
OSV.dev · 实时热榜
- 01BIT-gitlab-2026-19650 · Cross-Site Request Forgery (CSRF) in GitLab
Cross-Site Request Forgery (CSRF) in GitLab Affected packages: Bitnami/gitlab Attributes: Fix available、Severity - 7.1 (High)
最高第 1 名17:19 达到17:19 首次观测上榜18:23 观测离榜累计约1小时4分 - 02CLSA-2026-1787292931 · TuxCare security update for io.projectreactor.netty (2 CVEs)
TuxCare security update for io.projectreactor.netty (2 CVEs) Affected packages: TuxCare:Maven/io.projectreactor.netty:reactor-netty、TuxCare:Maven/io.projectreactor.netty:reactor-netty-core、TuxCare:Maven/io.projectreactor.netty:reactor-netty-http、TuxCare:Maven/io.projectreactor.netty:reactor-netty-http-brave Attributes: Fix available
最高第 1 名15:27 达到15:27 首次观测上榜17:19 观测离榜累计约1小时52分 - 03ECHO-2595-990f-e6ce · Echo/libsoup3
Affected packages: Echo/libsoup3 Attributes: No fix available
最高第 1 名09:51 达到09:51 首次观测上榜14:39 观测离榜累计约4小时48分 - 04ECHO-a2fc-1e4e-dfa3 · Echo/graphicsmagick
Affected packages: Echo/graphicsmagick Attributes: No fix available
最高第 1 名16:47 达到16:47 首次观测上榜17:19 观测离榜累计约32分钟 - 05EEF-CVE-2026-75484 · HTTP/2 header field values containing CR, LF or NUL are passed to the application unvalidated in Bandit
HTTP/2 header field values containing CR, LF or NUL are passed to the application unvalidated in Bandit Affected packages: Hex/bandit、github.com/mtrudel/bandit Attributes: Fix available、Severity - 6.9 (Medium)
最高第 1 名05:19 达到05:19 首次观测上榜07:43 观测离榜累计约2小时24分 - 06GHSA-42vx-43vc-x6pr · Laravel Backpack CRUD: HasMany/MorphMany relation fields allow cross-tenant record re-parenting (IDOR) via attachManyRelation
Laravel Backpack CRUD: HasMany/MorphMany relation fields allow cross-tenant record re-parenting (IDOR) via attachManyRelation Affected packages: Packagist/backpack/crud Attributes: Fix available、Severity - 6.5 (Medium)
最高第 1 名02:55 达到02:55 首次观测上榜03:11 观测离榜累计约16分钟 - 07GHSA-533j-2v4q-mw5h · LangChain MongoDB has NoSQL Operator Injection in MongoDBSaver.list() leading to cross-tenant data exposure
LangChain MongoDB has NoSQL Operator Injection in MongoDBSaver.list() leading to cross-tenant data exposure Affected packages: PyPI/langgraph-checkpoint-mongodb、PyPI/langgraph-store-mongodb Attributes: Fix available、Severity - 7.7 (High)
最高第 1 名01:51 达到01:51 首次观测上榜02:55 观测离榜累计约1小时4分 - 08GHSA-8r62-w5wh-fc5m · Mailpit: WebSocket origin check bypass via percent-encoded path (regression of CVE-2026-22689)
Mailpit: WebSocket origin check bypass via percent-encoded path (regression of CVE-2026-22689) Affected packages: Go/github.com/axllent/mailpit Attributes: Fix available、Severity - 6.5 (Medium)
最高第 1 名05:51 达到05:51 首次观测上榜07:43 观测离榜累计约1小时52分 - 09GHSA-9w56-46f6-3qhx · asteval Sandbox Escape: arbitrary native memory read/write via numpy ctypes in default asteval Interpreter
asteval Sandbox Escape: arbitrary native memory read/write via numpy ctypes in default asteval Interpreter Affected packages: PyPI/asteval Attributes: Fix available、Severity - 5.5 (Medium)
最高第 1 名01:35 达到01:35 首次观测上榜02:39 观测离榜累计约1小时4分 - 10GHSA-f4jp-rw7w-ccwg · gettext-converter: Prototype pollution in js2i18next() via crafted translation keys
gettext-converter: Prototype pollution in js2i18next() via crafted translation keys Affected packages: npm/gettext-converter Attributes: Fix available、Severity - 6.9 (Medium)
