
OSV.dev · 实时热榜
- 01BIT-gitlab-2026-10053 · Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GitLab
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GitLab Affected packages: Bitnami/gitlab Attributes: Fix available、Severity - 8.5 (High)
最高第 1 名23:57 达到23:57 首次观测上榜当日结束时仍在榜累计约0分钟 - 02CGA-v485-2jrm-hrh2 · Chainguard/apache-pulsar-fips-4.0
Affected packages: Chainguard/apache-pulsar-fips-4.0、Chainguard/druid、Wolfi/druid Attributes: Fix available
最高第 1 名12:13 达到12:13 首次观测上榜13:33 观测离榜累计约1小时20分 - 03DEBIAN-CVE-2026-18374 · Debian:11/glibc
Affected packages: Debian:11/glibc、Debian:12/glibc、Debian:13/glibc、Debian:14/glibc Attributes: No fix available
最高第 1 名07:09 达到07:09 首次观测上榜09:01 观测离榜累计约1小时52分 - 04DEBIAN-CVE-2026-80607 · Debian:13/linux
Affected packages: Debian:13/linux、Debian:14/linux Attributes: Fix available
最高第 1 名17:01 达到17:01 首次观测上榜18:53 观测离榜累计约1小时52分 - 05DEBIAN-CVE-2026-81499 · Debian:14/incus
Affected packages: Debian:14/incus Attributes: Fix available
最高第 1 名14:05 达到14:05 首次观测上榜16:45 观测离榜累计约2小时40分 - 06ECHO-9169-1fd9-0c1c · Echo/glibc
Affected packages: Echo/glibc Attributes: No fix available
最高第 1 名09:17 达到09:17 首次观测上榜13:33 观测离榜累计约4小时16分 - 07ECHO-add6-7bb2-f327 · Echo/glibc
Affected packages: Echo/glibc Attributes: No fix available
最高第 1 名21:17 达到21:17 首次观测上榜当日结束时仍在榜累计约2小时40分 - 08ECHO-b76b-475e-7ef9 · Echo/gdk-pixbuf
Affected packages: Echo/gdk-pixbuf Attributes: No fix available
最高第 1 名22:21 达到22:21 首次观测上榜当日结束时仍在榜累计约1小时36分 - 09EEF-CVE-2026-66353 · Doggo vulnerable to cross-site scripting via unescaped date field values
Doggo vulnerable to cross-site scripting via unescaped date field values Affected packages: Hex/doggo、github.com/woylie/doggo Attributes: Fix available、Severity - 5.3 (Medium)
最高第 1 名00:45 达到00:45 首次观测上榜02:37 观测离榜累计约1小时52分 - 10EEF-CVE-2026-75758 · Unbounded recursion between Inspect.List charlist rendering and List.to_string/1 error path in Elixir
Unbounded recursion between Inspect.List charlist rendering and List.to_string/1 error path in Elixir Affected packages: github.com/elixir-lang/elixir Attributes: Fix available、Severity - 5.9 (Medium)
最高第 1 名19:41 达到19:41 首次观测上榜20:13 观测离榜累计约32分钟 - 11GHSA-6hx8-3wjj-gr8g · WebOb: Open redirect in Location header normalization via leading C0 control / space characters
WebOb: Open redirect in Location header normalization via leading C0 control / space characters Affected packages: PyPI/webob Attributes: Fix available、Severity - 6.1 (Medium)
最高第 1 名06:21 达到06:21 首次观测上榜13:33 观测离榜累计约7小时12分 - 12GHSA-crx4-7mmq-j74j · OpenSTAManager has HTML Injection in modules/utenti/edit.php
OpenSTAManager has HTML Injection in modules/utenti/edit.php Affected packages: Packagist/devcode-it/openstamanager Attributes: Fix available、Severity - 3.5 (Low)
最高第 1 名00:00 达到当日首次采集时已在榜00:13 观测离榜累计约13分钟 - 13GHSA-g8wr-r2v2-vqc6 · silverstripe/userforms vulnerable to remote code execution via userforms email subject
silverstripe/userforms vulnerable to remote code execution via userforms email subject Affected packages: Packagist/silverstripe/userforms Attributes: Fix available、Severity - 8.8 (High)
最高第 1 名01:01 达到01:01 首次观测上榜02:37 观测离榜累计约1小时36分 - 14GHSA-mf7q-r4rv-jv94 · Crossplane's TOCTOU between cosign verification and image fetch in xpkg.CachedClient allows tag-based package install to bypass signature check
Crossplane's TOCTOU between cosign verification and image fetch in xpkg.CachedClient allows tag-based package install to bypass signature check Affected packages: Go/github.com/crossplane/crossplane-runtime/v2 Attributes: Fix available、Severity - 8.2 (High)
