
OSV.dev · 实时热榜
- 01GHSA-998g-7v5w-cr7g · MagicMirror newsfeed Socket.IO notification allows blind server-side request forgery
MagicMirror newsfeed Socket.IO notification allows blind server-side request forgery Affected packages: npm/magicmirror Attributes: Fix available、Severity - 6.3 (Medium)
最高第 2 名01:31 达到01:31 首次观测上榜04:11 观测离榜累计约2小时40分 - 02GHSA-w26r-fwg8-rcp3 · MagicMirror Socket.IO module namespaces bypass configured IP whitelist and allow unauthenticated server-side actions
MagicMirror Socket.IO module namespaces bypass configured IP whitelist and allow unauthenticated server-side actions Affected packages: npm/magicmirror Attributes: Fix available、Severity - 2.3 (Low)
最高第 3 名01:31 达到01:31 首次观测上榜04:11 观测离榜累计约2小时40分 - 03GHSA-w6x9-28jw-hq7j · MagicMirror: ssrf calendar .js
MagicMirror: ssrf calendar .js Affected packages: npm/magicmirror Attributes: Fix available、Severity - 6.3 (Medium)
最高第 1 名01:31 达到01:31 首次观测上榜04:11 观测离榜累计约2小时40分 - 04DEBIAN-CVE-2026-53525 · Debian:11/weechat
Affected packages: Debian:11/weechat、Debian:12/weechat、Debian:13/weechat、Debian:14/weechat Attributes: Fix available
最高第 2 名01:15 达到01:15 首次观测上榜03:39 观测离榜累计约2小时24分 - 05GO-2026-6115 · Multiple denial of service vulnerabilities in rsc.io/pdf and forks
Multiple denial of service vulnerabilities in rsc.io/pdf and forks Affected packages: Go/github.com/dslipak/pdf、Go/github.com/ledongthuc/pdf、Go/rsc.io/pdf Attributes: No fix available
最高第 1 名01:15 达到01:15 首次观测上榜03:39 观测离榜累计约2小时24分 - 06RHSA-2026:56219 · Red Hat Security Advisory: python3 security update
Red Hat Security Advisory: python3 security update Affected packages: Red Hat:enterprise_linux:8::appstream/platform-python、Red Hat:enterprise_linux:8::appstream/platform-python-debug、Red Hat:enterprise_linux:8::appstream/platform-python-devel、Red Hat:enterprise_linux:8::appstream/python3-debuginfo、Red Hat:enterprise_linux:8::appstream/python3-debugsource、... 9 more Attributes: Fix available、Severity - 7.3 (High)
最高第 8 名18:35 达到18:35 首次观测上榜20:27 观测离榜累计约1小时52分 - 07RHSA-2026:56223 · Red Hat Security Advisory: grafana-pcp security update
Red Hat Security Advisory: grafana-pcp security update Affected packages: Red Hat:rhel_eus:9.6::appstream/grafana-pcp、Red Hat:rhel_eus:9.6::appstream/grafana-pcp-debuginfo、Red Hat:rhel_eus:9.6::appstream/grafana-pcp-debugsource Attributes: Fix available、Severity - 8.2 (High)
最高第 9 名18:35 达到18:35 首次观测上榜20:27 观测离榜累计约1小时52分 - 08RHSA-2026:56224 · Red Hat Security Advisory: kpatch-patch-5_14_0-427_100_1, kpatch-patch-5_14_0-427_113_1, kpatch-patch-5_14_0-427_126_1, kpatch-patch-5_14_0-427_68_2, and kpatch-patch-5_14_0-427_84_1 security update
