
OSV.dev · 实时热榜
- 01GHSA-6hx8-3wjj-gr8g · WebOb: Open redirect in Location header normalization via leading C0 control / space characters
WebOb: Open redirect in Location header normalization via leading C0 control / space characters Affected packages: PyPI/webob Attributes: Fix available、Severity - 6.1 (Medium)
最高第 1 名06:21 达到06:21 首次观测上榜13:33 观测离榜累计约7小时12分 - 02MAL-2026-14569 · Malicious code in @hd-team/app-dnpkg-beta (npm)
Malicious code in @hd-team/app-dnpkg-beta (npm) Affected packages: npm/@hd-team/app-dnpkg-beta Attributes: No fix available
最高第 3 名06:53 达到06:53 首次观测上榜13:33 观测离榜累计约6小时40分 - 03MAL-2026-14571 · Malicious code in @hd-team/app-dnpkg-prod (npm)
Malicious code in @hd-team/app-dnpkg-prod (npm) Affected packages: npm/@hd-team/app-dnpkg-prod Attributes: No fix available
最高第 4 名06:53 达到06:53 首次观测上榜13:33 观测离榜累计约6小时40分 - 04MAL-2026-14574 · Malicious code in @hd-team/app-dnpkg-three (npm)
Malicious code in @hd-team/app-dnpkg-three (npm) Affected packages: npm/@hd-team/app-dnpkg-three Attributes: No fix available
最高第 5 名06:53 达到06:53 首次观测上榜13:33 观测离榜累计约6小时40分 - 05MAL-2026-14575 · Malicious code in @hd-team/app-impkg-prod (npm)
Malicious code in @hd-team/app-impkg-prod (npm) Affected packages: npm/@hd-team/app-impkg-prod Attributes: No fix available
最高第 6 名06:53 达到06:53 首次观测上榜13:33 观测离榜累计约6小时40分 - 06MAL-2026-14578 · Malicious code in pushgitquickx (npm)
Malicious code in pushgitquickx (npm) Affected packages: npm/pushgitquickx Attributes: No fix available
最高第 1 名06:53 达到06:53 首次观测上榜13:33 观测离榜累计约6小时40分 - 07MAL-2026-14576 · Malicious code in @hd-team/app-impkg-test (npm)
Malicious code in @hd-team/app-impkg-test (npm) Affected packages: npm/@hd-team/app-impkg-test Attributes: No fix available
最高第 7 名06:53 达到06:53 首次观测上榜13:01 观测离榜累计约6小时8分 - 08GHSA-vxj7-4xrp-5vr4 · aiosmtplib: STARTTLS response injection
aiosmtplib: STARTTLS response injection Affected packages: PyPI/aiosmtplib Attributes: Fix available、Severity - 5.9 (Medium)
最高第 1 名07:57 达到07:57 首次观测上榜13:33 观测离榜累计约5小时36分 - 09MAL-2026-14570 · Malicious code in @hd-team/app-dnpkg-eight (npm)
Malicious code in @hd-team/app-dnpkg-eight (npm) Affected packages: npm/@hd-team/app-dnpkg-eight Attributes: No fix available
最高第 8 名06:53 达到06:53 首次观测上榜12:13 观测离榜累计约5小时20分 - 10MAL-2026-14572 · Malicious code in @hd-team/app-dnpkg-ten (npm)
Malicious code in @hd-team/app-dnpkg-ten (npm) Affected packages: npm/@hd-team/app-dnpkg-ten Attributes: No fix available
最高第 9 名06:53 达到06:53 首次观测上榜12:13 观测离榜累计约5小时20分 - 11MAL-2026-14573 · Malicious code in @hd-team/app-dnpkg-test (npm)
Malicious code in @hd-team/app-dnpkg-test (npm) Affected packages: npm/@hd-team/app-dnpkg-test Attributes: No fix available
最高第 10 名06:53 达到06:53 首次观测上榜12:13 观测离榜累计约5小时20分 - 12GO-2026-6296 · Kyverno's NamespacedGeneratingPolicy generator.apply() namespace argument unvalidated -- background controller creates RoleBindings in any namespace including kube-system in github.com/kyverno/kyverno
Kyverno's NamespacedGeneratingPolicy generator.apply() namespace argument unvalidated -- background controller creates RoleBindings in any namespace including kube-system in github.com/kyverno/kyverno Affected packages: Go/github.com/kyverno/kyverno Attributes: Fix available