最高第 1 名01:33 达到01:33 首次观测上榜02:37 观测离榜累计约1小时4分 - 15GHSA-q7m3-rhxg-7vxr · n8n-nodes-sqlite3 vulnerable to path traversal via user-controlled database file path (db_path parameter)
n8n-nodes-sqlite3 vulnerable to path traversal via user-controlled database file path (db_path parameter) Affected packages: npm/n8n-nodes-sqlite3 Attributes: Fix available、Severity - 6.1 (Medium)
最高第 1 名01:17 达到01:17 首次观测上榜02:37 观测离榜累计约1小时20分 - 16GHSA-vxj7-4xrp-5vr4 · aiosmtplib: STARTTLS response injection
aiosmtplib: STARTTLS response injection Affected packages: PyPI/aiosmtplib Attributes: Fix available、Severity - 5.9 (Medium)
最高第 1 名07:57 达到07:57 首次观测上榜13:33 观测离榜累计约5小时36分 - 17GO-2026-6296 · Kyverno's NamespacedGeneratingPolicy generator.apply() namespace argument unvalidated -- background controller creates RoleBindings in any namespace including kube-system in github.com/kyverno/kyverno
Kyverno's NamespacedGeneratingPolicy generator.apply() namespace argument unvalidated -- background controller creates RoleBindings in any namespace including kube-system in github.com/kyverno/kyverno Affected packages: Go/github.com/kyverno/kyverno Attributes: Fix available
最高第 1 名04:29 达到04:29 首次观测上榜08:45 观测离榜累计约4小时16分 - 18GO-2026-6303 · Source-address critical option not enforced for non-public-key auth callbacks in golang.org/x/crypto/ssh
Source-address critical option not enforced for non-public-key auth callbacks in golang.org/x/crypto/ssh Affected packages: Go/golang.org/x/crypto Attributes: Fix available
最高第 1 名23:25 达到23:25 首次观测上榜当日结束时仍在榜累计约32分钟 - 19MAL-2026-14567 · Malicious code in tailwindcss-3d-animate (npm)
Malicious code in tailwindcss-3d-animate (npm) Affected packages: npm/tailwindcss-3d-animate Attributes: No fix available
最高第 1 名03:09 达到03:09 首次观测上榜06:53 观测离榜累计约3小时44分 - 20MAL-2026-14578 · Malicious code in pushgitquickx (npm)
Malicious code in pushgitquickx (npm) Affected packages: npm/pushgitquickx Attributes: No fix available
最高第 1 名06:53 达到06:53 首次观测上榜13:33 观测离榜累计约6小时40分 - 21MAL-2026-14586 · Malicious code in @fleetbo/svro (npm)
Malicious code in @fleetbo/svro (npm) Affected packages: npm/@fleetbo/svro Attributes: No fix available
最高第 1 名13:01 达到13:01 首次观测上榜13:33 观测离榜累计约32分钟 - 22MGASA-2026-0338 · Updated avahi packages fix security vulnerabilities
Updated avahi packages fix security vulnerabilities Affected packages: Mageia:10/avahi、Mageia:9/avahi Attributes: Fix available
最高第 1 名03:41 达到03:41 首次观测上榜06:53 观测离榜累计约3小时12分 - 23MINI-2738-6745-57jq · MinimOS/linstor-server-fips
Affected packages: MinimOS/linstor-server-fips Attributes: Fix available
最高第 1 名13:33 达到13:33 首次观测上榜16:45 观测离榜累计约3小时12分 - 24MINI-4fjm-6gxc-gqwg · MinimOS/splunk-otel-collector-fips
Affected packages: MinimOS/splunk-otel-collector-fips Attributes: Fix available
最高第 1 名20:13 达到20:13 首次观测上榜23:57 观测离榜累计约3小时44分 - 25MINI-c99c-8m97-w8cp · MinimOS/corretto-fips-config-8
Affected packages: MinimOS/corretto-fips-config-8 Attributes: Fix available
最高第 1 名00:13 达到00:13 首次观测上榜02:21 观测离榜累计约2小时8分 - 26MINI-pp77-qqg5-cf8w · MinimOS/apache-activemq-6.1-fips
Affected packages: MinimOS/apache-activemq-6.1-fips Attributes: No fix available
最高第 1 名02:37 达到02:37 首次观测上榜06:21 观测离榜累计约3小时44分 - 27RHSA-2026:60485 · Red Hat Security Advisory: kernel security update
