data/reports: add 66 reports - data/reports/GO-2026-5929.yaml - data/reports/GO-2026-5930.yaml - data/reports/GO-2026-5933.yaml - data/reports/GO-2026-5934.yaml - data/reports/GO-2026-5935.yaml - data/reports/GO-2026-5936.yaml - data/reports/GO-2026-5937.yaml - data/reports/GO-2026-5938.yaml - data/reports/GO-2026-5939.yaml - data/reports/GO-2026-5940.yaml - data/reports/GO-2026-5941.yaml - data/reports/GO-2026-5944.yaml - data/reports/GO-2026-5945.yaml - data/reports/GO-2026-5946.yaml - data/reports/GO-2026-5947.yaml - data/reports/GO-2026-5948.yaml - data/reports/GO-2026-5949.yaml - data/reports/GO-2026-5950.yaml - data/reports/GO-2026-5951.yaml - data/reports/GO-2026-5952.yaml - data/reports/GO-2026-5953.yaml - data/reports/GO-2026-5956.yaml - data/reports/GO-2026-5957.yaml - data/reports/GO-2026-5958.yaml - data/reports/GO-2026-5959.yaml - data/reports/GO-2026-5961.yaml - data/reports/GO-2026-5962.yaml - data/reports/GO-2026-5963.yaml - data/reports/GO-2026-5964.yaml - data/reports/GO-2026-5965.yaml - data/reports/GO-2026-5966.yaml - data/reports/GO-2026-5967.yaml - data/reports/GO-2026-5968.yaml - data/reports/GO-2026-5969.yaml - data/reports/GO-2026-5973.yaml - data/reports/GO-2026-5974.yaml - data/reports/GO-2026-5975.yaml - data/reports/GO-2026-5976.yaml - data/reports/GO-2026-5977.yaml - data/reports/GO-2026-5978.yaml - data/reports/GO-2026-5979.yaml - data/reports/GO-2026-5980.yaml - data/reports/GO-2026-5981.yaml - data/reports/GO-2026-5982.yaml - data/reports/GO-2026-5984.yaml - data/reports/GO-2026-5985.yaml - data/reports/GO-2026-5986.yaml - data/reports/GO-2026-5988.yaml - data/reports/GO-2026-5990.yaml - data/reports/GO-2026-5991.yaml - data/reports/GO-2026-5992.yaml - data/reports/GO-2026-5996.yaml - data/reports/GO-2026-5997.yaml - data/reports/GO-2026-5998.yaml - data/reports/GO-2026-5999.yaml - data/reports/GO-2026-6002.yaml - data/reports/GO-2026-6003.yaml - data/reports/GO-2026-6004.yaml - data/reports/GO-2026-6005.yaml - data/reports/GO-2026-6006.yaml - data/reports/GO-2026-6007.yaml - data/reports/GO-2026-6008.yaml - data/reports/GO-2026-6009.yaml - data/reports/GO-2026-6011.yaml - data/reports/GO-2026-6012.yaml - data/reports/GO-2026-6014.yaml Fixes golang/vulndb#5929 Fixes golang/vulndb#5930 Fixes golang/vulndb#5933 Fixes golang/vulndb#5934 Fixes golang/vulndb#5935 Fixes golang/vulndb#5936 Fixes golang/vulndb#5937 Fixes golang/vulndb#5938 Fixes golang/vulndb#5939 Fixes golang/vulndb#5940 Fixes golang/vulndb#5941 Fixes golang/vulndb#5944 Fixes golang/vulndb#5945 Fixes golang/vulndb#5946 Fixes golang/vulndb#5947 Fixes golang/vulndb#5948 Fixes golang/vulndb#5949 Fixes golang/vulndb#5950 Fixes golang/vulndb#5951 Fixes golang/vulndb#5952 Fixes golang/vulndb#5953 Fixes golang/vulndb#5956 Fixes golang/vulndb#5957 Fixes golang/vulndb#5958 Fixes golang/vulndb#5959 Fixes golang/vulndb#5961 Fixes golang/vulndb#5962 Fixes golang/vulndb#5963 Fixes golang/vulndb#5964 Fixes golang/vulndb#5965 Fixes golang/vulndb#5966 Fixes golang/vulndb#5967 Fixes golang/vulndb#5968 Fixes golang/vulndb#5969 Fixes golang/vulndb#5973 Fixes golang/vulndb#5974 Fixes golang/vulndb#5975 Fixes golang/vulndb#5976 Fixes golang/vulndb#5977 Fixes golang/vulndb#5978 Fixes golang/vulndb#5979 Fixes golang/vulndb#5980 Fixes golang/vulndb#5981 Fixes golang/vulndb#5982 Fixes golang/vulndb#5984 Fixes golang/vulndb#5985 Fixes golang/vulndb#5986 Fixes golang/vulndb#5988 Fixes golang/vulndb#5990 Fixes golang/vulndb#5991 Fixes golang/vulndb#5992 Fixes golang/vulndb#5996 Fixes golang/vulndb#5997 Fixes golang/vulndb#5998 Fixes golang/vulndb#5999 Fixes golang/vulndb#6002 Fixes golang/vulndb#6003 Fixes golang/vulndb#6004 Fixes golang/vulndb#6005 Fixes golang/vulndb#6006 Fixes golang/vulndb#6007 Fixes golang/vulndb#6008 Fixes golang/vulndb#6009 Fixes golang/vulndb#6011 Fixes golang/vulndb#6012 Fixes golang/vulndb#6014 Change-Id: I3b8ee51b15f56eef91cf025d01f75eea6f18bd4f Reviewed-on: https://go-review.googlesource.com/c/vulndb/+/802300 Reviewed-by: Nicholas Husin <husin@google.com> Reviewed-by: Ethan Lee <ethanalee@google.com> LUCI-TryBot-Result: golang-scoped@luci-project-accounts.iam.gserviceaccount.com <golang-scoped@luci-project-accounts.iam.gserviceaccount.com> Auto-Submit: Nicholas Husin <husin@google.com>
diff --git a/data/osv/GO-2026-5929.json b/data/osv/GO-2026-5929.json new file mode 100644 index 0000000..ab0dc28 --- /dev/null +++ b/data/osv/GO-2026-5929.json
@@ -0,0 +1,48 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-5929", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-44342", + "GHSA-26v7-h57m-gh9m" + ], + "summary": "New API is vulnerable to CSRF through user email binding in github.com/QuantumNous/new-api", + "details": "New API is vulnerable to CSRF through user email binding in github.com/QuantumNous/new-api", + "affected": [ + { + "package": { + "name": "github.com/QuantumNous/new-api", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.12.0-alpha.1" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/QuantumNous/new-api/security/advisories/GHSA-26v7-h57m-gh9m" + }, + { + "type": "FIX", + "url": "https://github.com/QuantumNous/new-api/commit/e099117c61391abdf888fb75e382a582e550bd0e" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-5929", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-5930.json b/data/osv/GO-2026-5930.json new file mode 100644 index 0000000..481ca2d --- /dev/null +++ b/data/osv/GO-2026-5930.json
@@ -0,0 +1,48 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-5930", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-33655", + "GHSA-6qcr-qxgr-m7fv" + ], + "summary": "New API: SSRF Protection Bypass via Unresolved Hostname in Notification URLs in github.com/QuantumNous/new-api", + "details": "New API: SSRF Protection Bypass via Unresolved Hostname in Notification URLs in github.com/QuantumNous/new-api", + "affected": [ + { + "package": { + "name": "github.com/QuantumNous/new-api", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.12.0-alpha.1" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/QuantumNous/new-api/security/advisories/GHSA-6qcr-qxgr-m7fv" + }, + { + "type": "FIX", + "url": "https://github.com/QuantumNous/new-api/commit/20399d3c8fcb4e3649d53163eb11940fd6763743" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-5930", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-5933.json b/data/osv/GO-2026-5933.json new file mode 100644 index 0000000..82483ac --- /dev/null +++ b/data/osv/GO-2026-5933.json
@@ -0,0 +1,43 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-5933", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "GHSA-3g4q-2f67-2gvh" + ], + "summary": "netfoil has a resource leak in LRU cache in github.com/tinfoil-factory/netfoil", + "details": "netfoil has a resource leak in LRU cache in github.com/tinfoil-factory/netfoil", + "affected": [ + { + "package": { + "name": "github.com/tinfoil-factory/netfoil", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.3.0" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/tinfoil-factory/netfoil/security/advisories/GHSA-3g4q-2f67-2gvh" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-5933", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-5934.json b/data/osv/GO-2026-5934.json new file mode 100644 index 0000000..324c5bd --- /dev/null +++ b/data/osv/GO-2026-5934.json
@@ -0,0 +1,43 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-5934", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "GHSA-59qp-cfj3-rp64" + ], + "summary": "netfoil has a domain name filter bypass via multiple questions in github.com/tinfoil-factory/netfoil", + "details": "netfoil has a domain name filter bypass via multiple questions in github.com/tinfoil-factory/netfoil", + "affected": [ + { + "package": { + "name": "github.com/tinfoil-factory/netfoil", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.3.0" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/tinfoil-factory/netfoil/security/advisories/GHSA-59qp-cfj3-rp64" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-5934", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-5935.json b/data/osv/GO-2026-5935.json new file mode 100644 index 0000000..7e35b88 --- /dev/null +++ b/data/osv/GO-2026-5935.json
@@ -0,0 +1,43 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-5935", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "GHSA-7856-g3gv-9wq8" + ], + "summary": "netfoil: Attacker controlled data written to logs in github.com/tinfoil-factory/netfoil", + "details": "netfoil: Attacker controlled data written to logs in github.com/tinfoil-factory/netfoil", + "affected": [ + { + "package": { + "name": "github.com/tinfoil-factory/netfoil", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.3.0" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/tinfoil-factory/netfoil/security/advisories/GHSA-7856-g3gv-9wq8" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-5935", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-5936.json b/data/osv/GO-2026-5936.json new file mode 100644 index 0000000..a262565 --- /dev/null +++ b/data/osv/GO-2026-5936.json
@@ -0,0 +1,41 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-5936", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-53552", + "GHSA-26rh-24rg-j3vv" + ], + "summary": "Goploy: Cross-namespace IDOR and RCE via body-supplied row id in project and project_file handlers in github.com/zhenorzz/goploy", + "details": "Goploy: Cross-namespace IDOR and RCE via body-supplied row id in project and project_file handlers in github.com/zhenorzz/goploy", + "affected": [ + { + "package": { + "name": "github.com/zhenorzz/goploy", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/zhenorzz/goploy/security/advisories/GHSA-26rh-24rg-j3vv" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-5936", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-5937.json b/data/osv/GO-2026-5937.json new file mode 100644 index 0000000..be5759a --- /dev/null +++ b/data/osv/GO-2026-5937.json
@@ -0,0 +1,56 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-5937", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-53508", + "GHSA-2jcc-mxv7-p3f9" + ], + "summary": "oasdiff does not enforce --allow-external-refs=false on the git-revision load path (SSRF / local file read) in github.com/oasdiff/oasdiff", + "details": "oasdiff does not enforce --allow-external-refs=false on the git-revision load path (SSRF / local file read) in github.com/oasdiff/oasdiff", + "affected": [ + { + "package": { + "name": "github.com/oasdiff/oasdiff", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "1.13.2" + }, + { + "fixed": "1.18.1" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/oasdiff/oasdiff/security/advisories/GHSA-2jcc-mxv7-p3f9" + }, + { + "type": "FIX", + "url": "https://github.com/oasdiff/oasdiff/pull/832" + }, + { + "type": "FIX", + "url": "https://github.com/oasdiff/oasdiff/pull/974" + }, + { + "type": "FIX", + "url": "https://github.com/oasdiff/oasdiff/pull/975" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-5937", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-5938.json b/data/osv/GO-2026-5938.json new file mode 100644 index 0000000..03cf906 --- /dev/null +++ b/data/osv/GO-2026-5938.json
@@ -0,0 +1,41 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-5938", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-53553", + "GHSA-4g5x-hcwm-82jw" + ], + "summary": "Goploy: Arbitrary File Read via Path Traversal in /deploy/fileDiff allows Remote Server Compromise in github.com/zhenorzz/goploy", + "details": "Goploy: Arbitrary File Read via Path Traversal in /deploy/fileDiff allows Remote Server Compromise in github.com/zhenorzz/goploy", + "affected": [ + { + "package": { + "name": "github.com/zhenorzz/goploy", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/zhenorzz/goploy/security/advisories/GHSA-4g5x-hcwm-82jw" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-5938", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-5939.json b/data/osv/GO-2026-5939.json new file mode 100644 index 0000000..65bc099 --- /dev/null +++ b/data/osv/GO-2026-5939.json
@@ -0,0 +1,53 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-5939", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-10517", + "GHSA-698x-9w2p-7vvp" + ], + "summary": "Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints in github.com/quay/claircore", + "details": "Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints in github.com/quay/claircore", + "affected": [ + { + "package": { + "name": "github.com/quay/claircore", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-698x-9w2p-7vvp" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-10517" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2026-10517" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2486779" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-5939", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-5940.json b/data/osv/GO-2026-5940.json new file mode 100644 index 0000000..aea069a --- /dev/null +++ b/data/osv/GO-2026-5940.json
@@ -0,0 +1,61 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-5940", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-53572", + "GHSA-6w3m-4hhp-775q" + ], + "summary": "KEDA has PostgreSQL connection string parameter injection via incomplete whitespace escaping in github.com/kedacore/keda", + "details": "KEDA has PostgreSQL connection string parameter injection via incomplete whitespace escaping in github.com/kedacore/keda", + "affected": [ + { + "package": { + "name": "github.com/kedacore/keda", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": {} + }, + { + "package": { + "name": "github.com/kedacore/keda/v2", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "2.20.0" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/kedacore/keda/security/advisories/GHSA-6w3m-4hhp-775q" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-5940", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-5941.json b/data/osv/GO-2026-5941.json new file mode 100644 index 0000000..2bc3f10 --- /dev/null +++ b/data/osv/GO-2026-5941.json
@@ -0,0 +1,44 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-5941", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-53487", + "GHSA-gvhc-wv3v-7pf8" + ], + "summary": "Kite has an authenticated cluster RBAC bypass in /api/v1/overview in github.com/zxh326/kite", + "details": "Kite has an authenticated cluster RBAC bypass in /api/v1/overview in github.com/zxh326/kite", + "affected": [ + { + "package": { + "name": "github.com/zxh326/kite", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.12.3" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/kite-org/kite/security/advisories/GHSA-gvhc-wv3v-7pf8" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-5941", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-5944.json b/data/osv/GO-2026-5944.json new file mode 100644 index 0000000..db1cf49 --- /dev/null +++ b/data/osv/GO-2026-5944.json
@@ -0,0 +1,44 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-5944", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-50197", + "GHSA-659f-rgp5-w4wf" + ], + "summary": "Skipper: opaAuthorizeRequestWithBody filter bypasses OPA policy on Transfer-Encoding — chunked / HTTP/2 requests in github.com/zalando/skipper", + "details": "Skipper: opaAuthorizeRequestWithBody filter bypasses OPA policy on Transfer-Encoding — chunked / HTTP/2 requests in github.com/zalando/skipper", + "affected": [ + { + "package": { + "name": "github.com/zalando/skipper", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.26.10" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/zalando/skipper/security/advisories/GHSA-659f-rgp5-w4wf" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-5944", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-5945.json b/data/osv/GO-2026-5945.json new file mode 100644 index 0000000..40d2ff0 --- /dev/null +++ b/data/osv/GO-2026-5945.json