最高第 1 名04:15 达到04:15 首次观测上榜07:43 观测离榜累计约3小时28分 - 11GHSA-jm5p-837g-rv8g · Wagtail: Improper restriction handling on Page translation API endpoint
Wagtail: Improper restriction handling on Page translation API endpoint Affected packages: PyPI/wagtail Attributes: Fix available、Severity - 6.5 (Medium)
最高第 1 名03:11 达到03:11 首次观测上榜07:27 观测离榜累计约4小时16分 - 12MAL-2026-14324 · Malicious code in create-react-app-text (npm)
Malicious code in create-react-app-text (npm) Affected packages: npm/create-react-app-text Attributes: No fix available
最高第 1 名00:31 达到00:31 首次观测上榜01:35 观测离榜累计约1小时4分 - 13MAL-2026-14331 · Malicious code in exam-kit (npm)
Malicious code in exam-kit (npm) Affected packages: npm/exam-kit Attributes: No fix available
最高第 1 名02:39 达到02:39 首次观测上榜02:55 观测离榜累计约16分钟 - 14MAL-2026-14341 · Malicious code in reqcrypts (PyPI)
Malicious code in reqcrypts (PyPI) Affected packages: PyPI/reqcrypts Attributes: No fix available
最高第 1 名10:55 达到10:55 首次观测上榜14:39 观测离榜累计约3小时44分 - 15MAL-2026-14342 · Malicious code in coin-fees (npm)
Malicious code in coin-fees (npm) Affected packages: npm/coin-fees Attributes: No fix available
最高第 1 名11:43 达到11:43 首次观测上榜15:27 观测离榜累计约3小时44分 - 16MAL-2026-14343 · Malicious code in chai-as-soul (npm)
Malicious code in chai-as-soul (npm) Affected packages: npm/chai-as-soul Attributes: No fix available
最高第 1 名12:15 达到12:15 首次观测上榜15:27 观测离榜累计约3小时12分 - 17MAL-2026-14345 · Malicious code in express-session-handler (npm)
Malicious code in express-session-handler (npm) Affected packages: npm/express-session-handler Attributes: No fix available
最高第 1 名12:31 达到12:31 首次观测上榜15:27 观测离榜累计约2小时56分 - 18MAL-2026-14346 · Malicious code in @next-fonts/font (npm)
Malicious code in @next-fonts/font (npm) Affected packages: npm/@next-fonts/font Attributes: No fix available
最高第 1 名13:03 达到13:03 首次观测上榜15:27 观测离榜累计约2小时24分 - 19MINI-4hq8-c7vw-mv4m · MinimOS/elasticsearch-fips-9.5
Affected packages: MinimOS/elasticsearch-fips-9.5 Attributes: Fix available
最高第 1 名11:11 达到11:11 首次观测上榜14:39 观测离榜累计约3小时28分 - 20MINI-6x39-vh65-28cx · MinimOS/jenkins-2.555
Affected packages: MinimOS/jenkins-2.555、MinimOS/jenkins-2.555-advanced-compat、MinimOS/jenkins-2.555-compat、MinimOS/jenkins-2.555-entrypoint、MinimOS/jenkins-2.555-remoting Attributes: No fix available
最高第 1 名07:43 达到07:43 首次观测上榜07:59 观测离榜累计约16分钟 - 21MINI-8mq3-x96h-h8vr · MinimOS/prometheus-fips-2.53
Affected packages: MinimOS/prometheus-fips-2.53 Attributes: No fix available
最高第 1 名07:59 达到07:59 首次观测上榜13:03 观测离榜累计约5小时4分 - 22MINI-98qh-3xf2-gq4h · MinimOS/copa-fips
Affected packages: MinimOS/copa-fips Attributes: Fix available
最高第 1 名07:27 达到07:27 首次观测上榜07:43 观测离榜累计约16分钟 - 23MINI-p456-4456-jhcv · MinimOS/apache-activemq-6.1-fips
Affected packages: MinimOS/apache-activemq-6.1-fips、MinimOS/apache-activemq-6.1-fips-oci-entrypoint Attributes: No fix available
最高第 1 名01:19 达到01:19 首次观测上榜02:39 观测离榜累计约1小时20分 - 24RLSA-2026:57574 · Important: php:8.2 security, bug fix, and enhancement update
Important: php:8.2 security, bug fix, and enhancement update Affected packages: Rocky Linux:8/libzip、Rocky Linux:8/php-pear、Rocky Linux:8/php-pecl-apcu、Rocky Linux:8/php-pecl-rrd、Rocky Linux:8/php-pecl-xdebug3、... 1 more Attributes: Fix available、Severity - 7.4 (High)
最高第 1 名08:31 达到08:31 首次观测上榜14:39 观测离榜累计约6小时8分 - 25RLSA-2026:57610 · Moderate: kbd security update
