data/reports: add 66 reports

  - data/reports/GO-2026-5929.yaml
  - data/reports/GO-2026-5930.yaml
  - data/reports/GO-2026-5933.yaml
  - data/reports/GO-2026-5934.yaml
  - data/reports/GO-2026-5935.yaml
  - data/reports/GO-2026-5936.yaml
  - data/reports/GO-2026-5937.yaml
  - data/reports/GO-2026-5938.yaml
  - data/reports/GO-2026-5939.yaml
  - data/reports/GO-2026-5940.yaml
  - data/reports/GO-2026-5941.yaml
  - data/reports/GO-2026-5944.yaml
  - data/reports/GO-2026-5945.yaml
  - data/reports/GO-2026-5946.yaml
  - data/reports/GO-2026-5947.yaml
  - data/reports/GO-2026-5948.yaml
  - data/reports/GO-2026-5949.yaml
  - data/reports/GO-2026-5950.yaml
  - data/reports/GO-2026-5951.yaml
  - data/reports/GO-2026-5952.yaml
  - data/reports/GO-2026-5953.yaml
  - data/reports/GO-2026-5956.yaml
  - data/reports/GO-2026-5957.yaml
  - data/reports/GO-2026-5958.yaml
  - data/reports/GO-2026-5959.yaml
  - data/reports/GO-2026-5961.yaml
  - data/reports/GO-2026-5962.yaml
  - data/reports/GO-2026-5963.yaml
  - data/reports/GO-2026-5964.yaml
  - data/reports/GO-2026-5965.yaml
  - data/reports/GO-2026-5966.yaml
  - data/reports/GO-2026-5967.yaml
  - data/reports/GO-2026-5968.yaml
  - data/reports/GO-2026-5969.yaml
  - data/reports/GO-2026-5973.yaml
  - data/reports/GO-2026-5974.yaml
  - data/reports/GO-2026-5975.yaml
  - data/reports/GO-2026-5976.yaml
  - data/reports/GO-2026-5977.yaml
  - data/reports/GO-2026-5978.yaml
  - data/reports/GO-2026-5979.yaml
  - data/reports/GO-2026-5980.yaml
  - data/reports/GO-2026-5981.yaml
  - data/reports/GO-2026-5982.yaml
  - data/reports/GO-2026-5984.yaml
  - data/reports/GO-2026-5985.yaml
  - data/reports/GO-2026-5986.yaml
  - data/reports/GO-2026-5988.yaml
  - data/reports/GO-2026-5990.yaml
  - data/reports/GO-2026-5991.yaml
  - data/reports/GO-2026-5992.yaml
  - data/reports/GO-2026-5996.yaml
  - data/reports/GO-2026-5997.yaml
  - data/reports/GO-2026-5998.yaml
  - data/reports/GO-2026-5999.yaml
  - data/reports/GO-2026-6002.yaml
  - data/reports/GO-2026-6003.yaml
  - data/reports/GO-2026-6004.yaml
  - data/reports/GO-2026-6005.yaml
  - data/reports/GO-2026-6006.yaml
  - data/reports/GO-2026-6007.yaml
  - data/reports/GO-2026-6008.yaml
  - data/reports/GO-2026-6009.yaml
  - data/reports/GO-2026-6011.yaml
  - data/reports/GO-2026-6012.yaml
  - data/reports/GO-2026-6014.yaml

Fixes golang/vulndb#5929
Fixes golang/vulndb#5930
Fixes golang/vulndb#5933
Fixes golang/vulndb#5934
Fixes golang/vulndb#5935
Fixes golang/vulndb#5936
Fixes golang/vulndb#5937
Fixes golang/vulndb#5938
Fixes golang/vulndb#5939
Fixes golang/vulndb#5940
Fixes golang/vulndb#5941
Fixes golang/vulndb#5944
Fixes golang/vulndb#5945
Fixes golang/vulndb#5946
Fixes golang/vulndb#5947
Fixes golang/vulndb#5948
Fixes golang/vulndb#5949
Fixes golang/vulndb#5950
Fixes golang/vulndb#5951
Fixes golang/vulndb#5952
Fixes golang/vulndb#5953
Fixes golang/vulndb#5956
Fixes golang/vulndb#5957
Fixes golang/vulndb#5958
Fixes golang/vulndb#5959
Fixes golang/vulndb#5961
Fixes golang/vulndb#5962
Fixes golang/vulndb#5963
Fixes golang/vulndb#5964
Fixes golang/vulndb#5965
Fixes golang/vulndb#5966
Fixes golang/vulndb#5967
Fixes golang/vulndb#5968
Fixes golang/vulndb#5969
Fixes golang/vulndb#5973
Fixes golang/vulndb#5974
Fixes golang/vulndb#5975
Fixes golang/vulndb#5976
Fixes golang/vulndb#5977
Fixes golang/vulndb#5978
Fixes golang/vulndb#5979
Fixes golang/vulndb#5980
Fixes golang/vulndb#5981
Fixes golang/vulndb#5982
Fixes golang/vulndb#5984
Fixes golang/vulndb#5985
Fixes golang/vulndb#5986
Fixes golang/vulndb#5988
Fixes golang/vulndb#5990
Fixes golang/vulndb#5991
Fixes golang/vulndb#5992
Fixes golang/vulndb#5996
Fixes golang/vulndb#5997
Fixes golang/vulndb#5998
Fixes golang/vulndb#5999
Fixes golang/vulndb#6002
Fixes golang/vulndb#6003
Fixes golang/vulndb#6004
Fixes golang/vulndb#6005
Fixes golang/vulndb#6006
Fixes golang/vulndb#6007
Fixes golang/vulndb#6008
Fixes golang/vulndb#6009
Fixes golang/vulndb#6011
Fixes golang/vulndb#6012
Fixes golang/vulndb#6014

Change-Id: I3b8ee51b15f56eef91cf025d01f75eea6f18bd4f
Reviewed-on: https://go-review.googlesource.com/c/vulndb/+/802300
Reviewed-by: Nicholas Husin <husin@google.com>
Reviewed-by: Ethan Lee <ethanalee@google.com>
LUCI-TryBot-Result: golang-scoped@luci-project-accounts.iam.gserviceaccount.com <golang-scoped@luci-project-accounts.iam.gserviceaccount.com>
Auto-Submit: Nicholas Husin <husin@google.com>
diff --git a/data/osv/GO-2026-5929.json b/data/osv/GO-2026-5929.json
new file mode 100644
index 0000000..ab0dc28
--- /dev/null
+++ b/data/osv/GO-2026-5929.json
@@ -0,0 +1,48 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-5929",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-44342",
+    "GHSA-26v7-h57m-gh9m"
+  ],
+  "summary": "New API is vulnerable to CSRF through user email binding in github.com/QuantumNous/new-api",
+  "details": "New API is vulnerable to CSRF through user email binding in github.com/QuantumNous/new-api",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/QuantumNous/new-api",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "0.12.0-alpha.1"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/QuantumNous/new-api/security/advisories/GHSA-26v7-h57m-gh9m"
+    },
+    {
+      "type": "FIX",
+      "url": "https://github.com/QuantumNous/new-api/commit/e099117c61391abdf888fb75e382a582e550bd0e"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-5929",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-5930.json b/data/osv/GO-2026-5930.json
new file mode 100644
index 0000000..481ca2d
--- /dev/null
+++ b/data/osv/GO-2026-5930.json
@@ -0,0 +1,48 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-5930",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-33655",
+    "GHSA-6qcr-qxgr-m7fv"
+  ],
+  "summary": "New API: SSRF Protection Bypass via Unresolved Hostname in Notification URLs in github.com/QuantumNous/new-api",
+  "details": "New API: SSRF Protection Bypass via Unresolved Hostname in Notification URLs in github.com/QuantumNous/new-api",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/QuantumNous/new-api",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "0.12.0-alpha.1"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/QuantumNous/new-api/security/advisories/GHSA-6qcr-qxgr-m7fv"
+    },
+    {
+      "type": "FIX",
+      "url": "https://github.com/QuantumNous/new-api/commit/20399d3c8fcb4e3649d53163eb11940fd6763743"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-5930",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-5933.json b/data/osv/GO-2026-5933.json
new file mode 100644
index 0000000..82483ac
--- /dev/null
+++ b/data/osv/GO-2026-5933.json
@@ -0,0 +1,43 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-5933",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "GHSA-3g4q-2f67-2gvh"
+  ],
+  "summary": "netfoil has a resource leak in LRU cache in github.com/tinfoil-factory/netfoil",
+  "details": "netfoil has a resource leak in LRU cache in github.com/tinfoil-factory/netfoil",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/tinfoil-factory/netfoil",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "0.3.0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/tinfoil-factory/netfoil/security/advisories/GHSA-3g4q-2f67-2gvh"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-5933",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-5934.json b/data/osv/GO-2026-5934.json
new file mode 100644
index 0000000..324c5bd
--- /dev/null
+++ b/data/osv/GO-2026-5934.json
@@ -0,0 +1,43 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-5934",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "GHSA-59qp-cfj3-rp64"
+  ],
+  "summary": "netfoil has a domain name filter bypass via multiple questions in github.com/tinfoil-factory/netfoil",
+  "details": "netfoil has a domain name filter bypass via multiple questions in github.com/tinfoil-factory/netfoil",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/tinfoil-factory/netfoil",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "0.3.0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/tinfoil-factory/netfoil/security/advisories/GHSA-59qp-cfj3-rp64"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-5934",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-5935.json b/data/osv/GO-2026-5935.json
new file mode 100644
index 0000000..7e35b88
--- /dev/null
+++ b/data/osv/GO-2026-5935.json
@@ -0,0 +1,43 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-5935",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "GHSA-7856-g3gv-9wq8"
+  ],
+  "summary": "netfoil: Attacker controlled data written to logs in github.com/tinfoil-factory/netfoil",
+  "details": "netfoil: Attacker controlled data written to logs in github.com/tinfoil-factory/netfoil",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/tinfoil-factory/netfoil",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "0.3.0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/tinfoil-factory/netfoil/security/advisories/GHSA-7856-g3gv-9wq8"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-5935",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-5936.json b/data/osv/GO-2026-5936.json
new file mode 100644
index 0000000..a262565
--- /dev/null
+++ b/data/osv/GO-2026-5936.json
@@ -0,0 +1,41 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-5936",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-53552",
+    "GHSA-26rh-24rg-j3vv"
+  ],
+  "summary": "Goploy: Cross-namespace IDOR and RCE via body-supplied row id in project and project_file handlers in github.com/zhenorzz/goploy",
+  "details": "Goploy: Cross-namespace IDOR and RCE via body-supplied row id in project and project_file handlers in github.com/zhenorzz/goploy",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/zhenorzz/goploy",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/zhenorzz/goploy/security/advisories/GHSA-26rh-24rg-j3vv"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-5936",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-5937.json b/data/osv/GO-2026-5937.json
new file mode 100644
index 0000000..be5759a
--- /dev/null
+++ b/data/osv/GO-2026-5937.json
@@ -0,0 +1,56 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-5937",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-53508",
+    "GHSA-2jcc-mxv7-p3f9"
+  ],
+  "summary": "oasdiff does not enforce --allow-external-refs=false on the git-revision load path (SSRF / local file read) in github.com/oasdiff/oasdiff",
+  "details": "oasdiff does not enforce --allow-external-refs=false on the git-revision load path (SSRF / local file read) in github.com/oasdiff/oasdiff",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/oasdiff/oasdiff",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "1.13.2"
+            },
+            {
+              "fixed": "1.18.1"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/oasdiff/oasdiff/security/advisories/GHSA-2jcc-mxv7-p3f9"
+    },
+    {
+      "type": "FIX",
+      "url": "https://github.com/oasdiff/oasdiff/pull/832"
+    },
+    {
+      "type": "FIX",
+      "url": "https://github.com/oasdiff/oasdiff/pull/974"
+    },
+    {
+      "type": "FIX",
+      "url": "https://github.com/oasdiff/oasdiff/pull/975"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-5937",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-5938.json b/data/osv/GO-2026-5938.json
new file mode 100644
index 0000000..03cf906
--- /dev/null
+++ b/data/osv/GO-2026-5938.json
@@ -0,0 +1,41 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-5938",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-53553",
+    "GHSA-4g5x-hcwm-82jw"
+  ],
+  "summary": "Goploy: Arbitrary File Read via Path Traversal in /deploy/fileDiff allows Remote Server Compromise in github.com/zhenorzz/goploy",
+  "details": "Goploy: Arbitrary File Read via Path Traversal in /deploy/fileDiff allows Remote Server Compromise in github.com/zhenorzz/goploy",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/zhenorzz/goploy",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/zhenorzz/goploy/security/advisories/GHSA-4g5x-hcwm-82jw"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-5938",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-5939.json b/data/osv/GO-2026-5939.json
new file mode 100644
index 0000000..65bc099
--- /dev/null
+++ b/data/osv/GO-2026-5939.json
@@ -0,0 +1,53 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-5939",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-10517",
+    "GHSA-698x-9w2p-7vvp"