@@ -0,0 +1,53 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-5945", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-6815", + "GHSA-rmxx-v9rj-vpvg" + ], + "summary": "Casdoor: Arbitrary file write possible through Local File System storage provider in github.com/casdoor/casdoor", + "details": "Casdoor: Arbitrary file write possible through Local File System storage provider in github.com/casdoor/casdoor", + "affected": [ + { + "package": { + "name": "github.com/casdoor/casdoor", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-rmxx-v9rj-vpvg" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6815" + }, + { + "type": "WEB", + "url": "https://kb.cert.org/vuls/id/937808" + }, + { + "type": "WEB", + "url": "https://www.kb.cert.org/vuls/id/937808" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-5945", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-5946.json b/data/osv/GO-2026-5946.json new file mode 100644 index 0000000..74080bd --- /dev/null +++ b/data/osv/GO-2026-5946.json
@@ -0,0 +1,52 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-5946", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-52831", + "GHSA-v5px-423j-pf7p" + ], + "summary": "Nuclio: Unsanitized cron trigger event headers/body injected into CronJob shell command leads to persistent RCE in github.com/nuclio/nuclio", + "details": "Nuclio: Unsanitized cron trigger event headers/body injected into CronJob shell command leads to persistent RCE in github.com/nuclio/nuclio", + "affected": [ + { + "package": { + "name": "github.com/nuclio/nuclio", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.0.0-20260601075854-3356b86a8bfa" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/nuclio/nuclio/security/advisories/GHSA-v5px-423j-pf7p" + }, + { + "type": "FIX", + "url": "https://github.com/nuclio/nuclio/commit/3356b86a8bfab3f960aa420310ebff765df9dede" + }, + { + "type": "WEB", + "url": "https://github.com/nuclio/nuclio/releases/tag/1.16.4" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-5946", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-5947.json b/data/osv/GO-2026-5947.json new file mode 100644 index 0000000..98f08a1 --- /dev/null +++ b/data/osv/GO-2026-5947.json
@@ -0,0 +1,44 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-5947", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-53649", + "GHSA-xqhv-chqm-fhcc" + ], + "summary": "Joro: Unauthenticated Cross-Origin Plugin Upload Leads to RCE in github.com/BishopFox/joro", + "details": "Joro: Unauthenticated Cross-Origin Plugin Upload Leads to RCE in github.com/BishopFox/joro", + "affected": [ + { + "package": { + "name": "github.com/BishopFox/joro", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.0.0-20260601151442-5c0ca35db828" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/BishopFox/joro/security/advisories/GHSA-xqhv-chqm-fhcc" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-5947", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-5948.json b/data/osv/GO-2026-5948.json new file mode 100644 index 0000000..e8bfd90 --- /dev/null +++ b/data/osv/GO-2026-5948.json
@@ -0,0 +1,48 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-5948", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-50554", + "GHSA-588f-fvcv-xhvf" + ], + "summary": "Note Mark: Unauthenticated disclosure of soft-deleted note metadata via deleted=true on public books in github.com/enchant97/note-mark/backend", + "details": "Note Mark: Unauthenticated disclosure of soft-deleted note metadata via deleted=true on public books in github.com/enchant97/note-mark/backend", + "affected": [ + { + "package": { + "name": "github.com/enchant97/note-mark/backend", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.0.0-20260601210758-9c9b72740f22" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/enchant97/note-mark/security/advisories/GHSA-588f-fvcv-xhvf" + }, + { + "type": "WEB", + "url": "https://github.com/enchant97/note-mark/commit/9c9b72740f22a06131a8f64b53bb08e3b05b81a6" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-5948", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-5949.json b/data/osv/GO-2026-5949.json new file mode 100644 index 0000000..982527d --- /dev/null +++ b/data/osv/GO-2026-5949.json
@@ -0,0 +1,48 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-5949", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-50553", + "GHSA-rqrh-8wpv-x7hh" + ], + "summary": "Note Mark: Path traversal via unsanitized book/note slug in migrate export (sibling of GHSA-g49p) in github.com/enchant97/note-mark/backend", + "details": "Note Mark: Path traversal via unsanitized book/note slug in migrate export (sibling of GHSA-g49p) in github.com/enchant97/note-mark/backend", + "affected": [ + { + "package": { + "name": "github.com/enchant97/note-mark/backend", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.0.0-20260601210719-67b7de04308a" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/enchant97/note-mark/security/advisories/GHSA-rqrh-8wpv-x7hh" + }, + { + "type": "WEB", + "url": "https://github.com/enchant97/note-mark/commit/67b7de04308a858ef27ceff87b514067b6d667e5" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-5949", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-5950.json b/data/osv/GO-2026-5950.json new file mode 100644 index 0000000..eecfd0c --- /dev/null +++ b/data/osv/GO-2026-5950.json
@@ -0,0 +1,48 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-5950", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-53602", + "GHSA-339v-266x-79xr" + ], + "summary": "nebula-mesh: Host revocation is not durable - blocked/offboarded hosts can regain a valid certificate in github.com/forgekeep/nebula-mesh", + "details": "nebula-mesh: Host revocation is not durable - blocked/offboarded hosts can regain a valid certificate in github.com/forgekeep/nebula-mesh", + "affected": [ + { + "package": { + "name": "github.com/forgekeep/nebula-mesh", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.3.7" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/forgekeep/nebula-mesh/security/advisories/GHSA-339v-266x-79xr" + }, + { + "type": "REPORT", + "url": "https://github.com/forgekeep/nebula-mesh/issues/178" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-5950", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-5951.json b/data/osv/GO-2026-5951.json new file mode 100644 index 0000000..ec53c03 --- /dev/null +++ b/data/osv/GO-2026-5951.json
@@ -0,0 +1,69 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-5951", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-10219", + "GHSA-6jm8-4fhr-5w64" + ], + "summary": "GoClaw has a Command Injection issue in github.com/nextlevelbuilder/goclaw", + "details": "GoClaw has a Command Injection issue in github.com/nextlevelbuilder/goclaw", + "affected": [ + { + "package": { + "name": "github.com/nextlevelbuilder/goclaw", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-6jm8-4fhr-5w64" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-10219" + }, + { + "type": "FIX", + "url": "https://github.com/nextlevelbuilder/goclaw/pull/1155" + }, + { + "type": "REPORT", + "url": "https://github.com/nextlevelbuilder/goclaw/issues/1121" + }, + { + "type": "WEB", + "url": "https://vuldb.com/cve/CVE-2026-10219" + }, + { + "type": "WEB", + "url": "https://vuldb.com/submit/821939" + }, + { + "type": "WEB", + "url": "https://vuldb.com/vuln/367498" + }, + { + "type": "WEB", + "url": "https://vuldb.com/vuln/367498/cti" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-5951", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-5952.json b/data/osv/GO-2026-5952.json new file mode 100644 index 0000000..cc9b6dc --- /dev/null +++ b/data/osv/GO-2026-5952.json
@@ -0,0 +1,44 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-5952", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-49834", + "GHSA-9vcr-p3rj-q5q6" + ], + "summary": "sigstore-go has a multi-log threshold bypass via single compromised log in github.com/sigstore/sigstore-go", + "details": "sigstore-go has a multi-log threshold bypass via single compromised log in github.com/sigstore/sigstore-go", + "affected": [ + { + "package": { + "name": "github.com/sigstore/sigstore-go", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.2.0" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/sigstore/sigstore-go/security/advisories/GHSA-9vcr-p3rj-q5q6" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-5952", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-5953.json b/data/osv/GO-2026-5953.json new file mode 100644 index 0000000..70b87a2 --- /dev/null +++ b/data/osv/GO-2026-5953.json
@@ -0,0 +1,67 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-5953", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-9094", + "GHSA-c9w5-qp6m-m395" + ], + "summary": "Casdoor: GetTokenExchangeToken bypass through lack of cross-organization JWT signature check in github.com/casdoor/casdoor", + "details": "Casdoor: GetTokenExchangeToken bypass through lack of cross-organization JWT signature check in github.com/casdoor/casdoor.\n\nNOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.\n\n(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)\n\nThe additional affected modules and versions are: github.com/casdoor/casdoor before v2.387.0.", + "affected": [ + { + "package": { + "name": "github.com/casdoor/casdoor", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "custom_ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "2.387.0" + } + ] + } + ] + } + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-c9w5-qp6m-m395" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-9094" + }, + { + "type": "FIX", + "url": "https://github.com/casdoor/casdoor/commit/d92b8568686d" + }, + { + "type": "WEB", + "url": "https://kb.cert.org/vuls/id/780781" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-5953", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-5956.json b/data/osv/GO-2026-5956.json new file mode 100644 index 0000000..df11d50 --- /dev/null +++ b/data/osv/GO-2026-5956.json
@@ -0,0 +1,52 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-5956", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-55252", + "GHSA-h5g6-xmh4-hc37" + ], + "summary": "OpenRun: Redirect URL validation bypass using //host paths leads to Open Redirect in github.com/openrundev/openrun", + "details": "OpenRun: Redirect URL validation bypass using //host paths leads to Open Redirect in github.com/openrundev/openrun", + "affected": [ + { + "package": { + "name": "github.com/openrundev/openrun", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.17.7" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/openrundev/openrun/security/advisories/GHSA-h5g6-xmh4-hc37" + }, + { + "type": "FIX", + "url": "https://github.com/openrundev/openrun/commit/709da784fcf1311c85f30f3542cfa3601a78bbf0" + }, + { + "type": "WEB", + "url": "https://github.com/openrundev/openrun/releases/tag/v0.17.7" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-5956", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-5957.json b/data/osv/GO-2026-5957.json new file mode 100644 index 0000000..63e63d3 --- /dev/null +++ b/data/osv/GO-2026-5957.json
@@ -0,0 +1,48 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-5957", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-54158", + "GHSA-5xfx-xj4h-5p7r" + ], + "summary": "SiYuan: Stored XSS to RCE via attribute-view cell rendering in genAVValueHTML() in github.com/siyuan-note/siyuan/kernel", + "details": "SiYuan: Stored XSS to RCE via attribute-view cell rendering in genAVValueHTML() in github.com/siyuan-note/siyuan/kernel", + "affected": [ + { + "package": { + "name": "github.com/siyuan-note/siyuan/kernel", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.0.0-20260628153353-2d5d72223df4" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/siyuan-note/siyuan/security/advisories/GHSA-5xfx-xj4h-5p7r" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54158" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-5957", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-5958.json b/data/osv/GO-2026-5958.json new file mode 100644 index 0000000..5ea5301 --- /dev/null +++ b/data/osv/GO-2026-5958.json
@@ -0,0 +1,48 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-5958", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-54068", + "GHSA-gcm7-57gf-953c" + ], + "summary": "SiYuan: Unauthenticated SQLite Data Exfiltration via Template Injection in /api/icon/getDynamicIcon in github.com/siyuan-note/siyuan/kernel", + "details": "SiYuan: Unauthenticated SQLite Data Exfiltration via Template Injection in /api/icon/getDynamicIcon in github.com/siyuan-note/siyuan/kernel", + "affected": [ + { + "package": { + "name": "github.com/siyuan-note/siyuan/kernel", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.0.0-20260628153353-2d5d72223df4" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/siyuan-note/siyuan/security/advisories/GHSA-gcm7-57gf-953c" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54068" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-5958", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-5959.json b/data/osv/GO-2026-5959.json new file mode 100644 index 0000000..8ec4d94 --- /dev/null +++ b/data/osv/GO-2026-5959.json
@@ -0,0 +1,44 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-5959", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-54072", + "GHSA-h29v-hj44-q8cv" + ], + "summary": "Authorizer: Unvalidated redirect_uri in /authorize leaks OAuth2 tokens to attacker-controlled URL in github.com/authorizerdev/authorizer", + "details": "Authorizer: Unvalidated redirect_uri in /authorize leaks OAuth2 tokens to attacker-controlled URL in github.com/authorizerdev/authorizer", + "affected": [ + { + "package": { + "name": "github.com/authorizerdev/authorizer", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.0.0-20260409051328-bd3f5baf6d3d" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/authorizerdev/authorizer/security/advisories/GHSA-h29v-hj44-q8cv" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-5959", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-5961.json b/data/osv/GO-2026-5961.json new file mode 100644 index 0000000..fcc4511 --- /dev/null +++ b/data/osv/GO-2026-5961.json
@@ -0,0 +1,48 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-5961", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-54069", + "GHSA-hvr9-72v2-fff3" + ], + "summary": "SiYuan: Unauthenticated Admin API Access via Blanket chrome-extension:// Origin Allowlist in github.com/siyuan-note/siyuan/kernel", + "details": "SiYuan: Unauthenticated Admin API Access via Blanket chrome-extension:// Origin Allowlist in github.com/siyuan-note/siyuan/kernel", + "affected": [ + { + "package": { + "name": "github.com/siyuan-note/siyuan/kernel", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.0.0-20260628153353-2d5d72223df4" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/siyuan-note/siyuan/security/advisories/GHSA-hvr9-72v2-fff3" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54069" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-5961", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-5962.json b/data/osv/GO-2026-5962.json new file mode 100644 index 0000000..c7dc87e --- /dev/null +++ b/data/osv/GO-2026-5962.json
@@ -0,0 +1,65 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-5962", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-54088", + "GHSA-m93h-4hw7-5qcm" + ], + "summary": "File Browser: Command Injection via Authentication Hook Shell Substitution (Pre-Authentication RCE) in github.com/filebrowser/filebrowser", + "details": "File Browser: Command Injection via Authentication Hook Shell Substitution (Pre-Authentication RCE) in github.com/filebrowser/filebrowser", + "affected": [ + { + "package": { + "name": "github.com/filebrowser/filebrowser", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": {} + }, + { + "package": { + "name": "github.com/filebrowser/filebrowser/v2", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "2.63.6" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/filebrowser/filebrowser/security/advisories/GHSA-m93h-4hw7-5qcm" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54088" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-5962", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-5963.json b/data/osv/GO-2026-5963.json new file mode 100644 index 0000000..1ceb629 --- /dev/null +++ b/data/osv/GO-2026-5963.json