Red Hat Security Advisory: kpatch-patch-5_14_0-427_100_1, kpatch-patch-5_14_0-427_113_1, kpatch-patch-5_14_0-427_126_1, kpatch-patch-5_14_0-427_68_2, and kpatch-patch-5_14_0-427_84_1 security update Affected packages: Red Hat:rhel_e4s:9.4::baseos/kpatch-patch-5_14_0-427_100_1、Red Hat:rhel_e4s:9.4::baseos/kpatch-patch-5_14_0-427_100_1-debuginfo、Red Hat:rhel_e4s:9.4::baseos/kpatch-patch-5_14_0-427_100_1-debugsource、Red Hat:rhel_e4s:9.4::baseos/kpatch-patch-5_14_0-427_113_1、Red Hat:rhel_e4s:9.4::baseos/kpatch-patch-5_14_0-427_113_1-debuginfo、... 10 more Attributes: Fix available、Severity - 7.8 (High)
最高第 7 名18:35 达到18:35 首次观测上榜20:27 观测离榜累计约1小时52分 - 09RHSA-2026:56225 · Red Hat Security Advisory: kpatch-patch-5_14_0-570_116_1, kpatch-patch-5_14_0-570_17_1, kpatch-patch-5_14_0-570_39_1, kpatch-patch-5_14_0-570_66_1, and kpatch-patch-5_14_0-570_94_1 security update
Red Hat Security Advisory: kpatch-patch-5_14_0-570_116_1, kpatch-patch-5_14_0-570_17_1, kpatch-patch-5_14_0-570_39_1, kpatch-patch-5_14_0-570_66_1, and kpatch-patch-5_14_0-570_94_1 security update Affected packages: Red Hat:rhel_eus:9.6::baseos/kpatch-patch-5_14_0-570_116_1、Red Hat:rhel_eus:9.6::baseos/kpatch-patch-5_14_0-570_116_1-debuginfo、Red Hat:rhel_eus:9.6::baseos/kpatch-patch-5_14_0-570_116_1-debugsource、Red Hat:rhel_eus:9.6::baseos/kpatch-patch-5_14_0-570_17_1、Red Hat:rhel_eus:9.6::baseos/kpatch-patch-5_14_0-570_17_1-debuginfo、... 10 more Attributes: Fix available、Severity - 7.8 (High)
最高第 6 名18:35 达到18:35 首次观测上榜20:27 观测离榜累计约1小时52分 - 10RHSA-2026:56521 · Red Hat Security Advisory: gstreamer1-plugins-bad-free security update
Red Hat Security Advisory: gstreamer1-plugins-bad-free security update Affected packages: Red Hat:enterprise_linux:8::appstream/gstreamer1-plugins-bad-free、Red Hat:enterprise_linux:8::appstream/gstreamer1-plugins-bad-free-debuginfo、Red Hat:enterprise_linux:8::appstream/gstreamer1-plugins-bad-free-debugsource、Red Hat:enterprise_linux:8::crb/gstreamer1-plugins-bad-free-debuginfo、Red Hat:enterprise_linux:8::crb/gstreamer1-plugins-bad-free-debugsource、... 1 more Attributes: Fix available、Severity - 7.6 (High)
最高第 4 名18:35 达到18:35 首次观测上榜20:27 观测离榜累计约1小时52分 - 11RHSA-2026:56573 · Red Hat Security Advisory: kernel security, bug fix, and enhancement update
Red Hat Security Advisory: kernel security, bug fix, and enhancement update Affected packages: Red Hat:rhel_e4s:9.4::appstream/bpftool-debuginfo、Red Hat:rhel_e4s:9.4::appstream/kernel-64k-debug-debuginfo、Red Hat:rhel_e4s:9.4::appstream/kernel-64k-debug-devel、Red Hat:rhel_e4s:9.4::appstream/kernel-64k-debug-devel-matched、Red Hat:rhel_e4s:9.4::appstream/kernel-64k-debuginfo、... 119 more Attributes: Fix available、Severity - 8.1 (High)
最高第 5 名18:35 达到18:35 首次观测上榜20:27 观测离榜累计约1小时52分 - 12RHSA-2026:56574 · Red Hat Security Advisory: kernel security, bug fix, and enhancement update
Red Hat Security Advisory: kernel security, bug fix, and enhancement update Affected packages: Red Hat:rhel_eus:9.6::appstream/kernel-64k-debug-debuginfo、Red Hat:rhel_eus:9.6::appstream/kernel-64k-debug-devel、Red Hat:rhel_eus:9.6::appstream/kernel-64k-debug-devel-matched、Red Hat:rhel_eus:9.6::appstream/kernel-64k-debuginfo、Red Hat:rhel_eus:9.6::appstream/kernel-64k-devel、... 155 more Attributes: Fix available、Severity - 7.1 (High)