+  ],
+  "summary": "Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints in github.com/quay/claircore",
+  "details": "Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints in github.com/quay/claircore",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/quay/claircore",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/advisories/GHSA-698x-9w2p-7vvp"
+    },
+    {
+      "type": "ADVISORY",
+      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-10517"
+    },
+    {
+      "type": "WEB",
+      "url": "https://access.redhat.com/security/cve/CVE-2026-10517"
+    },
+    {
+      "type": "WEB",
+      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2486779"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-5939",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-5940.json b/data/osv/GO-2026-5940.json
new file mode 100644
index 0000000..aea069a
--- /dev/null
+++ b/data/osv/GO-2026-5940.json
@@ -0,0 +1,61 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-5940",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-53572",
+    "GHSA-6w3m-4hhp-775q"
+  ],
+  "summary": "KEDA has PostgreSQL connection string parameter injection via incomplete whitespace escaping in github.com/kedacore/keda",
+  "details": "KEDA has PostgreSQL connection string parameter injection via incomplete whitespace escaping in github.com/kedacore/keda",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/kedacore/keda",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    },
+    {
+      "package": {
+        "name": "github.com/kedacore/keda/v2",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "2.20.0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/kedacore/keda/security/advisories/GHSA-6w3m-4hhp-775q"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-5940",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-5941.json b/data/osv/GO-2026-5941.json
new file mode 100644
index 0000000..2bc3f10
--- /dev/null
+++ b/data/osv/GO-2026-5941.json
@@ -0,0 +1,44 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-5941",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-53487",
+    "GHSA-gvhc-wv3v-7pf8"
+  ],
+  "summary": "Kite has an authenticated cluster RBAC bypass in /api/v1/overview in github.com/zxh326/kite",
+  "details": "Kite has an authenticated cluster RBAC bypass in /api/v1/overview in github.com/zxh326/kite",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/zxh326/kite",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "0.12.3"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/kite-org/kite/security/advisories/GHSA-gvhc-wv3v-7pf8"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-5941",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-5944.json b/data/osv/GO-2026-5944.json
new file mode 100644
index 0000000..db1cf49
--- /dev/null
+++ b/data/osv/GO-2026-5944.json
@@ -0,0 +1,44 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-5944",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-50197",
+    "GHSA-659f-rgp5-w4wf"
+  ],
+  "summary": "Skipper: opaAuthorizeRequestWithBody filter bypasses OPA policy on Transfer-Encoding — chunked / HTTP/2 requests in github.com/zalando/skipper",
+  "details": "Skipper: opaAuthorizeRequestWithBody filter bypasses OPA policy on Transfer-Encoding — chunked / HTTP/2 requests in github.com/zalando/skipper",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/zalando/skipper",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "0.26.10"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/zalando/skipper/security/advisories/GHSA-659f-rgp5-w4wf"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-5944",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-5945.json b/data/osv/GO-2026-5945.json
new file mode 100644
index 0000000..40d2ff0
--- /dev/null
+++ b/data/osv/GO-2026-5945.json
@@ -0,0 +1,53 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-5945",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-6815",
+    "GHSA-rmxx-v9rj-vpvg"
+  ],
+  "summary": "Casdoor: Arbitrary file write possible through Local File System storage provider in github.com/casdoor/casdoor",
+  "details": "Casdoor: Arbitrary file write possible through Local File System storage provider in github.com/casdoor/casdoor",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/casdoor/casdoor",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/advisories/GHSA-rmxx-v9rj-vpvg"
+    },
+    {
+      "type": "ADVISORY",
+      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6815"
+    },
+    {
+      "type": "WEB",
+      "url": "https://kb.cert.org/vuls/id/937808"
+    },
+    {
+      "type": "WEB",
+      "url": "https://www.kb.cert.org/vuls/id/937808"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-5945",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-5946.json b/data/osv/GO-2026-5946.json
new file mode 100644
index 0000000..74080bd
--- /dev/null
+++ b/data/osv/GO-2026-5946.json
@@ -0,0 +1,52 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-5946",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-52831",
+    "GHSA-v5px-423j-pf7p"
+  ],
+  "summary": "Nuclio: Unsanitized cron trigger event headers/body injected into CronJob shell command leads to persistent RCE in github.com/nuclio/nuclio",
+  "details": "Nuclio: Unsanitized cron trigger event headers/body injected into CronJob shell command leads to persistent RCE in github.com/nuclio/nuclio",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/nuclio/nuclio",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "0.0.0-20260601075854-3356b86a8bfa"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/nuclio/nuclio/security/advisories/GHSA-v5px-423j-pf7p"
+    },
+    {
+      "type": "FIX",
+      "url": "https://github.com/nuclio/nuclio/commit/3356b86a8bfab3f960aa420310ebff765df9dede"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/nuclio/nuclio/releases/tag/1.16.4"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-5946",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-5947.json b/data/osv/GO-2026-5947.json
new file mode 100644
index 0000000..98f08a1
--- /dev/null
+++ b/data/osv/GO-2026-5947.json
@@ -0,0 +1,44 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-5947",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-53649",
+    "GHSA-xqhv-chqm-fhcc"
+  ],
+  "summary": "Joro: Unauthenticated Cross-Origin Plugin Upload Leads to RCE in github.com/BishopFox/joro",
+  "details": "Joro: Unauthenticated Cross-Origin Plugin Upload Leads to RCE in github.com/BishopFox/joro",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/BishopFox/joro",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "0.0.0-20260601151442-5c0ca35db828"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/BishopFox/joro/security/advisories/GHSA-xqhv-chqm-fhcc"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-5947",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-5948.json b/data/osv/GO-2026-5948.json
new file mode 100644
index 0000000..e8bfd90
--- /dev/null
+++ b/data/osv/GO-2026-5948.json
@@ -0,0 +1,48 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-5948",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-50554",
+    "GHSA-588f-fvcv-xhvf"
+  ],
+  "summary": "Note Mark: Unauthenticated disclosure of soft-deleted note metadata via deleted=true on public books in github.com/enchant97/note-mark/backend",
+  "details": "Note Mark: Unauthenticated disclosure of soft-deleted note metadata via deleted=true on public books in github.com/enchant97/note-mark/backend",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/enchant97/note-mark/backend",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "0.0.0-20260601210758-9c9b72740f22"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/enchant97/note-mark/security/advisories/GHSA-588f-fvcv-xhvf"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/enchant97/note-mark/commit/9c9b72740f22a06131a8f64b53bb08e3b05b81a6"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-5948",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-5949.json b/data/osv/GO-2026-5949.json
new file mode 100644
index 0000000..982527d
--- /dev/null
+++ b/data/osv/GO-2026-5949.json
@@ -0,0 +1,48 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-5949",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-50553",
+    "GHSA-rqrh-8wpv-x7hh"
+  ],
+  "summary": "Note Mark: Path traversal via unsanitized book/note slug in migrate export (sibling of GHSA-g49p) in github.com/enchant97/note-mark/backend",
+  "details": "Note Mark: Path traversal via unsanitized book/note slug in migrate export (sibling of GHSA-g49p) in github.com/enchant97/note-mark/backend",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/enchant97/note-mark/backend",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "0.0.0-20260601210719-67b7de04308a"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/enchant97/note-mark/security/advisories/GHSA-rqrh-8wpv-x7hh"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/enchant97/note-mark/commit/67b7de04308a858ef27ceff87b514067b6d667e5"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-5949",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-5950.json b/data/osv/GO-2026-5950.json
new file mode 100644
index 0000000..eecfd0c
--- /dev/null
+++ b/data/osv/GO-2026-5950.json
@@ -0,0 +1,48 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-5950",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-53602",
+    "GHSA-339v-266x-79xr"
+  ],
+  "summary": "nebula-mesh: Host revocation is not durable - blocked/offboarded hosts can regain a valid certificate in github.com/forgekeep/nebula-mesh",
+  "details": "nebula-mesh: Host revocation is not durable - blocked/offboarded hosts can regain a valid certificate in github.com/forgekeep/nebula-mesh",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/forgekeep/nebula-mesh",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "0.3.7"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/forgekeep/nebula-mesh/security/advisories/GHSA-339v-266x-79xr"
+    },
+    {
+      "type": "REPORT",
+      "url": "https://github.com/forgekeep/nebula-mesh/issues/178"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-5950",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-5951.json b/data/osv/GO-2026-5951.json
new file mode 100644
index 0000000..ec53c03
--- /dev/null
+++ b/data/osv/GO-2026-5951.json
@@ -0,0 +1,69 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-5951",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-10219",
+    "GHSA-6jm8-4fhr-5w64"
+  ],
+  "summary": "GoClaw has a Command Injection issue in github.com/nextlevelbuilder/goclaw",
+  "details": "GoClaw has a Command Injection issue in github.com/nextlevelbuilder/goclaw",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/nextlevelbuilder/goclaw",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/advisories/GHSA-6jm8-4fhr-5w64"
+    },
+    {
+      "type": "ADVISORY",
+      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-10219"
+    },
+    {
+      "type": "FIX",
+      "url": "https://github.com/nextlevelbuilder/goclaw/pull/1155"
+    },
+    {
+      "type": "REPORT",
+      "url": "https://github.com/nextlevelbuilder/goclaw/issues/1121"
+    },
+    {
+      "type": "WEB",
+      "url": "https://vuldb.com/cve/CVE-2026-10219"
+    },
+    {
+      "type": "WEB",
+      "url": "https://vuldb.com/submit/821939"
+    },
+    {
+      "type": "WEB",
+      "url": "https://vuldb.com/vuln/367498"
+    },
+    {
+      "type": "WEB",
+      "url": "https://vuldb.com/vuln/367498/cti"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-5951",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-5952.json b/data/osv/GO-2026-5952.json
new file mode 100644
index 0000000..cc9b6dc
--- /dev/null
+++ b/data/osv/GO-2026-5952.json
@@ -0,0 +1,44 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-5952",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-49834",
+    "GHSA-9vcr-p3rj-q5q6"
+  ],
+  "summary": "sigstore-go has a multi-log threshold bypass via single compromised log in github.com/sigstore/sigstore-go",
+  "details": "sigstore-go has a multi-log threshold bypass via single compromised log in github.com/sigstore/sigstore-go",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/sigstore/sigstore-go",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "1.2.0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/sigstore/sigstore-go/security/advisories/GHSA-9vcr-p3rj-q5q6"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-5952",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-5953.json b/data/osv/GO-2026-5953.json
