data/reports: add 40 reports - data/reports/GO-2026-6480.yaml - data/reports/GO-2026-6481.yaml - data/reports/GO-2026-6482.yaml - data/reports/GO-2026-6483.yaml - data/reports/GO-2026-6484.yaml - data/reports/GO-2026-6485.yaml - data/reports/GO-2026-6486.yaml - data/reports/GO-2026-6487.yaml - data/reports/GO-2026-6488.yaml - data/reports/GO-2026-6490.yaml - data/reports/GO-2026-6495.yaml - data/reports/GO-2026-6506.yaml - data/reports/GO-2026-6507.yaml - data/reports/GO-2026-6508.yaml - data/reports/GO-2026-6514.yaml - data/reports/GO-2026-6515.yaml - data/reports/GO-2026-6516.yaml - data/reports/GO-2026-6517.yaml - data/reports/GO-2026-6518.yaml - data/reports/GO-2026-6519.yaml - data/reports/GO-2026-6520.yaml - data/reports/GO-2026-6521.yaml - data/reports/GO-2026-6522.yaml - data/reports/GO-2026-6523.yaml - data/reports/GO-2026-6525.yaml - data/reports/GO-2026-6526.yaml - data/reports/GO-2026-6527.yaml - data/reports/GO-2026-6528.yaml - data/reports/GO-2026-6529.yaml - data/reports/GO-2026-6530.yaml - data/reports/GO-2026-6535.yaml - data/reports/GO-2026-6537.yaml - data/reports/GO-2026-6538.yaml - data/reports/GO-2026-6539.yaml - data/reports/GO-2026-6540.yaml - data/reports/GO-2026-6541.yaml - data/reports/GO-2026-6542.yaml - data/reports/GO-2026-6543.yaml - data/reports/GO-2026-6544.yaml - data/reports/GO-2026-6545.yaml Fixes golang/vulndb#6480 Fixes golang/vulndb#6481 Fixes golang/vulndb#6482 Fixes golang/vulndb#6483 Fixes golang/vulndb#6484 Fixes golang/vulndb#6485 Fixes golang/vulndb#6486 Fixes golang/vulndb#6487 Fixes golang/vulndb#6488 Fixes golang/vulndb#6490 Fixes golang/vulndb#6495 Fixes golang/vulndb#6506 Fixes golang/vulndb#6507 Fixes golang/vulndb#6508 Fixes golang/vulndb#6514 Fixes golang/vulndb#6515 Fixes golang/vulndb#6516 Fixes golang/vulndb#6517 Fixes golang/vulndb#6518 Fixes golang/vulndb#6519 Fixes golang/vulndb#6520 Fixes golang/vulndb#6521 Fixes golang/vulndb#6522 Fixes golang/vulndb#6523 Fixes golang/vulndb#6525 Fixes golang/vulndb#6526 Fixes golang/vulndb#6527 Fixes golang/vulndb#6528 Fixes golang/vulndb#6529 Fixes golang/vulndb#6530 Fixes golang/vulndb#6535 Fixes golang/vulndb#6537 Fixes golang/vulndb#6538 Fixes golang/vulndb#6539 Fixes golang/vulndb#6540 Fixes golang/vulndb#6541 Fixes golang/vulndb#6542 Fixes golang/vulndb#6543 Fixes golang/vulndb#6544 Fixes golang/vulndb#6545 Change-Id: I5f379000ad20332286b7b886b59740a95f514fc2 Reviewed-on: https://go-review.googlesource.com/c/vulndb/+/836785 Reviewed-by: Neal Patel <nealpatel@google.com> Auto-Submit: Ian Alexander <jitsu@google.com> LUCI-TryBot-Result: golang-scoped@luci-project-accounts.iam.gserviceaccount.com <golang-scoped@luci-project-accounts.iam.gserviceaccount.com>
diff --git a/data/osv/GO-2026-6480.json b/data/osv/GO-2026-6480.json new file mode 100644 index 0000000..2299a5c --- /dev/null +++ b/data/osv/GO-2026-6480.json
@@ -0,0 +1,70 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6480", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-5139", + "GHSA-2g8v-grq3-hq2g" + ], + "summary": "Mattermost doesn't enforce administrator authorization on the {{setDefaultInstance}} call within the {{/gitlab connect}} command handler in github.com/mattermost/mattermost-server", + "details": "Mattermost doesn't enforce administrator authorization on the {{setDefaultInstance}} call within the {{/gitlab connect}} command handler in github.com/mattermost/mattermost-server", + "affected": [ + { + "package": { + "name": "github.com/mattermost/mattermost-server", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "10.11.0+incompatible" + }, + { + "fixed": "10.11.18+incompatible" + }, + { + "introduced": "11.5.0+incompatible" + }, + { + "fixed": "11.5.6+incompatible" + }, + { + "introduced": "11.6.0+incompatible" + }, + { + "fixed": "11.6.3+incompatible" + }, + { + "introduced": "11.7.0+incompatible" + }, + { + "fixed": "11.7.1+incompatible" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-2g8v-grq3-hq2g" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-5139" + }, + { + "type": "WEB", + "url": "https://mattermost.com/security-updates" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6480", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6481.json b/data/osv/GO-2026-6481.json new file mode 100644 index 0000000..58e5652 --- /dev/null +++ b/data/osv/GO-2026-6481.json
@@ -0,0 +1,58 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6481", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-8074", + "GHSA-g5vr-6pgg-74qv" + ], + "summary": "Mattermost doesn't enforce bot-specific permission checks on the user active status endpoint in github.com/mattermost/mattermost-server", + "details": "Mattermost doesn't enforce bot-specific permission checks on the user active status endpoint in github.com/mattermost/mattermost-server", + "affected": [ + { + "package": { + "name": "github.com/mattermost/mattermost-server", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "10.11.0+incompatible" + }, + { + "fixed": "10.11.18+incompatible" + }, + { + "introduced": "11.7.0+incompatible" + }, + { + "fixed": "11.7.1+incompatible" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-g5vr-6pgg-74qv" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-8074" + }, + { + "type": "WEB", + "url": "https://mattermost.com/security-updates" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6481", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6482.json b/data/osv/GO-2026-6482.json new file mode 100644 index 0000000..cb63c2a --- /dev/null +++ b/data/osv/GO-2026-6482.json
@@ -0,0 +1,70 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6482", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-9162", + "GHSA-h998-hxxj-8q83" + ], + "summary": "Mattermost doesn't invalidate cached authentication state for active WebSocket connections during global session revocation in github.com/mattermost/mattermost-server", + "details": "Mattermost doesn't invalidate cached authentication state for active WebSocket connections during global session revocation in github.com/mattermost/mattermost-server", + "affected": [ + { + "package": { + "name": "github.com/mattermost/mattermost-server", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "10.11.0+incompatible" + }, + { + "fixed": "10.11.18+incompatible" + }, + { + "introduced": "11.5.0+incompatible" + }, + { + "fixed": "11.5.6+incompatible" + }, + { + "introduced": "11.6.0+incompatible" + }, + { + "fixed": "11.6.3+incompatible" + }, + { + "introduced": "11.7.0+incompatible" + }, + { + "fixed": "11.7.1+incompatible" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-h998-hxxj-8q83" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-9162" + }, + { + "type": "WEB", + "url": "https://mattermost.com/security-updates" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6482", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6483.json b/data/osv/GO-2026-6483.json new file mode 100644 index 0000000..13a9178 --- /dev/null +++ b/data/osv/GO-2026-6483.json
@@ -0,0 +1,70 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6483", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-6673", + "GHSA-jqgv-39mg-7c2r" + ], + "summary": "Mattermost doesn't authenticate Atlassian Connect installed callbacks, allowing a remote unauthenticated attacker to inject a rogue sharedSecret in github.com/mattermost/mattermost-server", + "details": "Mattermost doesn't authenticate Atlassian Connect installed callbacks, allowing a remote unauthenticated attacker to inject a rogue sharedSecret in github.com/mattermost/mattermost-server", + "affected": [ + { + "package": { + "name": "github.com/mattermost/mattermost-server", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "10.11.0+incompatible" + }, + { + "fixed": "10.11.18+incompatible" + }, + { + "introduced": "11.5.0+incompatible" + }, + { + "fixed": "11.5.6+incompatible" + }, + { + "introduced": "11.6.0+incompatible" + }, + { + "fixed": "11.6.3+incompatible" + }, + { + "introduced": "11.7.0+incompatible" + }, + { + "fixed": "11.7.1+incompatible" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-jqgv-39mg-7c2r" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6673" + }, + { + "type": "WEB", + "url": "https://mattermost.com/security-updates" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6483", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6484.json b/data/osv/GO-2026-6484.json new file mode 100644 index 0000000..003f53e --- /dev/null +++ b/data/osv/GO-2026-6484.json
@@ -0,0 +1,70 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6484", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-6062", + "GHSA-mxq2-5jpg-7474" + ], + "summary": "Mattermost doesn't validate channel ownership of an existing subscription before applying edits in github.com/mattermost/mattermost-server", + "details": "Mattermost doesn't validate channel ownership of an existing subscription before applying edits in github.com/mattermost/mattermost-server", + "affected": [ + { + "package": { + "name": "github.com/mattermost/mattermost-server", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "10.11.0+incompatible" + }, + { + "fixed": "10.11.18+incompatible" + }, + { + "introduced": "11.5.0+incompatible" + }, + { + "fixed": "11.5.6+incompatible" + }, + { + "introduced": "11.6.0+incompatible" + }, + { + "fixed": "11.6.3+incompatible" + }, + { + "introduced": "11.7.0+incompatible" + }, + { + "fixed": "11.7.1+incompatible" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-mxq2-5jpg-7474" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6062" + }, + { + "type": "WEB", + "url": "https://mattermost.com/security-updates" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6484", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6485.json b/data/osv/GO-2026-6485.json new file mode 100644 index 0000000..2536846 --- /dev/null +++ b/data/osv/GO-2026-6485.json
@@ -0,0 +1,48 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6485", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-32599", + "GHSA-r8cr-4f9w-7r75" + ], + "summary": "Netmaker has a boolean‑based SQL Injection in github.com/gravitl/netmaker", + "details": "Netmaker has a boolean‑based SQL Injection in github.com/gravitl/netmaker", + "affected": [ + { + "package": { + "name": "github.com/gravitl/netmaker", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.5.0" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/gravitl/netmaker/security/advisories/GHSA-r8cr-4f9w-7r75" + }, + { + "type": "WEB", + "url": "https://github.com/gravitl/netmaker/releases/tag/v1.5.0" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6485", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6486.json b/data/osv/GO-2026-6486.json new file mode 100644 index 0000000..b0cf6dd --- /dev/null +++ b/data/osv/GO-2026-6486.json
@@ -0,0 +1,44 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6486", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "GHSA-rf68-8gjr-36q7" + ], + "summary": "Nezha: OAuth2 redirect_uri Host header injection regression when dashboard_host is empty in github.com/nezhahq/nezha", + "details": "Nezha: OAuth2 redirect_uri Host header injection regression when dashboard_host is empty in github.com/nezhahq/nezha", + "affected": [ + { + "package": { + "name": "github.com/nezhahq/nezha", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/nezhahq/nezha/security/advisories/GHSA-rf68-8gjr-36q7" + }, + { + "type": "FIX", + "url": "https://github.com/nezhahq/nezha/commit/38824dbc11a63964c5b9296ae4c68e62b34fa04b" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6486", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6487.json b/data/osv/GO-2026-6487.json new file mode 100644 index 0000000..ad63f1e --- /dev/null +++ b/data/osv/GO-2026-6487.json
@@ -0,0 +1,48 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6487", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-61554", + "GHSA-4595-rvpx-4q34" + ], + "summary": "emp3r0r has an unauthenticated HTTP Polling DoS in github.com/jm33-m0/emp3r0r/core", + "details": "emp3r0r has an unauthenticated HTTP Polling DoS in github.com/jm33-m0/emp3r0r/core", + "affected": [ + { + "package": { + "name": "github.com/jm33-m0/emp3r0r/core", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.0.0-20260531142011-aed3d81641ab" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/jm33-m0/emp3r0r/security/advisories/GHSA-4595-rvpx-4q34" + }, + { + "type": "WEB", + "url": "https://github.com/jm33-m0/emp3r0r/releases/tag/v4.2.5" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6487", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6488.json b/data/osv/GO-2026-6488.json new file mode 100644 index 0000000..ed83c4c --- /dev/null +++ b/data/osv/GO-2026-6488.json
@@ -0,0 +1,56 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6488", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-61709", + "GHSA-g3pg-frfm-pr2m" + ], + "summary": "OpenFGA: ListUsers returns a deliberately-excluded user when a `but not` exclusion under a type-bound wildcard is intersected (`and`) with another relation that also grants that user in github.com/openfga/openfga", + "details": "OpenFGA: ListUsers returns a deliberately-excluded user when a `but not` exclusion under a type-bound wildcard is intersected (`and`) with another relation that also grants that user in github.com/openfga/openfga", + "affected": [ + { + "package": { + "name": "github.com/openfga/openfga", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.18.1" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/openfga/openfga/security/advisories/GHSA-g3pg-frfm-pr2m" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-61709" + }, + { + "type": "FIX", + "url": "https://github.com/openfga/openfga/commit/171806c93b86bca29e0212ceb8b6ee9c48eb9ac3" + }, + { + "type": "WEB", + "url": "https://github.com/openfga/openfga/releases/tag/v1.18.1" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6488", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6490.json b/data/osv/GO-2026-6490.json new file mode 100644 index 0000000..c88a28d --- /dev/null +++ b/data/osv/GO-2026-6490.json