最高第 3 名18:35 达到18:35 首次观测上榜20:27 观测离榜累计约1小时52分 - 13RHSA-2026:56658 · Red Hat Security Advisory: gstreamer1-plugins-bad-free security update
Red Hat Security Advisory: gstreamer1-plugins-bad-free security update Affected packages: Red Hat:rhel_e4s:9.2::appstream/gstreamer1-plugins-bad-free、Red Hat:rhel_e4s:9.2::appstream/gstreamer1-plugins-bad-free-debuginfo、Red Hat:rhel_e4s:9.2::appstream/gstreamer1-plugins-bad-free-debugsource Attributes: Fix available、Severity - 7.5 (High)
最高第 1 名18:35 达到18:35 首次观测上榜20:27 观测离榜累计约1小时52分 - 14RHSA-2026:56772 · Red Hat Security Advisory: gstreamer1-plugins-bad-free security update
Red Hat Security Advisory: gstreamer1-plugins-bad-free security update Affected packages: Red Hat:rhel_aus:8.4::appstream/gstreamer1-plugins-bad-free、Red Hat:rhel_aus:8.4::appstream/gstreamer1-plugins-bad-free-debuginfo、Red Hat:rhel_aus:8.4::appstream/gstreamer1-plugins-bad-free-debugsource、Red Hat:rhel_eus_long_life:8.4::appstream/gstreamer1-plugins-bad-free、Red Hat:rhel_eus_long_life:8.4::appstream/gstreamer1-plugins-bad-free-debuginfo、... 1 more Attributes: Fix available、Severity - 7.5 (High)
最高第 2 名18:35 达到18:35 首次观测上榜20:27 观测离榜累计约1小时52分 - 15DEBIAN-CVE-2026-53524 · Debian:11/weechat
Affected packages: Debian:11/weechat、Debian:12/weechat、Debian:13/weechat、Debian:14/weechat Attributes: Fix available
最高第 3 名01:15 达到01:15 首次观测上榜03:07 观测离榜累计约1小时52分 - 16GHSA-3p54-567p-2wpr · MobSF's CSRF checks not enforced after Django migration
MobSF's CSRF checks not enforced after Django migration Affected packages: PyPI/mobsf Attributes: Fix available、Severity - 6.5 (Medium)
最高第 2 名02:19 达到02:19 首次观测上榜04:11 观测离榜累计约1小时51分 - 17GHSA-8j49-mmcx-4mp5 · MobSF Vulnerable to Arbitrary File Read via Path Traversal in ZIP Uploads
MobSF Vulnerable to Arbitrary File Read via Path Traversal in ZIP Uploads Affected packages: PyPI/mobsf Attributes: Fix available、Severity - 5.5 (Medium)
最高第 1 名02:19 达到02:19 首次观测上榜04:11 观测离榜累计约1小时51分 - 18GHSA-95px-34x5-p37h · MobSF has SSRF port restriction bypass in assetlinks_check
MobSF has SSRF port restriction bypass in assetlinks_check Affected packages: PyPI/mobsf Attributes: Fix available、Severity - 3.0 (Low)
最高第 3 名02:19 达到02:19 首次观测上榜04:11 观测离榜累计约1小时51分 - 19GHSA-c9fv-cgmm-2wg7 · LibreNMS Vulnerable to Remote Code Execution by Signal Alert Transportation module
LibreNMS Vulnerable to Remote Code Execution by Signal Alert Transportation module Affected packages: Packagist/librenms/librenms Attributes: Fix available、Severity - 8.6 (High)
最高第 7 名02:19 达到02:19 首次观测上榜04:11 观测离榜累计约1小时51分 - 20GHSA-p23g-mvhj-jh3j · GeoLens: Cross-dataset authorization bypass discloses private dataset metadata, schema, sample values, table rows, and raster/vector tile data
