data/reports: add 11 reports - data/reports/GO-2026-6491.yaml - data/reports/GO-2026-6492.yaml - data/reports/GO-2026-6493.yaml - data/reports/GO-2026-6494.yaml - data/reports/GO-2026-6496.yaml - data/reports/GO-2026-6498.yaml - data/reports/GO-2026-6500.yaml - data/reports/GO-2026-6502.yaml - data/reports/GO-2026-6503.yaml - data/reports/GO-2026-6505.yaml - data/reports/GO-2026-6566.yaml Fixes golang/vulndb#6491 Fixes golang/vulndb#6492 Fixes golang/vulndb#6493 Fixes golang/vulndb#6494 Fixes golang/vulndb#6496 Fixes golang/vulndb#6498 Fixes golang/vulndb#6500 Fixes golang/vulndb#6502 Fixes golang/vulndb#6503 Fixes golang/vulndb#6505 Fixes golang/vulndb#6566 Change-Id: I1d5bbf4f4695756675908e8fbb45d803a7d92414 Reviewed-on: https://go-review.googlesource.com/c/vulndb/+/840745 LUCI-TryBot-Result: golang-scoped@luci-project-accounts.iam.gserviceaccount.com <golang-scoped@luci-project-accounts.iam.gserviceaccount.com> Auto-Submit: Ian Alexander <jitsu@google.com> Reviewed-by: Damien Neil <dneil@google.com>
diff --git a/data/osv/GO-2026-6491.json b/data/osv/GO-2026-6491.json new file mode 100644 index 0000000..e94577f --- /dev/null +++ b/data/osv/GO-2026-6491.json
@@ -0,0 +1,76 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6491", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-77407", + "GHSA-27gv-rfvv-22mv" + ], + "summary": "RabbitMQ amqp091-go: Plaintext Credential Exposure via Exported PLAIN Authentication Struct Fields in github.com/rabbitmq/amqp091-go", + "details": "RabbitMQ amqp091-go: Plaintext Credential Exposure via Exported PLAIN Authentication Struct Fields in github.com/rabbitmq/amqp091-go", + "affected": [ + { + "package": { + "name": "github.com/rabbitmq/amqp091-go", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.13.0" + } + ] + } + ], + "ecosystem_specific": { + "imports": [ + { + "path": "github.com/rabbitmq/amqp091-go", + "symbols": [ + "Connection.Reconnect", + "Connection.openComplete", + "DefaultConnectionRecovery.OnConnectionClose", + "Dial", + "DialConfig", + "DialTLS", + "DialTLS_ExternalAuth", + "Open" + ] + } + ] + } + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/rabbitmq/amqp091-go/security/advisories/GHSA-27gv-rfvv-22mv" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-77407" + }, + { + "type": "FIX", + "url": "https://github.com/rabbitmq/amqp091-go/commit/fa013b8447eb60988db3c9281ff6b981e4d2fb4f" + }, + { + "type": "FIX", + "url": "https://github.com/rabbitmq/amqp091-go/pull/350" + }, + { + "type": "WEB", + "url": "https://github.com/rabbitmq/amqp091-go/releases/tag/v1.13.0" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6491", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6492.json b/data/osv/GO-2026-6492.json new file mode 100644 index 0000000..67c5e6e --- /dev/null +++ b/data/osv/GO-2026-6492.json
@@ -0,0 +1,73 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6492", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-77405", + "GHSA-33mj-cw25-m34h" + ], + "summary": "RabbitMQ amqp091-go: Missing Explicit TLS Minimum Version Configuration In URI Parser in github.com/rabbitmq/amqp091-go", + "details": "RabbitMQ amqp091-go: Missing Explicit TLS Minimum Version Configuration In URI Parser in github.com/rabbitmq/amqp091-go", + "affected": [ + { + "package": { + "name": "github.com/rabbitmq/amqp091-go", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.13.0" + } + ] + } + ], + "ecosystem_specific": { + "imports": [ + { + "path": "github.com/rabbitmq/amqp091-go", + "symbols": [ + "Dial", + "DialConfig", + "DialTLS", + "DialTLS_ExternalAuth", + "tlsConfigFromURI" + ] + } + ] + } + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/rabbitmq/amqp091-go/security/advisories/GHSA-33mj-cw25-m34h" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-77405" + }, + { + "type": "FIX", + "url": "https://github.com/rabbitmq/amqp091-go/commit/c9fd433ecac2e557919e51acc9d809390c402c6e" + }, + { + "type": "FIX", + "url": "https://github.com/rabbitmq/amqp091-go/pull/355" + }, + { + "type": "WEB", + "url": "https://github.com/rabbitmq/amqp091-go/releases/tag/v1.13.0" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6492", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6493.json b/data/osv/GO-2026-6493.json new file mode 100644 index 0000000..7011a62 --- /dev/null +++ b/data/osv/GO-2026-6493.json
