Repository advisory GHSA-2xp9-vwfh-vxw4 (Next.js, Critical 9.5, published 2026-08-25) not ingested into the Advisory Database
维护者通常 1 天内回复
还没有人认领这个 Issue。
评估
调研方向
首先查看 repository 的贡献指南,然后核验 issue 中针对 GHSA-2xp9-vwfh-vxw4 列出的 advisory 详细信息和查询结果。未指定源文件、测试或 ingestion 入口,因此首要任务是定位 review 和 import 工作流。完成标准是该 advisory 已存在于全局数据库中,并且所请求的 review 延迟或待处理 advisory 行为已得到明确。
由索引模型根据 Issue 内容生成。
描述
Summary
A Critical repository-level security advisory published on vercel/next.js
on 2026-08-25 is still absent from the global GitHub Advisory Database as of
2026-09-03, nine days later. Because every downstream consumer keys off that
database, the vulnerability is currently invisible to Dependabot, npm audit,
yarn audit, osv-scanner and anything else built on the OSV mirror.
Advisory
- GHSA ID: GHSA-2xp9-vwfh-vxw4
- Title: Unauthenticated Remote Code Execution in Image Optimization API when
AVIF files are used - Package: npm
next - Affected:
>= 10.0.0 < 15.5.24and< 16.3.3 - Patched: 15.5.24, 16.3.3
- Severity: Critical, CVSS v4 9.5
(CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H) - CVE: none assigned
- Upstream reference: GHSA-g89c-p67h-r497 (strukturag/libheif)
Current state
| Lookup | Result |
|---|---|
github.com/vercel/next.js/security/advisories/GHSA-2xp9-vwfh-vxw4 |
200, Critical, ranges as above |
github.com/advisories/GHSA-2xp9-vwfh-vxw4 |
404 |
api.github.com/[email protected] |
advisory not returned |
api.osv.dev/v1/vulns/GHSA-2xp9-vwfh-vxw4 |
404 |
Expected behaviour
A published repository advisory in a supported ecosystem (npm) should be
reviewed and ingested into the global Advisory Database, and from there
propagate to the API, the OSV mirror and Dependabot alerts.
Impact
Any team whose vulnerability management relies on the documented tooling —
which is the tooling GitHub itself recommends — got a clean bill of health
for a Critical unauthenticated RCE affecting two major release branches of
one of the most widely deployed npm packages. Verifying it required manually
opening the vendor's own advisory page, which does not scale and is not a
process any automated pipeline can perform.
Requests
- Ingest GHSA-2xp9-vwfh-vxw4 into the Advisory Database.
- Clarify the expected review latency for repository advisories, and whether
Critical-severity submissions are prioritised. - Consider exposing an API surface for published-but-not-yet-curated
repository advisories, so scanners can at least flag them as pending
rather than reporting zero findings.
- 主要语言
- 没有语言数据
- 星标
- 2.5k
- 派生
- 789
- 平均合并
- 6 天 10 小时
- 30 天内合并 PR
- 61
环境准备
- 没有 Dockerfile 或 Docker Compose 文件
- 没有 Pull Request 模板
- 阅读贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
github/advisory-database 的其他 Issue
-
Update https://github.com/advisories/GHSA-5pf6-cq2v-23ww to include patched version可能已有人在做 @GreyforgeLabs 于 3 天前认领。 未关闭
难度 2/5 1-3 小时 新手友好度 76/100
github/advisory-database#9879 ·
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 68/100
github/advisory-database#9255 ·
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 72/100
github/advisory-database#9164 · 1 个 reaction ·
维护者通常 1 天内回复
-
CVE-2026-5598 has incorrect fixed versions for bcprov-jdk packages可能已有人在做 @ECD5A 于 46 天前认领。 未关闭
难度 2/5 1-3 小时 新手友好度 72/100
github/advisory-database#8994 ·
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 68/100
github/advisory-database#8898 · 4 条评论 · 1 个 reaction ·
维护者通常 1 天内回复
查看 github/advisory-database 的全部 Issue
相似的 Issue
-
bug
难度 2/5 1-3 小时 新手友好度 72/100
AOSSIE-Org/DebateAI#611 ·
维护者通常 3 天内回复
-
terraform-provider
难度 2/5 1-3 小时 新手友好度 73/100
ClickHouse/terraform-provider-clickhousedbops#281 ·
维护者通常 2 天内回复
-
[CoreBundle] Migrations are silently skipped on MariaDB with DBAL 4 (AbstractMigration::isMySql())未关闭Potential Bug
难度 2/5 1-3 小时 新手友好度 78/100
Sylius/Sylius#19270 · 1 条评论 · 4 个 reaction ·
维护者通常 1 天内回复
-
channels:edit check:passed
难度 2/5 1-3 小时 新手友好度 65/100
维护者通常 4 天内回复
-
data-model security
难度 2/5 1-3 小时 新手友好度 65/100
Popoboxxo/ReqogniLoom#1184 ·
维护者通常 1 天内回复