@@ -0,0 +1,48 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-5963", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-54067", + "GHSA-mvjr-vv3c-w4qv" + ], + "summary": "SiYuan: Stored XSS to RCE via CSS-snippet \u003cstyle\u003e breakout in renderSnippet() in github.com/siyuan-note/siyuan/kernel", + "details": "SiYuan: Stored XSS to RCE via CSS-snippet \u003cstyle\u003e breakout in renderSnippet() in github.com/siyuan-note/siyuan/kernel", + "affected": [ + { + "package": { + "name": "github.com/siyuan-note/siyuan/kernel", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.0.0-20260628153353-2d5d72223df4" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/siyuan-note/siyuan/security/advisories/GHSA-mvjr-vv3c-w4qv" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54067" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-5963", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-5964.json b/data/osv/GO-2026-5964.json new file mode 100644 index 0000000..d0929d5 --- /dev/null +++ b/data/osv/GO-2026-5964.json
@@ -0,0 +1,48 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-5964", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-54066", + "GHSA-p4m3-mgmm-c664" + ], + "summary": "SiYuan: Path Traversal via Double URL Encoding in /assets/*path (publish mode arbitrary file─read), Incomplete fix of CVE-2026-41894 in github.com/siyuan-note/siyuan/kernel", + "details": "SiYuan: Path Traversal via Double URL Encoding in /assets/*path (publish mode arbitrary file─read), Incomplete fix of CVE-2026-41894 in github.com/siyuan-note/siyuan/kernel", + "affected": [ + { + "package": { + "name": "github.com/siyuan-note/siyuan/kernel", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.0.0-20260628153353-2d5d72223df4" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/siyuan-note/siyuan/security/advisories/GHSA-p4m3-mgmm-c664" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54066" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-5964", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-5965.json b/data/osv/GO-2026-5965.json new file mode 100644 index 0000000..8d0a9a6 --- /dev/null +++ b/data/osv/GO-2026-5965.json
@@ -0,0 +1,48 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-5965", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-54070", + "GHSA-w7cg-whh7-xp28" + ], + "summary": "SiYuan: Stored XSS in Bazaar marketplace via package README event handlers in github.com/siyuan-note/siyuan/kernel", + "details": "SiYuan: Stored XSS in Bazaar marketplace via package README event handlers in github.com/siyuan-note/siyuan/kernel", + "affected": [ + { + "package": { + "name": "github.com/siyuan-note/siyuan/kernel", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.0.0-20260628153353-2d5d72223df4" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/siyuan-note/siyuan/security/advisories/GHSA-w7cg-whh7-xp28" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54070" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-5965", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-5966.json b/data/osv/GO-2026-5966.json new file mode 100644 index 0000000..44223c7 --- /dev/null +++ b/data/osv/GO-2026-5966.json
@@ -0,0 +1,62 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-5966", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-54089", + "GHSA-xqp3-jq6g-x3qm" + ], + "summary": "File Browser: Authentication Bypass via Proxy Auth Header Forgery in github.com/filebrowser/filebrowser", + "details": "File Browser: Authentication Bypass via Proxy Auth Header Forgery in github.com/filebrowser/filebrowser", + "affected": [ + { + "package": { + "name": "github.com/filebrowser/filebrowser", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": {} + }, + { + "package": { + "name": "github.com/filebrowser/filebrowser/v2", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "2.0.0-rc.1" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/filebrowser/filebrowser/security/advisories/GHSA-xqp3-jq6g-x3qm" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54089" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-5966", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-5967.json b/data/osv/GO-2026-5967.json new file mode 100644 index 0000000..00b5082 --- /dev/null +++ b/data/osv/GO-2026-5967.json
@@ -0,0 +1,48 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-5967", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-50551", + "GHSA-56mp-4f3v-fgj2" + ], + "summary": "SiYuan: Stored XSS to RCE via Unsanitized Attribute View Asset Cell Content in github.com/siyuan-note/siyuan/kernel", + "details": "SiYuan: Stored XSS to RCE via Unsanitized Attribute View Asset Cell Content in github.com/siyuan-note/siyuan/kernel", + "affected": [ + { + "package": { + "name": "github.com/siyuan-note/siyuan/kernel", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.0.0-20260628153353-2d5d72223df4" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/siyuan-note/siyuan/security/advisories/GHSA-56mp-4f3v-fgj2" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-50551" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-5967", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-5968.json b/data/osv/GO-2026-5968.json new file mode 100644 index 0000000..c2b658e --- /dev/null +++ b/data/osv/GO-2026-5968.json
@@ -0,0 +1,64 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-5968", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-54174", + "GHSA-fpg8-7664-jc5q" + ], + "summary": "melange: Incomplete package integrity verification allows data section substitution in chainguard.dev/apko", + "details": "melange: Incomplete package integrity verification allows data section substitution in chainguard.dev/apko", + "affected": [ + { + "package": { + "name": "chainguard.dev/apko", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.2.9" + } + ] + } + ], + "ecosystem_specific": {} + }, + { + "package": { + "name": "chainguard.dev/melange", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.50.4" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/chainguard-dev/melange/security/advisories/GHSA-fpg8-7664-jc5q" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-5968", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-5969.json b/data/osv/GO-2026-5969.json new file mode 100644 index 0000000..685d57a --- /dev/null +++ b/data/osv/GO-2026-5969.json
@@ -0,0 +1,43 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-5969", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "GHSA-g936-7jqj-mwv8" + ], + "summary": "TSDProxy: Internal proxy auth token forwarded to backend services enables management API escalation in github.com/almeidapaulopt/tsdproxy", + "details": "TSDProxy: Internal proxy auth token forwarded to backend services enables management API escalation in github.com/almeidapaulopt/tsdproxy", + "affected": [ + { + "package": { + "name": "github.com/almeidapaulopt/tsdproxy", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.4.4-0.20260603142855-434819b4421e" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/almeidapaulopt/tsdproxy/security/advisories/GHSA-g936-7jqj-mwv8" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-5969", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-5973.json b/data/osv/GO-2026-5973.json new file mode 100644 index 0000000..ea0f43c --- /dev/null +++ b/data/osv/GO-2026-5973.json
@@ -0,0 +1,71 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-5973", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-54250", + "GHSA-jxr7-mqhw-9p98" + ], + "summary": "K3s: ZIP Archive Path Traversal Vulnerability in etcd Snapshot Decompression in github.com/k3s-io/k3s", + "details": "K3s: ZIP Archive Path Traversal Vulnerability in etcd Snapshot Decompression in github.com/k3s-io/k3s.\n\nNOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.\n\n(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)\n\nThe additional affected modules and versions are: github.com/k3s-io/k3s before v1.33.10, from v1.34.0-rc1 before v1.34.6, from v1.35.0-rc1 before v1.35.3.", + "affected": [ + { + "package": { + "name": "github.com/k3s-io/k3s", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "custom_ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.33.10" + }, + { + "introduced": "1.34.0-rc1" + }, + { + "fixed": "1.34.6" + }, + { + "introduced": "1.35.0-rc1" + }, + { + "fixed": "1.35.3" + } + ] + } + ] + } + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/k3s-io/k3s/security/advisories/GHSA-jxr7-mqhw-9p98" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54250" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-5973", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-5974.json b/data/osv/GO-2026-5974.json new file mode 100644 index 0000000..9b8320f --- /dev/null +++ b/data/osv/GO-2026-5974.json
@@ -0,0 +1,44 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-5974", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-44300", + "GHSA-wmj8-9953-vff5" + ], + "summary": "OpenCost ServiceKey Endpoint Unauthorized Credential Overwrite/Injection in github.com/opencost/opencost", + "details": "OpenCost ServiceKey Endpoint Unauthorized Credential Overwrite/Injection in github.com/opencost/opencost", + "affected": [ + { + "package": { + "name": "github.com/opencost/opencost", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.119.1" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/opencost/opencost/security/advisories/GHSA-wmj8-9953-vff5" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-5974", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-5975.json b/data/osv/GO-2026-5975.json new file mode 100644 index 0000000..35a30a9 --- /dev/null +++ b/data/osv/GO-2026-5975.json
@@ -0,0 +1,52 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-5975", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-50018", + "GHSA-42j2-w334-qxw7" + ], + "summary": "Hoverfly: Denial of Service via Goroutine Leak in Remote Post-Serve Actions in github.com/SpectoLabs/hoverfly", + "details": "Hoverfly: Denial of Service via Goroutine Leak in Remote Post-Serve Actions in github.com/SpectoLabs/hoverfly", + "affected": [ + { + "package": { + "name": "github.com/SpectoLabs/hoverfly", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.12.8" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/SpectoLabs/hoverfly/security/advisories/GHSA-42j2-w334-qxw7" + }, + { + "type": "FIX", + "url": "https://github.com/SpectoLabs/hoverfly/pull/1228" + }, + { + "type": "WEB", + "url": "https://github.com/SpectoLabs/hoverfly/releases/tag/v1.12.8" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-5975", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-5976.json b/data/osv/GO-2026-5976.json new file mode 100644 index 0000000..e40c0a9 --- /dev/null +++ b/data/osv/GO-2026-5976.json
@@ -0,0 +1,94 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-5976", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-50141", + "GHSA-g7mm-9vx7-jm7h" + ], + "summary": "Woodpecker gRPC agent_id metadata can be spoofed- cross-tenant agent impersonation in go.woodpecker-ci.org/woodpecker", + "details": "Woodpecker gRPC agent_id metadata can be spoofed- cross-tenant agent impersonation in go.woodpecker-ci.org/woodpecker", + "affected": [ + { + "package": { + "name": "go.woodpecker-ci.org/woodpecker", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": {} + }, + { + "package": { + "name": "go.woodpecker-ci.org/woodpecker/v2", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": {} + }, + { + "package": { + "name": "go.woodpecker-ci.org/woodpecker/v3", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "3.0.0" + }, + { + "fixed": "3.14.1" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/woodpecker-ci/woodpecker/security/advisories/GHSA-g7mm-9vx7-jm7h" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-50141" + }, + { + "type": "WEB", + "url": "https://github.com/woodpecker-ci/woodpecker/issues/6541" + }, + { + "type": "WEB", + "url": "https://github.com/woodpecker-ci/woodpecker/pull/6567" + }, + { + "type": "WEB", + "url": "https://github.com/woodpecker-ci/woodpecker/pull/6569" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-5976", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-5977.json b/data/osv/GO-2026-5977.json new file mode 100644 index 0000000..86a1ba4 --- /dev/null +++ b/data/osv/GO-2026-5977.json
@@ -0,0 +1,52 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-5977", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-50013", + "GHSA-qrh4-p6v4-mrfg" + ], + "summary": "Hoverfly: Process Crash via Concurrent Map Write Race Condition in Diff Mode in github.com/SpectoLabs/hoverfly", + "details": "Hoverfly: Process Crash via Concurrent Map Write Race Condition in Diff Mode in github.com/SpectoLabs/hoverfly", + "affected": [ + { + "package": { + "name": "github.com/SpectoLabs/hoverfly", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.12.8" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/SpectoLabs/hoverfly/security/advisories/GHSA-qrh4-p6v4-mrfg" + }, + { + "type": "FIX", + "url": "https://github.com/SpectoLabs/hoverfly/pull/1227" + }, + { + "type": "WEB", + "url": "https://github.com/SpectoLabs/hoverfly/releases/tag/v1.12.8" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-5977", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-5978.json b/data/osv/GO-2026-5978.json new file mode 100644 index 0000000..66af877 --- /dev/null +++ b/data/osv/GO-2026-5978.json
@@ -0,0 +1,44 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-5978", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-50125", + "GHSA-qw5r-ppcg-f8rj" + ], + "summary": "MKP: Unbounded Pod Log Read via Attacker-Controlled `limitBytes`/`tailLines` Causes Memory Exhaustion in github.com/StacklokLabs/mkp", + "details": "MKP: Unbounded Pod Log Read via Attacker-Controlled `limitBytes`/`tailLines` Causes Memory Exhaustion in github.com/StacklokLabs/mkp", + "affected": [ + { + "package": { + "name": "github.com/StacklokLabs/mkp", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.4.1" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/StacklokLabs/mkp/security/advisories/GHSA-qw5r-ppcg-f8rj" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-5978", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-5979.json b/data/osv/GO-2026-5979.json new file mode 100644 index 0000000..591d1fd --- /dev/null +++ b/data/osv/GO-2026-5979.json
@@ -0,0 +1,45 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-5979", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-50006", + "GHSA-xrcf-6jh3-ggvx" + ], + "summary": "Anyquery: Arbitrary File Write (AFW) which could lead to Remote Code Execution (RCE) via Unrestricted ATTACH DATABASE in Server Mode in github.com/julien040/anyquery", + "details": "Anyquery: Arbitrary File Write (AFW) which could lead to Remote Code Execution (RCE) via Unrestricted ATTACH DATABASE in Server Mode in github.com/julien040/anyquery", + "affected": [ + { + "package": { + "name": "github.com/julien040/anyquery", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/julien040/anyquery/security/advisories/GHSA-xrcf-6jh3-ggvx" + }, + { + "type": "WEB", + "url": "https://github.com/julien040/anyquery/releases/tag/0.4.5" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-5979", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-5980.json b/data/osv/GO-2026-5980.json new file mode 100644 index 0000000..2116433 --- /dev/null +++ b/data/osv/GO-2026-5980.json
@@ -0,0 +1,52 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-5980", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-50158", + "GHSA-2c7f-fxww-6w6c" + ], + "summary": "yutu: Arbitrary File Write via MCP `caption-download` Tool in github.com/eat-pray-ai/yutu", + "details": "yutu: Arbitrary File Write via MCP `caption-download` Tool in github.com/eat-pray-ai/yutu", + "affected": [ + { + "package": { + "name": "github.com/eat-pray-ai/yutu", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.10.9-dev1" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/eat-pray-ai/yutu/security/advisories/GHSA-2c7f-fxww-6w6c" + }, + { + "type": "FIX", + "url": "https://github.com/eat-pray-ai/yutu/commit/87026c4eee1ed28775383807087343a750707bf3" + }, + { + "type": "WEB", + "url": "https://github.com/eat-pray-ai/yutu/releases/tag/v0.10.9-dev1" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-5980", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-5981.json b/data/osv/GO-2026-5981.json new file mode 100644 index 0000000..d225374 --- /dev/null +++ b/data/osv/GO-2026-5981.json