Red Hat Security Advisory: kernel security update Affected packages: Red Hat:rhel_aus:8.6::baseos/bpftool、Red Hat:rhel_aus:8.6::baseos/bpftool-debuginfo、Red Hat:rhel_aus:8.6::baseos/kernel、Red Hat:rhel_aus:8.6::baseos/kernel-abi-stablelists、Red Hat:rhel_aus:8.6::baseos/kernel-core、... 43 more Attributes: Fix available、Severity - 7.8 (High)
最高第 1 名18:21 达到18:21 首次观测上榜20:13 观测离榜累计约1小时52分 - 28RLSA-2026:60394 · Moderate: libxml2 security update
Moderate: libxml2 security update Affected packages: Rocky Linux:10/libxml2 Attributes: Fix available、Severity - 4.8 (Medium)
最高第 1 名20:45 达到20:45 首次观测上榜当日结束时仍在榜累计约3小时12分 - 29ROOT-APP-NPM-CVE-2023-44270 · CVE-2023-44270 in postcss - Patched by Root
CVE-2023-44270 in postcss - Patched by Root Affected packages: Root:npm/@rootio/postcss、Root:npm/postcss Attributes: Fix available
最高第 1 名16:45 达到16:45 首次观测上榜17:01 观测离榜累计约16分钟 - 30ROOT-APP-NPM-CVE-2023-45133 · CVE-2023-45133 in babel-traverse - Patched by Root
CVE-2023-45133 in babel-traverse - Patched by Root Affected packages: Root:npm/@babel/traverse、Root:npm/@rootio/babel-traverse、Root:npm/@rootio/babel__traverse、Root:npm/babel-traverse Attributes: Fix available
最高第 1 名02:21 达到01:17 首次观测上榜06:53 观测离榜上榜 2 次(重入 1 次)累计约3小时44分 - 31BIT-tomcat-2026-65637 · Apache Tomcat: HTTP/2 no-authority bypass of strict SNI validation - CVE-2026-32990 fix incomplete
Apache Tomcat: HTTP/2 no-authority bypass of strict SNI validation - CVE-2026-32990 fix incomplete Affected packages: Bitnami/tomcat Attributes: Fix available、Severity - 9.8 (Critical)
最高第 2 名23:57 达到23:57 首次观测上榜当日结束时仍在榜累计约0分钟 - 32DEBIAN-CVE-2026-80590 · Debian:11/linux
Affected packages: Debian:11/linux、Debian:12/linux、Debian:13/linux、Debian:14/linux Attributes: No fix available
最高第 2 名17:01 达到17:01 首次观测上榜18:53 观测离榜累计约1小时52分 - 33DEBIAN-CVE-2026-81494 · Debian:14/incus
Affected packages: Debian:14/incus Attributes: Fix available
最高第 2 名14:05 达到14:05 首次观测上榜16:45 观测离榜累计约2小时40分 - 34GHSA-gmxc-r82q-347r · libreoffice-convert vulnerable to path traversal / arbitrary file write
libreoffice-convert vulnerable to path traversal / arbitrary file write Affected packages: npm/libreoffice-convert Attributes: Fix available、Severity - 6.5 (Medium)
最高第 2 名01:33 达到01:33 首次观测上榜02:37 观测离榜累计约1小时4分 - 35GHSA-gvrw-qqp5-jgc5 · Silverstripe Framework: Possible XSS attack through media embed
Silverstripe Framework: Possible XSS attack through media embed Affected packages: Packagist/silverstripe/framework Attributes: Fix available、Severity - 5.4 (Medium)
最高第 2 名01:01 达到01:01 首次观测上榜02:37 观测离榜累计约1小时36分 - 36GHSA-r5pm-vrc5-3m73 · cakephp/queue's Incomplete Comparison in getUniqueId vulnerable to collisions
cakephp/queue's Incomplete Comparison in getUniqueId vulnerable to collisions Affected packages: Packagist/cakephp/queue Attributes: Fix available、Severity - 3.7 (Low)
最高第 2 名01:17 达到01:17 首次观测上榜02:37 观测离榜累计约1小时20分 - 37GO-2026-6297 · linx-server has an issue in the uploadPostHandler component that allows attackers to cause a Denial of Service (DoS) via a crafted POST request in github.com/andreimarcu/linx-server
linx-server has an issue in the uploadPostHandler component that allows attackers to cause a Denial of Service (DoS) via a crafted POST request in github.com/andreimarcu/linx-server Affected packages: Go/github.com/andreimarcu/linx-server Attributes: No fix available
最高第 2 名04:29 达到04:29 首次观测上榜08:45 观测离榜累计约4小时16分 - 38MAL-2026-14568 · Malicious code in tailwindcss-form-styles (npm)
Malicious code in tailwindcss-form-styles (npm) Affected packages: npm/tailwindcss-form-styles Attributes: No fix available
