data/reports: add 40 reports

  - data/reports/GO-2026-6480.yaml
  - data/reports/GO-2026-6481.yaml
  - data/reports/GO-2026-6482.yaml
  - data/reports/GO-2026-6483.yaml
  - data/reports/GO-2026-6484.yaml
  - data/reports/GO-2026-6485.yaml
  - data/reports/GO-2026-6486.yaml
  - data/reports/GO-2026-6487.yaml
  - data/reports/GO-2026-6488.yaml
  - data/reports/GO-2026-6490.yaml
  - data/reports/GO-2026-6495.yaml
  - data/reports/GO-2026-6506.yaml
  - data/reports/GO-2026-6507.yaml
  - data/reports/GO-2026-6508.yaml
  - data/reports/GO-2026-6514.yaml
  - data/reports/GO-2026-6515.yaml
  - data/reports/GO-2026-6516.yaml
  - data/reports/GO-2026-6517.yaml
  - data/reports/GO-2026-6518.yaml
  - data/reports/GO-2026-6519.yaml
  - data/reports/GO-2026-6520.yaml
  - data/reports/GO-2026-6521.yaml
  - data/reports/GO-2026-6522.yaml
  - data/reports/GO-2026-6523.yaml
  - data/reports/GO-2026-6525.yaml
  - data/reports/GO-2026-6526.yaml
  - data/reports/GO-2026-6527.yaml
  - data/reports/GO-2026-6528.yaml
  - data/reports/GO-2026-6529.yaml
  - data/reports/GO-2026-6530.yaml
  - data/reports/GO-2026-6535.yaml
  - data/reports/GO-2026-6537.yaml
  - data/reports/GO-2026-6538.yaml
  - data/reports/GO-2026-6539.yaml
  - data/reports/GO-2026-6540.yaml
  - data/reports/GO-2026-6541.yaml
  - data/reports/GO-2026-6542.yaml
  - data/reports/GO-2026-6543.yaml
  - data/reports/GO-2026-6544.yaml
  - data/reports/GO-2026-6545.yaml

Fixes golang/vulndb#6480
Fixes golang/vulndb#6481
Fixes golang/vulndb#6482
Fixes golang/vulndb#6483
Fixes golang/vulndb#6484
Fixes golang/vulndb#6485
Fixes golang/vulndb#6486
Fixes golang/vulndb#6487
Fixes golang/vulndb#6488
Fixes golang/vulndb#6490
Fixes golang/vulndb#6495
Fixes golang/vulndb#6506
Fixes golang/vulndb#6507
Fixes golang/vulndb#6508
Fixes golang/vulndb#6514
Fixes golang/vulndb#6515
Fixes golang/vulndb#6516
Fixes golang/vulndb#6517
Fixes golang/vulndb#6518
Fixes golang/vulndb#6519
Fixes golang/vulndb#6520
Fixes golang/vulndb#6521
Fixes golang/vulndb#6522
Fixes golang/vulndb#6523
Fixes golang/vulndb#6525
Fixes golang/vulndb#6526
Fixes golang/vulndb#6527
Fixes golang/vulndb#6528
Fixes golang/vulndb#6529
Fixes golang/vulndb#6530
Fixes golang/vulndb#6535
Fixes golang/vulndb#6537
Fixes golang/vulndb#6538
Fixes golang/vulndb#6539
Fixes golang/vulndb#6540
Fixes golang/vulndb#6541
Fixes golang/vulndb#6542
Fixes golang/vulndb#6543
Fixes golang/vulndb#6544
Fixes golang/vulndb#6545

Change-Id: I5f379000ad20332286b7b886b59740a95f514fc2
Reviewed-on: https://go-review.googlesource.com/c/vulndb/+/836785
Reviewed-by: Neal Patel <nealpatel@google.com>
Auto-Submit: Ian Alexander <jitsu@google.com>
LUCI-TryBot-Result: golang-scoped@luci-project-accounts.iam.gserviceaccount.com <golang-scoped@luci-project-accounts.iam.gserviceaccount.com>
diff --git a/data/osv/GO-2026-6480.json b/data/osv/GO-2026-6480.json
new file mode 100644
index 0000000..2299a5c
--- /dev/null
+++ b/data/osv/GO-2026-6480.json
@@ -0,0 +1,70 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6480",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-5139",
+    "GHSA-2g8v-grq3-hq2g"
+  ],
+  "summary": "Mattermost doesn't enforce administrator authorization on the {{setDefaultInstance}} call within the {{/gitlab connect}} command handler in github.com/mattermost/mattermost-server",
+  "details": "Mattermost doesn't enforce administrator authorization on the {{setDefaultInstance}} call within the {{/gitlab connect}} command handler in github.com/mattermost/mattermost-server",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/mattermost/mattermost-server",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "10.11.0+incompatible"
+            },
+            {
+              "fixed": "10.11.18+incompatible"
+            },
+            {
+              "introduced": "11.5.0+incompatible"
+            },
+            {
+              "fixed": "11.5.6+incompatible"
+            },
+            {
+              "introduced": "11.6.0+incompatible"
+            },
+            {
+              "fixed": "11.6.3+incompatible"
+            },
+            {
+              "introduced": "11.7.0+incompatible"
+            },
+            {
+              "fixed": "11.7.1+incompatible"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/advisories/GHSA-2g8v-grq3-hq2g"
+    },
+    {
+      "type": "ADVISORY",
+      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-5139"
+    },
+    {
+      "type": "WEB",
+      "url": "https://mattermost.com/security-updates"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6480",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6481.json b/data/osv/GO-2026-6481.json
new file mode 100644
index 0000000..58e5652
--- /dev/null
+++ b/data/osv/GO-2026-6481.json
@@ -0,0 +1,58 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6481",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-8074",
+    "GHSA-g5vr-6pgg-74qv"
+  ],
+  "summary": "Mattermost doesn't enforce bot-specific permission checks on the user active status endpoint in github.com/mattermost/mattermost-server",
+  "details": "Mattermost doesn't enforce bot-specific permission checks on the user active status endpoint in github.com/mattermost/mattermost-server",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/mattermost/mattermost-server",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "10.11.0+incompatible"
+            },
+            {
+              "fixed": "10.11.18+incompatible"
+            },
+            {
+              "introduced": "11.7.0+incompatible"
+            },
+            {
+              "fixed": "11.7.1+incompatible"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/advisories/GHSA-g5vr-6pgg-74qv"
+    },
+    {
+      "type": "ADVISORY",
+      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-8074"
+    },
+    {
+      "type": "WEB",
+      "url": "https://mattermost.com/security-updates"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6481",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6482.json b/data/osv/GO-2026-6482.json
new file mode 100644
index 0000000..cb63c2a
--- /dev/null
+++ b/data/osv/GO-2026-6482.json
@@ -0,0 +1,70 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6482",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-9162",
+    "GHSA-h998-hxxj-8q83"
+  ],
+  "summary": "Mattermost doesn't invalidate cached authentication state for active WebSocket connections during global session revocation in github.com/mattermost/mattermost-server",
+  "details": "Mattermost doesn't invalidate cached authentication state for active WebSocket connections during global session revocation in github.com/mattermost/mattermost-server",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/mattermost/mattermost-server",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "10.11.0+incompatible"
+            },
+            {
+              "fixed": "10.11.18+incompatible"
+            },
+            {
+              "introduced": "11.5.0+incompatible"
+            },
+            {
+              "fixed": "11.5.6+incompatible"
+            },
+            {
+              "introduced": "11.6.0+incompatible"
+            },
+            {
+              "fixed": "11.6.3+incompatible"
+            },
+            {
+              "introduced": "11.7.0+incompatible"
+            },
+            {
+              "fixed": "11.7.1+incompatible"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/advisories/GHSA-h998-hxxj-8q83"
+    },
+    {
+      "type": "ADVISORY",
+      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-9162"
+    },
+    {
+      "type": "WEB",
+      "url": "https://mattermost.com/security-updates"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6482",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6483.json b/data/osv/GO-2026-6483.json
new file mode 100644
index 0000000..13a9178
--- /dev/null
+++ b/data/osv/GO-2026-6483.json
@@ -0,0 +1,70 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6483",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-6673",
+    "GHSA-jqgv-39mg-7c2r"
+  ],
+  "summary": "Mattermost doesn't authenticate Atlassian Connect installed callbacks, allowing a remote unauthenticated attacker to inject a rogue sharedSecret in github.com/mattermost/mattermost-server",
+  "details": "Mattermost doesn't authenticate Atlassian Connect installed callbacks, allowing a remote unauthenticated attacker to inject a rogue sharedSecret in github.com/mattermost/mattermost-server",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/mattermost/mattermost-server",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "10.11.0+incompatible"
+            },
+            {
+              "fixed": "10.11.18+incompatible"
+            },
+            {
+              "introduced": "11.5.0+incompatible"
+            },
+            {
+              "fixed": "11.5.6+incompatible"
+            },
+            {
+              "introduced": "11.6.0+incompatible"
+            },
+            {
+              "fixed": "11.6.3+incompatible"
+            },
+            {
+              "introduced": "11.7.0+incompatible"
+            },
+            {
+              "fixed": "11.7.1+incompatible"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/advisories/GHSA-jqgv-39mg-7c2r"
+    },
+    {
+      "type": "ADVISORY",
+      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6673"
+    },
+    {
+      "type": "WEB",
+      "url": "https://mattermost.com/security-updates"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6483",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6484.json b/data/osv/GO-2026-6484.json
new file mode 100644
index 0000000..003f53e
--- /dev/null
+++ b/data/osv/GO-2026-6484.json
@@ -0,0 +1,70 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6484",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-6062",
+    "GHSA-mxq2-5jpg-7474"
+  ],
+  "summary": "Mattermost doesn't validate channel ownership of an existing subscription before applying edits in github.com/mattermost/mattermost-server",
+  "details": "Mattermost doesn't validate channel ownership of an existing subscription before applying edits in github.com/mattermost/mattermost-server",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/mattermost/mattermost-server",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "10.11.0+incompatible"
+            },
+            {
+              "fixed": "10.11.18+incompatible"
+            },
+            {
+              "introduced": "11.5.0+incompatible"
+            },
+            {
+              "fixed": "11.5.6+incompatible"
+            },
+            {
+              "introduced": "11.6.0+incompatible"
+            },
+            {
+              "fixed": "11.6.3+incompatible"
+            },
+            {
+              "introduced": "11.7.0+incompatible"
+            },
+            {
+              "fixed": "11.7.1+incompatible"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/advisories/GHSA-mxq2-5jpg-7474"
+    },
+    {
+      "type": "ADVISORY",
+      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6062"
+    },
+    {
+      "type": "WEB",
+      "url": "https://mattermost.com/security-updates"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6484",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6485.json b/data/osv/GO-2026-6485.json
new file mode 100644
index 0000000..2536846
--- /dev/null
+++ b/data/osv/GO-2026-6485.json
@@ -0,0 +1,48 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6485",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-32599",
+    "GHSA-r8cr-4f9w-7r75"
+  ],
+  "summary": "Netmaker has a boolean‑based SQL Injection in github.com/gravitl/netmaker",
+  "details": "Netmaker has a boolean‑based SQL Injection in github.com/gravitl/netmaker",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/gravitl/netmaker",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "1.5.0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/gravitl/netmaker/security/advisories/GHSA-r8cr-4f9w-7r75"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/gravitl/netmaker/releases/tag/v1.5.0"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6485",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6486.json b/data/osv/GO-2026-6486.json
new file mode 100644
index 0000000..b0cf6dd
--- /dev/null
+++ b/data/osv/GO-2026-6486.json
@@ -0,0 +1,44 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6486",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "GHSA-rf68-8gjr-36q7"
+  ],
+  "summary": "Nezha: OAuth2 redirect_uri Host header injection regression when dashboard_host is empty in github.com/nezhahq/nezha",
+  "details": "Nezha: OAuth2 redirect_uri Host header injection regression when dashboard_host is empty in github.com/nezhahq/nezha",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/nezhahq/nezha",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/nezhahq/nezha/security/advisories/GHSA-rf68-8gjr-36q7"
+    },
+    {
+      "type": "FIX",
+      "url": "https://github.com/nezhahq/nezha/commit/38824dbc11a63964c5b9296ae4c68e62b34fa04b"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6486",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6487.json b/data/osv/GO-2026-6487.json
new file mode 100644
index 0000000..ad63f1e
--- /dev/null
+++ b/data/osv/GO-2026-6487.json
@@ -0,0 +1,48 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6487",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-61554",
+    "GHSA-4595-rvpx-4q34"
+  ],
+  "summary": "emp3r0r has an unauthenticated HTTP Polling DoS in github.com/jm33-m0/emp3r0r/core",
+  "details": "emp3r0r has an unauthenticated HTTP Polling DoS in github.com/jm33-m0/emp3r0r/core",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/jm33-m0/emp3r0r/core",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "0.0.0-20260531142011-aed3d81641ab"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/jm33-m0/emp3r0r/security/advisories/GHSA-4595-rvpx-4q34"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/jm33-m0/emp3r0r/releases/tag/v4.2.5"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6487",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6488.json b/data/osv/GO-2026-6488.json
new file mode 100644
index 0000000..ed83c4c
--- /dev/null
+++ b/data/osv/GO-2026-6488.json
@@ -0,0 +1,56 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6488",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-61709",
+    "GHSA-g3pg-frfm-pr2m"
+  ],
+  "summary": "OpenFGA: ListUsers returns a deliberately-excluded user when a `but not` exclusion under a type-bound wildcard is intersected (`and`) with another relation that also grants that user in github.com/openfga/openfga",