@@ -0,0 +1,40 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-5981", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "GHSA-mqxv-9rm6-w8qc" + ], + "summary": "Ech0: ParseAcceptLanguage `_` separator bypass enables ~70x CPU amplification via Accept-Language header in i18n.Middleware in github.com/lin-snow/ech0", + "details": "Ech0: ParseAcceptLanguage `_` separator bypass enables ~70x CPU amplification via Accept-Language header in i18n.Middleware in github.com/lin-snow/ech0", + "affected": [ + { + "package": { + "name": "github.com/lin-snow/ech0", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/lin-snow/Ech0/security/advisories/GHSA-mqxv-9rm6-w8qc" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-5981", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-5982.json b/data/osv/GO-2026-5982.json new file mode 100644 index 0000000..3c7056d --- /dev/null +++ b/data/osv/GO-2026-5982.json
@@ -0,0 +1,44 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-5982", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "GHSA-pqg7-v6wh-3pfp" + ], + "summary": "TsDProxy: X-Forwarded-For header injection allows IP spoofing in proxied requests to backend services in github.com/almeidapaulopt/tsdproxy", + "details": "TsDProxy: X-Forwarded-For header injection allows IP spoofing in proxied requests to backend services in github.com/almeidapaulopt/tsdproxy", + "affected": [ + { + "package": { + "name": "github.com/almeidapaulopt/tsdproxy", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/almeidapaulopt/tsdproxy/security/advisories/GHSA-pqg7-v6wh-3pfp" + }, + { + "type": "FIX", + "url": "https://github.com/almeidapaulopt/tsdproxy/commit/e8200b7947719e5e7fbbbdb9c34f459a4c285e77" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-5982", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-5984.json b/data/osv/GO-2026-5984.json new file mode 100644 index 0000000..736dda9 --- /dev/null +++ b/data/osv/GO-2026-5984.json
@@ -0,0 +1,52 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-5984", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-53604", + "GHSA-2p2f-px33-4vv5" + ], + "summary": "nebula-mesh: CA private key not zeroized on web mobile-bundle error paths in github.com/forgekeep/nebula-mesh", + "details": "nebula-mesh: CA private key not zeroized on web mobile-bundle error paths in github.com/forgekeep/nebula-mesh", + "affected": [ + { + "package": { + "name": "github.com/forgekeep/nebula-mesh", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.3.8" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/forgekeep/nebula-mesh/security/advisories/GHSA-2p2f-px33-4vv5" + }, + { + "type": "FIX", + "url": "https://github.com/forgekeep/nebula-mesh/commit/1f1ab9aa8472239763d967e3d50a3cd53a1a79b9" + }, + { + "type": "WEB", + "url": "https://github.com/forgekeep/nebula-mesh/releases/tag/v0.3.8" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-5984", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-5985.json b/data/osv/GO-2026-5985.json new file mode 100644 index 0000000..2b1f398 --- /dev/null +++ b/data/osv/GO-2026-5985.json
@@ -0,0 +1,51 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-5985", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "GHSA-7rx3-5wx3-5v76" + ], + "summary": "Nebula-mesh allows non-admin operators to disable webhook SSRF protection via `allow_private` in github.com/forgekeep/nebula-mesh", + "details": "Nebula-mesh allows non-admin operators to disable webhook SSRF protection via `allow_private` in github.com/forgekeep/nebula-mesh", + "affected": [ + { + "package": { + "name": "github.com/forgekeep/nebula-mesh", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0.6.0" + }, + { + "fixed": "0.7.2" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/forgekeep/nebula-mesh/security/advisories/GHSA-7rx3-5wx3-5v76" + }, + { + "type": "FIX", + "url": "https://github.com/forgekeep/nebula-mesh/commit/f3c54530e388dd21763e548923426e60a8e93ff0" + }, + { + "type": "WEB", + "url": "https://github.com/forgekeep/nebula-mesh/releases/tag/v0.7.2" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-5985", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-5986.json b/data/osv/GO-2026-5986.json new file mode 100644 index 0000000..06c3463 --- /dev/null +++ b/data/osv/GO-2026-5986.json
@@ -0,0 +1,52 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-5986", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-61699", + "GHSA-cm26-5974-52h8" + ], + "summary": "nebula-mesh: Certificate revocation is never enforced at the mesh in github.com/forgekeep/nebula-mesh", + "details": "nebula-mesh: Certificate revocation is never enforced at the mesh in github.com/forgekeep/nebula-mesh", + "affected": [ + { + "package": { + "name": "github.com/forgekeep/nebula-mesh", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.7.1" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/forgekeep/nebula-mesh/security/advisories/GHSA-cm26-5974-52h8" + }, + { + "type": "FIX", + "url": "https://github.com/forgekeep/nebula-mesh/commit/0426e2f224a9b1e2029029bf923c93ed39d21cdb" + }, + { + "type": "WEB", + "url": "https://github.com/forgekeep/nebula-mesh/releases/tag/v0.7.1" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-5986", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-5988.json b/data/osv/GO-2026-5988.json new file mode 100644 index 0000000..df4a341 --- /dev/null +++ b/data/osv/GO-2026-5988.json
@@ -0,0 +1,45 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-5988", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-54628", + "GHSA-hwrq-8wxh-q4xv" + ], + "summary": "Anyquery: Server-Side Request Forgery (SSRF) via Unrestricted SQLite Virtual Table Modules in Server Mode in github.com/julien040/anyquery", + "details": "Anyquery: Server-Side Request Forgery (SSRF) via Unrestricted SQLite Virtual Table Modules in Server Mode in github.com/julien040/anyquery", + "affected": [ + { + "package": { + "name": "github.com/julien040/anyquery", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/julien040/anyquery/security/advisories/GHSA-hwrq-8wxh-q4xv" + }, + { + "type": "WEB", + "url": "https://github.com/julien040/anyquery/releases/tag/0.4.5" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-5988", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-5990.json b/data/osv/GO-2026-5990.json new file mode 100644 index 0000000..01710a5 --- /dev/null +++ b/data/osv/GO-2026-5990.json
@@ -0,0 +1,45 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-5990", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-54629", + "GHSA-mf78-3rpf-r784" + ], + "summary": "Anyquery: Local File Read (LFR) via Unrestricted SQLite Virtual Table Modules in Server Mode in github.com/julien040/anyquery", + "details": "Anyquery: Local File Read (LFR) via Unrestricted SQLite Virtual Table Modules in Server Mode in github.com/julien040/anyquery", + "affected": [ + { + "package": { + "name": "github.com/julien040/anyquery", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/julien040/anyquery/security/advisories/GHSA-mf78-3rpf-r784" + }, + { + "type": "WEB", + "url": "https://github.com/julien040/anyquery/releases/tag/0.4.5" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-5990", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-5991.json b/data/osv/GO-2026-5991.json new file mode 100644 index 0000000..b7c3982 --- /dev/null +++ b/data/osv/GO-2026-5991.json
@@ -0,0 +1,52 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-5991", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-53603", + "GHSA-q4vm-pq3q-8wgq" + ], + "summary": "nebula-mesh: Operator session tokens stored in plaintext in the database in github.com/forgekeep/nebula-mesh", + "details": "nebula-mesh: Operator session tokens stored in plaintext in the database in github.com/forgekeep/nebula-mesh", + "affected": [ + { + "package": { + "name": "github.com/forgekeep/nebula-mesh", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.3.8" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/forgekeep/nebula-mesh/security/advisories/GHSA-q4vm-pq3q-8wgq" + }, + { + "type": "FIX", + "url": "https://github.com/forgekeep/nebula-mesh/commit/7cb01bab281ded557f8b6c81dab5f48d4c10182e" + }, + { + "type": "WEB", + "url": "https://github.com/forgekeep/nebula-mesh/releases/tag/v0.3.8" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-5991", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-5992.json b/data/osv/GO-2026-5992.json new file mode 100644 index 0000000..771914e --- /dev/null +++ b/data/osv/GO-2026-5992.json
@@ -0,0 +1,99 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-5992", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-61549", + "GHSA-qf34-295c-26v8" + ], + "summary": "Woodpecker: Privilege escalation via unrestricted serviceAccountName in the Kubernetes backend in github.com/woodpecker-ci/woodpecker", + "details": "Woodpecker: Privilege escalation via unrestricted serviceAccountName in the Kubernetes backend in github.com/woodpecker-ci/woodpecker", + "affected": [ + { + "package": { + "name": "github.com/woodpecker-ci/woodpecker", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "1.0.0" + } + ] + } + ], + "ecosystem_specific": {} + }, + { + "package": { + "name": "go.woodpecker-ci.org/woodpecker", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": {} + }, + { + "package": { + "name": "go.woodpecker-ci.org/woodpecker/v2", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": {} + }, + { + "package": { + "name": "go.woodpecker-ci.org/woodpecker/v3", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "3.16.0" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/woodpecker-ci/woodpecker/security/advisories/GHSA-qf34-295c-26v8" + }, + { + "type": "FIX", + "url": "https://github.com/woodpecker-ci/woodpecker/pull/6792" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-5992", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-5996.json b/data/osv/GO-2026-5996.json new file mode 100644 index 0000000..2bb1625 --- /dev/null +++ b/data/osv/GO-2026-5996.json
@@ -0,0 +1,44 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-5996", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-54450", + "GHSA-pph6-vfjv-vpjw" + ], + "summary": "ToolHive: SSRF guard misses IPv6 NAT64 ranges (64:ff9b::/96, 64:ff9b:1::/48), allowing metadata/internal access behind a NAT64 gateway in github.com/stacklok/toolhive", + "details": "ToolHive: SSRF guard misses IPv6 NAT64 ranges (64:ff9b::/96, 64:ff9b:1::/48), allowing metadata/internal access behind a NAT64 gateway in github.com/stacklok/toolhive", + "affected": [ + { + "package": { + "name": "github.com/stacklok/toolhive", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.29.1" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/stacklok/toolhive/security/advisories/GHSA-pph6-vfjv-vpjw" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-5996", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-5997.json b/data/osv/GO-2026-5997.json new file mode 100644 index 0000000..b71abc0 --- /dev/null +++ b/data/osv/GO-2026-5997.json
@@ -0,0 +1,48 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-5997", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-54452", + "GHSA-xgch-x3mx-cm3c" + ], + "summary": "safeurl is Missing IPv6 CIDR Ranges in Blocklist in github.com/doyensec/safeurl", + "details": "safeurl is Missing IPv6 CIDR Ranges in Blocklist in github.com/doyensec/safeurl", + "affected": [ + { + "package": { + "name": "github.com/doyensec/safeurl", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.2.4" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/doyensec/safeurl/security/advisories/GHSA-xgch-x3mx-cm3c" + }, + { + "type": "WEB", + "url": "https://github.com/doyensec/safeurl/releases/tag/v0.2.4" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-5997", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-5998.json b/data/osv/GO-2026-5998.json new file mode 100644 index 0000000..4bca967 --- /dev/null +++ b/data/osv/GO-2026-5998.json
@@ -0,0 +1,45 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-5998", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-54495", + "GHSA-398h-7f66-3h4p" + ], + "summary": "open-feature-operator: Cross-namespace FeatureFlagSource and InProcessConfiguration resolution exposes spec contents on multi-tenant clusters in github.com/open-feature/open-feature-operator", + "details": "open-feature-operator: Cross-namespace FeatureFlagSource and InProcessConfiguration resolution exposes spec contents on multi-tenant clusters in github.com/open-feature/open-feature-operator", + "affected": [ + { + "package": { + "name": "github.com/open-feature/open-feature-operator", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/open-feature/open-feature-operator/security/advisories/GHSA-398h-7f66-3h4p" + }, + { + "type": "REPORT", + "url": "https://github.com/open-feature/open-feature-operator/issues/847" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-5998", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-5999.json b/data/osv/GO-2026-5999.json new file mode 100644 index 0000000..9883208 --- /dev/null +++ b/data/osv/GO-2026-5999.json
@@ -0,0 +1,76 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-5999", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-10814", + "GHSA-jh6h-v6mp-h22v" + ], + "summary": "milvus: RBAC grantee-id uses truncated MD5 (64-bit), enabling privilege-binding collisions and cross-role privilege forgery in github.com/milvus-io/milvus", + "details": "milvus: RBAC grantee-id uses truncated MD5 (64-bit), enabling privilege-binding collisions and cross-role privilege forgery in github.com/milvus-io/milvus", + "affected": [ + { + "package": { + "name": "github.com/milvus-io/milvus", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.10.3-0.20260602041816-3d932f1c3e06" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-jh6h-v6mp-h22v" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-10814" + }, + { + "type": "FIX", + "url": "https://github.com/milvus-io/milvus/commit/3d932f1c3e065351c4440c27abe1e6479752544d" + }, + { + "type": "FIX", + "url": "https://github.com/milvus-io/milvus/pull/50060" + }, + { + "type": "REPORT", + "url": "https://github.com/milvus-io/milvus/issues/49857" + }, + { + "type": "WEB", + "url": "https://vuldb.com/cve/CVE-2026-10814" + }, + { + "type": "WEB", + "url": "https://vuldb.com/submit/831645" + }, + { + "type": "WEB", + "url": "https://vuldb.com/vuln/368262" + }, + { + "type": "WEB", + "url": "https://vuldb.com/vuln/368262/cti" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-5999", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6002.json b/data/osv/GO-2026-6002.json new file mode 100644 index 0000000..2c4c41c --- /dev/null +++ b/data/osv/GO-2026-6002.json
@@ -0,0 +1,44 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6002", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-58196", + "GHSA-pr64-jmmf-jp54" + ], + "summary": "ToolHive: SSRF in remote MCP server authentication discovery (host-side, bypasses container isolation) in github.com/stacklok/toolhive", + "details": "ToolHive: SSRF in remote MCP server authentication discovery (host-side, bypasses container isolation) in github.com/stacklok/toolhive", + "affected": [ + { + "package": { + "name": "github.com/stacklok/toolhive", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.31.0" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/stacklok/toolhive/security/advisories/GHSA-pr64-jmmf-jp54" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6002", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6003.json b/data/osv/GO-2026-6003.json new file mode 100644 index 0000000..b710694 --- /dev/null +++ b/data/osv/GO-2026-6003.json
@@ -0,0 +1,50 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6003", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-53714", + "GHSA-22xc-xg2r-9j7v" + ], + "summary": "Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode in github.com/envoyproxy/gateway", + "details": "Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode in github.com/envoyproxy/gateway", + "affected": [ + { + "package": { + "name": "github.com/envoyproxy/gateway", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.7.4" + }, + { + "introduced": "1.8.0-rc.0" + }, + { + "fixed": "1.8.1" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/envoyproxy/gateway/security/advisories/GHSA-22xc-xg2r-9j7v" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6003", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6004.json b/data/osv/GO-2026-6004.json new file mode 100644 index 0000000..0937916 --- /dev/null +++ b/data/osv/GO-2026-6004.json