new file mode 100644
index 0000000..70b87a2
--- /dev/null
+++ b/data/osv/GO-2026-5953.json
@@ -0,0 +1,67 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-5953",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-9094",
+    "GHSA-c9w5-qp6m-m395"
+  ],
+  "summary": "Casdoor: GetTokenExchangeToken bypass through lack of cross-organization JWT signature check in github.com/casdoor/casdoor",
+  "details": "Casdoor: GetTokenExchangeToken bypass through lack of cross-organization JWT signature check in github.com/casdoor/casdoor.\n\nNOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.\n\n(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)\n\nThe additional affected modules and versions are: github.com/casdoor/casdoor before v2.387.0.",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/casdoor/casdoor",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {
+        "custom_ranges": [
+          {
+            "type": "ECOSYSTEM",
+            "events": [
+              {
+                "introduced": "0"
+              },
+              {
+                "fixed": "2.387.0"
+              }
+            ]
+          }
+        ]
+      }
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/advisories/GHSA-c9w5-qp6m-m395"
+    },
+    {
+      "type": "ADVISORY",
+      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-9094"
+    },
+    {
+      "type": "FIX",
+      "url": "https://github.com/casdoor/casdoor/commit/d92b8568686d"
+    },
+    {
+      "type": "WEB",
+      "url": "https://kb.cert.org/vuls/id/780781"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-5953",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-5956.json b/data/osv/GO-2026-5956.json
new file mode 100644
index 0000000..df11d50
--- /dev/null
+++ b/data/osv/GO-2026-5956.json
@@ -0,0 +1,52 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-5956",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-55252",
+    "GHSA-h5g6-xmh4-hc37"
+  ],
+  "summary": "OpenRun: Redirect URL validation bypass using  //host  paths leads to Open Redirect in github.com/openrundev/openrun",
+  "details": "OpenRun: Redirect URL validation bypass using  //host  paths leads to Open Redirect in github.com/openrundev/openrun",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/openrundev/openrun",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "0.17.7"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/openrundev/openrun/security/advisories/GHSA-h5g6-xmh4-hc37"
+    },
+    {
+      "type": "FIX",
+      "url": "https://github.com/openrundev/openrun/commit/709da784fcf1311c85f30f3542cfa3601a78bbf0"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/openrundev/openrun/releases/tag/v0.17.7"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-5956",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-5957.json b/data/osv/GO-2026-5957.json
new file mode 100644
index 0000000..63e63d3
--- /dev/null
+++ b/data/osv/GO-2026-5957.json
@@ -0,0 +1,48 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-5957",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-54158",
+    "GHSA-5xfx-xj4h-5p7r"
+  ],
+  "summary": "SiYuan: Stored XSS to RCE via attribute-view cell rendering in genAVValueHTML() in github.com/siyuan-note/siyuan/kernel",
+  "details": "SiYuan: Stored XSS to RCE via attribute-view cell rendering in genAVValueHTML() in github.com/siyuan-note/siyuan/kernel",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/siyuan-note/siyuan/kernel",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "0.0.0-20260628153353-2d5d72223df4"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/siyuan-note/siyuan/security/advisories/GHSA-5xfx-xj4h-5p7r"
+    },
+    {
+      "type": "ADVISORY",
+      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54158"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-5957",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-5958.json b/data/osv/GO-2026-5958.json
new file mode 100644
index 0000000..5ea5301
--- /dev/null
+++ b/data/osv/GO-2026-5958.json
@@ -0,0 +1,48 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-5958",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-54068",
+    "GHSA-gcm7-57gf-953c"
+  ],
+  "summary": "SiYuan: Unauthenticated SQLite Data Exfiltration via Template Injection in /api/icon/getDynamicIcon in github.com/siyuan-note/siyuan/kernel",
+  "details": "SiYuan: Unauthenticated SQLite Data Exfiltration via Template Injection in /api/icon/getDynamicIcon in github.com/siyuan-note/siyuan/kernel",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/siyuan-note/siyuan/kernel",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "0.0.0-20260628153353-2d5d72223df4"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/siyuan-note/siyuan/security/advisories/GHSA-gcm7-57gf-953c"
+    },
+    {
+      "type": "ADVISORY",
+      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54068"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-5958",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-5959.json b/data/osv/GO-2026-5959.json
new file mode 100644
index 0000000..8ec4d94
--- /dev/null
+++ b/data/osv/GO-2026-5959.json
@@ -0,0 +1,44 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-5959",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-54072",
+    "GHSA-h29v-hj44-q8cv"
+  ],
+  "summary": "Authorizer: Unvalidated redirect_uri in /authorize leaks OAuth2 tokens to attacker-controlled URL in github.com/authorizerdev/authorizer",
+  "details": "Authorizer: Unvalidated redirect_uri in /authorize leaks OAuth2 tokens to attacker-controlled URL in github.com/authorizerdev/authorizer",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/authorizerdev/authorizer",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "0.0.0-20260409051328-bd3f5baf6d3d"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/authorizerdev/authorizer/security/advisories/GHSA-h29v-hj44-q8cv"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-5959",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-5961.json b/data/osv/GO-2026-5961.json
new file mode 100644
index 0000000..fcc4511
--- /dev/null
+++ b/data/osv/GO-2026-5961.json
@@ -0,0 +1,48 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-5961",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-54069",
+    "GHSA-hvr9-72v2-fff3"
+  ],
+  "summary": "SiYuan: Unauthenticated Admin API Access via Blanket chrome-extension:// Origin Allowlist in github.com/siyuan-note/siyuan/kernel",
+  "details": "SiYuan: Unauthenticated Admin API Access via Blanket chrome-extension:// Origin Allowlist in github.com/siyuan-note/siyuan/kernel",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/siyuan-note/siyuan/kernel",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "0.0.0-20260628153353-2d5d72223df4"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/siyuan-note/siyuan/security/advisories/GHSA-hvr9-72v2-fff3"
+    },
+    {
+      "type": "ADVISORY",
+      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54069"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-5961",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-5962.json b/data/osv/GO-2026-5962.json
new file mode 100644
index 0000000..c7dc87e
--- /dev/null
+++ b/data/osv/GO-2026-5962.json
@@ -0,0 +1,65 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-5962",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-54088",
+    "GHSA-m93h-4hw7-5qcm"
+  ],
+  "summary": "File Browser: Command Injection via Authentication Hook Shell Substitution (Pre-Authentication RCE) in github.com/filebrowser/filebrowser",
+  "details": "File Browser: Command Injection via Authentication Hook Shell Substitution (Pre-Authentication RCE) in github.com/filebrowser/filebrowser",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/filebrowser/filebrowser",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    },
+    {
+      "package": {
+        "name": "github.com/filebrowser/filebrowser/v2",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "2.63.6"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/filebrowser/filebrowser/security/advisories/GHSA-m93h-4hw7-5qcm"
+    },
+    {
+      "type": "ADVISORY",
+      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54088"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-5962",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-5963.json b/data/osv/GO-2026-5963.json
new file mode 100644
index 0000000..1ceb629
--- /dev/null
+++ b/data/osv/GO-2026-5963.json
@@ -0,0 +1,48 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-5963",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-54067",
+    "GHSA-mvjr-vv3c-w4qv"
+  ],
+  "summary": "SiYuan: Stored XSS to RCE via CSS-snippet \u003cstyle\u003e breakout in renderSnippet() in github.com/siyuan-note/siyuan/kernel",
+  "details": "SiYuan: Stored XSS to RCE via CSS-snippet \u003cstyle\u003e breakout in renderSnippet() in github.com/siyuan-note/siyuan/kernel",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/siyuan-note/siyuan/kernel",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "0.0.0-20260628153353-2d5d72223df4"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/siyuan-note/siyuan/security/advisories/GHSA-mvjr-vv3c-w4qv"
+    },
+    {
+      "type": "ADVISORY",
+      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54067"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-5963",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-5964.json b/data/osv/GO-2026-5964.json
new file mode 100644
index 0000000..d0929d5
--- /dev/null
+++ b/data/osv/GO-2026-5964.json
@@ -0,0 +1,48 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-5964",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-54066",
+    "GHSA-p4m3-mgmm-c664"
+  ],
+  "summary": "SiYuan: Path Traversal via Double URL Encoding in /assets/*path (publish mode arbitrary file─read), Incomplete fix of CVE-2026-41894 in github.com/siyuan-note/siyuan/kernel",
+  "details": "SiYuan: Path Traversal via Double URL Encoding in /assets/*path (publish mode arbitrary file─read), Incomplete fix of CVE-2026-41894 in github.com/siyuan-note/siyuan/kernel",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/siyuan-note/siyuan/kernel",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "0.0.0-20260628153353-2d5d72223df4"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/siyuan-note/siyuan/security/advisories/GHSA-p4m3-mgmm-c664"
+    },
+    {
+      "type": "ADVISORY",
+      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54066"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-5964",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-5965.json b/data/osv/GO-2026-5965.json
new file mode 100644
index 0000000..8d0a9a6
--- /dev/null
+++ b/data/osv/GO-2026-5965.json
@@ -0,0 +1,48 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-5965",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-54070",
+    "GHSA-w7cg-whh7-xp28"
+  ],
+  "summary": "SiYuan: Stored XSS in Bazaar marketplace via package README event handlers in github.com/siyuan-note/siyuan/kernel",
+  "details": "SiYuan: Stored XSS in Bazaar marketplace via package README event handlers in github.com/siyuan-note/siyuan/kernel",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/siyuan-note/siyuan/kernel",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "0.0.0-20260628153353-2d5d72223df4"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/siyuan-note/siyuan/security/advisories/GHSA-w7cg-whh7-xp28"
+    },
+    {
+      "type": "ADVISORY",
+      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54070"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-5965",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-5966.json b/data/osv/GO-2026-5966.json
new file mode 100644
index 0000000..44223c7
--- /dev/null
+++ b/data/osv/GO-2026-5966.json
@@ -0,0 +1,62 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-5966",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-54089",
+    "GHSA-xqp3-jq6g-x3qm"
+  ],
+  "summary": "File Browser: Authentication Bypass via Proxy Auth Header Forgery in github.com/filebrowser/filebrowser",
+  "details": "File Browser: Authentication Bypass via Proxy Auth Header Forgery in github.com/filebrowser/filebrowser",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/filebrowser/filebrowser",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    },