+  "details": "OpenFGA: ListUsers returns a deliberately-excluded user when a `but not` exclusion under a type-bound wildcard is intersected (`and`) with another relation that also grants that user in github.com/openfga/openfga",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/openfga/openfga",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "1.18.1"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/openfga/openfga/security/advisories/GHSA-g3pg-frfm-pr2m"
+    },
+    {
+      "type": "ADVISORY",
+      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-61709"
+    },
+    {
+      "type": "FIX",
+      "url": "https://github.com/openfga/openfga/commit/171806c93b86bca29e0212ceb8b6ee9c48eb9ac3"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/openfga/openfga/releases/tag/v1.18.1"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6488",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6490.json b/data/osv/GO-2026-6490.json
new file mode 100644
index 0000000..c88a28d
--- /dev/null
+++ b/data/osv/GO-2026-6490.json
@@ -0,0 +1,128 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6490",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-71485",
+    "GHSA-9468-v6mj-fppw"
+  ],
+  "summary": "Centrifugo: Client-forgeable headers emulation lets any client spoof headers forwarded to proxy backends in github.com/centrifugal/centrifugo",
+  "details": "Centrifugo: Client-forgeable headers emulation lets any client spoof headers forwarded to proxy backends in github.com/centrifugal/centrifugo",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/centrifugal/centrifugo",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    },
+    {
+      "package": {
+        "name": "github.com/centrifugal/centrifugo/v3",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    },
+    {
+      "package": {
+        "name": "github.com/centrifugal/centrifugo/v4",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    },
+    {
+      "package": {
+        "name": "github.com/centrifugal/centrifugo/v5",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    },
+    {
+      "package": {
+        "name": "github.com/centrifugal/centrifugo/v6",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "6.9.0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/centrifugal/centrifugo/security/advisories/GHSA-9468-v6mj-fppw"
+    },
+    {
+      "type": "ADVISORY",
+      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-71485"
+    },
+    {
+      "type": "FIX",
+      "url": "https://github.com/centrifugal/centrifugo/commit/84d38cea1dd2efa24375a148817a974c8727f4b0"
+    },
+    {
+      "type": "FIX",
+      "url": "https://github.com/centrifugal/centrifugo/pull/1182"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/centrifugal/centrifugo/releases/tag/v6.9.0"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6490",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6495.json b/data/osv/GO-2026-6495.json
new file mode 100644
index 0000000..7fba8e3
--- /dev/null
+++ b/data/osv/GO-2026-6495.json
@@ -0,0 +1,64 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6495",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-86043",
+    "GHSA-5gpm-rgj3-9q76"
+  ],
+  "summary": "Skipper has OPA body-authz bypass: truncated_body mitigation fails open on chunked/HTTP-2 (incomplete fix GHSA-8qqm-fp2q-v734) in github.com/zalando/skipper",
+  "details": "Skipper has OPA body-authz bypass: truncated_body mitigation fails open on chunked/HTTP-2 (incomplete fix GHSA-8qqm-fp2q-v734) in github.com/zalando/skipper",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/zalando/skipper",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "0.27.37"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/zalando/skipper/security/advisories/GHSA-5gpm-rgj3-9q76"
+    },
+    {
+      "type": "ADVISORY",
+      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86043"
+    },
+    {
+      "type": "FIX",
+      "url": "https://github.com/zalando/skipper/commit/2cfceabaa6ff0af65b312dcb9bcbe84691b9d507"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/zalando/skipper/releases/tag/v0.27.35"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/zalando/skipper/releases/tag/v0.27.37"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/zalando/skipper/tree/v0.27.35"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6495",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6506.json b/data/osv/GO-2026-6506.json
new file mode 100644
index 0000000..7f320bc
--- /dev/null
+++ b/data/osv/GO-2026-6506.json
@@ -0,0 +1,56 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6506",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-86003",
+    "GHSA-9gm5-9rfh-m6vx"
+  ],
+  "summary": "CoreDNS DoH/DoQ/gRPC bypass UPDATE rejection enforced on UDP/TCP in github.com/coredns/coredns",
+  "details": "CoreDNS DoH/DoQ/gRPC bypass UPDATE rejection enforced on UDP/TCP in github.com/coredns/coredns",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/coredns/coredns",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "1.14.7"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/coredns/coredns/security/advisories/GHSA-9gm5-9rfh-m6vx"
+    },
+    {
+      "type": "ADVISORY",
+      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86003"
+    },
+    {
+      "type": "FIX",
+      "url": "https://github.com/coredns/coredns/commit/530b0a5ff2ad68cc0421f10dd93568945cc671c9"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/coredns/coredns/releases/tag/v1.14.7"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6506",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6507.json b/data/osv/GO-2026-6507.json
new file mode 100644
index 0000000..4502b03
--- /dev/null
+++ b/data/osv/GO-2026-6507.json
@@ -0,0 +1,56 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6507",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-82399",
+    "GHSA-mrg3-qvqr-jw29"
+  ],
+  "summary": "CoreDNS: Unauthenticated memory exhaustion in custom transports in github.com/coredns/coredns",
+  "details": "CoreDNS: Unauthenticated memory exhaustion in custom transports in github.com/coredns/coredns",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/coredns/coredns",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "1.14.7"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/coredns/coredns/security/advisories/GHSA-mrg3-qvqr-jw29"
+    },
+    {
+      "type": "ADVISORY",
+      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-82399"
+    },
+    {
+      "type": "FIX",
+      "url": "https://github.com/coredns/coredns/commit/530b0a5ff2ad68cc0421f10dd93568945cc671c9"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/coredns/coredns/releases/tag/v1.14.7"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6507",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6508.json b/data/osv/GO-2026-6508.json
new file mode 100644
index 0000000..d00bf26
--- /dev/null
+++ b/data/osv/GO-2026-6508.json
@@ -0,0 +1,56 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6508",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-81871",
+    "GHSA-w34q-cm8f-9c5x"
+  ],
+  "summary": "OpenTelemetry-Go: Log gRPC exporter ignores env TLS certs, bypassing mTLS/pinning in go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc",
+  "details": "OpenTelemetry-Go: Log gRPC exporter ignores env TLS certs, bypassing mTLS/pinning in go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc",
+  "affected": [
+    {
+      "package": {
+        "name": "go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "0.21.0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/open-telemetry/opentelemetry-go/security/advisories/GHSA-w34q-cm8f-9c5x"
+    },
+    {
+      "type": "ADVISORY",
+      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-81871"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/open-telemetry/opentelemetry-go/commit/c65d435b43e5e6b82310e6b18dd4cdcb8ac63a0c"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/open-telemetry/opentelemetry-go/releases/tag/exporters/otlp/otlplog/otlploggrpc/v0.21.0"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6508",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6514.json b/data/osv/GO-2026-6514.json
new file mode 100644
index 0000000..f569580
--- /dev/null
+++ b/data/osv/GO-2026-6514.json
@@ -0,0 +1,52 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6514",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-63199",
+    "GHSA-4227-9989-jrhx"
+  ],
+  "summary": "Perses's missing authorization in datasource proxy allows cross-scope secret disclosure in github.com/perses/perses",
+  "details": "Perses's missing authorization in datasource proxy allows cross-scope secret disclosure in github.com/perses/perses",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/perses/perses",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0.43.0"
+            },
+            {
+              "fixed": "0.54.0-rc.0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/perses/perses/security/advisories/GHSA-4227-9989-jrhx"
+    },
+    {
+      "type": "FIX",
+      "url": "https://github.com/perses/perses/commit/2368c9ef4eb0a70fbca5df69aa20e595821ab625"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/perses/perses/releases/tag/v0.54.0-rc.0"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6514",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6515.json b/data/osv/GO-2026-6515.json
new file mode 100644
index 0000000..60ac406
--- /dev/null
+++ b/data/osv/GO-2026-6515.json
@@ -0,0 +1,52 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6515",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-77339",
+    "GHSA-5gm3-9crp-6g3v"
+  ],
+  "summary": "Process Compose: Browser DNS rebinding lets websites control local process-compose MCP tools in github.com/f1bonacc1/process-compose",
+  "details": "Process Compose: Browser DNS rebinding lets websites control local process-compose MCP tools in github.com/f1bonacc1/process-compose",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/f1bonacc1/process-compose",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "1.120.0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/F1bonacc1/process-compose/security/advisories/GHSA-5gm3-9crp-6g3v"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/F1bonacc1/process-compose/commit/6ffa74f462cd2fa4f8dc1ee63c70b793b298c858"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/F1bonacc1/process-compose/releases/tag/v1.120.0"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6515",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6516.json b/data/osv/GO-2026-6516.json
new file mode 100644
index 0000000..5c79534
--- /dev/null
+++ b/data/osv/GO-2026-6516.json
@@ -0,0 +1,63 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6516",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-63405",
+    "GHSA-5p54-whvp-x327"
+  ],
+  "summary": "AnyCable: Pusher REST API Does Not Verify Request Body MD5 Enabling Signed-Request Replay with Arbitrary Body in github.com/anycable/anycable-go",
+  "details": "AnyCable: Pusher REST API Does Not Verify Request Body MD5 Enabling Signed-Request Replay with Arbitrary Body in github.com/anycable/anycable-go.\n\nNOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.\n\n(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)\n\nThe additional affected modules and versions are: github.com/anycable/anycable-go before v1.6.15.",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/anycable/anycable-go",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {
+        "custom_ranges": [
+          {
+            "type": "ECOSYSTEM",
+            "events": [
+              {
+                "introduced": "0"
+              },
+              {
+                "fixed": "1.6.15"
+              }
+            ]
+          }
+        ]
+      }
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/anycable/anycable/security/advisories/GHSA-5p54-whvp-x327"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/anycable/anycable/commit/d2cbadec792f038f4695c84a65c0d957b0fde72c"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/anycable/anycable/releases/tag/v1.6.15"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6516",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6517.json b/data/osv/GO-2026-6517.json
new file mode 100644
index 0000000..ef2f57a
--- /dev/null
+++ b/data/osv/GO-2026-6517.json
@@ -0,0 +1,62 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6517",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-61682",
+    "GHSA-c8w2-fgvx-vhv4"
+  ],
+  "summary": "kcp front-proxy does not strip inbound X-Remote-* identity headers, allowing any authenticated client to inject groups/warrants and impersonate system:masters in any workspace in github.com/kcp-dev/kcp",
+  "details": "kcp front-proxy does not strip inbound X-Remote-* identity headers, allowing any authenticated client to inject groups/warrants and impersonate system:masters in any workspace in github.com/kcp-dev/kcp",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/kcp-dev/kcp",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "0.31.4"
+            },
+            {
+              "introduced": "0.32.0"
+            },
+            {
+              "fixed": "0.32.2"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/kcp-dev/kcp/security/advisories/GHSA-c8w2-fgvx-vhv4"
+    },
+    {
+      "type": "FIX",
+      "url": "https://github.com/kcp-dev/kcp/commit/7437cdcfec8f927d1a9bf1b2dd1e075d038e27ca"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/kcp-dev/kcp/releases/tag/v0.31.4"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/kcp-dev/kcp/releases/tag/v0.32.2"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6517",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6518.json b/data/osv/GO-2026-6518.json
new file mode 100644
index 0000000..dd1bbb5
--- /dev/null
+++ b/data/osv/GO-2026-6518.json
@@ -0,0 +1,52 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6518",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-63458",
+    "GHSA-cjgj-2fwf-4c2w"
+  ],
+  "summary": "Perses's project query parameter authorization bypass exposes cross-project resources in github.com/perses/perses",
+  "details": "Perses's project query parameter authorization bypass exposes cross-project resources in github.com/perses/perses",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/perses/perses",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "0.54.0-beta.3"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/perses/perses/security/advisories/GHSA-cjgj-2fwf-4c2w"
+    },
+    {
+      "type": "FIX",
+      "url": "https://github.com/perses/perses/commit/8015fb340bdc625953e73a7a688be5b939159540"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/perses/perses/releases/tag/v0.54.0-beta.3"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6518",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6519.json b/data/osv/GO-2026-6519.json
new file mode 100644
index 0000000..c58dac3
--- /dev/null
+++ b/data/osv/GO-2026-6519.json