@@ -0,0 +1,128 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6490", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-71485", + "GHSA-9468-v6mj-fppw" + ], + "summary": "Centrifugo: Client-forgeable headers emulation lets any client spoof headers forwarded to proxy backends in github.com/centrifugal/centrifugo", + "details": "Centrifugo: Client-forgeable headers emulation lets any client spoof headers forwarded to proxy backends in github.com/centrifugal/centrifugo", + "affected": [ + { + "package": { + "name": "github.com/centrifugal/centrifugo", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": {} + }, + { + "package": { + "name": "github.com/centrifugal/centrifugo/v3", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": {} + }, + { + "package": { + "name": "github.com/centrifugal/centrifugo/v4", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": {} + }, + { + "package": { + "name": "github.com/centrifugal/centrifugo/v5", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": {} + }, + { + "package": { + "name": "github.com/centrifugal/centrifugo/v6", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "6.9.0" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/centrifugal/centrifugo/security/advisories/GHSA-9468-v6mj-fppw" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-71485" + }, + { + "type": "FIX", + "url": "https://github.com/centrifugal/centrifugo/commit/84d38cea1dd2efa24375a148817a974c8727f4b0" + }, + { + "type": "FIX", + "url": "https://github.com/centrifugal/centrifugo/pull/1182" + }, + { + "type": "WEB", + "url": "https://github.com/centrifugal/centrifugo/releases/tag/v6.9.0" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6490", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6495.json b/data/osv/GO-2026-6495.json new file mode 100644 index 0000000..7fba8e3 --- /dev/null +++ b/data/osv/GO-2026-6495.json
@@ -0,0 +1,64 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6495", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-86043", + "GHSA-5gpm-rgj3-9q76" + ], + "summary": "Skipper has OPA body-authz bypass: truncated_body mitigation fails open on chunked/HTTP-2 (incomplete fix GHSA-8qqm-fp2q-v734) in github.com/zalando/skipper", + "details": "Skipper has OPA body-authz bypass: truncated_body mitigation fails open on chunked/HTTP-2 (incomplete fix GHSA-8qqm-fp2q-v734) in github.com/zalando/skipper", + "affected": [ + { + "package": { + "name": "github.com/zalando/skipper", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.27.37" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/zalando/skipper/security/advisories/GHSA-5gpm-rgj3-9q76" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86043" + }, + { + "type": "FIX", + "url": "https://github.com/zalando/skipper/commit/2cfceabaa6ff0af65b312dcb9bcbe84691b9d507" + }, + { + "type": "WEB", + "url": "https://github.com/zalando/skipper/releases/tag/v0.27.35" + }, + { + "type": "WEB", + "url": "https://github.com/zalando/skipper/releases/tag/v0.27.37" + }, + { + "type": "WEB", + "url": "https://github.com/zalando/skipper/tree/v0.27.35" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6495", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6506.json b/data/osv/GO-2026-6506.json new file mode 100644 index 0000000..7f320bc --- /dev/null +++ b/data/osv/GO-2026-6506.json
@@ -0,0 +1,56 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6506", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-86003", + "GHSA-9gm5-9rfh-m6vx" + ], + "summary": "CoreDNS DoH/DoQ/gRPC bypass UPDATE rejection enforced on UDP/TCP in github.com/coredns/coredns", + "details": "CoreDNS DoH/DoQ/gRPC bypass UPDATE rejection enforced on UDP/TCP in github.com/coredns/coredns", + "affected": [ + { + "package": { + "name": "github.com/coredns/coredns", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.14.7" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/coredns/coredns/security/advisories/GHSA-9gm5-9rfh-m6vx" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86003" + }, + { + "type": "FIX", + "url": "https://github.com/coredns/coredns/commit/530b0a5ff2ad68cc0421f10dd93568945cc671c9" + }, + { + "type": "WEB", + "url": "https://github.com/coredns/coredns/releases/tag/v1.14.7" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6506", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6507.json b/data/osv/GO-2026-6507.json new file mode 100644 index 0000000..4502b03 --- /dev/null +++ b/data/osv/GO-2026-6507.json
@@ -0,0 +1,56 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6507", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-82399", + "GHSA-mrg3-qvqr-jw29" + ], + "summary": "CoreDNS: Unauthenticated memory exhaustion in custom transports in github.com/coredns/coredns", + "details": "CoreDNS: Unauthenticated memory exhaustion in custom transports in github.com/coredns/coredns", + "affected": [ + { + "package": { + "name": "github.com/coredns/coredns", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.14.7" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/coredns/coredns/security/advisories/GHSA-mrg3-qvqr-jw29" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-82399" + }, + { + "type": "FIX", + "url": "https://github.com/coredns/coredns/commit/530b0a5ff2ad68cc0421f10dd93568945cc671c9" + }, + { + "type": "WEB", + "url": "https://github.com/coredns/coredns/releases/tag/v1.14.7" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6507", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6508.json b/data/osv/GO-2026-6508.json new file mode 100644 index 0000000..d00bf26 --- /dev/null +++ b/data/osv/GO-2026-6508.json
@@ -0,0 +1,56 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6508", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-81871", + "GHSA-w34q-cm8f-9c5x" + ], + "summary": "OpenTelemetry-Go: Log gRPC exporter ignores env TLS certs, bypassing mTLS/pinning in go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc", + "details": "OpenTelemetry-Go: Log gRPC exporter ignores env TLS certs, bypassing mTLS/pinning in go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc", + "affected": [ + { + "package": { + "name": "go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.21.0" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/open-telemetry/opentelemetry-go/security/advisories/GHSA-w34q-cm8f-9c5x" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-81871" + }, + { + "type": "WEB", + "url": "https://github.com/open-telemetry/opentelemetry-go/commit/c65d435b43e5e6b82310e6b18dd4cdcb8ac63a0c" + }, + { + "type": "WEB", + "url": "https://github.com/open-telemetry/opentelemetry-go/releases/tag/exporters/otlp/otlplog/otlploggrpc/v0.21.0" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6508", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6514.json b/data/osv/GO-2026-6514.json new file mode 100644 index 0000000..f569580 --- /dev/null +++ b/data/osv/GO-2026-6514.json
@@ -0,0 +1,52 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6514", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-63199", + "GHSA-4227-9989-jrhx" + ], + "summary": "Perses's missing authorization in datasource proxy allows cross-scope secret disclosure in github.com/perses/perses", + "details": "Perses's missing authorization in datasource proxy allows cross-scope secret disclosure in github.com/perses/perses", + "affected": [ + { + "package": { + "name": "github.com/perses/perses", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0.43.0" + }, + { + "fixed": "0.54.0-rc.0" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/perses/perses/security/advisories/GHSA-4227-9989-jrhx" + }, + { + "type": "FIX", + "url": "https://github.com/perses/perses/commit/2368c9ef4eb0a70fbca5df69aa20e595821ab625" + }, + { + "type": "WEB", + "url": "https://github.com/perses/perses/releases/tag/v0.54.0-rc.0" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6514", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6515.json b/data/osv/GO-2026-6515.json new file mode 100644 index 0000000..60ac406 --- /dev/null +++ b/data/osv/GO-2026-6515.json
@@ -0,0 +1,52 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6515", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-77339", + "GHSA-5gm3-9crp-6g3v" + ], + "summary": "Process Compose: Browser DNS rebinding lets websites control local process-compose MCP tools in github.com/f1bonacc1/process-compose", + "details": "Process Compose: Browser DNS rebinding lets websites control local process-compose MCP tools in github.com/f1bonacc1/process-compose", + "affected": [ + { + "package": { + "name": "github.com/f1bonacc1/process-compose", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.120.0" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/F1bonacc1/process-compose/security/advisories/GHSA-5gm3-9crp-6g3v" + }, + { + "type": "WEB", + "url": "https://github.com/F1bonacc1/process-compose/commit/6ffa74f462cd2fa4f8dc1ee63c70b793b298c858" + }, + { + "type": "WEB", + "url": "https://github.com/F1bonacc1/process-compose/releases/tag/v1.120.0" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6515", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6516.json b/data/osv/GO-2026-6516.json new file mode 100644 index 0000000..5c79534 --- /dev/null +++ b/data/osv/GO-2026-6516.json
@@ -0,0 +1,63 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6516", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-63405", + "GHSA-5p54-whvp-x327" + ], + "summary": "AnyCable: Pusher REST API Does Not Verify Request Body MD5 Enabling Signed-Request Replay with Arbitrary Body in github.com/anycable/anycable-go", + "details": "AnyCable: Pusher REST API Does Not Verify Request Body MD5 Enabling Signed-Request Replay with Arbitrary Body in github.com/anycable/anycable-go.\n\nNOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.\n\n(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)\n\nThe additional affected modules and versions are: github.com/anycable/anycable-go before v1.6.15.", + "affected": [ + { + "package": { + "name": "github.com/anycable/anycable-go", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "custom_ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.6.15" + } + ] + } + ] + } + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/anycable/anycable/security/advisories/GHSA-5p54-whvp-x327" + }, + { + "type": "WEB", + "url": "https://github.com/anycable/anycable/commit/d2cbadec792f038f4695c84a65c0d957b0fde72c" + }, + { + "type": "WEB", + "url": "https://github.com/anycable/anycable/releases/tag/v1.6.15" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6516", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6517.json b/data/osv/GO-2026-6517.json new file mode 100644 index 0000000..ef2f57a --- /dev/null +++ b/data/osv/GO-2026-6517.json
@@ -0,0 +1,62 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6517", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-61682", + "GHSA-c8w2-fgvx-vhv4" + ], + "summary": "kcp front-proxy does not strip inbound X-Remote-* identity headers, allowing any authenticated client to inject groups/warrants and impersonate system:masters in any workspace in github.com/kcp-dev/kcp", + "details": "kcp front-proxy does not strip inbound X-Remote-* identity headers, allowing any authenticated client to inject groups/warrants and impersonate system:masters in any workspace in github.com/kcp-dev/kcp", + "affected": [ + { + "package": { + "name": "github.com/kcp-dev/kcp", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.31.4" + }, + { + "introduced": "0.32.0" + }, + { + "fixed": "0.32.2" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/kcp-dev/kcp/security/advisories/GHSA-c8w2-fgvx-vhv4" + }, + { + "type": "FIX", + "url": "https://github.com/kcp-dev/kcp/commit/7437cdcfec8f927d1a9bf1b2dd1e075d038e27ca" + }, + { + "type": "WEB", + "url": "https://github.com/kcp-dev/kcp/releases/tag/v0.31.4" + }, + { + "type": "WEB", + "url": "https://github.com/kcp-dev/kcp/releases/tag/v0.32.2" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6517", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6518.json b/data/osv/GO-2026-6518.json new file mode 100644 index 0000000..dd1bbb5 --- /dev/null +++ b/data/osv/GO-2026-6518.json
@@ -0,0 +1,52 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6518", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-63458", + "GHSA-cjgj-2fwf-4c2w" + ], + "summary": "Perses's project query parameter authorization bypass exposes cross-project resources in github.com/perses/perses", + "details": "Perses's project query parameter authorization bypass exposes cross-project resources in github.com/perses/perses", + "affected": [ + { + "package": { + "name": "github.com/perses/perses", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.54.0-beta.3" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/perses/perses/security/advisories/GHSA-cjgj-2fwf-4c2w" + }, + { + "type": "FIX", + "url": "https://github.com/perses/perses/commit/8015fb340bdc625953e73a7a688be5b939159540" + }, + { + "type": "WEB", + "url": "https://github.com/perses/perses/releases/tag/v0.54.0-beta.3" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6518", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6519.json b/data/osv/GO-2026-6519.json new file mode 100644 index 0000000..c58dac3 --- /dev/null +++ b/data/osv/GO-2026-6519.json
