
OSV.dev · 实时热榜
- 01BIT-gitlab-2026-77801 · Allocation of Resources Without Limits or Throttling in GitLab
Allocation of Resources Without Limits or Throttling in GitLab Affected packages: Bitnami/gitlab Attributes: Fix available、Severity - 6.5 (Medium)
最高第 1 名17:15 达到17:15 首次观测上榜当日结束时仍在榜累计约1小时20分 - 02BIT-keycloak-2026-18573 · Keycloak-services: keycloak-services: client access-type policy condition bypass during client update
Keycloak-services: keycloak-services: client access-type policy condition bypass during client update Affected packages: Bitnami/keycloak Attributes: Fix available、Severity - 6.5 (Medium)
最高第 1 名00:00 达到当日首次采集时已在榜00:32 观测离榜累计约32分钟 - 03CLSA-2026-1788216921 · TuxCare security update for io.netty (28 CVEs)
TuxCare security update for io.netty (28 CVEs) Affected packages: TuxCare:Maven/io.netty:netty-all、TuxCare:Maven/io.netty:netty-bom、TuxCare:Maven/io.netty:netty-buffer、TuxCare:Maven/io.netty:netty-codec、TuxCare:Maven/io.netty:netty-codec-dns、... 41 more Attributes: Fix available
最高第 1 名09:31 达到09:31 首次观测上榜10:51 观测离榜累计约1小时20分 - 04DEBIAN-CVE-2026-82820 · Debian:11/flvmeta
Affected packages: Debian:11/flvmeta、Debian:12/flvmeta、Debian:13/flvmeta、Debian:14/flvmeta Attributes: No fix available
最高第 1 名05:09 达到05:09 首次观测上榜07:01 观测离榜累计约1小时52分 - 05EEF-CVE-2026-82731 · Unescaped path parameters in AshTypescript generated TypeScript client allow request redirection
Unescaped path parameters in AshTypescript generated TypeScript client allow request redirection Affected packages: Hex/ash_typescript、github.com/ash-project/ash_typescript Attributes: Fix available、Severity - 2.3 (Low)
最高第 1 名10:19 达到10:19 首次观测上榜10:51 观测离榜累计约32分钟 - 06EEF-CVE-2026-82740 · Ash.Type ignores outer array constraints on nested {:array, {:array, type}} inputs
Ash.Type ignores outer array constraints on nested {:array, {:array, type}} inputs Affected packages: Hex/ash、github.com/ash-project/ash Attributes: Fix available、Severity - 2.1 (Low)
最高第 1 名11:39 达到11:39 首次观测上榜14:35 观测离榜累计约2小时56分 - 07EEF-CVE-2026-82745 · ETS and Mnesia data layers overwrite an existing record on create instead of enforcing primary-key uniqueness
ETS and Mnesia data layers overwrite an existing record on create instead of enforcing primary-key uniqueness Affected packages: Hex/ash、github.com/ash-project/ash Attributes: Fix available、Severity - 5.9 (Medium)
最高第 1 名11:55 达到11:55 首次观测上榜15:07 观测离榜累计约3小时12分 - 08EEF-CVE-2026-82747 · Ash.Policy.Authorizer returns records denied by a runtime read policy to any actor
Ash.Policy.Authorizer returns records denied by a runtime read policy to any actor Affected packages: Hex/ash、github.com/ash-project/ash Attributes: Fix available、Severity - 5.9 (Medium)
最高第 1 名12:27 达到12:27 首次观测上榜15:07 观测离榜累计约2小时40分 - 09EEF-CVE-2026-82749 · Ash relationship parent(...) filter degrades to an IS NULL match when the parent field is unresolved, leaking scoped records
