
OSV.dev · 实时热榜
- 01MINI-2p7v-w6j4-569m · MinimOS/vela-core-1.10
Affected packages: MinimOS/vela-core-1.10 Attributes: Fix available
最高第 2 名05:00 达到05:00 首次观测上榜10:52 观测离榜累计约5小时52分 - 02MINI-65q7-mpr5-jpj5 · MinimOS/velero-plugin-for-microsoft-azure-fips
Affected packages: MinimOS/velero-plugin-for-microsoft-azure-fips Attributes: Fix available
最高第 3 名05:00 达到05:00 首次观测上榜10:52 观测离榜累计约5小时52分 - 03MINI-xq4r-f6jg-86x6 · MinimOS/weaviate-1.39
Affected packages: MinimOS/weaviate-1.39 Attributes: Fix available
最高第 1 名05:00 达到05:00 首次观测上榜10:52 观测离榜累计约5小时52分 - 04EEF-CVE-2026-82724 · Broken access control in AshPhoenix SubdomainHook via a nil tenant in handle_subdomain
Broken access control in AshPhoenix SubdomainHook via a nil tenant in handle_subdomain Affected packages: Hex/ash_phoenix、github.com/ash-project/ash_phoenix Attributes: Fix available、Severity - 7.6 (High)
最高第 2 名11:24 达到11:24 首次观测上榜17:00 观测离榜累计约5小时36分 - 05EEF-CVE-2026-82725 · AshPhoenix FilterForm allows filtering across non-public relationships, disclosing private related data
AshPhoenix FilterForm allows filtering across non-public relationships, disclosing private related data Affected packages: Hex/ash_phoenix、github.com/ash-project/ash_phoenix Attributes: Fix available、Severity - 2.3 (Low)
最高第 1 名11:24 达到11:24 首次观测上榜17:00 观测离榜累计约5小时36分 - 06EEF-CVE-2026-82726 · AshPhoenix get_subdomain maps a crafted or differently-cased Host header to an arbitrary tenant
AshPhoenix get_subdomain maps a crafted or differently-cased Host header to an arbitrary tenant Affected packages: Hex/ash_phoenix、github.com/ash-project/ash_phoenix Attributes: Fix available、Severity - 6.3 (Medium)
最高第 3 名11:24 达到11:24 首次观测上榜17:00 观测离榜累计约5小时36分 - 07EEF-CVE-2026-82727 · AshPhoenix Form.Auto leaks submitted params in an unknown _union_type error message
AshPhoenix Form.Auto leaks submitted params in an unknown _union_type error message Affected packages: Hex/ash_phoenix、github.com/ash-project/ash_phoenix Attributes: Fix available、Severity - 2.3 (Low)
最高第 4 名11:24 达到11:24 首次观测上榜17:00 观测离榜累计约5小时36分 - 08MINI-79m9-v8r8-5f39 · MinimOS/vela-core-fips-1.11
Affected packages: MinimOS/vela-core-fips-1.11 Attributes: Fix available
最高第 4 名05:00 达到05:00 首次观测上榜10:36 观测离榜累计约5小时36分 - 09MINI-8xvw-ggp3-fg72 · MinimOS/vela-core-fips-1.10
Affected packages: MinimOS/vela-core-fips-1.10 Attributes: Fix available
最高第 5 名05:00 达到05:00 首次观测上榜10:36 观测离榜累计约5小时36分 - 10MINI-h92f-86f7-r8c4 · MinimOS/vela-core-1.10
Affected packages: MinimOS/vela-core-1.10 Attributes: Fix available
最高第 6 名05:00 达到05:00 首次观测上榜10:36 观测离榜累计约5小时36分 - 11MINI-jcxh-wjxr-94px · MinimOS/vela-core-fips-1.11
Affected packages: MinimOS/vela-core-fips-1.11 Attributes: Fix available
最高第 7 名05:00 达到05:00 首次观测上榜10:36 观测离榜累计约5小时36分 - 12MINI-jhjx-9rmv-mp83 · MinimOS/vela-core-1.11
Affected packages: MinimOS/vela-core-1.11 Attributes: Fix available
最高第 8 名05:00 达到05:00 首次观测上榜10:36 观测离榜累计约5小时36分 - 13EEF-CVE-2026-81853 · AshAdmin composite primary key decoding accepts arbitrary fields, enabling a secret-attribute oracle