@@ -0,0 +1,67 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6004", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-52833", + "GHSA-3v79-m2cg-89ww" + ], + "summary": "Nuclio: Unsanitized runtimeAttributes.repositories injected into Groovy build.gradle leads to build-time RCE in github.com/nuclio/nuclio", + "details": "Nuclio: Unsanitized runtimeAttributes.repositories injected into Groovy build.gradle leads to build-time RCE in github.com/nuclio/nuclio.\n\nNOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.\n\n(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)\n\nThe additional affected modules and versions are: github.com/nuclio/nuclio before v1.16.5.", + "affected": [ + { + "package": { + "name": "github.com/nuclio/nuclio", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "custom_ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.16.5" + } + ] + } + ] + } + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/nuclio/nuclio/security/advisories/GHSA-3v79-m2cg-89ww" + }, + { + "type": "FIX", + "url": "https://github.com/nuclio/nuclio/commit/4c78040c759068e927f3ed7c6507543c15d4ae56" + }, + { + "type": "FIX", + "url": "https://github.com/nuclio/nuclio/pull/4149" + }, + { + "type": "WEB", + "url": "https://github.com/nuclio/nuclio/releases/tag/1.16.5" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6004", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6005.json b/data/osv/GO-2026-6005.json new file mode 100644 index 0000000..c684f00 --- /dev/null +++ b/data/osv/GO-2026-6005.json
@@ -0,0 +1,50 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6005", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-53715", + "GHSA-8fv2-88gg-hm7q" + ], + "summary": "Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock in github.com/envoyproxy/gateway", + "details": "Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock in github.com/envoyproxy/gateway", + "affected": [ + { + "package": { + "name": "github.com/envoyproxy/gateway", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.7.4" + }, + { + "introduced": "1.8.0-rc.0" + }, + { + "fixed": "1.8.1" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/envoyproxy/gateway/security/advisories/GHSA-8fv2-88gg-hm7q" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6005", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6006.json b/data/osv/GO-2026-6006.json new file mode 100644 index 0000000..496d684 --- /dev/null +++ b/data/osv/GO-2026-6006.json
@@ -0,0 +1,50 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6006", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-53716", + "GHSA-cxpq-8v7q-cg56" + ], + "summary": "Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit in github.com/envoyproxy/gateway", + "details": "Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit in github.com/envoyproxy/gateway", + "affected": [ + { + "package": { + "name": "github.com/envoyproxy/gateway", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.7.4" + }, + { + "introduced": "1.8.0-rc.0" + }, + { + "fixed": "1.8.1" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/envoyproxy/gateway/security/advisories/GHSA-cxpq-8v7q-cg56" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6006", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6007.json b/data/osv/GO-2026-6007.json new file mode 100644 index 0000000..e4dfbe1 --- /dev/null +++ b/data/osv/GO-2026-6007.json
@@ -0,0 +1,50 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6007", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-53718", + "GHSA-fcrp-7gc2-93g7" + ], + "summary": "Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass in github.com/envoyproxy/gateway", + "details": "Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass in github.com/envoyproxy/gateway", + "affected": [ + { + "package": { + "name": "github.com/envoyproxy/gateway", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.7.4" + }, + { + "introduced": "1.8.0-rc.0" + }, + { + "fixed": "1.8.1" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/envoyproxy/gateway/security/advisories/GHSA-fcrp-7gc2-93g7" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6007", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6008.json b/data/osv/GO-2026-6008.json new file mode 100644 index 0000000..ad264b8 --- /dev/null +++ b/data/osv/GO-2026-6008.json
@@ -0,0 +1,50 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6008", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-53717", + "GHSA-h7pq-86h8-rp5x" + ], + "summary": "Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header in github.com/envoyproxy/gateway", + "details": "Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header in github.com/envoyproxy/gateway", + "affected": [ + { + "package": { + "name": "github.com/envoyproxy/gateway", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.7.4" + }, + { + "introduced": "1.8.0-rc.0" + }, + { + "fixed": "1.8.1" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/envoyproxy/gateway/security/advisories/GHSA-h7pq-86h8-rp5x" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6008", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6009.json b/data/osv/GO-2026-6009.json new file mode 100644 index 0000000..98df17b --- /dev/null +++ b/data/osv/GO-2026-6009.json
@@ -0,0 +1,50 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6009", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-53719", + "GHSA-m2v6-2jmh-4c68" + ], + "summary": "Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization in github.com/envoyproxy/gateway", + "details": "Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization in github.com/envoyproxy/gateway", + "affected": [ + { + "package": { + "name": "github.com/envoyproxy/gateway", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.7.4" + }, + { + "introduced": "1.8.0-rc.0" + }, + { + "fixed": "1.8.1" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/envoyproxy/gateway/security/advisories/GHSA-m2v6-2jmh-4c68" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6009", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6011.json b/data/osv/GO-2026-6011.json new file mode 100644 index 0000000..e02df7e --- /dev/null +++ b/data/osv/GO-2026-6011.json
@@ -0,0 +1,50 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6011", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-53713", + "GHSA-wcrf-9vrr-854f" + ], + "summary": "Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure in github.com/envoyproxy/gateway", + "details": "Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure in github.com/envoyproxy/gateway", + "affected": [ + { + "package": { + "name": "github.com/envoyproxy/gateway", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.7.4" + }, + { + "introduced": "1.8.0-rc.0" + }, + { + "fixed": "1.8.1" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/envoyproxy/gateway/security/advisories/GHSA-wcrf-9vrr-854f" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6011", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6012.json b/data/osv/GO-2026-6012.json new file mode 100644 index 0000000..7ffb37c --- /dev/null +++ b/data/osv/GO-2026-6012.json
@@ -0,0 +1,67 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6012", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-52832", + "GHSA-wpcj-rmv4-86qg" + ], + "summary": "Nuclio: Unauthenticated path traversal in spec.handler allows arbitrary file write in Dashboard container in github.com/nuclio/nuclio", + "details": "Nuclio: Unauthenticated path traversal in spec.handler allows arbitrary file write in Dashboard container in github.com/nuclio/nuclio.\n\nNOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.\n\n(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)\n\nThe additional affected modules and versions are: github.com/nuclio/nuclio before v1.16.5.", + "affected": [ + { + "package": { + "name": "github.com/nuclio/nuclio", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "custom_ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.16.5" + } + ] + } + ] + } + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/nuclio/nuclio/security/advisories/GHSA-wpcj-rmv4-86qg" + }, + { + "type": "FIX", + "url": "https://github.com/nuclio/nuclio/commit/2a55d3a8bd4d49226cb4742020303f5bf2a0931d" + }, + { + "type": "FIX", + "url": "https://github.com/nuclio/nuclio/pull/4143" + }, + { + "type": "WEB", + "url": "https://github.com/nuclio/nuclio/releases/tag/1.16.5" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6012", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6014.json b/data/osv/GO-2026-6014.json new file mode 100644 index 0000000..be54729 --- /dev/null +++ b/data/osv/GO-2026-6014.json
@@ -0,0 +1,76 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6014", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2025-7453", + "GHSA-2hfh-94w5-wxvf" + ], + "summary": "ZPan Uses Hard-Coded Password in github.com/saltbo/zpan", + "details": "ZPan Uses Hard-Coded Password in github.com/saltbo/zpan", + "affected": [ + { + "package": { + "name": "github.com/saltbo/zpan", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.6.6" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-2hfh-94w5-wxvf" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-7453" + }, + { + "type": "FIX", + "url": "https://github.com/saltbo/zpan/commit/8662db8d4b06057631faf3deba4132e66705e947" + }, + { + "type": "FIX", + "url": "https://github.com/saltbo/zpan/pull/410" + }, + { + "type": "REPORT", + "url": "https://github.com/saltbo/zpan/issues/219" + }, + { + "type": "WEB", + "url": "https://github.com/saltbo/zpan/releases/tag/v1.6.6" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.316097" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.316097" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.608447" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6014", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/reports/GO-2026-5929.yaml b/data/reports/GO-2026-5929.yaml new file mode 100644 index 0000000..2b31b2b --- /dev/null +++ b/data/reports/GO-2026-5929.yaml
@@ -0,0 +1,18 @@ +id: GO-2026-5929 +modules: + - module: github.com/QuantumNous/new-api + versions: + - fixed: 0.12.0-alpha.1 + vulnerable_at: 0.11.9 +summary: New API is vulnerable to CSRF through user email binding in github.com/QuantumNous/new-api +cves: + - CVE-2026-44342 +ghsas: + - GHSA-26v7-h57m-gh9m +references: + - advisory: https://github.com/QuantumNous/new-api/security/advisories/GHSA-26v7-h57m-gh9m + - fix: https://github.com/QuantumNous/new-api/commit/e099117c61391abdf888fb75e382a582e550bd0e +source: + id: GHSA-26v7-h57m-gh9m + created: 2026-07-17T13:20:03.81816488-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-5930.yaml b/data/reports/GO-2026-5930.yaml new file mode 100644 index 0000000..0299000 --- /dev/null +++ b/data/reports/GO-2026-5930.yaml
@@ -0,0 +1,18 @@ +id: GO-2026-5930 +modules: + - module: github.com/QuantumNous/new-api + versions: + - fixed: 0.12.0-alpha.1 + vulnerable_at: 0.11.9 +summary: 'New API: SSRF Protection Bypass via Unresolved Hostname in Notification URLs in github.com/QuantumNous/new-api' +cves: + - CVE-2026-33655 +ghsas: + - GHSA-6qcr-qxgr-m7fv +references: + - advisory: https://github.com/QuantumNous/new-api/security/advisories/GHSA-6qcr-qxgr-m7fv + - fix: https://github.com/QuantumNous/new-api/commit/20399d3c8fcb4e3649d53163eb11940fd6763743 +source: + id: GHSA-6qcr-qxgr-m7fv + created: 2026-07-17T13:19:58.005020144-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-5933.yaml b/data/reports/GO-2026-5933.yaml new file mode 100644 index 0000000..81bd184 --- /dev/null +++ b/data/reports/GO-2026-5933.yaml
@@ -0,0 +1,15 @@ +id: GO-2026-5933 +modules: + - module: github.com/tinfoil-factory/netfoil + versions: + - fixed: 0.3.0 + vulnerable_at: 0.2.1 +summary: netfoil has a resource leak in LRU cache in github.com/tinfoil-factory/netfoil +ghsas: + - GHSA-3g4q-2f67-2gvh +references: + - advisory: https://github.com/tinfoil-factory/netfoil/security/advisories/GHSA-3g4q-2f67-2gvh +source: + id: GHSA-3g4q-2f67-2gvh + created: 2026-07-17T13:19:55.218369739-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-5934.yaml b/data/reports/GO-2026-5934.yaml new file mode 100644 index 0000000..eff5647 --- /dev/null +++ b/data/reports/GO-2026-5934.yaml
@@ -0,0 +1,15 @@ +id: GO-2026-5934 +modules: + - module: github.com/tinfoil-factory/netfoil + versions: + - fixed: 0.3.0 + vulnerable_at: 0.2.1 +summary: netfoil has a domain name filter bypass via multiple questions in github.com/tinfoil-factory/netfoil +ghsas: + - GHSA-59qp-cfj3-rp64 +references: + - advisory: https://github.com/tinfoil-factory/netfoil/security/advisories/GHSA-59qp-cfj3-rp64 +source: + id: GHSA-59qp-cfj3-rp64 + created: 2026-07-17T13:19:54.278594333-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-5935.yaml b/data/reports/GO-2026-5935.yaml new file mode 100644 index 0000000..6035004 --- /dev/null +++ b/data/reports/GO-2026-5935.yaml
@@ -0,0 +1,15 @@ +id: GO-2026-5935 +modules: + - module: github.com/tinfoil-factory/netfoil + versions: + - fixed: 0.3.0 + vulnerable_at: 0.2.1 +summary: 'netfoil: Attacker controlled data written to logs in github.com/tinfoil-factory/netfoil' +ghsas: + - GHSA-7856-g3gv-9wq8 +references: + - advisory: https://github.com/tinfoil-factory/netfoil/security/advisories/GHSA-7856-g3gv-9wq8 +source: + id: GHSA-7856-g3gv-9wq8 + created: 2026-07-17T13:19:53.289445864-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-5936.yaml b/data/reports/GO-2026-5936.yaml new file mode 100644 index 0000000..ae2f9c4 --- /dev/null +++ b/data/reports/GO-2026-5936.yaml
@@ -0,0 +1,19 @@ +id: GO-2026-5936 +modules: + - module: github.com/zhenorzz/goploy + unsupported_versions: + - last_affected: 1.17.5 + vulnerable_at: 1.17.5 +summary: |- + Goploy: Cross-namespace IDOR and RCE via body-supplied row id in project and + project_file handlers in github.com/zhenorzz/goploy +cves: + - CVE-2026-53552 +ghsas: + - GHSA-26rh-24rg-j3vv +references: + - advisory: https://github.com/zhenorzz/goploy/security/advisories/GHSA-26rh-24rg-j3vv +source: + id: GHSA-26rh-24rg-j3vv + created: 2026-07-17T13:19:49.871027759-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-5937.yaml b/data/reports/GO-2026-5937.yaml new file mode 100644 index 0000000..6296092 --- /dev/null +++ b/data/reports/GO-2026-5937.yaml
@@ -0,0 +1,23 @@ +id: GO-2026-5937 +modules: + - module: github.com/oasdiff/oasdiff + versions: + - introduced: 1.13.2 + - fixed: 1.18.1 + vulnerable_at: 1.18.0 +summary: |- + oasdiff does not enforce --allow-external-refs=false on the git-revision load + path (SSRF / local file read) in github.com/oasdiff/oasdiff +cves: + - CVE-2026-53508 +ghsas: + - GHSA-2jcc-mxv7-p3f9 +references: + - advisory: https://github.com/oasdiff/oasdiff/security/advisories/GHSA-2jcc-mxv7-p3f9 + - fix: https://github.com/oasdiff/oasdiff/pull/832 + - fix: https://github.com/oasdiff/oasdiff/pull/974 + - fix: https://github.com/oasdiff/oasdiff/pull/975 +source: + id: GHSA-2jcc-mxv7-p3f9 + created: 2026-07-17T13:19:43.274448277-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-5938.yaml b/data/reports/GO-2026-5938.yaml new file mode 100644 index 0000000..f48dc33 --- /dev/null +++ b/data/reports/GO-2026-5938.yaml
@@ -0,0 +1,19 @@ +id: GO-2026-5938 +modules: + - module: github.com/zhenorzz/goploy + unsupported_versions: + - last_affected: 1.17.5 + vulnerable_at: 1.17.5 +summary: |- + Goploy: Arbitrary File Read via Path Traversal in /deploy/fileDiff allows Remote + Server Compromise in github.com/zhenorzz/goploy +cves: + - CVE-2026-53553 +ghsas: + - GHSA-4g5x-hcwm-82jw +references: + - advisory: https://github.com/zhenorzz/goploy/security/advisories/GHSA-4g5x-hcwm-82jw +source: + id: GHSA-4g5x-hcwm-82jw + created: 2026-07-17T13:19:38.285073747-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-5939.yaml b/data/reports/GO-2026-5939.yaml new file mode 100644 index 0000000..195b4fc --- /dev/null +++ b/data/reports/GO-2026-5939.yaml
