmqg-cxww-wqhq · PHP_CodeSniffer gitblame report command injection via crafted filename
PHP_CodeSniffer gitblame report command injection via crafted filename Affected packages: Packagist/squizlabs/php_codesniffer Attributes: Fix available、Severity - 7.3 (High)
最高第 4 名05:55 达到05:55 首次观测上榜08:51 观测离榜累计约2小时56分 - 30GHSA-rvmm-v933-jgxq · Craft CMS: Missing authorization check allows non-admin control panel users access to user registration metrics
Craft CMS: Missing authorization check allows non-admin control panel users access to user registration metrics Affected packages: Packagist/craftcms/cms Attributes: Fix available、Severity - 5.3 (Medium)
最高第 1 名05:55 达到05:55 首次观测上榜08:51 观测离榜累计约2小时56分 - 31GHSA-x677-9fxg-v5c5 · Traefik: Incomplete fix for CVE-2026-33433 + CVE-2026-39858 cross-cohort: headerField underscore-variant identity spoofing in BasicAuth / DigestAuth / ForwardAuth
Traefik: Incomplete fix for CVE-2026-33433 + CVE-2026-39858 cross-cohort: headerField underscore-variant identity spoofing in BasicAuth / DigestAuth / ForwardAuth Affected packages: Go/github.com/traefik/traefik/v2、Go/github.com/traefik/traefik/v3 Attributes: Fix available、Severity - 7.8 (High)
最高第 1 名01:07 达到01:07 首次观测上榜04:03 观测离榜累计约2小时56分 - 32GHSA-596p-6jv8-775v · Craft CMS: Authenticated leak of secret environment variables
Craft CMS: Authenticated leak of secret environment variables Affected packages: Packagist/craftcms/cms Attributes: Fix available、Severity - 5.1 (Medium)
最高第 3 名06:11 达到06:11 首次观测上榜08:51 观测离榜累计约2小时40分 - 33GHSA-6hr6-w5qg-qmwg · h2: Duplicate Host header could facilitate request smuggling
h2: Duplicate Host header could facilitate request smuggling Affected packages: PyPI/h2 Attributes: Fix available、Severity - 5.3 (Medium)
最高第 2 名06:11 达到06:11 首次观测上榜08:51 观测离榜累计约2小时40分 - 34GHSA-957r-qf9p-67xw · Craft CMS: Arbitrary file read via SplFileObject in non-sandboxed template contexts
Craft CMS: Arbitrary file read via SplFileObject in non-sandboxed template contexts Affected packages: Packagist/craftcms/cms Attributes: Fix available、Severity - 6.9 (Medium)
最高第 1 名06:11 达到06:11 首次观测上榜08:51 观测离榜累计约2小时40分 - 35GHSA-xxpx-f366-4xpq · Craft CMS:Authorization bypass: view-only Categories user can modify category structure via structures/move-element
Craft CMS:Authorization bypass: view-only Categories user can modify category structure via structures/move-element Affected packages: Packagist/craftcms/cms Attributes: Fix available
最高第 4 名06:11 达到06:11 首次观测上榜08:51 观测离榜累计约2小时40分 - 36ROOT-APP-MAVEN-CVE-2025-8916 · CVE-2025-8916 in org.bouncycastle:bcpkix-jdk18on - Patched by Root