最高第 1 名04:29 达到04:29 首次观测上榜08:45 观测离榜累计约4小时16分 - 13GO-2026-6297 · linx-server has an issue in the uploadPostHandler component that allows attackers to cause a Denial of Service (DoS) via a crafted POST request in github.com/andreimarcu/linx-server
linx-server has an issue in the uploadPostHandler component that allows attackers to cause a Denial of Service (DoS) via a crafted POST request in github.com/andreimarcu/linx-server Affected packages: Go/github.com/andreimarcu/linx-server Attributes: No fix available
最高第 2 名04:29 达到04:29 首次观测上榜08:45 观测离榜累计约4小时16分 - 14CLSA-2026-1787867443 · TuxCare security update for 206 packages (4 CVEs)
TuxCare security update for 206 packages (4 CVEs) Affected packages: TuxCare:Maven/org.apache.cxf.archetype:cxf-jaxrs-service、TuxCare:Maven/org.apache.cxf.archetype:cxf-jaxws-javafirst、TuxCare:Maven/org.apache.cxf.archetype:cxf-jaxws-wsdlfirst、TuxCare:Maven/org.apache.cxf.karaf:apache-cxf、TuxCare:Maven/org.apache.cxf.karaf:cxf-karaf-commands、... 201 more Attributes: Fix available
最高第 6 名09:17 达到09:17 首次观测上榜13:33 观测离榜累计约4小时16分 - 15CLSA-2026-1787867848 · TuxCare security update for org.grails (1 CVE)
TuxCare security update for org.grails (1 CVE) Affected packages: TuxCare:Maven/org.grails:grails-bom、TuxCare:Maven/org.grails:grails-bootstrap、TuxCare:Maven/org.grails:grails-codecs、TuxCare:Maven/org.grails:grails-console、TuxCare:Maven/org.grails:grails-core、... 28 more Attributes: Fix available
最高第 5 名09:17 达到09:17 首次观测上榜13:33 观测离榜累计约4小时16分 - 16ECHO-9169-1fd9-0c1c · Echo/glibc
Affected packages: Echo/glibc Attributes: No fix available
最高第 1 名09:17 达到09:17 首次观测上榜13:33 观测离榜累计约4小时16分 - 17MINI-4fjm-6gxc-gqwg · MinimOS/splunk-otel-collector-fips
Affected packages: MinimOS/splunk-otel-collector-fips Attributes: Fix available
最高第 1 名20:13 达到20:13 首次观测上榜23:57 观测离榜累计约3小时44分 - 18MINI-pp77-qqg5-cf8w · MinimOS/apache-activemq-6.1-fips
Affected packages: MinimOS/apache-activemq-6.1-fips Attributes: No fix available
最高第 1 名02:37 达到02:37 首次观测上榜06:21 观测离榜累计约3小时44分 - 19MAL-2026-14567 · Malicious code in tailwindcss-3d-animate (npm)
Malicious code in tailwindcss-3d-animate (npm) Affected packages: npm/tailwindcss-3d-animate Attributes: No fix available
最高第 1 名03:09 达到03:09 首次观测上榜06:53 观测离榜累计约3小时44分 - 20MAL-2026-14568 · Malicious code in tailwindcss-form-styles (npm)
Malicious code in tailwindcss-form-styles (npm) Affected packages: npm/tailwindcss-form-styles Attributes: No fix available
最高第 2 名03:09 达到03:09 首次观测上榜06:53 观测离榜累计约3小时44分 - 21ROOT-APP-NPM-CVE-2023-45133 · CVE-2023-45133 in babel-traverse - Patched by Root
CVE-2023-45133 in babel-traverse - Patched by Root Affected packages: Root:npm/@babel/traverse、Root:npm/@rootio/babel-traverse、Root:npm/@rootio/babel__traverse、Root:npm/babel-traverse Attributes: Fix available
最高第 1 名02:21 达到01:17 首次观测上榜06:53 观测离榜上榜 2 次(重入 1 次)累计约3小时44分 - 22MAL-2026-14584 · Malicious code in flyteplugins-redis (PyPI)
Malicious code in flyteplugins-redis (PyPI) Affected packages: PyPI/flyteplugins-redis Attributes: No fix available
