
OSV.dev · 实时热榜
- 01GHSA-8x3q-jpjh-qh5c · elFinder: SSRF protection bypass via DNS rebinding in the `fsock_get_contents()` fallback
elFinder: SSRF protection bypass via DNS rebinding in the `fsock_get_contents()` fallback Affected packages: Packagist/studio-42/elfinder Attributes: Fix available、Severity - 8.6 (High)
最高第 2 名04:53 达到04:53 首次观测上榜10:19 观测离榜累计约5小时26分 - 02GHSA-fm3f-ch8h-qw8q · @hono/oauth-providers: OAuth state check fails open on omitted state, enabling login CSRF and forced account linking
@hono/oauth-providers: OAuth state check fails open on omitted state, enabling login CSRF and forced account linking Affected packages: npm/@hono/oauth-providers Attributes: Fix available、Severity - 5.4 (Medium)
最高第 1 名04:53 达到04:53 首次观测上榜10:19 观测离榜累计约5小时26分 - 03MINI-2gpr-x365-m7vg · MinimOS/openclaw
Affected packages: MinimOS/openclaw Attributes: Fix available
最高第 7 名04:53 达到04:53 首次观测上榜10:19 观测离榜累计约5小时26分 - 04MINI-2jm4-pxh2-c3mv · MinimOS/openclaw
Affected packages: MinimOS/openclaw Attributes: Fix available
最高第 8 名04:53 达到04:53 首次观测上榜10:19 观测离榜累计约5小时26分 - 05MINI-423q-vpg7-439w · MinimOS/paketo-buildpacks-jam
Affected packages: MinimOS/paketo-buildpacks-jam Attributes: Fix available
最高第 3 名04:53 达到04:53 首次观测上榜10:19 观测离榜累计约5小时26分 - 06MINI-8mmx-h3h4-63cx · MinimOS/paketo-buildpacks-jam
Affected packages: MinimOS/paketo-buildpacks-jam Attributes: Fix available
最高第 4 名04:53 达到04:53 首次观测上榜10:19 观测离榜累计约5小时26分 - 07MINI-f25p-q2jj-hcgh · MinimOS/paketo-buildpacks-clojure-tools-2.17.12
Affected packages: MinimOS/paketo-buildpacks-clojure-tools-2.17.12 Attributes: Fix available
最高第 5 名04:53 达到04:53 首次观测上榜10:19 观测离榜累计约5小时26分 - 08MINI-qvrm-4xvh-3r95 · MinimOS/paketo-buildpacks-apache-tomcat-8.10.4
Affected packages: MinimOS/paketo-buildpacks-apache-tomcat-8.10.4 Attributes: Fix available
最高第 6 名04:53 达到04:53 首次观测上榜10:19 观测离榜累计约5小时26分 - 09MINI-35gv-w3r2-rhf4 · MinimOS/openclaw
Affected packages: MinimOS/openclaw Attributes: Fix available
最高第 9 名04:53 达到04:53 首次观测上榜09:31 观测离榜累计约4小时38分 - 10GHSA-gr94-w7qr-f4j3 · Socket.IO: Engine.IO WebTransport SID DoS
Socket.IO: Engine.IO WebTransport SID DoS Affected packages: npm/engine.io Attributes: Fix available、Severity - 7.5 (High)
最高第 1 名05:57 达到05:57 首次观测上榜10:19 观测离榜累计约4小时22分 - 11MINI-39j3-48x2-p745 · MinimOS/openclaw
Affected packages: MinimOS/openclaw Attributes: Fix available
最高第 10 名04:53 达到04:53 首次观测上榜09:31 观测离榜上榜 2 次(重入 1 次)累计约4小时22分 - 12MINI-4g9w-8q8v-v8px · MinimOS/openclaw
Affected packages: MinimOS/openclaw Attributes: Fix available
最高第 11 名04:53 达到04:53 首次观测上榜09:31 观测离榜上榜 2 次(重入 1 次)累计约4小时22分 - 13GHSA-67mx-6wf2-92xp · Kirby: File upload permissions are not checked during processing of chunk data
Kirby: File upload permissions are not checked during processing of chunk data Affected packages: Packagist/getkirby/cms Attributes: Fix available、Severity - 7.1 (High)
最高第 2 名06:45 达到06:45 首次观测上榜10:51 观测离榜累计约4小时6分 - 14GHSA-rgwj-5xj2-c3m3 · MySQL2: Unbounded zlib inflate in compressed MySQL protocol handler allows decompression-bomb DoS
MySQL2: Unbounded zlib inflate in compressed MySQL protocol handler allows decompression-bomb DoS Affected packages: npm/mysql2 Attributes: Fix available
最高第 1 名06:45 达到06:45 首次观测上榜10:51 观测离榜累计约4小时6分 - 15GHSA-vcc3-ghjq-m6fr · decode-uri-component: Denial of service via exponential decoding of malformed percent-encoded input
decode-uri-component: Denial of service via exponential decoding of malformed percent-encoded input Affected packages: npm/decode-uri-component Attributes: Fix available、Severity - 6.6 (Medium)
