data/reports: review 2 first-party reports For golang/vulndb#5005 For golang/vulndb#5006 Fixes golang/vulndb#6149 Fixes golang/vulndb#6150 Change-Id: I0ddb1a5e0f00c34eb5fb7307de6e526569753283 Reviewed-on: https://go-review.googlesource.com/c/vulndb/+/813240 Auto-Submit: Neal Patel <nealpatel@google.com> LUCI-TryBot-Result: golang-scoped@luci-project-accounts.iam.gserviceaccount.com <golang-scoped@luci-project-accounts.iam.gserviceaccount.com> Reviewed-by: Nicholas Husin <husin@google.com>
diff --git a/data/cve/v5/GO-2026-5005.json b/data/cve/v5/GO-2026-5005.json index 0acb1e9..b321426 100644 --- a/data/cve/v5/GO-2026-5005.json +++ b/data/cve/v5/GO-2026-5005.json
@@ -53,10 +53,7 @@ "url": "https://go.dev/issue/79436" }, { - "url": "https://go.dev/cl/778640" - }, - { - "url": "https://go.dev/cl/778641" + "url": "https://go.dev/cl/778642" }, { "url": "https://groups.google.com/g/golang-announce/c/a082jnz-LvI"
diff --git a/data/cve/v5/GO-2026-5006.json b/data/cve/v5/GO-2026-5006.json index a7cc98f..011cc33 100644 --- a/data/cve/v5/GO-2026-5006.json +++ b/data/cve/v5/GO-2026-5006.json
@@ -56,7 +56,10 @@ "url": "https://go.dev/issue/79435" }, { - "url": "https://go.dev/cl/778642" + "url": "https://go.dev/cl/778640" + }, + { + "url": "https://go.dev/cl/778641" }, { "url": "https://groups.google.com/g/golang-announce/c/a082jnz-LvI"
diff --git a/data/osv/GO-2026-5005.json b/data/osv/GO-2026-5005.json index 077c03f..b9333f4 100644 --- a/data/osv/GO-2026-5005.json +++ b/data/osv/GO-2026-5005.json
@@ -4,7 +4,8 @@ "modified": "0001-01-01T00:00:00Z", "published": "0001-01-01T00:00:00Z", "aliases": [ - "CVE-2026-39833" + "CVE-2026-39833", + "GHSA-jppx-rxg9-jmrx" ], "summary": "Invoking key constraints not enforced in golang.org/x/crypto/ssh/agent", "details": "The in-memory keyring returned by NewKeyring() silently accepted keys with the ConfirmBeforeUse constraint but never enforced it. The key would sign without any confirmation prompt, with no indication to the caller that the constraint was not in effect. NewKeyring() now returns an error when unsupported constraints are requested.", @@ -46,11 +47,7 @@ }, { "type": "FIX", - "url": "https://go.dev/cl/778640" - }, - { - "type": "FIX", - "url": "https://go.dev/cl/778641" + "url": "https://go.dev/cl/778642" }, { "type": "WEB",
diff --git a/data/osv/GO-2026-5006.json b/data/osv/GO-2026-5006.json index 351cd2b..e8aa4b0 100644 --- a/data/osv/GO-2026-5006.json +++ b/data/osv/GO-2026-5006.json
@@ -4,7 +4,8 @@ "modified": "0001-01-01T00:00:00Z", "published": "0001-01-01T00:00:00Z", "aliases": [ - "CVE-2026-39832" + "CVE-2026-39832", + "GHSA-f5wc-c3c7-36mc" ], "summary": "Invoking agent constraints dropped when forwarding keys in golang.org/x/crypto/ssh/agent", "details": "When adding a key to a remote agent constraint extensions such as restrict-destination-v00@openssh.com were not serialized in the request. Destination restrictions were silently stripped when forwarding keys, allowing unrestricted use of the key on the remote host. The client now serializes all constraint extensions. Additionally, the in-memory keyring returned by NewKeyring() now rejects keys with unsupported constraint extensions instead of silently ignoring them.", @@ -47,7 +48,11 @@ }, { "type": "FIX", - "url": "https://go.dev/cl/778642" + "url": "https://go.dev/cl/778640" + }, + { + "type": "FIX", + "url": "https://go.dev/cl/778641" }, { "type": "WEB",
diff --git a/data/reports/GO-2026-5005.yaml b/data/reports/GO-2026-5005.yaml index 84c713e..0ab38a3 100644 --- a/data/reports/GO-2026-5005.yaml +++ b/data/reports/GO-2026-5005.yaml
@@ -17,12 +17,13 @@ that the constraint was not in effect. NewKeyring() now returns an error when unsupported constraints are requested. +ghsas: + - GHSA-jppx-rxg9-jmrx credits: - NCC Group Cryptography Services, sponsored by Teleport references: - report: https://go.dev/issue/79436 - - fix: https://go.dev/cl/778640 - - fix: https://go.dev/cl/778641 + - fix: https://go.dev/cl/778642 - web: https://groups.google.com/g/golang-announce/c/a082jnz-LvI cve_metadata: id: CVE-2026-39833
diff --git a/data/reports/GO-2026-5006.yaml b/data/reports/GO-2026-5006.yaml index 4ae726a..039498d 100644 --- a/data/reports/GO-2026-5006.yaml +++ b/data/reports/GO-2026-5006.yaml
@@ -19,11 +19,14 @@ all constraint extensions. Additionally, the in-memory keyring returned by NewKeyring() now rejects keys with unsupported constraint extensions instead of silently ignoring them. +ghsas: + - GHSA-f5wc-c3c7-36mc credits: - NCC Group Cryptography Services, sponsored by Teleport references: - report: https://go.dev/issue/79435 - - fix: https://go.dev/cl/778642 + - fix: https://go.dev/cl/778640 + - fix: https://go.dev/cl/778641 - web: https://groups.google.com/g/golang-announce/c/a082jnz-LvI cve_metadata: id: CVE-2026-39832