
OSV.dev · 实时热榜
- 01BIT-keycloak-2026-18573 · Keycloak-services: keycloak-services: client access-type policy condition bypass during client update
Keycloak-services: keycloak-services: client access-type policy condition bypass during client update Affected packages: Bitnami/keycloak Attributes: Fix available、Severity - 6.5 (Medium)
最高第 1 名23:24 达到23:24 首次观测上榜当日结束时仍在榜累计约20分钟 - 02BIT-python-2026-15310 · zipfile: bzip2/LZMA/Zstandard members decompress without a max_length bound, defeating chunked-read memory limits
zipfile: bzip2/LZMA/Zstandard members decompress without a max_length bound, defeating chunked-read memory limits Affected packages: Bitnami/python Attributes: No fix available、Severity - 2.1 (Low)
最高第 1 名19:24 达到19:24 首次观测上榜20:44 观测离榜累计约1小时20分 - 03BIT-tomcat-2026-73180 · Apache Tomcat: Authenticated WebSocket session survives end of HTTP session
Apache Tomcat: Authenticated WebSocket session survives end of HTTP session Affected packages: Bitnami/tomcat Attributes: Fix available、Severity - 6.8 (Medium)
最高第 1 名17:00 达到17:00 首次观测上榜18:20 观测离榜累计约1小时20分 - 04DEBIAN-CVE-2026-19873 · Debian:11/libhtml-formfu-perl
Affected packages: Debian:11/libhtml-formfu-perl、Debian:12/libhtml-formfu-perl、Debian:13/libhtml-formfu-perl、Debian:14/libhtml-formfu-perl Attributes: No fix available
最高第 1 名20:12 达到20:12 首次观测上榜21:32 观测离榜累计约1小时20分 - 05DEBIAN-CVE-2026-82623 · Debian:13/open62541
Affected packages: Debian:13/open62541、Debian:14/open62541 Attributes: No fix available
最高第 1 名19:08 达到19:08 首次观测上榜20:44 观测离榜累计约1小时36分 - 06ECHO-0030-65ec-f55d · Echo/keycloak-25
Affected packages: Echo/keycloak-25 Attributes: Fix available
最高第 1 名01:32 达到01:32 首次观测上榜05:00 观测离榜累计约3小时28分 - 07EEF-CVE-2026-75760 · AshAi vectorize change leaks raw embedding-provider errors, including credentials, in a user-facing error
AshAi vectorize change leaks raw embedding-provider errors, including credentials, in a user-facing error Affected packages: Hex/ash_ai、github.com/ash-project/ash_ai Attributes: Fix available、Severity - 7.1 (High)
最高第 1 名09:16 达到09:16 首次观测上榜10:52 观测离榜累计约1小时36分 - 08EEF-CVE-2026-78693 · Incomplete redaction re-attaches the original error path in AshGraphql, leaking internal field names
Incomplete redaction re-attaches the original error path in AshGraphql, leaking internal field names Affected packages: Hex/ash_graphql、github.com/ash-project/ash_graphql Attributes: Fix available、Severity - 6.9 (Medium)
最高第 1 名02:36 达到02:36 首次观测上榜05:00 观测离榜累计约2小时24分 - 09EEF-CVE-2026-78699 · rename_tenant returns :ok on a failed rename, enabling cross-tenant access in AshPostgres
rename_tenant returns :ok on a failed rename, enabling cross-tenant access in AshPostgres Affected packages: Hex/ash_postgres、github.com/ash-project/ash_postgres Attributes: Fix available、Severity - 7.2 (High)
最高第 1 名00:00 达到当日首次采集时已在榜01:32 观测离榜累计约1小时33分 - 10EEF-CVE-2026-81315 · MCP DNS-rebinding origin check in AshAi is bypassed by a spoofed X-Forwarded-Proto header