Moderate: kbd security update Affected packages: Rocky Linux:9/kbd Attributes: Fix available、Severity - 7.8 (High)
最高第 1 名14:39 达到14:39 首次观测上榜15:43 观测离榜累计约1小时4分 - 26ROOT-APP-NPM-CVE-2026-67214 · CVE-2026-67214 in nanoid - Patched by Root
CVE-2026-67214 in nanoid - Patched by Root Affected packages: Root:npm/@rootio/nanoid、Root:npm/nanoid Attributes: Fix available
最高第 1 名15:43 达到15:43 首次观测上榜17:19 观测离榜累计约1小时36分 - 27ROOT-OS-DEBIAN-11-CVE-2023-34152 · CVE-2023-34152 in imagemagick - Patched by Root
CVE-2023-34152 in imagemagick - Patched by Root Affected packages: Root:Debian:11/imagemagick、Root:Debian:11/rootio-imagemagick Attributes: Fix available、Severity - 9.8 (Critical)
最高第 1 名00:00 达到当日首次采集时已在榜01:19 观测离榜累计约1小时20分 - 28UBUNTU-CVE-2026-75803 · Ubuntu:22.04:LTS/openssl
Affected packages: Ubuntu:22.04:LTS/openssl、Ubuntu:24.04:LTS/edk2、Ubuntu:24.04:LTS/openssl、Ubuntu:26.04:LTS/edk2、Ubuntu:26.04:LTS/openssl、... 7 more Attributes: No fix available
最高第 1 名18:07 达到18:07 首次观测上榜当日结束时仍在榜累计约5小时37分 - 29BIT-discourse-2026-55704 · Discourse: Shared-draft titles and excerpts leak through group post serialization
Discourse: Shared-draft titles and excerpts leak through group post serialization Affected packages: Bitnami/discourse Attributes: Fix available、Severity - 4.3 (Medium)
最高第 2 名20:15 达到20:15 首次观测上榜21:51 观测离榜累计约1小时36分 - 30BIT-gitlab-2026-19478 · Improper Control of Generation of Code ('Code Injection') in GitLab
Improper Control of Generation of Code ('Code Injection') in GitLab Affected packages: Bitnami/gitlab Attributes: Fix available、Severity - 9.4 (Critical)
最高第 2 名17:19 达到17:19 首次观测上榜18:23 观测离榜累计约1小时4分 - 31EEF-CVE-2026-47079 · Round-trip Corruption via Improper Entity Escaping in xml_builder
Round-trip Corruption via Improper Entity Escaping in xml_builder Affected packages: Hex/xml_builder、github.com/joshnuss/xml_builder Attributes: Fix available、Severity - 2.1 (Low)
最高第 2 名18:07 达到18:07 首次观测上榜18:23 观测离榜累计约16分钟 - 32EEF-CVE-2026-74836 · HTTP/2 connection-window starvation pins Plug processes indefinitely in Bandit
HTTP/2 connection-window starvation pins Plug processes indefinitely in Bandit Affected packages: Hex/bandit、github.com/mtrudel/bandit Attributes: Fix available、Severity - 8.7 (High)
最高第 2 名05:19 达到05:19 首次观测上榜07:43 观测离榜累计约2小时24分 - 33GHSA-3vrh-m9w7-v94f · Wagtail: Improper restriction handling on Pages admin API
Wagtail: Improper restriction handling on Pages admin API Affected packages: PyPI/wagtail Attributes: Fix available、Severity - 4.3 (Medium)
最高第 2 名02:55 达到02:55 首次观测上榜03:11 观测离榜累计约16分钟 - 34GHSA-qqff-5854-px68 · vouch-proxy has an Unbounded Multipart Cookie Allocation DoS
vouch-proxy has an Unbounded Multipart Cookie Allocation DoS Affected packages: Go/github.com/vouch/vouch-proxy Attributes: Fix available、Severity - 7.5 (High)
最高第 2 名01:35 达到01:35 首次观测上榜02:39 观测离榜累计约1小时4分 - 35GHSA-r553-m4fv-5v97 · Mailpit: SMTP DATA line reader buffers over-limit input before size enforcement
Mailpit: SMTP DATA line reader buffers over-limit input before size enforcement Affected packages: Go/github.com/axllent/mailpit Attributes: Fix available、Severity - 5.3 (Medium)
最高第 2 名05:51 达到05:51 首次观测上榜07:43 观测离榜累计约1小时52分 - 36GHSA-rrwh-6jrq-wp5v · Dgraph Alpha group stores can be replaced via unauthenticated external snapshot import