@@ -0,0 +1,56 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6519", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-61795", + "GHSA-f94q-w3w8-cj67" + ], + "summary": "Capsule: hostnameRegexHandler.OnUpdate validates stale (old) Tenant regex, allowing invalid AllowedHostnames regex to bypass webhook validation in github.com/projectcapsule/capsule", + "details": "Capsule: hostnameRegexHandler.OnUpdate validates stale (old) Tenant regex, allowing invalid AllowedHostnames regex to bypass webhook validation in github.com/projectcapsule/capsule", + "affected": [ + { + "package": { + "name": "github.com/projectcapsule/capsule", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0.13.0" + }, + { + "fixed": "0.13.7" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/projectcapsule/capsule/security/advisories/GHSA-f94q-w3w8-cj67" + }, + { + "type": "FIX", + "url": "https://github.com/projectcapsule/capsule/commit/8d89d6865df6f41c7faa22fc9e807a57b01bfd0e" + }, + { + "type": "FIX", + "url": "https://github.com/projectcapsule/capsule/pull/1983" + }, + { + "type": "WEB", + "url": "https://github.com/projectcapsule/capsule/releases/tag/v0.13.7" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6519", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6520.json b/data/osv/GO-2026-6520.json new file mode 100644 index 0000000..58f6ca1 --- /dev/null +++ b/data/osv/GO-2026-6520.json
@@ -0,0 +1,56 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6520", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-61672", + "GHSA-gjw4-3v3v-rqxg" + ], + "summary": "Capsule: Tenant owner bypasses Capsule's forbidden namespace/service/node label and annotation enforcement in github.com/projectcapsule/capsule", + "details": "Capsule: Tenant owner bypasses Capsule's forbidden namespace/service/node label and annotation enforcement in github.com/projectcapsule/capsule", + "affected": [ + { + "package": { + "name": "github.com/projectcapsule/capsule", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.13.7" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/projectcapsule/capsule/security/advisories/GHSA-gjw4-3v3v-rqxg" + }, + { + "type": "FIX", + "url": "https://github.com/projectcapsule/capsule/commit/755cef54bf4a1bc56d6692130132bc70755bef46" + }, + { + "type": "FIX", + "url": "https://github.com/projectcapsule/capsule/pull/1982" + }, + { + "type": "WEB", + "url": "https://github.com/projectcapsule/capsule/releases/tag/v0.13.7" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6520", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6521.json b/data/osv/GO-2026-6521.json new file mode 100644 index 0000000..96651ad --- /dev/null +++ b/data/osv/GO-2026-6521.json
@@ -0,0 +1,56 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6521", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-61794", + "GHSA-gxjc-74v5-3vx3" + ], + "summary": "Capsule: Malformed ForbiddenAnnotations.Regex can bypass Tenant validation and trigger namespace admission panic in github.com/projectcapsule/capsule", + "details": "Capsule: Malformed ForbiddenAnnotations.Regex can bypass Tenant validation and trigger namespace admission panic in github.com/projectcapsule/capsule", + "affected": [ + { + "package": { + "name": "github.com/projectcapsule/capsule", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0.13.0" + }, + { + "fixed": "0.13.7" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/projectcapsule/capsule/security/advisories/GHSA-gxjc-74v5-3vx3" + }, + { + "type": "FIX", + "url": "https://github.com/projectcapsule/capsule/commit/8d89d6865df6f41c7faa22fc9e807a57b01bfd0e" + }, + { + "type": "FIX", + "url": "https://github.com/projectcapsule/capsule/pull/1983" + }, + { + "type": "WEB", + "url": "https://github.com/projectcapsule/capsule/releases/tag/v0.13.7" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6521", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6522.json b/data/osv/GO-2026-6522.json new file mode 100644 index 0000000..919f6a4 --- /dev/null +++ b/data/osv/GO-2026-6522.json
@@ -0,0 +1,47 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6522", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "GHSA-jgh3-fggc-mcpm" + ], + "summary": "Obot: Server-Side Request Forgery via remote MCP server URL in github.com/obot-platform/obot", + "details": "Obot: Server-Side Request Forgery via remote MCP server URL in github.com/obot-platform/obot", + "affected": [ + { + "package": { + "name": "github.com/obot-platform/obot", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.23.0" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/obot-platform/obot/security/advisories/GHSA-jgh3-fggc-mcpm" + }, + { + "type": "WEB", + "url": "https://github.com/obot-platform/obot/releases/tag/v0.23.0" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6522", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6523.json b/data/osv/GO-2026-6523.json new file mode 100644 index 0000000..7f40168 --- /dev/null +++ b/data/osv/GO-2026-6523.json
@@ -0,0 +1,56 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6523", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-81505", + "GHSA-p5vg-v7mj-f6q4" + ], + "summary": "Convoy: Cross-Tenant Source IDOR Leaks Plaintext Message Broker Credentials in github.com/frain-dev/convoy", + "details": "Convoy: Cross-Tenant Source IDOR Leaks Plaintext Message Broker Credentials in github.com/frain-dev/convoy", + "affected": [ + { + "package": { + "name": "github.com/frain-dev/convoy", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.9.3-0.20260724092134-1cc67cd16fb1" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/frain-dev/convoy/security/advisories/GHSA-p5vg-v7mj-f6q4" + }, + { + "type": "FIX", + "url": "https://github.com/frain-dev/convoy/commit/1cc67cd16fb1f8890cc83a3998d3f92dceb7fd06" + }, + { + "type": "FIX", + "url": "https://github.com/frain-dev/convoy/pull/2755" + }, + { + "type": "WEB", + "url": "https://github.com/frain-dev/convoy/releases/tag/v26.6.8" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6523", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6525.json b/data/osv/GO-2026-6525.json new file mode 100644 index 0000000..e01f894 --- /dev/null +++ b/data/osv/GO-2026-6525.json
@@ -0,0 +1,47 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6525", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "GHSA-pr6h-vr44-xq8j" + ], + "summary": "Obot: MCP Registry API readable without authentication in github.com/obot-platform/obot", + "details": "Obot: MCP Registry API readable without authentication in github.com/obot-platform/obot", + "affected": [ + { + "package": { + "name": "github.com/obot-platform/obot", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.23.0" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/obot-platform/obot/security/advisories/GHSA-pr6h-vr44-xq8j" + }, + { + "type": "WEB", + "url": "https://github.com/obot-platform/obot/releases/tag/v0.23.0" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6525", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6526.json b/data/osv/GO-2026-6526.json new file mode 100644 index 0000000..7987584 --- /dev/null +++ b/data/osv/GO-2026-6526.json
@@ -0,0 +1,68 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6526", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-58197", + "GHSA-qg2g-g9w3-m5h8" + ], + "summary": "ToolHive: containerized MCP servers can reach host services via host.docker.internal, enabling lateral movement in github.com/stacklok/toolhive", + "details": "ToolHive: containerized MCP servers can reach host services via host.docker.internal, enabling lateral movement in github.com/stacklok/toolhive", + "affected": [ + { + "package": { + "name": "github.com/stacklok/toolhive", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.30.1" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/stacklok/toolhive/security/advisories/GHSA-qg2g-g9w3-m5h8" + }, + { + "type": "FIX", + "url": "https://github.com/stacklok/toolhive/commit/d8f40cb1599b8bf66657f2dfff15bfbfc236e712" + }, + { + "type": "FIX", + "url": "https://github.com/stacklok/toolhive/pull/5583" + }, + { + "type": "WEB", + "url": "https://github.com/stacklok/toolhive-studio/commit/968182d7f3ee1e55123369e66ad88f82128119b0" + }, + { + "type": "WEB", + "url": "https://github.com/stacklok/toolhive-studio/pull/2469" + }, + { + "type": "WEB", + "url": "https://github.com/stacklok/toolhive-studio/releases/tag/v0.38.0" + }, + { + "type": "WEB", + "url": "https://github.com/stacklok/toolhive/releases/tag/v0.30.1" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6526", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6527.json b/data/osv/GO-2026-6527.json new file mode 100644 index 0000000..4b417d3 --- /dev/null +++ b/data/osv/GO-2026-6527.json
@@ -0,0 +1,73 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6527", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-61833", + "GHSA-qg67-7m6v-qg25" + ], + "summary": "zot: Bearer authentication maps DELETE to push scope, allowing unauthorized deletion in zotregistry.dev/zot", + "details": "zot: Bearer authentication maps DELETE to push scope, allowing unauthorized deletion in zotregistry.dev/zot", + "affected": [ + { + "package": { + "name": "zotregistry.dev/zot", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": {} + }, + { + "package": { + "name": "zotregistry.dev/zot/v2", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "2.1.18" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/project-zot/zot/security/advisories/GHSA-qg67-7m6v-qg25" + }, + { + "type": "WEB", + "url": "https://github.com/project-zot/zot/commit/7bb211bcd4352b90f3e99752607fbd1f050bf7ca" + }, + { + "type": "WEB", + "url": "https://github.com/project-zot/zot/pull/4161" + }, + { + "type": "WEB", + "url": "https://github.com/project-zot/zot/releases/tag/v2.1.18" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6527", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6528.json b/data/osv/GO-2026-6528.json new file mode 100644 index 0000000..0b80ce4 --- /dev/null +++ b/data/osv/GO-2026-6528.json
@@ -0,0 +1,52 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6528", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-63445", + "GHSA-vr5f-w35q-98jp" + ], + "summary": "Perses's unvalidated project parameter enables filesystem path traversal in github.com/perses/perses", + "details": "Perses's unvalidated project parameter enables filesystem path traversal in github.com/perses/perses", + "affected": [ + { + "package": { + "name": "github.com/perses/perses", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.54.0-rc.0" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/perses/perses/security/advisories/GHSA-vr5f-w35q-98jp" + }, + { + "type": "FIX", + "url": "https://github.com/perses/perses/commit/75e5471040ccb5674ea8d25c2aa16c80ccb70b2a" + }, + { + "type": "WEB", + "url": "https://github.com/perses/perses/releases/tag/v0.54.0-rc.0" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6528", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6529.json b/data/osv/GO-2026-6529.json new file mode 100644 index 0000000..c6bdc15 --- /dev/null +++ b/data/osv/GO-2026-6529.json
@@ -0,0 +1,63 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6529", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-63406", + "GHSA-w72w-9qmj-c9qm" + ], + "summary": "AnyCable: Telemetry Subsystem Contains Hardcoded Authentication Token and Transmits CLI Arguments Including Secrets in github.com/anycable/anycable-go", + "details": "AnyCable: Telemetry Subsystem Contains Hardcoded Authentication Token and Transmits CLI Arguments Including Secrets in github.com/anycable/anycable-go.\n\nNOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.\n\n(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)\n\nThe additional affected modules and versions are: github.com/anycable/anycable-go before v1.6.15.", + "affected": [ + { + "package": { + "name": "github.com/anycable/anycable-go", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "custom_ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.6.15" + } + ] + } + ] + } + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/anycable/anycable/security/advisories/GHSA-w72w-9qmj-c9qm" + }, + { + "type": "WEB", + "url": "https://github.com/anycable/anycable/commit/201c67e99e463ed63bd6b345562f4c458385fcee" + }, + { + "type": "WEB", + "url": "https://github.com/anycable/anycable/releases/tag/v1.6.15" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6529", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6530.json b/data/osv/GO-2026-6530.json new file mode 100644 index 0000000..7dba75b --- /dev/null +++ b/data/osv/GO-2026-6530.json
@@ -0,0 +1,47 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6530", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "GHSA-xwmw-prc4-v3cr" + ], + "summary": "Obot: OAuth Dynamic Client Registration Enables API Token Theft via Audience Confusion in github.com/obot-platform/obot", + "details": "Obot: OAuth Dynamic Client Registration Enables API Token Theft via Audience Confusion in github.com/obot-platform/obot", + "affected": [ + { + "package": { + "name": "github.com/obot-platform/obot", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.23.0" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/obot-platform/obot/security/advisories/GHSA-xwmw-prc4-v3cr" + }, + { + "type": "WEB", + "url": "https://github.com/obot-platform/obot/releases/tag/v0.23.0" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6530", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6535.json b/data/osv/GO-2026-6535.json new file mode 100644 index 0000000..c3f110f --- /dev/null +++ b/data/osv/GO-2026-6535.json