GeoLens: Cross-dataset authorization bypass discloses private dataset metadata, schema, sample values, table rows, and raster/vector tile data Affected packages: PyPI/geolens、PyPI/geolens-cli、npm/@geolens/sdk Attributes: Fix available、Severity - 7.5 (High)
最高第 6 名02:19 达到02:19 首次观测上榜04:11 观测离榜累计约1小时51分 - 21GHSA-q4gh-4ffp-5cg8 · MagicMirror socket payload secret placeholder expansion can disclose SECRET_* environment variables
MagicMirror socket payload secret placeholder expansion can disclose SECRET_* environment variables Affected packages: npm/magicmirror Attributes: Fix available、Severity - 4.3 (Medium)
最高第 5 名02:19 达到02:19 首次观测上榜04:11 观测离榜累计约1小时51分 - 22GHSA-x768-8642-mmq9 · MobSF Vulnerable to Zip Bomb Denial of Service via Per-File Size Limit Bypass in ZIP/APK Extraction
MobSF Vulnerable to Zip Bomb Denial of Service via Per-File Size Limit Bypass in ZIP/APK Extraction Affected packages: PyPI/mobsf Attributes: Fix available、Severity - 4.9 (Medium)
最高第 4 名02:19 达到02:19 首次观测上榜04:11 观测离榜累计约1小时51分 - 23GO-2026-6093 · AWS CDK CodeBuild S3 Log Encryption Boolean Inversion in github.com/aws/aws-cdk-go/awscdk
AWS CDK CodeBuild S3 Log Encryption Boolean Inversion in github.com/aws/aws-cdk-go/awscdk Affected packages: Go/github.com/aws/aws-cdk-go/awscdk、Go/github.com/aws/aws-cdk-go/awscdk/v2 Attributes: Fix available
最高第 4 名01:15 达到01:15 首次观测上榜02:51 观测离榜累计约1小时36分 - 24MINI-27hf-3g4q-8h3f · MinimOS/vertical-pod-autoscaler
Affected packages: MinimOS/vertical-pod-autoscaler、MinimOS/vertical-pod-autoscaler-recommender、MinimOS/vertical-pod-autoscaler-updater Attributes: Fix available
最高第 1 名19:22 达到19:22 首次观测上榜20:59 观测离榜累计约1小时36分 - 25MINI-q689-5p2w-32w4 · MinimOS/temporal-cassandra-tool-1.28
Affected packages: MinimOS/temporal-cassandra-tool-1.28、MinimOS/temporal-server-1.28 Attributes: Fix available
最高第 1 名13:15 达到13:15 首次观测上榜14:51 观测离榜累计约1小时36分 - 26MAL-2026-14261 · Malicious code in postcss-initialize-provider (npm)
Malicious code in postcss-initialize-provider (npm) Affected packages: npm/postcss-initialize-provider Attributes: No fix available
最高第 1 名14:03 达到14:03 首次观测上榜15:39 观测离榜累计约1小时36分 - 27RLSA-2026:55856 · Important: .NET 9.0 security, bug fix, and enhancement update
Important: .NET 9.0 security, bug fix, and enhancement update Affected packages: Rocky Linux:9/dotnet9.0 Attributes: Fix available、Severity - 7.8 (High)
最高第 1 名14:35 达到14:35 首次观测上榜16:11 观测离榜累计约1小时36分 - 28RLSA-2026:55857 · Important: .NET 10.0 security, bug fix, and enhancement update
Important: .NET 10.0 security, bug fix, and enhancement update Affected packages: Rocky Linux:9/dotnet10.0 Attributes: Fix available、Severity - 7.8 (High)
最高第 2 名14:35 达到14:35 首次观测上榜16:11 观测离榜累计约1小时36分 - 29RLSA-2026:56130 · Important: sg3_utils security, bug fix, and enhancement update
Important: sg3_utils security, bug fix, and enhancement update Affected packages: Rocky Linux:8/sg3_utils Attributes: Fix available、Severity - 7.6 (High)