最高第 12 名09:01 达到08:45 首次观测上榜12:13 观测离榜累计约3小时28分 - 23GO-2026-6298 · Cloudreve WebDAV (`/dav`) has Path Traversal / Broken Access Control — scoped DAV credential escapes its configured account root in github.com/cloudreve/Cloudreve
Cloudreve WebDAV (`/dav`) has Path Traversal / Broken Access Control — scoped DAV credential escapes its configured account root in github.com/cloudreve/Cloudreve Affected packages: Go/github.com/cloudreve/Cloudreve、Go/github.com/cloudreve/Cloudreve/v3、Go/github.com/cloudreve/Cloudreve/v4 Attributes: Fix available
最高第 3 名04:29 达到04:29 首次观测上榜07:57 观测离榜累计约3小时28分 - 24MAL-2026-14585 · Malicious code in @znan/wabot (npm)
Malicious code in @znan/wabot (npm) Affected packages: npm/@znan/wabot Attributes: No fix available
最高第 2 名10:05 达到10:05 首次观测上榜13:33 观测离榜累计约3小时28分 - 25MINI-2738-6745-57jq · MinimOS/linstor-server-fips
Affected packages: MinimOS/linstor-server-fips Attributes: Fix available
最高第 1 名13:33 达到13:33 首次观测上榜16:45 观测离榜累计约3小时12分 - 26MINI-29mp-c84q-fcrj · MinimOS/linstor-server-fips
Affected packages: MinimOS/linstor-server-fips Attributes: Fix available
最高第 2 名13:33 达到13:33 首次观测上榜16:45 观测离榜累计约3小时12分 - 27MINI-2hjm-6fr8-24j9 · MinimOS/linstor-server-fips
Affected packages: MinimOS/linstor-server-fips Attributes: Fix available
最高第 3 名13:33 达到13:33 首次观测上榜16:45 观测离榜累计约3小时12分 - 28MINI-2p7r-cmfx-3pqm · MinimOS/linstor-server-fips
Affected packages: MinimOS/linstor-server-fips Attributes: Fix available
最高第 4 名13:33 达到13:33 首次观测上榜16:45 观测离榜累计约3小时12分 - 29MINI-6v24-vcvc-37xr · MinimOS/splunk-otel-collector-fips
Affected packages: MinimOS/splunk-otel-collector-fips Attributes: Fix available
最高第 2 名20:13 达到20:13 首次观测上榜23:25 观测离榜累计约3小时12分 - 30MINI-8xgj-8w33-h66j · MinimOS/splunk-otel-collector
Affected packages: MinimOS/splunk-otel-collector Attributes: Fix available
最高第 3 名20:13 达到20:13 首次观测上榜23:25 观测离榜累计约3小时12分 - 31MGASA-2026-0338 · Updated avahi packages fix security vulnerabilities
Updated avahi packages fix security vulnerabilities Affected packages: Mageia:10/avahi、Mageia:9/avahi Attributes: Fix available
最高第 1 名03:41 达到03:41 首次观测上榜06:53 观测离榜累计约3小时12分 - 32MGASA-2026-0339 · Updated python-django packages fix security vulnerabilities
Updated python-django packages fix security vulnerabilities Affected packages: Mageia:10/python-django Attributes: Fix available
最高第 2 名03:41 达到03:41 首次观测上榜06:53 观测离榜累计约3小时12分 - 33RLSA-2026:60394 · Moderate: libxml2 security update
Moderate: libxml2 security update Affected packages: Rocky Linux:10/libxml2 Attributes: Fix available、Severity - 4.8 (Medium)
最高第 1 名20:45 达到20:45 首次观测上榜当日结束时仍在榜累计约3小时12分 - 34ROOT-APP-NPM-CVE-2020-15138 · CVE-2020-15138 in prismjs - Patched by Root
CVE-2020-15138 in prismjs - Patched by Root Affected packages: Root:npm/@rootio/prismjs、Root:npm/prismjs Attributes: Fix available
最高第 3 名03:41 达到03:41 首次观测上榜06:53 观测离榜累计约3小时12分 - 35ROOT-APP-NPM-CVE-2021-23341 · CVE-2021-23341 in prismjs - Patched by Root
CVE-2021-23341 in prismjs - Patched by Root Affected packages: Root:npm/@rootio/prismjs、Root:npm/prismjs Attributes: Fix available
最高第 4 名03:41 达到03:41 首次观测上榜06:53 观测离榜累计约3小时12分 - 36ROOT-APP-NPM-CVE-2021-32723 · CVE-2021-32723 in prismjs - Patched by Root
