data/reports: review 8 reports

  - data/reports/GO-2026-6115.yaml
  - data/reports/GO-2026-6166.yaml
  - data/reports/GO-2026-6168.yaml
  - data/reports/GO-2026-6169.yaml
  - data/reports/GO-2026-6170.yaml
  - data/reports/GO-2026-6171.yaml
  - data/reports/GO-2026-6172.yaml
  - data/reports/GO-2026-6173.yaml

Fixes golang/vulndb#6115
Fixes golang/vulndb#6166
Fixes golang/vulndb#6168
Fixes golang/vulndb#6169
Fixes golang/vulndb#6170
Fixes golang/vulndb#6171
Fixes golang/vulndb#6172
Fixes golang/vulndb#6173

Change-Id: I8e8f92f3f0326b12086df9be264d9c5cf904a829
Reviewed-on: https://go-review.googlesource.com/c/vulndb/+/817420
LUCI-TryBot-Result: golang-scoped@luci-project-accounts.iam.gserviceaccount.com <golang-scoped@luci-project-accounts.iam.gserviceaccount.com>
Reviewed-by: Nicholas Husin <husin@google.com>
Reviewed-by: Neal Patel <neal@golang.org>
Reviewed-by: Neal Patel <nealpatel@google.com>
Auto-Submit: Nicholas Husin <husin@google.com>
diff --git a/data/osv/GO-2026-6115.json b/data/osv/GO-2026-6115.json
index b4d1acb..ccb2b0e 100644
--- a/data/osv/GO-2026-6115.json
+++ b/data/osv/GO-2026-6115.json
@@ -8,7 +8,7 @@
     "CVE-2026-56867"
   ],
   "summary": "WITHDRAWN: Multiple denial of service vulnerabilities in rsc.io/pdf and forks",
-  "details": "(This report has been withdrawn with reason: \"Requesting a CVE ID via the Go CNA as part of this report\"). The PDF parser in rsc.io/pdf and its downstream forks github.com/ledongthuc/pdf and github.com/dslipak/pdf contains multiple defects when parsing untrusted input:\n\n- Unchecked /Size, /Index, /W, and classic subsection header parameters in cross-reference tables allow crafted values to trigger fatal out-of-memory (OOM) panics.\n- Unterminated hexadecimal strings cause an infinite loop in readByte and readHexString.\n- Cyclic object references (/First, /Parent, /Kids, /Next) in document outlines cause unbounded recursion leading to uncatchable stack overflow.\n- Various malformed constructs trigger runtime panics in NewReader and Page.Content (such as empty graphics state pop 'Q', oversized CMap entries, odd-length UTF-16 strings, and newline buffer underflows).",
+  "details": "(This report has been withdrawn with reason: \"Report mistakenly added without having CVE / GHSA associated\"). The PDF parser in rsc.io/pdf and its downstream forks github.com/ledongthuc/pdf and github.com/dslipak/pdf contains multiple defects when parsing untrusted input:\n\n- Unchecked /Size, /Index, /W, and classic subsection header parameters in cross-reference tables allow crafted values to trigger fatal out-of-memory (OOM) panics.\n- Unterminated hexadecimal strings cause an infinite loop in readByte and readHexString.\n- Cyclic object references (/First, /Parent, /Kids, /Next) in document outlines cause unbounded recursion leading to uncatchable stack overflow.\n- Various malformed constructs trigger runtime panics in NewReader and Page.Content (such as empty graphics state pop 'Q', oversized CMap entries, odd-length UTF-16 strings, and newline buffer underflows).",
   "affected": [
     {
       "package": {
diff --git a/data/osv/GO-2026-6166.json b/data/osv/GO-2026-6166.json
index c1381c8..c06dcef 100644
--- a/data/osv/GO-2026-6166.json
+++ b/data/osv/GO-2026-6166.json
@@ -8,7 +8,7 @@
     "CVE-2026-56868"
   ],
   "summary": "WITHDRAWN: GSS authentication completes without mutual proof in github.com/lib/pq",
-  "details": "(This report has been withdrawn with reason: \"False positive\"). github.com/lib/pq does not require a GSSAPI exchange to reach cryptographic completion before accepting AuthenticationOk and ReadyForQuery. After an unauthenticated peer requests GSS authentication, the driver sends its initial GSS token and stores the provider, but it tracks neither whether a continuation occurred nor the provider's done result. The startup loop then accepts AuthenticationOk and completes the connection. The continuation branch also discards provider errors and can proceed after failed mutual authentication.",
