目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

安全情报专区 191+

精选漏洞公告、利用分析、安全博客、GHSA Advisory 等情报来源,已自动清洗 + 中英双语呈现,持续更新。

240
已接入情报源
119
当前稳定在线
405
24 小时新增
191+
AI 处理情报
持续监听、清洗、翻译并进行 AI 分析 监听情报
示例:RCE · SSRF · GHSA · 反序列化
筛选
清除筛选
High
Python asyncio sock_recvfrom_into 缓冲区长度检查缺失漏洞
github.com · 2026-04-22
Python CPython main branch
Read more
Unknown
Python CPython远程调试偏移表验证缺失漏洞修复
github.com · 2026-04-18

### 漏洞概述 该漏洞涉及Python CPython项目中的远程调试偏移表(remote debug offset tables)在处理来自目标进程的数据时,未进行严格验证。这可能导致内存读取或解释远程布局时的安全问题。 ### 影响范围 - **模块**:`Modules/remote_debugging/` 目录下的相关文件。 - **功能**:远程调试功能。 - **风险**:未经严格验…

Read more
High
Python CPython _remote_debugging 远程调试偏移表验证漏洞
GHSA-gh-148178 · github.com · 2026-04-18
Python < 3.14
Read more
High
Python bz2/lzma/zlib模块UAF漏洞修复分析
CVE-2024-6345 · github.com · 2026-04-18
Python 3.13 before 3.13.1 · Python 3.12 before 3.12.8 …
Read more
High
Python bz2/lzma/zlib模块UAF漏洞修复分析
gh-148395 · github.com · 2026-04-18
Python 3.14
Read more
High
Python webbrowser模块--newaction参数绕过检查漏洞修复
gh-148169 · github.com · 2026-04-18
Python webbrowser module
Read more
High
Python webbrowser模块newtab参数绕过漏洞(GH-148189)
GH-148189 · github.com · 2026-04-18
Python 3.10
Read more
High
CVE-2026-5713 Python远程调试偏移表验证漏洞及修复
CVE-2026-5713 · github.com · 2026-04-18
Python < 3.15 · Python < 3.14.2
Read more
High
CVE-2026-6100: Python lzma/bz2/zlib Decompressor UAF漏洞
CVE-2026-6100 · github.com · 2026-04-18
Python <3.12.14 · Python <3.14.5
Read more
High
Python bz2/lzma模块UAF漏洞修复分析
github.com · 2026-04-18
Python lzma module · Python bz2 module
Read more
Unknown
Python pkgutil.get_data 移除路径遍历限制及安全警告
github.com · 2026-04-08

### 漏洞概述 `pkgutil.get_data` 函数的安全模型被重新澄清。之前的版本试图通过禁止父目录引用(`..`)和绝对路径来防止路径遍历攻击,但该限制已被撤销。现在的行为允许路径遍历(类似于 `open` 函数),因此该函数被设计为仅用于受信任的输入。 ### 影响范围 Python 标准库 `pkgutil` 模块中的 `get_data` 函数。 ### 修复方案 移除了 `Li…

Read more
High
Python webbrowser模块命令注入漏洞修复
github.com · 2026-04-08
Python (webbrowser module)
Read more
Medium
Python webbrowser模块URL参数注入漏洞修复
gh-143930 · github.com · 2026-04-08
Python webbrowser module
Read more
High
Python webbrowser模块参数注入漏洞修复
github.com · 2026-04-08
Python 3.11
Read more
Medium
pymanager CVE-2024-1271: sys.path操纵导致CWD模块劫持
CVE-2024-1271 · github.com · 2026-04-02
pymanager <= 26.0
Read more
Medium
Python email BytesGenerator Header注入漏洞修复
github.com · 2026-01-27
Python < 3.14.0a1
Read more
High
Python Lib/email 头部注入漏洞修复 (gh-144181)
GHSA-gh-144125 · github.com · 2026-01-27
Python < 3.14
Read more

每篇文章经过自动 HTML→Markdown 清洗 + LLM 去噪 + 中英双语翻译。原始链接保留在文章末尾。

想看哪个安全博客 / 公告源?邮件告诉我们,每周新接 1-2 个。