@@ -0,0 +1,67 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6535", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-61687", + "GHSA-phg3-3g28-wq9v" + ], + "summary": "Hatchet - Unauthenticated OAuth state CSRF / login-CSRF via empty-state collision in ValidateOAuthState in hatchet in github.com/hatchet-dev/hatchet", + "details": "Hatchet - Unauthenticated OAuth state CSRF / login-CSRF via empty-state collision in ValidateOAuthState in hatchet in github.com/hatchet-dev/hatchet.\n\nNOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.\n\n(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)\n\nThe additional affected modules and versions are: github.com/hatchet-dev/hatchet before v0.91.1.", + "affected": [ + { + "package": { + "name": "github.com/hatchet-dev/hatchet", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "imports": [ + { + "path": "github.com/hatchet-dev/hatchet/api/v1/server/authn", + "symbols": [ + "SessionHelpers.ValidateOAuthState" + ] + } + ], + "custom_ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.91.1" + } + ] + } + ] + } + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/hatchet-dev/hatchet/security/advisories/GHSA-phg3-3g28-wq9v" + }, + { + "type": "FIX", + "url": "https://github.com/hatchet-dev/hatchet/commit/f90464189ad642251e09412d0f99fde353036428" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6535", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6537.json b/data/osv/GO-2026-6537.json new file mode 100644 index 0000000..32eba13 --- /dev/null +++ b/data/osv/GO-2026-6537.json
@@ -0,0 +1,68 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6537", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-61630", + "GHSA-hf33-q6cf-c66f" + ], + "summary": "nginx ignition has TOTP Reuse During Validity Window in github.com/lucasdillmann/nginx-ignition", + "details": "nginx ignition has TOTP Reuse During Validity Window in github.com/lucasdillmann/nginx-ignition", + "affected": [ + { + "package": { + "name": "github.com/lucasdillmann/nginx-ignition", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0.0.0-20260217145239-1cbfae0296f1" + }, + { + "fixed": "0.0.0-20260328015550-8d35e1eb5dd6" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/lucasdillmann/nginx-ignition/security/advisories/GHSA-hf33-q6cf-c66f" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-61630" + }, + { + "type": "FIX", + "url": "https://github.com/lucasdillmann/nginx-ignition/commit/1cbfae0296f1b186158f5a294ec484060e00102e" + }, + { + "type": "FIX", + "url": "https://github.com/lucasdillmann/nginx-ignition/commit/8d35e1eb5dd6a40fef94a45511fe08b0603af107" + }, + { + "type": "FIX", + "url": "https://github.com/lucasdillmann/nginx-ignition/pull/104" + }, + { + "type": "WEB", + "url": "https://github.com/lucasdillmann/nginx-ignition/releases/tag/2.35.1" + }, + { + "type": "WEB", + "url": "https://github.com/pquerna/otp/issues/61" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6537", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6538.json b/data/osv/GO-2026-6538.json new file mode 100644 index 0000000..89f7a5b --- /dev/null +++ b/data/osv/GO-2026-6538.json
@@ -0,0 +1,151 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6538", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "GHSA-jhjp-4c2q-xmx4" + ], + "summary": "k8saudit shipped rules do not detect privileged/sensitive settings on init or ephemeral containers in github.com/falcosecurity/plugins/plugins/k8saudit", + "details": "k8saudit shipped rules do not detect privileged/sensitive settings on init or ephemeral containers in github.com/falcosecurity/plugins/plugins/k8saudit", + "affected": [ + { + "package": { + "name": "github.com/falcosecurity/plugins/plugins/k8saudit", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.18.0" + } + ] + } + ], + "ecosystem_specific": {} + }, + { + "package": { + "name": "github.com/falcosecurity/plugins/plugins/k8saudit-aks", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.6.0" + } + ] + } + ], + "ecosystem_specific": {} + }, + { + "package": { + "name": "github.com/falcosecurity/plugins/plugins/k8saudit-eks", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.12.0" + } + ] + } + ], + "ecosystem_specific": {} + }, + { + "package": { + "name": "github.com/falcosecurity/plugins/plugins/k8saudit-gke", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.9.0" + } + ] + } + ], + "ecosystem_specific": {} + }, + { + "package": { + "name": "github.com/falcosecurity/plugins/plugins/k8saudit-ovh", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.6.0" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/falcosecurity/plugins/security/advisories/GHSA-jhjp-4c2q-xmx4" + }, + { + "type": "WEB", + "url": "https://github.com/falcosecurity/plugins/commit/0adb9b3c7e2c8bad53f30d01c057e038b2afa5e1" + }, + { + "type": "WEB", + "url": "https://github.com/falcosecurity/plugins/pull/1400" + }, + { + "type": "WEB", + "url": "https://github.com/falcosecurity/plugins/releases/tag/plugins/k8saudit-aks/v0.6.0" + }, + { + "type": "WEB", + "url": "https://github.com/falcosecurity/plugins/releases/tag/plugins/k8saudit-eks/v0.12.0" + }, + { + "type": "WEB", + "url": "https://github.com/falcosecurity/plugins/releases/tag/plugins/k8saudit-gke/v0.9.0" + }, + { + "type": "WEB", + "url": "https://github.com/falcosecurity/plugins/releases/tag/plugins/k8saudit-ovh/v0.6.0" + }, + { + "type": "WEB", + "url": "https://github.com/falcosecurity/plugins/releases/tag/plugins/k8saudit/v0.18.0" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6538", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6539.json b/data/osv/GO-2026-6539.json new file mode 100644 index 0000000..0197de3 --- /dev/null +++ b/data/osv/GO-2026-6539.json
@@ -0,0 +1,64 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6539", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-61629", + "GHSA-jr34-h97m-9hpx" + ], + "summary": "nginx ignition has ParseAcceptLanguage `_` separator bypass that enables ~75x CPU amplification via Accept-Language header in i18nMiddleware in github.com/lucasdillmann/nginx-ignition", + "details": "nginx ignition has ParseAcceptLanguage `_` separator bypass that enables ~75x CPU amplification via Accept-Language header in i18nMiddleware in github.com/lucasdillmann/nginx-ignition", + "affected": [ + { + "package": { + "name": "github.com/lucasdillmann/nginx-ignition", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0.0.0-20260126024607-cbaf0fc16ed8" + }, + { + "fixed": "0.0.0-20260526022344-0c988fc1277c" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/lucasdillmann/nginx-ignition/security/advisories/GHSA-jr34-h97m-9hpx" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-61629" + }, + { + "type": "FIX", + "url": "https://github.com/lucasdillmann/nginx-ignition/commit/0c988fc1277c7d291725e8373313f8486fa1b31a" + }, + { + "type": "FIX", + "url": "https://github.com/lucasdillmann/nginx-ignition/commit/cbaf0fc16ed873f7178a2ca9b0d00a696e44b485" + }, + { + "type": "FIX", + "url": "https://github.com/lucasdillmann/nginx-ignition/pull/125" + }, + { + "type": "WEB", + "url": "https://github.com/lucasdillmann/nginx-ignition/releases/tag/2.40.1" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6539", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6540.json b/data/osv/GO-2026-6540.json new file mode 100644 index 0000000..6c1d697 --- /dev/null +++ b/data/osv/GO-2026-6540.json
@@ -0,0 +1,71 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6540", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-61628", + "GHSA-pxcx-fv34-x9p5" + ], + "summary": "nginx ignition has Unauthenticated Admin Account Creation via Onboarding Race Condition in github.com/lucasdillmann/nginx-ignition", + "details": "nginx ignition has Unauthenticated Admin Account Creation via Onboarding Race Condition in github.com/lucasdillmann/nginx-ignition.\n\nNOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.\n\n(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)\n\nThe additional affected modules and versions are: github.com/lucasdillmann/nginx-ignition before v0.0.0-20260621194639-0586b4e55ab.", + "affected": [ + { + "package": { + "name": "github.com/lucasdillmann/nginx-ignition", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "custom_ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.0.0-20260621194639-0586b4e55ab" + } + ] + } + ] + } + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/lucasdillmann/nginx-ignition/security/advisories/GHSA-pxcx-fv34-x9p5" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-61628" + }, + { + "type": "FIX", + "url": "https://github.com/lucasdillmann/nginx-ignition/commit/0586b4e55ab780676d3553a2592979dfa2fb0183" + }, + { + "type": "FIX", + "url": "https://github.com/lucasdillmann/nginx-ignition/pull/131" + }, + { + "type": "WEB", + "url": "https://github.com/lucasdillmann/nginx-ignition/releases/tag/2.41.1" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6540", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6541.json b/data/osv/GO-2026-6541.json new file mode 100644 index 0000000..6db56c8 --- /dev/null +++ b/data/osv/GO-2026-6541.json
@@ -0,0 +1,220 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6541", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-42127", + "GHSA-3w66-95m3-8jxg" + ], + "summary": "Grafana: Pre-authentication denial of service in the public dashboard query handler in github.com/grafana/grafana", + "details": "Grafana: Pre-authentication denial of service in the public dashboard query handler in github.com/grafana/grafana.\n\nNOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.\n\n(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)\n\nThe additional affected modules and versions are: github.com/grafana/grafana before v1.9.2-0.20260616075434-82ef13993059.", + "affected": [ + { + "package": { + "name": "github.com/grafana/grafana", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "custom_ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.9.2-0.20260616075434-82ef13993059" + } + ] + } + ] + } + }, + { + "package": { + "name": "github.com/grafana/grafana", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "custom_ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "13.0.0" + } + ] + } + ] + } + }, + { + "package": { + "name": "github.com/grafana/grafana", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "custom_ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "12.4.0" + } + ] + } + ] + } + }, + { + "package": { + "name": "github.com/grafana/grafana", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "custom_ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "12.3.0" + } + ] + } + ] + } + }, + { + "package": { + "name": "github.com/grafana/grafana", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "custom_ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "12.0.0" + } + ] + } + ] + } + }, + { + "package": { + "name": "github.com/grafana/grafana", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "2.0.0-beta1+incompatible" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-3w66-95m3-8jxg" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42127" + }, + { + "type": "FIX", + "url": "https://github.com/grafana/grafana/commit/82ef13993059351bf21de35b8488bbd9b42df4f4" + }, + { + "type": "FIX", + "url": "https://github.com/grafana/grafana/pull/125789" + }, + { + "type": "WEB", + "url": "https://github.com/grafana/grafana/releases/tag/v11.6.15" + }, + { + "type": "WEB", + "url": "https://github.com/grafana/grafana/releases/tag/v12.2.9" + }, + { + "type": "WEB", + "url": "https://github.com/grafana/grafana/releases/tag/v12.3.7" + }, + { + "type": "WEB", + "url": "https://github.com/grafana/grafana/releases/tag/v12.4.4" + }, + { + "type": "WEB", + "url": "https://github.com/grafana/grafana/releases/tag/v13.0.2" + }, + { + "type": "WEB", + "url": "https://grafana.com/security/security-advisories/cve-2026-42127" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6541", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6542.json b/data/osv/GO-2026-6542.json new file mode 100644 index 0000000..b68c83d --- /dev/null +++ b/data/osv/GO-2026-6542.json
@@ -0,0 +1,132 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6542", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-9029", + "GHSA-9g84-39mm-q4p3" + ], + "summary": "Grafana geomap panel's XYZ tile layer has a sanitize-then-interpolate ordering bug in github.com/grafana/grafana", + "details": "Grafana geomap panel's XYZ tile layer has a sanitize-then-interpolate ordering bug in github.com/grafana/grafana.\n\nNOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.\n\n(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)\n\nThe additional affected modules and versions are: github.com/grafana/grafana before v1.9.2-0.20260616075434-82ef13993059.", + "affected": [ + { + "package": { + "name": "github.com/grafana/grafana", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "custom_ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.9.2-0.20260616075434-82ef13993059" + } + ] + } + ] + } + }, + { + "package": { + "name": "github.com/grafana/grafana", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "custom_ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "13.0.0" + } + ] + } + ] + } + }, + { + "package": { + "name": "github.com/grafana/grafana", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "2.0.0-beta1+incompatible" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-9g84-39mm-q4p3" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-9029" + }, + { + "type": "FIX", + "url": "https://github.com/grafana/grafana/commit/3fcdbc5a6e5c955bd42bd3715dd03cbad2b078c1" + }, + { + "type": "FIX", + "url": "https://github.com/grafana/grafana/commit/42cdc39124912a8506a0c613c319c345aa950b29" + }, + { + "type": "FIX", + "url": "https://github.com/grafana/grafana/commit/82ef13993059351bf21de35b8488bbd9b42df4f4" + }, + { + "type": "FIX", + "url": "https://github.com/grafana/grafana/commit/dc695b9649530064e19c7c120bd6ebe104908e58" + }, + { + "type": "WEB", + "url": "https://github.com/grafana/grafana/releases/tag/v12.4.4" + }, + { + "type": "WEB", + "url": "https://github.com/grafana/grafana/releases/tag/v13.0.2" + }, + { + "type": "WEB", + "url": "https://grafana.com/security/security-advisories/cve-2026-9029" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6542", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6543.json b/data/osv/GO-2026-6543.json new file mode 100644 index 0000000..534fafd --- /dev/null +++ b/data/osv/GO-2026-6543.json