+  "details": "(This report has been withdrawn with reason: \"Report mistakenly added without having CVE / GHSA associated\"). github.com/lib/pq does not require a GSSAPI exchange to reach cryptographic completion before accepting AuthenticationOk and ReadyForQuery. After an unauthenticated peer requests GSS authentication, the driver sends its initial GSS token and stores the provider, but it tracks neither whether a continuation occurred nor the provider's done result. The startup loop then accepts AuthenticationOk and completes the connection. The continuation branch also discards provider errors and can proceed after failed mutual authentication.",
   "affected": [
     {
       "package": {
diff --git a/data/osv/GO-2026-6168.json b/data/osv/GO-2026-6168.json
index ac10e3b..16b22d7 100644
--- a/data/osv/GO-2026-6168.json
+++ b/data/osv/GO-2026-6168.json
@@ -8,7 +8,7 @@
     "CVE-2026-56869"
   ],
   "summary": "WITHDRAWN: Unbounded iteration count causes CPU denial of service in github.com/lib/pq/scram",
-  "details": "(This report has been withdrawn with reason: \"False positive\"). The SCRAM client in github.com/lib/pq/scram accepts an attacker-controlled iteration count with no upper bound and immediately performs that many PBKDF2-style HMAC rounds. A PostgreSQL endpoint or active network attacker can send a valid SCRAM server-first message with a large iteration count (such as i=2147483647), causing client authentication to consume excessive CPU resources before verifying the server signature.",
+  "details": "(This report has been withdrawn with reason: \"Report mistakenly added without having CVE / GHSA associated\"). The SCRAM client in github.com/lib/pq/scram accepts an attacker-controlled iteration count with no upper bound and immediately performs that many PBKDF2-style HMAC rounds. A PostgreSQL endpoint or active network attacker can send a valid SCRAM server-first message with a large iteration count (such as i=2147483647), causing client authentication to consume excessive CPU resources before verifying the server signature.",
   "affected": [
     {
       "package": {
diff --git a/data/osv/GO-2026-6169.json b/data/osv/GO-2026-6169.json
index d5e89c1..3126cfd 100644
--- a/data/osv/GO-2026-6169.json
+++ b/data/osv/GO-2026-6169.json
@@ -8,7 +8,7 @@
     "CVE-2026-56870"
   ],
   "summary": "WITHDRAWN: Disclosure of wrong .pgpass credential via hostaddr in github.com/lib/pq",
-  "details": "(This report has been withdrawn with reason: \"False positive\"). When a connection specifies hostaddr without host, github.com/lib/pq dials the numeric hostaddr but performs .pgpass lookup using the default Config.Host value, localhost. If the passfile contains different credentials for localhost and the remote address, the driver selects the secret intended for the local database and sends it to the remote endpoint when that endpoint requests password authentication.",
+  "details": "(This report has been withdrawn with reason: \"Report mistakenly added without having CVE / GHSA associated\"). When a connection specifies hostaddr without host, github.com/lib/pq dials the numeric hostaddr but performs .pgpass lookup using the default Config.Host value, localhost. If the passfile contains different credentials for localhost and the remote address, the driver selects the secret intended for the local database and sends it to the remote endpoint when that endpoint requests password authentication.",
   "affected": [
     {
       "package": {
diff --git a/data/osv/GO-2026-6170.json b/data/osv/GO-2026-6170.json
index 8494594..217b5b8 100644
--- a/data/osv/GO-2026-6170.json
+++ b/data/osv/GO-2026-6170.json
@@ -8,7 +8,7 @@
     "CVE-2026-56871"
   ],
   "summary": "WITHDRAWN: Malformed backend frame length causes panic in github.com/lib/pq",