@@ -0,0 +1,56 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6519",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-61795",
+    "GHSA-f94q-w3w8-cj67"
+  ],
+  "summary": "Capsule: hostnameRegexHandler.OnUpdate validates stale (old) Tenant regex, allowing invalid AllowedHostnames regex to bypass webhook validation in github.com/projectcapsule/capsule",
+  "details": "Capsule: hostnameRegexHandler.OnUpdate validates stale (old) Tenant regex, allowing invalid AllowedHostnames regex to bypass webhook validation in github.com/projectcapsule/capsule",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/projectcapsule/capsule",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0.13.0"
+            },
+            {
+              "fixed": "0.13.7"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/projectcapsule/capsule/security/advisories/GHSA-f94q-w3w8-cj67"
+    },
+    {
+      "type": "FIX",
+      "url": "https://github.com/projectcapsule/capsule/commit/8d89d6865df6f41c7faa22fc9e807a57b01bfd0e"
+    },
+    {
+      "type": "FIX",
+      "url": "https://github.com/projectcapsule/capsule/pull/1983"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/projectcapsule/capsule/releases/tag/v0.13.7"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6519",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6520.json b/data/osv/GO-2026-6520.json
new file mode 100644
index 0000000..58f6ca1
--- /dev/null
+++ b/data/osv/GO-2026-6520.json
@@ -0,0 +1,56 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6520",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-61672",
+    "GHSA-gjw4-3v3v-rqxg"
+  ],
+  "summary": "Capsule: Tenant owner bypasses Capsule's forbidden namespace/service/node label and annotation enforcement in github.com/projectcapsule/capsule",
+  "details": "Capsule: Tenant owner bypasses Capsule's forbidden namespace/service/node label and annotation enforcement in github.com/projectcapsule/capsule",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/projectcapsule/capsule",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "0.13.7"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/projectcapsule/capsule/security/advisories/GHSA-gjw4-3v3v-rqxg"
+    },
+    {
+      "type": "FIX",
+      "url": "https://github.com/projectcapsule/capsule/commit/755cef54bf4a1bc56d6692130132bc70755bef46"
+    },
+    {
+      "type": "FIX",
+      "url": "https://github.com/projectcapsule/capsule/pull/1982"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/projectcapsule/capsule/releases/tag/v0.13.7"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6520",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6521.json b/data/osv/GO-2026-6521.json
new file mode 100644
index 0000000..96651ad
--- /dev/null
+++ b/data/osv/GO-2026-6521.json
@@ -0,0 +1,56 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6521",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-61794",
+    "GHSA-gxjc-74v5-3vx3"
+  ],
+  "summary": "Capsule: Malformed ForbiddenAnnotations.Regex can bypass Tenant validation and trigger namespace admission panic in github.com/projectcapsule/capsule",
+  "details": "Capsule: Malformed ForbiddenAnnotations.Regex can bypass Tenant validation and trigger namespace admission panic in github.com/projectcapsule/capsule",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/projectcapsule/capsule",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0.13.0"
+            },
+            {
+              "fixed": "0.13.7"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/projectcapsule/capsule/security/advisories/GHSA-gxjc-74v5-3vx3"
+    },
+    {
+      "type": "FIX",
+      "url": "https://github.com/projectcapsule/capsule/commit/8d89d6865df6f41c7faa22fc9e807a57b01bfd0e"
+    },
+    {
+      "type": "FIX",
+      "url": "https://github.com/projectcapsule/capsule/pull/1983"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/projectcapsule/capsule/releases/tag/v0.13.7"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6521",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6522.json b/data/osv/GO-2026-6522.json
new file mode 100644
index 0000000..919f6a4
--- /dev/null
+++ b/data/osv/GO-2026-6522.json
@@ -0,0 +1,47 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6522",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "GHSA-jgh3-fggc-mcpm"
+  ],
+  "summary": "Obot: Server-Side Request Forgery via remote MCP server URL in github.com/obot-platform/obot",
+  "details": "Obot: Server-Side Request Forgery via remote MCP server URL in github.com/obot-platform/obot",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/obot-platform/obot",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "0.23.0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/obot-platform/obot/security/advisories/GHSA-jgh3-fggc-mcpm"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/obot-platform/obot/releases/tag/v0.23.0"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6522",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6523.json b/data/osv/GO-2026-6523.json
new file mode 100644
index 0000000..7f40168
--- /dev/null
+++ b/data/osv/GO-2026-6523.json
@@ -0,0 +1,56 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6523",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-81505",
+    "GHSA-p5vg-v7mj-f6q4"
+  ],
+  "summary": "Convoy: Cross-Tenant Source IDOR Leaks Plaintext Message Broker Credentials in github.com/frain-dev/convoy",
+  "details": "Convoy: Cross-Tenant Source IDOR Leaks Plaintext Message Broker Credentials in github.com/frain-dev/convoy",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/frain-dev/convoy",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "0.9.3-0.20260724092134-1cc67cd16fb1"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/frain-dev/convoy/security/advisories/GHSA-p5vg-v7mj-f6q4"
+    },
+    {
+      "type": "FIX",
+      "url": "https://github.com/frain-dev/convoy/commit/1cc67cd16fb1f8890cc83a3998d3f92dceb7fd06"
+    },
+    {
+      "type": "FIX",
+      "url": "https://github.com/frain-dev/convoy/pull/2755"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/frain-dev/convoy/releases/tag/v26.6.8"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6523",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6525.json b/data/osv/GO-2026-6525.json
new file mode 100644
index 0000000..e01f894
--- /dev/null
+++ b/data/osv/GO-2026-6525.json
@@ -0,0 +1,47 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6525",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "GHSA-pr6h-vr44-xq8j"
+  ],
+  "summary": "Obot: MCP Registry API readable without authentication in github.com/obot-platform/obot",
+  "details": "Obot: MCP Registry API readable without authentication in github.com/obot-platform/obot",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/obot-platform/obot",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "0.23.0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/obot-platform/obot/security/advisories/GHSA-pr6h-vr44-xq8j"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/obot-platform/obot/releases/tag/v0.23.0"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6525",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6526.json b/data/osv/GO-2026-6526.json
new file mode 100644
index 0000000..7987584
--- /dev/null
+++ b/data/osv/GO-2026-6526.json
@@ -0,0 +1,68 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6526",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-58197",
+    "GHSA-qg2g-g9w3-m5h8"
+  ],
+  "summary": "ToolHive: containerized MCP servers can reach host services via host.docker.internal, enabling lateral movement in github.com/stacklok/toolhive",
+  "details": "ToolHive: containerized MCP servers can reach host services via host.docker.internal, enabling lateral movement in github.com/stacklok/toolhive",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/stacklok/toolhive",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "0.30.1"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/stacklok/toolhive/security/advisories/GHSA-qg2g-g9w3-m5h8"
+    },
+    {
+      "type": "FIX",
+      "url": "https://github.com/stacklok/toolhive/commit/d8f40cb1599b8bf66657f2dfff15bfbfc236e712"
+    },
+    {
+      "type": "FIX",
+      "url": "https://github.com/stacklok/toolhive/pull/5583"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/stacklok/toolhive-studio/commit/968182d7f3ee1e55123369e66ad88f82128119b0"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/stacklok/toolhive-studio/pull/2469"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/stacklok/toolhive-studio/releases/tag/v0.38.0"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/stacklok/toolhive/releases/tag/v0.30.1"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6526",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6527.json b/data/osv/GO-2026-6527.json
new file mode 100644
index 0000000..4b417d3
--- /dev/null
+++ b/data/osv/GO-2026-6527.json
@@ -0,0 +1,73 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6527",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-61833",
+    "GHSA-qg67-7m6v-qg25"
+  ],
+  "summary": "zot: Bearer authentication maps DELETE to push scope, allowing unauthorized deletion in zotregistry.dev/zot",
+  "details": "zot: Bearer authentication maps DELETE to push scope, allowing unauthorized deletion in zotregistry.dev/zot",
+  "affected": [
+    {
+      "package": {
+        "name": "zotregistry.dev/zot",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    },
+    {
+      "package": {
+        "name": "zotregistry.dev/zot/v2",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "2.1.18"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/project-zot/zot/security/advisories/GHSA-qg67-7m6v-qg25"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/project-zot/zot/commit/7bb211bcd4352b90f3e99752607fbd1f050bf7ca"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/project-zot/zot/pull/4161"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/project-zot/zot/releases/tag/v2.1.18"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6527",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6528.json b/data/osv/GO-2026-6528.json
new file mode 100644
index 0000000..0b80ce4
--- /dev/null
+++ b/data/osv/GO-2026-6528.json
@@ -0,0 +1,52 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6528",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-63445",
+    "GHSA-vr5f-w35q-98jp"
+  ],
+  "summary": "Perses's unvalidated project parameter enables filesystem path traversal in github.com/perses/perses",
+  "details": "Perses's unvalidated project parameter enables filesystem path traversal in github.com/perses/perses",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/perses/perses",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "0.54.0-rc.0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/perses/perses/security/advisories/GHSA-vr5f-w35q-98jp"
+    },
+    {
+      "type": "FIX",
+      "url": "https://github.com/perses/perses/commit/75e5471040ccb5674ea8d25c2aa16c80ccb70b2a"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/perses/perses/releases/tag/v0.54.0-rc.0"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6528",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6529.json b/data/osv/GO-2026-6529.json
new file mode 100644
index 0000000..c6bdc15
--- /dev/null
+++ b/data/osv/GO-2026-6529.json
@@ -0,0 +1,63 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6529",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-63406",
+    "GHSA-w72w-9qmj-c9qm"
+  ],
+  "summary": "AnyCable: Telemetry Subsystem Contains Hardcoded Authentication Token and Transmits CLI Arguments Including Secrets in github.com/anycable/anycable-go",
+  "details": "AnyCable: Telemetry Subsystem Contains Hardcoded Authentication Token and Transmits CLI Arguments Including Secrets in github.com/anycable/anycable-go.\n\nNOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.\n\n(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)\n\nThe additional affected modules and versions are: github.com/anycable/anycable-go before v1.6.15.",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/anycable/anycable-go",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {
+        "custom_ranges": [
+          {
+            "type": "ECOSYSTEM",
+            "events": [
+              {
+                "introduced": "0"
+              },
+              {
+                "fixed": "1.6.15"
+              }
+            ]
+          }
+        ]
+      }
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/anycable/anycable/security/advisories/GHSA-w72w-9qmj-c9qm"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/anycable/anycable/commit/201c67e99e463ed63bd6b345562f4c458385fcee"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/anycable/anycable/releases/tag/v1.6.15"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6529",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6530.json b/data/osv/GO-2026-6530.json
new file mode 100644
index 0000000..7dba75b
--- /dev/null
+++ b/data/osv/GO-2026-6530.json
@@ -0,0 +1,47 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6530",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "GHSA-xwmw-prc4-v3cr"
+  ],
+  "summary": "Obot: OAuth Dynamic Client Registration Enables API Token Theft via Audience Confusion in github.com/obot-platform/obot",
+  "details": "Obot: OAuth Dynamic Client Registration Enables API Token Theft via Audience Confusion in github.com/obot-platform/obot",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/obot-platform/obot",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "0.23.0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/obot-platform/obot/security/advisories/GHSA-xwmw-prc4-v3cr"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/obot-platform/obot/releases/tag/v0.23.0"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6530",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6535.json b/data/osv/GO-2026-6535.json
new file mode 100644
index 0000000..c3f110f
--- /dev/null
+++ b/data/osv/GO-2026-6535.json
@@ -0,0 +1,67 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6535",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-61687",
+    "GHSA-phg3-3g28-wq9v"
+  ],
+  "summary": "Hatchet - Unauthenticated OAuth state CSRF / login-CSRF via empty-state collision in ValidateOAuthState in hatchet in github.com/hatchet-dev/hatchet",
+  "details": "Hatchet - Unauthenticated OAuth state CSRF / login-CSRF via empty-state collision in ValidateOAuthState in hatchet in github.com/hatchet-dev/hatchet.\n\nNOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.\n\n(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)\n\nThe additional affected modules and versions are: github.com/hatchet-dev/hatchet before v0.91.1.",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/hatchet-dev/hatchet",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {
+        "imports": [
+          {
+            "path": "github.com/hatchet-dev/hatchet/api/v1/server/authn",
+            "symbols": [
+              "SessionHelpers.ValidateOAuthState"
+            ]
+          }
+        ],
+        "custom_ranges": [
+          {
+            "type": "ECOSYSTEM",
+            "events": [
+              {
+                "introduced": "0"
+              },
+              {
+                "fixed": "0.91.1"
+              }
+            ]
+          }
+        ]
+      }
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/hatchet-dev/hatchet/security/advisories/GHSA-phg3-3g28-wq9v"
+    },
+    {
+      "type": "FIX",
+      "url": "https://github.com/hatchet-dev/hatchet/commit/f90464189ad642251e09412d0f99fde353036428"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6535",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6537.json b/data/osv/GO-2026-6537.json
new file mode 100644
index 0000000..32eba13
--- /dev/null
+++ b/data/osv/GO-2026-6537.json
@@ -0,0 +1,68 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6537",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-61630",
+    "GHSA-hf33-q6cf-c66f"
+  ],
+  "summary": "nginx ignition has TOTP Reuse During Validity Window in github.com/lucasdillmann/nginx-ignition",
+  "details": "nginx ignition has TOTP Reuse During Validity Window in github.com/lucasdillmann/nginx-ignition",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/lucasdillmann/nginx-ignition",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0.0.0-20260217145239-1cbfae0296f1"
+            },
+            {
+              "fixed": "0.0.0-20260328015550-8d35e1eb5dd6"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/lucasdillmann/nginx-ignition/security/advisories/GHSA-hf33-q6cf-c66f"
+    },
+    {
+      "type": "ADVISORY",
+      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-61630"
+    },
+    {
+      "type": "FIX",
+      "url": "https://github.com/lucasdillmann/nginx-ignition/commit/1cbfae0296f1b186158f5a294ec484060e00102e"
+    },
+    {
+      "type": "FIX",
+      "url": "https://github.com/lucasdillmann/nginx-ignition/commit/8d35e1eb5dd6a40fef94a45511fe08b0603af107"
+    },
+    {
+      "type": "FIX",
+      "url": "https://github.com/lucasdillmann/nginx-ignition/pull/104"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/lucasdillmann/nginx-ignition/releases/tag/2.35.1"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/pquerna/otp/issues/61"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6537",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6538.json b/data/osv/GO-2026-6538.json
new file mode 100644
index 0000000..89f7a5b
--- /dev/null
+++ b/data/osv/GO-2026-6538.json
@@ -0,0 +1,151 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6538",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "GHSA-jhjp-4c2q-xmx4"
+  ],
+  "summary": "k8saudit shipped rules do not detect privileged/sensitive settings on init or ephemeral containers in github.com/falcosecurity/plugins/plugins/k8saudit",
+  "details": "k8saudit shipped rules do not detect privileged/sensitive settings on init or ephemeral containers in github.com/falcosecurity/plugins/plugins/k8saudit",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/falcosecurity/plugins/plugins/k8saudit",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "0.18.0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    },
+    {
+      "package": {
+        "name": "github.com/falcosecurity/plugins/plugins/k8saudit-aks",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "0.6.0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    },
+    {
+      "package": {
+        "name": "github.com/falcosecurity/plugins/plugins/k8saudit-eks",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "0.12.0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    },
+    {
+      "package": {
+        "name": "github.com/falcosecurity/plugins/plugins/k8saudit-gke",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "0.9.0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    },
+    {
+      "package": {
+        "name": "github.com/falcosecurity/plugins/plugins/k8saudit-ovh",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "0.6.0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/falcosecurity/plugins/security/advisories/GHSA-jhjp-4c2q-xmx4"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/falcosecurity/plugins/commit/0adb9b3c7e2c8bad53f30d01c057e038b2afa5e1"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/falcosecurity/plugins/pull/1400"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/falcosecurity/plugins/releases/tag/plugins/k8saudit-aks/v0.6.0"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/falcosecurity/plugins/releases/tag/plugins/k8saudit-eks/v0.12.0"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/falcosecurity/plugins/releases/tag/plugins/k8saudit-gke/v0.9.0"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/falcosecurity/plugins/releases/tag/plugins/k8saudit-ovh/v0.6.0"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/falcosecurity/plugins/releases/tag/plugins/k8saudit/v0.18.0"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6538",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6539.json b/data/osv/GO-2026-6539.json
new file mode 100644
index 0000000..0197de3
--- /dev/null
+++ b/data/osv/GO-2026-6539.json
@@ -0,0 +1,64 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6539",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-61629",
+    "GHSA-jr34-h97m-9hpx"
+  ],
+  "summary": "nginx ignition has ParseAcceptLanguage `_` separator bypass that enables ~75x CPU amplification via Accept-Language header in i18nMiddleware in github.com/lucasdillmann/nginx-ignition",
+  "details": "nginx ignition has ParseAcceptLanguage `_` separator bypass that enables ~75x CPU amplification via Accept-Language header in i18nMiddleware in github.com/lucasdillmann/nginx-ignition",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/lucasdillmann/nginx-ignition",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0.0.0-20260126024607-cbaf0fc16ed8"
+            },
+            {
+              "fixed": "0.0.0-20260526022344-0c988fc1277c"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/lucasdillmann/nginx-ignition/security/advisories/GHSA-jr34-h97m-9hpx"
+    },
+    {
+      "type": "ADVISORY",
+      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-61629"
+    },
+    {
+      "type": "FIX",
+      "url": "https://github.com/lucasdillmann/nginx-ignition/commit/0c988fc1277c7d291725e8373313f8486fa1b31a"
+    },
+    {
+      "type": "FIX",
+      "url": "https://github.com/lucasdillmann/nginx-ignition/commit/cbaf0fc16ed873f7178a2ca9b0d00a696e44b485"
+    },
+    {
+      "type": "FIX",
+      "url": "https://github.com/lucasdillmann/nginx-ignition/pull/125"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/lucasdillmann/nginx-ignition/releases/tag/2.40.1"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6539",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6540.json b/data/osv/GO-2026-6540.json
new file mode 100644
index 0000000..6c1d697
--- /dev/null
+++ b/data/osv/GO-2026-6540.json
@@ -0,0 +1,71 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6540",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-61628",
+    "GHSA-pxcx-fv34-x9p5"
+  ],
+  "summary": "nginx ignition has Unauthenticated Admin Account Creation via Onboarding Race Condition in github.com/lucasdillmann/nginx-ignition",
+  "details": "nginx ignition has Unauthenticated Admin Account Creation via Onboarding Race Condition in github.com/lucasdillmann/nginx-ignition.\n\nNOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.\n\n(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)\n\nThe additional affected modules and versions are: github.com/lucasdillmann/nginx-ignition before v0.0.0-20260621194639-0586b4e55ab.",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/lucasdillmann/nginx-ignition",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {
+        "custom_ranges": [
+          {
+            "type": "ECOSYSTEM",
+            "events": [
+              {
+                "introduced": "0"
+              },
+              {
+                "fixed": "0.0.0-20260621194639-0586b4e55ab"
+              }
+            ]
+          }
+        ]
+      }
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/lucasdillmann/nginx-ignition/security/advisories/GHSA-pxcx-fv34-x9p5"
+    },
+    {
+      "type": "ADVISORY",
+      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-61628"
+    },
+    {
+      "type": "FIX",
+      "url": "https://github.com/lucasdillmann/nginx-ignition/commit/0586b4e55ab780676d3553a2592979dfa2fb0183"
+    },
+    {
+      "type": "FIX",
+      "url": "https://github.com/lucasdillmann/nginx-ignition/pull/131"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/lucasdillmann/nginx-ignition/releases/tag/2.41.1"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6540",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6541.json b/data/osv/GO-2026-6541.json
new file mode 100644
index 0000000..6db56c8
--- /dev/null
+++ b/data/osv/GO-2026-6541.json
@@ -0,0 +1,220 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6541",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-42127",
+    "GHSA-3w66-95m3-8jxg"
+  ],
+  "summary": "Grafana: Pre-authentication denial of service in the public dashboard query handler in github.com/grafana/grafana",
+  "details": "Grafana: Pre-authentication denial of service in the public dashboard query handler in github.com/grafana/grafana.\n\nNOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.\n\n(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)\n\nThe additional affected modules and versions are: github.com/grafana/grafana before v1.9.2-0.20260616075434-82ef13993059.",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/grafana/grafana",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {
+        "custom_ranges": [
+          {
+            "type": "ECOSYSTEM",
+            "events": [
+              {
+                "introduced": "0"
+              },
+              {
+                "fixed": "1.9.2-0.20260616075434-82ef13993059"
+              }
+            ]
+          }
+        ]
+      }
+    },
+    {
+      "package": {
+        "name": "github.com/grafana/grafana",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {
+        "custom_ranges": [
+          {
+            "type": "ECOSYSTEM",
+            "events": [
+              {
+                "introduced": "13.0.0"
+              }
+            ]
+          }
+        ]
+      }
+    },
+    {
+      "package": {
+        "name": "github.com/grafana/grafana",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {
+        "custom_ranges": [
+          {
+            "type": "ECOSYSTEM",
+            "events": [
+              {
+                "introduced": "12.4.0"
+              }
+            ]
+          }
+        ]
+      }
+    },
+    {
+      "package": {
+        "name": "github.com/grafana/grafana",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {
+        "custom_ranges": [
+          {
+            "type": "ECOSYSTEM",
+            "events": [
+              {
+                "introduced": "12.3.0"
+              }
+            ]
+          }
+        ]
+      }
+    },
+    {
+      "package": {
+        "name": "github.com/grafana/grafana",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {
+        "custom_ranges": [
+          {
+            "type": "ECOSYSTEM",
+            "events": [
+              {
+                "introduced": "12.0.0"
+              }
+            ]
+          }
+        ]
+      }
+    },
+    {
+      "package": {
+        "name": "github.com/grafana/grafana",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "2.0.0-beta1+incompatible"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/advisories/GHSA-3w66-95m3-8jxg"
+    },
+    {
+      "type": "ADVISORY",
+      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42127"
+    },
+    {
+      "type": "FIX",
+      "url": "https://github.com/grafana/grafana/commit/82ef13993059351bf21de35b8488bbd9b42df4f4"
+    },
+    {
+      "type": "FIX",
+      "url": "https://github.com/grafana/grafana/pull/125789"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/grafana/grafana/releases/tag/v11.6.15"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/grafana/grafana/releases/tag/v12.2.9"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/grafana/grafana/releases/tag/v12.3.7"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/grafana/grafana/releases/tag/v12.4.4"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/grafana/grafana/releases/tag/v13.0.2"
+    },
+    {
+      "type": "WEB",
+      "url": "https://grafana.com/security/security-advisories/cve-2026-42127"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6541",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6542.json b/data/osv/GO-2026-6542.json
new file mode 100644
index 0000000..b68c83d
--- /dev/null
+++ b/data/osv/GO-2026-6542.json
@@ -0,0 +1,132 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6542",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-9029",
+    "GHSA-9g84-39mm-q4p3"
+  ],
+  "summary": "Grafana geomap panel's XYZ tile layer has a sanitize-then-interpolate ordering bug in github.com/grafana/grafana",
+  "details": "Grafana geomap panel's XYZ tile layer has a sanitize-then-interpolate ordering bug in github.com/grafana/grafana.\n\nNOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.\n\n(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)\n\nThe additional affected modules and versions are: github.com/grafana/grafana before v1.9.2-0.20260616075434-82ef13993059.",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/grafana/grafana",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {
+        "custom_ranges": [
+          {
+            "type": "ECOSYSTEM",
+            "events": [
+              {
+                "introduced": "0"
+              },
+              {
+                "fixed": "1.9.2-0.20260616075434-82ef13993059"
+              }
+            ]
+          }
+        ]
+      }
+    },
+    {
+      "package": {
+        "name": "github.com/grafana/grafana",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {
+        "custom_ranges": [
+          {
+            "type": "ECOSYSTEM",
+            "events": [
+              {
+                "introduced": "13.0.0"
+              }
+            ]
+          }
+        ]
+      }
+    },
+    {
+      "package": {
+        "name": "github.com/grafana/grafana",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "2.0.0-beta1+incompatible"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/advisories/GHSA-9g84-39mm-q4p3"
+    },
+    {
+      "type": "ADVISORY",