最高第 1 名06:29 达到06:29 首次观测上榜10:19 观测离榜累计约3小时50分 - 16GHSA-9vx2-j98c-p72w · Kirby: Access to image files and limited access to JSON files outside of the site root via path traversal in the media handling
Kirby: Access to image files and limited access to JSON files outside of the site root via path traversal in the media handling Affected packages: Packagist/getkirby/cms Attributes: Fix available、Severity - 8.2 (High)
最高第 3 名06:45 达到06:45 首次观测上榜10:19 观测离榜累计约3小时34分 - 17EEF-CVE-2026-82741 · Ash.Type.Union with :map_with_tag does not force the tag on dump, enabling tag confusion
Ash.Type.Union with :map_with_tag does not force the tag on dump, enabling tag confusion Affected packages: Hex/ash、github.com/ash-project/ash Attributes: Fix available、Severity - 2.1 (Low)
最高第 5 名11:55 达到11:55 首次观测上榜15:07 观测离榜累计约3小时12分 - 18EEF-CVE-2026-82742 · Ash.Filter.Runtime materializes a combinatorial cross-product over to-many relationships, exhausting memory
Ash.Filter.Runtime materializes a combinatorial cross-product over to-many relationships, exhausting memory Affected packages: Hex/ash、github.com/ash-project/ash Attributes: Fix available、Severity - 5.9 (Medium)
最高第 4 名11:55 达到11:55 首次观测上榜15:07 观测离榜累计约3小时12分 - 19EEF-CVE-2026-82743 · Ash.Actions.Read.AsyncLimiter busy-spins a scheduler while awaiting slow async reads
Ash.Actions.Read.AsyncLimiter busy-spins a scheduler while awaiting slow async reads Affected packages: Hex/ash、github.com/ash-project/ash Attributes: Fix available、Severity - 2.1 (Low)
最高第 3 名11:55 达到11:55 首次观测上榜15:07 观测离榜累计约3小时12分 - 20EEF-CVE-2026-82744 · Ash.Reactor change step fails open, skipping a change when its where guard raises
Ash.Reactor change step fails open, skipping a change when its where guard raises Affected packages: Hex/ash、github.com/ash-project/ash Attributes: Fix available、Severity - 2.1 (Low)
最高第 2 名11:55 达到11:55 首次观测上榜15:07 观测离榜累计约3小时12分 - 21EEF-CVE-2026-82745 · ETS and Mnesia data layers overwrite an existing record on create instead of enforcing primary-key uniqueness
ETS and Mnesia data layers overwrite an existing record on create instead of enforcing primary-key uniqueness Affected packages: Hex/ash、github.com/ash-project/ash Attributes: Fix available、Severity - 5.9 (Medium)
最高第 1 名11:55 达到11:55 首次观测上榜15:07 观测离榜累计约3小时12分 - 22EEF-CVE-2026-82746 · Ash.update_many/4 atomic path skips resource policy authorization, allowing updates to forbidden records
Ash.update_many/4 atomic path skips resource policy authorization, allowing updates to forbidden records Affected packages: Hex/ash、github.com/ash-project/ash Attributes: Fix available、Severity - 5.9 (Medium)
最高第 3 名12:11 达到12:11 首次观测上榜15:07 观测离榜累计约2小时56分 - 23EEF-CVE-2026-82748 · Ash.Actions.Aggregate authorizes an aggregate under one action but computes it under another
Ash.Actions.Aggregate authorizes an aggregate under one action but computes it under another Affected packages: Hex/ash、github.com/ash-project/ash Attributes: Fix available、Severity - 2.1 (Low)
最高第 2 名12:11 达到12:11 首次观测上榜15:07 观测离榜累计约2小时56分 - 24EEF-CVE-2026-82749 · Ash relationship parent(...) filter degrades to an IS NULL match when the parent field is unresolved, leaking scoped records
Ash relationship parent(...) filter degrades to an IS NULL match when the parent field is unresolved, leaking scoped records Affected packages: Hex/ash、github.com/ash-project/ash Attributes: Fix available、Severity - 5.9 (Medium)
最高第 1 名12:11 达到12:11 首次观测上榜15:07 观测离榜累计约2小时56分 - 25EEF-CVE-2026-82734 · Non-finite Infinity/NaN decimal values bypass bounds constraints in Ash.Type.Decimal
Non-finite Infinity/NaN decimal values bypass bounds constraints in Ash.Type.Decimal Affected packages: Hex/ash、github.com/ash-project/ash Attributes: Fix available、Severity - 2.1 (Low)