@@ -0,0 +1,69 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6493", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-77404", + "GHSA-465g-fh3v-9jw4" + ], + "summary": "RabbitMQ amqp091-go: Connection Configuration Overwrite via Unsanitized TLS Path Parameter Injection in github.com/rabbitmq/amqp091-go", + "details": "RabbitMQ amqp091-go: Connection Configuration Overwrite via Unsanitized TLS Path Parameter Injection in github.com/rabbitmq/amqp091-go", + "affected": [ + { + "package": { + "name": "github.com/rabbitmq/amqp091-go", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.13.0" + } + ] + } + ], + "ecosystem_specific": { + "imports": [ + { + "path": "github.com/rabbitmq/amqp091-go", + "symbols": [ + "URI.String" + ] + } + ] + } + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/rabbitmq/amqp091-go/security/advisories/GHSA-465g-fh3v-9jw4" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-77404" + }, + { + "type": "FIX", + "url": "https://github.com/rabbitmq/amqp091-go/commit/743d488e46955fe7ffc55506fe2c401d01216783" + }, + { + "type": "FIX", + "url": "https://github.com/rabbitmq/amqp091-go/pull/352" + }, + { + "type": "WEB", + "url": "https://github.com/rabbitmq/amqp091-go/releases/tag/v1.13.0" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6493", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6494.json b/data/osv/GO-2026-6494.json new file mode 100644 index 0000000..646e59e --- /dev/null +++ b/data/osv/GO-2026-6494.json
@@ -0,0 +1,77 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6494", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-77412", + "GHSA-4v58-74mf-rjx3" + ], + "summary": "RabbitMQ amqp091-go: Denial of Service via Malicious Field Length in AMQP Client in github.com/rabbitmq/amqp091-go", + "details": "RabbitMQ amqp091-go: Denial of Service via Malicious Field Length in AMQP Client in github.com/rabbitmq/amqp091-go", + "affected": [ + { + "package": { + "name": "github.com/rabbitmq/amqp091-go", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.13.0" + } + ] + } + ], + "ecosystem_specific": { + "imports": [ + { + "path": "github.com/rabbitmq/amqp091-go", + "symbols": [ + "Connection.Reconnect", + "DefaultConnectionRecovery.OnConnectionClose", + "Dial", + "DialConfig", + "DialTLS", + "DialTLS_ExternalAuth", + "Open", + "readField", + "reader.ReadFrame" + ] + } + ] + } + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/rabbitmq/amqp091-go/security/advisories/GHSA-4v58-74mf-rjx3" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-77412" + }, + { + "type": "FIX", + "url": "https://github.com/rabbitmq/amqp091-go/commit/669b42bf7b1db76bc6d4973e3634247f680accbf" + }, + { + "type": "FIX", + "url": "https://github.com/rabbitmq/amqp091-go/pull/344" + }, + { + "type": "WEB", + "url": "https://github.com/rabbitmq/amqp091-go/releases/tag/v1.13.0" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6494", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6496.json b/data/osv/GO-2026-6496.json new file mode 100644 index 0000000..5a77a2e --- /dev/null +++ b/data/osv/GO-2026-6496.json
@@ -0,0 +1,77 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6496", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-77411", + "GHSA-c5pq-fr2g-9jpf" + ], + "summary": "RabbitMQ amqp091-go: Protocol Desynchronization and Frame Injection via Integer Overflow in readLongstr in github.com/rabbitmq/amqp091-go", + "details": "RabbitMQ amqp091-go: Protocol Desynchronization and Frame Injection via Integer Overflow in readLongstr in github.com/rabbitmq/amqp091-go", + "affected": [ + { + "package": { + "name": "github.com/rabbitmq/amqp091-go", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.13.0" + } + ] + } + ], + "ecosystem_specific": { + "imports": [ + { + "path": "github.com/rabbitmq/amqp091-go", + "symbols": [ + "Connection.Reconnect", + "DefaultConnectionRecovery.OnConnectionClose", + "Dial", + "DialConfig", + "DialTLS", + "DialTLS_ExternalAuth", + "Open", + "readLongstr", + "reader.ReadFrame" + ] + } + ] + } + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/rabbitmq/amqp091-go/security/advisories/GHSA-c5pq-fr2g-9jpf" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-77411" + }, + { + "type": "FIX", + "url": "https://github.com/rabbitmq/amqp091-go/commit/143c1ace5fa7344cee135e5c7d22970f0de68282" + }, + { + "type": "FIX", + "url": "https://github.com/rabbitmq/amqp091-go/pull/347" + }, + { + "type": "WEB", + "url": "https://github.com/rabbitmq/amqp091-go/releases/tag/v1.13.0" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6496", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6498.json b/data/osv/GO-2026-6498.json new file mode 100644 index 0000000..7b6bb27 --- /dev/null +++ b/data/osv/GO-2026-6498.json
