
OSV.dev · 实时热榜
- 01MAL-2026-13629 · Malicious code in @coralxyz/anchor (npm)
Malicious code in @coralxyz/anchor (npm) Affected packages: npm/@coralxyz/anchor Attributes: No fix available
最高第 1 名09:13 达到09:13 首次观测上榜18:17 观测离榜累计约9小时4分 - 02MAL-2026-13664 · Malicious code in titan-exchange-shared-permissions (npm)
Malicious code in titan-exchange-shared-permissions (npm) Affected packages: npm/titan-exchange-shared-permissions Attributes: No fix available
最高第 2 名09:13 达到09:13 首次观测上榜18:17 观测离榜累计约9小时4分 - 03MINI-8w8f-pp74-rj4f · MinimOS/external-secrets-operator-fips
Affected packages: MinimOS/external-secrets-operator-fips Attributes: Fix available
最高第 2 名10:01 达到10:01 首次观测上榜18:33 观测离榜累计约8小时32分 - 04MINI-c62j-q4p5-pr66 · MinimOS/external-secrets-operator
Affected packages: MinimOS/external-secrets-operator Attributes: Fix available
最高第 3 名10:01 达到10:01 首次观测上榜18:33 观测离榜累计约8小时32分 - 05MINI-vxw9-6v68-j9hf · MinimOS/gotenberg
Affected packages: MinimOS/gotenberg、MinimOS/gotenberg-libreoffice Attributes: Fix available
最高第 1 名10:01 达到10:01 首次观测上榜18:33 观测离榜累计约8小时32分 - 06ECHO-c1f2-5b8f-bfa5 · Echo/zip
Affected packages: Echo/zip Attributes: No fix available
最高第 1 名10:17 达到10:17 首次观测上榜18:33 观测离榜累计约8小时16分 - 07MINI-j98r-56wv-7mw3 · MinimOS/external-secrets-operator-fips
Affected packages: MinimOS/external-secrets-operator-fips Attributes: Fix available
最高第 4 名10:01 达到10:01 首次观测上榜18:17 观测离榜累计约8小时16分 - 08MINI-vhhx-c5pm-7jqp · MinimOS/external-secrets-operator
Affected packages: MinimOS/external-secrets-operator Attributes: Fix available
最高第 5 名10:01 达到10:01 首次观测上榜18:17 观测离榜累计约8小时16分 - 09MAL-2026-13630 · Malicious code in @rbx-ts/services (npm)
Malicious code in @rbx-ts/services (npm) Affected packages: npm/@rbx-ts/services Attributes: No fix available
最高第 5 名09:13 达到09:13 首次观测上榜17:29 观测离榜累计约8小时16分 - 10MAL-2026-13631 · Malicious code in localization-fixer (npm)
Malicious code in localization-fixer (npm) Affected packages: npm/localization-fixer Attributes: No fix available
最高第 4 名09:13 达到09:13 首次观测上榜17:29 观测离榜累计约8小时16分 - 11MAL-2026-13632 · Malicious code in map-streak-kit (npm)
Malicious code in map-streak-kit (npm) Affected packages: npm/map-streak-kit Attributes: No fix available
最高第 6 名09:13 达到09:13 首次观测上榜17:29 观测离榜累计约8小时16分 - 12MAL-2026-13633 · Malicious code in modern-localization (npm)
Malicious code in modern-localization (npm) Affected packages: npm/modern-localization Attributes: No fix available
最高第 3 名09:13 达到09:13 首次观测上榜17:29 观测离榜累计约8小时16分 - 13MAL-2026-13640 · Malicious code in sme-rko-finance-front-operations-notifications-impl (npm)
Malicious code in sme-rko-finance-front-operations-notifications-impl (npm) Affected packages: npm/sme-rko-finance-front-operations-notifications-impl Attributes: No fix available
最高第 7 名09:13 达到09:13 首次观测上榜17:29 观测离榜累计约8小时16分 - 14MAL-2026-13649 · Malicious code in sme-rko-finance-front-operations-tax (npm)
Malicious code in sme-rko-finance-front-operations-tax (npm) Affected packages: npm/sme-rko-finance-front-operations-tax Attributes: No fix available
最高第 8 名09:13 达到09:13 首次观测上榜17:29 观测离榜累计约8小时16分 - 15MAL-2026-13660 · Malicious code in sme-rko-finance-front-payments-domain (npm)
Malicious code in sme-rko-finance-front-payments-domain (npm) Affected packages: npm/sme-rko-finance-front-payments-domain Attributes: No fix available
最高第 9 名09:13 达到09:13 首次观测上榜17:29 观测离榜累计约8小时16分 - 16MAL-2026-13661 · Malicious code in sme-rko-finance-front-payments-feed-adapter (npm)
Malicious code in sme-rko-finance-front-payments-feed-adapter (npm) Affected packages: npm/sme-rko-finance-front-payments-feed-adapter Attributes: No fix available
最高第 10 名09:13 达到09:13 首次观测上榜17:29 观测离榜累计约8小时16分 - 17JLSEC-2026-1197 · A use-after-free vulnerability exists in libcurl when an application configures an HTTP/2 stream...
