
OSV.dev · 实时热榜
- 01DEBIAN-CVE-2026-12570 · Debian:11/keras
Affected packages: Debian:11/keras Attributes: No fix available
最高第 1 名18:07 达到18:07 首次观测上榜18:39 观测离榜累计约32分钟 - 02DEBIAN-CVE-2026-61552 · Debian:11/icinga2
Affected packages: Debian:11/icinga2、Debian:12/icinga2、Debian:13/icinga2、Debian:14/icinga2 Attributes: Fix available
最高第 1 名23:11 达到23:11 首次观测上榜当日结束时仍在榜累计约48分钟 - 03ECHO-de7d-deea-1f3e · Echo/expat
Affected packages: Echo/expat Attributes: No fix available
最高第 1 名21:51 达到21:51 首次观测上榜22:07 观测离榜累计约16分钟 - 04EEF-CVE-2026-64941 · Open redirect in Phoenix.LiveView.validate_local_url!/2 via ASCII tab, LF and CR
Open redirect in Phoenix.LiveView.validate_local_url!/2 via ASCII tab, LF and CR Affected packages: Hex/phoenix_live_view、github.com/phoenixframework/phoenix_live_view Attributes: Fix available、Severity - 2.1 (Low)
最高第 1 名19:27 达到19:27 首次观测上榜21:19 观测离榜累计约1小时52分 - 05EEF-CVE-2026-70395 · Predicate injection in manage_relationship belongs_to lookup discloses secret lookup keys in Ash
Predicate injection in manage_relationship belongs_to lookup discloses secret lookup keys in Ash Affected packages: Hex/ash、github.com/ash-project/ash Attributes: Fix available、Severity - 2.1 (Low)
最高第 1 名02:23 达到02:23 首次观测上榜03:59 观测离榜累计约1小时36分 - 06JLSEC-2026-1237 · Julia/XML2_jll
Affected packages: Julia/XML2_jll Attributes: Fix available、Severity - 3.7 (Low)
最高第 1 名10:07 达到10:07 首次观测上榜16:31 观测离榜累计约6小时24分 - 07MAL-2026-13667 · Malicious code in kotanku (PyPI)
Malicious code in kotanku (PyPI) Affected packages: PyPI/kotanku Attributes: No fix available
最高第 1 名05:35 达到05:35 首次观测上榜16:31 观测离榜累计约10小时56分 - 08MAL-2026-13682 · Malicious code in btcflx (PyPI)
Malicious code in btcflx (PyPI) Affected packages: PyPI/btcflx Attributes: No fix available
最高第 1 名14:55 达到14:55 首次观测上榜16:31 观测离榜累计约1小时36分 - 09MAL-2026-13684 · Malicious code in @ssgw/icon (npm)
Malicious code in @ssgw/icon (npm) Affected packages: npm/@ssgw/icon Attributes: No fix available
最高第 1 名17:03 达到17:03 首次观测上榜18:39 观测离榜累计约1小时36分 - 10MAL-2026-13687 · Malicious code in tokocrytodev (npm)
Malicious code in tokocrytodev (npm) Affected packages: npm/tokocrytodev Attributes: No fix available
最高第 1 名20:15 达到20:15 首次观测上榜21:19 观测离榜累计约1小时4分 - 11MAL-2026-13688 · Malicious code in @kuperka/chainguard-sdk (npm)
Malicious code in @kuperka/chainguard-sdk (npm) Affected packages: npm/@kuperka/chainguard-sdk Attributes: No fix available
最高第 1 名21:03 达到21:03 首次观测上榜22:07 观测离榜累计约1小时4分 - 12MAL-2026-13707 · Malicious code in polymarket-stake-mathss (npm)
Malicious code in polymarket-stake-mathss (npm) Affected packages: npm/polymarket-stake-mathss Attributes: No fix available
最高第 1 名21:19 达到21:19 首次观测上榜22:07 观测离榜累计约48分钟 - 13MINI-26c5-jcfv-9rrq · MinimOS/kyverno-policy-reporter-plugin-fips
Affected packages: MinimOS/kyverno-policy-reporter-plugin-fips Attributes: No fix available
最高第 1 名22:07 达到22:07 首次观测上榜23:59 观测离榜累计约1小时52分 - 14MINI-3r77-4wgr-f5q3 · MinimOS/chronograf-fips
Affected packages: MinimOS/chronograf-fips Attributes: Fix available
最高第 1 名16:31 达到16:31 首次观测上榜18:39 观测离榜累计约2小时8分 - 15MINI-59pm-452g-j8r3 · MinimOS/ruby3.4-fluentd-kubernetes-daemonset-1.16-kinesis