+      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-9029"
+    },
+    {
+      "type": "FIX",
+      "url": "https://github.com/grafana/grafana/commit/3fcdbc5a6e5c955bd42bd3715dd03cbad2b078c1"
+    },
+    {
+      "type": "FIX",
+      "url": "https://github.com/grafana/grafana/commit/42cdc39124912a8506a0c613c319c345aa950b29"
+    },
+    {
+      "type": "FIX",
+      "url": "https://github.com/grafana/grafana/commit/82ef13993059351bf21de35b8488bbd9b42df4f4"
+    },
+    {
+      "type": "FIX",
+      "url": "https://github.com/grafana/grafana/commit/dc695b9649530064e19c7c120bd6ebe104908e58"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/grafana/grafana/releases/tag/v12.4.4"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/grafana/grafana/releases/tag/v13.0.2"
+    },
+    {
+      "type": "WEB",
+      "url": "https://grafana.com/security/security-advisories/cve-2026-9029"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6542",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6543.json b/data/osv/GO-2026-6543.json
new file mode 100644
index 0000000..534fafd
--- /dev/null
+++ b/data/osv/GO-2026-6543.json
@@ -0,0 +1,71 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6543",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-12249",
+    "GHSA-crm4-q7v4-c2r2"
+  ],
+  "summary": "Canonical ADSys Uses a Less Trusted Source in github.com/ubuntu/adsys",
+  "details": "Canonical ADSys Uses a Less Trusted Source in github.com/ubuntu/adsys.\n\nNOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.\n\n(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)\n\nThe additional affected modules and versions are: github.com/ubuntu/adsys before v0.16.3-0.20250318112551-8b1939f96d38.",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/ubuntu/adsys",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {
+        "custom_ranges": [
+          {
+            "type": "ECOSYSTEM",
+            "events": [
+              {
+                "introduced": "0"
+              },
+              {
+                "fixed": "0.16.3-0.20250318112551-8b1939f96d38"
+              }
+            ]
+          }
+        ]
+      }
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/advisories/GHSA-crm4-q7v4-c2r2"
+    },
+    {
+      "type": "ADVISORY",
+      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-12249"
+    },
+    {
+      "type": "FIX",
+      "url": "https://github.com/ubuntu/adsys/commit/8b1939f96d3827b4426eb06c1ced5bf317b0a99d"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/ubuntu/adsys/releases/tag/v0.16.3"
+    },
+    {
+      "type": "WEB",
+      "url": "https://ubuntu.com/security/CVE-2026-12249"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6543",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6544.json b/data/osv/GO-2026-6544.json
new file mode 100644
index 0000000..e6a7fd5
--- /dev/null
+++ b/data/osv/GO-2026-6544.json
@@ -0,0 +1,240 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6544",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-42129",
+    "GHSA-f74p-cwhp-x2wx"
+  ],
+  "summary": "Grafana Loki datasource plugin's callResource handler contains a path traversal vulnerability. in github.com/grafana/grafana",
+  "details": "Grafana Loki datasource plugin's callResource handler contains a path traversal vulnerability. in github.com/grafana/grafana.\n\nNOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.\n\n(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)\n\nThe additional affected modules and versions are: github.com/grafana/grafana before v1.9.2-0.20260616075434-82ef13993059.",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/grafana/grafana",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {
+        "custom_ranges": [
+          {
+            "type": "ECOSYSTEM",
+            "events": [
+              {
+                "introduced": "0"
+              },
+              {
+                "fixed": "1.9.2-0.20260616075434-82ef13993059"
+              }
+            ]
+          }
+        ]
+      }
+    },
+    {
+      "package": {
+        "name": "github.com/grafana/grafana",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {
+        "custom_ranges": [
+          {
+            "type": "ECOSYSTEM",
+            "events": [
+              {
+                "introduced": "12.4.0"
+              }
+            ]
+          }
+        ]
+      }
+    },
+    {
+      "package": {
+        "name": "github.com/grafana/grafana",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {
+        "custom_ranges": [
+          {
+            "type": "ECOSYSTEM",
+            "events": [
+              {
+                "introduced": "13.0.0"
+              }
+            ]
+          }
+        ]
+      }
+    },
+    {
+      "package": {
+        "name": "github.com/grafana/grafana",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {
+        "custom_ranges": [
+          {
+            "type": "ECOSYSTEM",
+            "events": [
+              {
+                "introduced": "12.3.0"
+              }
+            ]
+          }
+        ]
+      }
+    },
+    {
+      "package": {
+        "name": "github.com/grafana/grafana",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {
+        "custom_ranges": [
+          {
+            "type": "ECOSYSTEM",
+            "events": [
+              {
+                "introduced": "12.0.0"
+              }
+            ]
+          }
+        ]
+      }
+    },
+    {
+      "package": {
+        "name": "github.com/grafana/grafana",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "2.0.0-beta1+incompatible"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/advisories/GHSA-f74p-cwhp-x2wx"
+    },
+    {
+      "type": "ADVISORY",
+      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42129"
+    },
+    {
+      "type": "FIX",
+      "url": "https://github.com/grafana/grafana/commit/3fcdbc5a6e5c955bd42bd3715dd03cbad2b078c1"
+    },
+    {
+      "type": "FIX",
+      "url": "https://github.com/grafana/grafana/commit/42cdc39124912a8506a0c613c319c345aa950b29"
+    },
+    {
+      "type": "FIX",
+      "url": "https://github.com/grafana/grafana/commit/82ef13993059351bf21de35b8488bbd9b42df4f4"
+    },
+    {
+      "type": "FIX",
+      "url": "https://github.com/grafana/grafana/commit/d27d2eba9c509d16f214d290436a6ad0bd9c6c01"
+    },
+    {
+      "type": "FIX",
+      "url": "https://github.com/grafana/grafana/commit/dd5dc51681ff0133ddb2e206c2ea318713aeca16"
+    },
+    {
+      "type": "FIX",
+      "url": "https://github.com/grafana/grafana/commit/eeb08ceb020c4381242d8400e5878044e9877505"
+    },
+    {
+      "type": "FIX",
+      "url": "https://github.com/grafana/grafana/commit/f70d3e480274a5dbd12006338c393f4b05d441ca"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/grafana/grafana/releases/tag/v11.6.15"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/grafana/grafana/releases/tag/v12.2.9"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/grafana/grafana/releases/tag/v12.3.7"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/grafana/grafana/releases/tag/v12.4.4"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/grafana/grafana/releases/tag/v13.0.2"
+    },
+    {
+      "type": "WEB",
+      "url": "https://grafana.com/security/security-advisories/cve-2026-42129"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6544",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6545.json b/data/osv/GO-2026-6545.json
new file mode 100644
index 0000000..8cc0bab
--- /dev/null
+++ b/data/osv/GO-2026-6545.json
@@ -0,0 +1,240 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6545",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-10601",
+    "GHSA-9493-h4f5-633x"
+  ],
+  "summary": "Grafana: Path traversal in the Tempo and Loki data source plugins in github.com/grafana/grafana",
+  "details": "Grafana: Path traversal in the Tempo and Loki data source plugins in github.com/grafana/grafana.\n\nNOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.\n\n(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)\n\nThe additional affected modules and versions are: github.com/grafana/grafana before v1.9.2-0.20260616075434-82ef13993059.",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/grafana/grafana",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {
+        "custom_ranges": [
+          {
+            "type": "ECOSYSTEM",
+            "events": [
+              {
+                "introduced": "0"
+              },
+              {
+                "fixed": "1.9.2-0.20260616075434-82ef13993059"
+              }
+            ]
+          }
+        ]
+      }
+    },
+    {
+      "package": {
+        "name": "github.com/grafana/grafana",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {
+        "custom_ranges": [
+          {
+            "type": "ECOSYSTEM",
+            "events": [
+              {
+                "introduced": "12.4.0"
+              }
+            ]
+          }
+        ]
+      }
+    },
+    {
+      "package": {
+        "name": "github.com/grafana/grafana",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {
+        "custom_ranges": [
+          {
+            "type": "ECOSYSTEM",
+            "events": [
+              {
+                "introduced": "13.0.0"
+              }
+            ]
+          }
+        ]
+      }
+    },
+    {
+      "package": {
+        "name": "github.com/grafana/grafana",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {
+        "custom_ranges": [
+          {
+            "type": "ECOSYSTEM",
+            "events": [
+              {
+                "introduced": "12.3.0"
+              }
+            ]
+          }
+        ]
+      }
+    },
+    {
+      "package": {
+        "name": "github.com/grafana/grafana",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {
+        "custom_ranges": [
+          {
+            "type": "ECOSYSTEM",
+            "events": [
+              {
+                "introduced": "12.0.0"
+              }
+            ]
+          }
+        ]
+      }
+    },
+    {
+      "package": {
+        "name": "github.com/grafana/grafana",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "2.0.0-beta1+incompatible"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/advisories/GHSA-9493-h4f5-633x"
+    },
+    {
+      "type": "ADVISORY",
+      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-10601"
+    },
+    {
+      "type": "FIX",
+      "url": "https://github.com/grafana/grafana/commit/3fcdbc5a6e5c955bd42bd3715dd03cbad2b078c1"
+    },
+    {
+      "type": "FIX",
+      "url": "https://github.com/grafana/grafana/commit/42cdc39124912a8506a0c613c319c345aa950b29"
+    },
+    {
+      "type": "FIX",
+      "url": "https://github.com/grafana/grafana/commit/82ef13993059351bf21de35b8488bbd9b42df4f4"
+    },
+    {
+      "type": "FIX",
+      "url": "https://github.com/grafana/grafana/commit/d27d2eba9c509d16f214d290436a6ad0bd9c6c01"
+    },
+    {
+      "type": "FIX",
+      "url": "https://github.com/grafana/grafana/commit/dd5dc51681ff0133ddb2e206c2ea318713aeca16"
+    },
+    {
+      "type": "FIX",
+      "url": "https://github.com/grafana/grafana/commit/f70d3e480274a5dbd12006338c393f4b05d441ca"
+    },
+    {
+      "type": "FIX",
+      "url": "https://github.com/grafana/grafana/pull/125789"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/grafana/grafana/releases/tag/v11.6.15"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/grafana/grafana/releases/tag/v12.2.9"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/grafana/grafana/releases/tag/v12.3.7"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/grafana/grafana/releases/tag/v12.4.4"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/grafana/grafana/releases/tag/v13.0.2"
+    },
+    {
+      "type": "WEB",
+      "url": "https://grafana.com/security/security-advisories/cve-2026-10601"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6545",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/reports/GO-2026-6480.yaml b/data/reports/GO-2026-6480.yaml
new file mode 100644
index 0000000..481fb21
--- /dev/null
+++ b/data/reports/GO-2026-6480.yaml
@@ -0,0 +1,28 @@
+id: GO-2026-6480
+modules:
+    - module: github.com/mattermost/mattermost-server
+      versions:
+        - introduced: 10.11.0+incompatible
+        - fixed: 10.11.18+incompatible
+        - introduced: 11.5.0+incompatible
+        - fixed: 11.5.6+incompatible
+        - introduced: 11.6.0+incompatible
+        - fixed: 11.6.3+incompatible
+        - introduced: 11.7.0+incompatible
+        - fixed: 11.7.1+incompatible
+      vulnerable_at: 11.7.0+incompatible
+summary: |-
+    Mattermost doesn't enforce administrator authorization on the
+    {{setDefaultInstance}} call within the {{/gitlab connect}} command handler in github.com/mattermost/mattermost-server
+cves:
+    - CVE-2026-5139
+ghsas:
+    - GHSA-2g8v-grq3-hq2g
+references:
+    - advisory: https://github.com/advisories/GHSA-2g8v-grq3-hq2g
+    - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-5139
+    - web: https://mattermost.com/security-updates
+source:
+    id: GHSA-2g8v-grq3-hq2g
+    created: 2026-09-22T10:18:04.761818-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6481.yaml b/data/reports/GO-2026-6481.yaml
new file mode 100644
index 0000000..d5c7c8f
--- /dev/null
+++ b/data/reports/GO-2026-6481.yaml
@@ -0,0 +1,24 @@
+id: GO-2026-6481
+modules:
+    - module: github.com/mattermost/mattermost-server
+      versions:
+        - introduced: 10.11.0+incompatible
+        - fixed: 10.11.18+incompatible
+        - introduced: 11.7.0+incompatible
+        - fixed: 11.7.1+incompatible
+      vulnerable_at: 11.7.0+incompatible
+summary: |-
+    Mattermost doesn't enforce bot-specific permission checks on the user active
+    status endpoint in github.com/mattermost/mattermost-server
+cves:
+    - CVE-2026-8074
+ghsas:
+    - GHSA-g5vr-6pgg-74qv
+references:
+    - advisory: https://github.com/advisories/GHSA-g5vr-6pgg-74qv
+    - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-8074
+    - web: https://mattermost.com/security-updates
+source:
+    id: GHSA-g5vr-6pgg-74qv
+    created: 2026-09-22T10:17:58.203898-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6482.yaml b/data/reports/GO-2026-6482.yaml
new file mode 100644
index 0000000..3de8b50
--- /dev/null
+++ b/data/reports/GO-2026-6482.yaml
@@ -0,0 +1,28 @@
+id: GO-2026-6482
+modules:
+    - module: github.com/mattermost/mattermost-server
+      versions:
+        - introduced: 10.11.0+incompatible
+        - fixed: 10.11.18+incompatible
+        - introduced: 11.5.0+incompatible
+        - fixed: 11.5.6+incompatible
+        - introduced: 11.6.0+incompatible
+        - fixed: 11.6.3+incompatible
+        - introduced: 11.7.0+incompatible
+        - fixed: 11.7.1+incompatible
+      vulnerable_at: 11.7.0+incompatible