Ash relationship parent(...) filter degrades to an IS NULL match when the parent field is unresolved, leaking scoped records Affected packages: Hex/ash、github.com/ash-project/ash Attributes: Fix available、Severity - 5.9 (Medium)
最高第 1 名12:11 达到12:11 首次观测上榜15:07 观测离榜累计约2小时56分 - 10GHSA-fm3f-ch8h-qw8q · @hono/oauth-providers: OAuth state check fails open on omitted state, enabling login CSRF and forced account linking
@hono/oauth-providers: OAuth state check fails open on omitted state, enabling login CSRF and forced account linking Affected packages: npm/@hono/oauth-providers Attributes: Fix available、Severity - 5.4 (Medium)
最高第 1 名04:53 达到04:53 首次观测上榜10:19 观测离榜累计约5小时26分 - 11GHSA-gr94-w7qr-f4j3 · Socket.IO: Engine.IO WebTransport SID DoS
Socket.IO: Engine.IO WebTransport SID DoS Affected packages: npm/engine.io Attributes: Fix available、Severity - 7.5 (High)
最高第 1 名05:57 达到05:57 首次观测上榜10:19 观测离榜累计约4小时22分 - 12GHSA-mfqj-cqv3-h7xw · TYPO3 CMS - Unrestricted File Upload in Form Framework
TYPO3 CMS - Unrestricted File Upload in Form Framework Affected packages: Packagist/typo3/cms-form Attributes: Fix available、Severity - 6.3 (Medium)
最高第 1 名04:21 达到04:21 首次观测上榜04:53 观测离榜累计约32分钟 - 13GHSA-rgwj-5xj2-c3m3 · MySQL2: Unbounded zlib inflate in compressed MySQL protocol handler allows decompression-bomb DoS
MySQL2: Unbounded zlib inflate in compressed MySQL protocol handler allows decompression-bomb DoS Affected packages: npm/mysql2 Attributes: Fix available
最高第 1 名06:45 达到06:45 首次观测上榜10:51 观测离榜累计约4小时6分 - 14GHSA-vcc3-ghjq-m6fr · decode-uri-component: Denial of service via exponential decoding of malformed percent-encoded input
decode-uri-component: Denial of service via exponential decoding of malformed percent-encoded input Affected packages: npm/decode-uri-component Attributes: Fix available、Severity - 6.6 (Medium)
最高第 1 名06:29 达到06:29 首次观测上榜10:19 观测离榜累计约3小时50分 - 15MAL-2026-15623 · Malicious code in selfsigned-certificate (npm)
Malicious code in selfsigned-certificate (npm) Affected packages: npm/selfsigned-certificate Attributes: No fix available
最高第 1 名01:36 达到01:36 首次观测上榜02:40 观测离榜累计约1小时4分 - 16MGASA-2026-0342 · Updated flatpak package fixes security vulnerabilities
Updated flatpak package fixes security vulnerabilities Affected packages: Mageia:10/flatpak Attributes: Fix available
最高第 1 名00:32 达到00:32 首次观测上榜02:40 观测离榜累计约2小时8分 - 17MGASA-2026-0348 · Updated clamav packages fix security vulnerabilities
Updated clamav packages fix security vulnerabilities Affected packages: Mageia:10/clamav Attributes: Fix available
最高第 1 名03:49 达到03:49 首次观测上榜04:53 观测离榜累计约1小时4分 - 18MGASA-2026-0355 · Updated vim packages fix security vulnerabilities
Updated vim packages fix security vulnerabilities Affected packages: Mageia:10/vim、Mageia:9/vim Attributes: Fix available
最高第 1 名11:23 达到11:23 首次观测上榜12:27 观测离榜累计约1小时4分 - 19MGASA-2026-0360 · Updated perl-HTML-FormHandler packages fix a security vulnerability