Affected packages: MinimOS/ruby3.4-fluentd-kubernetes-daemonset-1.16-kinesis Attributes: No fix available
最高第 1 名03:59 达到03:59 首次观测上榜16:31 观测离榜累计约12小时32分 - 16MINI-852j-mq6w-2jrf · MinimOS/python-3.14
Affected packages: MinimOS/python-3.14、MinimOS/python-3.14-base、MinimOS/python-3.14-base-dev、MinimOS/python-3.14-dev、MinimOS/python-3.14-doc、... 1 more Attributes: Fix available
最高第 1 名19:59 达到19:59 首次观测上榜21:19 观测离榜累计约1小时20分 - 17MINI-9683-7wp9-4mrq · MinimOS/python-3.10
Affected packages: MinimOS/python-3.10、MinimOS/python-3.10-base、MinimOS/python-3.10-base-dev、MinimOS/python-3.10-dev、MinimOS/python-3.10-doc Attributes: Fix available
最高第 1 名18:55 达到18:55 首次观测上榜19:43 观测离榜累计约48分钟 - 18PSF-2026-35 · github.com/python/cpython
Affected packages: github.com/python/cpython Attributes: Fix available
最高第 1 名22:55 达到22:55 首次观测上榜23:59 观测离榜累计约1小时4分 - 19RHSA-2026:52761 · Red Hat Security Advisory: kernel-rt security update
Red Hat Security Advisory: kernel-rt security update Affected packages: Red Hat:enterprise_linux:8::nfv/kernel-rt、Red Hat:enterprise_linux:8::nfv/kernel-rt-core、Red Hat:enterprise_linux:8::nfv/kernel-rt-debug、Red Hat:enterprise_linux:8::nfv/kernel-rt-debug-core、Red Hat:enterprise_linux:8::nfv/kernel-rt-debug-debuginfo、... 23 more Attributes: Fix available、Severity - 5.5 (Medium)
最高第 1 名18:39 达到18:39 首次观测上榜19:43 观测离榜累计约1小时4分 - 20ROOT-OS-ALPINE-317-CVE-2025-69418 · CVE-2025-69418 in openssl - Patched by Root
CVE-2025-69418 in openssl - Patched by Root Affected packages: Root:Alpine:3.17/openssl、Root:Alpine:3.17/rootio-openssl Attributes: Fix available、Severity - 4.0 (Medium)
最高第 1 名00:31 达到00:31 首次观测上榜03:59 观测离榜累计约3小时28分 - 21ROOT-OS-DEBIAN-12-CVE-2011-4116 · CVE-2011-4116 in perl - Patched by Root
CVE-2011-4116 in perl - Patched by Root Affected packages: Root:Debian:12/perl、Root:Debian:12/rootio-perl Attributes: Fix available
最高第 1 名00:00 达到当日首次采集时已在榜03:59 观测离榜累计约3小时59分 - 22ROOT-OS-DEBIAN-13-CVE-2026-32327 · CVE-2026-32327 in apr-util - Patched by Root
CVE-2026-32327 in apr-util - Patched by Root Affected packages: Root:Debian:13/apr-util、Root:Debian:13/rootio-apr-util Attributes: Fix available
最高第 1 名17:35 达到17:35 首次观测上榜22:07 观测离榜上榜 2 次(重入 1 次)累计约1小时20分 - 23CGA-gw2f-vgrm-gw58 · Chainguard/jitsucom-jitsu-console
Affected packages: Chainguard/jitsucom-jitsu-console、Chainguard/langfuse-2-worker、Wolfi/jitsucom-jitsu-console Attributes: Fix available
最高第 2 名18:07 达到18:07 首次观测上榜18:39 观测离榜累计约32分钟 - 24DEBIAN-CVE-2026-61551 · Debian:11/icinga2
Affected packages: Debian:11/icinga2、Debian:12/icinga2、Debian:13/icinga2、Debian:14/icinga2 Attributes: Fix available
最高第 2 名23:11 达到23:11 首次观测上榜当日结束时仍在榜累计约48分钟 - 25EEF-CVE-2026-69659 · Memory exhaustion via unbounded deserialization of keyset pagination cursors in Ash.Page.Keyset
Memory exhaustion via unbounded deserialization of keyset pagination cursors in Ash.Page.Keyset Affected packages: Hex/ash、github.com/ash-project/ash Attributes: Fix available、Severity - 5.9 (Medium)
最高第 2 名02:23 达到02:23 首次观测上榜03:59 观测离榜累计约1小时36分 - 26JLSEC-2026-1238 · Julia/XML2_jll
Affected packages: Julia/XML2_jll Attributes: Fix available、Severity - 5.9 (Medium)