+summary: |-
+    Mattermost doesn't invalidate cached authentication state for active WebSocket
+    connections during global session revocation in github.com/mattermost/mattermost-server
+cves:
+    - CVE-2026-9162
+ghsas:
+    - GHSA-h998-hxxj-8q83
+references:
+    - advisory: https://github.com/advisories/GHSA-h998-hxxj-8q83
+    - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-9162
+    - web: https://mattermost.com/security-updates
+source:
+    id: GHSA-h998-hxxj-8q83
+    created: 2026-09-22T10:17:50.189409-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6483.yaml b/data/reports/GO-2026-6483.yaml
new file mode 100644
index 0000000..c509f83
--- /dev/null
+++ b/data/reports/GO-2026-6483.yaml
@@ -0,0 +1,28 @@
+id: GO-2026-6483
+modules:
+    - module: github.com/mattermost/mattermost-server
+      versions:
+        - introduced: 10.11.0+incompatible
+        - fixed: 10.11.18+incompatible
+        - introduced: 11.5.0+incompatible
+        - fixed: 11.5.6+incompatible
+        - introduced: 11.6.0+incompatible
+        - fixed: 11.6.3+incompatible
+        - introduced: 11.7.0+incompatible
+        - fixed: 11.7.1+incompatible
+      vulnerable_at: 11.7.0+incompatible
+summary: |-
+    Mattermost doesn't authenticate Atlassian Connect installed callbacks, allowing
+    a remote unauthenticated attacker to inject a rogue sharedSecret in github.com/mattermost/mattermost-server
+cves:
+    - CVE-2026-6673
+ghsas:
+    - GHSA-jqgv-39mg-7c2r
+references:
+    - advisory: https://github.com/advisories/GHSA-jqgv-39mg-7c2r
+    - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-6673
+    - web: https://mattermost.com/security-updates
+source:
+    id: GHSA-jqgv-39mg-7c2r
+    created: 2026-09-22T10:17:42.442379-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6484.yaml b/data/reports/GO-2026-6484.yaml
new file mode 100644
index 0000000..fd10578
--- /dev/null
+++ b/data/reports/GO-2026-6484.yaml
@@ -0,0 +1,28 @@
+id: GO-2026-6484
+modules:
+    - module: github.com/mattermost/mattermost-server
+      versions:
+        - introduced: 10.11.0+incompatible
+        - fixed: 10.11.18+incompatible
+        - introduced: 11.5.0+incompatible
+        - fixed: 11.5.6+incompatible
+        - introduced: 11.6.0+incompatible
+        - fixed: 11.6.3+incompatible
+        - introduced: 11.7.0+incompatible
+        - fixed: 11.7.1+incompatible
+      vulnerable_at: 11.7.0+incompatible
+summary: |-
+    Mattermost doesn't validate channel ownership of an existing subscription before
+    applying edits in github.com/mattermost/mattermost-server
+cves:
+    - CVE-2026-6062
+ghsas:
+    - GHSA-mxq2-5jpg-7474
+references:
+    - advisory: https://github.com/advisories/GHSA-mxq2-5jpg-7474
+    - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-6062
+    - web: https://mattermost.com/security-updates
+source:
+    id: GHSA-mxq2-5jpg-7474
+    created: 2026-09-22T10:17:07.85964-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6485.yaml b/data/reports/GO-2026-6485.yaml
new file mode 100644
index 0000000..bb66048
--- /dev/null
+++ b/data/reports/GO-2026-6485.yaml
@@ -0,0 +1,18 @@
+id: GO-2026-6485
+modules:
+    - module: github.com/gravitl/netmaker
+      versions:
+        - fixed: 1.5.0
+      vulnerable_at: 1.4.0
+summary: Netmaker has a boolean‑based SQL Injection in github.com/gravitl/netmaker
+cves:
+    - CVE-2026-32599
+ghsas:
+    - GHSA-r8cr-4f9w-7r75
+references:
+    - advisory: https://github.com/gravitl/netmaker/security/advisories/GHSA-r8cr-4f9w-7r75
+    - web: https://github.com/gravitl/netmaker/releases/tag/v1.5.0
+source:
+    id: GHSA-r8cr-4f9w-7r75
+    created: 2026-09-22T10:17:00.917771-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6486.yaml b/data/reports/GO-2026-6486.yaml
new file mode 100644
index 0000000..0486599
--- /dev/null
+++ b/data/reports/GO-2026-6486.yaml
@@ -0,0 +1,16 @@
+id: GO-2026-6486
+modules:
+    - module: github.com/nezhahq/nezha
+      vulnerable_at: 1.14.14
+summary: |-
+    Nezha: OAuth2 redirect_uri Host header injection regression when dashboard_host
+    is empty in github.com/nezhahq/nezha
+ghsas:
+    - GHSA-rf68-8gjr-36q7
+references:
+    - advisory: https://github.com/nezhahq/nezha/security/advisories/GHSA-rf68-8gjr-36q7
+    - fix: https://github.com/nezhahq/nezha/commit/38824dbc11a63964c5b9296ae4c68e62b34fa04b
+source:
+    id: GHSA-rf68-8gjr-36q7
+    created: 2026-09-22T10:16:56.538133-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6487.yaml b/data/reports/GO-2026-6487.yaml
new file mode 100644
index 0000000..0e80f3b
--- /dev/null
+++ b/data/reports/GO-2026-6487.yaml
@@ -0,0 +1,19 @@
+id: GO-2026-6487
+modules:
+    - module: github.com/jm33-m0/emp3r0r/core
+      versions:
+        - fixed: 0.0.0-20260531142011-aed3d81641ab
+summary: emp3r0r has an unauthenticated HTTP Polling DoS in github.com/jm33-m0/emp3r0r/core
+cves:
+    - CVE-2026-61554
+ghsas:
+    - GHSA-4595-rvpx-4q34
+references:
+    - advisory: https://github.com/jm33-m0/emp3r0r/security/advisories/GHSA-4595-rvpx-4q34
+    - web: https://github.com/jm33-m0/emp3r0r/releases/tag/v4.2.5
+notes:
+    - fix: 'github.com/jm33-m0/emp3r0r/core: could not add vulnerable_at: cannot auto-guess when fixed version is 0.0.0 pseudo-version'
+source:
+    id: GHSA-4595-rvpx-4q34
+    created: 2026-09-22T10:16:50.985152-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6488.yaml b/data/reports/GO-2026-6488.yaml
new file mode 100644
index 0000000..5c31c29
--- /dev/null
+++ b/data/reports/GO-2026-6488.yaml
@@ -0,0 +1,23 @@
+id: GO-2026-6488
+modules:
+    - module: github.com/openfga/openfga
+      versions:
+        - fixed: 1.18.1
+      vulnerable_at: 1.18.0
+summary: |-
+    OpenFGA: ListUsers returns a deliberately-excluded user when a `but not`
+    exclusion under a type-bound wildcard is intersected (`and`) with another
+    relation that also grants that user in github.com/openfga/openfga
+cves:
+    - CVE-2026-61709
+ghsas:
+    - GHSA-g3pg-frfm-pr2m
+references:
+    - advisory: https://github.com/openfga/openfga/security/advisories/GHSA-g3pg-frfm-pr2m
+    - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-61709
+    - fix: https://github.com/openfga/openfga/commit/171806c93b86bca29e0212ceb8b6ee9c48eb9ac3
+    - web: https://github.com/openfga/openfga/releases/tag/v1.18.1
+source:
+    id: GHSA-g3pg-frfm-pr2m
+    created: 2026-09-22T10:16:43.051223-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6490.yaml b/data/reports/GO-2026-6490.yaml
new file mode 100644
index 0000000..0b1a691
--- /dev/null
+++ b/data/reports/GO-2026-6490.yaml
@@ -0,0 +1,31 @@
+id: GO-2026-6490
+modules:
+    - module: github.com/centrifugal/centrifugo
+      vulnerable_at: 1.8.0
+    - module: github.com/centrifugal/centrifugo/v3
+      vulnerable_at: 3.2.3
+    - module: github.com/centrifugal/centrifugo/v4
+      vulnerable_at: 4.1.5
+    - module: github.com/centrifugal/centrifugo/v5
+      vulnerable_at: 5.4.9
+    - module: github.com/centrifugal/centrifugo/v6
+      versions:
+        - fixed: 6.9.0
+      vulnerable_at: 6.8.4
+summary: |-
+    Centrifugo: Client-forgeable headers emulation lets any client spoof headers
+    forwarded to proxy backends in github.com/centrifugal/centrifugo
+cves:
+    - CVE-2026-71485
+ghsas:
+    - GHSA-9468-v6mj-fppw
+references:
+    - advisory: https://github.com/centrifugal/centrifugo/security/advisories/GHSA-9468-v6mj-fppw
+    - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-71485
+    - fix: https://github.com/centrifugal/centrifugo/commit/84d38cea1dd2efa24375a148817a974c8727f4b0
+    - fix: https://github.com/centrifugal/centrifugo/pull/1182
+    - web: https://github.com/centrifugal/centrifugo/releases/tag/v6.9.0
+source:
+    id: GHSA-9468-v6mj-fppw
+    created: 2026-09-22T10:15:08.655437-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6495.yaml b/data/reports/GO-2026-6495.yaml
new file mode 100644
index 0000000..aee4eec
--- /dev/null
+++ b/data/reports/GO-2026-6495.yaml
@@ -0,0 +1,24 @@
+id: GO-2026-6495
+modules:
+    - module: github.com/zalando/skipper
+      versions:
+        - fixed: 0.27.37
+      vulnerable_at: 0.27.36
+summary: |-
+    Skipper has OPA body-authz bypass: truncated_body mitigation fails open on
+    chunked/HTTP-2 (incomplete fix GHSA-8qqm-fp2q-v734) in github.com/zalando/skipper
+cves:
+    - CVE-2026-86043
+ghsas:
+    - GHSA-5gpm-rgj3-9q76
+references:
+    - advisory: https://github.com/zalando/skipper/security/advisories/GHSA-5gpm-rgj3-9q76
+    - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-86043
+    - fix: https://github.com/zalando/skipper/commit/2cfceabaa6ff0af65b312dcb9bcbe84691b9d507
+    - web: https://github.com/zalando/skipper/releases/tag/v0.27.35
+    - web: https://github.com/zalando/skipper/releases/tag/v0.27.37
+    - web: https://github.com/zalando/skipper/tree/v0.27.35
+source:
+    id: GHSA-5gpm-rgj3-9q76
+    created: 2026-09-22T10:14:21.41098-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6506.yaml b/data/reports/GO-2026-6506.yaml
new file mode 100644
index 0000000..ac89217
--- /dev/null
+++ b/data/reports/GO-2026-6506.yaml
@@ -0,0 +1,20 @@
+id: GO-2026-6506
+modules:
+    - module: github.com/coredns/coredns
+      versions:
+        - fixed: 1.14.7
+      vulnerable_at: 1.14.6
+summary: CoreDNS DoH/DoQ/gRPC bypass UPDATE rejection enforced on UDP/TCP in github.com/coredns/coredns
+cves:
+    - CVE-2026-86003
+ghsas:
+    - GHSA-9gm5-9rfh-m6vx
+references:
+    - advisory: https://github.com/coredns/coredns/security/advisories/GHSA-9gm5-9rfh-m6vx
+    - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-86003
+    - fix: https://github.com/coredns/coredns/commit/530b0a5ff2ad68cc0421f10dd93568945cc671c9
+    - web: https://github.com/coredns/coredns/releases/tag/v1.14.7
+source:
+    id: GHSA-9gm5-9rfh-m6vx
+    created: 2026-09-22T10:12:57.869273-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6507.yaml b/data/reports/GO-2026-6507.yaml
new file mode 100644
index 0000000..961e46a
--- /dev/null
+++ b/data/reports/GO-2026-6507.yaml
@@ -0,0 +1,20 @@
+id: GO-2026-6507
+modules:
+    - module: github.com/coredns/coredns
+      versions:
+        - fixed: 1.14.7
+      vulnerable_at: 1.14.6
+summary: 'CoreDNS: Unauthenticated memory exhaustion in custom transports in github.com/coredns/coredns'
+cves:
+    - CVE-2026-82399
+ghsas:
+    - GHSA-mrg3-qvqr-jw29
+references:
+    - advisory: https://github.com/coredns/coredns/security/advisories/GHSA-mrg3-qvqr-jw29
+    - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-82399
+    - fix: https://github.com/coredns/coredns/commit/530b0a5ff2ad68cc0421f10dd93568945cc671c9
+    - web: https://github.com/coredns/coredns/releases/tag/v1.14.7
+source:
+    id: GHSA-mrg3-qvqr-jw29
+    created: 2026-09-22T10:12:50.573298-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6508.yaml b/data/reports/GO-2026-6508.yaml
new file mode 100644
index 0000000..aa56739
--- /dev/null
+++ b/data/reports/GO-2026-6508.yaml
@@ -0,0 +1,22 @@
+id: GO-2026-6508
+modules:
+    - module: go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc
+      versions:
+        - fixed: 0.21.0
+      vulnerable_at: 0.20.0
+summary: |-
+    OpenTelemetry-Go: Log gRPC exporter ignores env TLS certs, bypassing
+    mTLS/pinning in go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc
+cves:
+    - CVE-2026-81871
+ghsas:
+    - GHSA-w34q-cm8f-9c5x
+references:
+    - advisory: https://github.com/open-telemetry/opentelemetry-go/security/advisories/GHSA-w34q-cm8f-9c5x
+    - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-81871
+    - web: https://github.com/open-telemetry/opentelemetry-go/commit/c65d435b43e5e6b82310e6b18dd4cdcb8ac63a0c
+    - web: https://github.com/open-telemetry/opentelemetry-go/releases/tag/exporters/otlp/otlplog/otlploggrpc/v0.21.0
+source:
+    id: GHSA-w34q-cm8f-9c5x
+    created: 2026-09-22T10:12:43.613148-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6514.yaml b/data/reports/GO-2026-6514.yaml
new file mode 100644
index 0000000..6e8eba3
--- /dev/null
+++ b/data/reports/GO-2026-6514.yaml
@@ -0,0 +1,22 @@
+id: GO-2026-6514
+modules:
+    - module: github.com/perses/perses
+      versions:
+        - introduced: 0.43.0
+        - fixed: 0.54.0-rc.0
+      vulnerable_at: 0.54.0-beta.3
+summary: |-
+    Perses's missing authorization in datasource proxy allows cross-scope secret
+    disclosure in github.com/perses/perses
+cves:
+    - CVE-2026-63199
+ghsas:
+    - GHSA-4227-9989-jrhx
+references:
+    - advisory: https://github.com/perses/perses/security/advisories/GHSA-4227-9989-jrhx
+    - fix: https://github.com/perses/perses/commit/2368c9ef4eb0a70fbca5df69aa20e595821ab625
+    - web: https://github.com/perses/perses/releases/tag/v0.54.0-rc.0
+source:
+    id: GHSA-4227-9989-jrhx
+    created: 2026-09-22T10:12:23.911805-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6515.yaml b/data/reports/GO-2026-6515.yaml
new file mode 100644
index 0000000..ab825ab
--- /dev/null
+++ b/data/reports/GO-2026-6515.yaml
@@ -0,0 +1,21 @@
+id: GO-2026-6515
+modules:
+    - module: github.com/f1bonacc1/process-compose
+      versions:
+        - fixed: 1.120.0
+      vulnerable_at: 1.116.0
+summary: |-
+    Process Compose: Browser DNS rebinding lets websites control local
+    process-compose MCP tools in github.com/f1bonacc1/process-compose
+cves:
+    - CVE-2026-77339
+ghsas:
+    - GHSA-5gm3-9crp-6g3v
+references:
+    - advisory: https://github.com/F1bonacc1/process-compose/security/advisories/GHSA-5gm3-9crp-6g3v
+    - web: https://github.com/F1bonacc1/process-compose/commit/6ffa74f462cd2fa4f8dc1ee63c70b793b298c858
+    - web: https://github.com/F1bonacc1/process-compose/releases/tag/v1.120.0
+source:
+    id: GHSA-5gm3-9crp-6g3v
+    created: 2026-09-22T10:12:16.446138-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6516.yaml b/data/reports/GO-2026-6516.yaml
new file mode 100644
index 0000000..1e10f18
--- /dev/null
+++ b/data/reports/GO-2026-6516.yaml
@@ -0,0 +1,21 @@
+id: GO-2026-6516
+modules:
+    - module: github.com/anycable/anycable-go
+      non_go_versions:
+        - fixed: 1.6.15
+      vulnerable_at: 1.5.6
+summary: |-
+    AnyCable: Pusher REST API Does Not Verify Request Body MD5 Enabling
+    Signed-Request Replay with Arbitrary Body in github.com/anycable/anycable-go
+cves:
+    - CVE-2026-63405
+ghsas:
+    - GHSA-5p54-whvp-x327
+references:
+    - advisory: https://github.com/anycable/anycable/security/advisories/GHSA-5p54-whvp-x327
+    - web: https://github.com/anycable/anycable/commit/d2cbadec792f038f4695c84a65c0d957b0fde72c
+    - web: https://github.com/anycable/anycable/releases/tag/v1.6.15
+source:
+    id: GHSA-5p54-whvp-x327
+    created: 2026-09-22T10:12:09.488921-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6517.yaml b/data/reports/GO-2026-6517.yaml
new file mode 100644
index 0000000..4d5f3ee
--- /dev/null
+++ b/data/reports/GO-2026-6517.yaml