MCP DNS-rebinding origin check in AshAi is bypassed by a spoofed X-Forwarded-Proto header Affected packages: Hex/ash_ai、github.com/ash-project/ash_ai Attributes: Fix available、Severity - 7.4 (High)
最高第 1 名09:00 达到09:00 首次观测上榜10:52 观测离榜累计约1小时52分 - 11EEF-CVE-2026-81322 · Cloaked plaintext leaks through a non-sensitive action argument in AshCloak
Cloaked plaintext leaks through a non-sensitive action argument in AshCloak Affected packages: Hex/ash_cloak、github.com/ash-project/ash_cloak Attributes: Fix available、Severity - 2.1 (Low)
最高第 1 名02:20 达到02:20 首次观测上榜05:00 观测离榜累计约2小时40分 - 12EEF-CVE-2026-81852 · AshAdmin ships a hardcoded CSP nonce, allowing nonce-based CSP bypass
AshAdmin ships a hardcoded CSP nonce, allowing nonce-based CSP bypass Affected packages: Hex/ash_admin、github.com/ash-project/ash_admin Attributes: Fix available、Severity - 2.1 (Low)
最高第 1 名10:36 达到10:36 首次观测上榜14:52 观测离榜累计约4小时16分 - 13EEF-CVE-2026-82673 · Path traversal in AshAdmin file uploads via unsanitized client filename
Path traversal in AshAdmin file uploads via unsanitized client filename Affected packages: Hex/ash_admin、github.com/ash-project/ash_admin Attributes: Fix available、Severity - 8.3 (High)
最高第 1 名10:52 达到10:52 首次观测上榜16:12 观测离榜累计约5小时20分 - 14EEF-CVE-2026-82725 · AshPhoenix FilterForm allows filtering across non-public relationships, disclosing private related data
AshPhoenix FilterForm allows filtering across non-public relationships, disclosing private related data Affected packages: Hex/ash_phoenix、github.com/ash-project/ash_phoenix Attributes: Fix available、Severity - 2.3 (Low)
最高第 1 名11:24 达到11:24 首次观测上榜17:00 观测离榜累计约5小时36分 - 15MAL-2026-15588 · Malicious code in tronlinker (PyPI)
Malicious code in tronlinker (PyPI) Affected packages: PyPI/tronlinker Attributes: No fix available
最高第 1 名06:36 达到06:36 首次观测上榜10:52 观测离榜累计约4小时16分 - 16MAL-2026-15603 · Malicious code in pyservercheck (PyPI)
Malicious code in pyservercheck (PyPI) Affected packages: PyPI/pyservercheck Attributes: No fix available
最高第 1 名13:32 达到13:32 首次观测上榜17:00 观测离榜累计约3小时28分 - 17MINI-phfw-96xm-7673 · MinimOS/argocd-3.5
Affected packages: MinimOS/argocd-3.5、MinimOS/argocd-3.5-compat Attributes: Fix available
最高第 1 名04:44 达到04:44 首次观测上榜05:00 观测离榜累计约16分钟 - 18MINI-xq4r-f6jg-86x6 · MinimOS/weaviate-1.39
Affected packages: MinimOS/weaviate-1.39 Attributes: Fix available
最高第 1 名05:00 达到05:00 首次观测上榜10:52 观测离榜累计约5小时52分 - 19RHSA-2026:61313 · Red Hat Security Advisory: rhc security update
Red Hat Security Advisory: rhc security update Affected packages: Red Hat:enterprise_linux_eus:10.0/rhc、Red Hat:enterprise_linux_eus:10.0/rhc-debuginfo、Red Hat:enterprise_linux_eus:10.0/rhc-debugsource Attributes: Fix available、Severity - 8.8 (High)
最高第 1 名18:20 达到18:20 首次观测上榜19:40 观测离榜累计约1小时20分 - 20RLSA-2026:61240 · Moderate: pipewire security update
Moderate: pipewire security update Affected packages: Rocky Linux:9/pipewire Attributes: Fix available、Severity - 6.5 (Medium)
最高第 1 名20:44 达到20:44 首次观测上榜21:32 观测离榜累计约48分钟 - 21ROOT-APP-MAVEN-AIKIDO-2026-61483 · AIKIDO-2026-61483 in spring-security-oauth2-jose - Patched by Root