A use-after-free vulnerability exists in libcurl when an application configures an HTTP/2 stream... Affected packages: Julia/CURL_jll、Julia/LibCURL_jll Attributes: Fix available、Severity - 9.8 (Critical)
最高第 1 名04:19 达到04:19 首次观测上榜09:13 观测离榜累计约4小时54分 - 18JLSEC-2026-1198 · An issue in curl’s QUIC UDP receive function allows a malicious HTTP/3 server to trigger a remote...
An issue in curl’s QUIC UDP receive function allows a malicious HTTP/3 server to trigger a remote... Affected packages: Julia/CURL_jll、Julia/LibCURL_jll Attributes: Fix available、Severity - 7.5 (High)
最高第 2 名04:19 达到04:19 首次观测上榜09:13 观测离榜累计约4小时54分 - 19JLSEC-2026-1199 · libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse...
libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse... Affected packages: Julia/CURL_jll、Julia/LibCURL_jll Attributes: Fix available、Severity - 9.1 (Critical)
最高第 3 名04:19 达到04:19 首次观测上榜09:13 观测离榜累计约4小时54分 - 20JLSEC-2026-1200 · By default, curl automatically responds to WebSocket PING frames. Because curl lacks an upper...
By default, curl automatically responds to WebSocket PING frames. Because curl lacks an upper... Affected packages: Julia/CURL_jll、Julia/LibCURL_jll Attributes: Fix available、Severity - 7.5 (High)
最高第 4 名04:19 达到04:19 首次观测上榜09:13 观测离榜累计约4小时54分 - 21JLSEC-2026-1201 · Successfully using libcurl to do a transfer to a specific HTTP origin ( ` hostA ` ) with **Digest**...
Successfully using libcurl to do a transfer to a specific HTTP origin ( ` hostA ` ) with **Digest**... Affected packages: Julia/CURL_jll、Julia/LibCURL_jll Attributes: Fix available、Severity - 9.8 (Critical)
最高第 5 名04:19 达到04:19 首次观测上榜09:13 观测离榜累计约4小时54分 - 22JLSEC-2026-1202 · When a user invokes curl using a schemeless URL combined with ` --proto-default ` sftp (or scp), a...
When a user invokes curl using a schemeless URL combined with ` --proto-default ` sftp (or scp), a... Affected packages: Julia/CURL_jll、Julia/LibCURL_jll Attributes: Fix available、Severity - 7.5 (High)
最高第 6 名04:19 达到04:19 首次观测上榜09:13 观测离榜累计约4小时54分 - 23JLSEC-2026-1203 · A vulnerability exists where a connection requiring TLS incorrectly reuses an existing...