@@ -0,0 +1,119 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6498", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-77408", + "GHSA-j497-x9hr-x34x" + ], + "summary": "RabbitMQ amqp091-go: Silent Data Truncation and State Corruption via Shortstr Integer Overflow in github.com/rabbitmq/amqp091-go", + "details": "RabbitMQ amqp091-go: Silent Data Truncation and State Corruption via Shortstr Integer Overflow in github.com/rabbitmq/amqp091-go", + "affected": [ + { + "package": { + "name": "github.com/rabbitmq/amqp091-go", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.13.0" + } + ] + } + ], + "ecosystem_specific": { + "imports": [ + { + "path": "github.com/rabbitmq/amqp091-go", + "symbols": [ + "AMQPlainAuth.Response", + "Channel.Ack", + "Channel.Cancel", + "Channel.Close", + "Channel.Confirm", + "Channel.Consume", + "Channel.ConsumeWithContext", + "Channel.ExchangeBind", + "Channel.ExchangeDeclare", + "Channel.ExchangeDeclarePassive", + "Channel.ExchangeDelete", + "Channel.ExchangeUnbind", + "Channel.Flow", + "Channel.Get", + "Channel.Nack", + "Channel.Publish", + "Channel.PublishWithContext", + "Channel.PublishWithDeferredConfirm", + "Channel.PublishWithDeferredConfirmWithContext", + "Channel.Qos", + "Channel.QueueBind", + "Channel.QueueDeclare", + "Channel.QueueDeclarePassive", + "Channel.QueueDelete", + "Channel.QueueInspect", + "Channel.QueuePurge", + "Channel.QueueUnbind", + "Channel.Reconnect", + "Channel.Recover", + "Channel.Reject", + "Channel.Tx", + "Channel.TxCommit", + "Channel.TxRollback", + "Connection.Channel", + "Connection.Close", + "Connection.CloseDeadline", + "Connection.Reconnect", + "Connection.UpdateSecret", + "DefaultConnectionRecovery.OnChannelClose", + "DefaultConnectionRecovery.OnConnectionClose", + "Delivery.Ack", + "Delivery.Nack", + "Delivery.Reject", + "Dial", + "DialConfig", + "DialTLS", + "DialTLS_ExternalAuth", + "Open", + "writeShortstr", + "writer.WriteFrame", + "writer.WriteFrameNoFlush" + ] + } + ] + } + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/rabbitmq/amqp091-go/security/advisories/GHSA-j497-x9hr-x34x" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-77408" + }, + { + "type": "FIX", + "url": "https://github.com/rabbitmq/amqp091-go/commit/6959423aa2784a1971e399175dfb2065dea0f3b0" + }, + { + "type": "FIX", + "url": "https://github.com/rabbitmq/amqp091-go/pull/354" + }, + { + "type": "WEB", + "url": "https://github.com/rabbitmq/amqp091-go/releases/tag/v1.13.0" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6498", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6500.json b/data/osv/GO-2026-6500.json new file mode 100644 index 0000000..b418c84 --- /dev/null +++ b/data/osv/GO-2026-6500.json
@@ -0,0 +1,76 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6500", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-77410", + "GHSA-r9c8-gcjp-xfwh" + ], + "summary": "RabbitMQ amqp091-go: Resource Exhaustion (OOM) via Unbounded Body Buffer Allocation in github.com/rabbitmq/amqp091-go", + "details": "RabbitMQ amqp091-go: Resource Exhaustion (OOM) via Unbounded Body Buffer Allocation in github.com/rabbitmq/amqp091-go", + "affected": [ + { + "package": { + "name": "github.com/rabbitmq/amqp091-go", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.13.0" + } + ] + } + ], + "ecosystem_specific": { + "imports": [ + { + "path": "github.com/rabbitmq/amqp091-go", + "symbols": [ + "Channel.recvContent", + "Connection.Reconnect", + "DefaultConnectionRecovery.OnConnectionClose", + "Dial", + "DialConfig", + "DialTLS", + "DialTLS_ExternalAuth", + "Open" + ] + } + ] + } + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/rabbitmq/amqp091-go/security/advisories/GHSA-r9c8-gcjp-xfwh" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-77410" + }, + { + "type": "FIX", + "url": "https://github.com/rabbitmq/amqp091-go/commit/91b65fa0096a99a580cf51a31b24028ff1c60382" + }, + { + "type": "FIX", + "url": "https://github.com/rabbitmq/amqp091-go/pull/346" + }, + { + "type": "WEB", + "url": "https://github.com/rabbitmq/amqp091-go/releases/tag/v1.13.0" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6500", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6502.json b/data/osv/GO-2026-6502.json new file mode 100644 index 0000000..f581d1f --- /dev/null +++ b/data/osv/GO-2026-6502.json
