data/reports: add 2 reports

  - data/reports/GO-2026-6619.yaml
  - data/reports/GO-2026-6620.yaml

Fixes golang/vulndb#6619
Fixes golang/vulndb#6620

Change-Id: I5c0c82aa853ee6428c5afa27f77d7abbe5ca8472
Reviewed-on: https://go-review.googlesource.com/c/vulndb/+/842845
Auto-Submit: Ian Alexander <jitsu@google.com>
LUCI-TryBot-Result: golang-scoped@luci-project-accounts.iam.gserviceaccount.com <golang-scoped@luci-project-accounts.iam.gserviceaccount.com>
Reviewed-by: Damien Neil <dneil@google.com>
diff --git a/data/osv/GO-2026-6619.json b/data/osv/GO-2026-6619.json
new file mode 100644
index 0000000..72a2dd2
--- /dev/null
+++ b/data/osv/GO-2026-6619.json
@@ -0,0 +1,72 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6619",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2024-29296",
+    "GHSA-87x6-8m9v-g8c2"
+  ],
+  "summary": "Portainer CE allows username enumeration through authentication response timing in github.com/portainer/portainer",
+  "details": "Portainer CE allows username enumeration through authentication response timing in github.com/portainer/portainer",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/portainer/portainer",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "0.6.1-0.20240417040827-48bc7d0d92f0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/advisories/GHSA-87x6-8m9v-g8c2"
+    },
+    {
+      "type": "ADVISORY",
+      "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29296"
+    },
+    {
+      "type": "FIX",
+      "url": "https://github.com/portainer/portainer/commit/48bc7d0d92f038e04a72c1e0585bc325eb63a9e6"
+    },
+    {
+      "type": "FIX",
+      "url": "https://github.com/portainer/portainer/pull/11589"
+    },
+    {
+      "type": "REPORT",
+      "url": "https://github.com/portainer/portainer/issues/11736"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/ThaySolis/CVE-2024-29296"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/portainer/portainer/releases/tag/2.19.5"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/portainer/portainer/releases/tag/2.20.2"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6619",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6620.json b/data/osv/GO-2026-6620.json
new file mode 100644
index 0000000..ddd29d2
--- /dev/null
+++ b/data/osv/GO-2026-6620.json
@@ -0,0 +1,60 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6620",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-53433",
+    "GHSA-mvmf-94v6-879g"
+  ],
+  "summary": "fzf vulnerable to denial of service through quadratic HTTP request-body accumulation in github.com/junegunn/fzf",
+  "details": "fzf vulnerable to denial of service through quadratic HTTP request-body accumulation in github.com/junegunn/fzf",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/junegunn/fzf",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "0.73.1"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/advisories/GHSA-mvmf-94v6-879g"
+    },
+    {
+      "type": "ADVISORY",
+      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-53433"
+    },
+    {
+      "type": "FIX",
+      "url": "https://github.com/junegunn/fzf/commit/7963a2c6586c0b9eaa89b8995de8f0e08cf8a4ce"
+    },
+    {
+      "type": "WEB",
+      "url": "https://cert.pl/en/posts/2026/06/CVE-2026-53432"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/junegunn/fzf/releases/tag/v0.73.1"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6620",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/reports/GO-2026-6619.yaml b/data/reports/GO-2026-6619.yaml
new file mode 100644
index 0000000..683e31d
--- /dev/null
+++ b/data/reports/GO-2026-6619.yaml
@@ -0,0 +1,24 @@
+id: GO-2026-6619
+modules:
+    - module: github.com/portainer/portainer
+      versions:
+        - fixed: 0.6.1-0.20240417040827-48bc7d0d92f0
+      vulnerable_at: 0.6.0
+summary: Portainer CE allows username enumeration through authentication response timing in github.com/portainer/portainer
+cves:
+    - CVE-2024-29296
+ghsas:
+    - GHSA-87x6-8m9v-g8c2
+references:
+    - advisory: https://github.com/advisories/GHSA-87x6-8m9v-g8c2
+    - advisory: https://nvd.nist.gov/vuln/detail/CVE-2024-29296
+    - fix: https://github.com/portainer/portainer/commit/48bc7d0d92f038e04a72c1e0585bc325eb63a9e6
+    - fix: https://github.com/portainer/portainer/pull/11589
+    - report: https://github.com/portainer/portainer/issues/11736
+    - web: https://github.com/ThaySolis/CVE-2024-29296
+    - web: https://github.com/portainer/portainer/releases/tag/2.19.5
+    - web: https://github.com/portainer/portainer/releases/tag/2.20.2
+source:
+    id: GHSA-87x6-8m9v-g8c2
+    created: 2026-10-01T09:18:01.321668-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6620.yaml b/data/reports/GO-2026-6620.yaml
new file mode 100644
index 0000000..a8e73d7
--- /dev/null
+++ b/data/reports/GO-2026-6620.yaml
@@ -0,0 +1,23 @@
+id: GO-2026-6620
+modules:
+    - module: github.com/junegunn/fzf
+      versions:
+        - fixed: 0.73.1
+      vulnerable_at: 0.73.0
+summary: |-
+    fzf vulnerable to denial of service through quadratic HTTP request-body
+    accumulation in github.com/junegunn/fzf
+cves:
+    - CVE-2026-53433
+ghsas:
+    - GHSA-mvmf-94v6-879g
+references:
+    - advisory: https://github.com/advisories/GHSA-mvmf-94v6-879g
+    - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-53433
+    - fix: https://github.com/junegunn/fzf/commit/7963a2c6586c0b9eaa89b8995de8f0e08cf8a4ce
+    - web: https://cert.pl/en/posts/2026/06/CVE-2026-53432
+    - web: https://github.com/junegunn/fzf/releases/tag/v0.73.1
+source:
+    id: GHSA-mvmf-94v6-879g
+    created: 2026-10-01T09:17:50.354919-04:00
+review_status: UNREVIEWED