AshAdmin composite primary key decoding accepts arbitrary fields, enabling a secret-attribute oracle Affected packages: Hex/ash_admin、github.com/ash-project/ash_admin Attributes: Fix available、Severity - 2.3 (Low)
最高第 2 名10:52 达到10:52 首次观测上榜16:12 观测离榜累计约5小时20分 - 14EEF-CVE-2026-82673 · Path traversal in AshAdmin file uploads via unsanitized client filename
Path traversal in AshAdmin file uploads via unsanitized client filename Affected packages: Hex/ash_admin、github.com/ash-project/ash_admin Attributes: Fix available、Severity - 8.3 (High)
最高第 1 名10:52 达到10:52 首次观测上榜16:12 观测离榜累计约5小时20分 - 15MAL-2026-15601 · Malicious code in eslint-prettier-js (npm)
Malicious code in eslint-prettier-js (npm) Affected packages: npm/eslint-prettier-js Attributes: No fix available
最高第 5 名11:56 达到11:56 首次观测上榜17:00 观测离榜累计约5小时4分 - 16EEF-CVE-2026-75757 · AshAdmin cookie reader matches names by substring, enabling actor/session shadowing from a sibling subdomain
AshAdmin cookie reader matches names by substring, enabling actor/session shadowing from a sibling subdomain Affected packages: Hex/ash_admin、github.com/ash-project/ash_admin Attributes: Fix available、Severity - 8.3 (High)
最高第 5 名10:36 达到10:36 首次观测上榜14:52 观测离榜累计约4小时16分 - 17EEF-CVE-2026-77850 · Stored XSS in AshAdmin relationship typeahead via unescaped label_field content
Stored XSS in AshAdmin relationship typeahead via unescaped label_field content Affected packages: Hex/ash_admin、github.com/ash-project/ash_admin Attributes: Fix available、Severity - 8.4 (High)
最高第 3 名10:36 达到10:36 首次观测上榜14:52 观测离榜累计约4小时16分 - 18EEF-CVE-2026-81852 · AshAdmin ships a hardcoded CSP nonce, allowing nonce-based CSP bypass
AshAdmin ships a hardcoded CSP nonce, allowing nonce-based CSP bypass Affected packages: Hex/ash_admin、github.com/ash-project/ash_admin Attributes: Fix available、Severity - 2.1 (Low)
最高第 1 名10:36 达到10:36 首次观测上榜14:52 观测离榜累计约4小时16分 - 19EEF-CVE-2026-82681 · Query-parameter injection in AshAdmin row-action links via unencoded string primary keys
Query-parameter injection in AshAdmin row-action links via unencoded string primary keys Affected packages: Hex/ash_admin、github.com/ash-project/ash_admin Attributes: Fix available、Severity - 2.0 (Low)
最高第 2 名10:36 达到10:36 首次观测上榜14:52 观测离榜累计约4小时16分 - 20EEF-CVE-2026-82722 · AshAdmin LiveView events intern atoms from client input, exhausting the atom table (node DoS)
AshAdmin LiveView events intern atoms from client input, exhausting the atom table (node DoS) Affected packages: Hex/ash_admin、github.com/ash-project/ash_admin Attributes: Fix available、Severity - 8.3 (High)
最高第 4 名10:36 达到10:36 首次观测上榜14:52 观测离榜累计约4小时16分 - 21MAL-2026-15602 · Malicious code in redis-cookie-server (npm)
Malicious code in redis-cookie-server (npm) Affected packages: npm/redis-cookie-server Attributes: No fix available
最高第 6 名11:56 达到11:56 首次观测上榜16:12 观测离榜累计约4小时16分 - 22MAL-2026-15588 · Malicious code in tronlinker (PyPI)
Malicious code in tronlinker (PyPI) Affected packages: PyPI/tronlinker Attributes: No fix available