最高第 2 名10:07 达到10:07 首次观测上榜16:31 观测离榜累计约6小时24分 - 27MAL-2026-13681 · Malicious code in btcflip (PyPI)
Malicious code in btcflip (PyPI) Affected packages: PyPI/btcflip Attributes: No fix available
最高第 2 名14:55 达到14:55 首次观测上榜16:31 观测离榜累计约1小时36分 - 28MAL-2026-13685 · Malicious code in pytablute (PyPI)
Malicious code in pytablute (PyPI) Affected packages: PyPI/pytablute Attributes: No fix available
最高第 2 名17:51 达到17:51 首次观测上榜18:39 观测离榜累计约48分钟 - 29MAL-2026-13691 · Malicious code in @rblxts/services (npm)
Malicious code in @rblxts/services (npm) Affected packages: npm/@rblxts/services Attributes: No fix available
最高第 2 名21:03 达到21:03 首次观测上榜21:51 观测离榜累计约48分钟 - 30MAL-2026-13708 · Malicious code in xerohub-discord-voice (npm)
Malicious code in xerohub-discord-voice (npm) Affected packages: npm/xerohub-discord-voice Attributes: No fix available
最高第 2 名21:19 达到21:19 首次观测上榜22:07 观测离榜累计约48分钟 - 31MINI-5g56-6xhr-4w95 · MinimOS/chronograf-fips
Affected packages: MinimOS/chronograf-fips Attributes: Fix available
最高第 2 名16:31 达到16:31 首次观测上榜18:39 观测离榜累计约2小时8分 - 32MINI-6cv3-h6mc-9hrw · MinimOS/python-3.11
Affected packages: MinimOS/python-3.11、MinimOS/python-3.11-base、MinimOS/python-3.11-base-dev、MinimOS/python-3.11-dev、MinimOS/python-3.11-doc Attributes: Fix available
最高第 2 名18:55 达到18:55 首次观测上榜19:43 观测离榜累计约48分钟 - 33MINI-8m8g-jg9p-86vj · MinimOS/kyverno-policy-reporter-plugin-fips
Affected packages: MinimOS/kyverno-policy-reporter-plugin-fips Attributes: No fix available
最高第 2 名22:07 达到22:07 首次观测上榜23:59 观测离榜累计约1小时52分 - 34MINI-c2pp-f9x7-xv84 · MinimOS/ruby3.4-fluentd-kubernetes-daemonset-1.16-kinesis
Affected packages: MinimOS/ruby3.4-fluentd-kubernetes-daemonset-1.16-kinesis Attributes: No fix available
最高第 2 名03:59 达到03:59 首次观测上榜16:31 观测离榜累计约12小时32分 - 35RHSA-2026:52674 · Red Hat Security Advisory: libarchive security update
Red Hat Security Advisory: libarchive security update Affected packages: Red Hat:enterprise_linux:9::appstream/bsdcat-debuginfo、Red Hat:enterprise_linux:9::appstream/bsdcpio-debuginfo、Red Hat:enterprise_linux:9::appstream/bsdtar、Red Hat:enterprise_linux:9::appstream/bsdtar-debuginfo、Red Hat:enterprise_linux:9::appstream/libarchive-debuginfo、... 8 more Attributes: Fix available、Severity - 7.5 (High)
最高第 2 名18:39 达到18:39 首次观测上榜19:43 观测离榜累计约1小时4分 - 36ROOT-OS-ALPINE-315-CVE-2026-8932 · CVE-2026-8932 in curl - Patched by Root
CVE-2026-8932 in curl - Patched by Root Affected packages: Root:Alpine:3.15/curl、Root:Alpine:3.15/rootio-curl Attributes: Fix available
最高第 2 名19:43 达到19:43 首次观测上榜21:19 观测离榜累计约1小时36分 - 37ROOT-OS-ALPINE-317-CVE-2026-28387 · CVE-2026-28387 in openssl - Patched by Root
CVE-2026-28387 in openssl - Patched by Root Affected packages: Root:Alpine:3.17/openssl、Root:Alpine:3.17/rootio-openssl Attributes: Fix available、Severity - 8.1 (High)
最高第 2 名00:31 达到00:31 首次观测上榜03:59 观测离榜累计约3小时28分 - 38ROOT-OS-DEBIAN-12-CVE-2023-31486 · CVE-2023-31486 in perl - Patched by Root
CVE-2023-31486 in perl - Patched by Root Affected packages: Root:Debian:12/libhttp-tiny-perl、Root:Debian:12/perl、Root:Debian:12/rootio-libhttp-tiny-perl、Root:Debian:12/rootio-perl Attributes: Fix available