最高第 4 名14:35 达到14:35 首次观测上榜16:11 观测离榜累计约1小时36分 - 30RLSA-2026:56521 · Important: gstreamer1-plugins-bad-free security update
Important: gstreamer1-plugins-bad-free security update Affected packages: Rocky Linux:8/gstreamer1-plugins-bad-free Attributes: Fix available、Severity - 7.6 (High)
最高第 3 名14:35 达到14:35 首次观测上榜16:11 观测离榜累计约1小时36分 - 31MINI-jf7m-j9ww-895r · MinimOS/tdbg-1.31
Affected packages: MinimOS/tdbg-1.31、MinimOS/temporal-cassandra-tool-1.31、MinimOS/temporal-server-1.31、MinimOS/temporal-sql-tool-1.31 Attributes: Fix available
最高第 1 名18:51 达到18:51 首次观测上榜20:27 观测离榜累计约1小时36分 - 32RLSA-2026:52395 · Important: postgresql security update
Important: postgresql security update Affected packages: Rocky Linux:9/postgresql Attributes: Fix available、Severity - 7.5 (High)
最高第 1 名02:35 达到02:35 首次观测上榜04:11 观测离榜累计约1小时35分 - 33RLSA-2026:52396 · Important: postgresql:12 security update
Important: postgresql:12 security update Affected packages: Rocky Linux:8/pg_repack、Rocky Linux:8/pgaudit、Rocky Linux:8/postgres-decoderbufs、Rocky Linux:8/postgresql Attributes: Fix available、Severity - 7.5 (High)
最高第 3 名02:35 达到02:35 首次观测上榜04:11 观测离榜累计约1小时35分 - 34GO-2026-6094 · JSON private fields exposed via NativeTypes and ParseStructTag in github.com/google/cel-go
JSON private fields exposed via NativeTypes and ParseStructTag in github.com/google/cel-go Affected packages: Go/github.com/google/cel-go Attributes: Fix available
最高第 5 名01:15 达到01:15 首次观测上榜02:35 观测离榜累计约1小时20分 - 35GO-2026-6095 · Authentication bypass via default NoopAuthenticationFunc in github.com/getkin/kin-openapi
Authentication bypass via default NoopAuthenticationFunc in github.com/getkin/kin-openapi Affected packages: Go/github.com/getkin/kin-openapi Attributes: Fix available
最高第 6 名01:15 达到01:15 首次观测上榜02:35 观测离榜累计约1小时20分 - 36CLSA-2026-1787140595 · TuxCare security update for orjson (2 CVEs)
TuxCare security update for orjson (2 CVEs) Affected packages: TuxCare:PyPI/orjson Attributes: Fix available
最高第 2 名20:59 达到20:59 首次观测上榜22:19 观测离榜累计约1小时20分 - 37CLSA-2026-1787141079 · TuxCare security update for log4j:log4j (1 CVE)
TuxCare security update for log4j:log4j (1 CVE) Affected packages: TuxCare:Maven/log4j:log4j Attributes: Fix available
最高第 1 名20:59 达到20:59 首次观测上榜22:19 观测离榜累计约1小时20分 - 38MAL-2026-14248 · Malicious code in nice-utils-helper (npm)
Malicious code in nice-utils-helper (npm) Affected packages: npm/nice-utils-helper Attributes: No fix available
最高第 1 名12:43 达到12:43 首次观测上榜14:03 观测离榜累计约1小时20分 - 39MAL-2026-14262 · Malicious code in pump-fun-skills (npm)
Malicious code in pump-fun-skills (npm) Affected packages: npm/pump-fun-skills Attributes: No fix available
最高第 2 名14:03 达到14:03 首次观测上榜15:23 观测离榜累计约1小时20分 - 40MAL-2026-14264 · Malicious code in de-morgan (npm)
Malicious code in de-morgan (npm) Affected packages: npm/de-morgan Attributes: No fix available