Updated perl-HTML-FormHandler packages fix a security vulnerability Affected packages: Mageia:10/perl-HTML-FormHandler、Mageia:9/perl-HTML-FormHandler Attributes: Fix available
最高第 1 名15:23 达到15:23 首次观测上榜17:15 观测离榜累计约1小时52分 - 20MINI-25p2-fwwp-9p52 · MinimOS/paketo-buildpacks-jam
Affected packages: MinimOS/paketo-buildpacks-jam Attributes: Fix available
最高第 1 名16:43 达到16:43 首次观测上榜17:15 观测离榜累计约32分钟 - 21MINI-2g8f-q63w-crj6 · MinimOS/fluxcd-source-watcher-fips
Affected packages: MinimOS/fluxcd-source-watcher-fips Attributes: Fix available
最高第 1 名10:51 达到10:51 首次观测上榜11:55 观测离榜累计约1小时4分 - 22MINI-86v4-f23r-qqm3 · MinimOS/argo-workflow-controller-4.0
Affected packages: MinimOS/argo-workflow-controller-4.0 Attributes: Fix available
最高第 1 名04:37 达到04:37 首次观测上榜04:53 观测离榜累计约16分钟 - 23MINI-mx4x-fhf5-9mhh · MinimOS/corretto-fips-config-8
Affected packages: MinimOS/corretto-fips-config-8 Attributes: Fix available
最高第 1 名00:16 达到00:16 首次观测上榜00:32 观测离榜累计约16分钟 - 24RLSA-2026:61355 · Moderate: dbus-broker security update
Moderate: dbus-broker security update Affected packages: Rocky Linux:9/dbus-broker Attributes: Fix available、Severity - 5.5 (Medium)
最高第 1 名14:35 达到14:35 首次观测上榜16:43 观测离榜累计约2小时8分 - 25RLSA-2026:61383 · Important: nodejs:22 security update
Important: nodejs:22 security update Affected packages: Rocky Linux:9/nodejs-nodemon、Rocky Linux:9/nodejs-packaging Attributes: Fix available、Severity - 7.5 (High)
最高第 1 名02:40 达到02:40 首次观测上榜04:53 观测离榜累计约2小时14分 - 26BIT-gitlab-2026-7487 · Access Control Check Implemented After Asset is Accessed in GitLab
Access Control Check Implemented After Asset is Accessed in GitLab Affected packages: Bitnami/gitlab Attributes: Fix available、Severity - 3.5 (Low)
最高第 2 名17:15 达到17:15 首次观测上榜当日结束时仍在榜累计约1小时20分 - 27BIT-keycloak-2026-18572 · Keycloak-services: keycloak-services: uma claim token can override authorization time-policy evaluation attributes
Keycloak-services: keycloak-services: uma claim token can override authorization time-policy evaluation attributes Affected packages: Bitnami/keycloak Attributes: Fix available、Severity - 6.5 (Medium)
最高第 2 名00:00 达到当日首次采集时已在榜00:32 观测离榜累计约32分钟 - 28DEBIAN-CVE-2026-82821 · Debian:11/flvmeta
Affected packages: Debian:11/flvmeta、Debian:12/flvmeta、Debian:13/flvmeta、Debian:14/flvmeta Attributes: No fix available
最高第 2 名05:09 达到05:09 首次观测上榜07:01 观测离榜累计约1小时52分 - 29ECHO-1c69-349a-b2ee · Echo/ffmpeg
Affected packages: Echo/ffmpeg Attributes: No fix available
最高第 2 名00:16 达到00:16 首次观测上榜00:32 观测离榜累计约16分钟 - 30EEF-CVE-2026-74837 · Unbounded atom creation from client-supplied RPC field names in AshTypescript field formatter
Unbounded atom creation from client-supplied RPC field names in AshTypescript field formatter Affected packages: Hex/ash_typescript、github.com/ash-project/ash_typescript Attributes: Fix available、Severity - 8.7 (High)
最高第 2 名10:19 达到10:19 首次观测上榜10:51 观测离榜累计约32分钟 - 31EEF-CVE-2026-82739 · Ash.Resource.Validation.Confirm leaks a confirmed field's stored value in the atomic mismatch error