+    {
+      "package": {
+        "name": "github.com/filebrowser/filebrowser/v2",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "2.0.0-rc.1"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/filebrowser/filebrowser/security/advisories/GHSA-xqp3-jq6g-x3qm"
+    },
+    {
+      "type": "ADVISORY",
+      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54089"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-5966",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-5967.json b/data/osv/GO-2026-5967.json
new file mode 100644
index 0000000..00b5082
--- /dev/null
+++ b/data/osv/GO-2026-5967.json
@@ -0,0 +1,48 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-5967",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-50551",
+    "GHSA-56mp-4f3v-fgj2"
+  ],
+  "summary": "SiYuan: Stored XSS to RCE via Unsanitized Attribute View Asset Cell Content in github.com/siyuan-note/siyuan/kernel",
+  "details": "SiYuan: Stored XSS to RCE via Unsanitized Attribute View Asset Cell Content in github.com/siyuan-note/siyuan/kernel",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/siyuan-note/siyuan/kernel",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "0.0.0-20260628153353-2d5d72223df4"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/siyuan-note/siyuan/security/advisories/GHSA-56mp-4f3v-fgj2"
+    },
+    {
+      "type": "ADVISORY",
+      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-50551"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-5967",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-5968.json b/data/osv/GO-2026-5968.json
new file mode 100644
index 0000000..c2b658e
--- /dev/null
+++ b/data/osv/GO-2026-5968.json
@@ -0,0 +1,64 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-5968",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-54174",
+    "GHSA-fpg8-7664-jc5q"
+  ],
+  "summary": "melange: Incomplete package integrity verification allows data section substitution in chainguard.dev/apko",
+  "details": "melange: Incomplete package integrity verification allows data section substitution in chainguard.dev/apko",
+  "affected": [
+    {
+      "package": {
+        "name": "chainguard.dev/apko",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "1.2.9"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    },
+    {
+      "package": {
+        "name": "chainguard.dev/melange",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "0.50.4"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/chainguard-dev/melange/security/advisories/GHSA-fpg8-7664-jc5q"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-5968",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-5969.json b/data/osv/GO-2026-5969.json
new file mode 100644
index 0000000..685d57a
--- /dev/null
+++ b/data/osv/GO-2026-5969.json
@@ -0,0 +1,43 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-5969",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "GHSA-g936-7jqj-mwv8"
+  ],
+  "summary": "TSDProxy: Internal proxy auth token forwarded to backend services enables management API escalation in github.com/almeidapaulopt/tsdproxy",
+  "details": "TSDProxy: Internal proxy auth token forwarded to backend services enables management API escalation in github.com/almeidapaulopt/tsdproxy",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/almeidapaulopt/tsdproxy",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "1.4.4-0.20260603142855-434819b4421e"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/almeidapaulopt/tsdproxy/security/advisories/GHSA-g936-7jqj-mwv8"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-5969",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-5973.json b/data/osv/GO-2026-5973.json
new file mode 100644
index 0000000..ea0f43c
--- /dev/null
+++ b/data/osv/GO-2026-5973.json
@@ -0,0 +1,71 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-5973",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-54250",
+    "GHSA-jxr7-mqhw-9p98"
+  ],
+  "summary": "K3s: ZIP Archive Path Traversal Vulnerability in etcd Snapshot Decompression in github.com/k3s-io/k3s",
+  "details": "K3s: ZIP Archive Path Traversal Vulnerability in etcd Snapshot Decompression in github.com/k3s-io/k3s.\n\nNOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.\n\n(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)\n\nThe additional affected modules and versions are: github.com/k3s-io/k3s before v1.33.10, from v1.34.0-rc1 before v1.34.6, from v1.35.0-rc1 before v1.35.3.",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/k3s-io/k3s",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {
+        "custom_ranges": [
+          {
+            "type": "ECOSYSTEM",
+            "events": [
+              {
+                "introduced": "0"
+              },
+              {
+                "fixed": "1.33.10"
+              },
+              {
+                "introduced": "1.34.0-rc1"
+              },
+              {
+                "fixed": "1.34.6"
+              },
+              {
+                "introduced": "1.35.0-rc1"
+              },
+              {
+                "fixed": "1.35.3"
+              }
+            ]
+          }
+        ]
+      }
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/k3s-io/k3s/security/advisories/GHSA-jxr7-mqhw-9p98"
+    },
+    {
+      "type": "ADVISORY",
+      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54250"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-5973",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-5974.json b/data/osv/GO-2026-5974.json
new file mode 100644
index 0000000..9b8320f
--- /dev/null
+++ b/data/osv/GO-2026-5974.json
@@ -0,0 +1,44 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-5974",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-44300",
+    "GHSA-wmj8-9953-vff5"
+  ],
+  "summary": "OpenCost ServiceKey Endpoint Unauthorized Credential Overwrite/Injection in github.com/opencost/opencost",
+  "details": "OpenCost ServiceKey Endpoint Unauthorized Credential Overwrite/Injection in github.com/opencost/opencost",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/opencost/opencost",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "1.119.1"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/opencost/opencost/security/advisories/GHSA-wmj8-9953-vff5"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-5974",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-5975.json b/data/osv/GO-2026-5975.json
new file mode 100644
index 0000000..35a30a9
--- /dev/null
+++ b/data/osv/GO-2026-5975.json
@@ -0,0 +1,52 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-5975",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-50018",
+    "GHSA-42j2-w334-qxw7"
+  ],
+  "summary": "Hoverfly: Denial of Service via Goroutine Leak in Remote Post-Serve Actions in github.com/SpectoLabs/hoverfly",
+  "details": "Hoverfly: Denial of Service via Goroutine Leak in Remote Post-Serve Actions in github.com/SpectoLabs/hoverfly",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/SpectoLabs/hoverfly",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "1.12.8"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/SpectoLabs/hoverfly/security/advisories/GHSA-42j2-w334-qxw7"
+    },
+    {
+      "type": "FIX",
+      "url": "https://github.com/SpectoLabs/hoverfly/pull/1228"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/SpectoLabs/hoverfly/releases/tag/v1.12.8"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-5975",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-5976.json b/data/osv/GO-2026-5976.json
new file mode 100644
index 0000000..e40c0a9
--- /dev/null
+++ b/data/osv/GO-2026-5976.json
@@ -0,0 +1,94 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-5976",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-50141",
+    "GHSA-g7mm-9vx7-jm7h"
+  ],
+  "summary": "Woodpecker gRPC agent_id metadata can be spoofed- cross-tenant agent impersonation in go.woodpecker-ci.org/woodpecker",
+  "details": "Woodpecker gRPC agent_id metadata can be spoofed- cross-tenant agent impersonation in go.woodpecker-ci.org/woodpecker",
+  "affected": [
+    {
+      "package": {
+        "name": "go.woodpecker-ci.org/woodpecker",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    },
+    {
+      "package": {
+        "name": "go.woodpecker-ci.org/woodpecker/v2",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    },
+    {
+      "package": {
+        "name": "go.woodpecker-ci.org/woodpecker/v3",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "3.0.0"
+            },
+            {
+              "fixed": "3.14.1"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/woodpecker-ci/woodpecker/security/advisories/GHSA-g7mm-9vx7-jm7h"
+    },
+    {
+      "type": "ADVISORY",
+      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-50141"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/woodpecker-ci/woodpecker/issues/6541"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/woodpecker-ci/woodpecker/pull/6567"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/woodpecker-ci/woodpecker/pull/6569"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-5976",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-5977.json b/data/osv/GO-2026-5977.json
new file mode 100644
index 0000000..86a1ba4
--- /dev/null
+++ b/data/osv/GO-2026-5977.json
@@ -0,0 +1,52 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-5977",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-50013",
+    "GHSA-qrh4-p6v4-mrfg"
+  ],
+  "summary": "Hoverfly: Process Crash via Concurrent Map Write Race Condition in Diff Mode in github.com/SpectoLabs/hoverfly",
+  "details": "Hoverfly: Process Crash via Concurrent Map Write Race Condition in Diff Mode in github.com/SpectoLabs/hoverfly",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/SpectoLabs/hoverfly",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "1.12.8"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/SpectoLabs/hoverfly/security/advisories/GHSA-qrh4-p6v4-mrfg"
+    },
+    {
+      "type": "FIX",
+      "url": "https://github.com/SpectoLabs/hoverfly/pull/1227"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/SpectoLabs/hoverfly/releases/tag/v1.12.8"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-5977",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-5978.json b/data/osv/GO-2026-5978.json
new file mode 100644
index 0000000..66af877
--- /dev/null
+++ b/data/osv/GO-2026-5978.json
@@ -0,0 +1,44 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-5978",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-50125",
+    "GHSA-qw5r-ppcg-f8rj"
+  ],
+  "summary": "MKP: Unbounded Pod Log Read via Attacker-Controlled `limitBytes`/`tailLines` Causes Memory Exhaustion in github.com/StacklokLabs/mkp",
+  "details": "MKP: Unbounded Pod Log Read via Attacker-Controlled `limitBytes`/`tailLines` Causes Memory Exhaustion in github.com/StacklokLabs/mkp",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/StacklokLabs/mkp",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "0.4.1"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/StacklokLabs/mkp/security/advisories/GHSA-qw5r-ppcg-f8rj"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-5978",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-5979.json b/data/osv/GO-2026-5979.json
new file mode 100644
index 0000000..591d1fd
--- /dev/null
+++ b/data/osv/GO-2026-5979.json
@@ -0,0 +1,45 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-5979",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-50006",
+    "GHSA-xrcf-6jh3-ggvx"
+  ],
+  "summary": "Anyquery: Arbitrary File Write (AFW) which could lead to Remote Code Execution (RCE) via Unrestricted ATTACH DATABASE in Server Mode in github.com/julien040/anyquery",
+  "details": "Anyquery: Arbitrary File Write (AFW) which could lead to Remote Code Execution (RCE) via Unrestricted ATTACH DATABASE in Server Mode in github.com/julien040/anyquery",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/julien040/anyquery",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/julien040/anyquery/security/advisories/GHSA-xrcf-6jh3-ggvx"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/julien040/anyquery/releases/tag/0.4.5"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-5979",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-5980.json b/data/osv/GO-2026-5980.json
new file mode 100644
