data/reports: review 2 first-party reports

For golang/vulndb#5005
For golang/vulndb#5006
Fixes golang/vulndb#6149
Fixes golang/vulndb#6150

Change-Id: I0ddb1a5e0f00c34eb5fb7307de6e526569753283
Reviewed-on: https://go-review.googlesource.com/c/vulndb/+/813240
Auto-Submit: Neal Patel <nealpatel@google.com>
LUCI-TryBot-Result: golang-scoped@luci-project-accounts.iam.gserviceaccount.com <golang-scoped@luci-project-accounts.iam.gserviceaccount.com>
Reviewed-by: Nicholas Husin <husin@google.com>
diff --git a/data/cve/v5/GO-2026-5005.json b/data/cve/v5/GO-2026-5005.json
index 0acb1e9..b321426 100644
--- a/data/cve/v5/GO-2026-5005.json
+++ b/data/cve/v5/GO-2026-5005.json
@@ -53,10 +53,7 @@
           "url": "https://go.dev/issue/79436"
         },
         {
-          "url": "https://go.dev/cl/778640"
-        },
-        {
-          "url": "https://go.dev/cl/778641"
+          "url": "https://go.dev/cl/778642"
         },
         {
           "url": "https://groups.google.com/g/golang-announce/c/a082jnz-LvI"
diff --git a/data/cve/v5/GO-2026-5006.json b/data/cve/v5/GO-2026-5006.json
index a7cc98f..011cc33 100644
--- a/data/cve/v5/GO-2026-5006.json
+++ b/data/cve/v5/GO-2026-5006.json
@@ -56,7 +56,10 @@
           "url": "https://go.dev/issue/79435"
         },
         {
-          "url": "https://go.dev/cl/778642"
+          "url": "https://go.dev/cl/778640"
+        },
+        {
+          "url": "https://go.dev/cl/778641"
         },
         {
           "url": "https://groups.google.com/g/golang-announce/c/a082jnz-LvI"
diff --git a/data/osv/GO-2026-5005.json b/data/osv/GO-2026-5005.json
index 077c03f..b9333f4 100644
--- a/data/osv/GO-2026-5005.json
+++ b/data/osv/GO-2026-5005.json
@@ -4,7 +4,8 @@
   "modified": "0001-01-01T00:00:00Z",
   "published": "0001-01-01T00:00:00Z",
   "aliases": [
-    "CVE-2026-39833"
+    "CVE-2026-39833",
+    "GHSA-jppx-rxg9-jmrx"
   ],
   "summary": "Invoking key constraints not enforced in golang.org/x/crypto/ssh/agent",
   "details": "The in-memory keyring returned by NewKeyring() silently accepted keys with the ConfirmBeforeUse constraint but never enforced it. The key would sign without any confirmation prompt, with no indication to the caller that the constraint was not in effect. NewKeyring() now returns an error when unsupported constraints are requested.",
@@ -46,11 +47,7 @@
     },
     {
       "type": "FIX",
-      "url": "https://go.dev/cl/778640"
-    },
-    {
-      "type": "FIX",
-      "url": "https://go.dev/cl/778641"
+      "url": "https://go.dev/cl/778642"
     },
     {
       "type": "WEB",
diff --git a/data/osv/GO-2026-5006.json b/data/osv/GO-2026-5006.json
index 351cd2b..e8aa4b0 100644
--- a/data/osv/GO-2026-5006.json
+++ b/data/osv/GO-2026-5006.json
@@ -4,7 +4,8 @@
   "modified": "0001-01-01T00:00:00Z",
   "published": "0001-01-01T00:00:00Z",
   "aliases": [
-    "CVE-2026-39832"
+    "CVE-2026-39832",
+    "GHSA-f5wc-c3c7-36mc"
   ],
   "summary": "Invoking agent constraints dropped when forwarding keys in golang.org/x/crypto/ssh/agent",
   "details": "When adding a key to a remote agent constraint extensions such as restrict-destination-v00@openssh.com were not serialized in the request. Destination restrictions were silently stripped when forwarding keys, allowing unrestricted use of the key on the remote host. The client now serializes all constraint extensions. Additionally, the in-memory keyring returned by NewKeyring() now rejects keys with unsupported constraint extensions instead of silently ignoring them.",
@@ -47,7 +48,11 @@
     },
     {
       "type": "FIX",
-      "url": "https://go.dev/cl/778642"
+      "url": "https://go.dev/cl/778640"
+    },
+    {
+      "type": "FIX",
+      "url": "https://go.dev/cl/778641"
     },
     {
       "type": "WEB",
diff --git a/data/reports/GO-2026-5005.yaml b/data/reports/GO-2026-5005.yaml
index 84c713e..0ab38a3 100644
--- a/data/reports/GO-2026-5005.yaml
+++ b/data/reports/GO-2026-5005.yaml
@@ -17,12 +17,13 @@
     that the constraint was not in effect. NewKeyring()
     now returns an error when unsupported constraints are
     requested.
+ghsas:
+    - GHSA-jppx-rxg9-jmrx
 credits:
     - NCC Group Cryptography Services, sponsored by Teleport
 references:
     - report: https://go.dev/issue/79436
-    - fix: https://go.dev/cl/778640
-    - fix: https://go.dev/cl/778641
+    - fix: https://go.dev/cl/778642
     - web: https://groups.google.com/g/golang-announce/c/a082jnz-LvI
 cve_metadata:
     id: CVE-2026-39833
diff --git a/data/reports/GO-2026-5006.yaml b/data/reports/GO-2026-5006.yaml
index 4ae726a..039498d 100644
--- a/data/reports/GO-2026-5006.yaml
+++ b/data/reports/GO-2026-5006.yaml
@@ -19,11 +19,14 @@
     all constraint extensions. Additionally, the in-memory keyring
     returned by NewKeyring() now rejects keys with unsupported
     constraint extensions instead of silently ignoring them.
+ghsas:
+    - GHSA-f5wc-c3c7-36mc
 credits:
     - NCC Group Cryptography Services, sponsored by Teleport
 references:
     - report: https://go.dev/issue/79435
-    - fix: https://go.dev/cl/778642
+    - fix: https://go.dev/cl/778640
+    - fix: https://go.dev/cl/778641
     - web: https://groups.google.com/g/golang-announce/c/a082jnz-LvI
 cve_metadata:
     id: CVE-2026-39832