AIKIDO-2026-61483 in spring-security-oauth2-jose - Patched by Root Affected packages: Root:Maven/io.root.spring-security-oauth2-jose、Root:Maven/spring-security-oauth2-jose Attributes: Fix available
最高第 1 名22:20 达到22:20 首次观测上榜23:24 观测离榜累计约1小时4分 - 22ROOT-APP-NPM-CVE-2026-23745 · CVE-2026-23745 in tar - Patched by Root
CVE-2026-23745 in tar - Patched by Root Affected packages: Root:npm/@rootio/tar、Root:npm/tar Attributes: Fix available、Severity - 6.1 (Medium)
最高第 1 名17:16 达到17:16 首次观测上榜18:20 观测离榜累计约1小时4分 - 23ROOT-OS-ALPINE-318-CVE-2025-29087 · CVE-2025-29087 in sqlite - Patched by Root
CVE-2025-29087 in sqlite - Patched by Root Affected packages: Root:Alpine:3.18/rootio-sqlite、Root:Alpine:3.18/sqlite Attributes: Fix available、Severity - 7.5 (High)
最高第 1 名14:52 达到14:52 首次观测上榜17:16 观测离榜累计约2小时24分 - 24ROOT-OS-ALPINE-320-CVE-2026-1642 · CVE-2026-1642 in nginx - Patched by Root
CVE-2026-1642 in nginx - Patched by Root Affected packages: Root:Alpine:3.20/nginx、Root:Alpine:3.20/rootio-nginx Attributes: Fix available
最高第 1 名19:40 达到19:40 首次观测上榜21:32 观测离榜累计约1小时52分 - 25ROOT-OS-DEBIAN-12-CVE-2026-63382 · CVE-2026-63382 in libevent - Patched by Root
CVE-2026-63382 in libevent - Patched by Root Affected packages: Root:Debian:12/libevent、Root:Debian:12/rootio-libevent Attributes: Fix available
最高第 1 名21:32 达到21:32 首次观测上榜22:20 观测离榜累计约48分钟 - 26BIT-keycloak-2026-18572 · Keycloak-services: keycloak-services: uma claim token can override authorization time-policy evaluation attributes
Keycloak-services: keycloak-services: uma claim token can override authorization time-policy evaluation attributes Affected packages: Bitnami/keycloak Attributes: Fix available、Severity - 6.5 (Medium)
最高第 2 名23:24 达到23:24 首次观测上榜当日结束时仍在榜累计约20分钟 - 27BIT-python-min-2026-15310 · zipfile: bzip2/LZMA/Zstandard members decompress without a max_length bound, defeating chunked-read memory limits
zipfile: bzip2/LZMA/Zstandard members decompress without a max_length bound, defeating chunked-read memory limits Affected packages: Bitnami/python-min Attributes: No fix available、Severity - 2.1 (Low)
最高第 2 名19:24 达到19:24 首次观测上榜20:44 观测离榜累计约1小时20分 - 28BIT-tomcat-2026-68763 · Apache Tomcat: DoS via allocation leak in HTTP/2 backlog tracking when a stream is reset
Apache Tomcat: DoS via allocation leak in HTTP/2 backlog tracking when a stream is reset Affected packages: Bitnami/tomcat Attributes: Fix available、Severity - 7.5 (High)
最高第 2 名17:00 达到17:00 首次观测上榜18:20 观测离榜累计约1小时20分 - 29ECHO-12de-2dca-d7dc · Echo/keycloak-25
Affected packages: Echo/keycloak-25 Attributes: Fix available
最高第 2 名01:32 达到01:32 首次观测上榜05:00 观测离榜累计约3小时28分 - 30EEF-CVE-2026-77956 · EEx template evaluation of prompt content in AshAi enables remote code execution
EEx template evaluation of prompt content in AshAi enables remote code execution Affected packages: Hex/ash_ai、github.com/ash-project/ash_ai Attributes: Fix available、Severity - 10.0 (Critical)
最高第 2 名09:00 达到09:00 首次观测上榜10:52 观测离榜累计约1小时52分 - 31EEF-CVE-2026-80223 · Cross-tenant subscription disclosure in AshGraphql authorizes notifications in memory without a tenant-scoped read
