data/reports: add 2 reports - data/reports/GO-2026-6619.yaml - data/reports/GO-2026-6620.yaml Fixes golang/vulndb#6619 Fixes golang/vulndb#6620 Change-Id: I5c0c82aa853ee6428c5afa27f77d7abbe5ca8472 Reviewed-on: https://go-review.googlesource.com/c/vulndb/+/842845 Auto-Submit: Ian Alexander <jitsu@google.com> LUCI-TryBot-Result: golang-scoped@luci-project-accounts.iam.gserviceaccount.com <golang-scoped@luci-project-accounts.iam.gserviceaccount.com> Reviewed-by: Damien Neil <dneil@google.com>
diff --git a/data/osv/GO-2026-6619.json b/data/osv/GO-2026-6619.json new file mode 100644 index 0000000..72a2dd2 --- /dev/null +++ b/data/osv/GO-2026-6619.json
@@ -0,0 +1,72 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6619", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2024-29296", + "GHSA-87x6-8m9v-g8c2" + ], + "summary": "Portainer CE allows username enumeration through authentication response timing in github.com/portainer/portainer", + "details": "Portainer CE allows username enumeration through authentication response timing in github.com/portainer/portainer", + "affected": [ + { + "package": { + "name": "github.com/portainer/portainer", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.6.1-0.20240417040827-48bc7d0d92f0" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-87x6-8m9v-g8c2" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29296" + }, + { + "type": "FIX", + "url": "https://github.com/portainer/portainer/commit/48bc7d0d92f038e04a72c1e0585bc325eb63a9e6" + }, + { + "type": "FIX", + "url": "https://github.com/portainer/portainer/pull/11589" + }, + { + "type": "REPORT", + "url": "https://github.com/portainer/portainer/issues/11736" + }, + { + "type": "WEB", + "url": "https://github.com/ThaySolis/CVE-2024-29296" + }, + { + "type": "WEB", + "url": "https://github.com/portainer/portainer/releases/tag/2.19.5" + }, + { + "type": "WEB", + "url": "https://github.com/portainer/portainer/releases/tag/2.20.2" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6619", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6620.json b/data/osv/GO-2026-6620.json new file mode 100644 index 0000000..ddd29d2 --- /dev/null +++ b/data/osv/GO-2026-6620.json
@@ -0,0 +1,60 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6620", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-53433", + "GHSA-mvmf-94v6-879g" + ], + "summary": "fzf vulnerable to denial of service through quadratic HTTP request-body accumulation in github.com/junegunn/fzf", + "details": "fzf vulnerable to denial of service through quadratic HTTP request-body accumulation in github.com/junegunn/fzf", + "affected": [ + { + "package": { + "name": "github.com/junegunn/fzf", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.73.1" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-mvmf-94v6-879g" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-53433" + }, + { + "type": "FIX", + "url": "https://github.com/junegunn/fzf/commit/7963a2c6586c0b9eaa89b8995de8f0e08cf8a4ce" + }, + { + "type": "WEB", + "url": "https://cert.pl/en/posts/2026/06/CVE-2026-53432" + }, + { + "type": "WEB", + "url": "https://github.com/junegunn/fzf/releases/tag/v0.73.1" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6620", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/reports/GO-2026-6619.yaml b/data/reports/GO-2026-6619.yaml new file mode 100644 index 0000000..683e31d --- /dev/null +++ b/data/reports/GO-2026-6619.yaml
@@ -0,0 +1,24 @@ +id: GO-2026-6619 +modules: + - module: github.com/portainer/portainer + versions: + - fixed: 0.6.1-0.20240417040827-48bc7d0d92f0 + vulnerable_at: 0.6.0 +summary: Portainer CE allows username enumeration through authentication response timing in github.com/portainer/portainer +cves: + - CVE-2024-29296 +ghsas: + - GHSA-87x6-8m9v-g8c2 +references: + - advisory: https://github.com/advisories/GHSA-87x6-8m9v-g8c2 + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2024-29296 + - fix: https://github.com/portainer/portainer/commit/48bc7d0d92f038e04a72c1e0585bc325eb63a9e6 + - fix: https://github.com/portainer/portainer/pull/11589 + - report: https://github.com/portainer/portainer/issues/11736 + - web: https://github.com/ThaySolis/CVE-2024-29296 + - web: https://github.com/portainer/portainer/releases/tag/2.19.5 + - web: https://github.com/portainer/portainer/releases/tag/2.20.2 +source: + id: GHSA-87x6-8m9v-g8c2 + created: 2026-10-01T09:18:01.321668-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6620.yaml b/data/reports/GO-2026-6620.yaml new file mode 100644 index 0000000..a8e73d7 --- /dev/null +++ b/data/reports/GO-2026-6620.yaml
@@ -0,0 +1,23 @@ +id: GO-2026-6620 +modules: + - module: github.com/junegunn/fzf + versions: + - fixed: 0.73.1 + vulnerable_at: 0.73.0 +summary: |- + fzf vulnerable to denial of service through quadratic HTTP request-body + accumulation in github.com/junegunn/fzf +cves: + - CVE-2026-53433 +ghsas: + - GHSA-mvmf-94v6-879g +references: + - advisory: https://github.com/advisories/GHSA-mvmf-94v6-879g + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-53433 + - fix: https://github.com/junegunn/fzf/commit/7963a2c6586c0b9eaa89b8995de8f0e08cf8a4ce + - web: https://cert.pl/en/posts/2026/06/CVE-2026-53432 + - web: https://github.com/junegunn/fzf/releases/tag/v0.73.1 +source: + id: GHSA-mvmf-94v6-879g + created: 2026-10-01T09:17:50.354919-04:00 +review_status: UNREVIEWED