@@ -0,0 +1,69 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6502", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-77406", + "GHSA-rm6m-hrcw-jw33" + ], + "summary": "RabbitMQ amqp091-go: Consumer Message Flooding via Signed-to-Unsigned Integer Casting in Qos Configuration in github.com/rabbitmq/amqp091-go", + "details": "RabbitMQ amqp091-go: Consumer Message Flooding via Signed-to-Unsigned Integer Casting in Qos Configuration in github.com/rabbitmq/amqp091-go", + "affected": [ + { + "package": { + "name": "github.com/rabbitmq/amqp091-go", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.13.0" + } + ] + } + ], + "ecosystem_specific": { + "imports": [ + { + "path": "github.com/rabbitmq/amqp091-go", + "symbols": [ + "Channel.Qos" + ] + } + ] + } + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/rabbitmq/amqp091-go/security/advisories/GHSA-rm6m-hrcw-jw33" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-77406" + }, + { + "type": "FIX", + "url": "https://github.com/rabbitmq/amqp091-go/commit/3b879e1d1d25b544e26b3bc3d7db3213203c0f3b" + }, + { + "type": "FIX", + "url": "https://github.com/rabbitmq/amqp091-go/pull/351" + }, + { + "type": "WEB", + "url": "https://github.com/rabbitmq/amqp091-go/releases/tag/v1.13.0" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6502", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6503.json b/data/osv/GO-2026-6503.json new file mode 100644 index 0000000..b800abe --- /dev/null +++ b/data/osv/GO-2026-6503.json
@@ -0,0 +1,76 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6503", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-77403", + "GHSA-xwwf-m8fg-p9q2" + ], + "summary": "RabbitMQ amqp091-go: Denial of Service via Sub-Spec Frame Size Negotiation in github.com/rabbitmq/amqp091-go", + "details": "RabbitMQ amqp091-go: Denial of Service via Sub-Spec Frame Size Negotiation in github.com/rabbitmq/amqp091-go", + "affected": [ + { + "package": { + "name": "github.com/rabbitmq/amqp091-go", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.13.0" + } + ] + } + ], + "ecosystem_specific": { + "imports": [ + { + "path": "github.com/rabbitmq/amqp091-go", + "symbols": [ + "Connection.Reconnect", + "Connection.openTune", + "DefaultConnectionRecovery.OnConnectionClose", + "Dial", + "DialConfig", + "DialTLS", + "DialTLS_ExternalAuth", + "Open" + ] + } + ] + } + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/rabbitmq/amqp091-go/security/advisories/GHSA-xwwf-m8fg-p9q2" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-77403" + }, + { + "type": "FIX", + "url": "https://github.com/rabbitmq/amqp091-go/commit/2e0a919b89f337dbf58db2bb34ab206dac354a06" + }, + { + "type": "FIX", + "url": "https://github.com/rabbitmq/amqp091-go/pull/353" + }, + { + "type": "WEB", + "url": "https://github.com/rabbitmq/amqp091-go/releases/tag/v1.13.0" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6503", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6505.json b/data/osv/GO-2026-6505.json new file mode 100644 index 0000000..bf2b9c2 --- /dev/null +++ b/data/osv/GO-2026-6505.json
@@ -0,0 +1,144 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6505", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-81870", + "GHSA-8wmf-6v46-5gfg" + ], + "summary": "OpenTelemetry-Go: Exporter config logging may leak endpoint URLs in info logs in go.opentelemetry.io/otel/exporters/otlp/otlptrace", + "details": "OpenTelemetry-Go: Exporter config logging may leak endpoint URLs in info logs in go.opentelemetry.io/otel/exporters/otlp/otlptrace", + "affected": [ + { + "package": { + "name": "go.opentelemetry.io/otel/exporters/otlp/otlptrace", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "1.5.0" + }, + { + "fixed": "1.45.0" + } + ] + } + ], + "ecosystem_specific": {} + }, + { + "package": { + "name": "go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "1.5.0" + }, + { + "fixed": "1.45.0" + } + ] + } + ], + "ecosystem_specific": {} + }, + { + "package": { + "name": "go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "1.5.0" + }, + { + "fixed": "1.45.0" + } + ] + } + ], + "ecosystem_specific": {} + }, + { + "package": { + "name": "go.opentelemetry.io/otel/exporters/zipkin", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "1.5.0" + }, + { + "fixed": "1.45.0" + } + ] + } + ], + "ecosystem_specific": {} + }, + { + "package": { + "name": "go.opentelemetry.io/otel/sdk", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "1.5.0" + }, + { + "fixed": "1.45.0" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/open-telemetry/opentelemetry-go/security/advisories/GHSA-8wmf-6v46-5gfg" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-81870" + }, + { + "type": "WEB", + "url": "https://github.com/open-telemetry/opentelemetry-go/commit/3a1412d2b3bc4e4231fbeac2ed42117ae541bb38" + }, + { + "type": "WEB", + "url": "https://github.com/open-telemetry/opentelemetry-go/pull/8438" + }, + { + "type": "WEB", + "url": "https://github.com/open-telemetry/opentelemetry-go/releases/tag/exporters/zipkin/v1.45.0" + }, + { + "type": "WEB", + "url": "https://github.com/open-telemetry/opentelemetry-go/releases/tag/sdk/v1.45.0" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6505", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6566.json b/data/osv/GO-2026-6566.json new file mode 100644 index 0000000..0f2c841 --- /dev/null +++ b/data/osv/GO-2026-6566.json
@@ -0,0 +1,73 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6566", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-62987", + "GHSA-fq95-v8xc-jm3v" + ], + "summary": "Fabio - Incomplete fix for CVE-2025-48865: operator-configured trust headers (clientip/tls/requestid) still strippable via the Connection header in github.com/fabiolb/fabio", + "details": "Fabio - Incomplete fix for CVE-2025-48865: operator-configured trust headers (clientip/tls/requestid) still strippable via the Connection header in github.com/fabiolb/fabio", + "affected": [ + { + "package": { + "name": "github.com/fabiolb/fabio", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "1.6.6" + }, + { + "fixed": "1.7.2" + } + ] + } + ], + "ecosystem_specific": { + "imports": [ + { + "path": "github.com/fabiolb/fabio", + "symbols": [ + "main", + "newHTTPProxy" + ] + }, + { + "path": "github.com/fabiolb/fabio/proxy", + "symbols": [ + "HTTPProxy.ServeHTTP", + "addHeaders" + ] + } + ] + } + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/fabiolb/fabio/security/advisories/GHSA-fq95-v8xc-jm3v" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-62987" + }, + { + "type": "FIX", + "url": "https://github.com/fabiolb/fabio/commit/240526a8004077edad4fb96d25b382bfc3901357" + }, + { + "type": "WEB", + "url": "https://github.com/fabiolb/fabio/releases/tag/v1.7.2" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6566", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/reports/GO-2026-6491.yaml b/data/reports/GO-2026-6491.yaml new file mode 100644 index 0000000..7da088f --- /dev/null +++ b/data/reports/GO-2026-6491.yaml
@@ -0,0 +1,35 @@ +id: GO-2026-6491 +modules: + - module: github.com/rabbitmq/amqp091-go + versions: + - fixed: 1.13.0 + vulnerable_at: 1.12.0 + packages: + - package: github.com/rabbitmq/amqp091-go + symbols: + - Connection.openComplete + - DialConfig + - Connection.Reconnect + derived_symbols: + - DefaultConnectionRecovery.OnConnectionClose + - Dial + - DialTLS + - DialTLS_ExternalAuth + - Open +summary: |- + RabbitMQ amqp091-go: Plaintext Credential Exposure via Exported PLAIN + Authentication Struct Fields in github.com/rabbitmq/amqp091-go +cves: + - CVE-2026-77407 +ghsas: + - GHSA-27gv-rfvv-22mv +references: + - advisory: https://github.com/rabbitmq/amqp091-go/security/advisories/GHSA-27gv-rfvv-22mv + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-77407 + - fix: https://github.com/rabbitmq/amqp091-go/commit/fa013b8447eb60988db3c9281ff6b981e4d2fb4f + - fix: https://github.com/rabbitmq/amqp091-go/pull/350 + - web: https://github.com/rabbitmq/amqp091-go/releases/tag/v1.13.0 +source: + id: GHSA-27gv-rfvv-22mv + created: 2026-09-28T14:15:57.847422-04:00 +review_status: NEEDS_REVIEW
diff --git a/data/reports/GO-2026-6492.yaml b/data/reports/GO-2026-6492.yaml new file mode 100644 index 0000000..160ccf9 --- /dev/null +++ b/data/reports/GO-2026-6492.yaml