A vulnerability exists where a connection requiring TLS incorrectly reuses an existing... Affected packages: Julia/CURL_jll、Julia/LibCURL_jll Attributes: Fix available、Severity - 5.9 (Medium)
最高第 7 名04:19 达到04:19 首次观测上榜09:13 观测离榜累计约4小时54分 - 24JLSEC-2026-1204 · libcurl might in some circumstances reuse the wrong connection when asked to do an authenticated...
libcurl might in some circumstances reuse the wrong connection when asked to do an authenticated... Affected packages: Julia/CURL_jll、Julia/LibCURL_jll Attributes: Fix available、Severity - 6.5 (Medium)
最高第 8 名04:19 达到04:19 首次观测上榜09:13 观测离榜累计约4小时54分 - 25ECHO-2c71-7b73-53dd · Echo/ffmpeg
Affected packages: Echo/ffmpeg Attributes: No fix available
最高第 1 名04:51 达到04:51 首次观测上榜09:13 观测离榜累计约4小时22分 - 26ECHO-6324-d2f6-0441 · Echo/ffmpeg
Affected packages: Echo/ffmpeg Attributes: No fix available
最高第 2 名04:51 达到04:51 首次观测上榜09:13 观测离榜累计约4小时22分 - 27ECHO-6986-2e97-593f · Echo/ffmpeg
Affected packages: Echo/ffmpeg Attributes: No fix available
最高第 3 名04:51 达到04:51 首次观测上榜09:13 观测离榜累计约4小时22分 - 28ECHO-d1bb-4d4f-3ea6 · Echo/ffmpeg
Affected packages: Echo/ffmpeg Attributes: No fix available
最高第 4 名04:51 达到04:51 首次观测上榜09:13 观测离榜累计约4小时22分 - 29ECHO-fb13-cd27-af33 · Echo/ffmpeg
Affected packages: Echo/ffmpeg Attributes: No fix available
最高第 5 名04:51 达到04:51 首次观测上榜09:13 观测离榜累计约4小时22分 - 30CGA-5c4q-86pf-x59c · Chainguard/tensorflow-cpu-jupyter
Affected packages: Chainguard/tensorflow-cpu-jupyter Attributes: Fix available
最高第 3 名17:29 达到17:29 首次观测上榜21:45 观测离榜累计约4小时16分 - 31CGA-5rcr-hj5p-4fc7 · Chainguard/flux-notification-controller
Affected packages: Chainguard/flux-notification-controller、Wolfi/flux-notification-controller Attributes: Fix available
最高第 1 名17:29 达到17:29 首次观测上榜21:45 观测离榜累计约4小时16分 - 32CGA-76w3-rghh-v4jj · Chainguard/flux-notification-controller
Affected packages: Chainguard/flux-notification-controller、Wolfi/flux-notification-controller Attributes: Fix available
最高第 2 名17:29 达到17:29 首次观测上榜21:45 观测离榜累计约4小时16分 - 33CGA-92qr-8jjf-cpq8 · Chainguard/tensorflow-cpu-jupyter
Affected packages: Chainguard/tensorflow-cpu-jupyter Attributes: Fix available
最高第 4 名17:29 达到17:29 首次观测上榜21:45 观测离榜累计约4小时16分 - 34CGA-g576-948v-7r27 · Chainguard/tensorflow-cpu-jupyter
Affected packages: Chainguard/tensorflow-cpu-jupyter Attributes: Fix available
最高第 5 名17:29 达到17:29 首次观测上榜21:45 观测离榜累计约4小时16分 - 35DEBIAN-CVE-2026-62289 · Debian:11/libheif
Affected packages: Debian:11/libheif、Debian:12/libheif、Debian:13/libheif、Debian:14/libheif Attributes: Fix available
最高第 1 名05:07 达到05:07 首次观测上榜09:13 观测离榜累计约4小时6分 - 36DEBIAN-CVE-2026-62292 · Debian:11/libheif
Affected packages: Debian:11/libheif、Debian:12/libheif、Debian:13/libheif、Debian:14/libheif Attributes: Fix available
最高第 2 名06:11 达到05:07 首次观测上榜09:13 观测离榜累计约4小时6分 - 37RHEA-2026:14435 · Red Hat Enhancement Advisory: Red Hat Edge Manager Version 1.1.2