最高第 1 名06:36 达到06:36 首次观测上榜10:52 观测离榜累计约4小时16分 - 23MINI-jv3x-2wjr-5hvx · MinimOS/velero-fips
Affected packages: MinimOS/velero-fips Attributes: Fix available
最高第 9 名05:00 达到05:00 首次观测上榜09:16 观测离榜累计约4小时16分 - 24MINI-mp49-xh26-c6f4 · MinimOS/versitygw
Affected packages: MinimOS/versitygw Attributes: Fix available
最高第 10 名05:00 达到05:00 首次观测上榜09:16 观测离榜累计约4小时16分 - 25MINI-qgv3-pfrg-mw7c · MinimOS/velero-plugin-for-microsoft-azure
Affected packages: MinimOS/velero-plugin-for-microsoft-azure Attributes: Fix available
最高第 11 名05:00 达到05:00 首次观测上榜09:16 观测离榜累计约4小时16分 - 26MINI-rmxj-83c8-787x · MinimOS/vela-core-fips-1.10
Affected packages: MinimOS/vela-core-fips-1.10 Attributes: Fix available
最高第 12 名05:00 达到05:00 首次观测上榜09:16 观测离榜累计约4小时16分 - 27MINI-wcmq-52hj-54jx · MinimOS/versitygw-fips
Affected packages: MinimOS/versitygw-fips Attributes: Fix available
最高第 13 名05:00 达到05:00 首次观测上榜09:16 观测离榜累计约4小时16分 - 28MINI-2m4p-q8p6-v433 · MinimOS/kubernetes-csi-external-provisioner
Affected packages: MinimOS/kubernetes-csi-external-provisioner Attributes: Fix available
最高第 8 名10:52 达到10:52 首次观测上榜14:52 观测离榜累计约4小时 - 29MINI-3f82-xg25-2vgf · MinimOS/kubernetes-event-exporter-fips
Affected packages: MinimOS/kubernetes-event-exporter-fips Attributes: Fix available
最高第 9 名10:52 达到10:52 首次观测上榜14:52 观测离榜累计约4小时 - 30MINI-c5gw-xrr9-f8w8 · MinimOS/vela-cli-fips-1.11
Affected packages: MinimOS/vela-cli-fips-1.11 Attributes: Fix available
最高第 15 名05:00 达到05:00 首次观测上榜09:00 观测离榜累计约4小时 - 31MINI-xpcx-qhpg-7h34 · MinimOS/vela-core-1.11
Affected packages: MinimOS/vela-core-1.11 Attributes: Fix available
最高第 14 名05:00 达到05:00 首次观测上榜09:00 观测离榜累计约4小时 - 32ECHO-0030-65ec-f55d · Echo/keycloak-25
Affected packages: Echo/keycloak-25 Attributes: Fix available
最高第 1 名01:32 达到01:32 首次观测上榜05:00 观测离榜累计约3小时28分 - 33ECHO-12de-2dca-d7dc · Echo/keycloak-25
Affected packages: Echo/keycloak-25 Attributes: Fix available
最高第 2 名01:32 达到01:32 首次观测上榜05:00 观测离榜累计约3小时28分 - 34ECHO-1814-da4f-7983 · Echo/keycloak-25
Affected packages: Echo/keycloak-25 Attributes: Fix available
最高第 3 名01:32 达到01:32 首次观测上榜05:00 观测离榜累计约3小时28分 - 35ECHO-1969-c688-a45c · Echo/keycloak-25
Affected packages: Echo/keycloak-25 Attributes: Fix available
最高第 4 名01:32 达到01:32 首次观测上榜05:00 观测离榜累计约3小时28分 - 36ECHO-1ec0-58d1-cb3d · Echo/keycloak-25
Affected packages: Echo/keycloak-25 Attributes: Fix available
最高第 5 名01:32 达到01:32 首次观测上榜05:00 观测离榜累计约3小时28分 - 37MAL-2026-15603 · Malicious code in pyservercheck (PyPI)
Malicious code in pyservercheck (PyPI) Affected packages: PyPI/pyservercheck Attributes: No fix available
最高第 1 名13:32 达到13:32 首次观测上榜17:00 观测离榜累计约3小时28分 - 38ROOT-APP-NPM-CVE-2026-26960 · CVE-2026-26960 in tar - Patched by Root
CVE-2026-26960 in tar - Patched by Root Affected packages: Root:npm/@rootio/tar、Root:npm/tar Attributes: Fix available、Severity - 7.1 (High)
最高第 4 名17:16 达到14:52 首次观测上榜18:20 观测离榜上榜 2 次(重入 1 次)累计约3小时12分 - 39ROOT-APP-NPM-CVE-2026-29786 · CVE-2026-29786 in tar - Patched by Root