@@ -0,0 +1,32 @@ +id: GO-2026-6492 +modules: + - module: github.com/rabbitmq/amqp091-go + versions: + - fixed: 1.13.0 + vulnerable_at: 1.12.0 + packages: + - package: github.com/rabbitmq/amqp091-go + symbols: + - tlsConfigFromURI + derived_symbols: + - Dial + - DialConfig + - DialTLS + - DialTLS_ExternalAuth +summary: |- + RabbitMQ amqp091-go: Missing Explicit TLS Minimum Version Configuration In URI + Parser in github.com/rabbitmq/amqp091-go +cves: + - CVE-2026-77405 +ghsas: + - GHSA-33mj-cw25-m34h +references: + - advisory: https://github.com/rabbitmq/amqp091-go/security/advisories/GHSA-33mj-cw25-m34h + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-77405 + - fix: https://github.com/rabbitmq/amqp091-go/commit/c9fd433ecac2e557919e51acc9d809390c402c6e + - fix: https://github.com/rabbitmq/amqp091-go/pull/355 + - web: https://github.com/rabbitmq/amqp091-go/releases/tag/v1.13.0 +source: + id: GHSA-33mj-cw25-m34h + created: 2026-09-28T14:15:47.02331-04:00 +review_status: NEEDS_REVIEW
diff --git a/data/reports/GO-2026-6493.yaml b/data/reports/GO-2026-6493.yaml new file mode 100644 index 0000000..ec32fda --- /dev/null +++ b/data/reports/GO-2026-6493.yaml
@@ -0,0 +1,27 @@ +id: GO-2026-6493 +modules: + - module: github.com/rabbitmq/amqp091-go + versions: + - fixed: 1.13.0 + vulnerable_at: 1.12.0 + packages: + - package: github.com/rabbitmq/amqp091-go + symbols: + - URI.String +summary: |- + RabbitMQ amqp091-go: Connection Configuration Overwrite via Unsanitized TLS Path + Parameter Injection in github.com/rabbitmq/amqp091-go +cves: + - CVE-2026-77404 +ghsas: + - GHSA-465g-fh3v-9jw4 +references: + - advisory: https://github.com/rabbitmq/amqp091-go/security/advisories/GHSA-465g-fh3v-9jw4 + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-77404 + - fix: https://github.com/rabbitmq/amqp091-go/commit/743d488e46955fe7ffc55506fe2c401d01216783 + - fix: https://github.com/rabbitmq/amqp091-go/pull/352 + - web: https://github.com/rabbitmq/amqp091-go/releases/tag/v1.13.0 +source: + id: GHSA-465g-fh3v-9jw4 + created: 2026-09-28T14:15:35.73771-04:00 +review_status: NEEDS_REVIEW
diff --git a/data/reports/GO-2026-6494.yaml b/data/reports/GO-2026-6494.yaml new file mode 100644 index 0000000..560cfe7 --- /dev/null +++ b/data/reports/GO-2026-6494.yaml
@@ -0,0 +1,34 @@ +id: GO-2026-6494 +modules: + - module: github.com/rabbitmq/amqp091-go + versions: + - fixed: 1.13.0 + vulnerable_at: 1.12.0 + packages: + - package: github.com/rabbitmq/amqp091-go + symbols: + - readField + derived_symbols: + - Connection.Reconnect + - DefaultConnectionRecovery.OnConnectionClose + - Dial + - DialConfig + - DialTLS + - DialTLS_ExternalAuth + - Open + - reader.ReadFrame +summary: 'RabbitMQ amqp091-go: Denial of Service via Malicious Field Length in AMQP Client in github.com/rabbitmq/amqp091-go' +cves: + - CVE-2026-77412 +ghsas: + - GHSA-4v58-74mf-rjx3 +references: + - advisory: https://github.com/rabbitmq/amqp091-go/security/advisories/GHSA-4v58-74mf-rjx3 + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-77412 + - fix: https://github.com/rabbitmq/amqp091-go/commit/669b42bf7b1db76bc6d4973e3634247f680accbf + - fix: https://github.com/rabbitmq/amqp091-go/pull/344 + - web: https://github.com/rabbitmq/amqp091-go/releases/tag/v1.13.0 +source: + id: GHSA-4v58-74mf-rjx3 + created: 2026-09-28T14:15:24.018661-04:00 +review_status: NEEDS_REVIEW
diff --git a/data/reports/GO-2026-6496.yaml b/data/reports/GO-2026-6496.yaml new file mode 100644 index 0000000..69980c6 --- /dev/null +++ b/data/reports/GO-2026-6496.yaml
@@ -0,0 +1,36 @@ +id: GO-2026-6496 +modules: + - module: github.com/rabbitmq/amqp091-go + versions: + - fixed: 1.13.0 + vulnerable_at: 1.12.0 + packages: + - package: github.com/rabbitmq/amqp091-go + symbols: + - readLongstr + derived_symbols: + - Connection.Reconnect + - DefaultConnectionRecovery.OnConnectionClose + - Dial + - DialConfig + - DialTLS + - DialTLS_ExternalAuth + - Open + - reader.ReadFrame +summary: |- + RabbitMQ amqp091-go: Protocol Desynchronization and Frame Injection via Integer + Overflow in readLongstr in github.com/rabbitmq/amqp091-go +cves: + - CVE-2026-77411 +ghsas: + - GHSA-c5pq-fr2g-9jpf +references: + - advisory: https://github.com/rabbitmq/amqp091-go/security/advisories/GHSA-c5pq-fr2g-9jpf + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-77411 + - fix: https://github.com/rabbitmq/amqp091-go/commit/143c1ace5fa7344cee135e5c7d22970f0de68282 + - fix: https://github.com/rabbitmq/amqp091-go/pull/347 + - web: https://github.com/rabbitmq/amqp091-go/releases/tag/v1.13.0 +source: + id: GHSA-c5pq-fr2g-9jpf + created: 2026-09-28T14:15:13.119863-04:00 +review_status: NEEDS_REVIEW
diff --git a/data/reports/GO-2026-6498.yaml b/data/reports/GO-2026-6498.yaml new file mode 100644 index 0000000..2c34b5c --- /dev/null +++ b/data/reports/GO-2026-6498.yaml