@@ -0,0 +1,71 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6543", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-12249", + "GHSA-crm4-q7v4-c2r2" + ], + "summary": "Canonical ADSys Uses a Less Trusted Source in github.com/ubuntu/adsys", + "details": "Canonical ADSys Uses a Less Trusted Source in github.com/ubuntu/adsys.\n\nNOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.\n\n(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)\n\nThe additional affected modules and versions are: github.com/ubuntu/adsys before v0.16.3-0.20250318112551-8b1939f96d38.", + "affected": [ + { + "package": { + "name": "github.com/ubuntu/adsys", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "custom_ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.16.3-0.20250318112551-8b1939f96d38" + } + ] + } + ] + } + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-crm4-q7v4-c2r2" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-12249" + }, + { + "type": "FIX", + "url": "https://github.com/ubuntu/adsys/commit/8b1939f96d3827b4426eb06c1ced5bf317b0a99d" + }, + { + "type": "WEB", + "url": "https://github.com/ubuntu/adsys/releases/tag/v0.16.3" + }, + { + "type": "WEB", + "url": "https://ubuntu.com/security/CVE-2026-12249" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6543", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6544.json b/data/osv/GO-2026-6544.json new file mode 100644 index 0000000..e6a7fd5 --- /dev/null +++ b/data/osv/GO-2026-6544.json
@@ -0,0 +1,240 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6544", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-42129", + "GHSA-f74p-cwhp-x2wx" + ], + "summary": "Grafana Loki datasource plugin's callResource handler contains a path traversal vulnerability. in github.com/grafana/grafana", + "details": "Grafana Loki datasource plugin's callResource handler contains a path traversal vulnerability. in github.com/grafana/grafana.\n\nNOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.\n\n(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)\n\nThe additional affected modules and versions are: github.com/grafana/grafana before v1.9.2-0.20260616075434-82ef13993059.", + "affected": [ + { + "package": { + "name": "github.com/grafana/grafana", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "custom_ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.9.2-0.20260616075434-82ef13993059" + } + ] + } + ] + } + }, + { + "package": { + "name": "github.com/grafana/grafana", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "custom_ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "12.4.0" + } + ] + } + ] + } + }, + { + "package": { + "name": "github.com/grafana/grafana", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "custom_ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "13.0.0" + } + ] + } + ] + } + }, + { + "package": { + "name": "github.com/grafana/grafana", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "custom_ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "12.3.0" + } + ] + } + ] + } + }, + { + "package": { + "name": "github.com/grafana/grafana", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "custom_ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "12.0.0" + } + ] + } + ] + } + }, + { + "package": { + "name": "github.com/grafana/grafana", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "2.0.0-beta1+incompatible" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-f74p-cwhp-x2wx" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42129" + }, + { + "type": "FIX", + "url": "https://github.com/grafana/grafana/commit/3fcdbc5a6e5c955bd42bd3715dd03cbad2b078c1" + }, + { + "type": "FIX", + "url": "https://github.com/grafana/grafana/commit/42cdc39124912a8506a0c613c319c345aa950b29" + }, + { + "type": "FIX", + "url": "https://github.com/grafana/grafana/commit/82ef13993059351bf21de35b8488bbd9b42df4f4" + }, + { + "type": "FIX", + "url": "https://github.com/grafana/grafana/commit/d27d2eba9c509d16f214d290436a6ad0bd9c6c01" + }, + { + "type": "FIX", + "url": "https://github.com/grafana/grafana/commit/dd5dc51681ff0133ddb2e206c2ea318713aeca16" + }, + { + "type": "FIX", + "url": "https://github.com/grafana/grafana/commit/eeb08ceb020c4381242d8400e5878044e9877505" + }, + { + "type": "FIX", + "url": "https://github.com/grafana/grafana/commit/f70d3e480274a5dbd12006338c393f4b05d441ca" + }, + { + "type": "WEB", + "url": "https://github.com/grafana/grafana/releases/tag/v11.6.15" + }, + { + "type": "WEB", + "url": "https://github.com/grafana/grafana/releases/tag/v12.2.9" + }, + { + "type": "WEB", + "url": "https://github.com/grafana/grafana/releases/tag/v12.3.7" + }, + { + "type": "WEB", + "url": "https://github.com/grafana/grafana/releases/tag/v12.4.4" + }, + { + "type": "WEB", + "url": "https://github.com/grafana/grafana/releases/tag/v13.0.2" + }, + { + "type": "WEB", + "url": "https://grafana.com/security/security-advisories/cve-2026-42129" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6544", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6545.json b/data/osv/GO-2026-6545.json new file mode 100644 index 0000000..8cc0bab --- /dev/null +++ b/data/osv/GO-2026-6545.json
@@ -0,0 +1,240 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6545", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-10601", + "GHSA-9493-h4f5-633x" + ], + "summary": "Grafana: Path traversal in the Tempo and Loki data source plugins in github.com/grafana/grafana", + "details": "Grafana: Path traversal in the Tempo and Loki data source plugins in github.com/grafana/grafana.\n\nNOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.\n\n(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)\n\nThe additional affected modules and versions are: github.com/grafana/grafana before v1.9.2-0.20260616075434-82ef13993059.", + "affected": [ + { + "package": { + "name": "github.com/grafana/grafana", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "custom_ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.9.2-0.20260616075434-82ef13993059" + } + ] + } + ] + } + }, + { + "package": { + "name": "github.com/grafana/grafana", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "custom_ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "12.4.0" + } + ] + } + ] + } + }, + { + "package": { + "name": "github.com/grafana/grafana", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "custom_ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "13.0.0" + } + ] + } + ] + } + }, + { + "package": { + "name": "github.com/grafana/grafana", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "custom_ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "12.3.0" + } + ] + } + ] + } + }, + { + "package": { + "name": "github.com/grafana/grafana", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "custom_ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "12.0.0" + } + ] + } + ] + } + }, + { + "package": { + "name": "github.com/grafana/grafana", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "2.0.0-beta1+incompatible" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-9493-h4f5-633x" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-10601" + }, + { + "type": "FIX", + "url": "https://github.com/grafana/grafana/commit/3fcdbc5a6e5c955bd42bd3715dd03cbad2b078c1" + }, + { + "type": "FIX", + "url": "https://github.com/grafana/grafana/commit/42cdc39124912a8506a0c613c319c345aa950b29" + }, + { + "type": "FIX", + "url": "https://github.com/grafana/grafana/commit/82ef13993059351bf21de35b8488bbd9b42df4f4" + }, + { + "type": "FIX", + "url": "https://github.com/grafana/grafana/commit/d27d2eba9c509d16f214d290436a6ad0bd9c6c01" + }, + { + "type": "FIX", + "url": "https://github.com/grafana/grafana/commit/dd5dc51681ff0133ddb2e206c2ea318713aeca16" + }, + { + "type": "FIX", + "url": "https://github.com/grafana/grafana/commit/f70d3e480274a5dbd12006338c393f4b05d441ca" + }, + { + "type": "FIX", + "url": "https://github.com/grafana/grafana/pull/125789" + }, + { + "type": "WEB", + "url": "https://github.com/grafana/grafana/releases/tag/v11.6.15" + }, + { + "type": "WEB", + "url": "https://github.com/grafana/grafana/releases/tag/v12.2.9" + }, + { + "type": "WEB", + "url": "https://github.com/grafana/grafana/releases/tag/v12.3.7" + }, + { + "type": "WEB", + "url": "https://github.com/grafana/grafana/releases/tag/v12.4.4" + }, + { + "type": "WEB", + "url": "https://github.com/grafana/grafana/releases/tag/v13.0.2" + }, + { + "type": "WEB", + "url": "https://grafana.com/security/security-advisories/cve-2026-10601" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6545", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/reports/GO-2026-6480.yaml b/data/reports/GO-2026-6480.yaml new file mode 100644 index 0000000..481fb21 --- /dev/null +++ b/data/reports/GO-2026-6480.yaml
@@ -0,0 +1,28 @@ +id: GO-2026-6480 +modules: + - module: github.com/mattermost/mattermost-server + versions: + - introduced: 10.11.0+incompatible + - fixed: 10.11.18+incompatible + - introduced: 11.5.0+incompatible + - fixed: 11.5.6+incompatible + - introduced: 11.6.0+incompatible + - fixed: 11.6.3+incompatible + - introduced: 11.7.0+incompatible + - fixed: 11.7.1+incompatible + vulnerable_at: 11.7.0+incompatible +summary: |- + Mattermost doesn't enforce administrator authorization on the + {{setDefaultInstance}} call within the {{/gitlab connect}} command handler in github.com/mattermost/mattermost-server +cves: + - CVE-2026-5139 +ghsas: + - GHSA-2g8v-grq3-hq2g +references: + - advisory: https://github.com/advisories/GHSA-2g8v-grq3-hq2g + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-5139 + - web: https://mattermost.com/security-updates +source: + id: GHSA-2g8v-grq3-hq2g + created: 2026-09-22T10:18:04.761818-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6481.yaml b/data/reports/GO-2026-6481.yaml new file mode 100644 index 0000000..d5c7c8f --- /dev/null +++ b/data/reports/GO-2026-6481.yaml
@@ -0,0 +1,24 @@ +id: GO-2026-6481 +modules: + - module: github.com/mattermost/mattermost-server + versions: + - introduced: 10.11.0+incompatible + - fixed: 10.11.18+incompatible + - introduced: 11.7.0+incompatible + - fixed: 11.7.1+incompatible + vulnerable_at: 11.7.0+incompatible +summary: |- + Mattermost doesn't enforce bot-specific permission checks on the user active + status endpoint in github.com/mattermost/mattermost-server +cves: + - CVE-2026-8074 +ghsas: + - GHSA-g5vr-6pgg-74qv +references: + - advisory: https://github.com/advisories/GHSA-g5vr-6pgg-74qv + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-8074 + - web: https://mattermost.com/security-updates +source: + id: GHSA-g5vr-6pgg-74qv + created: 2026-09-22T10:17:58.203898-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6482.yaml b/data/reports/GO-2026-6482.yaml new file mode 100644 index 0000000..3de8b50 --- /dev/null +++ b/data/reports/GO-2026-6482.yaml
@@ -0,0 +1,28 @@ +id: GO-2026-6482 +modules: + - module: github.com/mattermost/mattermost-server + versions: + - introduced: 10.11.0+incompatible + - fixed: 10.11.18+incompatible + - introduced: 11.5.0+incompatible + - fixed: 11.5.6+incompatible + - introduced: 11.6.0+incompatible + - fixed: 11.6.3+incompatible + - introduced: 11.7.0+incompatible + - fixed: 11.7.1+incompatible + vulnerable_at: 11.7.0+incompatible +summary: |- + Mattermost doesn't invalidate cached authentication state for active WebSocket + connections during global session revocation in github.com/mattermost/mattermost-server +cves: + - CVE-2026-9162 +ghsas: + - GHSA-h998-hxxj-8q83 +references: + - advisory: https://github.com/advisories/GHSA-h998-hxxj-8q83 + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-9162 + - web: https://mattermost.com/security-updates +source: + id: GHSA-h998-hxxj-8q83 + created: 2026-09-22T10:17:50.189409-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6483.yaml b/data/reports/GO-2026-6483.yaml new file mode 100644 index 0000000..c509f83 --- /dev/null +++ b/data/reports/GO-2026-6483.yaml
@@ -0,0 +1,28 @@ +id: GO-2026-6483 +modules: + - module: github.com/mattermost/mattermost-server + versions: + - introduced: 10.11.0+incompatible + - fixed: 10.11.18+incompatible + - introduced: 11.5.0+incompatible + - fixed: 11.5.6+incompatible + - introduced: 11.6.0+incompatible + - fixed: 11.6.3+incompatible + - introduced: 11.7.0+incompatible + - fixed: 11.7.1+incompatible + vulnerable_at: 11.7.0+incompatible +summary: |- + Mattermost doesn't authenticate Atlassian Connect installed callbacks, allowing + a remote unauthenticated attacker to inject a rogue sharedSecret in github.com/mattermost/mattermost-server +cves: + - CVE-2026-6673 +ghsas: + - GHSA-jqgv-39mg-7c2r +references: + - advisory: https://github.com/advisories/GHSA-jqgv-39mg-7c2r + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-6673 + - web: https://mattermost.com/security-updates +source: + id: GHSA-jqgv-39mg-7c2r + created: 2026-09-22T10:17:42.442379-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6484.yaml b/data/reports/GO-2026-6484.yaml new file mode 100644 index 0000000..fd10578 --- /dev/null +++ b/data/reports/GO-2026-6484.yaml