@@ -0,0 +1,25 @@
+id: GO-2026-6517
+modules:
+    - module: github.com/kcp-dev/kcp
+      versions:
+        - fixed: 0.31.4
+        - introduced: 0.32.0
+        - fixed: 0.32.2
+      vulnerable_at: 0.32.1
+summary: |-
+    kcp front-proxy does not strip inbound X-Remote-* identity headers, allowing any
+    authenticated client to inject groups/warrants and impersonate system:masters in
+    any workspace in github.com/kcp-dev/kcp
+cves:
+    - CVE-2026-61682
+ghsas:
+    - GHSA-c8w2-fgvx-vhv4
+references:
+    - advisory: https://github.com/kcp-dev/kcp/security/advisories/GHSA-c8w2-fgvx-vhv4
+    - fix: https://github.com/kcp-dev/kcp/commit/7437cdcfec8f927d1a9bf1b2dd1e075d038e27ca
+    - web: https://github.com/kcp-dev/kcp/releases/tag/v0.31.4
+    - web: https://github.com/kcp-dev/kcp/releases/tag/v0.32.2
+source:
+    id: GHSA-c8w2-fgvx-vhv4
+    created: 2026-09-22T10:12:01.87658-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6518.yaml b/data/reports/GO-2026-6518.yaml
new file mode 100644
index 0000000..bbcd7b6
--- /dev/null
+++ b/data/reports/GO-2026-6518.yaml
@@ -0,0 +1,21 @@
+id: GO-2026-6518
+modules:
+    - module: github.com/perses/perses
+      versions:
+        - fixed: 0.54.0-beta.3
+      vulnerable_at: 0.54.0-beta.2
+summary: |-
+    Perses's project query parameter authorization bypass exposes cross-project
+    resources in github.com/perses/perses
+cves:
+    - CVE-2026-63458
+ghsas:
+    - GHSA-cjgj-2fwf-4c2w
+references:
+    - advisory: https://github.com/perses/perses/security/advisories/GHSA-cjgj-2fwf-4c2w
+    - fix: https://github.com/perses/perses/commit/8015fb340bdc625953e73a7a688be5b939159540
+    - web: https://github.com/perses/perses/releases/tag/v0.54.0-beta.3
+source:
+    id: GHSA-cjgj-2fwf-4c2w
+    created: 2026-09-22T10:11:54.58659-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6519.yaml b/data/reports/GO-2026-6519.yaml
new file mode 100644
index 0000000..e33fd32
--- /dev/null
+++ b/data/reports/GO-2026-6519.yaml
@@ -0,0 +1,23 @@
+id: GO-2026-6519
+modules:
+    - module: github.com/projectcapsule/capsule
+      versions:
+        - introduced: 0.13.0
+        - fixed: 0.13.7
+      vulnerable_at: 0.13.6
+summary: |-
+    Capsule: hostnameRegexHandler.OnUpdate validates stale (old) Tenant regex,
+    allowing invalid AllowedHostnames regex to bypass webhook validation in github.com/projectcapsule/capsule
+cves:
+    - CVE-2026-61795
+ghsas:
+    - GHSA-f94q-w3w8-cj67
+references:
+    - advisory: https://github.com/projectcapsule/capsule/security/advisories/GHSA-f94q-w3w8-cj67
+    - fix: https://github.com/projectcapsule/capsule/commit/8d89d6865df6f41c7faa22fc9e807a57b01bfd0e
+    - fix: https://github.com/projectcapsule/capsule/pull/1983
+    - web: https://github.com/projectcapsule/capsule/releases/tag/v0.13.7
+source:
+    id: GHSA-f94q-w3w8-cj67
+    created: 2026-09-22T10:11:47.500495-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6520.yaml b/data/reports/GO-2026-6520.yaml
new file mode 100644
index 0000000..998cd32
--- /dev/null
+++ b/data/reports/GO-2026-6520.yaml
@@ -0,0 +1,22 @@
+id: GO-2026-6520
+modules:
+    - module: github.com/projectcapsule/capsule
+      versions:
+        - fixed: 0.13.7
+      vulnerable_at: 0.13.6
+summary: |-
+    Capsule: Tenant owner bypasses Capsule's forbidden namespace/service/node label
+    and annotation enforcement in github.com/projectcapsule/capsule
+cves:
+    - CVE-2026-61672
+ghsas:
+    - GHSA-gjw4-3v3v-rqxg
+references:
+    - advisory: https://github.com/projectcapsule/capsule/security/advisories/GHSA-gjw4-3v3v-rqxg
+    - fix: https://github.com/projectcapsule/capsule/commit/755cef54bf4a1bc56d6692130132bc70755bef46
+    - fix: https://github.com/projectcapsule/capsule/pull/1982
+    - web: https://github.com/projectcapsule/capsule/releases/tag/v0.13.7
+source:
+    id: GHSA-gjw4-3v3v-rqxg
+    created: 2026-09-22T10:11:38.640435-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6521.yaml b/data/reports/GO-2026-6521.yaml
new file mode 100644
index 0000000..04eea93
--- /dev/null
+++ b/data/reports/GO-2026-6521.yaml
@@ -0,0 +1,23 @@
+id: GO-2026-6521
+modules:
+    - module: github.com/projectcapsule/capsule
+      versions:
+        - introduced: 0.13.0
+        - fixed: 0.13.7
+      vulnerable_at: 0.13.6
+summary: |-
+    Capsule: Malformed ForbiddenAnnotations.Regex can bypass Tenant validation and
+    trigger namespace admission panic in github.com/projectcapsule/capsule
+cves:
+    - CVE-2026-61794
+ghsas:
+    - GHSA-gxjc-74v5-3vx3
+references:
+    - advisory: https://github.com/projectcapsule/capsule/security/advisories/GHSA-gxjc-74v5-3vx3
+    - fix: https://github.com/projectcapsule/capsule/commit/8d89d6865df6f41c7faa22fc9e807a57b01bfd0e
+    - fix: https://github.com/projectcapsule/capsule/pull/1983
+    - web: https://github.com/projectcapsule/capsule/releases/tag/v0.13.7
+source:
+    id: GHSA-gxjc-74v5-3vx3
+    created: 2026-09-22T10:11:29.911683-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6522.yaml b/data/reports/GO-2026-6522.yaml
new file mode 100644
index 0000000..245d835
--- /dev/null
+++ b/data/reports/GO-2026-6522.yaml
@@ -0,0 +1,16 @@
+id: GO-2026-6522
+modules:
+    - module: github.com/obot-platform/obot
+      versions:
+        - fixed: 0.23.0
+      vulnerable_at: 0.23.0-rc5
+summary: 'Obot: Server-Side Request Forgery via remote MCP server URL in github.com/obot-platform/obot'
+ghsas:
+    - GHSA-jgh3-fggc-mcpm
+references:
+    - advisory: https://github.com/obot-platform/obot/security/advisories/GHSA-jgh3-fggc-mcpm
+    - web: https://github.com/obot-platform/obot/releases/tag/v0.23.0
+source:
+    id: GHSA-jgh3-fggc-mcpm
+    created: 2026-09-22T10:11:26.996243-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6523.yaml b/data/reports/GO-2026-6523.yaml
new file mode 100644
index 0000000..33d462e
--- /dev/null
+++ b/data/reports/GO-2026-6523.yaml
@@ -0,0 +1,20 @@
+id: GO-2026-6523
+modules:
+    - module: github.com/frain-dev/convoy
+      versions:
+        - fixed: 0.9.3-0.20260724092134-1cc67cd16fb1
+      vulnerable_at: 0.9.2
+summary: 'Convoy: Cross-Tenant Source IDOR Leaks Plaintext Message Broker Credentials in github.com/frain-dev/convoy'
+cves:
+    - CVE-2026-81505
+ghsas:
+    - GHSA-p5vg-v7mj-f6q4
+references:
+    - advisory: https://github.com/frain-dev/convoy/security/advisories/GHSA-p5vg-v7mj-f6q4
+    - fix: https://github.com/frain-dev/convoy/commit/1cc67cd16fb1f8890cc83a3998d3f92dceb7fd06
+    - fix: https://github.com/frain-dev/convoy/pull/2755
+    - web: https://github.com/frain-dev/convoy/releases/tag/v26.6.8
+source:
+    id: GHSA-p5vg-v7mj-f6q4
+    created: 2026-09-22T10:11:20.707596-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6525.yaml b/data/reports/GO-2026-6525.yaml
new file mode 100644
index 0000000..07ab997
--- /dev/null
+++ b/data/reports/GO-2026-6525.yaml
@@ -0,0 +1,16 @@
+id: GO-2026-6525
+modules:
+    - module: github.com/obot-platform/obot
+      versions:
+        - fixed: 0.23.0
+      vulnerable_at: 0.23.0-rc5
+summary: 'Obot: MCP Registry API readable without authentication in github.com/obot-platform/obot'
+ghsas:
+    - GHSA-pr6h-vr44-xq8j
+references:
+    - advisory: https://github.com/obot-platform/obot/security/advisories/GHSA-pr6h-vr44-xq8j
+    - web: https://github.com/obot-platform/obot/releases/tag/v0.23.0
+source:
+    id: GHSA-pr6h-vr44-xq8j
+    created: 2026-09-22T10:11:17.618829-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6526.yaml b/data/reports/GO-2026-6526.yaml
new file mode 100644
index 0000000..329a499
--- /dev/null
+++ b/data/reports/GO-2026-6526.yaml
@@ -0,0 +1,25 @@
+id: GO-2026-6526
+modules:
+    - module: github.com/stacklok/toolhive
+      versions:
+        - fixed: 0.30.1
+      vulnerable_at: 0.30.0
+summary: |-
+    ToolHive: containerized MCP servers can reach host services via
+    host.docker.internal, enabling lateral movement in github.com/stacklok/toolhive
+cves:
+    - CVE-2026-58197
+ghsas:
+    - GHSA-qg2g-g9w3-m5h8
+references:
+    - advisory: https://github.com/stacklok/toolhive/security/advisories/GHSA-qg2g-g9w3-m5h8
+    - fix: https://github.com/stacklok/toolhive/commit/d8f40cb1599b8bf66657f2dfff15bfbfc236e712
+    - fix: https://github.com/stacklok/toolhive/pull/5583
+    - web: https://github.com/stacklok/toolhive-studio/commit/968182d7f3ee1e55123369e66ad88f82128119b0
+    - web: https://github.com/stacklok/toolhive-studio/pull/2469
+    - web: https://github.com/stacklok/toolhive-studio/releases/tag/v0.38.0
+    - web: https://github.com/stacklok/toolhive/releases/tag/v0.30.1
+source:
+    id: GHSA-qg2g-g9w3-m5h8
+    created: 2026-09-22T10:11:08.428997-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6527.yaml b/data/reports/GO-2026-6527.yaml
new file mode 100644
index 0000000..6973e4c
--- /dev/null
+++ b/data/reports/GO-2026-6527.yaml
@@ -0,0 +1,24 @@
+id: GO-2026-6527
+modules:
+    - module: zotregistry.dev/zot
+      vulnerable_at: 1.4.3
+    - module: zotregistry.dev/zot/v2
+      versions:
+        - fixed: 2.1.18
+      vulnerable_at: 2.1.17
+summary: |-
+    zot: Bearer authentication maps DELETE to push scope, allowing unauthorized
+    deletion in zotregistry.dev/zot
+cves:
+    - CVE-2026-61833
+ghsas:
+    - GHSA-qg67-7m6v-qg25
+references:
+    - advisory: https://github.com/project-zot/zot/security/advisories/GHSA-qg67-7m6v-qg25
+    - web: https://github.com/project-zot/zot/commit/7bb211bcd4352b90f3e99752607fbd1f050bf7ca
+    - web: https://github.com/project-zot/zot/pull/4161
+    - web: https://github.com/project-zot/zot/releases/tag/v2.1.18
+source:
+    id: GHSA-qg67-7m6v-qg25
+    created: 2026-09-22T10:10:59.988618-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6528.yaml b/data/reports/GO-2026-6528.yaml
new file mode 100644
index 0000000..910d903
--- /dev/null
+++ b/data/reports/GO-2026-6528.yaml
@@ -0,0 +1,19 @@
+id: GO-2026-6528
+modules:
+    - module: github.com/perses/perses
+      versions:
+        - fixed: 0.54.0-rc.0
+      vulnerable_at: 0.54.0-beta.3
+summary: Perses's unvalidated project parameter enables filesystem path traversal in github.com/perses/perses
+cves:
+    - CVE-2026-63445
+ghsas:
+    - GHSA-vr5f-w35q-98jp
+references:
+    - advisory: https://github.com/perses/perses/security/advisories/GHSA-vr5f-w35q-98jp
+    - fix: https://github.com/perses/perses/commit/75e5471040ccb5674ea8d25c2aa16c80ccb70b2a
+    - web: https://github.com/perses/perses/releases/tag/v0.54.0-rc.0
+source:
+    id: GHSA-vr5f-w35q-98jp
+    created: 2026-09-22T10:10:52.899776-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6529.yaml b/data/reports/GO-2026-6529.yaml
new file mode 100644
index 0000000..752f4fb
--- /dev/null
+++ b/data/reports/GO-2026-6529.yaml
@@ -0,0 +1,21 @@
+id: GO-2026-6529
+modules:
+    - module: github.com/anycable/anycable-go
+      non_go_versions:
+        - fixed: 1.6.15
+      vulnerable_at: 1.5.6
+summary: |-
+    AnyCable: Telemetry Subsystem Contains Hardcoded Authentication Token and
+    Transmits CLI Arguments Including Secrets in github.com/anycable/anycable-go
+cves:
+    - CVE-2026-63406
+ghsas:
+    - GHSA-w72w-9qmj-c9qm
+references:
+    - advisory: https://github.com/anycable/anycable/security/advisories/GHSA-w72w-9qmj-c9qm
+    - web: https://github.com/anycable/anycable/commit/201c67e99e463ed63bd6b345562f4c458385fcee
+    - web: https://github.com/anycable/anycable/releases/tag/v1.6.15
+source:
+    id: GHSA-w72w-9qmj-c9qm
+    created: 2026-09-22T10:10:44.35196-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6530.yaml b/data/reports/GO-2026-6530.yaml
new file mode 100644
index 0000000..f840618
--- /dev/null
+++ b/data/reports/GO-2026-6530.yaml
@@ -0,0 +1,18 @@
+id: GO-2026-6530
+modules:
+    - module: github.com/obot-platform/obot
+      versions:
+        - fixed: 0.23.0
+      vulnerable_at: 0.23.0-rc5
+summary: |-
+    Obot: OAuth Dynamic Client Registration Enables API Token Theft via Audience
+    Confusion in github.com/obot-platform/obot
+ghsas:
+    - GHSA-xwmw-prc4-v3cr
+references:
+    - advisory: https://github.com/obot-platform/obot/security/advisories/GHSA-xwmw-prc4-v3cr
+    - web: https://github.com/obot-platform/obot/releases/tag/v0.23.0
+source:
+    id: GHSA-xwmw-prc4-v3cr
+    created: 2026-09-22T10:10:40.633814-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6535.yaml b/data/reports/GO-2026-6535.yaml
new file mode 100644
index 0000000..e1f1614
--- /dev/null
+++ b/data/reports/GO-2026-6535.yaml
@@ -0,0 +1,24 @@
+id: GO-2026-6535
+modules:
+    - module: github.com/hatchet-dev/hatchet
+      non_go_versions:
+        - fixed: 0.91.1
+      vulnerable_at: 0.108.3
+      packages:
+        - package: github.com/hatchet-dev/hatchet/api/v1/server/authn
+          symbols:
+            - SessionHelpers.ValidateOAuthState
+summary: |-
+    Hatchet - Unauthenticated OAuth state CSRF / login-CSRF via empty-state
+    collision in ValidateOAuthState in hatchet in github.com/hatchet-dev/hatchet
+cves:
+    - CVE-2026-61687
+ghsas:
+    - GHSA-phg3-3g28-wq9v
+references:
+    - advisory: https://github.com/hatchet-dev/hatchet/security/advisories/GHSA-phg3-3g28-wq9v
+    - fix: https://github.com/hatchet-dev/hatchet/commit/f90464189ad642251e09412d0f99fde353036428
+source:
+    id: GHSA-phg3-3g28-wq9v
+    created: 2026-09-22T10:10:35.931675-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6537.yaml b/data/reports/GO-2026-6537.yaml
new file mode 100644
index 0000000..9150db2
--- /dev/null
+++ b/data/reports/GO-2026-6537.yaml
@@ -0,0 +1,25 @@
+id: GO-2026-6537
+modules:
+    - module: github.com/lucasdillmann/nginx-ignition
+      versions:
+        - introduced: 0.0.0-20260217145239-1cbfae0296f1
+        - fixed: 0.0.0-20260328015550-8d35e1eb5dd6
+summary: nginx ignition has TOTP Reuse During Validity Window in github.com/lucasdillmann/nginx-ignition
+cves:
+    - CVE-2026-61630
+ghsas:
+    - GHSA-hf33-q6cf-c66f
+references:
+    - advisory: https://github.com/lucasdillmann/nginx-ignition/security/advisories/GHSA-hf33-q6cf-c66f
+    - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-61630
+    - fix: https://github.com/lucasdillmann/nginx-ignition/commit/1cbfae0296f1b186158f5a294ec484060e00102e
+    - fix: https://github.com/lucasdillmann/nginx-ignition/commit/8d35e1eb5dd6a40fef94a45511fe08b0603af107
+    - fix: https://github.com/lucasdillmann/nginx-ignition/pull/104
+    - web: https://github.com/lucasdillmann/nginx-ignition/releases/tag/2.35.1
+    - web: https://github.com/pquerna/otp/issues/61
+notes:
+    - fix: 'github.com/lucasdillmann/nginx-ignition: could not add vulnerable_at: cannot auto-guess when fixed version is 0.0.0 pseudo-version'
+source:
+    id: GHSA-hf33-q6cf-c66f
+    created: 2026-09-22T10:10:27.07864-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6538.yaml b/data/reports/GO-2026-6538.yaml
new file mode 100644
index 0000000..7bb01e6
--- /dev/null
+++ b/data/reports/GO-2026-6538.yaml