Red Hat Enhancement Advisory: Red Hat Edge Manager Version 1.1.2 Affected packages: Red Hat:edge_manager:1.1::el10/flightctl、Red Hat:edge_manager:1.1::el10/flightctl-agent、Red Hat:edge_manager:1.1::el10/flightctl-cli、Red Hat:edge_manager:1.1::el10/flightctl-observability、Red Hat:edge_manager:1.1::el10/flightctl-selinux、... 7 more Attributes: Fix available、Severity - 7.5 (High)
最高第 4 名18:17 达到18:17 首次观测上榜21:45 观测离榜累计约3小时28分 - 38RHSA-2026:50807 · Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update
Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update Affected packages: Red Hat:hummingbird:1/tar Attributes: Fix available、Severity - 4.4 (Medium)
最高第 3 名18:17 达到18:17 首次观测上榜21:45 观测离榜累计约3小时28分 - 39RHSA-2026:51603 · Red Hat Security Advisory: kernel security, bug fix, and enhancement update
Red Hat Security Advisory: kernel security, bug fix, and enhancement update Affected packages: Red Hat:rhel_e4s:9.2::appstream/bpftool-debuginfo、Red Hat:rhel_e4s:9.2::appstream/kernel-64k-debug-debuginfo、Red Hat:rhel_e4s:9.2::appstream/kernel-64k-debug-devel、Red Hat:rhel_e4s:9.2::appstream/kernel-64k-debug-devel-matched、Red Hat:rhel_e4s:9.2::appstream/kernel-64k-debuginfo、... 66 more Attributes: Fix available、Severity - 8.4 (High)
最高第 1 名18:17 达到18:17 首次观测上榜21:45 观测离榜累计约3小时28分 - 40RHSA-2026:51604 · Red Hat Security Advisory: kernel-rt security, bug fix, and enhancement update
Red Hat Security Advisory: kernel-rt security, bug fix, and enhancement update Affected packages: Red Hat:rhel_e4s:9.2::nfv/kernel-rt、Red Hat:rhel_e4s:9.2::nfv/kernel-rt-core、Red Hat:rhel_e4s:9.2::nfv/kernel-rt-debug、Red Hat:rhel_e4s:9.2::nfv/kernel-rt-debug-core、Red Hat:rhel_e4s:9.2::nfv/kernel-rt-debug-debuginfo、... 27 more Attributes: Fix available、Severity - 8.4 (High)
最高第 2 名18:17 达到18:17 首次观测上榜21:45 观测离榜累计约3小时28分 - 41JLSEC-2026-1205 · libcurl might in some circumstances reuse the wrong connection for SMB(S) transfers. libcurl...
libcurl might in some circumstances reuse the wrong connection for SMB(S) transfers. libcurl... Affected packages: Julia/CURL_jll、Julia/LibCURL_jll Attributes: Fix available、Severity - 7.5 (High)
最高第 9 名04:19 达到04:19 首次观测上榜08:41 观测离榜上榜 2 次(重入 1 次)累计约3小时18分 - 42RHBA-2020:0582 · Red Hat Bug Fix Advisory: OpenShift Container Platform 4.4 RPM release advisory
Red Hat Bug Fix Advisory: OpenShift Container Platform 4.4 RPM release advisory Affected packages: Red Hat:openshift:4.4::el7/ansible-asb-modules、Red Hat:openshift:4.4::el7/ansible-kubernetes-modules、Red Hat:openshift:4.4::el7/ansible-runner、Red Hat:openshift:4.4::el7/ansible-runner-http、Red Hat:openshift:4.4::el7/apb、... 306 more Attributes: Fix available、Severity - 8.8 (High)
最高第 10 名18:33 达到18:33 首次观测上榜21:45 观测离榜累计约3小时12分 - 43RHBA-2025:21221 · Red Hat Bug Fix Advisory: OpenShift Container Platform 4.17.44 packages update