@@ -0,0 +1,78 @@ +id: GO-2026-6498 +modules: + - module: github.com/rabbitmq/amqp091-go + versions: + - fixed: 1.13.0 + vulnerable_at: 1.12.0 + packages: + - package: github.com/rabbitmq/amqp091-go + symbols: + - writeShortstr + derived_symbols: + - AMQPlainAuth.Response + - Channel.Ack + - Channel.Cancel + - Channel.Close + - Channel.Confirm + - Channel.Consume + - Channel.ConsumeWithContext + - Channel.ExchangeBind + - Channel.ExchangeDeclare + - Channel.ExchangeDeclarePassive + - Channel.ExchangeDelete + - Channel.ExchangeUnbind + - Channel.Flow + - Channel.Get + - Channel.Nack + - Channel.Publish + - Channel.PublishWithContext + - Channel.PublishWithDeferredConfirm + - Channel.PublishWithDeferredConfirmWithContext + - Channel.Qos + - Channel.QueueBind + - Channel.QueueDeclare + - Channel.QueueDeclarePassive + - Channel.QueueDelete + - Channel.QueueInspect + - Channel.QueuePurge + - Channel.QueueUnbind + - Channel.Reconnect + - Channel.Recover + - Channel.Reject + - Channel.Tx + - Channel.TxCommit + - Channel.TxRollback + - Connection.Channel + - Connection.Close + - Connection.CloseDeadline + - Connection.Reconnect + - Connection.UpdateSecret + - DefaultConnectionRecovery.OnChannelClose + - DefaultConnectionRecovery.OnConnectionClose + - Delivery.Ack + - Delivery.Nack + - Delivery.Reject + - Dial + - DialConfig + - DialTLS + - DialTLS_ExternalAuth + - Open + - writer.WriteFrame + - writer.WriteFrameNoFlush +summary: |- + RabbitMQ amqp091-go: Silent Data Truncation and State Corruption via Shortstr + Integer Overflow in github.com/rabbitmq/amqp091-go +cves: + - CVE-2026-77408 +ghsas: + - GHSA-j497-x9hr-x34x +references: + - advisory: https://github.com/rabbitmq/amqp091-go/security/advisories/GHSA-j497-x9hr-x34x + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-77408 + - fix: https://github.com/rabbitmq/amqp091-go/commit/6959423aa2784a1971e399175dfb2065dea0f3b0 + - fix: https://github.com/rabbitmq/amqp091-go/pull/354 + - web: https://github.com/rabbitmq/amqp091-go/releases/tag/v1.13.0 +source: + id: GHSA-j497-x9hr-x34x + created: 2026-09-28T14:14:54.209569-04:00 +review_status: NEEDS_REVIEW
diff --git a/data/reports/GO-2026-6500.yaml b/data/reports/GO-2026-6500.yaml new file mode 100644 index 0000000..ecbeeee --- /dev/null +++ b/data/reports/GO-2026-6500.yaml
@@ -0,0 +1,35 @@ +id: GO-2026-6500 +modules: + - module: github.com/rabbitmq/amqp091-go + versions: + - fixed: 1.13.0 + vulnerable_at: 1.12.0 + packages: + - package: github.com/rabbitmq/amqp091-go + symbols: + - Channel.recvContent + derived_symbols: + - Connection.Reconnect + - DefaultConnectionRecovery.OnConnectionClose + - Dial + - DialConfig + - DialTLS + - DialTLS_ExternalAuth + - Open +summary: |- + RabbitMQ amqp091-go: Resource Exhaustion (OOM) via Unbounded Body Buffer + Allocation in github.com/rabbitmq/amqp091-go +cves: + - CVE-2026-77410 +ghsas: + - GHSA-r9c8-gcjp-xfwh +references: + - advisory: https://github.com/rabbitmq/amqp091-go/security/advisories/GHSA-r9c8-gcjp-xfwh + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-77410 + - fix: https://github.com/rabbitmq/amqp091-go/commit/91b65fa0096a99a580cf51a31b24028ff1c60382 + - fix: https://github.com/rabbitmq/amqp091-go/pull/346 + - web: https://github.com/rabbitmq/amqp091-go/releases/tag/v1.13.0 +source: + id: GHSA-r9c8-gcjp-xfwh + created: 2026-09-28T14:14:34.511097-04:00 +review_status: NEEDS_REVIEW
diff --git a/data/reports/GO-2026-6502.yaml b/data/reports/GO-2026-6502.yaml new file mode 100644 index 0000000..1e4f2e4 --- /dev/null +++ b/data/reports/GO-2026-6502.yaml
@@ -0,0 +1,27 @@ +id: GO-2026-6502 +modules: + - module: github.com/rabbitmq/amqp091-go + versions: + - fixed: 1.13.0 + vulnerable_at: 1.12.0 + packages: + - package: github.com/rabbitmq/amqp091-go + symbols: + - Channel.Qos +summary: |- + RabbitMQ amqp091-go: Consumer Message Flooding via Signed-to-Unsigned Integer + Casting in Qos Configuration in github.com/rabbitmq/amqp091-go +cves: + - CVE-2026-77406 +ghsas: + - GHSA-rm6m-hrcw-jw33 +references: + - advisory: https://github.com/rabbitmq/amqp091-go/security/advisories/GHSA-rm6m-hrcw-jw33 + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-77406 + - fix: https://github.com/rabbitmq/amqp091-go/commit/3b879e1d1d25b544e26b3bc3d7db3213203c0f3b + - fix: https://github.com/rabbitmq/amqp091-go/pull/351 + - web: https://github.com/rabbitmq/amqp091-go/releases/tag/v1.13.0 +source: + id: GHSA-rm6m-hrcw-jw33 + created: 2026-09-28T14:14:23.053831-04:00 +review_status: NEEDS_REVIEW