index 0000000..2116433
--- /dev/null
+++ b/data/osv/GO-2026-5980.json
@@ -0,0 +1,52 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-5980",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-50158",
+    "GHSA-2c7f-fxww-6w6c"
+  ],
+  "summary": "yutu: Arbitrary File Write via MCP `caption-download` Tool in github.com/eat-pray-ai/yutu",
+  "details": "yutu: Arbitrary File Write via MCP `caption-download` Tool in github.com/eat-pray-ai/yutu",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/eat-pray-ai/yutu",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "0.10.9-dev1"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/eat-pray-ai/yutu/security/advisories/GHSA-2c7f-fxww-6w6c"
+    },
+    {
+      "type": "FIX",
+      "url": "https://github.com/eat-pray-ai/yutu/commit/87026c4eee1ed28775383807087343a750707bf3"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/eat-pray-ai/yutu/releases/tag/v0.10.9-dev1"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-5980",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-5981.json b/data/osv/GO-2026-5981.json
new file mode 100644
index 0000000..d225374
--- /dev/null
+++ b/data/osv/GO-2026-5981.json
@@ -0,0 +1,40 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-5981",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "GHSA-mqxv-9rm6-w8qc"
+  ],
+  "summary": "Ech0: ParseAcceptLanguage `_` separator bypass enables ~70x CPU amplification via Accept-Language header in i18n.Middleware in github.com/lin-snow/ech0",
+  "details": "Ech0: ParseAcceptLanguage `_` separator bypass enables ~70x CPU amplification via Accept-Language header in i18n.Middleware in github.com/lin-snow/ech0",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/lin-snow/ech0",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/lin-snow/Ech0/security/advisories/GHSA-mqxv-9rm6-w8qc"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-5981",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-5982.json b/data/osv/GO-2026-5982.json
new file mode 100644
index 0000000..3c7056d
--- /dev/null
+++ b/data/osv/GO-2026-5982.json
@@ -0,0 +1,44 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-5982",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "GHSA-pqg7-v6wh-3pfp"
+  ],
+  "summary": "TsDProxy: X-Forwarded-For header injection allows IP spoofing in proxied requests to backend services in github.com/almeidapaulopt/tsdproxy",
+  "details": "TsDProxy: X-Forwarded-For header injection allows IP spoofing in proxied requests to backend services in github.com/almeidapaulopt/tsdproxy",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/almeidapaulopt/tsdproxy",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/almeidapaulopt/tsdproxy/security/advisories/GHSA-pqg7-v6wh-3pfp"
+    },
+    {
+      "type": "FIX",
+      "url": "https://github.com/almeidapaulopt/tsdproxy/commit/e8200b7947719e5e7fbbbdb9c34f459a4c285e77"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-5982",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-5984.json b/data/osv/GO-2026-5984.json
new file mode 100644
index 0000000..736dda9
--- /dev/null
+++ b/data/osv/GO-2026-5984.json
@@ -0,0 +1,52 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-5984",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-53604",
+    "GHSA-2p2f-px33-4vv5"
+  ],
+  "summary": "nebula-mesh: CA private key not zeroized on web mobile-bundle error paths in github.com/forgekeep/nebula-mesh",
+  "details": "nebula-mesh: CA private key not zeroized on web mobile-bundle error paths in github.com/forgekeep/nebula-mesh",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/forgekeep/nebula-mesh",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "0.3.8"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/forgekeep/nebula-mesh/security/advisories/GHSA-2p2f-px33-4vv5"
+    },
+    {
+      "type": "FIX",
+      "url": "https://github.com/forgekeep/nebula-mesh/commit/1f1ab9aa8472239763d967e3d50a3cd53a1a79b9"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/forgekeep/nebula-mesh/releases/tag/v0.3.8"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-5984",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-5985.json b/data/osv/GO-2026-5985.json
new file mode 100644
index 0000000..2b1f398
--- /dev/null
+++ b/data/osv/GO-2026-5985.json
@@ -0,0 +1,51 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-5985",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "GHSA-7rx3-5wx3-5v76"
+  ],
+  "summary": "Nebula-mesh allows non-admin operators to disable webhook SSRF protection via `allow_private` in github.com/forgekeep/nebula-mesh",
+  "details": "Nebula-mesh allows non-admin operators to disable webhook SSRF protection via `allow_private` in github.com/forgekeep/nebula-mesh",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/forgekeep/nebula-mesh",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0.6.0"
+            },
+            {
+              "fixed": "0.7.2"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/forgekeep/nebula-mesh/security/advisories/GHSA-7rx3-5wx3-5v76"
+    },
+    {
+      "type": "FIX",
+      "url": "https://github.com/forgekeep/nebula-mesh/commit/f3c54530e388dd21763e548923426e60a8e93ff0"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/forgekeep/nebula-mesh/releases/tag/v0.7.2"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-5985",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-5986.json b/data/osv/GO-2026-5986.json
new file mode 100644
index 0000000..06c3463
--- /dev/null
+++ b/data/osv/GO-2026-5986.json
@@ -0,0 +1,52 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-5986",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-61699",
+    "GHSA-cm26-5974-52h8"
+  ],
+  "summary": "nebula-mesh: Certificate revocation is never enforced at the mesh in github.com/forgekeep/nebula-mesh",
+  "details": "nebula-mesh: Certificate revocation is never enforced at the mesh in github.com/forgekeep/nebula-mesh",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/forgekeep/nebula-mesh",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "0.7.1"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/forgekeep/nebula-mesh/security/advisories/GHSA-cm26-5974-52h8"
+    },
+    {
+      "type": "FIX",
+      "url": "https://github.com/forgekeep/nebula-mesh/commit/0426e2f224a9b1e2029029bf923c93ed39d21cdb"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/forgekeep/nebula-mesh/releases/tag/v0.7.1"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-5986",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-5988.json b/data/osv/GO-2026-5988.json
new file mode 100644
index 0000000..df4a341
--- /dev/null
+++ b/data/osv/GO-2026-5988.json
@@ -0,0 +1,45 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-5988",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-54628",
+    "GHSA-hwrq-8wxh-q4xv"
+  ],
+  "summary": "Anyquery: Server-Side Request Forgery (SSRF) via Unrestricted SQLite Virtual Table Modules in Server Mode in github.com/julien040/anyquery",
+  "details": "Anyquery: Server-Side Request Forgery (SSRF) via Unrestricted SQLite Virtual Table Modules in Server Mode in github.com/julien040/anyquery",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/julien040/anyquery",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/julien040/anyquery/security/advisories/GHSA-hwrq-8wxh-q4xv"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/julien040/anyquery/releases/tag/0.4.5"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-5988",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-5990.json b/data/osv/GO-2026-5990.json
new file mode 100644
index 0000000..01710a5
--- /dev/null
+++ b/data/osv/GO-2026-5990.json
@@ -0,0 +1,45 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-5990",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-54629",
+    "GHSA-mf78-3rpf-r784"
+  ],
+  "summary": "Anyquery: Local File Read (LFR) via Unrestricted SQLite Virtual Table Modules in Server Mode in github.com/julien040/anyquery",
+  "details": "Anyquery: Local File Read (LFR) via Unrestricted SQLite Virtual Table Modules in Server Mode in github.com/julien040/anyquery",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/julien040/anyquery",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/julien040/anyquery/security/advisories/GHSA-mf78-3rpf-r784"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/julien040/anyquery/releases/tag/0.4.5"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-5990",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-5991.json b/data/osv/GO-2026-5991.json
new file mode 100644
index 0000000..b7c3982
--- /dev/null
+++ b/data/osv/GO-2026-5991.json
@@ -0,0 +1,52 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-5991",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-53603",
+    "GHSA-q4vm-pq3q-8wgq"
+  ],
+  "summary": "nebula-mesh: Operator session tokens stored in plaintext in the database in github.com/forgekeep/nebula-mesh",
+  "details": "nebula-mesh: Operator session tokens stored in plaintext in the database in github.com/forgekeep/nebula-mesh",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/forgekeep/nebula-mesh",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "0.3.8"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/forgekeep/nebula-mesh/security/advisories/GHSA-q4vm-pq3q-8wgq"
+    },
+    {
+      "type": "FIX",
+      "url": "https://github.com/forgekeep/nebula-mesh/commit/7cb01bab281ded557f8b6c81dab5f48d4c10182e"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/forgekeep/nebula-mesh/releases/tag/v0.3.8"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-5991",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-5992.json b/data/osv/GO-2026-5992.json
new file mode 100644
index 0000000..771914e
--- /dev/null
+++ b/data/osv/GO-2026-5992.json
@@ -0,0 +1,99 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-5992",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-61549",
+    "GHSA-qf34-295c-26v8"
+  ],
+  "summary": "Woodpecker: Privilege escalation via unrestricted serviceAccountName in the Kubernetes backend in github.com/woodpecker-ci/woodpecker",
+  "details": "Woodpecker: Privilege escalation via unrestricted serviceAccountName in the Kubernetes backend in github.com/woodpecker-ci/woodpecker",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/woodpecker-ci/woodpecker",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "1.0.0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    },
+    {
+      "package": {
+        "name": "go.woodpecker-ci.org/woodpecker",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    },
+    {
+      "package": {
+        "name": "go.woodpecker-ci.org/woodpecker/v2",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    },
+    {
+      "package": {
+        "name": "go.woodpecker-ci.org/woodpecker/v3",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "3.16.0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/woodpecker-ci/woodpecker/security/advisories/GHSA-qf34-295c-26v8"
+    },
+    {
+      "type": "FIX",
+      "url": "https://github.com/woodpecker-ci/woodpecker/pull/6792"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-5992",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-5996.json b/data/osv/GO-2026-5996.json
new file mode 100644
index 0000000..2bb1625
--- /dev/null
+++ b/data/osv/GO-2026-5996.json
@@ -0,0 +1,44 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-5996",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-54450",
+    "GHSA-pph6-vfjv-vpjw"
+  ],
+  "summary": "ToolHive: SSRF guard misses IPv6 NAT64 ranges (64:ff9b::/96, 64:ff9b:1::/48), allowing metadata/internal access behind a NAT64 gateway in github.com/stacklok/toolhive",
+  "details": "ToolHive: SSRF guard misses IPv6 NAT64 ranges (64:ff9b::/96, 64:ff9b:1::/48), allowing metadata/internal access behind a NAT64 gateway in github.com/stacklok/toolhive",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/stacklok/toolhive",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "0.29.1"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/stacklok/toolhive/security/advisories/GHSA-pph6-vfjv-vpjw"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-5996",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-5997.json b/data/osv/GO-2026-5997.json
new file mode 100644
index 0000000..b71abc0
--- /dev/null
+++ b/data/osv/GO-2026-5997.json
@@ -0,0 +1,48 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-5997",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-54452",