最高第 7 名11:39 达到11:39 首次观测上榜14:35 观测离榜累计约2小时56分 - 26EEF-CVE-2026-82735 · Match regex runs on over-length input in Ash.Type.String, enabling regex denial of service
Match regex runs on over-length input in Ash.Type.String, enabling regex denial of service Affected packages: Hex/ash、github.com/ash-project/ash Attributes: Fix available、Severity - 5.9 (Medium)
最高第 6 名11:39 达到11:39 首次观测上榜14:35 观测离榜累计约2小时56分 - 27EEF-CVE-2026-82736 · Ash.Type.CiString validates length and match constraints before case folding, allowing constraint bypass
Ash.Type.CiString validates length and match constraints before case folding, allowing constraint bypass Affected packages: Hex/ash、github.com/ash-project/ash Attributes: Fix available、Severity - 2.1 (Low)
最高第 5 名11:39 达到11:39 首次观测上榜14:35 观测离榜累计约2小时56分 - 28EEF-CVE-2026-82737 · Ash.Vector wraps the 16-bit dimension header for vectors over 65,535 elements, corrupting data and crashing reads
Ash.Vector wraps the 16-bit dimension header for vectors over 65,535 elements, corrupting data and crashing reads Affected packages: Hex/ash、github.com/ash-project/ash Attributes: Fix available、Severity - 5.9 (Medium)
最高第 4 名11:39 达到11:39 首次观测上榜14:35 观测离榜累计约2小时56分 - 29EEF-CVE-2026-82738 · Ash.Type.UUIDv7 accepts non-v7 UUIDs that then fail to load, causing persistent denial of service
Ash.Type.UUIDv7 accepts non-v7 UUIDs that then fail to load, causing persistent denial of service Affected packages: Hex/ash、github.com/ash-project/ash Attributes: Fix available、Severity - 5.9 (Medium)
最高第 3 名11:39 达到11:39 首次观测上榜14:35 观测离榜累计约2小时56分 - 30EEF-CVE-2026-82739 · Ash.Resource.Validation.Confirm leaks a confirmed field's stored value in the atomic mismatch error
Ash.Resource.Validation.Confirm leaks a confirmed field's stored value in the atomic mismatch error Affected packages: Hex/ash、github.com/ash-project/ash Attributes: Fix available、Severity - 2.1 (Low)
最高第 2 名11:39 达到11:39 首次观测上榜14:35 观测离榜累计约2小时56分 - 31EEF-CVE-2026-82740 · Ash.Type ignores outer array constraints on nested {:array, {:array, type}} inputs
Ash.Type ignores outer array constraints on nested {:array, {:array, type}} inputs Affected packages: Hex/ash、github.com/ash-project/ash Attributes: Fix available、Severity - 2.1 (Low)
最高第 1 名11:39 达到11:39 首次观测上榜14:35 观测离榜累计约2小时56分 - 32EEF-CVE-2026-82747 · Ash.Policy.Authorizer returns records denied by a runtime read policy to any actor
Ash.Policy.Authorizer returns records denied by a runtime read policy to any actor Affected packages: Hex/ash、github.com/ash-project/ash Attributes: Fix available、Severity - 5.9 (Medium)
最高第 1 名12:27 达到12:27 首次观测上榜15:07 观测离榜累计约2小时40分 - 33MAL-2026-15624 · Malicious code in claude-channel-telegram (npm)
Malicious code in claude-channel-telegram (npm) Affected packages: npm/claude-channel-telegram Attributes: No fix available
最高第 3 名02:40 达到02:40 首次观测上榜04:53 观测离榜累计约2小时14分 - 34MAL-2026-15631 · Malicious code in nextjsupdater (npm)
Malicious code in nextjsupdater (npm) Affected packages: npm/nextjsupdater Attributes: No fix available
最高第 4 名02:40 达到02:40 首次观测上榜04:53 观测离榜累计约2小时14分 - 35RLSA-2026:61383 · Important: nodejs:22 security update
Important: nodejs:22 security update Affected packages: Rocky Linux:9/nodejs-nodemon、Rocky Linux:9/nodejs-packaging Attributes: Fix available、Severity - 7.5 (High)
最高第 1 名02:40 达到02:40 首次观测上榜04:53 观测离榜累计约2小时14分 - 36RLSA-2026:61386 · Important: nodejs:24 security update
Important: nodejs:24 security update Affected packages: Rocky Linux:9/nodejs-nodemon、Rocky Linux:9/nodejs-packaging Attributes: Fix available、Severity - 7.5 (High)