@@ -0,0 +1,28 @@ +id: GO-2026-6484 +modules: + - module: github.com/mattermost/mattermost-server + versions: + - introduced: 10.11.0+incompatible + - fixed: 10.11.18+incompatible + - introduced: 11.5.0+incompatible + - fixed: 11.5.6+incompatible + - introduced: 11.6.0+incompatible + - fixed: 11.6.3+incompatible + - introduced: 11.7.0+incompatible + - fixed: 11.7.1+incompatible + vulnerable_at: 11.7.0+incompatible +summary: |- + Mattermost doesn't validate channel ownership of an existing subscription before + applying edits in github.com/mattermost/mattermost-server +cves: + - CVE-2026-6062 +ghsas: + - GHSA-mxq2-5jpg-7474 +references: + - advisory: https://github.com/advisories/GHSA-mxq2-5jpg-7474 + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-6062 + - web: https://mattermost.com/security-updates +source: + id: GHSA-mxq2-5jpg-7474 + created: 2026-09-22T10:17:07.85964-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6485.yaml b/data/reports/GO-2026-6485.yaml new file mode 100644 index 0000000..bb66048 --- /dev/null +++ b/data/reports/GO-2026-6485.yaml
@@ -0,0 +1,18 @@ +id: GO-2026-6485 +modules: + - module: github.com/gravitl/netmaker + versions: + - fixed: 1.5.0 + vulnerable_at: 1.4.0 +summary: Netmaker has a boolean‑based SQL Injection in github.com/gravitl/netmaker +cves: + - CVE-2026-32599 +ghsas: + - GHSA-r8cr-4f9w-7r75 +references: + - advisory: https://github.com/gravitl/netmaker/security/advisories/GHSA-r8cr-4f9w-7r75 + - web: https://github.com/gravitl/netmaker/releases/tag/v1.5.0 +source: + id: GHSA-r8cr-4f9w-7r75 + created: 2026-09-22T10:17:00.917771-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6486.yaml b/data/reports/GO-2026-6486.yaml new file mode 100644 index 0000000..0486599 --- /dev/null +++ b/data/reports/GO-2026-6486.yaml
@@ -0,0 +1,16 @@ +id: GO-2026-6486 +modules: + - module: github.com/nezhahq/nezha + vulnerable_at: 1.14.14 +summary: |- + Nezha: OAuth2 redirect_uri Host header injection regression when dashboard_host + is empty in github.com/nezhahq/nezha +ghsas: + - GHSA-rf68-8gjr-36q7 +references: + - advisory: https://github.com/nezhahq/nezha/security/advisories/GHSA-rf68-8gjr-36q7 + - fix: https://github.com/nezhahq/nezha/commit/38824dbc11a63964c5b9296ae4c68e62b34fa04b +source: + id: GHSA-rf68-8gjr-36q7 + created: 2026-09-22T10:16:56.538133-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6487.yaml b/data/reports/GO-2026-6487.yaml new file mode 100644 index 0000000..0e80f3b --- /dev/null +++ b/data/reports/GO-2026-6487.yaml
@@ -0,0 +1,19 @@ +id: GO-2026-6487 +modules: + - module: github.com/jm33-m0/emp3r0r/core + versions: + - fixed: 0.0.0-20260531142011-aed3d81641ab +summary: emp3r0r has an unauthenticated HTTP Polling DoS in github.com/jm33-m0/emp3r0r/core +cves: + - CVE-2026-61554 +ghsas: + - GHSA-4595-rvpx-4q34 +references: + - advisory: https://github.com/jm33-m0/emp3r0r/security/advisories/GHSA-4595-rvpx-4q34 + - web: https://github.com/jm33-m0/emp3r0r/releases/tag/v4.2.5 +notes: + - fix: 'github.com/jm33-m0/emp3r0r/core: could not add vulnerable_at: cannot auto-guess when fixed version is 0.0.0 pseudo-version' +source: + id: GHSA-4595-rvpx-4q34 + created: 2026-09-22T10:16:50.985152-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6488.yaml b/data/reports/GO-2026-6488.yaml new file mode 100644 index 0000000..5c31c29 --- /dev/null +++ b/data/reports/GO-2026-6488.yaml
@@ -0,0 +1,23 @@ +id: GO-2026-6488 +modules: + - module: github.com/openfga/openfga + versions: + - fixed: 1.18.1 + vulnerable_at: 1.18.0 +summary: |- + OpenFGA: ListUsers returns a deliberately-excluded user when a `but not` + exclusion under a type-bound wildcard is intersected (`and`) with another + relation that also grants that user in github.com/openfga/openfga +cves: + - CVE-2026-61709 +ghsas: + - GHSA-g3pg-frfm-pr2m +references: + - advisory: https://github.com/openfga/openfga/security/advisories/GHSA-g3pg-frfm-pr2m + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-61709 + - fix: https://github.com/openfga/openfga/commit/171806c93b86bca29e0212ceb8b6ee9c48eb9ac3 + - web: https://github.com/openfga/openfga/releases/tag/v1.18.1 +source: + id: GHSA-g3pg-frfm-pr2m + created: 2026-09-22T10:16:43.051223-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6490.yaml b/data/reports/GO-2026-6490.yaml new file mode 100644 index 0000000..0b1a691 --- /dev/null +++ b/data/reports/GO-2026-6490.yaml
@@ -0,0 +1,31 @@ +id: GO-2026-6490 +modules: + - module: github.com/centrifugal/centrifugo + vulnerable_at: 1.8.0 + - module: github.com/centrifugal/centrifugo/v3 + vulnerable_at: 3.2.3 + - module: github.com/centrifugal/centrifugo/v4 + vulnerable_at: 4.1.5 + - module: github.com/centrifugal/centrifugo/v5 + vulnerable_at: 5.4.9 + - module: github.com/centrifugal/centrifugo/v6 + versions: + - fixed: 6.9.0 + vulnerable_at: 6.8.4 +summary: |- + Centrifugo: Client-forgeable headers emulation lets any client spoof headers + forwarded to proxy backends in github.com/centrifugal/centrifugo +cves: + - CVE-2026-71485 +ghsas: + - GHSA-9468-v6mj-fppw +references: + - advisory: https://github.com/centrifugal/centrifugo/security/advisories/GHSA-9468-v6mj-fppw + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-71485 + - fix: https://github.com/centrifugal/centrifugo/commit/84d38cea1dd2efa24375a148817a974c8727f4b0 + - fix: https://github.com/centrifugal/centrifugo/pull/1182 + - web: https://github.com/centrifugal/centrifugo/releases/tag/v6.9.0 +source: + id: GHSA-9468-v6mj-fppw + created: 2026-09-22T10:15:08.655437-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6495.yaml b/data/reports/GO-2026-6495.yaml new file mode 100644 index 0000000..aee4eec --- /dev/null +++ b/data/reports/GO-2026-6495.yaml
@@ -0,0 +1,24 @@ +id: GO-2026-6495 +modules: + - module: github.com/zalando/skipper + versions: + - fixed: 0.27.37 + vulnerable_at: 0.27.36 +summary: |- + Skipper has OPA body-authz bypass: truncated_body mitigation fails open on + chunked/HTTP-2 (incomplete fix GHSA-8qqm-fp2q-v734) in github.com/zalando/skipper +cves: + - CVE-2026-86043 +ghsas: + - GHSA-5gpm-rgj3-9q76 +references: + - advisory: https://github.com/zalando/skipper/security/advisories/GHSA-5gpm-rgj3-9q76 + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-86043 + - fix: https://github.com/zalando/skipper/commit/2cfceabaa6ff0af65b312dcb9bcbe84691b9d507 + - web: https://github.com/zalando/skipper/releases/tag/v0.27.35 + - web: https://github.com/zalando/skipper/releases/tag/v0.27.37 + - web: https://github.com/zalando/skipper/tree/v0.27.35 +source: + id: GHSA-5gpm-rgj3-9q76 + created: 2026-09-22T10:14:21.41098-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6506.yaml b/data/reports/GO-2026-6506.yaml new file mode 100644 index 0000000..ac89217 --- /dev/null +++ b/data/reports/GO-2026-6506.yaml
@@ -0,0 +1,20 @@ +id: GO-2026-6506 +modules: + - module: github.com/coredns/coredns + versions: + - fixed: 1.14.7 + vulnerable_at: 1.14.6 +summary: CoreDNS DoH/DoQ/gRPC bypass UPDATE rejection enforced on UDP/TCP in github.com/coredns/coredns +cves: + - CVE-2026-86003 +ghsas: + - GHSA-9gm5-9rfh-m6vx +references: + - advisory: https://github.com/coredns/coredns/security/advisories/GHSA-9gm5-9rfh-m6vx + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-86003 + - fix: https://github.com/coredns/coredns/commit/530b0a5ff2ad68cc0421f10dd93568945cc671c9 + - web: https://github.com/coredns/coredns/releases/tag/v1.14.7 +source: + id: GHSA-9gm5-9rfh-m6vx + created: 2026-09-22T10:12:57.869273-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6507.yaml b/data/reports/GO-2026-6507.yaml new file mode 100644 index 0000000..961e46a --- /dev/null +++ b/data/reports/GO-2026-6507.yaml
@@ -0,0 +1,20 @@ +id: GO-2026-6507 +modules: + - module: github.com/coredns/coredns + versions: + - fixed: 1.14.7 + vulnerable_at: 1.14.6 +summary: 'CoreDNS: Unauthenticated memory exhaustion in custom transports in github.com/coredns/coredns' +cves: + - CVE-2026-82399 +ghsas: + - GHSA-mrg3-qvqr-jw29 +references: + - advisory: https://github.com/coredns/coredns/security/advisories/GHSA-mrg3-qvqr-jw29 + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-82399 + - fix: https://github.com/coredns/coredns/commit/530b0a5ff2ad68cc0421f10dd93568945cc671c9 + - web: https://github.com/coredns/coredns/releases/tag/v1.14.7 +source: + id: GHSA-mrg3-qvqr-jw29 + created: 2026-09-22T10:12:50.573298-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6508.yaml b/data/reports/GO-2026-6508.yaml new file mode 100644 index 0000000..aa56739 --- /dev/null +++ b/data/reports/GO-2026-6508.yaml
@@ -0,0 +1,22 @@ +id: GO-2026-6508 +modules: + - module: go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc + versions: + - fixed: 0.21.0 + vulnerable_at: 0.20.0 +summary: |- + OpenTelemetry-Go: Log gRPC exporter ignores env TLS certs, bypassing + mTLS/pinning in go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc +cves: + - CVE-2026-81871 +ghsas: + - GHSA-w34q-cm8f-9c5x +references: + - advisory: https://github.com/open-telemetry/opentelemetry-go/security/advisories/GHSA-w34q-cm8f-9c5x + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-81871 + - web: https://github.com/open-telemetry/opentelemetry-go/commit/c65d435b43e5e6b82310e6b18dd4cdcb8ac63a0c + - web: https://github.com/open-telemetry/opentelemetry-go/releases/tag/exporters/otlp/otlplog/otlploggrpc/v0.21.0 +source: + id: GHSA-w34q-cm8f-9c5x + created: 2026-09-22T10:12:43.613148-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6514.yaml b/data/reports/GO-2026-6514.yaml new file mode 100644 index 0000000..6e8eba3 --- /dev/null +++ b/data/reports/GO-2026-6514.yaml
@@ -0,0 +1,22 @@ +id: GO-2026-6514 +modules: + - module: github.com/perses/perses + versions: + - introduced: 0.43.0 + - fixed: 0.54.0-rc.0 + vulnerable_at: 0.54.0-beta.3 +summary: |- + Perses's missing authorization in datasource proxy allows cross-scope secret + disclosure in github.com/perses/perses +cves: + - CVE-2026-63199 +ghsas: + - GHSA-4227-9989-jrhx +references: + - advisory: https://github.com/perses/perses/security/advisories/GHSA-4227-9989-jrhx + - fix: https://github.com/perses/perses/commit/2368c9ef4eb0a70fbca5df69aa20e595821ab625 + - web: https://github.com/perses/perses/releases/tag/v0.54.0-rc.0 +source: + id: GHSA-4227-9989-jrhx + created: 2026-09-22T10:12:23.911805-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6515.yaml b/data/reports/GO-2026-6515.yaml new file mode 100644 index 0000000..ab825ab --- /dev/null +++ b/data/reports/GO-2026-6515.yaml
@@ -0,0 +1,21 @@ +id: GO-2026-6515 +modules: + - module: github.com/f1bonacc1/process-compose + versions: + - fixed: 1.120.0 + vulnerable_at: 1.116.0 +summary: |- + Process Compose: Browser DNS rebinding lets websites control local + process-compose MCP tools in github.com/f1bonacc1/process-compose +cves: + - CVE-2026-77339 +ghsas: + - GHSA-5gm3-9crp-6g3v +references: + - advisory: https://github.com/F1bonacc1/process-compose/security/advisories/GHSA-5gm3-9crp-6g3v + - web: https://github.com/F1bonacc1/process-compose/commit/6ffa74f462cd2fa4f8dc1ee63c70b793b298c858 + - web: https://github.com/F1bonacc1/process-compose/releases/tag/v1.120.0 +source: + id: GHSA-5gm3-9crp-6g3v + created: 2026-09-22T10:12:16.446138-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6516.yaml b/data/reports/GO-2026-6516.yaml new file mode 100644 index 0000000..1e10f18 --- /dev/null +++ b/data/reports/GO-2026-6516.yaml
@@ -0,0 +1,21 @@ +id: GO-2026-6516 +modules: + - module: github.com/anycable/anycable-go + non_go_versions: + - fixed: 1.6.15 + vulnerable_at: 1.5.6 +summary: |- + AnyCable: Pusher REST API Does Not Verify Request Body MD5 Enabling + Signed-Request Replay with Arbitrary Body in github.com/anycable/anycable-go +cves: + - CVE-2026-63405 +ghsas: + - GHSA-5p54-whvp-x327 +references: + - advisory: https://github.com/anycable/anycable/security/advisories/GHSA-5p54-whvp-x327 + - web: https://github.com/anycable/anycable/commit/d2cbadec792f038f4695c84a65c0d957b0fde72c + - web: https://github.com/anycable/anycable/releases/tag/v1.6.15 +source: + id: GHSA-5p54-whvp-x327 + created: 2026-09-22T10:12:09.488921-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6517.yaml b/data/reports/GO-2026-6517.yaml new file mode 100644 index 0000000..4d5f3ee --- /dev/null +++ b/data/reports/GO-2026-6517.yaml
@@ -0,0 +1,25 @@ +id: GO-2026-6517 +modules: + - module: github.com/kcp-dev/kcp + versions: + - fixed: 0.31.4 + - introduced: 0.32.0 + - fixed: 0.32.2 + vulnerable_at: 0.32.1 +summary: |- + kcp front-proxy does not strip inbound X-Remote-* identity headers, allowing any + authenticated client to inject groups/warrants and impersonate system:masters in + any workspace in github.com/kcp-dev/kcp +cves: + - CVE-2026-61682 +ghsas: + - GHSA-c8w2-fgvx-vhv4 +references: + - advisory: https://github.com/kcp-dev/kcp/security/advisories/GHSA-c8w2-fgvx-vhv4 + - fix: https://github.com/kcp-dev/kcp/commit/7437cdcfec8f927d1a9bf1b2dd1e075d038e27ca + - web: https://github.com/kcp-dev/kcp/releases/tag/v0.31.4 + - web: https://github.com/kcp-dev/kcp/releases/tag/v0.32.2 +source: + id: GHSA-c8w2-fgvx-vhv4 + created: 2026-09-22T10:12:01.87658-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6518.yaml b/data/reports/GO-2026-6518.yaml new file mode 100644 index 0000000..bbcd7b6 --- /dev/null +++ b/data/reports/GO-2026-6518.yaml