+    "GHSA-xgch-x3mx-cm3c"
+  ],
+  "summary": "safeurl is Missing IPv6 CIDR Ranges in Blocklist in github.com/doyensec/safeurl",
+  "details": "safeurl is Missing IPv6 CIDR Ranges in Blocklist in github.com/doyensec/safeurl",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/doyensec/safeurl",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "0.2.4"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/doyensec/safeurl/security/advisories/GHSA-xgch-x3mx-cm3c"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/doyensec/safeurl/releases/tag/v0.2.4"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-5997",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-5998.json b/data/osv/GO-2026-5998.json
new file mode 100644
index 0000000..4bca967
--- /dev/null
+++ b/data/osv/GO-2026-5998.json
@@ -0,0 +1,45 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-5998",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-54495",
+    "GHSA-398h-7f66-3h4p"
+  ],
+  "summary": "open-feature-operator: Cross-namespace FeatureFlagSource and InProcessConfiguration resolution exposes spec contents on multi-tenant clusters in github.com/open-feature/open-feature-operator",
+  "details": "open-feature-operator: Cross-namespace FeatureFlagSource and InProcessConfiguration resolution exposes spec contents on multi-tenant clusters in github.com/open-feature/open-feature-operator",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/open-feature/open-feature-operator",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/open-feature/open-feature-operator/security/advisories/GHSA-398h-7f66-3h4p"
+    },
+    {
+      "type": "REPORT",
+      "url": "https://github.com/open-feature/open-feature-operator/issues/847"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-5998",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-5999.json b/data/osv/GO-2026-5999.json
new file mode 100644
index 0000000..9883208
--- /dev/null
+++ b/data/osv/GO-2026-5999.json
@@ -0,0 +1,76 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-5999",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-10814",
+    "GHSA-jh6h-v6mp-h22v"
+  ],
+  "summary": "milvus: RBAC grantee-id uses truncated MD5 (64-bit), enabling privilege-binding collisions and cross-role privilege forgery in github.com/milvus-io/milvus",
+  "details": "milvus: RBAC grantee-id uses truncated MD5 (64-bit), enabling privilege-binding collisions and cross-role privilege forgery in github.com/milvus-io/milvus",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/milvus-io/milvus",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "0.10.3-0.20260602041816-3d932f1c3e06"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/advisories/GHSA-jh6h-v6mp-h22v"
+    },
+    {
+      "type": "ADVISORY",
+      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-10814"
+    },
+    {
+      "type": "FIX",
+      "url": "https://github.com/milvus-io/milvus/commit/3d932f1c3e065351c4440c27abe1e6479752544d"
+    },
+    {
+      "type": "FIX",
+      "url": "https://github.com/milvus-io/milvus/pull/50060"
+    },
+    {
+      "type": "REPORT",
+      "url": "https://github.com/milvus-io/milvus/issues/49857"
+    },
+    {
+      "type": "WEB",
+      "url": "https://vuldb.com/cve/CVE-2026-10814"
+    },
+    {
+      "type": "WEB",
+      "url": "https://vuldb.com/submit/831645"
+    },
+    {
+      "type": "WEB",
+      "url": "https://vuldb.com/vuln/368262"
+    },
+    {
+      "type": "WEB",
+      "url": "https://vuldb.com/vuln/368262/cti"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-5999",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6002.json b/data/osv/GO-2026-6002.json
new file mode 100644
index 0000000..2c4c41c
--- /dev/null
+++ b/data/osv/GO-2026-6002.json
@@ -0,0 +1,44 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6002",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-58196",
+    "GHSA-pr64-jmmf-jp54"
+  ],
+  "summary": "ToolHive: SSRF in remote MCP server authentication discovery (host-side, bypasses container isolation) in github.com/stacklok/toolhive",
+  "details": "ToolHive: SSRF in remote MCP server authentication discovery (host-side, bypasses container isolation) in github.com/stacklok/toolhive",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/stacklok/toolhive",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "0.31.0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/stacklok/toolhive/security/advisories/GHSA-pr64-jmmf-jp54"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6002",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6003.json b/data/osv/GO-2026-6003.json
new file mode 100644
index 0000000..b710694
--- /dev/null
+++ b/data/osv/GO-2026-6003.json
@@ -0,0 +1,50 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6003",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-53714",
+    "GHSA-22xc-xg2r-9j7v"
+  ],
+  "summary": "Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode in github.com/envoyproxy/gateway",
+  "details": "Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode in github.com/envoyproxy/gateway",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/envoyproxy/gateway",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "1.7.4"
+            },
+            {
+              "introduced": "1.8.0-rc.0"
+            },
+            {
+              "fixed": "1.8.1"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/envoyproxy/gateway/security/advisories/GHSA-22xc-xg2r-9j7v"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6003",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6004.json b/data/osv/GO-2026-6004.json
new file mode 100644
index 0000000..0937916
--- /dev/null
+++ b/data/osv/GO-2026-6004.json
@@ -0,0 +1,67 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6004",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-52833",
+    "GHSA-3v79-m2cg-89ww"
+  ],
+  "summary": "Nuclio: Unsanitized runtimeAttributes.repositories injected into Groovy build.gradle leads to build-time RCE in github.com/nuclio/nuclio",
+  "details": "Nuclio: Unsanitized runtimeAttributes.repositories injected into Groovy build.gradle leads to build-time RCE in github.com/nuclio/nuclio.\n\nNOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.\n\n(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)\n\nThe additional affected modules and versions are: github.com/nuclio/nuclio before v1.16.5.",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/nuclio/nuclio",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {
+        "custom_ranges": [
+          {
+            "type": "ECOSYSTEM",
+            "events": [
+              {
+                "introduced": "0"
+              },
+              {
+                "fixed": "1.16.5"
+              }
+            ]
+          }
+        ]
+      }
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/nuclio/nuclio/security/advisories/GHSA-3v79-m2cg-89ww"
+    },
+    {
+      "type": "FIX",
+      "url": "https://github.com/nuclio/nuclio/commit/4c78040c759068e927f3ed7c6507543c15d4ae56"
+    },
+    {
+      "type": "FIX",
+      "url": "https://github.com/nuclio/nuclio/pull/4149"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/nuclio/nuclio/releases/tag/1.16.5"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6004",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6005.json b/data/osv/GO-2026-6005.json
new file mode 100644
index 0000000..c684f00
--- /dev/null
+++ b/data/osv/GO-2026-6005.json
@@ -0,0 +1,50 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6005",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-53715",
+    "GHSA-8fv2-88gg-hm7q"
+  ],
+  "summary": "Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock in github.com/envoyproxy/gateway",
+  "details": "Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock in github.com/envoyproxy/gateway",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/envoyproxy/gateway",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "1.7.4"
+            },
+            {
+              "introduced": "1.8.0-rc.0"
+            },
+            {
+              "fixed": "1.8.1"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/envoyproxy/gateway/security/advisories/GHSA-8fv2-88gg-hm7q"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6005",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6006.json b/data/osv/GO-2026-6006.json
new file mode 100644
index 0000000..496d684
--- /dev/null
+++ b/data/osv/GO-2026-6006.json
@@ -0,0 +1,50 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6006",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-53716",
+    "GHSA-cxpq-8v7q-cg56"
+  ],
+  "summary": "Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit in github.com/envoyproxy/gateway",
+  "details": "Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit in github.com/envoyproxy/gateway",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/envoyproxy/gateway",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "1.7.4"
+            },
+            {
+              "introduced": "1.8.0-rc.0"
+            },
+            {
+              "fixed": "1.8.1"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/envoyproxy/gateway/security/advisories/GHSA-cxpq-8v7q-cg56"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6006",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6007.json b/data/osv/GO-2026-6007.json
new file mode 100644
index 0000000..e4dfbe1
--- /dev/null
+++ b/data/osv/GO-2026-6007.json
@@ -0,0 +1,50 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6007",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-53718",
+    "GHSA-fcrp-7gc2-93g7"
+  ],
+  "summary": "Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass in github.com/envoyproxy/gateway",
+  "details": "Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass in github.com/envoyproxy/gateway",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/envoyproxy/gateway",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "1.7.4"
+            },
+            {
+              "introduced": "1.8.0-rc.0"
+            },
+            {
+              "fixed": "1.8.1"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/envoyproxy/gateway/security/advisories/GHSA-fcrp-7gc2-93g7"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6007",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6008.json b/data/osv/GO-2026-6008.json
new file mode 100644
index 0000000..ad264b8
--- /dev/null
+++ b/data/osv/GO-2026-6008.json
@@ -0,0 +1,50 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6008",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-53717",
+    "GHSA-h7pq-86h8-rp5x"
+  ],
+  "summary": "Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header in github.com/envoyproxy/gateway",
+  "details": "Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header in github.com/envoyproxy/gateway",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/envoyproxy/gateway",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "1.7.4"
+            },
+            {
+              "introduced": "1.8.0-rc.0"
+            },
+            {
+              "fixed": "1.8.1"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/envoyproxy/gateway/security/advisories/GHSA-h7pq-86h8-rp5x"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6008",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6009.json b/data/osv/GO-2026-6009.json
new file mode 100644
index 0000000..98df17b
--- /dev/null
+++ b/data/osv/GO-2026-6009.json
@@ -0,0 +1,50 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6009",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-53719",
+    "GHSA-m2v6-2jmh-4c68"
+  ],
+  "summary": "Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization in github.com/envoyproxy/gateway",
+  "details": "Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization in github.com/envoyproxy/gateway",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/envoyproxy/gateway",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "1.7.4"
+            },
+            {
+              "introduced": "1.8.0-rc.0"
+            },
+            {
+              "fixed": "1.8.1"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/envoyproxy/gateway/security/advisories/GHSA-m2v6-2jmh-4c68"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6009",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6011.json b/data/osv/GO-2026-6011.json