Red Hat Bug Fix Advisory: OpenShift Container Platform 4.17.44 packages update Affected packages: Red Hat:openshift:4.17::el8/runc、Red Hat:openshift:4.17::el8/runc-debuginfo、Red Hat:openshift:4.17::el8/runc-debugsource、Red Hat:openshift:4.17::el9/runc、Red Hat:openshift:4.17::el9/runc-debuginfo、... 1 more Attributes: Fix available、Severity - 8.2 (High)
最高第 9 名18:33 达到18:33 首次观测上榜21:45 观测离榜累计约3小时12分 - 44RHEA-2024:6124 · Red Hat Enhancement Advisory: Red Hat build of MicroShift 4.18.1 security update
Red Hat Enhancement Advisory: Red Hat build of MicroShift 4.18.1 security update Affected packages: Red Hat:openshift:4.18::el9/microshift、Red Hat:openshift:4.18::el9/microshift-gateway-api、Red Hat:openshift:4.18::el9/microshift-gateway-api-release-info、Red Hat:openshift:4.18::el9/microshift-greenboot、Red Hat:openshift:4.18::el9/microshift-low-latency、... 7 more Attributes: Fix available、Severity - 8.6 (High)
最高第 8 名18:33 达到18:33 首次观测上榜21:45 观测离榜累计约3小时12分 - 45RHEA-2025:4438 · Red Hat Enhancement Advisory: Red Hat OpenShift Service on AWS 1.0 enhancements
Red Hat Enhancement Advisory: Red Hat OpenShift Service on AWS 1.0 enhancements Affected packages: Red Hat:openshift_service_on_aws:1::el8/rosa、Red Hat:openshift_service_on_aws:1::el8/rosa-redistributable Attributes: Fix available、Severity - 8.2 (High)
最高第 7 名18:33 达到18:33 首次观测上榜21:45 观测离榜累计约3小时12分 - 46RHSA-2026:51746 · Red Hat Security Advisory: kernel security, bug fix, and enhancement update
Red Hat Security Advisory: kernel security, bug fix, and enhancement update Affected packages: Red Hat:rhel_e4s:9.4::appstream/bpftool-debuginfo、Red Hat:rhel_e4s:9.4::appstream/kernel-64k-debug-debuginfo、Red Hat:rhel_e4s:9.4::appstream/kernel-64k-debug-devel、Red Hat:rhel_e4s:9.4::appstream/kernel-64k-debug-devel-matched、Red Hat:rhel_e4s:9.4::appstream/kernel-64k-debuginfo、... 119 more Attributes: Fix available、Severity - 8.4 (High)
最高第 1 名18:33 达到18:33 首次观测上榜21:45 观测离榜累计约3小时12分 - 47RHSA-2026:51861 · Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update
Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update Affected packages: Red Hat:hummingbird:1/policycoreutils、Red Hat:hummingbird:1/policycoreutils-dbus Attributes: Fix available、Severity - 4.4 (Medium)
最高第 2 名18:33 达到18:33 首次观测上榜21:45 观测离榜累计约3小时12分 - 48DEBIAN-CVE-2026-61478 · Debian:11/libvirt
Affected packages: Debian:11/libvirt、Debian:12/libvirt、Debian:13/libvirt、Debian:14/libvirt Attributes: No fix available
最高第 1 名19:05 达到19:05 首次观测上榜21:45 观测离榜累计约2小时40分 - 49MINI-2vph-xc66-pvgv · MinimOS/nodejs-25
Affected packages: MinimOS/nodejs-25、MinimOS/nodejs-25-doc、MinimOS/nodejs-25-oci-entrypoint Attributes: No fix available
最高第 15 名22:01 达到22:01 首次观测上榜当日结束时仍在榜累计约1小时52分 - 50MINI-369g-jcwf-xgr8 · MinimOS/opensearch-dashboards-3-plugin-reports
Affected packages: MinimOS/opensearch-dashboards-3-plugin-reports Attributes: No fix available
最高第 8 名22:01 达到22:01 首次观测上榜当日结束时仍在榜累计约1小时52分


































































