Cross-tenant subscription disclosure in AshGraphql authorizes notifications in memory without a tenant-scoped read Affected packages: Hex/ash_graphql、github.com/ash-project/ash_graphql Attributes: Fix available、Severity - 7.1 (High)
最高第 2 名02:36 达到02:36 首次观测上榜05:00 观测离榜累计约2小时24分 - 32EEF-CVE-2026-81319 · Unsafe deserialization of decrypted terms enables node DoS in AshCloak
Unsafe deserialization of decrypted terms enables node DoS in AshCloak Affected packages: Hex/ash_cloak、github.com/ash-project/ash_cloak Attributes: Fix available、Severity - 5.9 (Medium)
最高第 2 名02:20 达到02:20 首次观测上榜05:00 观测离榜累计约2小时40分 - 33EEF-CVE-2026-81853 · AshAdmin composite primary key decoding accepts arbitrary fields, enabling a secret-attribute oracle
AshAdmin composite primary key decoding accepts arbitrary fields, enabling a secret-attribute oracle Affected packages: Hex/ash_admin、github.com/ash-project/ash_admin Attributes: Fix available、Severity - 2.3 (Low)
最高第 2 名10:52 达到10:52 首次观测上榜16:12 观测离榜累计约5小时20分 - 34EEF-CVE-2026-82580 · AshAi echoes raw tool exception messages into the conversation, disclosing internal details
AshAi echoes raw tool exception messages into the conversation, disclosing internal details Affected packages: Hex/ash_ai、github.com/ash-project/ash_ai Attributes: Fix available、Severity - 5.3 (Medium)
最高第 2 名09:16 达到09:16 首次观测上榜10:52 观测离榜累计约1小时36分 - 35EEF-CVE-2026-82681 · Query-parameter injection in AshAdmin row-action links via unencoded string primary keys
Query-parameter injection in AshAdmin row-action links via unencoded string primary keys Affected packages: Hex/ash_admin、github.com/ash-project/ash_admin Attributes: Fix available、Severity - 2.0 (Low)
最高第 2 名10:36 达到10:36 首次观测上榜14:52 观测离榜累计约4小时16分 - 36EEF-CVE-2026-82724 · Broken access control in AshPhoenix SubdomainHook via a nil tenant in handle_subdomain
Broken access control in AshPhoenix SubdomainHook via a nil tenant in handle_subdomain Affected packages: Hex/ash_phoenix、github.com/ash-project/ash_phoenix Attributes: Fix available、Severity - 7.6 (High)
最高第 2 名11:24 达到11:24 首次观测上榜17:00 观测离榜累计约5小时36分 - 37MINI-2p7v-w6j4-569m · MinimOS/vela-core-1.10
Affected packages: MinimOS/vela-core-1.10 Attributes: Fix available
最高第 2 名05:00 达到05:00 首次观测上榜10:52 观测离榜累计约5小时52分 - 38MINI-9c4q-8wfr-435f · MinimOS/amazon-cloudwatch-agent
Affected packages: MinimOS/amazon-cloudwatch-agent Attributes: Fix available
最高第 2 名04:44 达到04:44 首次观测上榜05:00 观测离榜累计约16分钟 - 39MINI-m826-28qr-7wcw · MinimOS/weaviate-fips-1.38
Affected packages: MinimOS/weaviate-fips-1.38 Attributes: Fix available
最高第 2 名00:00 达到当日首次采集时已在榜01:32 观测离榜累计约1小时33分 - 40RHSA-2026:61261 · Red Hat Security Advisory: sg3_utils security, bug fix, and enhancement update
Red Hat Security Advisory: sg3_utils security, bug fix, and enhancement update Affected packages: Red Hat:rhel_e4s:9.2::baseos/sg3_utils、Red Hat:rhel_e4s:9.2::baseos/sg3_utils-debuginfo、Red Hat:rhel_e4s:9.2::baseos/sg3_utils-debugsource、Red Hat:rhel_e4s:9.2::baseos/sg3_utils-libs、Red Hat:rhel_e4s:9.2::baseos/sg3_utils-libs-debuginfo Attributes: Fix available、Severity - 7.6 (High)