new file mode 100644
index 0000000..e02df7e
--- /dev/null
+++ b/data/osv/GO-2026-6011.json
@@ -0,0 +1,50 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6011",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-53713",
+    "GHSA-wcrf-9vrr-854f"
+  ],
+  "summary": "Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure in github.com/envoyproxy/gateway",
+  "details": "Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure in github.com/envoyproxy/gateway",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/envoyproxy/gateway",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "1.7.4"
+            },
+            {
+              "introduced": "1.8.0-rc.0"
+            },
+            {
+              "fixed": "1.8.1"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/envoyproxy/gateway/security/advisories/GHSA-wcrf-9vrr-854f"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6011",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6012.json b/data/osv/GO-2026-6012.json
new file mode 100644
index 0000000..7ffb37c
--- /dev/null
+++ b/data/osv/GO-2026-6012.json
@@ -0,0 +1,67 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6012",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-52832",
+    "GHSA-wpcj-rmv4-86qg"
+  ],
+  "summary": "Nuclio: Unauthenticated path traversal in spec.handler allows arbitrary file write in Dashboard container in github.com/nuclio/nuclio",
+  "details": "Nuclio: Unauthenticated path traversal in spec.handler allows arbitrary file write in Dashboard container in github.com/nuclio/nuclio.\n\nNOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.\n\n(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)\n\nThe additional affected modules and versions are: github.com/nuclio/nuclio before v1.16.5.",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/nuclio/nuclio",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {
+        "custom_ranges": [
+          {
+            "type": "ECOSYSTEM",
+            "events": [
+              {
+                "introduced": "0"
+              },
+              {
+                "fixed": "1.16.5"
+              }
+            ]
+          }
+        ]
+      }
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/nuclio/nuclio/security/advisories/GHSA-wpcj-rmv4-86qg"
+    },
+    {
+      "type": "FIX",
+      "url": "https://github.com/nuclio/nuclio/commit/2a55d3a8bd4d49226cb4742020303f5bf2a0931d"
+    },
+    {
+      "type": "FIX",
+      "url": "https://github.com/nuclio/nuclio/pull/4143"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/nuclio/nuclio/releases/tag/1.16.5"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6012",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6014.json b/data/osv/GO-2026-6014.json
new file mode 100644
index 0000000..be54729
--- /dev/null
+++ b/data/osv/GO-2026-6014.json
@@ -0,0 +1,76 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6014",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2025-7453",
+    "GHSA-2hfh-94w5-wxvf"
+  ],
+  "summary": "ZPan Uses Hard-Coded Password in github.com/saltbo/zpan",
+  "details": "ZPan Uses Hard-Coded Password in github.com/saltbo/zpan",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/saltbo/zpan",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "1.6.6"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/advisories/GHSA-2hfh-94w5-wxvf"
+    },
+    {
+      "type": "ADVISORY",
+      "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-7453"
+    },
+    {
+      "type": "FIX",
+      "url": "https://github.com/saltbo/zpan/commit/8662db8d4b06057631faf3deba4132e66705e947"
+    },
+    {
+      "type": "FIX",
+      "url": "https://github.com/saltbo/zpan/pull/410"
+    },
+    {
+      "type": "REPORT",
+      "url": "https://github.com/saltbo/zpan/issues/219"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/saltbo/zpan/releases/tag/v1.6.6"
+    },
+    {
+      "type": "WEB",
+      "url": "https://vuldb.com/?ctiid.316097"
+    },
+    {
+      "type": "WEB",
+      "url": "https://vuldb.com/?id.316097"
+    },
+    {
+      "type": "WEB",
+      "url": "https://vuldb.com/?submit.608447"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6014",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/reports/GO-2026-5929.yaml b/data/reports/GO-2026-5929.yaml
new file mode 100644
index 0000000..2b31b2b
--- /dev/null
+++ b/data/reports/GO-2026-5929.yaml
@@ -0,0 +1,18 @@
+id: GO-2026-5929
+modules:
+    - module: github.com/QuantumNous/new-api
+      versions:
+        - fixed: 0.12.0-alpha.1
+      vulnerable_at: 0.11.9
+summary: New API is vulnerable to CSRF through user email binding in github.com/QuantumNous/new-api
+cves:
+    - CVE-2026-44342
+ghsas:
+    - GHSA-26v7-h57m-gh9m
+references:
+    - advisory: https://github.com/QuantumNous/new-api/security/advisories/GHSA-26v7-h57m-gh9m
+    - fix: https://github.com/QuantumNous/new-api/commit/e099117c61391abdf888fb75e382a582e550bd0e
+source:
+    id: GHSA-26v7-h57m-gh9m
+    created: 2026-07-17T13:20:03.81816488-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-5930.yaml b/data/reports/GO-2026-5930.yaml
new file mode 100644
index 0000000..0299000
--- /dev/null
+++ b/data/reports/GO-2026-5930.yaml
@@ -0,0 +1,18 @@
+id: GO-2026-5930
+modules:
+    - module: github.com/QuantumNous/new-api
+      versions:
+        - fixed: 0.12.0-alpha.1
+      vulnerable_at: 0.11.9
+summary: 'New API: SSRF Protection Bypass via Unresolved Hostname in Notification URLs in github.com/QuantumNous/new-api'
+cves:
+    - CVE-2026-33655
+ghsas:
+    - GHSA-6qcr-qxgr-m7fv
+references:
+    - advisory: https://github.com/QuantumNous/new-api/security/advisories/GHSA-6qcr-qxgr-m7fv
+    - fix: https://github.com/QuantumNous/new-api/commit/20399d3c8fcb4e3649d53163eb11940fd6763743
+source:
+    id: GHSA-6qcr-qxgr-m7fv
+    created: 2026-07-17T13:19:58.005020144-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-5933.yaml b/data/reports/GO-2026-5933.yaml
new file mode 100644
index 0000000..81bd184
--- /dev/null
+++ b/data/reports/GO-2026-5933.yaml
@@ -0,0 +1,15 @@
+id: GO-2026-5933
+modules:
+    - module: github.com/tinfoil-factory/netfoil
+      versions:
+        - fixed: 0.3.0
+      vulnerable_at: 0.2.1
+summary: netfoil has a resource leak in LRU cache in github.com/tinfoil-factory/netfoil
+ghsas:
+    - GHSA-3g4q-2f67-2gvh
+references:
+    - advisory: https://github.com/tinfoil-factory/netfoil/security/advisories/GHSA-3g4q-2f67-2gvh
+source:
+    id: GHSA-3g4q-2f67-2gvh
+    created: 2026-07-17T13:19:55.218369739-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-5934.yaml b/data/reports/GO-2026-5934.yaml
new file mode 100644
index 0000000..eff5647
--- /dev/null
+++ b/data/reports/GO-2026-5934.yaml
@@ -0,0 +1,15 @@
+id: GO-2026-5934
+modules:
+    - module: github.com/tinfoil-factory/netfoil
+      versions:
+        - fixed: 0.3.0
+      vulnerable_at: 0.2.1
+summary: netfoil has a domain name filter bypass via multiple questions in github.com/tinfoil-factory/netfoil
+ghsas:
+    - GHSA-59qp-cfj3-rp64
+references:
+    - advisory: https://github.com/tinfoil-factory/netfoil/security/advisories/GHSA-59qp-cfj3-rp64
+source:
+    id: GHSA-59qp-cfj3-rp64
+    created: 2026-07-17T13:19:54.278594333-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-5935.yaml b/data/reports/GO-2026-5935.yaml
new file mode 100644
index 0000000..6035004
--- /dev/null
+++ b/data/reports/GO-2026-5935.yaml
@@ -0,0 +1,15 @@
+id: GO-2026-5935
+modules:
+    - module: github.com/tinfoil-factory/netfoil
+      versions:
+        - fixed: 0.3.0
+      vulnerable_at: 0.2.1
+summary: 'netfoil: Attacker controlled data written to logs in github.com/tinfoil-factory/netfoil'
+ghsas:
+    - GHSA-7856-g3gv-9wq8
+references:
+    - advisory: https://github.com/tinfoil-factory/netfoil/security/advisories/GHSA-7856-g3gv-9wq8
+source:
+    id: GHSA-7856-g3gv-9wq8
+    created: 2026-07-17T13:19:53.289445864-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-5936.yaml b/data/reports/GO-2026-5936.yaml
new file mode 100644
index 0000000..ae2f9c4
--- /dev/null
+++ b/data/reports/GO-2026-5936.yaml
@@ -0,0 +1,19 @@
+id: GO-2026-5936
+modules:
+    - module: github.com/zhenorzz/goploy
+      unsupported_versions:
+        - last_affected: 1.17.5
+      vulnerable_at: 1.17.5
+summary: |-
+    Goploy: Cross-namespace IDOR and RCE via body-supplied row id in project and
+    project_file handlers in github.com/zhenorzz/goploy
+cves:
+    - CVE-2026-53552
+ghsas:
+    - GHSA-26rh-24rg-j3vv
+references:
+    - advisory: https://github.com/zhenorzz/goploy/security/advisories/GHSA-26rh-24rg-j3vv
+source:
+    id: GHSA-26rh-24rg-j3vv
+    created: 2026-07-17T13:19:49.871027759-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-5937.yaml b/data/reports/GO-2026-5937.yaml
new file mode 100644
index 0000000..6296092
--- /dev/null
+++ b/data/reports/GO-2026-5937.yaml
@@ -0,0 +1,23 @@
+id: GO-2026-5937
+modules:
+    - module: github.com/oasdiff/oasdiff
+      versions:
+        - introduced: 1.13.2
+        - fixed: 1.18.1
+      vulnerable_at: 1.18.0
+summary: |-
+    oasdiff does not enforce --allow-external-refs=false on the git-revision load
+    path (SSRF / local file read) in github.com/oasdiff/oasdiff
+cves:
+    - CVE-2026-53508
+ghsas:
+    - GHSA-2jcc-mxv7-p3f9
+references:
+    - advisory: https://github.com/oasdiff/oasdiff/security/advisories/GHSA-2jcc-mxv7-p3f9
+    - fix: https://github.com/oasdiff/oasdiff/pull/832
+    - fix: https://github.com/oasdiff/oasdiff/pull/974
+    - fix: https://github.com/oasdiff/oasdiff/pull/975
+source:
+    id: GHSA-2jcc-mxv7-p3f9
+    created: 2026-07-17T13:19:43.274448277-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-5938.yaml b/data/reports/GO-2026-5938.yaml
new file mode 100644
index 0000000..f48dc33
--- /dev/null
+++ b/data/reports/GO-2026-5938.yaml
@@ -0,0 +1,19 @@
+id: GO-2026-5938
+modules:
+    - module: github.com/zhenorzz/goploy
+      unsupported_versions:
+        - last_affected: 1.17.5
+      vulnerable_at: 1.17.5
+summary: |-
+    Goploy: Arbitrary File Read via Path Traversal in /deploy/fileDiff allows Remote
+    Server Compromise in github.com/zhenorzz/goploy
+cves:
+    - CVE-2026-53553
+ghsas:
+    - GHSA-4g5x-hcwm-82jw
+references:
+    - advisory: https://github.com/zhenorzz/goploy/security/advisories/GHSA-4g5x-hcwm-82jw
+source:
+    id: GHSA-4g5x-hcwm-82jw
+    created: 2026-07-17T13:19:38.285073747-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-5939.yaml b/data/reports/GO-2026-5939.yaml
new file mode 100644
index 0000000..195b4fc
--- /dev/null
+++ b/data/reports/GO-2026-5939.yaml
@@ -0,0 +1,22 @@
+id: GO-2026-5939
+modules:
+    - module: github.com/quay/claircore
+      unsupported_versions:
+        - last_affected: 1.5.52
+      vulnerable_at: 1.5.52
+summary: |-
+    Claircore: Unauthenticated attackers can submit manifests with URIs pointing to
+    internal services or cloud metadata endpoints in github.com/quay/claircore
+cves:
+    - CVE-2026-10517
+ghsas:
+    - GHSA-698x-9w2p-7vvp
+references:
+    - advisory: https://github.com/advisories/GHSA-698x-9w2p-7vvp
+    - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-10517
+    - web: https://access.redhat.com/security/cve/CVE-2026-10517
+    - web: https://bugzilla.redhat.com/show_bug.cgi?id=2486779
+source:
+    id: GHSA-698x-9w2p-7vvp
+    created: 2026-07-17T13:19:30.26227296-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-5940.yaml b/data/reports/GO-2026-5940.yaml
new file mode 100644
index 0000000..68f4d54
--- /dev/null
+++ b/data/reports/GO-2026-5940.yaml
@@ -0,0 +1,21 @@
+id: GO-2026-5940
+modules:
+    - module: github.com/kedacore/keda
+      vulnerable_at: 1.5.0
+    - module: github.com/kedacore/keda/v2
+      versions:
+        - fixed: 2.20.0
+      vulnerable_at: 2.19.0
+summary: |-
+    KEDA has PostgreSQL connection string parameter injection via incomplete
+    whitespace escaping in github.com/kedacore/keda
+cves:
+    - CVE-2026-53572
+ghsas:
+    - GHSA-6w3m-4hhp-775q
+references:
+    - advisory: https://github.com/kedacore/keda/security/advisories/GHSA-6w3m-4hhp-775q
+source:
+    id: GHSA-6w3m-4hhp-775q
+    created: 2026-07-17T13:19:25.223878839-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-5941.yaml b/data/reports/GO-2026-5941.yaml
new file mode 100644
index 0000000..9ee45a5
--- /dev/null
+++ b/data/reports/GO-2026-5941.yaml
@@ -0,0 +1,17 @@