@@ -0,0 +1,21 @@ +id: GO-2026-6518 +modules: + - module: github.com/perses/perses + versions: + - fixed: 0.54.0-beta.3 + vulnerable_at: 0.54.0-beta.2 +summary: |- + Perses's project query parameter authorization bypass exposes cross-project + resources in github.com/perses/perses +cves: + - CVE-2026-63458 +ghsas: + - GHSA-cjgj-2fwf-4c2w +references: + - advisory: https://github.com/perses/perses/security/advisories/GHSA-cjgj-2fwf-4c2w + - fix: https://github.com/perses/perses/commit/8015fb340bdc625953e73a7a688be5b939159540 + - web: https://github.com/perses/perses/releases/tag/v0.54.0-beta.3 +source: + id: GHSA-cjgj-2fwf-4c2w + created: 2026-09-22T10:11:54.58659-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6519.yaml b/data/reports/GO-2026-6519.yaml new file mode 100644 index 0000000..e33fd32 --- /dev/null +++ b/data/reports/GO-2026-6519.yaml
@@ -0,0 +1,23 @@ +id: GO-2026-6519 +modules: + - module: github.com/projectcapsule/capsule + versions: + - introduced: 0.13.0 + - fixed: 0.13.7 + vulnerable_at: 0.13.6 +summary: |- + Capsule: hostnameRegexHandler.OnUpdate validates stale (old) Tenant regex, + allowing invalid AllowedHostnames regex to bypass webhook validation in github.com/projectcapsule/capsule +cves: + - CVE-2026-61795 +ghsas: + - GHSA-f94q-w3w8-cj67 +references: + - advisory: https://github.com/projectcapsule/capsule/security/advisories/GHSA-f94q-w3w8-cj67 + - fix: https://github.com/projectcapsule/capsule/commit/8d89d6865df6f41c7faa22fc9e807a57b01bfd0e + - fix: https://github.com/projectcapsule/capsule/pull/1983 + - web: https://github.com/projectcapsule/capsule/releases/tag/v0.13.7 +source: + id: GHSA-f94q-w3w8-cj67 + created: 2026-09-22T10:11:47.500495-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6520.yaml b/data/reports/GO-2026-6520.yaml new file mode 100644 index 0000000..998cd32 --- /dev/null +++ b/data/reports/GO-2026-6520.yaml
@@ -0,0 +1,22 @@ +id: GO-2026-6520 +modules: + - module: github.com/projectcapsule/capsule + versions: + - fixed: 0.13.7 + vulnerable_at: 0.13.6 +summary: |- + Capsule: Tenant owner bypasses Capsule's forbidden namespace/service/node label + and annotation enforcement in github.com/projectcapsule/capsule +cves: + - CVE-2026-61672 +ghsas: + - GHSA-gjw4-3v3v-rqxg +references: + - advisory: https://github.com/projectcapsule/capsule/security/advisories/GHSA-gjw4-3v3v-rqxg + - fix: https://github.com/projectcapsule/capsule/commit/755cef54bf4a1bc56d6692130132bc70755bef46 + - fix: https://github.com/projectcapsule/capsule/pull/1982 + - web: https://github.com/projectcapsule/capsule/releases/tag/v0.13.7 +source: + id: GHSA-gjw4-3v3v-rqxg + created: 2026-09-22T10:11:38.640435-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6521.yaml b/data/reports/GO-2026-6521.yaml new file mode 100644 index 0000000..04eea93 --- /dev/null +++ b/data/reports/GO-2026-6521.yaml
@@ -0,0 +1,23 @@ +id: GO-2026-6521 +modules: + - module: github.com/projectcapsule/capsule + versions: + - introduced: 0.13.0 + - fixed: 0.13.7 + vulnerable_at: 0.13.6 +summary: |- + Capsule: Malformed ForbiddenAnnotations.Regex can bypass Tenant validation and + trigger namespace admission panic in github.com/projectcapsule/capsule +cves: + - CVE-2026-61794 +ghsas: + - GHSA-gxjc-74v5-3vx3 +references: + - advisory: https://github.com/projectcapsule/capsule/security/advisories/GHSA-gxjc-74v5-3vx3 + - fix: https://github.com/projectcapsule/capsule/commit/8d89d6865df6f41c7faa22fc9e807a57b01bfd0e + - fix: https://github.com/projectcapsule/capsule/pull/1983 + - web: https://github.com/projectcapsule/capsule/releases/tag/v0.13.7 +source: + id: GHSA-gxjc-74v5-3vx3 + created: 2026-09-22T10:11:29.911683-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6522.yaml b/data/reports/GO-2026-6522.yaml new file mode 100644 index 0000000..245d835 --- /dev/null +++ b/data/reports/GO-2026-6522.yaml
@@ -0,0 +1,16 @@ +id: GO-2026-6522 +modules: + - module: github.com/obot-platform/obot + versions: + - fixed: 0.23.0 + vulnerable_at: 0.23.0-rc5 +summary: 'Obot: Server-Side Request Forgery via remote MCP server URL in github.com/obot-platform/obot' +ghsas: + - GHSA-jgh3-fggc-mcpm +references: + - advisory: https://github.com/obot-platform/obot/security/advisories/GHSA-jgh3-fggc-mcpm + - web: https://github.com/obot-platform/obot/releases/tag/v0.23.0 +source: + id: GHSA-jgh3-fggc-mcpm + created: 2026-09-22T10:11:26.996243-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6523.yaml b/data/reports/GO-2026-6523.yaml new file mode 100644 index 0000000..33d462e --- /dev/null +++ b/data/reports/GO-2026-6523.yaml
@@ -0,0 +1,20 @@ +id: GO-2026-6523 +modules: + - module: github.com/frain-dev/convoy + versions: + - fixed: 0.9.3-0.20260724092134-1cc67cd16fb1 + vulnerable_at: 0.9.2 +summary: 'Convoy: Cross-Tenant Source IDOR Leaks Plaintext Message Broker Credentials in github.com/frain-dev/convoy' +cves: + - CVE-2026-81505 +ghsas: + - GHSA-p5vg-v7mj-f6q4 +references: + - advisory: https://github.com/frain-dev/convoy/security/advisories/GHSA-p5vg-v7mj-f6q4 + - fix: https://github.com/frain-dev/convoy/commit/1cc67cd16fb1f8890cc83a3998d3f92dceb7fd06 + - fix: https://github.com/frain-dev/convoy/pull/2755 + - web: https://github.com/frain-dev/convoy/releases/tag/v26.6.8 +source: + id: GHSA-p5vg-v7mj-f6q4 + created: 2026-09-22T10:11:20.707596-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6525.yaml b/data/reports/GO-2026-6525.yaml new file mode 100644 index 0000000..07ab997 --- /dev/null +++ b/data/reports/GO-2026-6525.yaml
@@ -0,0 +1,16 @@ +id: GO-2026-6525 +modules: + - module: github.com/obot-platform/obot + versions: + - fixed: 0.23.0 + vulnerable_at: 0.23.0-rc5 +summary: 'Obot: MCP Registry API readable without authentication in github.com/obot-platform/obot' +ghsas: + - GHSA-pr6h-vr44-xq8j +references: + - advisory: https://github.com/obot-platform/obot/security/advisories/GHSA-pr6h-vr44-xq8j + - web: https://github.com/obot-platform/obot/releases/tag/v0.23.0 +source: + id: GHSA-pr6h-vr44-xq8j + created: 2026-09-22T10:11:17.618829-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6526.yaml b/data/reports/GO-2026-6526.yaml new file mode 100644 index 0000000..329a499 --- /dev/null +++ b/data/reports/GO-2026-6526.yaml
@@ -0,0 +1,25 @@ +id: GO-2026-6526 +modules: + - module: github.com/stacklok/toolhive + versions: + - fixed: 0.30.1 + vulnerable_at: 0.30.0 +summary: |- + ToolHive: containerized MCP servers can reach host services via + host.docker.internal, enabling lateral movement in github.com/stacklok/toolhive +cves: + - CVE-2026-58197 +ghsas: + - GHSA-qg2g-g9w3-m5h8 +references: + - advisory: https://github.com/stacklok/toolhive/security/advisories/GHSA-qg2g-g9w3-m5h8 + - fix: https://github.com/stacklok/toolhive/commit/d8f40cb1599b8bf66657f2dfff15bfbfc236e712 + - fix: https://github.com/stacklok/toolhive/pull/5583 + - web: https://github.com/stacklok/toolhive-studio/commit/968182d7f3ee1e55123369e66ad88f82128119b0 + - web: https://github.com/stacklok/toolhive-studio/pull/2469 + - web: https://github.com/stacklok/toolhive-studio/releases/tag/v0.38.0 + - web: https://github.com/stacklok/toolhive/releases/tag/v0.30.1 +source: + id: GHSA-qg2g-g9w3-m5h8 + created: 2026-09-22T10:11:08.428997-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6527.yaml b/data/reports/GO-2026-6527.yaml new file mode 100644 index 0000000..6973e4c --- /dev/null +++ b/data/reports/GO-2026-6527.yaml
@@ -0,0 +1,24 @@ +id: GO-2026-6527 +modules: + - module: zotregistry.dev/zot + vulnerable_at: 1.4.3 + - module: zotregistry.dev/zot/v2 + versions: + - fixed: 2.1.18 + vulnerable_at: 2.1.17 +summary: |- + zot: Bearer authentication maps DELETE to push scope, allowing unauthorized + deletion in zotregistry.dev/zot +cves: + - CVE-2026-61833 +ghsas: + - GHSA-qg67-7m6v-qg25 +references: + - advisory: https://github.com/project-zot/zot/security/advisories/GHSA-qg67-7m6v-qg25 + - web: https://github.com/project-zot/zot/commit/7bb211bcd4352b90f3e99752607fbd1f050bf7ca + - web: https://github.com/project-zot/zot/pull/4161 + - web: https://github.com/project-zot/zot/releases/tag/v2.1.18 +source: + id: GHSA-qg67-7m6v-qg25 + created: 2026-09-22T10:10:59.988618-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6528.yaml b/data/reports/GO-2026-6528.yaml new file mode 100644 index 0000000..910d903 --- /dev/null +++ b/data/reports/GO-2026-6528.yaml
@@ -0,0 +1,19 @@ +id: GO-2026-6528 +modules: + - module: github.com/perses/perses + versions: + - fixed: 0.54.0-rc.0 + vulnerable_at: 0.54.0-beta.3 +summary: Perses's unvalidated project parameter enables filesystem path traversal in github.com/perses/perses +cves: + - CVE-2026-63445 +ghsas: + - GHSA-vr5f-w35q-98jp +references: + - advisory: https://github.com/perses/perses/security/advisories/GHSA-vr5f-w35q-98jp + - fix: https://github.com/perses/perses/commit/75e5471040ccb5674ea8d25c2aa16c80ccb70b2a + - web: https://github.com/perses/perses/releases/tag/v0.54.0-rc.0 +source: + id: GHSA-vr5f-w35q-98jp + created: 2026-09-22T10:10:52.899776-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6529.yaml b/data/reports/GO-2026-6529.yaml new file mode 100644 index 0000000..752f4fb --- /dev/null +++ b/data/reports/GO-2026-6529.yaml
@@ -0,0 +1,21 @@ +id: GO-2026-6529 +modules: + - module: github.com/anycable/anycable-go + non_go_versions: + - fixed: 1.6.15 + vulnerable_at: 1.5.6 +summary: |- + AnyCable: Telemetry Subsystem Contains Hardcoded Authentication Token and + Transmits CLI Arguments Including Secrets in github.com/anycable/anycable-go +cves: + - CVE-2026-63406 +ghsas: + - GHSA-w72w-9qmj-c9qm +references: + - advisory: https://github.com/anycable/anycable/security/advisories/GHSA-w72w-9qmj-c9qm + - web: https://github.com/anycable/anycable/commit/201c67e99e463ed63bd6b345562f4c458385fcee + - web: https://github.com/anycable/anycable/releases/tag/v1.6.15 +source: + id: GHSA-w72w-9qmj-c9qm + created: 2026-09-22T10:10:44.35196-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6530.yaml b/data/reports/GO-2026-6530.yaml new file mode 100644 index 0000000..f840618 --- /dev/null +++ b/data/reports/GO-2026-6530.yaml
@@ -0,0 +1,18 @@ +id: GO-2026-6530 +modules: + - module: github.com/obot-platform/obot + versions: + - fixed: 0.23.0 + vulnerable_at: 0.23.0-rc5 +summary: |- + Obot: OAuth Dynamic Client Registration Enables API Token Theft via Audience + Confusion in github.com/obot-platform/obot +ghsas: + - GHSA-xwmw-prc4-v3cr +references: + - advisory: https://github.com/obot-platform/obot/security/advisories/GHSA-xwmw-prc4-v3cr + - web: https://github.com/obot-platform/obot/releases/tag/v0.23.0 +source: + id: GHSA-xwmw-prc4-v3cr + created: 2026-09-22T10:10:40.633814-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6535.yaml b/data/reports/GO-2026-6535.yaml new file mode 100644 index 0000000..e1f1614 --- /dev/null +++ b/data/reports/GO-2026-6535.yaml
@@ -0,0 +1,24 @@ +id: GO-2026-6535 +modules: + - module: github.com/hatchet-dev/hatchet + non_go_versions: + - fixed: 0.91.1 + vulnerable_at: 0.108.3 + packages: + - package: github.com/hatchet-dev/hatchet/api/v1/server/authn + symbols: + - SessionHelpers.ValidateOAuthState +summary: |- + Hatchet - Unauthenticated OAuth state CSRF / login-CSRF via empty-state + collision in ValidateOAuthState in hatchet in github.com/hatchet-dev/hatchet +cves: + - CVE-2026-61687 +ghsas: + - GHSA-phg3-3g28-wq9v +references: + - advisory: https://github.com/hatchet-dev/hatchet/security/advisories/GHSA-phg3-3g28-wq9v + - fix: https://github.com/hatchet-dev/hatchet/commit/f90464189ad642251e09412d0f99fde353036428 +source: + id: GHSA-phg3-3g28-wq9v + created: 2026-09-22T10:10:35.931675-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6537.yaml b/data/reports/GO-2026-6537.yaml new file mode 100644 index 0000000..9150db2 --- /dev/null +++ b/data/reports/GO-2026-6537.yaml
@@ -0,0 +1,25 @@ +id: GO-2026-6537 +modules: + - module: github.com/lucasdillmann/nginx-ignition + versions: + - introduced: 0.0.0-20260217145239-1cbfae0296f1 + - fixed: 0.0.0-20260328015550-8d35e1eb5dd6 +summary: nginx ignition has TOTP Reuse During Validity Window in github.com/lucasdillmann/nginx-ignition +cves: + - CVE-2026-61630 +ghsas: + - GHSA-hf33-q6cf-c66f +references: + - advisory: https://github.com/lucasdillmann/nginx-ignition/security/advisories/GHSA-hf33-q6cf-c66f + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-61630 + - fix: https://github.com/lucasdillmann/nginx-ignition/commit/1cbfae0296f1b186158f5a294ec484060e00102e + - fix: https://github.com/lucasdillmann/nginx-ignition/commit/8d35e1eb5dd6a40fef94a45511fe08b0603af107 + - fix: https://github.com/lucasdillmann/nginx-ignition/pull/104 + - web: https://github.com/lucasdillmann/nginx-ignition/releases/tag/2.35.1 + - web: https://github.com/pquerna/otp/issues/61 +notes: + - fix: 'github.com/lucasdillmann/nginx-ignition: could not add vulnerable_at: cannot auto-guess when fixed version is 0.0.0 pseudo-version' +source: + id: GHSA-hf33-q6cf-c66f + created: 2026-09-22T10:10:27.07864-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6538.yaml b/data/reports/GO-2026-6538.yaml new file mode 100644 index 0000000..7bb01e6 --- /dev/null +++ b/data/reports/GO-2026-6538.yaml