-  "details": "(This report has been withdrawn with reason: \"False positive\"). github.com/lib/pq trusts the unsigned 32-bit length in every PostgreSQL backend frame and subtracts four without first checking that the wire length is at least four. A backend frame whose length is zero through three produces a negative payload length. recvMessage then slices the connection scratch buffer with that negative bound, causing an unrecovered runtime panic that terminates the calling goroutine and process.",
+  "details": "(This report has been withdrawn with reason: \"Report mistakenly added without having CVE / GHSA associated\"). github.com/lib/pq trusts the unsigned 32-bit length in every PostgreSQL backend frame and subtracts four without first checking that the wire length is at least four. A backend frame whose length is zero through three produces a negative payload length. recvMessage then slices the connection scratch buffer with that negative bound, causing an unrecovered runtime panic that terminates the calling goroutine and process.",
   "affected": [
     {
       "package": {
diff --git a/data/osv/GO-2026-6171.json b/data/osv/GO-2026-6171.json
index bc9b224..9da77d4 100644
--- a/data/osv/GO-2026-6171.json
+++ b/data/osv/GO-2026-6171.json
@@ -8,7 +8,7 @@
     "CVE-2026-56872"
   ],
   "summary": "WITHDRAWN: Malformed RowDescription and DataRow messages cause panics in github.com/lib/pq",
-  "details": "(This report has been withdrawn with reason: \"False positive\"). github.com/lib/pq decodes attacker-controlled RowDescription and DataRow payloads without validating their structural relationship or encoded value widths required by binary decoders. A malicious PostgreSQL endpoint or active network attacker on an unauthenticated transport can send malformed row responses, causing unrecovered runtime panics while reading query results.",
+  "details": "(This report has been withdrawn with reason: \"Report mistakenly added without having CVE / GHSA associated\"). github.com/lib/pq decodes attacker-controlled RowDescription and DataRow payloads without validating their structural relationship or encoded value widths required by binary decoders. A malicious PostgreSQL endpoint or active network attacker on an unauthenticated transport can send malformed row responses, causing unrecovered runtime panics while reading query results.",
   "affected": [
     {
       "package": {
diff --git a/data/osv/GO-2026-6172.json b/data/osv/GO-2026-6172.json
index 87b779a..7759951 100644
--- a/data/osv/GO-2026-6172.json
+++ b/data/osv/GO-2026-6172.json
@@ -8,7 +8,7 @@
     "CVE-2026-56873"
   ],
   "summary": "WITHDRAWN: Backend frame lengths cause pre-validation memory exhaustion in github.com/lib/pq",
-  "details": "(This report has been withdrawn with reason: \"False positive\"). github.com/lib/pq allocates the backend-declared PostgreSQL frame payload before applying a protocol length bound or a phase-specific message-type check. A malicious server or active network attacker on an unauthenticated connection can send frame headers declaring multi-gigabyte or invalid-phase payloads, forcing large allocations that lead to memory exhaustion and runtime out-of-memory crashes.",
+  "details": "(This report has been withdrawn with reason: \"Report mistakenly added without having CVE / GHSA associated\"). github.com/lib/pq allocates the backend-declared PostgreSQL frame payload before applying a protocol length bound or a phase-specific message-type check. A malicious server or active network attacker on an unauthenticated connection can send frame headers declaring multi-gigabyte or invalid-phase payloads, forcing large allocations that lead to memory exhaustion and runtime out-of-memory crashes.",
   "affected": [
     {
       "package": {
diff --git a/data/osv/GO-2026-6173.json b/data/osv/GO-2026-6173.json
index 550c39f..ecf0953 100644
--- a/data/osv/GO-2026-6173.json
+++ b/data/osv/GO-2026-6173.json
@@ -8,7 +8,7 @@
     "CVE-2026-56874"