CVE-2025-8916 in org.bouncycastle:bcpkix-jdk18on - Patched by Root Affected packages: Root:Maven/io.root.org.bouncycastle:bcpkix-jdk15on、Root:Maven/io.root.org.bouncycastle:bcpkix-jdk18on、Root:Maven/org.bouncycastle:bcpkix-jdk15on、Root:Maven/org.bouncycastle:bcpkix-jdk18on Attributes: Fix available、Severity - 5.3 (Medium)
最高第 9 名02:11 达到当日首次采集时已在榜03:47 观测离榜上榜 2 次(重入 1 次)累计约2小时27分 - 37ROOT-APP-MAVEN-CVE-2026-12802 · CVE-2026-12802 in org.bouncycastle:bcpkix-jdk18on - Patched by Root
CVE-2026-12802 in org.bouncycastle:bcpkix-jdk18on - Patched by Root Affected packages: Root:Maven/io.root.org.bouncycastle:bcpkix-jdk18on、Root:Maven/org.bouncycastle:bcpkix-jdk18on Attributes: Fix available
最高第 10 名02:11 达到当日首次采集时已在榜03:47 观测离榜上榜 2 次(重入 1 次)累计约2小时27分 - 38ECHO-2495-c2a6-88b6 · Echo:PyPi/pypdf
Affected packages: Echo:PyPi/pypdf Attributes: Fix available
最高第 1 名08:51 达到08:51 首次观测上榜11:15 观测离榜累计约2小时24分 - 39ECHO-28b6-f469-c293 · Echo:PyPi/pypdf
Affected packages: Echo:PyPi/pypdf Attributes: Fix available
最高第 2 名08:51 达到08:51 首次观测上榜11:15 观测离榜累计约2小时24分 - 40ECHO-28f1-37d9-e122 · Echo:PyPi/pypdf
Affected packages: Echo:PyPi/pypdf Attributes: Fix available
最高第 3 名08:51 达到08:51 首次观测上榜11:15 观测离榜累计约2小时24分 - 41ECHO-3032-4565-df6c · Echo:PyPi/pypdf
Affected packages: Echo:PyPi/pypdf Attributes: Fix available
最高第 4 名08:51 达到08:51 首次观测上榜11:15 观测离榜累计约2小时24分 - 42ECHO-3326-0933-380b · Echo:PyPi/pypdf
Affected packages: Echo:PyPi/pypdf Attributes: Fix available
最高第 5 名08:51 达到08:51 首次观测上榜11:15 观测离榜累计约2小时24分 - 43ECHO-37c4-a1ff-2363 · Echo:PyPi/pypdf
Affected packages: Echo:PyPi/pypdf Attributes: Fix available
最高第 6 名08:51 达到08:51 首次观测上榜11:15 观测离榜累计约2小时24分 - 44ECHO-6000-bce7-d021 · Echo:PyPi/pypdf
Affected packages: Echo:PyPi/pypdf Attributes: Fix available
最高第 7 名08:51 达到08:51 首次观测上榜11:15 观测离榜累计约2小时24分 - 45ECHO-6003-6cab-4953 · Echo:PyPi/pypdf
Affected packages: Echo:PyPi/pypdf Attributes: Fix available
最高第 8 名08:51 达到08:51 首次观测上榜11:15 观测离榜累计约2小时24分 - 46ECHO-6652-da99-9f06 · Echo:PyPi/pypdf
Affected packages: Echo:PyPi/pypdf Attributes: Fix available
最高第 9 名08:51 达到08:51 首次观测上榜11:15 观测离榜累计约2小时24分 - 47ECHO-7c7a-70d5-0b5d · Echo:PyPi/pypdf
Affected packages: Echo:PyPi/pypdf Attributes: Fix available
最高第 10 名08:51 达到08:51 首次观测上榜11:15 观测离榜累计约2小时24分 - 48ECHO-827c-a5a0-d582 · Echo:PyPi/pypdf
Affected packages: Echo:PyPi/pypdf Attributes: Fix available
最高第 11 名08:51 达到08:51 首次观测上榜11:15 观测离榜累计约2小时24分 - 49ECHO-8bab-aae8-22d2 · Echo:PyPi/pypdf
Affected packages: Echo:PyPi/pypdf Attributes: Fix available
最高第 12 名08:51 达到08:51 首次观测上榜11:15 观测离榜累计约2小时24分 - 50ECHO-9559-f7c7-5c47 · Echo:PyPi/pypdf
Affected packages: Echo:PyPi/pypdf Attributes: Fix available
最高第 13 名08:51 达到08:51 首次观测上榜11:15 观测离榜累计约2小时24分


































































