CVE-2026-29786 in tar - Patched by Root Affected packages: Root:npm/@rootio/tar、Root:npm/tar Attributes: Fix available、Severity - 6.3 (Medium)
最高第 5 名17:16 达到14:52 首次观测上榜18:20 观测离榜上榜 2 次(重入 1 次)累计约3小时12分 - 40ROOT-APP-NPM-CVE-2026-59873 · CVE-2026-59873 in tar - Patched by Root
CVE-2026-59873 in tar - Patched by Root Affected packages: Root:npm/@rootio/tar、Root:npm/tar Attributes: Fix available
最高第 6 名17:16 达到14:52 首次观测上榜18:20 观测离榜上榜 2 次(重入 1 次)累计约3小时12分 - 41ECHO-2426-223e-d79f · Echo/keycloak-25
Affected packages: Echo/keycloak-25 Attributes: Fix available
最高第 6 名01:32 达到01:32 首次观测上榜04:44 观测离榜累计约3小时12分 - 42ECHO-26f2-acde-46cc · Echo/keycloak-25
Affected packages: Echo/keycloak-25 Attributes: Fix available
最高第 7 名01:32 达到01:32 首次观测上榜04:44 观测离榜累计约3小时12分 - 43ECHO-2aab-293d-53af · Echo/keycloak-25
Affected packages: Echo/keycloak-25 Attributes: Fix available
最高第 8 名01:32 达到01:32 首次观测上榜04:44 观测离榜累计约3小时12分 - 44EEF-CVE-2026-81319 · Unsafe deserialization of decrypted terms enables node DoS in AshCloak
Unsafe deserialization of decrypted terms enables node DoS in AshCloak Affected packages: Hex/ash_cloak、github.com/ash-project/ash_cloak Attributes: Fix available、Severity - 5.9 (Medium)
最高第 2 名02:20 达到02:20 首次观测上榜05:00 观测离榜累计约2小时40分 - 45EEF-CVE-2026-81322 · Cloaked plaintext leaks through a non-sensitive action argument in AshCloak
Cloaked plaintext leaks through a non-sensitive action argument in AshCloak Affected packages: Hex/ash_cloak、github.com/ash-project/ash_cloak Attributes: Fix available、Severity - 2.1 (Low)
最高第 1 名02:20 达到02:20 首次观测上榜05:00 观测离榜累计约2小时40分 - 46MINI-3mf5-83cf-7r36 · MinimOS/kubernetes-csi-external-resizer-fips
Affected packages: MinimOS/kubernetes-csi-external-resizer-fips Attributes: Fix available
最高第 10 名10:52 达到10:52 首次观测上榜13:32 观测离榜累计约2小时40分 - 47ROOT-APP-NPM-CVE-2021-23424 · CVE-2021-23424 in ansi-html - Patched by Root
CVE-2021-23424 in ansi-html - Patched by Root Affected packages: Root:npm/@rootio/ansi-html、Root:npm/ansi-html Attributes: Fix available
最高第 4 名14:52 达到14:52 首次观测上榜17:16 观测离榜累计约2小时24分 - 48ROOT-APP-NPM-CVE-2022-25883 · CVE-2022-25883 in semver - Patched by Root
CVE-2022-25883 in semver - Patched by Root Affected packages: Root:npm/@rootio/semver、Root:npm/semver Attributes: Fix available、Severity - 7.5 (High)
最高第 3 名14:52 达到14:52 首次观测上榜17:16 观测离榜累计约2小时24分 - 49ROOT-OS-ALPINE-318-CVE-2025-29087 · CVE-2025-29087 in sqlite - Patched by Root
CVE-2025-29087 in sqlite - Patched by Root Affected packages: Root:Alpine:3.18/rootio-sqlite、Root:Alpine:3.18/sqlite Attributes: Fix available、Severity - 7.5 (High)
最高第 1 名14:52 达到14:52 首次观测上榜17:16 观测离榜累计约2小时24分 - 50ROOT-OS-ALPINE-318-CVE-2026-11824 · CVE-2026-11824 in sqlite - Patched by Root
CVE-2026-11824 in sqlite - Patched by Root Affected packages: Root:Alpine:3.18/rootio-sqlite、Root:Alpine:3.18/sqlite Attributes: Fix available
最高第 2 名14:52 达到14:52 首次观测上榜17:16 观测离榜累计约2小时24分


































































