@@ -0,0 +1,22 @@ +id: GO-2026-5939 +modules: + - module: github.com/quay/claircore + unsupported_versions: + - last_affected: 1.5.52 + vulnerable_at: 1.5.52 +summary: |- + Claircore: Unauthenticated attackers can submit manifests with URIs pointing to + internal services or cloud metadata endpoints in github.com/quay/claircore +cves: + - CVE-2026-10517 +ghsas: + - GHSA-698x-9w2p-7vvp +references: + - advisory: https://github.com/advisories/GHSA-698x-9w2p-7vvp + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-10517 + - web: https://access.redhat.com/security/cve/CVE-2026-10517 + - web: https://bugzilla.redhat.com/show_bug.cgi?id=2486779 +source: + id: GHSA-698x-9w2p-7vvp + created: 2026-07-17T13:19:30.26227296-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-5940.yaml b/data/reports/GO-2026-5940.yaml new file mode 100644 index 0000000..68f4d54 --- /dev/null +++ b/data/reports/GO-2026-5940.yaml
@@ -0,0 +1,21 @@ +id: GO-2026-5940 +modules: + - module: github.com/kedacore/keda + vulnerable_at: 1.5.0 + - module: github.com/kedacore/keda/v2 + versions: + - fixed: 2.20.0 + vulnerable_at: 2.19.0 +summary: |- + KEDA has PostgreSQL connection string parameter injection via incomplete + whitespace escaping in github.com/kedacore/keda +cves: + - CVE-2026-53572 +ghsas: + - GHSA-6w3m-4hhp-775q +references: + - advisory: https://github.com/kedacore/keda/security/advisories/GHSA-6w3m-4hhp-775q +source: + id: GHSA-6w3m-4hhp-775q + created: 2026-07-17T13:19:25.223878839-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-5941.yaml b/data/reports/GO-2026-5941.yaml new file mode 100644 index 0000000..9ee45a5 --- /dev/null +++ b/data/reports/GO-2026-5941.yaml
@@ -0,0 +1,17 @@ +id: GO-2026-5941 +modules: + - module: github.com/zxh326/kite + versions: + - fixed: 0.12.3 + vulnerable_at: 0.12.2 +summary: Kite has an authenticated cluster RBAC bypass in /api/v1/overview in github.com/zxh326/kite +cves: + - CVE-2026-53487 +ghsas: + - GHSA-gvhc-wv3v-7pf8 +references: + - advisory: https://github.com/kite-org/kite/security/advisories/GHSA-gvhc-wv3v-7pf8 +source: + id: GHSA-gvhc-wv3v-7pf8 + created: 2026-07-17T13:19:20.062176876-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-5944.yaml b/data/reports/GO-2026-5944.yaml new file mode 100644 index 0000000..0b5e1cb --- /dev/null +++ b/data/reports/GO-2026-5944.yaml
@@ -0,0 +1,19 @@ +id: GO-2026-5944 +modules: + - module: github.com/zalando/skipper + versions: + - fixed: 0.26.10 + vulnerable_at: 0.26.9 +summary: |- + Skipper: opaAuthorizeRequestWithBody filter bypasses OPA policy on + Transfer-Encoding — chunked / HTTP/2 requests in github.com/zalando/skipper +cves: + - CVE-2026-50197 +ghsas: + - GHSA-659f-rgp5-w4wf +references: + - advisory: https://github.com/zalando/skipper/security/advisories/GHSA-659f-rgp5-w4wf +source: + id: GHSA-659f-rgp5-w4wf + created: 2026-07-17T13:19:14.146583731-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-5945.yaml b/data/reports/GO-2026-5945.yaml new file mode 100644 index 0000000..55186d9 --- /dev/null +++ b/data/reports/GO-2026-5945.yaml
@@ -0,0 +1,22 @@ +id: GO-2026-5945 +modules: + - module: github.com/casdoor/casdoor + unsupported_versions: + - last_affected: 1.1000.0 + vulnerable_at: 1.1000.0 +summary: |- + Casdoor: Arbitrary file write possible through Local File System storage + provider in github.com/casdoor/casdoor +cves: + - CVE-2026-6815 +ghsas: + - GHSA-rmxx-v9rj-vpvg +references: + - advisory: https://github.com/advisories/GHSA-rmxx-v9rj-vpvg + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-6815 + - web: https://kb.cert.org/vuls/id/937808 + - web: https://www.kb.cert.org/vuls/id/937808 +source: + id: GHSA-rmxx-v9rj-vpvg + created: 2026-07-17T13:19:08.321606685-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-5946.yaml b/data/reports/GO-2026-5946.yaml new file mode 100644 index 0000000..0d5c1c9 --- /dev/null +++ b/data/reports/GO-2026-5946.yaml
@@ -0,0 +1,22 @@ +id: GO-2026-5946 +modules: + - module: github.com/nuclio/nuclio + versions: + - fixed: 0.0.0-20260601075854-3356b86a8bfa +summary: |- + Nuclio: Unsanitized cron trigger event headers/body injected into CronJob shell + command leads to persistent RCE in github.com/nuclio/nuclio +cves: + - CVE-2026-52831 +ghsas: + - GHSA-v5px-423j-pf7p +references: + - advisory: https://github.com/nuclio/nuclio/security/advisories/GHSA-v5px-423j-pf7p + - fix: https://github.com/nuclio/nuclio/commit/3356b86a8bfab3f960aa420310ebff765df9dede + - web: https://github.com/nuclio/nuclio/releases/tag/1.16.4 +notes: + - fix: 'github.com/nuclio/nuclio: could not add vulnerable_at: cannot auto-guess when fixed version is 0.0.0 pseudo-version' +source: + id: GHSA-v5px-423j-pf7p + created: 2026-07-17T13:19:02.028093346-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-5947.yaml b/data/reports/GO-2026-5947.yaml new file mode 100644 index 0000000..5e0f9bd --- /dev/null +++ b/data/reports/GO-2026-5947.yaml
@@ -0,0 +1,18 @@ +id: GO-2026-5947 +modules: + - module: github.com/BishopFox/joro + versions: + - fixed: 0.0.0-20260601151442-5c0ca35db828 +summary: 'Joro: Unauthenticated Cross-Origin Plugin Upload Leads to RCE in github.com/BishopFox/joro' +cves: + - CVE-2026-53649 +ghsas: + - GHSA-xqhv-chqm-fhcc +references: + - advisory: https://github.com/BishopFox/joro/security/advisories/GHSA-xqhv-chqm-fhcc +notes: + - fix: 'github.com/BishopFox/joro: could not add vulnerable_at: cannot auto-guess when fixed version is 0.0.0 pseudo-version' +source: + id: GHSA-xqhv-chqm-fhcc + created: 2026-07-17T13:18:57.173405632-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-5948.yaml b/data/reports/GO-2026-5948.yaml new file mode 100644 index 0000000..c2440c1 --- /dev/null +++ b/data/reports/GO-2026-5948.yaml
@@ -0,0 +1,21 @@ +id: GO-2026-5948 +modules: + - module: github.com/enchant97/note-mark/backend + versions: + - fixed: 0.0.0-20260601210758-9c9b72740f22 +summary: |- + Note Mark: Unauthenticated disclosure of soft-deleted note metadata via + deleted=true on public books in github.com/enchant97/note-mark/backend +cves: + - CVE-2026-50554 +ghsas: + - GHSA-588f-fvcv-xhvf +references: + - advisory: https://github.com/enchant97/note-mark/security/advisories/GHSA-588f-fvcv-xhvf + - web: https://github.com/enchant97/note-mark/commit/9c9b72740f22a06131a8f64b53bb08e3b05b81a6 +notes: + - fix: 'github.com/enchant97/note-mark/backend: could not add vulnerable_at: cannot auto-guess when fixed version is 0.0.0 pseudo-version' +source: + id: GHSA-588f-fvcv-xhvf + created: 2026-07-17T13:18:50.882177844-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-5949.yaml b/data/reports/GO-2026-5949.yaml new file mode 100644 index 0000000..344253b --- /dev/null +++ b/data/reports/GO-2026-5949.yaml
@@ -0,0 +1,21 @@ +id: GO-2026-5949 +modules: + - module: github.com/enchant97/note-mark/backend + versions: + - fixed: 0.0.0-20260601210719-67b7de04308a +summary: |- + Note Mark: Path traversal via unsanitized book/note slug in migrate export + (sibling of GHSA-g49p) in github.com/enchant97/note-mark/backend +cves: + - CVE-2026-50553 +ghsas: + - GHSA-rqrh-8wpv-x7hh +references: + - advisory: https://github.com/enchant97/note-mark/security/advisories/GHSA-rqrh-8wpv-x7hh + - web: https://github.com/enchant97/note-mark/commit/67b7de04308a858ef27ceff87b514067b6d667e5 +notes: + - fix: 'github.com/enchant97/note-mark/backend: could not add vulnerable_at: cannot auto-guess when fixed version is 0.0.0 pseudo-version' +source: + id: GHSA-rqrh-8wpv-x7hh + created: 2026-07-17T13:18:45.219492778-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-5950.yaml b/data/reports/GO-2026-5950.yaml new file mode 100644 index 0000000..3da1fc3 --- /dev/null +++ b/data/reports/GO-2026-5950.yaml
@@ -0,0 +1,20 @@ +id: GO-2026-5950 +modules: + - module: github.com/forgekeep/nebula-mesh + versions: + - fixed: 0.3.7 + vulnerable_at: 0.3.6 +summary: |- + nebula-mesh: Host revocation is not durable - blocked/offboarded hosts can + regain a valid certificate in github.com/forgekeep/nebula-mesh +cves: + - CVE-2026-53602 +ghsas: + - GHSA-339v-266x-79xr +references: + - advisory: https://github.com/forgekeep/nebula-mesh/security/advisories/GHSA-339v-266x-79xr + - report: https://github.com/forgekeep/nebula-mesh/issues/178 +source: + id: GHSA-339v-266x-79xr + created: 2026-07-17T13:18:39.819753025-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-5951.yaml b/data/reports/GO-2026-5951.yaml new file mode 100644 index 0000000..3e00286 --- /dev/null +++ b/data/reports/GO-2026-5951.yaml
@@ -0,0 +1,24 @@ +id: GO-2026-5951 +modules: + - module: github.com/nextlevelbuilder/goclaw + unsupported_versions: + - last_affected: 3.11.3 + vulnerable_at: 1.76.1 +summary: GoClaw has a Command Injection issue in github.com/nextlevelbuilder/goclaw +cves: + - CVE-2026-10219 +ghsas: + - GHSA-6jm8-4fhr-5w64 +references: + - advisory: https://github.com/advisories/GHSA-6jm8-4fhr-5w64 + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-10219 + - fix: https://github.com/nextlevelbuilder/goclaw/pull/1155 + - report: https://github.com/nextlevelbuilder/goclaw/issues/1121 + - web: https://vuldb.com/cve/CVE-2026-10219 + - web: https://vuldb.com/submit/821939 + - web: https://vuldb.com/vuln/367498 + - web: https://vuldb.com/vuln/367498/cti +source: + id: GHSA-6jm8-4fhr-5w64 + created: 2026-07-17T13:18:28.004519347-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-5952.yaml b/data/reports/GO-2026-5952.yaml new file mode 100644 index 0000000..b943b64 --- /dev/null +++ b/data/reports/GO-2026-5952.yaml
@@ -0,0 +1,17 @@ +id: GO-2026-5952 +modules: + - module: github.com/sigstore/sigstore-go + versions: + - fixed: 1.2.0 + vulnerable_at: 1.1.4 +summary: sigstore-go has a multi-log threshold bypass via single compromised log in github.com/sigstore/sigstore-go +cves: + - CVE-2026-49834 +ghsas: + - GHSA-9vcr-p3rj-q5q6 +references: + - advisory: https://github.com/sigstore/sigstore-go/security/advisories/GHSA-9vcr-p3rj-q5q6 +source: + id: GHSA-9vcr-p3rj-q5q6 + created: 2026-07-17T13:18:08.700921586-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-5953.yaml b/data/reports/GO-2026-5953.yaml new file mode 100644 index 0000000..8155fd3 --- /dev/null +++ b/data/reports/GO-2026-5953.yaml
@@ -0,0 +1,22 @@ +id: GO-2026-5953 +modules: + - module: github.com/casdoor/casdoor + non_go_versions: + - fixed: 2.387.0 + vulnerable_at: 1.1000.0 +summary: |- + Casdoor: GetTokenExchangeToken bypass through lack of cross-organization JWT + signature check in github.com/casdoor/casdoor +cves: + - CVE-2026-9094 +ghsas: + - GHSA-c9w5-qp6m-m395 +references: + - advisory: https://github.com/advisories/GHSA-c9w5-qp6m-m395 + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-9094 + - fix: https://github.com/casdoor/casdoor/commit/d92b8568686d + - web: https://kb.cert.org/vuls/id/780781 +source: + id: GHSA-c9w5-qp6m-m395 + created: 2026-07-17T13:17:57.601298905-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-5956.yaml b/data/reports/GO-2026-5956.yaml new file mode 100644 index 0000000..5ad0b47 --- /dev/null +++ b/data/reports/GO-2026-5956.yaml
@@ -0,0 +1,21 @@ +id: GO-2026-5956 +modules: + - module: github.com/openrundev/openrun + versions: + - fixed: 0.17.7 + vulnerable_at: 0.17.6 +summary: |- + OpenRun: Redirect URL validation bypass using //host paths leads to Open + Redirect in github.com/openrundev/openrun +cves: + - CVE-2026-55252 +ghsas: + - GHSA-h5g6-xmh4-hc37 +references: + - advisory: https://github.com/openrundev/openrun/security/advisories/GHSA-h5g6-xmh4-hc37 + - fix: https://github.com/openrundev/openrun/commit/709da784fcf1311c85f30f3542cfa3601a78bbf0 + - web: https://github.com/openrundev/openrun/releases/tag/v0.17.7 +source: + id: GHSA-h5g6-xmh4-hc37 + created: 2026-07-17T13:17:42.354227551-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-5957.yaml b/data/reports/GO-2026-5957.yaml new file mode 100644 index 0000000..5d814e1 --- /dev/null +++ b/data/reports/GO-2026-5957.yaml
@@ -0,0 +1,19 @@ +id: GO-2026-5957 +modules: + - module: github.com/siyuan-note/siyuan/kernel + versions: + - fixed: 0.0.0-20260628153353-2d5d72223df4 +summary: 'SiYuan: Stored XSS to RCE via attribute-view cell rendering in genAVValueHTML() in github.com/siyuan-note/siyuan/kernel' +cves: + - CVE-2026-54158 +ghsas: + - GHSA-5xfx-xj4h-5p7r +references: + - advisory: https://github.com/siyuan-note/siyuan/security/advisories/GHSA-5xfx-xj4h-5p7r + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-54158 +notes: + - fix: 'github.com/siyuan-note/siyuan/kernel: could not add vulnerable_at: cannot auto-guess when fixed version is 0.0.0 pseudo-version' +source: + id: GHSA-5xfx-xj4h-5p7r + created: 2026-07-17T13:17:36.502434723-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-5958.yaml b/data/reports/GO-2026-5958.yaml new file mode 100644 index 0000000..a76ea1a --- /dev/null +++ b/data/reports/GO-2026-5958.yaml
@@ -0,0 +1,21 @@ +id: GO-2026-5958 +modules: + - module: github.com/siyuan-note/siyuan/kernel + versions: + - fixed: 0.0.0-20260628153353-2d5d72223df4 +summary: |- + SiYuan: Unauthenticated SQLite Data Exfiltration via Template Injection in + /api/icon/getDynamicIcon in github.com/siyuan-note/siyuan/kernel +cves: + - CVE-2026-54068 +ghsas: + - GHSA-gcm7-57gf-953c +references: + - advisory: https://github.com/siyuan-note/siyuan/security/advisories/GHSA-gcm7-57gf-953c + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-54068 +notes: + - fix: 'github.com/siyuan-note/siyuan/kernel: could not add vulnerable_at: cannot auto-guess when fixed version is 0.0.0 pseudo-version' +source: + id: GHSA-gcm7-57gf-953c + created: 2026-07-17T13:17:31.805897218-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-5959.yaml b/data/reports/GO-2026-5959.yaml new file mode 100644 index 0000000..bade9d2 --- /dev/null +++ b/data/reports/GO-2026-5959.yaml
@@ -0,0 +1,20 @@ +id: GO-2026-5959 +modules: + - module: github.com/authorizerdev/authorizer + versions: + - fixed: 0.0.0-20260409051328-bd3f5baf6d3d +summary: |- + Authorizer: Unvalidated redirect_uri in /authorize leaks OAuth2 tokens to + attacker-controlled URL in github.com/authorizerdev/authorizer +cves: + - CVE-2026-54072 +ghsas: + - GHSA-h29v-hj44-q8cv +references: + - advisory: https://github.com/authorizerdev/authorizer/security/advisories/GHSA-h29v-hj44-q8cv +notes: + - fix: 'github.com/authorizerdev/authorizer: could not add vulnerable_at: cannot auto-guess when fixed version is 0.0.0 pseudo-version' +source: + id: GHSA-h29v-hj44-q8cv + created: 2026-07-17T13:17:26.988929471-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-5961.yaml b/data/reports/GO-2026-5961.yaml new file mode 100644 index 0000000..82ab6c6 --- /dev/null +++ b/data/reports/GO-2026-5961.yaml
@@ -0,0 +1,21 @@ +id: GO-2026-5961 +modules: + - module: github.com/siyuan-note/siyuan/kernel + versions: + - fixed: 0.0.0-20260628153353-2d5d72223df4 +summary: |- + SiYuan: Unauthenticated Admin API Access via Blanket chrome-extension:// Origin + Allowlist in github.com/siyuan-note/siyuan/kernel +cves: + - CVE-2026-54069 +ghsas: + - GHSA-hvr9-72v2-fff3 +references: + - advisory: https://github.com/siyuan-note/siyuan/security/advisories/GHSA-hvr9-72v2-fff3 + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-54069 +notes: + - fix: 'github.com/siyuan-note/siyuan/kernel: could not add vulnerable_at: cannot auto-guess when fixed version is 0.0.0 pseudo-version' +source: + id: GHSA-hvr9-72v2-fff3 + created: 2026-07-17T13:17:16.088927976-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-5962.yaml b/data/reports/GO-2026-5962.yaml new file mode 100644 index 0000000..48dc7ff --- /dev/null +++ b/data/reports/GO-2026-5962.yaml
@@ -0,0 +1,22 @@ +id: GO-2026-5962 +modules: + - module: github.com/filebrowser/filebrowser + vulnerable_at: 1.11.0 + - module: github.com/filebrowser/filebrowser/v2 + versions: + - fixed: 2.63.6 + vulnerable_at: 2.63.5 +summary: |- + File Browser: Command Injection via Authentication Hook Shell Substitution + (Pre-Authentication RCE) in github.com/filebrowser/filebrowser +cves: + - CVE-2026-54088 +ghsas: + - GHSA-m93h-4hw7-5qcm +references: + - advisory: https://github.com/filebrowser/filebrowser/security/advisories/GHSA-m93h-4hw7-5qcm + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-54088 +source: + id: GHSA-m93h-4hw7-5qcm + created: 2026-07-17T13:17:11.190450163-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-5963.yaml b/data/reports/GO-2026-5963.yaml new file mode 100644 index 0000000..1aac277 --- /dev/null +++ b/data/reports/GO-2026-5963.yaml
