GHSA-r3hx-x5rh-p9vv (django-haystack): affected version range is unparseable ("eval()"), so the advisory matches nothing
维护者通常 1 天内回复
还没有人认领这个 Issue。
评估
- 难度
- 3/5
- 预计耗时
- 1-2 天
- 新手友好度
- 52/100
调研方向
从 GHSA-r3hx-x5rh-p9vv 和 django-haystack#2066 开始,然后检查 haystack/backends/elasticsearch_backend.py:865 中引用的 sink 以及项目已发布的版本。在修正 advisory 的 affected 和 patched 元数据之前,与 upstream 维护者确认最早受影响的版本;当该范围能够被解析,且自动化消费者能够匹配受影响的发布版本时,即视为完成。
由索引模型根据 Issue 内容生成。
描述
Advisory
GHSA-r3hx-x5rh-p9vv — Remote Code Execution via eval() in Elasticsearch Result Deserialization, django-haystack (pip), published 2026-06-04, Moderate.
Problem
The advisory's version metadata is not a version range:
- Affected versions:
eval() - Patched versions:
None
eval() appears to be a paste slip from the advisory body (the vulnerable sink is eval(value) at haystack/backends/elasticsearch_backend.py:865).
Impact of the metadata bug
Because the affected range is not a parseable constraint, this advisory cannot match any installed version. In practice that means:
- Dependabot will not raise an alert for any django-haystack user
pip-audit, OSV-Scanner and other OSV consumers will not flag it- The advisory is published and visible to humans, but inert to every automated consumer
So a Moderate-severity RCE advisory exists while affected users receive no signal.
Suggested correction
Replace the affected range with a real constraint. django-haystack's latest release is 3.3.0 and the sink is still present on master, so the affected range appears to be all released versions up to and including the current one — e.g. <= 3.3.0, or an ecosystem-specific range once maintainers confirm the earliest affected version. Patched versions should stay empty/none until a fix ships, which is accurate today.
I've also opened django-haystack/django-haystack#2066 asking the maintainers to correct this at source and to consider requesting a CVE, since the advisory currently has none.
Disclosure
I'm the reporter of the underlying vulnerability. Raising this here only because the advisory is already public — nothing undisclosed is included above.
- 主要语言
- 没有语言数据
- 星标
- 2.5k
- 派生
- 789
- 平均合并
- 6 天 10 小时
- 30 天内合并 PR
- 61
环境准备
- 没有 Dockerfile 或 Docker Compose 文件
- 没有 Pull Request 模板
- 阅读贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
github/advisory-database 的其他 Issue
-
Update https://github.com/advisories/GHSA-5pf6-cq2v-23ww to include patched version可能已有人在做 @GreyforgeLabs 于 3 天前认领。 未关闭
难度 2/5 1-3 小时 新手友好度 76/100
github/advisory-database#9879 ·
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 68/100
github/advisory-database#9255 ·
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 72/100
github/advisory-database#9164 · 1 个 reaction ·
维护者通常 1 天内回复
-
CVE-2026-5598 has incorrect fixed versions for bcprov-jdk packages可能已有人在做 @ECD5A 于 45 天前认领。 未关闭
难度 2/5 1-3 小时 新手友好度 72/100
github/advisory-database#8994 ·
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 68/100
github/advisory-database#8898 · 4 条评论 · 1 个 reaction ·
维护者通常 1 天内回复
查看 github/advisory-database 的全部 Issue
相似的 Issue
-
[oblt-aw][security] SEC-031 — findings (2026-10-05)可能已有人在做 @elastic-vault-github-plugin-prod 今天认领。 未关闭oblt-aw/ai/fix-ready oblt-aw/detector/security oblt-aw/triage/security-secrets
难度 2/5 1-3 小时 新手友好度 78/100
elastic/oblt-aw#2301 · 2 条评论 · 1 个 reaction ·
维护者通常 1 天内回复
-
bug O&M Security - compliance
难度 2/5 1-3 小时 新手友好度 62/100
GSA/resources.data.gov#1101 ·
维护者通常 1 天内回复
-
security-scan
难度 2/5 1-3 小时 新手友好度 68/100
维护者通常 1 天内回复
-
难度 1/5 1 小时以内 新手友好度 90/100
anomalyco/opentui#1568 · 1 条评论 ·
维护者通常 1 天内回复
-
critical grype high security
难度 2/5 1-3 小时 新手友好度 66/100
维护者通常 2 天内回复