Dgraph Alpha group stores can be replaced via unauthenticated external snapshot import Affected packages: Go/github.com/dgraph-io/dgraph/v25 Attributes: Fix available、Severity - 9.1 (Critical)
最高第 2 名01:51 达到01:51 首次观测上榜02:55 观测离榜累计约1小时4分 - 37GHSA-x5cx-w6p2-mxf2 · Wagtail: Improper permission handling when copying snippets
Wagtail: Improper permission handling when copying snippets Affected packages: PyPI/wagtail Attributes: Fix available、Severity - 6.5 (Medium)
最高第 2 名03:11 达到03:11 首次观测上榜07:27 观测离榜累计约4小时16分 - 38MAL-2026-14325 · Malicious code in create-react-app-ui (npm)
Malicious code in create-react-app-ui (npm) Affected packages: npm/create-react-app-ui Attributes: No fix available
最高第 2 名00:31 达到00:31 首次观测上榜01:35 观测离榜累计约1小时4分 - 39MAL-2026-14329 · Malicious code in @pablo_clueless/printr (npm)
Malicious code in @pablo_clueless/printr (npm) Affected packages: npm/@pablo_clueless/printr Attributes: No fix available
最高第 2 名02:39 达到02:39 首次观测上榜02:55 观测离榜累计约16分钟 - 40MAL-2026-14344 · Malicious code in @js-lib-team/env-parser (npm)
Malicious code in @js-lib-team/env-parser (npm) Affected packages: npm/@js-lib-team/env-parser Attributes: No fix available
最高第 2 名12:31 达到12:31 首次观测上榜15:27 观测离榜累计约2小时56分 - 41MAL-2026-14347 · Malicious code in mcq-session (npm)
Malicious code in mcq-session (npm) Affected packages: npm/mcq-session Attributes: No fix available
最高第 2 名13:03 达到13:03 首次观测上榜15:27 观测离榜累计约2小时24分 - 42MAL-2026-14349 · Malicious code in boto4 (PyPI)
Malicious code in boto4 (PyPI) Affected packages: PyPI/boto4 Attributes: No fix available
最高第 2 名17:03 达到17:03 首次观测上榜17:19 观测离榜累计约16分钟 - 43MAL-2026-14351 · Malicious code in requests-crypt (PyPI)
Malicious code in requests-crypt (PyPI) Affected packages: PyPI/requests-crypt Attributes: No fix available
最高第 2 名19:27 达到19:27 首次观测上榜19:43 观测离榜累计约16分钟 - 44MAL-2026-14352 · Malicious code in tailwind-animate-css-plugin (npm)
Malicious code in tailwind-animate-css-plugin (npm) Affected packages: npm/tailwind-animate-css-plugin Attributes: No fix available
最高第 2 名19:43 达到19:43 首次观测上榜21:51 观测离榜累计约2小时8分 - 45MINI-452q-9vp2-c7v9 · MinimOS/crossplane
Affected packages: MinimOS/crossplane、MinimOS/crossplane-crank Attributes: No fix available
最高第 2 名23:27 达到23:27 首次观测上榜23:44 观测离榜累计约17分钟 - 46MINI-6742-8hx5-xmjg · MinimOS/elastic-otel-collector-9.5
Affected packages: MinimOS/elastic-otel-collector-9.5 Attributes: Fix available
最高第 2 名11:11 达到11:11 首次观测上榜14:39 观测离榜累计约3小时28分 - 47MINI-c364-xg57-c7vj · MinimOS/cluster-api-aws-controller
Affected packages: MinimOS/cluster-api-aws-controller Attributes: No fix available
最高第 2 名23:11 达到23:11 首次观测上榜23:27 观测离榜累计约16分钟 - 48MINI-c8vw-677g-69vr · MinimOS/prometheus-fips-2.53
Affected packages: MinimOS/prometheus-fips-2.53 Attributes: No fix available
最高第 2 名07:59 达到07:59 首次观测上榜13:03 观测离榜累计约5小时4分 - 49MINI-fp8f-cx55-c57r · MinimOS/cloudbeat-9.4
Affected packages: MinimOS/cloudbeat-9.4 Attributes: Fix available
最高第 2 名07:27 达到07:27 首次观测上榜07:43 观测离榜累计约16分钟 - 50MINI-g2rc-pw58-4c2v · MinimOS/eks-kube-apiserver-1.31
Affected packages: MinimOS/eks-kube-apiserver-1.31、MinimOS/eks-kube-controller-manager-1.31、MinimOS/eks-kube-proxy-1.31、MinimOS/eks-kube-scheduler-1.31、MinimOS/eks-kubelet-1.31 Attributes: No fix available
最高第 2 名23:44 达到23:44 首次观测上榜当日结束时仍在榜累计约0分钟


































































