最高第 2 名02:40 达到02:40 首次观测上榜04:53 观测离榜累计约2小时14分 - 37RLSA-2026:61316 · Important: xmlrpc-c security update
Important: xmlrpc-c security update Affected packages: Rocky Linux:9/xmlrpc-c Attributes: Fix available、Severity - 7.4 (High)
最高第 4 名14:35 达到14:35 首次观测上榜16:43 观测离榜累计约2小时8分 - 38RLSA-2026:61355 · Moderate: dbus-broker security update
Moderate: dbus-broker security update Affected packages: Rocky Linux:9/dbus-broker Attributes: Fix available、Severity - 5.5 (Medium)
最高第 1 名14:35 达到14:35 首次观测上榜16:43 观测离榜累计约2小时8分 - 39RLSA-2026:61379 · Important: freerdp security update
Important: freerdp security update Affected packages: Rocky Linux:9/freerdp Attributes: Fix available、Severity - 8.8 (High)
最高第 5 名14:35 达到14:35 首次观测上榜16:43 观测离榜累计约2小时8分 - 40RLSA-2026:61389 · Important: iperf3 security update
Important: iperf3 security update Affected packages: Rocky Linux:9/iperf3 Attributes: Fix available、Severity - 7.5 (High)
最高第 6 名14:35 达到14:35 首次观测上榜16:43 观测离榜累计约2小时8分 - 41RLSA-2026:61581 · Moderate: tar security, bug fix, and enhancement update
Moderate: tar security, bug fix, and enhancement update Affected packages: Rocky Linux:9/tar Attributes: Fix available、Severity - 5.0 (Medium)
最高第 2 名14:35 达到14:35 首次观测上榜16:43 观测离榜累计约2小时8分 - 42RLSA-2026:61623 · Moderate: gzip security update
Moderate: gzip security update Affected packages: Rocky Linux:9/gzip Attributes: Fix available、Severity - 6.0 (Medium)
最高第 3 名14:35 达到14:35 首次观测上榜16:43 观测离榜累计约2小时8分 - 43RLSA-2026:61766 · Moderate: glib2 security update
Moderate: glib2 security update Affected packages: Rocky Linux:8/glib2 Attributes: Fix available、Severity - 7.3 (High)
最高第 7 名14:35 达到14:35 首次观测上榜16:43 观测离榜累计约2小时8分 - 44MGASA-2026-0342 · Updated flatpak package fixes security vulnerabilities
Updated flatpak package fixes security vulnerabilities Affected packages: Mageia:10/flatpak Attributes: Fix available
最高第 1 名00:32 达到00:32 首次观测上榜02:40 观测离榜累计约2小时8分 - 45MGASA-2026-0343 · Updated c-ares packages fix security vulnerabilities
Updated c-ares packages fix security vulnerabilities Affected packages: Mageia:10/c-ares Attributes: Fix available
最高第 2 名00:32 达到00:32 首次观测上榜02:40 观测离榜累计约2小时8分 - 46MGASA-2026-0344 · Updated jbig2dec packages fix security vulnerabilities
Updated jbig2dec packages fix security vulnerabilities Affected packages: Mageia:10/jbig2dec、Mageia:9/jbig2dec Attributes: Fix available
最高第 3 名00:32 达到00:32 首次观测上榜02:40 观测离榜累计约2小时8分 - 47MGASA-2026-0345 · Updated nspr, nss, & firefox packages fix security vulnerabilities
Updated nspr, nss, & firefox packages fix security vulnerabilities Affected packages: Mageia:10/firefox、Mageia:10/firefox-l10n、Mageia:10/nspr、Mageia:10/nss、Mageia:9/firefox、... 3 more Attributes: Fix available
最高第 4 名00:32 达到00:32 首次观测上榜02:40 观测离榜累计约2小时8分 - 48MGASA-2026-0346 · Updated thunderbird packages fix security vulnerabilities
Updated thunderbird packages fix security vulnerabilities Affected packages: Mageia:10/thunderbird、Mageia:10/thunderbird-l10n、Mageia:9/thunderbird、Mageia:9/thunderbird-l10n Attributes: Fix available
最高第 5 名00:32 达到00:32 首次观测上榜02:40 观测离榜累计约2小时8分 - 49MGASA-2026-0347 · Updated postgresql18 & postgresql15 packages fix security vulnerabilities
Updated postgresql18 & postgresql15 packages fix security vulnerabilities Affected packages: Mageia:10/postgresql15、Mageia:10/postgresql18、Mageia:9/postgresql15 Attributes: Fix available
最高第 6 名00:32 达到00:32 首次观测上榜02:40 观测离榜累计约2小时8分 - 50MINI-58h5-gf69-rv6v · MinimOS/corretto-fips-config-11
Affected packages: MinimOS/corretto-fips-config-11 Attributes: Fix available
最高第 9 名00:32 达到00:32 首次观测上榜02:40 观测离榜累计约2小时8分


































































