最高第 2 名03:09 达到03:09 首次观测上榜06:53 观测离榜累计约3小时44分 - 39MAL-2026-14585 · Malicious code in @znan/wabot (npm)
Malicious code in @znan/wabot (npm) Affected packages: npm/@znan/wabot Attributes: No fix available
最高第 2 名10:05 达到10:05 首次观测上榜13:33 观测离榜累计约3小时28分 - 40MGASA-2026-0339 · Updated python-django packages fix security vulnerabilities
Updated python-django packages fix security vulnerabilities Affected packages: Mageia:10/python-django Attributes: Fix available
最高第 2 名03:41 达到03:41 首次观测上榜06:53 观测离榜累计约3小时12分 - 41MINI-29mp-c84q-fcrj · MinimOS/linstor-server-fips
Affected packages: MinimOS/linstor-server-fips Attributes: Fix available
最高第 2 名13:33 达到13:33 首次观测上榜16:45 观测离榜累计约3小时12分 - 42MINI-38c6-q7j9-pq6p · MinimOS/apache-activemq-6.1
Affected packages: MinimOS/apache-activemq-6.1 Attributes: No fix available
最高第 2 名02:37 达到02:37 首次观测上榜04:29 观测离榜累计约1小时52分 - 43MINI-6v24-vcvc-37xr · MinimOS/splunk-otel-collector-fips
Affected packages: MinimOS/splunk-otel-collector-fips Attributes: Fix available
最高第 2 名20:13 达到20:13 首次观测上榜23:25 观测离榜累计约3小时12分 - 44MINI-g2fx-7w64-f5xv · MinimOS/corretto-fips-config-26
Affected packages: MinimOS/corretto-fips-config-26 Attributes: Fix available
最高第 2 名00:13 达到00:13 首次观测上榜01:33 观测离榜累计约1小时20分 - 45RHSA-2026:60486 · Red Hat Security Advisory: kernel security update
Red Hat Security Advisory: kernel security update Affected packages: Red Hat:rhel_eus:9.6::appstream/kernel-64k-debug-debuginfo、Red Hat:rhel_eus:9.6::appstream/kernel-64k-debug-devel、Red Hat:rhel_eus:9.6::appstream/kernel-64k-debug-devel-matched、Red Hat:rhel_eus:9.6::appstream/kernel-64k-debuginfo、Red Hat:rhel_eus:9.6::appstream/kernel-64k-devel、... 155 more Attributes: Fix available、Severity - 7.8 (High)
最高第 2 名18:21 达到18:21 首次观测上榜20:13 观测离榜累计约1小时52分 - 46RLSA-2026:59972 · Important: gstreamer1-plugins-good security update
Important: gstreamer1-plugins-good security update Affected packages: Rocky Linux:10/gstreamer1-plugins-good Attributes: Fix available、Severity - 8.8 (High)
最高第 2 名00:00 达到当日首次采集时已在榜00:13 观测离榜累计约13分钟 - 47ROOT-APP-NPM-CVE-2026-41305 · CVE-2026-41305 in postcss - Patched by Root
CVE-2026-41305 in postcss - Patched by Root Affected packages: Root:npm/@rootio/postcss、Root:npm/postcss Attributes: Fix available、Severity - 6.1 (Medium)
最高第 2 名16:45 达到16:45 首次观测上榜17:01 观测离榜累计约16分钟 - 48ROOT-APP-NPM-CVE-2026-59869 · CVE-2026-59869 in js-yaml - Patched by Root
CVE-2026-59869 in js-yaml - Patched by Root Affected packages: Root:npm/@rootio/js-yaml、Root:npm/js-yaml Attributes: Fix available
最高第 2 名21:01 达到21:01 首次观测上榜当日结束时仍在榜累计约2小时56分 - 49BIT-vault-2026-5006 · Vault Vulnerable to Privilege Escalation via Slash Injection in Templated Policy Paths
Vault Vulnerable to Privilege Escalation via Slash Injection in Templated Policy Paths Affected packages: Bitnami/vault Attributes: Fix available、Severity - 6.8 (Medium)
最高第 3 名23:57 达到23:57 首次观测上榜当日结束时仍在榜累计约0分钟 - 50CLSA-2026-1787918303 · TuxCare security update for org.springframework (1 CVE)
TuxCare security update for org.springframework (1 CVE) Affected packages: TuxCare:Maven/org.springframework:spring、TuxCare:Maven/org.springframework:spring-aop、TuxCare:Maven/org.springframework:spring-aspects、TuxCare:Maven/org.springframework:spring-beans、TuxCare:Maven/org.springframework:spring-context、... 19 more Attributes: Fix available
最高第 3 名21:49 达到21:49 首次观测上榜当日结束时仍在榜累计约2小时8分


































































