最高第 5 名15:07 达到15:07 首次观测上榜16:27 观测离榜累计约1小时20分 - 41MAL-2026-14265 · Malicious code in easydsbots (npm)
Malicious code in easydsbots (npm) Affected packages: npm/easydsbots Attributes: No fix available
最高第 2 名15:07 达到15:07 首次观测上榜16:27 观测离榜累计约1小时20分 - 42MAL-2026-14266 · Malicious code in electron-sessions (npm)
Malicious code in electron-sessions (npm) Affected packages: npm/electron-sessions Attributes: No fix available
最高第 6 名15:07 达到15:07 首次观测上榜16:27 观测离榜累计约1小时20分 - 43MAL-2026-14267 · Malicious code in karma-proxy (npm)
Malicious code in karma-proxy (npm) Affected packages: npm/karma-proxy Attributes: No fix available
最高第 1 名15:07 达到15:07 首次观测上榜16:27 观测离榜累计约1小时20分 - 44MAL-2026-14268 · Malicious code in no-for-of-loops (npm)
Malicious code in no-for-of-loops (npm) Affected packages: npm/no-for-of-loops Attributes: No fix available
最高第 3 名15:07 达到15:07 首次观测上榜16:27 观测离榜累计约1小时20分 - 45MAL-2026-14269 · Malicious code in novel-suduko (npm)
Malicious code in novel-suduko (npm) Affected packages: npm/novel-suduko Attributes: No fix available
最高第 4 名15:07 达到15:07 首次观测上榜16:27 观测离榜累计约1小时20分 - 46PYSEC-2026-3673 · Lemur: Missing authorization check on POST /certificates/<id>/export for plugins with requires_key = False
Lemur: Missing authorization check on POST /certificates/<id>/export for plugins with requires_key = False Affected packages: PyPI/lemur Attributes: Fix available、Severity - 4.3 (Medium)
最高第 5 名20:59 达到20:59 首次观测上榜22:19 观测离榜累计约1小时20分 - 47PYSEC-2026-3677 · Lemur: Sub-CA creation never checks `AuthorityPermission` on the parent authority
Lemur: Sub-CA creation never checks `AuthorityPermission` on the parent authority Affected packages: PyPI/lemur Attributes: Fix available、Severity - 6.5 (Medium)
最高第 6 名20:59 达到20:59 首次观测上榜22:19 观测离榜累计约1小时20分 - 48PYSEC-2026-3678 · Lemur: Any user can revoke arbitrary certificates at the CA by uploading a duplicate record and revoking it
Lemur: Any user can revoke arbitrary certificates at the CA by uploading a duplicate record and revoking it Affected packages: PyPI/lemur Attributes: Fix available、Severity - 7.3 (High)
最高第 4 名20:59 达到20:59 首次观测上榜22:19 观测离榜累计约1小时20分 - 49PYSEC-2026-3682 · linuxfabrik-lib: Arbitrary root file read via live --test argument (lib.lftest) across sudoers-whitelisted plugins (LPE)
linuxfabrik-lib: Arbitrary root file read via live --test argument (lib.lftest) across sudoers-whitelisted plugins (LPE) Affected packages: PyPI/linuxfabrik-lib Attributes: Fix available、Severity - 5.5 (Medium)
最高第 3 名20:59 达到20:59 首次观测上榜22:19 观测离榜累计约1小时20分 - 50MAL-2026-14256 · Malicious code in api-rs-tuils (npm)
Malicious code in api-rs-tuils (npm) Affected packages: npm/api-rs-tuils Attributes: No fix available
最高第 2 名13:47 达到13:47 首次观测上榜15:07 观测离榜累计约1小时20分


































































