   ],
   "summary": "WITHDRAWN: Pre-protocol error reader permits unbounded memory consumption in github.com/lib/pq",
-  "details": "(This report has been withdrawn with reason: \"False positive\"). The special-case parser for PostgreSQL pre-protocol plain-text errors in github.com/lib/pq calls bufio.Reader.ReadString(0) without a byte limit. A malicious PostgreSQL endpoint or active network attacker on an unauthenticated transport can send an error message response with non-NUL bytes continuously, causing the client to buffer an arbitrarily large string and crash with an unrecoverable out-of-memory error.",
+  "details": "(This report has been withdrawn with reason: \"Report mistakenly added without having CVE / GHSA associated\"). The special-case parser for PostgreSQL pre-protocol plain-text errors in github.com/lib/pq calls bufio.Reader.ReadString(0) without a byte limit. A malicious PostgreSQL endpoint or active network attacker on an unauthenticated transport can send an error message response with non-NUL bytes continuously, causing the client to buffer an arbitrarily large string and crash with an unrecoverable out-of-memory error.",
   "affected": [
     {
       "package": {
diff --git a/data/reports/GO-2026-6115.yaml b/data/reports/GO-2026-6115.yaml
index 7039aa0..c5cd704 100644
--- a/data/reports/GO-2026-6115.yaml
+++ b/data/reports/GO-2026-6115.yaml
@@ -39,10 +39,10 @@
           skip_fix: repository is archived
 summary: 'WITHDRAWN: Multiple denial of service vulnerabilities in rsc.io/pdf and forks'
 description: |-
-    (This report has been withdrawn with reason: "Requesting a CVE ID via the Go CNA
-    as part of this report"). The PDF parser in rsc.io/pdf and its downstream forks
-    github.com/ledongthuc/pdf and github.com/dslipak/pdf contains multiple defects
-    when parsing untrusted input:
+    (This report has been withdrawn with reason: "Report mistakenly added without
+    having CVE / GHSA associated"). The PDF parser in rsc.io/pdf and its downstream
+    forks github.com/ledongthuc/pdf and github.com/dslipak/pdf contains multiple
+    defects when parsing untrusted input:
 
     - Unchecked /Size, /Index, /W, and classic subsection header parameters in
     cross-reference tables allow crafted values to trigger fatal out-of-memory (OOM)
diff --git a/data/reports/GO-2026-6166.yaml b/data/reports/GO-2026-6166.yaml
index 924266e..fe4804c 100644
--- a/data/reports/GO-2026-6166.yaml
+++ b/data/reports/GO-2026-6166.yaml
@@ -19,14 +19,15 @@
     WITHDRAWN: GSS authentication completes without mutual proof in
     github.com/lib/pq
 description: |-
-    (This report has been withdrawn with reason: "False positive").
-    github.com/lib/pq does not require a GSSAPI exchange to reach cryptographic
-    completion before accepting AuthenticationOk and ReadyForQuery. After an
-    unauthenticated peer requests GSS authentication, the driver sends its initial
-    GSS token and stores the provider, but it tracks neither whether a continuation
-    occurred nor the provider's done result. The startup loop then accepts
-    AuthenticationOk and completes the connection. The continuation branch also
-    discards provider errors and can proceed after failed mutual authentication.
+    (This report has been withdrawn with reason: "Report mistakenly added without
+    having CVE / GHSA associated"). github.com/lib/pq does not require a GSSAPI
+    exchange to reach cryptographic completion before accepting AuthenticationOk and
+    ReadyForQuery. After an unauthenticated peer requests GSS authentication, the
+    driver sends its initial GSS token and stores the provider, but it tracks
+    neither whether a continuation occurred nor the provider's done result. The
+    startup loop then accepts AuthenticationOk and completes the connection. The
+    continuation branch also discards provider errors and can proceed after failed
+    mutual authentication.