Ash.Resource.Validation.Confirm leaks a confirmed field's stored value in the atomic mismatch error Affected packages: Hex/ash、github.com/ash-project/ash Attributes: Fix available、Severity - 2.1 (Low)
最高第 2 名11:39 达到11:39 首次观测上榜14:35 观测离榜累计约2小时56分 - 32EEF-CVE-2026-82744 · Ash.Reactor change step fails open, skipping a change when its where guard raises
Ash.Reactor change step fails open, skipping a change when its where guard raises Affected packages: Hex/ash、github.com/ash-project/ash Attributes: Fix available、Severity - 2.1 (Low)
最高第 2 名11:55 达到11:55 首次观测上榜15:07 观测离榜累计约3小时12分 - 33EEF-CVE-2026-82748 · Ash.Actions.Aggregate authorizes an aggregate under one action but computes it under another
Ash.Actions.Aggregate authorizes an aggregate under one action but computes it under another Affected packages: Hex/ash、github.com/ash-project/ash Attributes: Fix available、Severity - 2.1 (Low)
最高第 2 名12:11 达到12:11 首次观测上榜15:07 观测离榜累计约2小时56分 - 34GHSA-67mx-6wf2-92xp · Kirby: File upload permissions are not checked during processing of chunk data
Kirby: File upload permissions are not checked during processing of chunk data Affected packages: Packagist/getkirby/cms Attributes: Fix available、Severity - 7.1 (High)
最高第 2 名06:45 达到06:45 首次观测上榜10:51 观测离榜累计约4小时6分 - 35GHSA-8x3q-jpjh-qh5c · elFinder: SSRF protection bypass via DNS rebinding in the `fsock_get_contents()` fallback
elFinder: SSRF protection bypass via DNS rebinding in the `fsock_get_contents()` fallback Affected packages: Packagist/studio-42/elfinder Attributes: Fix available、Severity - 8.6 (High)
最高第 2 名04:53 达到04:53 首次观测上榜10:19 观测离榜累计约5小时26分 - 36MAL-2026-15622 · Malicious code in spc_login (npm)
Malicious code in spc_login (npm) Affected packages: npm/spc_login Attributes: No fix available
最高第 2 名01:36 达到01:36 首次观测上榜02:40 观测离榜累计约1小时4分 - 37MGASA-2026-0343 · Updated c-ares packages fix security vulnerabilities
Updated c-ares packages fix security vulnerabilities Affected packages: Mageia:10/c-ares Attributes: Fix available
最高第 2 名00:32 达到00:32 首次观测上榜02:40 观测离榜累计约2小时8分 - 38MGASA-2026-0349 · Updated python-hpack packages fix a security vulnerability
Updated python-hpack packages fix a security vulnerability Affected packages: Mageia:10/python-hpack Attributes: Fix available
最高第 2 名03:49 达到03:49 首次观测上榜04:53 观测离榜累计约1小时4分 - 39MGASA-2026-0356 · Updated perl-Mojolicious packages fix a security vulnerability
Updated perl-Mojolicious packages fix a security vulnerability Affected packages: Mageia:10/perl-Mojolicious、Mageia:9/perl-Mojolicious Attributes: Fix available
最高第 2 名11:23 达到11:23 首次观测上榜12:11 观测离榜累计约48分钟 - 40MGASA-2026-0361 · Updated perl-Date-Manip packages fix security vulnerabilities
Updated perl-Date-Manip packages fix security vulnerabilities Affected packages: Mageia:10/perl-Date-Manip、Mageia:9/perl-Date-Manip Attributes: Fix available
最高第 2 名15:23 达到15:23 首次观测上榜17:15 观测离榜累计约1小时52分 - 41MINI-2mm7-jx89-vq5r · MinimOS/fluxcd-kustomize-controller-fips