@@ -0,0 +1,40 @@ +id: GO-2026-6538 +modules: + - module: github.com/falcosecurity/plugins/plugins/k8saudit + versions: + - fixed: 0.18.0 + vulnerable_at: 0.17.0 + - module: github.com/falcosecurity/plugins/plugins/k8saudit-aks + versions: + - fixed: 0.6.0 + vulnerable_at: 0.5.1 + - module: github.com/falcosecurity/plugins/plugins/k8saudit-eks + versions: + - fixed: 0.12.0 + vulnerable_at: 0.11.0 + - module: github.com/falcosecurity/plugins/plugins/k8saudit-gke + versions: + - fixed: 0.9.0 + vulnerable_at: 0.8.0 + - module: github.com/falcosecurity/plugins/plugins/k8saudit-ovh + versions: + - fixed: 0.6.0 + vulnerable_at: 0.5.0 +summary: |- + k8saudit shipped rules do not detect privileged/sensitive settings on init or + ephemeral containers in github.com/falcosecurity/plugins/plugins/k8saudit +ghsas: + - GHSA-jhjp-4c2q-xmx4 +references: + - advisory: https://github.com/falcosecurity/plugins/security/advisories/GHSA-jhjp-4c2q-xmx4 + - web: https://github.com/falcosecurity/plugins/commit/0adb9b3c7e2c8bad53f30d01c057e038b2afa5e1 + - web: https://github.com/falcosecurity/plugins/pull/1400 + - web: https://github.com/falcosecurity/plugins/releases/tag/plugins/k8saudit-aks/v0.6.0 + - web: https://github.com/falcosecurity/plugins/releases/tag/plugins/k8saudit-eks/v0.12.0 + - web: https://github.com/falcosecurity/plugins/releases/tag/plugins/k8saudit-gke/v0.9.0 + - web: https://github.com/falcosecurity/plugins/releases/tag/plugins/k8saudit-ovh/v0.6.0 + - web: https://github.com/falcosecurity/plugins/releases/tag/plugins/k8saudit/v0.18.0 +source: + id: GHSA-jhjp-4c2q-xmx4 + created: 2026-09-22T10:10:20.276412-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6539.yaml b/data/reports/GO-2026-6539.yaml new file mode 100644 index 0000000..37e7ff4 --- /dev/null +++ b/data/reports/GO-2026-6539.yaml
@@ -0,0 +1,26 @@ +id: GO-2026-6539 +modules: + - module: github.com/lucasdillmann/nginx-ignition + versions: + - introduced: 0.0.0-20260126024607-cbaf0fc16ed8 + - fixed: 0.0.0-20260526022344-0c988fc1277c +summary: |- + nginx ignition has ParseAcceptLanguage `_` separator bypass that enables ~75x + CPU amplification via Accept-Language header in i18nMiddleware in github.com/lucasdillmann/nginx-ignition +cves: + - CVE-2026-61629 +ghsas: + - GHSA-jr34-h97m-9hpx +references: + - advisory: https://github.com/lucasdillmann/nginx-ignition/security/advisories/GHSA-jr34-h97m-9hpx + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-61629 + - fix: https://github.com/lucasdillmann/nginx-ignition/commit/0c988fc1277c7d291725e8373313f8486fa1b31a + - fix: https://github.com/lucasdillmann/nginx-ignition/commit/cbaf0fc16ed873f7178a2ca9b0d00a696e44b485 + - fix: https://github.com/lucasdillmann/nginx-ignition/pull/125 + - web: https://github.com/lucasdillmann/nginx-ignition/releases/tag/2.40.1 +notes: + - fix: 'github.com/lucasdillmann/nginx-ignition: could not add vulnerable_at: cannot auto-guess when fixed version is 0.0.0 pseudo-version' +source: + id: GHSA-jr34-h97m-9hpx + created: 2026-09-22T10:10:12.874761-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6540.yaml b/data/reports/GO-2026-6540.yaml new file mode 100644 index 0000000..d1757ce --- /dev/null +++ b/data/reports/GO-2026-6540.yaml
@@ -0,0 +1,23 @@ +id: GO-2026-6540 +modules: + - module: github.com/lucasdillmann/nginx-ignition + non_go_versions: + - fixed: 0.0.0-20260621194639-0586b4e55ab + vulnerable_at: 0.0.0-20260921012428-371de245b282 +summary: |- + nginx ignition has Unauthenticated Admin Account Creation via Onboarding Race + Condition in github.com/lucasdillmann/nginx-ignition +cves: + - CVE-2026-61628 +ghsas: + - GHSA-pxcx-fv34-x9p5 +references: + - advisory: https://github.com/lucasdillmann/nginx-ignition/security/advisories/GHSA-pxcx-fv34-x9p5 + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-61628 + - fix: https://github.com/lucasdillmann/nginx-ignition/commit/0586b4e55ab780676d3553a2592979dfa2fb0183 + - fix: https://github.com/lucasdillmann/nginx-ignition/pull/131 + - web: https://github.com/lucasdillmann/nginx-ignition/releases/tag/2.41.1 +source: + id: GHSA-pxcx-fv34-x9p5 + created: 2026-09-22T10:09:57.177936-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6541.yaml b/data/reports/GO-2026-6541.yaml new file mode 100644 index 0000000..9b0d660 --- /dev/null +++ b/data/reports/GO-2026-6541.yaml
@@ -0,0 +1,50 @@ +id: GO-2026-6541 +modules: + - module: github.com/grafana/grafana + non_go_versions: + - fixed: 1.9.2-0.20260616075434-82ef13993059 + vulnerable_at: 5.4.5+incompatible + - module: github.com/grafana/grafana + non_go_versions: + - introduced: 13.0.0 + vulnerable_at: 5.4.5+incompatible + - module: github.com/grafana/grafana + non_go_versions: + - introduced: 12.4.0 + vulnerable_at: 5.4.5+incompatible + - module: github.com/grafana/grafana + non_go_versions: + - introduced: 12.3.0 + vulnerable_at: 5.4.5+incompatible + - module: github.com/grafana/grafana + non_go_versions: + - introduced: 12.0.0 + vulnerable_at: 5.4.5+incompatible + - module: github.com/grafana/grafana + versions: + - introduced: 2.0.0-beta1+incompatible + vulnerable_at: 5.4.5+incompatible +summary: |- + Grafana: Pre-authentication denial of service in the public dashboard query + handler in github.com/grafana/grafana +cves: + - CVE-2026-42127 +ghsas: + - GHSA-3w66-95m3-8jxg +references: + - advisory: https://github.com/advisories/GHSA-3w66-95m3-8jxg + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-42127 + - fix: https://github.com/grafana/grafana/commit/82ef13993059351bf21de35b8488bbd9b42df4f4 + - fix: https://github.com/grafana/grafana/pull/125789 + - web: https://github.com/grafana/grafana/releases/tag/v11.6.15 + - web: https://github.com/grafana/grafana/releases/tag/v12.2.9 + - web: https://github.com/grafana/grafana/releases/tag/v12.3.7 + - web: https://github.com/grafana/grafana/releases/tag/v12.4.4 + - web: https://github.com/grafana/grafana/releases/tag/v13.0.2 + - web: https://grafana.com/security/security-advisories/cve-2026-42127 +notes: + - fix: 'module merge error: could not merge versions of module github.com/grafana/grafana: introduced and fixed versions must alternate' +source: + id: GHSA-3w66-95m3-8jxg + created: 2026-09-22T10:09:48.252869-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6542.yaml b/data/reports/GO-2026-6542.yaml new file mode 100644 index 0000000..ef32f7a --- /dev/null +++ b/data/reports/GO-2026-6542.yaml
@@ -0,0 +1,37 @@ +id: GO-2026-6542 +modules: + - module: github.com/grafana/grafana + non_go_versions: + - fixed: 1.9.2-0.20260616075434-82ef13993059 + vulnerable_at: 5.4.5+incompatible + - module: github.com/grafana/grafana + non_go_versions: + - introduced: 13.0.0 + vulnerable_at: 5.4.5+incompatible + - module: github.com/grafana/grafana + versions: + - introduced: 2.0.0-beta1+incompatible + vulnerable_at: 5.4.5+incompatible +summary: |- + Grafana geomap panel's XYZ tile layer has a sanitize-then-interpolate ordering + bug in github.com/grafana/grafana +cves: + - CVE-2026-9029 +ghsas: + - GHSA-9g84-39mm-q4p3 +references: + - advisory: https://github.com/advisories/GHSA-9g84-39mm-q4p3 + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-9029 + - fix: https://github.com/grafana/grafana/commit/3fcdbc5a6e5c955bd42bd3715dd03cbad2b078c1 + - fix: https://github.com/grafana/grafana/commit/42cdc39124912a8506a0c613c319c345aa950b29 + - fix: https://github.com/grafana/grafana/commit/82ef13993059351bf21de35b8488bbd9b42df4f4 + - fix: https://github.com/grafana/grafana/commit/dc695b9649530064e19c7c120bd6ebe104908e58 + - web: https://github.com/grafana/grafana/releases/tag/v12.4.4 + - web: https://github.com/grafana/grafana/releases/tag/v13.0.2 + - web: https://grafana.com/security/security-advisories/cve-2026-9029 +notes: + - fix: 'module merge error: could not merge versions of module github.com/grafana/grafana: introduced and fixed versions must alternate' +source: + id: GHSA-9g84-39mm-q4p3 + created: 2026-09-22T10:09:39.482191-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6543.yaml b/data/reports/GO-2026-6543.yaml new file mode 100644 index 0000000..61237bf --- /dev/null +++ b/data/reports/GO-2026-6543.yaml
@@ -0,0 +1,21 @@ +id: GO-2026-6543 +modules: + - module: github.com/ubuntu/adsys + non_go_versions: + - fixed: 0.16.3-0.20250318112551-8b1939f96d38 + vulnerable_at: 0.0.0-20201015075421-5a3d5de42f92 +summary: Canonical ADSys Uses a Less Trusted Source in github.com/ubuntu/adsys +cves: + - CVE-2026-12249 +ghsas: + - GHSA-crm4-q7v4-c2r2 +references: + - advisory: https://github.com/advisories/GHSA-crm4-q7v4-c2r2 + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-12249 + - fix: https://github.com/ubuntu/adsys/commit/8b1939f96d3827b4426eb06c1ced5bf317b0a99d + - web: https://github.com/ubuntu/adsys/releases/tag/v0.16.3 + - web: https://ubuntu.com/security/CVE-2026-12249 +source: + id: GHSA-crm4-q7v4-c2r2 + created: 2026-09-22T10:09:22.09677-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6544.yaml b/data/reports/GO-2026-6544.yaml new file mode 100644 index 0000000..612635f --- /dev/null +++ b/data/reports/GO-2026-6544.yaml
@@ -0,0 +1,55 @@ +id: GO-2026-6544 +modules: + - module: github.com/grafana/grafana + non_go_versions: + - fixed: 1.9.2-0.20260616075434-82ef13993059 + vulnerable_at: 5.4.5+incompatible + - module: github.com/grafana/grafana + non_go_versions: + - introduced: 12.4.0 + vulnerable_at: 5.4.5+incompatible + - module: github.com/grafana/grafana + non_go_versions: + - introduced: 13.0.0 + vulnerable_at: 5.4.5+incompatible + - module: github.com/grafana/grafana + non_go_versions: + - introduced: 12.3.0 + vulnerable_at: 5.4.5+incompatible + - module: github.com/grafana/grafana + non_go_versions: + - introduced: 12.0.0 + vulnerable_at: 5.4.5+incompatible + - module: github.com/grafana/grafana + versions: + - introduced: 2.0.0-beta1+incompatible + vulnerable_at: 5.4.5+incompatible +summary: |- + Grafana Loki datasource plugin's callResource handler contains a path traversal + vulnerability. in github.com/grafana/grafana +cves: + - CVE-2026-42129 +ghsas: + - GHSA-f74p-cwhp-x2wx +references: + - advisory: https://github.com/advisories/GHSA-f74p-cwhp-x2wx + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-42129 + - fix: https://github.com/grafana/grafana/commit/3fcdbc5a6e5c955bd42bd3715dd03cbad2b078c1 + - fix: https://github.com/grafana/grafana/commit/42cdc39124912a8506a0c613c319c345aa950b29 + - fix: https://github.com/grafana/grafana/commit/82ef13993059351bf21de35b8488bbd9b42df4f4 + - fix: https://github.com/grafana/grafana/commit/d27d2eba9c509d16f214d290436a6ad0bd9c6c01 + - fix: https://github.com/grafana/grafana/commit/dd5dc51681ff0133ddb2e206c2ea318713aeca16 + - fix: https://github.com/grafana/grafana/commit/eeb08ceb020c4381242d8400e5878044e9877505 + - fix: https://github.com/grafana/grafana/commit/f70d3e480274a5dbd12006338c393f4b05d441ca + - web: https://github.com/grafana/grafana/releases/tag/v11.6.15 + - web: https://github.com/grafana/grafana/releases/tag/v12.2.9 + - web: https://github.com/grafana/grafana/releases/tag/v12.3.7 + - web: https://github.com/grafana/grafana/releases/tag/v12.4.4 + - web: https://github.com/grafana/grafana/releases/tag/v13.0.2 + - web: https://grafana.com/security/security-advisories/cve-2026-42129 +notes: + - fix: 'module merge error: could not merge versions of module github.com/grafana/grafana: introduced and fixed versions must alternate' +source: + id: GHSA-f74p-cwhp-x2wx + created: 2026-09-22T10:09:12.50033-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6545.yaml b/data/reports/GO-2026-6545.yaml new file mode 100644 index 0000000..52d3de4 --- /dev/null +++ b/data/reports/GO-2026-6545.yaml
@@ -0,0 +1,53 @@ +id: GO-2026-6545 +modules: + - module: github.com/grafana/grafana + non_go_versions: + - fixed: 1.9.2-0.20260616075434-82ef13993059 + vulnerable_at: 5.4.5+incompatible + - module: github.com/grafana/grafana + non_go_versions: + - introduced: 12.4.0 + vulnerable_at: 5.4.5+incompatible + - module: github.com/grafana/grafana + non_go_versions: + - introduced: 13.0.0 + vulnerable_at: 5.4.5+incompatible + - module: github.com/grafana/grafana + non_go_versions: + - introduced: 12.3.0 + vulnerable_at: 5.4.5+incompatible + - module: github.com/grafana/grafana + non_go_versions: + - introduced: 12.0.0 + vulnerable_at: 5.4.5+incompatible + - module: github.com/grafana/grafana + versions: + - introduced: 2.0.0-beta1+incompatible + vulnerable_at: 5.4.5+incompatible +summary: 'Grafana: Path traversal in the Tempo and Loki data source plugins in github.com/grafana/grafana' +cves: + - CVE-2026-10601 +ghsas: + - GHSA-9493-h4f5-633x +references: + - advisory: https://github.com/advisories/GHSA-9493-h4f5-633x + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-10601 + - fix: https://github.com/grafana/grafana/commit/3fcdbc5a6e5c955bd42bd3715dd03cbad2b078c1 + - fix: https://github.com/grafana/grafana/commit/42cdc39124912a8506a0c613c319c345aa950b29 + - fix: https://github.com/grafana/grafana/commit/82ef13993059351bf21de35b8488bbd9b42df4f4 + - fix: https://github.com/grafana/grafana/commit/d27d2eba9c509d16f214d290436a6ad0bd9c6c01 + - fix: https://github.com/grafana/grafana/commit/dd5dc51681ff0133ddb2e206c2ea318713aeca16 + - fix: https://github.com/grafana/grafana/commit/f70d3e480274a5dbd12006338c393f4b05d441ca + - fix: https://github.com/grafana/grafana/pull/125789 + - web: https://github.com/grafana/grafana/releases/tag/v11.6.15 + - web: https://github.com/grafana/grafana/releases/tag/v12.2.9 + - web: https://github.com/grafana/grafana/releases/tag/v12.3.7 + - web: https://github.com/grafana/grafana/releases/tag/v12.4.4 + - web: https://github.com/grafana/grafana/releases/tag/v13.0.2 + - web: https://grafana.com/security/security-advisories/cve-2026-10601 +notes: + - fix: 'module merge error: could not merge versions of module github.com/grafana/grafana: introduced and fixed versions must alternate' +source: + id: GHSA-9493-h4f5-633x + created: 2026-09-22T10:06:46.262469-04:00 +review_status: UNREVIEWED