最高第 2 名18:20 达到18:20 首次观测上榜19:40 观测离榜累计约1小时20分 - 41RLSA-2026:61247 · Moderate: libxml2 security update
Moderate: libxml2 security update Affected packages: Rocky Linux:9/libxml2 Attributes: Fix available、Severity - 5.9 (Medium)
最高第 2 名20:44 达到20:44 首次观测上榜21:32 观测离榜累计约48分钟 - 42ROOT-APP-NPM-CVE-2024-43414 · CVE-2024-43414 in @apollo/gateway - Patched by Root
CVE-2024-43414 in @apollo/gateway - Patched by Root Affected packages: Root:npm/@apollo/gateway、Root:npm/@apollo/query-planner、Root:npm/@rootio/apollo__gateway、Root:npm/@rootio/apollo__query-planner Attributes: Fix available
最高第 2 名22:20 达到22:20 首次观测上榜23:24 观测离榜累计约1小时4分 - 43ROOT-APP-NPM-CVE-2026-23950 · CVE-2026-23950 in tar - Patched by Root
CVE-2026-23950 in tar - Patched by Root Affected packages: Root:npm/@rootio/tar、Root:npm/tar Attributes: Fix available、Severity - 8.8 (High)
最高第 2 名17:16 达到17:16 首次观测上榜18:20 观测离榜累计约1小时4分 - 44ROOT-OS-ALPINE-318-CVE-2026-11824 · CVE-2026-11824 in sqlite - Patched by Root
CVE-2026-11824 in sqlite - Patched by Root Affected packages: Root:Alpine:3.18/rootio-sqlite、Root:Alpine:3.18/sqlite Attributes: Fix available
最高第 2 名14:52 达到14:52 首次观测上榜17:16 观测离榜累计约2小时24分 - 45ROOT-OS-ALPINE-320-CVE-2026-27651 · CVE-2026-27651 in nginx - Patched by Root
CVE-2026-27651 in nginx - Patched by Root Affected packages: Root:Alpine:3.20/nginx、Root:Alpine:3.20/rootio-nginx Attributes: Fix available
最高第 2 名19:40 达到19:40 首次观测上榜21:32 观测离榜累计约1小时52分 - 46ROOT-OS-DEBIAN-12-CVE-2026-63383 · CVE-2026-63383 in libevent - Patched by Root
CVE-2026-63383 in libevent - Patched by Root Affected packages: Root:Debian:12/libevent、Root:Debian:12/rootio-libevent Attributes: Fix available
最高第 2 名21:32 达到21:32 首次观测上榜22:20 观测离榜累计约48分钟 - 47BIT-keycloak-2026-18571 · Keycloak-services: keycloak-services: fgap v2 group assignment bypass during user creation
Keycloak-services: keycloak-services: fgap v2 group assignment bypass during user creation Affected packages: Bitnami/keycloak Attributes: Fix available、Severity - 7.2 (High)
最高第 3 名23:24 达到23:24 首次观测上榜当日结束时仍在榜累计约20分钟 - 48BIT-kibana-2026-78581 · Authorization Bypass Through User-Controlled Key in Kibana Leading to Unauthorized Data Modification in Kibana
Authorization Bypass Through User-Controlled Key in Kibana Leading to Unauthorized Data Modification in Kibana Affected packages: Bitnami/kibana Attributes: Fix available、Severity - 4.2 (Medium)
最高第 3 名16:12 达到16:12 首次观测上榜17:16 观测离榜累计约1小时4分 - 49BIT-tomcat-2026-68569 · Apache Tomcat: Principal lookup can fail open in some cases
Apache Tomcat: Principal lookup can fail open in some cases Affected packages: Bitnami/tomcat Attributes: Fix available、Severity - 8.1 (High)
最高第 3 名17:00 达到17:00 首次观测上榜18:20 观测离榜累计约1小时20分 - 50ECHO-1814-da4f-7983 · Echo/keycloak-25
Affected packages: Echo/keycloak-25 Attributes: Fix available
最高第 3 名01:32 达到01:32 首次观测上榜05:00 观测离榜累计约3小时28分


































































