Affected packages: MinimOS/fluxcd-kustomize-controller-fips Attributes: Fix available
最高第 2 名10:51 达到10:51 首次观测上榜11:55 观测离榜累计约1小时4分 - 42MINI-35pg-9qfp-h3x4 · MinimOS/paketo-buildpacks-jam
Affected packages: MinimOS/paketo-buildpacks-jam Attributes: Fix available
最高第 2 名16:43 达到16:43 首次观测上榜17:15 观测离榜累计约32分钟 - 43MINI-c46r-4v5w-v2g5 · MinimOS/argo-rollouts-gateway-api-router
Affected packages: MinimOS/argo-rollouts-gateway-api-router Attributes: Fix available
最高第 2 名04:37 达到04:37 首次观测上榜04:53 观测离榜累计约16分钟 - 44RLSA-2026:61386 · Important: nodejs:24 security update
Important: nodejs:24 security update Affected packages: Rocky Linux:9/nodejs-nodemon、Rocky Linux:9/nodejs-packaging Attributes: Fix available、Severity - 7.5 (High)
最高第 2 名02:40 达到02:40 首次观测上榜04:53 观测离榜累计约2小时14分 - 45RLSA-2026:61581 · Moderate: tar security, bug fix, and enhancement update
Moderate: tar security, bug fix, and enhancement update Affected packages: Rocky Linux:9/tar Attributes: Fix available、Severity - 5.0 (Medium)
最高第 2 名14:35 达到14:35 首次观测上榜16:43 观测离榜累计约2小时8分 - 46BIT-gitlab-2026-3035 · Authentication Bypass Using an Alternate Path or Channel in GitLab
Authentication Bypass Using an Alternate Path or Channel in GitLab Affected packages: Bitnami/gitlab Attributes: Fix available、Severity - 5.5 (Medium)
最高第 3 名17:15 达到17:15 首次观测上榜当日结束时仍在榜累计约1小时20分 - 47BIT-keycloak-2026-18571 · Keycloak-services: keycloak-services: fgap v2 group assignment bypass during user creation
Keycloak-services: keycloak-services: fgap v2 group assignment bypass during user creation Affected packages: Bitnami/keycloak Attributes: Fix available、Severity - 7.2 (High)
最高第 3 名00:00 达到当日首次采集时已在榜00:32 观测离榜累计约32分钟 - 48CLSA-2026-1788215347 · TuxCare security update for org.apache.logging.log4j (6 CVEs)
TuxCare security update for org.apache.logging.log4j (6 CVEs) Affected packages: TuxCare:Maven/org.apache.logging.log4j:log4j、TuxCare:Maven/org.apache.logging.log4j:log4j-1.2-api、TuxCare:Maven/org.apache.logging.log4j:log4j-api、TuxCare:Maven/org.apache.logging.log4j:log4j-appserver、TuxCare:Maven/org.apache.logging.log4j:log4j-bom、... 18 more Attributes: Fix available
最高第 3 名09:31 达到09:31 首次观测上榜10:51 观测离榜累计约1小时20分 - 49EEF-CVE-2026-82733 · Route handler return value echoed into AshTypescript error response
Route handler return value echoed into AshTypescript error response Affected packages: Hex/ash_typescript、github.com/ash-project/ash_typescript Attributes: Fix available、Severity - 6.3 (Medium)
最高第 3 名10:19 达到10:19 首次观测上榜10:51 观测离榜累计约32分钟 - 50EEF-CVE-2026-82738 · Ash.Type.UUIDv7 accepts non-v7 UUIDs that then fail to load, causing persistent denial of service
Ash.Type.UUIDv7 accepts non-v7 UUIDs that then fail to load, causing persistent denial of service Affected packages: Hex/ash、github.com/ash-project/ash Attributes: Fix available、Severity - 5.9 (Medium)
最高第 3 名11:39 达到11:39 首次观测上榜14:35 观测离榜累计约2小时56分


































































