 withdrawn: "2026-08-18T20:22:36Z"
 cves:
     - CVE-2026-56868
diff --git a/data/reports/GO-2026-6168.yaml b/data/reports/GO-2026-6168.yaml
index 72a0157..0a9f5b6 100644
--- a/data/reports/GO-2026-6168.yaml
+++ b/data/reports/GO-2026-6168.yaml
@@ -13,13 +13,13 @@
     WITHDRAWN: Unbounded iteration count causes CPU denial of service in
     github.com/lib/pq/scram
 description: |-
-    (This report has been withdrawn with reason: "False positive"). The SCRAM client
-    in github.com/lib/pq/scram accepts an attacker-controlled iteration count with
-    no upper bound and immediately performs that many PBKDF2-style HMAC rounds. A
-    PostgreSQL endpoint or active network attacker can send a valid SCRAM
-    server-first message with a large iteration count (such as i=2147483647),
-    causing client authentication to consume excessive CPU resources before
-    verifying the server signature.
+    (This report has been withdrawn with reason: "Report mistakenly added without
+    having CVE / GHSA associated"). The SCRAM client in github.com/lib/pq/scram
+    accepts an attacker-controlled iteration count with no upper bound and
+    immediately performs that many PBKDF2-style HMAC rounds. A PostgreSQL endpoint
+    or active network attacker can send a valid SCRAM server-first message with a
+    large iteration count (such as i=2147483647), causing client authentication to
+    consume excessive CPU resources before verifying the server signature.
 withdrawn: "2026-08-18T20:22:41Z"
 cves:
     - CVE-2026-56869
diff --git a/data/reports/GO-2026-6169.yaml b/data/reports/GO-2026-6169.yaml
index 5899d4c..1bf7cd5 100644
--- a/data/reports/GO-2026-6169.yaml
+++ b/data/reports/GO-2026-6169.yaml
@@ -19,13 +19,13 @@
     WITHDRAWN: Disclosure of wrong .pgpass credential via hostaddr in
     github.com/lib/pq
 description: |-
-    (This report has been withdrawn with reason: "False positive"). When a
-    connection specifies hostaddr without host, github.com/lib/pq dials the numeric
-    hostaddr but performs .pgpass lookup using the default Config.Host value,
-    localhost. If the passfile contains different credentials for localhost and the
-    remote address, the driver selects the secret intended for the local database
-    and sends it to the remote endpoint when that endpoint requests password
-    authentication.
+    (This report has been withdrawn with reason: "Report mistakenly added without
+    having CVE / GHSA associated"). When a connection specifies hostaddr without
+    host, github.com/lib/pq dials the numeric hostaddr but performs .pgpass lookup
+    using the default Config.Host value, localhost. If the passfile contains
+    different credentials for localhost and the remote address, the driver selects
+    the secret intended for the local database and sends it to the remote endpoint
+    when that endpoint requests password authentication.
 withdrawn: "2026-08-18T20:22:44Z"
 cves:
     - CVE-2026-56870
diff --git a/data/reports/GO-2026-6170.yaml b/data/reports/GO-2026-6170.yaml
index fd8bb4e..2b96b30 100644
--- a/data/reports/GO-2026-6170.yaml
+++ b/data/reports/GO-2026-6170.yaml
@@ -36,13 +36,13 @@
             - stmt.QueryContext
 summary: 'WITHDRAWN: Malformed backend frame length causes panic in github.com/lib/pq'
 description: |-
-    (This report has been withdrawn with reason: "False positive").
-    github.com/lib/pq trusts the unsigned 32-bit length in every PostgreSQL backend
-    frame and subtracts four without first checking that the wire length is at least
-    four. A backend frame whose length is zero through three produces a negative
-    payload length. recvMessage then slices the connection scratch buffer with that
-    negative bound, causing an unrecovered runtime panic that terminates the calling
-    goroutine and process.