@@ -0,0 +1,19 @@ +id: GO-2026-5963 +modules: + - module: github.com/siyuan-note/siyuan/kernel + versions: + - fixed: 0.0.0-20260628153353-2d5d72223df4 +summary: 'SiYuan: Stored XSS to RCE via CSS-snippet <style> breakout in renderSnippet() in github.com/siyuan-note/siyuan/kernel' +cves: + - CVE-2026-54067 +ghsas: + - GHSA-mvjr-vv3c-w4qv +references: + - advisory: https://github.com/siyuan-note/siyuan/security/advisories/GHSA-mvjr-vv3c-w4qv + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-54067 +notes: + - fix: 'github.com/siyuan-note/siyuan/kernel: could not add vulnerable_at: cannot auto-guess when fixed version is 0.0.0 pseudo-version' +source: + id: GHSA-mvjr-vv3c-w4qv + created: 2026-07-17T13:17:06.125966306-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-5964.yaml b/data/reports/GO-2026-5964.yaml new file mode 100644 index 0000000..d347224 --- /dev/null +++ b/data/reports/GO-2026-5964.yaml
@@ -0,0 +1,21 @@ +id: GO-2026-5964 +modules: + - module: github.com/siyuan-note/siyuan/kernel + versions: + - fixed: 0.0.0-20260628153353-2d5d72223df4 +summary: |- + SiYuan: Path Traversal via Double URL Encoding in /assets/*path (publish mode + arbitrary file─read), Incomplete fix of CVE-2026-41894 in github.com/siyuan-note/siyuan/kernel +cves: + - CVE-2026-54066 +ghsas: + - GHSA-p4m3-mgmm-c664 +references: + - advisory: https://github.com/siyuan-note/siyuan/security/advisories/GHSA-p4m3-mgmm-c664 + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-54066 +notes: + - fix: 'github.com/siyuan-note/siyuan/kernel: could not add vulnerable_at: cannot auto-guess when fixed version is 0.0.0 pseudo-version' +source: + id: GHSA-p4m3-mgmm-c664 + created: 2026-07-17T13:17:01.423761786-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-5965.yaml b/data/reports/GO-2026-5965.yaml new file mode 100644 index 0000000..aa980ef --- /dev/null +++ b/data/reports/GO-2026-5965.yaml
@@ -0,0 +1,19 @@ +id: GO-2026-5965 +modules: + - module: github.com/siyuan-note/siyuan/kernel + versions: + - fixed: 0.0.0-20260628153353-2d5d72223df4 +summary: 'SiYuan: Stored XSS in Bazaar marketplace via package README event handlers in github.com/siyuan-note/siyuan/kernel' +cves: + - CVE-2026-54070 +ghsas: + - GHSA-w7cg-whh7-xp28 +references: + - advisory: https://github.com/siyuan-note/siyuan/security/advisories/GHSA-w7cg-whh7-xp28 + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-54070 +notes: + - fix: 'github.com/siyuan-note/siyuan/kernel: could not add vulnerable_at: cannot auto-guess when fixed version is 0.0.0 pseudo-version' +source: + id: GHSA-w7cg-whh7-xp28 + created: 2026-07-17T13:16:56.853723037-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-5966.yaml b/data/reports/GO-2026-5966.yaml new file mode 100644 index 0000000..ae72642 --- /dev/null +++ b/data/reports/GO-2026-5966.yaml
@@ -0,0 +1,22 @@ +id: GO-2026-5966 +modules: + - module: github.com/filebrowser/filebrowser + vulnerable_at: 1.11.0 + - module: github.com/filebrowser/filebrowser/v2 + versions: + - introduced: 2.0.0-rc.1 + unsupported_versions: + - last_affected: 2.63.18 + vulnerable_at: 2.63.18 +summary: 'File Browser: Authentication Bypass via Proxy Auth Header Forgery in github.com/filebrowser/filebrowser' +cves: + - CVE-2026-54089 +ghsas: + - GHSA-xqp3-jq6g-x3qm +references: + - advisory: https://github.com/filebrowser/filebrowser/security/advisories/GHSA-xqp3-jq6g-x3qm + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-54089 +source: + id: GHSA-xqp3-jq6g-x3qm + created: 2026-07-17T13:16:51.312554402-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-5967.yaml b/data/reports/GO-2026-5967.yaml new file mode 100644 index 0000000..5aa2873 --- /dev/null +++ b/data/reports/GO-2026-5967.yaml
@@ -0,0 +1,19 @@ +id: GO-2026-5967 +modules: + - module: github.com/siyuan-note/siyuan/kernel + versions: + - fixed: 0.0.0-20260628153353-2d5d72223df4 +summary: 'SiYuan: Stored XSS to RCE via Unsanitized Attribute View Asset Cell Content in github.com/siyuan-note/siyuan/kernel' +cves: + - CVE-2026-50551 +ghsas: + - GHSA-56mp-4f3v-fgj2 +references: + - advisory: https://github.com/siyuan-note/siyuan/security/advisories/GHSA-56mp-4f3v-fgj2 + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-50551 +notes: + - fix: 'github.com/siyuan-note/siyuan/kernel: could not add vulnerable_at: cannot auto-guess when fixed version is 0.0.0 pseudo-version' +source: + id: GHSA-56mp-4f3v-fgj2 + created: 2026-07-17T13:16:46.233853889-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-5968.yaml b/data/reports/GO-2026-5968.yaml new file mode 100644 index 0000000..7a902cb --- /dev/null +++ b/data/reports/GO-2026-5968.yaml
@@ -0,0 +1,23 @@ +id: GO-2026-5968 +modules: + - module: chainguard.dev/apko + versions: + - fixed: 1.2.9 + vulnerable_at: 1.2.8 + - module: chainguard.dev/melange + versions: + - fixed: 0.50.4 + vulnerable_at: 0.50.3 +summary: |- + melange: Incomplete package integrity verification allows data section + substitution in chainguard.dev/apko +cves: + - CVE-2026-54174 +ghsas: + - GHSA-fpg8-7664-jc5q +references: + - advisory: https://github.com/chainguard-dev/melange/security/advisories/GHSA-fpg8-7664-jc5q +source: + id: GHSA-fpg8-7664-jc5q + created: 2026-07-17T13:16:41.524961494-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-5969.yaml b/data/reports/GO-2026-5969.yaml new file mode 100644 index 0000000..f4bfbe1 --- /dev/null +++ b/data/reports/GO-2026-5969.yaml
@@ -0,0 +1,17 @@ +id: GO-2026-5969 +modules: + - module: github.com/almeidapaulopt/tsdproxy + versions: + - fixed: 1.4.4-0.20260603142855-434819b4421e + vulnerable_at: 1.4.3 +summary: |- + TSDProxy: Internal proxy auth token forwarded to backend services enables + management API escalation in github.com/almeidapaulopt/tsdproxy +ghsas: + - GHSA-g936-7jqj-mwv8 +references: + - advisory: https://github.com/almeidapaulopt/tsdproxy/security/advisories/GHSA-g936-7jqj-mwv8 +source: + id: GHSA-g936-7jqj-mwv8 + created: 2026-07-17T13:16:39.187749739-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-5973.yaml b/data/reports/GO-2026-5973.yaml new file mode 100644 index 0000000..39902bd --- /dev/null +++ b/data/reports/GO-2026-5973.yaml
@@ -0,0 +1,22 @@ +id: GO-2026-5973 +modules: + - module: github.com/k3s-io/k3s + non_go_versions: + - fixed: 1.33.10 + - introduced: 1.34.0-rc1 + - fixed: 1.34.6 + - introduced: 1.35.0-rc1 + - fixed: 1.35.3 + vulnerable_at: 1.0.1 +summary: 'K3s: ZIP Archive Path Traversal Vulnerability in etcd Snapshot Decompression in github.com/k3s-io/k3s' +cves: + - CVE-2026-54250 +ghsas: + - GHSA-jxr7-mqhw-9p98 +references: + - advisory: https://github.com/k3s-io/k3s/security/advisories/GHSA-jxr7-mqhw-9p98 + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-54250 +source: + id: GHSA-jxr7-mqhw-9p98 + created: 2026-07-17T13:16:08.825294119-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-5974.yaml b/data/reports/GO-2026-5974.yaml new file mode 100644 index 0000000..9b27d69 --- /dev/null +++ b/data/reports/GO-2026-5974.yaml
@@ -0,0 +1,17 @@ +id: GO-2026-5974 +modules: + - module: github.com/opencost/opencost + versions: + - fixed: 1.119.1 + vulnerable_at: 1.119.0 +summary: OpenCost ServiceKey Endpoint Unauthorized Credential Overwrite/Injection in github.com/opencost/opencost +cves: + - CVE-2026-44300 +ghsas: + - GHSA-wmj8-9953-vff5 +references: + - advisory: https://github.com/opencost/opencost/security/advisories/GHSA-wmj8-9953-vff5 +source: + id: GHSA-wmj8-9953-vff5 + created: 2026-07-17T13:16:03.917454189-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-5975.yaml b/data/reports/GO-2026-5975.yaml new file mode 100644 index 0000000..de459f2 --- /dev/null +++ b/data/reports/GO-2026-5975.yaml
@@ -0,0 +1,19 @@ +id: GO-2026-5975 +modules: + - module: github.com/SpectoLabs/hoverfly + versions: + - fixed: 1.12.8 + vulnerable_at: 1.12.7 +summary: 'Hoverfly: Denial of Service via Goroutine Leak in Remote Post-Serve Actions in github.com/SpectoLabs/hoverfly' +cves: + - CVE-2026-50018 +ghsas: + - GHSA-42j2-w334-qxw7 +references: + - advisory: https://github.com/SpectoLabs/hoverfly/security/advisories/GHSA-42j2-w334-qxw7 + - fix: https://github.com/SpectoLabs/hoverfly/pull/1228 + - web: https://github.com/SpectoLabs/hoverfly/releases/tag/v1.12.8 +source: + id: GHSA-42j2-w334-qxw7 + created: 2026-07-17T13:15:58.690978288-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-5976.yaml b/data/reports/GO-2026-5976.yaml new file mode 100644 index 0000000..be86303 --- /dev/null +++ b/data/reports/GO-2026-5976.yaml
@@ -0,0 +1,28 @@ +id: GO-2026-5976 +modules: + - module: go.woodpecker-ci.org/woodpecker + vulnerable_at: 1.0.5 + - module: go.woodpecker-ci.org/woodpecker/v2 + vulnerable_at: 2.8.3 + - module: go.woodpecker-ci.org/woodpecker/v3 + versions: + - introduced: 3.0.0 + - fixed: 3.14.1 + vulnerable_at: 3.14.0 +summary: |- + Woodpecker gRPC agent_id metadata can be spoofed- cross-tenant agent + impersonation in go.woodpecker-ci.org/woodpecker +cves: + - CVE-2026-50141 +ghsas: + - GHSA-g7mm-9vx7-jm7h +references: + - advisory: https://github.com/woodpecker-ci/woodpecker/security/advisories/GHSA-g7mm-9vx7-jm7h + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-50141 + - web: https://github.com/woodpecker-ci/woodpecker/issues/6541 + - web: https://github.com/woodpecker-ci/woodpecker/pull/6567 + - web: https://github.com/woodpecker-ci/woodpecker/pull/6569 +source: + id: GHSA-g7mm-9vx7-jm7h + created: 2026-07-17T13:15:51.618203702-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-5977.yaml b/data/reports/GO-2026-5977.yaml new file mode 100644 index 0000000..f99c84c --- /dev/null +++ b/data/reports/GO-2026-5977.yaml
@@ -0,0 +1,19 @@ +id: GO-2026-5977 +modules: + - module: github.com/SpectoLabs/hoverfly + versions: + - fixed: 1.12.8 + vulnerable_at: 1.12.7 +summary: 'Hoverfly: Process Crash via Concurrent Map Write Race Condition in Diff Mode in github.com/SpectoLabs/hoverfly' +cves: + - CVE-2026-50013 +ghsas: + - GHSA-qrh4-p6v4-mrfg +references: + - advisory: https://github.com/SpectoLabs/hoverfly/security/advisories/GHSA-qrh4-p6v4-mrfg + - fix: https://github.com/SpectoLabs/hoverfly/pull/1227 + - web: https://github.com/SpectoLabs/hoverfly/releases/tag/v1.12.8 +source: + id: GHSA-qrh4-p6v4-mrfg + created: 2026-07-17T13:15:46.114723335-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-5978.yaml b/data/reports/GO-2026-5978.yaml new file mode 100644 index 0000000..61d5ad6 --- /dev/null +++ b/data/reports/GO-2026-5978.yaml
@@ -0,0 +1,19 @@ +id: GO-2026-5978 +modules: + - module: github.com/StacklokLabs/mkp + versions: + - fixed: 0.4.1 + vulnerable_at: 0.4.0 +summary: |- + MKP: Unbounded Pod Log Read via Attacker-Controlled `limitBytes`/`tailLines` + Causes Memory Exhaustion in github.com/StacklokLabs/mkp +cves: + - CVE-2026-50125 +ghsas: + - GHSA-qw5r-ppcg-f8rj +references: + - advisory: https://github.com/StacklokLabs/mkp/security/advisories/GHSA-qw5r-ppcg-f8rj +source: + id: GHSA-qw5r-ppcg-f8rj + created: 2026-07-17T13:15:41.561561877-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-5979.yaml b/data/reports/GO-2026-5979.yaml new file mode 100644 index 0000000..822a8a9 --- /dev/null +++ b/data/reports/GO-2026-5979.yaml
@@ -0,0 +1,18 @@ +id: GO-2026-5979 +modules: + - module: github.com/julien040/anyquery + vulnerable_at: 0.1.6 +summary: |- + Anyquery: Arbitrary File Write (AFW) which could lead to Remote Code Execution + (RCE) via Unrestricted ATTACH DATABASE in Server Mode in github.com/julien040/anyquery +cves: + - CVE-2026-50006 +ghsas: + - GHSA-xrcf-6jh3-ggvx +references: + - advisory: https://github.com/julien040/anyquery/security/advisories/GHSA-xrcf-6jh3-ggvx + - web: https://github.com/julien040/anyquery/releases/tag/0.4.5 +source: + id: GHSA-xrcf-6jh3-ggvx + created: 2026-07-17T13:15:36.616011219-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-5980.yaml b/data/reports/GO-2026-5980.yaml new file mode 100644 index 0000000..75494fb --- /dev/null +++ b/data/reports/GO-2026-5980.yaml
@@ -0,0 +1,19 @@ +id: GO-2026-5980 +modules: + - module: github.com/eat-pray-ai/yutu + versions: + - fixed: 0.10.9-dev1 + vulnerable_at: 0.10.8 +summary: 'yutu: Arbitrary File Write via MCP `caption-download` Tool in github.com/eat-pray-ai/yutu' +cves: + - CVE-2026-50158 +ghsas: + - GHSA-2c7f-fxww-6w6c +references: + - advisory: https://github.com/eat-pray-ai/yutu/security/advisories/GHSA-2c7f-fxww-6w6c + - fix: https://github.com/eat-pray-ai/yutu/commit/87026c4eee1ed28775383807087343a750707bf3 + - web: https://github.com/eat-pray-ai/yutu/releases/tag/v0.10.9-dev1 +source: + id: GHSA-2c7f-fxww-6w6c + created: 2026-07-17T13:15:30.861260392-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-5981.yaml b/data/reports/GO-2026-5981.yaml new file mode 100644 index 0000000..951437d --- /dev/null +++ b/data/reports/GO-2026-5981.yaml
@@ -0,0 +1,15 @@ +id: GO-2026-5981 +modules: + - module: github.com/lin-snow/ech0 + vulnerable_at: 1.4.7 +summary: |- + Ech0: ParseAcceptLanguage `_` separator bypass enables ~70x CPU amplification + via Accept-Language header in i18n.Middleware in github.com/lin-snow/ech0 +ghsas: + - GHSA-mqxv-9rm6-w8qc +references: + - advisory: https://github.com/lin-snow/Ech0/security/advisories/GHSA-mqxv-9rm6-w8qc +source: + id: GHSA-mqxv-9rm6-w8qc + created: 2026-07-17T13:15:28.723814873-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-5982.yaml b/data/reports/GO-2026-5982.yaml new file mode 100644 index 0000000..b6e30fc --- /dev/null +++ b/data/reports/GO-2026-5982.yaml
@@ -0,0 +1,16 @@ +id: GO-2026-5982 +modules: + - module: github.com/almeidapaulopt/tsdproxy + vulnerable_at: 1.4.7 +summary: |- + TsDProxy: X-Forwarded-For header injection allows IP spoofing in proxied + requests to backend services in github.com/almeidapaulopt/tsdproxy +ghsas: + - GHSA-pqg7-v6wh-3pfp +references: + - advisory: https://github.com/almeidapaulopt/tsdproxy/security/advisories/GHSA-pqg7-v6wh-3pfp + - fix: https://github.com/almeidapaulopt/tsdproxy/commit/e8200b7947719e5e7fbbbdb9c34f459a4c285e77 +source: + id: GHSA-pqg7-v6wh-3pfp + created: 2026-07-17T13:15:27.053143674-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-5984.yaml b/data/reports/GO-2026-5984.yaml new file mode 100644 index 0000000..f161e7b --- /dev/null +++ b/data/reports/GO-2026-5984.yaml
@@ -0,0 +1,19 @@ +id: GO-2026-5984 +modules: + - module: github.com/forgekeep/nebula-mesh + versions: + - fixed: 0.3.8 + vulnerable_at: 0.3.7 +summary: 'nebula-mesh: CA private key not zeroized on web mobile-bundle error paths in github.com/forgekeep/nebula-mesh' +cves: + - CVE-2026-53604 +ghsas: + - GHSA-2p2f-px33-4vv5 +references: + - advisory: https://github.com/forgekeep/nebula-mesh/security/advisories/GHSA-2p2f-px33-4vv5 + - fix: https://github.com/forgekeep/nebula-mesh/commit/1f1ab9aa8472239763d967e3d50a3cd53a1a79b9 + - web: https://github.com/forgekeep/nebula-mesh/releases/tag/v0.3.8 +source: + id: GHSA-2p2f-px33-4vv5 + created: 2026-07-17T13:14:41.433244565-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-5985.yaml b/data/reports/GO-2026-5985.yaml new file mode 100644 index 0000000..ca6a451 --- /dev/null +++ b/data/reports/GO-2026-5985.yaml
@@ -0,0 +1,20 @@ +id: GO-2026-5985 +modules: + - module: github.com/forgekeep/nebula-mesh + versions: + - introduced: 0.6.0 + - fixed: 0.7.2 + vulnerable_at: 0.7.1 +summary: |- + Nebula-mesh allows non-admin operators to disable webhook SSRF protection via + `allow_private` in github.com/forgekeep/nebula-mesh +ghsas: + - GHSA-7rx3-5wx3-5v76 +references: + - advisory: https://github.com/forgekeep/nebula-mesh/security/advisories/GHSA-7rx3-5wx3-5v76 + - fix: https://github.com/forgekeep/nebula-mesh/commit/f3c54530e388dd21763e548923426e60a8e93ff0 + - web: https://github.com/forgekeep/nebula-mesh/releases/tag/v0.7.2 +source: + id: GHSA-7rx3-5wx3-5v76 + created: 2026-07-17T13:14:38.435173061-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-5986.yaml b/data/reports/GO-2026-5986.yaml new file mode 100644 index 0000000..838308b --- /dev/null +++ b/data/reports/GO-2026-5986.yaml