@@ -0,0 +1,40 @@
+id: GO-2026-6538
+modules:
+    - module: github.com/falcosecurity/plugins/plugins/k8saudit
+      versions:
+        - fixed: 0.18.0
+      vulnerable_at: 0.17.0
+    - module: github.com/falcosecurity/plugins/plugins/k8saudit-aks
+      versions:
+        - fixed: 0.6.0
+      vulnerable_at: 0.5.1
+    - module: github.com/falcosecurity/plugins/plugins/k8saudit-eks
+      versions:
+        - fixed: 0.12.0
+      vulnerable_at: 0.11.0
+    - module: github.com/falcosecurity/plugins/plugins/k8saudit-gke
+      versions:
+        - fixed: 0.9.0
+      vulnerable_at: 0.8.0
+    - module: github.com/falcosecurity/plugins/plugins/k8saudit-ovh
+      versions:
+        - fixed: 0.6.0
+      vulnerable_at: 0.5.0
+summary: |-
+    k8saudit shipped rules do not detect privileged/sensitive settings on init or
+    ephemeral containers in github.com/falcosecurity/plugins/plugins/k8saudit
+ghsas:
+    - GHSA-jhjp-4c2q-xmx4
+references:
+    - advisory: https://github.com/falcosecurity/plugins/security/advisories/GHSA-jhjp-4c2q-xmx4
+    - web: https://github.com/falcosecurity/plugins/commit/0adb9b3c7e2c8bad53f30d01c057e038b2afa5e1
+    - web: https://github.com/falcosecurity/plugins/pull/1400
+    - web: https://github.com/falcosecurity/plugins/releases/tag/plugins/k8saudit-aks/v0.6.0
+    - web: https://github.com/falcosecurity/plugins/releases/tag/plugins/k8saudit-eks/v0.12.0
+    - web: https://github.com/falcosecurity/plugins/releases/tag/plugins/k8saudit-gke/v0.9.0
+    - web: https://github.com/falcosecurity/plugins/releases/tag/plugins/k8saudit-ovh/v0.6.0
+    - web: https://github.com/falcosecurity/plugins/releases/tag/plugins/k8saudit/v0.18.0
+source:
+    id: GHSA-jhjp-4c2q-xmx4
+    created: 2026-09-22T10:10:20.276412-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6539.yaml b/data/reports/GO-2026-6539.yaml
new file mode 100644
index 0000000..37e7ff4
--- /dev/null
+++ b/data/reports/GO-2026-6539.yaml
@@ -0,0 +1,26 @@
+id: GO-2026-6539
+modules:
+    - module: github.com/lucasdillmann/nginx-ignition
+      versions:
+        - introduced: 0.0.0-20260126024607-cbaf0fc16ed8
+        - fixed: 0.0.0-20260526022344-0c988fc1277c
+summary: |-
+    nginx ignition has ParseAcceptLanguage `_` separator bypass that enables ~75x
+    CPU amplification via Accept-Language header in i18nMiddleware in github.com/lucasdillmann/nginx-ignition
+cves:
+    - CVE-2026-61629
+ghsas:
+    - GHSA-jr34-h97m-9hpx
+references:
+    - advisory: https://github.com/lucasdillmann/nginx-ignition/security/advisories/GHSA-jr34-h97m-9hpx
+    - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-61629
+    - fix: https://github.com/lucasdillmann/nginx-ignition/commit/0c988fc1277c7d291725e8373313f8486fa1b31a
+    - fix: https://github.com/lucasdillmann/nginx-ignition/commit/cbaf0fc16ed873f7178a2ca9b0d00a696e44b485
+    - fix: https://github.com/lucasdillmann/nginx-ignition/pull/125
+    - web: https://github.com/lucasdillmann/nginx-ignition/releases/tag/2.40.1
+notes:
+    - fix: 'github.com/lucasdillmann/nginx-ignition: could not add vulnerable_at: cannot auto-guess when fixed version is 0.0.0 pseudo-version'
+source:
+    id: GHSA-jr34-h97m-9hpx
+    created: 2026-09-22T10:10:12.874761-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6540.yaml b/data/reports/GO-2026-6540.yaml
new file mode 100644
index 0000000..d1757ce
--- /dev/null
+++ b/data/reports/GO-2026-6540.yaml
@@ -0,0 +1,23 @@
+id: GO-2026-6540
+modules:
+    - module: github.com/lucasdillmann/nginx-ignition
+      non_go_versions:
+        - fixed: 0.0.0-20260621194639-0586b4e55ab
+      vulnerable_at: 0.0.0-20260921012428-371de245b282
+summary: |-
+    nginx ignition has Unauthenticated Admin Account Creation via Onboarding Race
+    Condition in github.com/lucasdillmann/nginx-ignition
+cves:
+    - CVE-2026-61628
+ghsas:
+    - GHSA-pxcx-fv34-x9p5
+references:
+    - advisory: https://github.com/lucasdillmann/nginx-ignition/security/advisories/GHSA-pxcx-fv34-x9p5
+    - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-61628
+    - fix: https://github.com/lucasdillmann/nginx-ignition/commit/0586b4e55ab780676d3553a2592979dfa2fb0183
+    - fix: https://github.com/lucasdillmann/nginx-ignition/pull/131
+    - web: https://github.com/lucasdillmann/nginx-ignition/releases/tag/2.41.1
+source:
+    id: GHSA-pxcx-fv34-x9p5
+    created: 2026-09-22T10:09:57.177936-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6541.yaml b/data/reports/GO-2026-6541.yaml
new file mode 100644
index 0000000..9b0d660
--- /dev/null
+++ b/data/reports/GO-2026-6541.yaml
@@ -0,0 +1,50 @@
+id: GO-2026-6541
+modules:
+    - module: github.com/grafana/grafana
+      non_go_versions:
+        - fixed: 1.9.2-0.20260616075434-82ef13993059
+      vulnerable_at: 5.4.5+incompatible
+    - module: github.com/grafana/grafana
+      non_go_versions:
+        - introduced: 13.0.0
+      vulnerable_at: 5.4.5+incompatible
+    - module: github.com/grafana/grafana
+      non_go_versions:
+        - introduced: 12.4.0
+      vulnerable_at: 5.4.5+incompatible
+    - module: github.com/grafana/grafana
+      non_go_versions:
+        - introduced: 12.3.0
+      vulnerable_at: 5.4.5+incompatible
+    - module: github.com/grafana/grafana
+      non_go_versions:
+        - introduced: 12.0.0
+      vulnerable_at: 5.4.5+incompatible
+    - module: github.com/grafana/grafana
+      versions:
+        - introduced: 2.0.0-beta1+incompatible
+      vulnerable_at: 5.4.5+incompatible
+summary: |-
+    Grafana: Pre-authentication denial of service in the public dashboard query
+    handler in github.com/grafana/grafana
+cves:
+    - CVE-2026-42127
+ghsas:
+    - GHSA-3w66-95m3-8jxg
+references:
+    - advisory: https://github.com/advisories/GHSA-3w66-95m3-8jxg
+    - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-42127
+    - fix: https://github.com/grafana/grafana/commit/82ef13993059351bf21de35b8488bbd9b42df4f4
+    - fix: https://github.com/grafana/grafana/pull/125789
+    - web: https://github.com/grafana/grafana/releases/tag/v11.6.15
+    - web: https://github.com/grafana/grafana/releases/tag/v12.2.9
+    - web: https://github.com/grafana/grafana/releases/tag/v12.3.7
+    - web: https://github.com/grafana/grafana/releases/tag/v12.4.4
+    - web: https://github.com/grafana/grafana/releases/tag/v13.0.2
+    - web: https://grafana.com/security/security-advisories/cve-2026-42127
+notes:
+    - fix: 'module merge error: could not merge versions of module github.com/grafana/grafana: introduced and fixed versions must alternate'
+source:
+    id: GHSA-3w66-95m3-8jxg
+    created: 2026-09-22T10:09:48.252869-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6542.yaml b/data/reports/GO-2026-6542.yaml
new file mode 100644
index 0000000..ef32f7a
--- /dev/null
+++ b/data/reports/GO-2026-6542.yaml
@@ -0,0 +1,37 @@
+id: GO-2026-6542
+modules:
+    - module: github.com/grafana/grafana
+      non_go_versions:
+        - fixed: 1.9.2-0.20260616075434-82ef13993059
+      vulnerable_at: 5.4.5+incompatible
+    - module: github.com/grafana/grafana
+      non_go_versions:
+        - introduced: 13.0.0
+      vulnerable_at: 5.4.5+incompatible
+    - module: github.com/grafana/grafana
+      versions:
+        - introduced: 2.0.0-beta1+incompatible
+      vulnerable_at: 5.4.5+incompatible
+summary: |-
+    Grafana geomap panel's XYZ tile layer has a sanitize-then-interpolate ordering
+    bug in github.com/grafana/grafana
+cves:
+    - CVE-2026-9029
+ghsas:
+    - GHSA-9g84-39mm-q4p3
+references:
+    - advisory: https://github.com/advisories/GHSA-9g84-39mm-q4p3
+    - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-9029
+    - fix: https://github.com/grafana/grafana/commit/3fcdbc5a6e5c955bd42bd3715dd03cbad2b078c1
+    - fix: https://github.com/grafana/grafana/commit/42cdc39124912a8506a0c613c319c345aa950b29
+    - fix: https://github.com/grafana/grafana/commit/82ef13993059351bf21de35b8488bbd9b42df4f4
+    - fix: https://github.com/grafana/grafana/commit/dc695b9649530064e19c7c120bd6ebe104908e58
+    - web: https://github.com/grafana/grafana/releases/tag/v12.4.4
+    - web: https://github.com/grafana/grafana/releases/tag/v13.0.2
+    - web: https://grafana.com/security/security-advisories/cve-2026-9029
+notes:
+    - fix: 'module merge error: could not merge versions of module github.com/grafana/grafana: introduced and fixed versions must alternate'
+source:
+    id: GHSA-9g84-39mm-q4p3
+    created: 2026-09-22T10:09:39.482191-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6543.yaml b/data/reports/GO-2026-6543.yaml
new file mode 100644
index 0000000..61237bf
--- /dev/null
+++ b/data/reports/GO-2026-6543.yaml
@@ -0,0 +1,21 @@
+id: GO-2026-6543
+modules:
+    - module: github.com/ubuntu/adsys
+      non_go_versions:
+        - fixed: 0.16.3-0.20250318112551-8b1939f96d38
+      vulnerable_at: 0.0.0-20201015075421-5a3d5de42f92
+summary: Canonical ADSys Uses a Less Trusted Source in github.com/ubuntu/adsys
+cves:
+    - CVE-2026-12249
+ghsas:
+    - GHSA-crm4-q7v4-c2r2
+references:
+    - advisory: https://github.com/advisories/GHSA-crm4-q7v4-c2r2
+    - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-12249
+    - fix: https://github.com/ubuntu/adsys/commit/8b1939f96d3827b4426eb06c1ced5bf317b0a99d
+    - web: https://github.com/ubuntu/adsys/releases/tag/v0.16.3
+    - web: https://ubuntu.com/security/CVE-2026-12249
+source:
+    id: GHSA-crm4-q7v4-c2r2
+    created: 2026-09-22T10:09:22.09677-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6544.yaml b/data/reports/GO-2026-6544.yaml
new file mode 100644
index 0000000..612635f
--- /dev/null
+++ b/data/reports/GO-2026-6544.yaml
@@ -0,0 +1,55 @@
+id: GO-2026-6544
+modules:
+    - module: github.com/grafana/grafana
+      non_go_versions:
+        - fixed: 1.9.2-0.20260616075434-82ef13993059
+      vulnerable_at: 5.4.5+incompatible
+    - module: github.com/grafana/grafana
+      non_go_versions:
+        - introduced: 12.4.0
+      vulnerable_at: 5.4.5+incompatible
+    - module: github.com/grafana/grafana
+      non_go_versions:
+        - introduced: 13.0.0
+      vulnerable_at: 5.4.5+incompatible
+    - module: github.com/grafana/grafana
+      non_go_versions:
+        - introduced: 12.3.0
+      vulnerable_at: 5.4.5+incompatible
+    - module: github.com/grafana/grafana
+      non_go_versions:
+        - introduced: 12.0.0
+      vulnerable_at: 5.4.5+incompatible
+    - module: github.com/grafana/grafana
+      versions:
+        - introduced: 2.0.0-beta1+incompatible
+      vulnerable_at: 5.4.5+incompatible
+summary: |-
+    Grafana Loki datasource plugin's callResource handler contains a path traversal
+    vulnerability. in github.com/grafana/grafana
+cves:
+    - CVE-2026-42129
+ghsas:
+    - GHSA-f74p-cwhp-x2wx
+references:
+    - advisory: https://github.com/advisories/GHSA-f74p-cwhp-x2wx
+    - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-42129
+    - fix: https://github.com/grafana/grafana/commit/3fcdbc5a6e5c955bd42bd3715dd03cbad2b078c1
+    - fix: https://github.com/grafana/grafana/commit/42cdc39124912a8506a0c613c319c345aa950b29
+    - fix: https://github.com/grafana/grafana/commit/82ef13993059351bf21de35b8488bbd9b42df4f4
+    - fix: https://github.com/grafana/grafana/commit/d27d2eba9c509d16f214d290436a6ad0bd9c6c01
+    - fix: https://github.com/grafana/grafana/commit/dd5dc51681ff0133ddb2e206c2ea318713aeca16
+    - fix: https://github.com/grafana/grafana/commit/eeb08ceb020c4381242d8400e5878044e9877505
+    - fix: https://github.com/grafana/grafana/commit/f70d3e480274a5dbd12006338c393f4b05d441ca
+    - web: https://github.com/grafana/grafana/releases/tag/v11.6.15
+    - web: https://github.com/grafana/grafana/releases/tag/v12.2.9
+    - web: https://github.com/grafana/grafana/releases/tag/v12.3.7
+    - web: https://github.com/grafana/grafana/releases/tag/v12.4.4
+    - web: https://github.com/grafana/grafana/releases/tag/v13.0.2
+    - web: https://grafana.com/security/security-advisories/cve-2026-42129
+notes:
+    - fix: 'module merge error: could not merge versions of module github.com/grafana/grafana: introduced and fixed versions must alternate'
+source:
+    id: GHSA-f74p-cwhp-x2wx
+    created: 2026-09-22T10:09:12.50033-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6545.yaml b/data/reports/GO-2026-6545.yaml
new file mode 100644
index 0000000..52d3de4
--- /dev/null
+++ b/data/reports/GO-2026-6545.yaml
@@ -0,0 +1,53 @@
+id: GO-2026-6545
+modules:
+    - module: github.com/grafana/grafana
+      non_go_versions:
+        - fixed: 1.9.2-0.20260616075434-82ef13993059
+      vulnerable_at: 5.4.5+incompatible
+    - module: github.com/grafana/grafana
+      non_go_versions:
+        - introduced: 12.4.0
+      vulnerable_at: 5.4.5+incompatible
+    - module: github.com/grafana/grafana
+      non_go_versions:
+        - introduced: 13.0.0
+      vulnerable_at: 5.4.5+incompatible
+    - module: github.com/grafana/grafana
+      non_go_versions:
+        - introduced: 12.3.0
+      vulnerable_at: 5.4.5+incompatible
+    - module: github.com/grafana/grafana
+      non_go_versions:
+        - introduced: 12.0.0
+      vulnerable_at: 5.4.5+incompatible
+    - module: github.com/grafana/grafana
+      versions:
+        - introduced: 2.0.0-beta1+incompatible
+      vulnerable_at: 5.4.5+incompatible
+summary: 'Grafana: Path traversal in the Tempo and Loki data source plugins in github.com/grafana/grafana'
+cves:
+    - CVE-2026-10601
+ghsas:
+    - GHSA-9493-h4f5-633x
+references:
+    - advisory: https://github.com/advisories/GHSA-9493-h4f5-633x
+    - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-10601
+    - fix: https://github.com/grafana/grafana/commit/3fcdbc5a6e5c955bd42bd3715dd03cbad2b078c1
+    - fix: https://github.com/grafana/grafana/commit/42cdc39124912a8506a0c613c319c345aa950b29
+    - fix: https://github.com/grafana/grafana/commit/82ef13993059351bf21de35b8488bbd9b42df4f4
+    - fix: https://github.com/grafana/grafana/commit/d27d2eba9c509d16f214d290436a6ad0bd9c6c01
+    - fix: https://github.com/grafana/grafana/commit/dd5dc51681ff0133ddb2e206c2ea318713aeca16
+    - fix: https://github.com/grafana/grafana/commit/f70d3e480274a5dbd12006338c393f4b05d441ca
+    - fix: https://github.com/grafana/grafana/pull/125789
+    - web: https://github.com/grafana/grafana/releases/tag/v11.6.15
+    - web: https://github.com/grafana/grafana/releases/tag/v12.2.9
+    - web: https://github.com/grafana/grafana/releases/tag/v12.3.7
+    - web: https://github.com/grafana/grafana/releases/tag/v12.4.4
+    - web: https://github.com/grafana/grafana/releases/tag/v13.0.2
+    - web: https://grafana.com/security/security-advisories/cve-2026-10601
+notes:
+    - fix: 'module merge error: could not merge versions of module github.com/grafana/grafana: introduced and fixed versions must alternate'
+source:
+    id: GHSA-9493-h4f5-633x
+    created: 2026-09-22T10:06:46.262469-04:00
+review_status: UNREVIEWED