最高第 2 名00:00 达到当日首次采集时已在榜02:23 观测离榜累计约2小时23分 - 39ROOT-OS-DEBIAN-13-CVE-2025-49506 · CVE-2025-49506 in apr-util - Patched by Root
CVE-2025-49506 in apr-util - Patched by Root Affected packages: Root:Debian:13/apr-util、Root:Debian:13/rootio-apr-util Attributes: Fix available
最高第 2 名21:51 达到21:51 首次观测上榜22:07 观测离榜累计约16分钟 - 40DEBIAN-CVE-2026-61550 · Debian:11/icinga2
Affected packages: Debian:11/icinga2、Debian:12/icinga2、Debian:13/icinga2、Debian:14/icinga2 Attributes: Fix available
最高第 3 名23:11 达到23:11 首次观测上榜当日结束时仍在榜累计约48分钟 - 41JLSEC-2026-1239 · Julia/XML2_jll
Affected packages: Julia/XML2_jll Attributes: Fix available、Severity - 2.9 (Low)
最高第 3 名10:07 达到10:07 首次观测上榜16:31 观测离榜累计约6小时24分 - 42MAL-2026-13683 · Malicious code in kotoraka (PyPI)
Malicious code in kotoraka (PyPI) Affected packages: PyPI/kotoraka Attributes: No fix available
最高第 3 名14:55 达到14:55 首次观测上榜16:31 观测离榜累计约1小时36分 - 43MAL-2026-13696 · Malicious code in postcss-initial-provider (npm)
Malicious code in postcss-initial-provider (npm) Affected packages: npm/postcss-initial-provider Attributes: No fix available
最高第 3 名21:03 达到21:03 首次观测上榜21:51 观测离榜累计约48分钟 - 44MAL-2026-13706 · Malicious code in neverthrow-js (npm)
Malicious code in neverthrow-js (npm) Affected packages: npm/neverthrow-js Attributes: No fix available
最高第 3 名21:19 达到21:19 首次观测上榜22:07 观测离榜累计约48分钟 - 45MINI-5r2v-5g2j-7fjg · MinimOS/chronograf-fips
Affected packages: MinimOS/chronograf-fips Attributes: Fix available
最高第 3 名16:31 达到16:31 首次观测上榜18:39 观测离榜累计约2小时8分 - 46MINI-7grw-h2m7-h6mw · MinimOS/python-3.12
Affected packages: MinimOS/python-3.12、MinimOS/python-3.12-base、MinimOS/python-3.12-base-dev、MinimOS/python-3.12-dev、MinimOS/python-3.12-doc、... 1 more Attributes: Fix available
最高第 3 名18:55 达到18:55 首次观测上榜19:43 观测离榜累计约48分钟 - 47MINI-9x74-778q-g7gx · MinimOS/kyverno-policy-reporter-plugin-fips
Affected packages: MinimOS/kyverno-policy-reporter-plugin-fips Attributes: No fix available
最高第 3 名22:07 达到22:07 首次观测上榜23:59 观测离榜累计约1小时52分 - 48MINI-j4wq-cp5r-ccw7 · MinimOS/ruby3.4-fluentd-kubernetes-daemonset-1.16-kinesis
Affected packages: MinimOS/ruby3.4-fluentd-kubernetes-daemonset-1.16-kinesis Attributes: No fix available
最高第 3 名03:59 达到03:59 首次观测上榜16:31 观测离榜累计约12小时32分 - 49PYSEC-2026-3655 · pypdf: Possible large memory usage for large /ToUnicode streams
pypdf: Possible large memory usage for large /ToUnicode streams Affected packages: PyPI/pypdf Attributes: Fix available、Severity - 4.8 (Medium)
最高第 3 名19:43 达到19:43 首次观测上榜21:19 观测离榜累计约1小时36分 - 50RHSA-2026:52675 · Red Hat Security Advisory: libarchive security update
Red Hat Security Advisory: libarchive security update Affected packages: Red Hat:enterprise_linux:10.2/bsdcat-debuginfo、Red Hat:enterprise_linux:10.2/bsdcpio-debuginfo、Red Hat:enterprise_linux:10.2/bsdtar、Red Hat:enterprise_linux:10.2/bsdtar-debuginfo、Red Hat:enterprise_linux:10.2/bsdunzip-debuginfo、... 4 more Attributes: Fix available、Severity - 7.5 (High)
最高第 3 名18:39 达到18:39 首次观测上榜19:43 观测离榜累计约1小时4分


































































