diff --git a/data/reports/GO-2026-6503.yaml b/data/reports/GO-2026-6503.yaml new file mode 100644 index 0000000..4de9836 --- /dev/null +++ b/data/reports/GO-2026-6503.yaml
@@ -0,0 +1,33 @@ +id: GO-2026-6503 +modules: + - module: github.com/rabbitmq/amqp091-go + versions: + - fixed: 1.13.0 + vulnerable_at: 1.12.0 + packages: + - package: github.com/rabbitmq/amqp091-go + symbols: + - Connection.openTune + derived_symbols: + - Connection.Reconnect + - DefaultConnectionRecovery.OnConnectionClose + - Dial + - DialConfig + - DialTLS + - DialTLS_ExternalAuth + - Open +summary: 'RabbitMQ amqp091-go: Denial of Service via Sub-Spec Frame Size Negotiation in github.com/rabbitmq/amqp091-go' +cves: + - CVE-2026-77403 +ghsas: + - GHSA-xwwf-m8fg-p9q2 +references: + - advisory: https://github.com/rabbitmq/amqp091-go/security/advisories/GHSA-xwwf-m8fg-p9q2 + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-77403 + - fix: https://github.com/rabbitmq/amqp091-go/commit/2e0a919b89f337dbf58db2bb34ab206dac354a06 + - fix: https://github.com/rabbitmq/amqp091-go/pull/353 + - web: https://github.com/rabbitmq/amqp091-go/releases/tag/v1.13.0 +source: + id: GHSA-xwwf-m8fg-p9q2 + created: 2026-09-28T14:14:09.345783-04:00 +review_status: NEEDS_REVIEW
diff --git a/data/reports/GO-2026-6505.yaml b/data/reports/GO-2026-6505.yaml new file mode 100644 index 0000000..a030973 --- /dev/null +++ b/data/reports/GO-2026-6505.yaml
@@ -0,0 +1,45 @@ +id: GO-2026-6505 +modules: + - module: go.opentelemetry.io/otel/exporters/otlp/otlptrace + versions: + - introduced: 1.5.0 + - fixed: 1.45.0 + vulnerable_at: 1.44.0 + - module: go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc + versions: + - introduced: 1.5.0 + - fixed: 1.45.0 + vulnerable_at: 1.44.0 + - module: go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp + versions: + - introduced: 1.5.0 + - fixed: 1.45.0 + vulnerable_at: 1.44.0 + - module: go.opentelemetry.io/otel/exporters/zipkin + versions: + - introduced: 1.5.0 + - fixed: 1.45.0 + vulnerable_at: 1.44.0 + - module: go.opentelemetry.io/otel/sdk + versions: + - introduced: 1.5.0 + - fixed: 1.45.0 + vulnerable_at: 1.44.0 +summary: 'OpenTelemetry-Go: Exporter config logging may leak endpoint URLs in info logs in go.opentelemetry.io/otel/exporters/otlp/otlptrace' +cves: + - CVE-2026-81870 +ghsas: + - GHSA-8wmf-6v46-5gfg +references: + - advisory: https://github.com/open-telemetry/opentelemetry-go/security/advisories/GHSA-8wmf-6v46-5gfg + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-81870 + - web: https://github.com/open-telemetry/opentelemetry-go/commit/3a1412d2b3bc4e4231fbeac2ed42117ae541bb38 + - web: https://github.com/open-telemetry/opentelemetry-go/pull/8438 + - web: https://github.com/open-telemetry/opentelemetry-go/releases/tag/exporters/zipkin/v1.45.0 + - web: https://github.com/open-telemetry/opentelemetry-go/releases/tag/sdk/v1.45.0 +notes: + - create: failed to auto-populate symbols +source: + id: GHSA-8wmf-6v46-5gfg + created: 2026-09-28T14:13:58.362805-04:00 +review_status: NEEDS_REVIEW
diff --git a/data/reports/GO-2026-6566.yaml b/data/reports/GO-2026-6566.yaml new file mode 100644 index 0000000..c7eecf3 --- /dev/null +++ b/data/reports/GO-2026-6566.yaml
@@ -0,0 +1,33 @@ +id: GO-2026-6566 +modules: + - module: github.com/fabiolb/fabio + versions: + - introduced: 1.6.6 + - fixed: 1.7.2 + vulnerable_at: 1.7.1 + packages: + - package: github.com/fabiolb/fabio + symbols: + - newHTTPProxy + derived_symbols: + - main + - package: github.com/fabiolb/fabio/proxy + symbols: + - HTTPProxy.ServeHTTP + - addHeaders +summary: |- + Fabio - Incomplete fix for CVE-2025-48865: operator-configured trust headers + (clientip/tls/requestid) still strippable via the Connection header in github.com/fabiolb/fabio +cves: + - CVE-2026-62987 +ghsas: + - GHSA-fq95-v8xc-jm3v +references: + - advisory: https://github.com/fabiolb/fabio/security/advisories/GHSA-fq95-v8xc-jm3v + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-62987 + - fix: https://github.com/fabiolb/fabio/commit/240526a8004077edad4fb96d25b382bfc3901357 + - web: https://github.com/fabiolb/fabio/releases/tag/v1.7.2 +source: + id: GHSA-fq95-v8xc-jm3v + created: 2026-09-28T14:08:48.809403-04:00 +review_status: NEEDS_REVIEW