+    (This report has been withdrawn with reason: "Report mistakenly added without
+    having CVE / GHSA associated"). github.com/lib/pq trusts the unsigned 32-bit
+    length in every PostgreSQL backend frame and subtracts four without first
+    checking that the wire length is at least four. A backend frame whose length is
+    zero through three produces a negative payload length. recvMessage then slices
+    the connection scratch buffer with that negative bound, causing an unrecovered
+    runtime panic that terminates the calling goroutine and process.
 withdrawn: "2026-08-18T20:22:49Z"
 cves:
     - CVE-2026-56871
diff --git a/data/reports/GO-2026-6171.yaml b/data/reports/GO-2026-6171.yaml
index a1fe0ef..ce6ee8d 100644
--- a/data/reports/GO-2026-6171.yaml
+++ b/data/reports/GO-2026-6171.yaml
@@ -22,12 +22,13 @@
     WITHDRAWN: Malformed RowDescription and DataRow messages cause panics in
     github.com/lib/pq
 description: |-
-    (This report has been withdrawn with reason: "False positive").
-    github.com/lib/pq decodes attacker-controlled RowDescription and DataRow
-    payloads without validating their structural relationship or encoded value
-    widths required by binary decoders. A malicious PostgreSQL endpoint or active
-    network attacker on an unauthenticated transport can send malformed row
-    responses, causing unrecovered runtime panics while reading query results.
+    (This report has been withdrawn with reason: "Report mistakenly added without
+    having CVE / GHSA associated"). github.com/lib/pq decodes attacker-controlled
+    RowDescription and DataRow payloads without validating their structural
+    relationship or encoded value widths required by binary decoders. A malicious
+    PostgreSQL endpoint or active network attacker on an unauthenticated transport
+    can send malformed row responses, causing unrecovered runtime panics while
+    reading query results.
 withdrawn: "2026-08-18T20:22:53Z"
 cves:
     - CVE-2026-56872
diff --git a/data/reports/GO-2026-6172.yaml b/data/reports/GO-2026-6172.yaml
index 731719b..c173bb8 100644
--- a/data/reports/GO-2026-6172.yaml
+++ b/data/reports/GO-2026-6172.yaml
@@ -39,13 +39,13 @@
     WITHDRAWN: Backend frame lengths cause pre-validation memory exhaustion in
     github.com/lib/pq
 description: |-
-    (This report has been withdrawn with reason: "False positive").
-    github.com/lib/pq allocates the backend-declared PostgreSQL frame payload before
-    applying a protocol length bound or a phase-specific message-type check. A
-    malicious server or active network attacker on an unauthenticated connection can
-    send frame headers declaring multi-gigabyte or invalid-phase payloads, forcing
-    large allocations that lead to memory exhaustion and runtime out-of-memory
-    crashes.
+    (This report has been withdrawn with reason: "Report mistakenly added without
+    having CVE / GHSA associated"). github.com/lib/pq allocates the backend-declared
+    PostgreSQL frame payload before applying a protocol length bound or a
+    phase-specific message-type check. A malicious server or active network attacker
+    on an unauthenticated connection can send frame headers declaring multi-gigabyte
+    or invalid-phase payloads, forcing large allocations that lead to memory
+    exhaustion and runtime out-of-memory crashes.
 withdrawn: "2026-08-18T20:22:58Z"
 cves:
     - CVE-2026-56873
diff --git a/data/reports/GO-2026-6173.yaml b/data/reports/GO-2026-6173.yaml
index 29b36a8..5132bbd 100644
--- a/data/reports/GO-2026-6173.yaml
+++ b/data/reports/GO-2026-6173.yaml
@@ -38,8 +38,9 @@
     WITHDRAWN: Pre-protocol error reader permits unbounded memory consumption in
     github.com/lib/pq
 description: |-
-    (This report has been withdrawn with reason: "False positive"). The special-case
-    parser for PostgreSQL pre-protocol plain-text errors in github.com/lib/pq calls
+    (This report has been withdrawn with reason: "Report mistakenly added without
+    having CVE / GHSA associated"). The special-case parser for PostgreSQL
+    pre-protocol plain-text errors in github.com/lib/pq calls
     bufio.Reader.ReadString(0) without a byte limit. A malicious PostgreSQL endpoint
     or active network attacker on an unauthenticated transport can send an error
     message response with non-NUL bytes continuously, causing the client to buffer