CVE-2021-32723 in prismjs - Patched by Root Affected packages: Root:npm/@rootio/prismjs、Root:npm/prismjs Attributes: Fix available
最高第 5 名03:41 达到03:41 首次观测上榜06:53 观测离榜累计约3小时12分 - 37ROOT-APP-NPM-CVE-2022-23647 · CVE-2022-23647 in prismjs - Patched by Root
CVE-2022-23647 in prismjs - Patched by Root Affected packages: Root:npm/@rootio/prismjs、Root:npm/prismjs Attributes: Fix available
最高第 6 名03:41 达到03:41 首次观测上榜06:53 观测离榜累计约3小时12分 - 38ROOT-APP-NPM-CVE-2026-59869 · CVE-2026-59869 in js-yaml - Patched by Root
CVE-2026-59869 in js-yaml - Patched by Root Affected packages: Root:npm/@rootio/js-yaml、Root:npm/js-yaml Attributes: Fix available
最高第 2 名21:01 达到21:01 首次观测上榜当日结束时仍在榜累计约2小时56分 - 39ROOT-APP-NPM-GHSA-5p4m-2wfm-xmqj · GHSA-5p4m-2wfm-xmqj in js-yaml - Patched by Root
GHSA-5p4m-2wfm-xmqj in js-yaml - Patched by Root Affected packages: Root:npm/@rootio/js-yaml、Root:npm/js-yaml Attributes: Fix available
最高第 3 名21:01 达到21:01 首次观测上榜当日结束时仍在榜累计约2小时56分 - 40DEBIAN-CVE-2026-81493 · Debian:13/incus
Affected packages: Debian:13/incus、Debian:14/incus Attributes: Fix available
最高第 9 名14:05 达到14:05 首次观测上榜16:45 观测离榜累计约2小时40分 - 41DEBIAN-CVE-2026-81494 · Debian:14/incus
Affected packages: Debian:14/incus Attributes: Fix available
最高第 2 名14:05 达到14:05 首次观测上榜16:45 观测离榜累计约2小时40分 - 42DEBIAN-CVE-2026-81495 · Debian:13/incus
Affected packages: Debian:13/incus、Debian:14/incus Attributes: Fix available
最高第 5 名14:05 达到14:05 首次观测上榜16:45 观测离榜累计约2小时40分 - 43DEBIAN-CVE-2026-81496 · Debian:13/incus
Affected packages: Debian:13/incus、Debian:14/incus Attributes: Fix available
最高第 8 名14:05 达到14:05 首次观测上榜16:45 观测离榜累计约2小时40分 - 44DEBIAN-CVE-2026-81497 · Debian:13/incus
Affected packages: Debian:13/incus、Debian:14/incus Attributes: Fix available
最高第 7 名14:05 达到14:05 首次观测上榜16:45 观测离榜累计约2小时40分 - 45DEBIAN-CVE-2026-81498 · Debian:13/incus
Affected packages: Debian:13/incus、Debian:14/incus Attributes: Fix available
最高第 6 名14:05 达到14:05 首次观测上榜16:45 观测离榜累计约2小时40分 - 46DEBIAN-CVE-2026-81499 · Debian:14/incus
Affected packages: Debian:14/incus Attributes: Fix available
最高第 1 名14:05 达到14:05 首次观测上榜16:45 观测离榜累计约2小时40分 - 47DEBIAN-CVE-2026-81500 · Debian:13/incus
Affected packages: Debian:13/incus、Debian:14/incus Attributes: No fix available
最高第 3 名14:05 达到14:05 首次观测上榜16:45 观测离榜累计约2小时40分 - 48DEBIAN-CVE-2026-81501 · Debian:13/incus
Affected packages: Debian:13/incus、Debian:14/incus Attributes: No fix available
最高第 4 名14:05 达到14:05 首次观测上榜16:45 观测离榜累计约2小时40分 - 49GO-2026-6299 · statping-ng allows attackers to escalate privileges to Administrator and access sensitive components in github.com/statping-ng/statping-ng
statping-ng allows attackers to escalate privileges to Administrator and access sensitive components in github.com/statping-ng/statping-ng Affected packages: Go/github.com/statping-ng/statping-ng Attributes: No fix available
最高第 4 名04:29 达到04:29 首次观测上榜07:09 观测离榜累计约2小时40分 - 50ECHO-add6-7bb2-f327 · Echo/glibc
Affected packages: Echo/glibc Attributes: No fix available
最高第 1 名21:17 达到21:17 首次观测上榜当日结束时仍在榜累计约2小时40分


































































