@@ -0,0 +1,19 @@ +id: GO-2026-5986 +modules: + - module: github.com/forgekeep/nebula-mesh + versions: + - fixed: 0.7.1 + vulnerable_at: 0.7.0 +summary: 'nebula-mesh: Certificate revocation is never enforced at the mesh in github.com/forgekeep/nebula-mesh' +cves: + - CVE-2026-61699 +ghsas: + - GHSA-cm26-5974-52h8 +references: + - advisory: https://github.com/forgekeep/nebula-mesh/security/advisories/GHSA-cm26-5974-52h8 + - fix: https://github.com/forgekeep/nebula-mesh/commit/0426e2f224a9b1e2029029bf923c93ed39d21cdb + - web: https://github.com/forgekeep/nebula-mesh/releases/tag/v0.7.1 +source: + id: GHSA-cm26-5974-52h8 + created: 2026-07-17T13:14:33.659440248-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-5988.yaml b/data/reports/GO-2026-5988.yaml new file mode 100644 index 0000000..12a0490 --- /dev/null +++ b/data/reports/GO-2026-5988.yaml
@@ -0,0 +1,18 @@ +id: GO-2026-5988 +modules: + - module: github.com/julien040/anyquery + vulnerable_at: 0.1.6 +summary: |- + Anyquery: Server-Side Request Forgery (SSRF) via Unrestricted SQLite Virtual + Table Modules in Server Mode in github.com/julien040/anyquery +cves: + - CVE-2026-54628 +ghsas: + - GHSA-hwrq-8wxh-q4xv +references: + - advisory: https://github.com/julien040/anyquery/security/advisories/GHSA-hwrq-8wxh-q4xv + - web: https://github.com/julien040/anyquery/releases/tag/0.4.5 +source: + id: GHSA-hwrq-8wxh-q4xv + created: 2026-07-17T13:14:23.478386682-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-5990.yaml b/data/reports/GO-2026-5990.yaml new file mode 100644 index 0000000..0b40d3f --- /dev/null +++ b/data/reports/GO-2026-5990.yaml
@@ -0,0 +1,18 @@ +id: GO-2026-5990 +modules: + - module: github.com/julien040/anyquery + vulnerable_at: 0.1.6 +summary: |- + Anyquery: Local File Read (LFR) via Unrestricted SQLite Virtual Table Modules in + Server Mode in github.com/julien040/anyquery +cves: + - CVE-2026-54629 +ghsas: + - GHSA-mf78-3rpf-r784 +references: + - advisory: https://github.com/julien040/anyquery/security/advisories/GHSA-mf78-3rpf-r784 + - web: https://github.com/julien040/anyquery/releases/tag/0.4.5 +source: + id: GHSA-mf78-3rpf-r784 + created: 2026-07-17T13:14:12.420326578-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-5991.yaml b/data/reports/GO-2026-5991.yaml new file mode 100644 index 0000000..877cdff --- /dev/null +++ b/data/reports/GO-2026-5991.yaml
@@ -0,0 +1,19 @@ +id: GO-2026-5991 +modules: + - module: github.com/forgekeep/nebula-mesh + versions: + - fixed: 0.3.8 + vulnerable_at: 0.3.7 +summary: 'nebula-mesh: Operator session tokens stored in plaintext in the database in github.com/forgekeep/nebula-mesh' +cves: + - CVE-2026-53603 +ghsas: + - GHSA-q4vm-pq3q-8wgq +references: + - advisory: https://github.com/forgekeep/nebula-mesh/security/advisories/GHSA-q4vm-pq3q-8wgq + - fix: https://github.com/forgekeep/nebula-mesh/commit/7cb01bab281ded557f8b6c81dab5f48d4c10182e + - web: https://github.com/forgekeep/nebula-mesh/releases/tag/v0.3.8 +source: + id: GHSA-q4vm-pq3q-8wgq + created: 2026-07-17T13:14:06.538356163-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-5992.yaml b/data/reports/GO-2026-5992.yaml new file mode 100644 index 0000000..fdeb8f0 --- /dev/null +++ b/data/reports/GO-2026-5992.yaml
@@ -0,0 +1,32 @@ +id: GO-2026-5992 +modules: + - module: github.com/woodpecker-ci/woodpecker + versions: + - introduced: 1.0.0 + unsupported_versions: + - last_affected: 1.0.4 + vulnerable_at: 1.0.5 + - module: go.woodpecker-ci.org/woodpecker + vulnerable_at: 1.0.5 + - module: go.woodpecker-ci.org/woodpecker/v2 + unsupported_versions: + - last_affected: 2.8.3 + vulnerable_at: 2.8.3 + - module: go.woodpecker-ci.org/woodpecker/v3 + versions: + - fixed: 3.16.0 + vulnerable_at: 3.15.0 +summary: |- + Woodpecker: Privilege escalation via unrestricted serviceAccountName in the + Kubernetes backend in github.com/woodpecker-ci/woodpecker +cves: + - CVE-2026-61549 +ghsas: + - GHSA-qf34-295c-26v8 +references: + - advisory: https://github.com/woodpecker-ci/woodpecker/security/advisories/GHSA-qf34-295c-26v8 + - fix: https://github.com/woodpecker-ci/woodpecker/pull/6792 +source: + id: GHSA-qf34-295c-26v8 + created: 2026-07-17T13:14:00.917758217-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-5996.yaml b/data/reports/GO-2026-5996.yaml new file mode 100644 index 0000000..c28343e --- /dev/null +++ b/data/reports/GO-2026-5996.yaml
@@ -0,0 +1,19 @@ +id: GO-2026-5996 +modules: + - module: github.com/stacklok/toolhive + versions: + - fixed: 0.29.1 + vulnerable_at: 0.29.0 +summary: |- + ToolHive: SSRF guard misses IPv6 NAT64 ranges (64:ff9b::/96, 64:ff9b:1::/48), + allowing metadata/internal access behind a NAT64 gateway in github.com/stacklok/toolhive +cves: + - CVE-2026-54450 +ghsas: + - GHSA-pph6-vfjv-vpjw +references: + - advisory: https://github.com/stacklok/toolhive/security/advisories/GHSA-pph6-vfjv-vpjw +source: + id: GHSA-pph6-vfjv-vpjw + created: 2026-07-17T13:13:56.016755013-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-5997.yaml b/data/reports/GO-2026-5997.yaml new file mode 100644 index 0000000..41ab289 --- /dev/null +++ b/data/reports/GO-2026-5997.yaml
@@ -0,0 +1,18 @@ +id: GO-2026-5997 +modules: + - module: github.com/doyensec/safeurl + versions: + - fixed: 0.2.4 + vulnerable_at: 0.2.3 +summary: safeurl is Missing IPv6 CIDR Ranges in Blocklist in github.com/doyensec/safeurl +cves: + - CVE-2026-54452 +ghsas: + - GHSA-xgch-x3mx-cm3c +references: + - advisory: https://github.com/doyensec/safeurl/security/advisories/GHSA-xgch-x3mx-cm3c + - web: https://github.com/doyensec/safeurl/releases/tag/v0.2.4 +source: + id: GHSA-xgch-x3mx-cm3c + created: 2026-07-17T13:13:50.874663558-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-5998.yaml b/data/reports/GO-2026-5998.yaml new file mode 100644 index 0000000..5d33eeb --- /dev/null +++ b/data/reports/GO-2026-5998.yaml
@@ -0,0 +1,20 @@ +id: GO-2026-5998 +modules: + - module: github.com/open-feature/open-feature-operator + unsupported_versions: + - last_affected: 0.9.2 + vulnerable_at: 0.9.2 +summary: |- + open-feature-operator: Cross-namespace FeatureFlagSource and + InProcessConfiguration resolution exposes spec contents on multi-tenant clusters in github.com/open-feature/open-feature-operator +cves: + - CVE-2026-54495 +ghsas: + - GHSA-398h-7f66-3h4p +references: + - advisory: https://github.com/open-feature/open-feature-operator/security/advisories/GHSA-398h-7f66-3h4p + - report: https://github.com/open-feature/open-feature-operator/issues/847 +source: + id: GHSA-398h-7f66-3h4p + created: 2026-07-17T13:13:45.606780633-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-5999.yaml b/data/reports/GO-2026-5999.yaml new file mode 100644 index 0000000..f325890 --- /dev/null +++ b/data/reports/GO-2026-5999.yaml
@@ -0,0 +1,27 @@ +id: GO-2026-5999 +modules: + - module: github.com/milvus-io/milvus + versions: + - fixed: 0.10.3-0.20260602041816-3d932f1c3e06 + vulnerable_at: 0.10.2 +summary: |- + milvus: RBAC grantee-id uses truncated MD5 (64-bit), enabling privilege-binding + collisions and cross-role privilege forgery in github.com/milvus-io/milvus +cves: + - CVE-2026-10814 +ghsas: + - GHSA-jh6h-v6mp-h22v +references: + - advisory: https://github.com/advisories/GHSA-jh6h-v6mp-h22v + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-10814 + - fix: https://github.com/milvus-io/milvus/commit/3d932f1c3e065351c4440c27abe1e6479752544d + - fix: https://github.com/milvus-io/milvus/pull/50060 + - report: https://github.com/milvus-io/milvus/issues/49857 + - web: https://vuldb.com/cve/CVE-2026-10814 + - web: https://vuldb.com/submit/831645 + - web: https://vuldb.com/vuln/368262 + - web: https://vuldb.com/vuln/368262/cti +source: + id: GHSA-jh6h-v6mp-h22v + created: 2026-07-17T13:13:38.813671366-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6002.yaml b/data/reports/GO-2026-6002.yaml new file mode 100644 index 0000000..606508c --- /dev/null +++ b/data/reports/GO-2026-6002.yaml
@@ -0,0 +1,19 @@ +id: GO-2026-6002 +modules: + - module: github.com/stacklok/toolhive + versions: + - fixed: 0.31.0 + vulnerable_at: 0.30.1 +summary: |- + ToolHive: SSRF in remote MCP server authentication discovery (host-side, + bypasses container isolation) in github.com/stacklok/toolhive +cves: + - CVE-2026-58196 +ghsas: + - GHSA-pr64-jmmf-jp54 +references: + - advisory: https://github.com/stacklok/toolhive/security/advisories/GHSA-pr64-jmmf-jp54 +source: + id: GHSA-pr64-jmmf-jp54 + created: 2026-07-17T13:13:28.786261645-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6003.yaml b/data/reports/GO-2026-6003.yaml new file mode 100644 index 0000000..7d8ed9d --- /dev/null +++ b/data/reports/GO-2026-6003.yaml
@@ -0,0 +1,21 @@ +id: GO-2026-6003 +modules: + - module: github.com/envoyproxy/gateway + versions: + - fixed: 1.7.4 + - introduced: 1.8.0-rc.0 + - fixed: 1.8.1 + vulnerable_at: 1.8.0 +summary: |- + Envoy Gateway: xDS Control Plane Information Disclosure when operating in + GatewayNamespaceMode in github.com/envoyproxy/gateway +cves: + - CVE-2026-53714 +ghsas: + - GHSA-22xc-xg2r-9j7v +references: + - advisory: https://github.com/envoyproxy/gateway/security/advisories/GHSA-22xc-xg2r-9j7v +source: + id: GHSA-22xc-xg2r-9j7v + created: 2026-07-17T13:13:24.159007384-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6004.yaml b/data/reports/GO-2026-6004.yaml new file mode 100644 index 0000000..27df446 --- /dev/null +++ b/data/reports/GO-2026-6004.yaml
@@ -0,0 +1,22 @@ +id: GO-2026-6004 +modules: + - module: github.com/nuclio/nuclio + non_go_versions: + - fixed: 1.16.5 + vulnerable_at: 1.14.2 +summary: |- + Nuclio: Unsanitized runtimeAttributes.repositories injected into Groovy + build.gradle leads to build-time RCE in github.com/nuclio/nuclio +cves: + - CVE-2026-52833 +ghsas: + - GHSA-3v79-m2cg-89ww +references: + - advisory: https://github.com/nuclio/nuclio/security/advisories/GHSA-3v79-m2cg-89ww + - fix: https://github.com/nuclio/nuclio/commit/4c78040c759068e927f3ed7c6507543c15d4ae56 + - fix: https://github.com/nuclio/nuclio/pull/4149 + - web: https://github.com/nuclio/nuclio/releases/tag/1.16.5 +source: + id: GHSA-3v79-m2cg-89ww + created: 2026-07-17T13:13:17.730178407-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6005.yaml b/data/reports/GO-2026-6005.yaml new file mode 100644 index 0000000..1601450 --- /dev/null +++ b/data/reports/GO-2026-6005.yaml
@@ -0,0 +1,19 @@ +id: GO-2026-6005 +modules: + - module: github.com/envoyproxy/gateway + versions: + - fixed: 1.7.4 + - introduced: 1.8.0-rc.0 + - fixed: 1.8.1 + vulnerable_at: 1.8.0 +summary: 'Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock in github.com/envoyproxy/gateway' +cves: + - CVE-2026-53715 +ghsas: + - GHSA-8fv2-88gg-hm7q +references: + - advisory: https://github.com/envoyproxy/gateway/security/advisories/GHSA-8fv2-88gg-hm7q +source: + id: GHSA-8fv2-88gg-hm7q + created: 2026-07-17T13:13:12.766137212-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6006.yaml b/data/reports/GO-2026-6006.yaml new file mode 100644 index 0000000..70c730e --- /dev/null +++ b/data/reports/GO-2026-6006.yaml
@@ -0,0 +1,19 @@ +id: GO-2026-6006 +modules: + - module: github.com/envoyproxy/gateway + versions: + - fixed: 1.7.4 + - introduced: 1.8.0-rc.0 + - fixed: 1.8.1 + vulnerable_at: 1.8.0 +summary: 'Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit in github.com/envoyproxy/gateway' +cves: + - CVE-2026-53716 +ghsas: + - GHSA-cxpq-8v7q-cg56 +references: + - advisory: https://github.com/envoyproxy/gateway/security/advisories/GHSA-cxpq-8v7q-cg56 +source: + id: GHSA-cxpq-8v7q-cg56 + created: 2026-07-17T13:13:08.071643908-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6007.yaml b/data/reports/GO-2026-6007.yaml new file mode 100644 index 0000000..3e1ef85 --- /dev/null +++ b/data/reports/GO-2026-6007.yaml
@@ -0,0 +1,19 @@ +id: GO-2026-6007 +modules: + - module: github.com/envoyproxy/gateway + versions: + - fixed: 1.7.4 + - introduced: 1.8.0-rc.0 + - fixed: 1.8.1 + vulnerable_at: 1.8.0 +summary: Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass in github.com/envoyproxy/gateway +cves: + - CVE-2026-53718 +ghsas: + - GHSA-fcrp-7gc2-93g7 +references: + - advisory: https://github.com/envoyproxy/gateway/security/advisories/GHSA-fcrp-7gc2-93g7 +source: + id: GHSA-fcrp-7gc2-93g7 + created: 2026-07-17T13:13:03.426486286-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6008.yaml b/data/reports/GO-2026-6008.yaml new file mode 100644 index 0000000..116e69b --- /dev/null +++ b/data/reports/GO-2026-6008.yaml
@@ -0,0 +1,21 @@ +id: GO-2026-6008 +modules: + - module: github.com/envoyproxy/gateway + versions: + - fixed: 1.7.4 + - introduced: 1.8.0-rc.0 + - fixed: 1.8.1 + vulnerable_at: 1.8.0 +summary: |- + Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from + untrusted tar header in github.com/envoyproxy/gateway +cves: + - CVE-2026-53717 +ghsas: + - GHSA-h7pq-86h8-rp5x +references: + - advisory: https://github.com/envoyproxy/gateway/security/advisories/GHSA-h7pq-86h8-rp5x +source: + id: GHSA-h7pq-86h8-rp5x + created: 2026-07-17T13:12:58.694810659-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6009.yaml b/data/reports/GO-2026-6009.yaml new file mode 100644 index 0000000..581589e --- /dev/null +++ b/data/reports/GO-2026-6009.yaml
@@ -0,0 +1,21 @@ +id: GO-2026-6009 +modules: + - module: github.com/envoyproxy/gateway + versions: + - fixed: 1.7.4 + - introduced: 1.8.0-rc.0 + - fixed: 1.8.1 + vulnerable_at: 1.8.0 +summary: |- + Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without + spec.authorization in github.com/envoyproxy/gateway +cves: + - CVE-2026-53719 +ghsas: + - GHSA-m2v6-2jmh-4c68 +references: + - advisory: https://github.com/envoyproxy/gateway/security/advisories/GHSA-m2v6-2jmh-4c68 +source: + id: GHSA-m2v6-2jmh-4c68 + created: 2026-07-17T13:12:54.188292688-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6011.yaml b/data/reports/GO-2026-6011.yaml new file mode 100644 index 0000000..cde07b9 --- /dev/null +++ b/data/reports/GO-2026-6011.yaml
@@ -0,0 +1,21 @@ +id: GO-2026-6011 +modules: + - module: github.com/envoyproxy/gateway + versions: + - fixed: 1.7.4 + - introduced: 1.8.0-rc.0 + - fixed: 1.8.1 + vulnerable_at: 1.8.0 +summary: |- + Envoy Gateway: Authentication Bypass via Improper Input Validation in + EnvoyExtensionPolicy Lua Allows Secret Disclosure in github.com/envoyproxy/gateway +cves: + - CVE-2026-53713 +ghsas: + - GHSA-wcrf-9vrr-854f +references: + - advisory: https://github.com/envoyproxy/gateway/security/advisories/GHSA-wcrf-9vrr-854f +source: + id: GHSA-wcrf-9vrr-854f + created: 2026-07-17T13:12:44.700642063-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6012.yaml b/data/reports/GO-2026-6012.yaml new file mode 100644 index 0000000..21a079a --- /dev/null +++ b/data/reports/GO-2026-6012.yaml
@@ -0,0 +1,22 @@ +id: GO-2026-6012 +modules: + - module: github.com/nuclio/nuclio + non_go_versions: + - fixed: 1.16.5 + vulnerable_at: 1.14.2 +summary: |- + Nuclio: Unauthenticated path traversal in spec.handler allows arbitrary file + write in Dashboard container in github.com/nuclio/nuclio +cves: + - CVE-2026-52832 +ghsas: + - GHSA-wpcj-rmv4-86qg +references: + - advisory: https://github.com/nuclio/nuclio/security/advisories/GHSA-wpcj-rmv4-86qg + - fix: https://github.com/nuclio/nuclio/commit/2a55d3a8bd4d49226cb4742020303f5bf2a0931d + - fix: https://github.com/nuclio/nuclio/pull/4143 + - web: https://github.com/nuclio/nuclio/releases/tag/1.16.5 +source: + id: GHSA-wpcj-rmv4-86qg + created: 2026-07-17T13:12:37.152813427-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6014.yaml b/data/reports/GO-2026-6014.yaml new file mode 100644 index 0000000..1695f84 --- /dev/null +++ b/data/reports/GO-2026-6014.yaml
@@ -0,0 +1,25 @@ +id: GO-2026-6014 +modules: + - module: github.com/saltbo/zpan + versions: + - fixed: 1.6.6 + vulnerable_at: 1.6.5 +summary: ZPan Uses Hard-Coded Password in github.com/saltbo/zpan +cves: + - CVE-2025-7453 +ghsas: + - GHSA-2hfh-94w5-wxvf +references: + - advisory: https://github.com/advisories/GHSA-2hfh-94w5-wxvf + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2025-7453 + - fix: https://github.com/saltbo/zpan/commit/8662db8d4b06057631faf3deba4132e66705e947 + - fix: https://github.com/saltbo/zpan/pull/410 + - report: https://github.com/saltbo/zpan/issues/219 + - web: https://github.com/saltbo/zpan/releases/tag/v1.6.6 + - web: https://vuldb.com/?ctiid.316097 + - web: https://vuldb.com/?id.316097 + - web: https://vuldb.com/?submit.608447 +source: + id: GHSA-2hfh-94w5-wxvf + created: 2026-07-17T13:12:17.850164996-04:00 +review_status: UNREVIEWED