| PR | Author | Title | Date |
|---|---|---|---|
| 642 | genesisrevelationinc-debug | [ShanaBoo] [BUG] Race Condition in File Upload Han | 2026-07-07 |
| 641 | genesisrevelationinc-debug | [ShanaBoo] [BUG] Full Chain: XSS → CSRF → Account | 2026-07-07 |
| 640 | namdamdoi68-oss | fix: resolve YAML block scalar indentation error i | 2026-07-07 |
| 634 | genesisrevelationinc-debug | [ShanaBoo] [BUG] WebSocket Cross-Origin Hijacking | 2026-07-07 |
| 631 | genesisrevelationinc-debug | [ShanaBoo] [BUG] Zero-Click Account Takeover via E | 2026-07-07 |
| 563 | dev-nana27 | [FIX] Unvalidated File Upload Type - Multi-layer v | 2026-07-07 |
| 557 | luccas12348486 | fix: [BUG] CRDT Conflict Resolution Bypass → Data | 2026-07-07 |
| 556 | luccas12348486 | fix: [BUG] JWT Algorithm Confusion + Key Injection | 2026-07-07 |
| 555 | luccas12348486 | fix: [BUG] SSRF via DNS Rebinding Bypassing Allowl | 2026-07-07 |
| 554 | luccas12348486 | fix: [BUG] Insecure Federation SSO → Cross-Tenant | 2026-07-07 |
| 553 | luccas12348486 | fix: [BUG] BGP Hijacking Simulation → TLS Certific | 2026-07-07 |
| 552 | luccas12348486 | fix: add input validation and sanitization guards | 2026-07-07 |
| 485 | ZLNiao | fix(security): prevent SSRF via DNS rebinding allo | 2026-07-07 |
| 469 | jacksong2049-prog | fix: OAuth 2.0 PKCE + Anti-Interception Protection | 2026-07-07 |
| 468 | zhaog100 | fix: NoSQL Injection in Login (#20) - $25 bounty | 2026-07-07 |
| 467 | zhaog100 | fix: IDOR (#12), SSTI (#13), Insecure File Upload | 2026-07-07 |
| 466 | zhaog100 | fix: Path Traversal (#10), Open Redirect (#15), CS | 2026-07-07 |
| 465 | luccas12348486 | Fix #423: XXE via SVG Upload → SSRF → Internal Por | 2026-07-07 |
| 464 | luccas12348486 | Fix #424: LDAP Injection with Blind Boolean-Based | 2026-07-07 |
| 463 | luccas12348486 | Fix #425: JWT None Algorithm + Weak Secret + Kid I | 2026-07-07 |
| 462 | luccas12348486 | Fix #426: DNS Rebinding + WebRTC → Internal Networ | 2026-07-07 |
| 461 | luccas12348486 | Fix #427: OAuth 2.0 Implicit Grant Flow → Authoriz | 2026-07-07 |
| 460 | luccas12348486 | Fix #434: Padding Oracle Attack on Encrypted Sessi | 2026-07-07 |
| 459 | luccas12348486 | Fix #436: Kubernetes RBAC Bypass via API Server Mi | 2026-07-07 |
| 458 | luccas12348486 | Fix #438: CRDT Conflict Resolution Bypass → Data C | 2026-07-07 |
| 457 | luccas12348486 | Fix #439: JWT Algorithm Confusion + Key Injection | 2026-07-07 |
| 456 | luccas12348486 | Fix #440: SSRF via DNS Rebinding Bypassing Allowli | 2026-07-07 |
| 455 | luccas12348486 | Fix #441: Insecure Federation SSO → Cross-Tenant A | 2026-07-07 |
| 454 | genesisrevelationinc-debug | [ShanaBoo] [BUG] Cross-Site Search (XS-Search) → U | 2026-07-07 |
| 446 | danielalanbates | Fix #433: mitigate dangling DNS subdomain takeover | 2026-07-07 |
| 445 | taibaihu | fix: auto-patch for issue #442 | 2026-07-07 |
| 405 | luccas12348486 | Fix #341: [BUG] RCE through Unsafe YAML Load in Co | 2026-07-07 |
| 404 | luccas12348486 | Fix #342: [BUG] Log4j JNDI Injection in Custom Log | 2026-07-07 |
| 403 | luccas12348486 | Fix #343: [BUG] Full Chain: XSS → CSRF → Account T | 2026-07-07 |
| 402 | luccas12348486 | Fix #344: security vulnerability patch | 2026-07-07 |
| 401 | luccas12348486 | Fix #345: security vulnerability patch | 2026-07-07 |
| 400 | luccas12348486 | fix: Side-Channel Timing Attack on Constant-Time C | 2026-07-07 |
| 399 | luccas12348486 | fix: Padding Oracle Attack on Encrypted Session Co | 2026-07-07 |
| 398 | luccas12348486 | fix: TCP Timestamp Side Channel → Cloud Provider I | 2026-07-07 |
| 397 | luccas12348486 | fix: CRLF Injection to HTTP Response Splitting + C | 2026-07-07 |
| 396 | luccas12348486 | fix: Flash Loan Attack → Oracle Manipulation → Liq | 2026-07-07 |
| 395 | luccas12348486 | fix: Apache/NGINX Misconfiguration → Source Code D | 2026-07-07 |
| 394 | luccas12348486 | fix: Timing-Based Blind Data Extraction via Race W | 2026-07-07 |
| 393 | luccas12348486 | fix: WebAssembly Memory Corruption → Sandbox Escap | 2026-07-07 |
| 392 | luccas12348486 | fix: Path Traversal + Log Poisoning → RCE Chain fo | 2026-07-07 |
| 391 | luccas12348486 | fix: GraphQL Depth Bypass + Batching → Data Exfilt | 2026-07-07 |
| 390 | luccas12348486 | fix: Supply Chain Attack via Dependency Confusion | 2026-07-07 |
| 389 | luccas12348486 | fix: Uniswap V3 TWAP Oracle Manipulation via Flash | 2026-07-07 |
| 388 | nexicturbo | fix: prevent password clipboard exposure | 2026-07-07 |
| 387 | luccas12348486 | fix: Docker Container Escape via Mounted Docker So | 2026-07-07 |
更新于 2026-07-07 18:40 UTC · 共 50 个已合并 PR