+id: GO-2026-5941
+modules:
+    - module: github.com/zxh326/kite
+      versions:
+        - fixed: 0.12.3
+      vulnerable_at: 0.12.2
+summary: Kite has an authenticated cluster RBAC bypass in /api/v1/overview in github.com/zxh326/kite
+cves:
+    - CVE-2026-53487
+ghsas:
+    - GHSA-gvhc-wv3v-7pf8
+references:
+    - advisory: https://github.com/kite-org/kite/security/advisories/GHSA-gvhc-wv3v-7pf8
+source:
+    id: GHSA-gvhc-wv3v-7pf8
+    created: 2026-07-17T13:19:20.062176876-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-5944.yaml b/data/reports/GO-2026-5944.yaml
new file mode 100644
index 0000000..0b5e1cb
--- /dev/null
+++ b/data/reports/GO-2026-5944.yaml
@@ -0,0 +1,19 @@
+id: GO-2026-5944
+modules:
+    - module: github.com/zalando/skipper
+      versions:
+        - fixed: 0.26.10
+      vulnerable_at: 0.26.9
+summary: |-
+    Skipper: opaAuthorizeRequestWithBody filter bypasses OPA policy on
+    Transfer-Encoding — chunked / HTTP/2 requests in github.com/zalando/skipper
+cves:
+    - CVE-2026-50197
+ghsas:
+    - GHSA-659f-rgp5-w4wf
+references:
+    - advisory: https://github.com/zalando/skipper/security/advisories/GHSA-659f-rgp5-w4wf
+source:
+    id: GHSA-659f-rgp5-w4wf
+    created: 2026-07-17T13:19:14.146583731-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-5945.yaml b/data/reports/GO-2026-5945.yaml
new file mode 100644
index 0000000..55186d9
--- /dev/null
+++ b/data/reports/GO-2026-5945.yaml
@@ -0,0 +1,22 @@
+id: GO-2026-5945
+modules:
+    - module: github.com/casdoor/casdoor
+      unsupported_versions:
+        - last_affected: 1.1000.0
+      vulnerable_at: 1.1000.0
+summary: |-
+    Casdoor: Arbitrary file write possible through Local File System storage
+    provider in github.com/casdoor/casdoor
+cves:
+    - CVE-2026-6815
+ghsas:
+    - GHSA-rmxx-v9rj-vpvg
+references:
+    - advisory: https://github.com/advisories/GHSA-rmxx-v9rj-vpvg
+    - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-6815
+    - web: https://kb.cert.org/vuls/id/937808
+    - web: https://www.kb.cert.org/vuls/id/937808
+source:
+    id: GHSA-rmxx-v9rj-vpvg
+    created: 2026-07-17T13:19:08.321606685-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-5946.yaml b/data/reports/GO-2026-5946.yaml
new file mode 100644
index 0000000..0d5c1c9
--- /dev/null
+++ b/data/reports/GO-2026-5946.yaml
@@ -0,0 +1,22 @@
+id: GO-2026-5946
+modules:
+    - module: github.com/nuclio/nuclio
+      versions:
+        - fixed: 0.0.0-20260601075854-3356b86a8bfa
+summary: |-
+    Nuclio: Unsanitized cron trigger event headers/body injected into CronJob shell
+    command leads to persistent RCE in github.com/nuclio/nuclio
+cves:
+    - CVE-2026-52831
+ghsas:
+    - GHSA-v5px-423j-pf7p
+references:
+    - advisory: https://github.com/nuclio/nuclio/security/advisories/GHSA-v5px-423j-pf7p
+    - fix: https://github.com/nuclio/nuclio/commit/3356b86a8bfab3f960aa420310ebff765df9dede
+    - web: https://github.com/nuclio/nuclio/releases/tag/1.16.4
+notes:
+    - fix: 'github.com/nuclio/nuclio: could not add vulnerable_at: cannot auto-guess when fixed version is 0.0.0 pseudo-version'
+source:
+    id: GHSA-v5px-423j-pf7p
+    created: 2026-07-17T13:19:02.028093346-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-5947.yaml b/data/reports/GO-2026-5947.yaml
new file mode 100644
index 0000000..5e0f9bd
--- /dev/null
+++ b/data/reports/GO-2026-5947.yaml
@@ -0,0 +1,18 @@
+id: GO-2026-5947
+modules:
+    - module: github.com/BishopFox/joro
+      versions:
+        - fixed: 0.0.0-20260601151442-5c0ca35db828
+summary: 'Joro: Unauthenticated Cross-Origin Plugin Upload Leads to RCE in github.com/BishopFox/joro'
+cves:
+    - CVE-2026-53649
+ghsas:
+    - GHSA-xqhv-chqm-fhcc
+references:
+    - advisory: https://github.com/BishopFox/joro/security/advisories/GHSA-xqhv-chqm-fhcc
+notes:
+    - fix: 'github.com/BishopFox/joro: could not add vulnerable_at: cannot auto-guess when fixed version is 0.0.0 pseudo-version'
+source:
+    id: GHSA-xqhv-chqm-fhcc
+    created: 2026-07-17T13:18:57.173405632-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-5948.yaml b/data/reports/GO-2026-5948.yaml
new file mode 100644
index 0000000..c2440c1
--- /dev/null
+++ b/data/reports/GO-2026-5948.yaml
@@ -0,0 +1,21 @@
+id: GO-2026-5948
+modules:
+    - module: github.com/enchant97/note-mark/backend
+      versions:
+        - fixed: 0.0.0-20260601210758-9c9b72740f22
+summary: |-
+    Note Mark: Unauthenticated disclosure of soft-deleted note metadata via
+    deleted=true on public books in github.com/enchant97/note-mark/backend
+cves:
+    - CVE-2026-50554
+ghsas:
+    - GHSA-588f-fvcv-xhvf
+references:
+    - advisory: https://github.com/enchant97/note-mark/security/advisories/GHSA-588f-fvcv-xhvf
+    - web: https://github.com/enchant97/note-mark/commit/9c9b72740f22a06131a8f64b53bb08e3b05b81a6
+notes:
+    - fix: 'github.com/enchant97/note-mark/backend: could not add vulnerable_at: cannot auto-guess when fixed version is 0.0.0 pseudo-version'
+source:
+    id: GHSA-588f-fvcv-xhvf
+    created: 2026-07-17T13:18:50.882177844-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-5949.yaml b/data/reports/GO-2026-5949.yaml
new file mode 100644
index 0000000..344253b
--- /dev/null
+++ b/data/reports/GO-2026-5949.yaml
@@ -0,0 +1,21 @@
+id: GO-2026-5949
+modules:
+    - module: github.com/enchant97/note-mark/backend
+      versions:
+        - fixed: 0.0.0-20260601210719-67b7de04308a
+summary: |-
+    Note Mark: Path traversal via unsanitized book/note slug in migrate export
+    (sibling of GHSA-g49p) in github.com/enchant97/note-mark/backend
+cves:
+    - CVE-2026-50553
+ghsas:
+    - GHSA-rqrh-8wpv-x7hh
+references:
+    - advisory: https://github.com/enchant97/note-mark/security/advisories/GHSA-rqrh-8wpv-x7hh
+    - web: https://github.com/enchant97/note-mark/commit/67b7de04308a858ef27ceff87b514067b6d667e5
+notes:
+    - fix: 'github.com/enchant97/note-mark/backend: could not add vulnerable_at: cannot auto-guess when fixed version is 0.0.0 pseudo-version'
+source:
+    id: GHSA-rqrh-8wpv-x7hh
+    created: 2026-07-17T13:18:45.219492778-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-5950.yaml b/data/reports/GO-2026-5950.yaml
new file mode 100644
index 0000000..3da1fc3
--- /dev/null
+++ b/data/reports/GO-2026-5950.yaml
@@ -0,0 +1,20 @@
+id: GO-2026-5950
+modules:
+    - module: github.com/forgekeep/nebula-mesh
+      versions:
+        - fixed: 0.3.7
+      vulnerable_at: 0.3.6
+summary: |-
+    nebula-mesh: Host revocation is not durable - blocked/offboarded hosts can
+    regain a valid certificate in github.com/forgekeep/nebula-mesh
+cves:
+    - CVE-2026-53602
+ghsas:
+    - GHSA-339v-266x-79xr
+references:
+    - advisory: https://github.com/forgekeep/nebula-mesh/security/advisories/GHSA-339v-266x-79xr
+    - report: https://github.com/forgekeep/nebula-mesh/issues/178
+source:
+    id: GHSA-339v-266x-79xr
+    created: 2026-07-17T13:18:39.819753025-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-5951.yaml b/data/reports/GO-2026-5951.yaml
new file mode 100644
index 0000000..3e00286
--- /dev/null
+++ b/data/reports/GO-2026-5951.yaml
@@ -0,0 +1,24 @@
+id: GO-2026-5951
+modules:
+    - module: github.com/nextlevelbuilder/goclaw
+      unsupported_versions:
+        - last_affected: 3.11.3
+      vulnerable_at: 1.76.1
+summary: GoClaw has a Command Injection issue in github.com/nextlevelbuilder/goclaw
+cves:
+    - CVE-2026-10219
+ghsas:
+    - GHSA-6jm8-4fhr-5w64
+references:
+    - advisory: https://github.com/advisories/GHSA-6jm8-4fhr-5w64
+    - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-10219
+    - fix: https://github.com/nextlevelbuilder/goclaw/pull/1155
+    - report: https://github.com/nextlevelbuilder/goclaw/issues/1121
+    - web: https://vuldb.com/cve/CVE-2026-10219
+    - web: https://vuldb.com/submit/821939
+    - web: https://vuldb.com/vuln/367498
+    - web: https://vuldb.com/vuln/367498/cti
+source:
+    id: GHSA-6jm8-4fhr-5w64
+    created: 2026-07-17T13:18:28.004519347-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-5952.yaml b/data/reports/GO-2026-5952.yaml
new file mode 100644
index 0000000..b943b64
--- /dev/null
+++ b/data/reports/GO-2026-5952.yaml
@@ -0,0 +1,17 @@
+id: GO-2026-5952
+modules:
+    - module: github.com/sigstore/sigstore-go
+      versions:
+        - fixed: 1.2.0
+      vulnerable_at: 1.1.4
+summary: sigstore-go has a multi-log threshold bypass via single compromised log in github.com/sigstore/sigstore-go
+cves:
+    - CVE-2026-49834
+ghsas:
+    - GHSA-9vcr-p3rj-q5q6
+references:
+    - advisory: https://github.com/sigstore/sigstore-go/security/advisories/GHSA-9vcr-p3rj-q5q6
+source:
+    id: GHSA-9vcr-p3rj-q5q6
+    created: 2026-07-17T13:18:08.700921586-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-5953.yaml b/data/reports/GO-2026-5953.yaml
new file mode 100644
index 0000000..8155fd3
--- /dev/null
+++ b/data/reports/GO-2026-5953.yaml
@@ -0,0 +1,22 @@
+id: GO-2026-5953
+modules:
+    - module: github.com/casdoor/casdoor
+      non_go_versions:
+        - fixed: 2.387.0
+      vulnerable_at: 1.1000.0
+summary: |-
+    Casdoor: GetTokenExchangeToken bypass through lack of cross-organization JWT
+    signature check in github.com/casdoor/casdoor
+cves:
+    - CVE-2026-9094
+ghsas:
+    - GHSA-c9w5-qp6m-m395
+references:
+    - advisory: https://github.com/advisories/GHSA-c9w5-qp6m-m395
+    - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-9094
+    - fix: https://github.com/casdoor/casdoor/commit/d92b8568686d
+    - web: https://kb.cert.org/vuls/id/780781
+source:
+    id: GHSA-c9w5-qp6m-m395
+    created: 2026-07-17T13:17:57.601298905-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-5956.yaml b/data/reports/GO-2026-5956.yaml
new file mode 100644
index 0000000..5ad0b47
--- /dev/null
+++ b/data/reports/GO-2026-5956.yaml
@@ -0,0 +1,21 @@
+id: GO-2026-5956
+modules:
+    - module: github.com/openrundev/openrun
+      versions:
+        - fixed: 0.17.7
+      vulnerable_at: 0.17.6
+summary: |-
+    OpenRun: Redirect URL validation bypass using  //host  paths leads to Open
+    Redirect in github.com/openrundev/openrun
+cves:
+    - CVE-2026-55252
+ghsas:
+    - GHSA-h5g6-xmh4-hc37
+references:
+    - advisory: https://github.com/openrundev/openrun/security/advisories/GHSA-h5g6-xmh4-hc37
+    - fix: https://github.com/openrundev/openrun/commit/709da784fcf1311c85f30f3542cfa3601a78bbf0
+    - web: https://github.com/openrundev/openrun/releases/tag/v0.17.7
+source:
+    id: GHSA-h5g6-xmh4-hc37
+    created: 2026-07-17T13:17:42.354227551-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-5957.yaml b/data/reports/GO-2026-5957.yaml
new file mode 100644
index 0000000..5d814e1
--- /dev/null
+++ b/data/reports/GO-2026-5957.yaml
@@ -0,0 +1,19 @@
+id: GO-2026-5957
+modules:
+    - module: github.com/siyuan-note/siyuan/kernel
+      versions:
+        - fixed: 0.0.0-20260628153353-2d5d72223df4
+summary: 'SiYuan: Stored XSS to RCE via attribute-view cell rendering in genAVValueHTML() in github.com/siyuan-note/siyuan/kernel'
+cves:
+    - CVE-2026-54158
+ghsas:
+    - GHSA-5xfx-xj4h-5p7r
+references:
+    - advisory: https://github.com/siyuan-note/siyuan/security/advisories/GHSA-5xfx-xj4h-5p7r
+    - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-54158
+notes:
+    - fix: 'github.com/siyuan-note/siyuan/kernel: could not add vulnerable_at: cannot auto-guess when fixed version is 0.0.0 pseudo-version'
+source:
+    id: GHSA-5xfx-xj4h-5p7r
+    created: 2026-07-17T13:17:36.502434723-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-5958.yaml b/data/reports/GO-2026-5958.yaml
new file mode 100644
index 0000000..a76ea1a
--- /dev/null
+++ b/data/reports/GO-2026-5958.yaml
@@ -0,0 +1,21 @@
+id: GO-2026-5958
+modules:
+    - module: github.com/siyuan-note/siyuan/kernel
+      versions:
+        - fixed: 0.0.0-20260628153353-2d5d72223df4
+summary: |-
+    SiYuan: Unauthenticated SQLite Data Exfiltration via Template Injection in
+    /api/icon/getDynamicIcon in github.com/siyuan-note/siyuan/kernel
+cves:
+    - CVE-2026-54068
+ghsas:
+    - GHSA-gcm7-57gf-953c
+references:
+    - advisory: https://github.com/siyuan-note/siyuan/security/advisories/GHSA-gcm7-57gf-953c
+    - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-54068
+notes:
+    - fix: 'github.com/siyuan-note/siyuan/kernel: could not add vulnerable_at: cannot auto-guess when fixed version is 0.0.0 pseudo-version'
+source:
+    id: GHSA-gcm7-57gf-953c
+    created: 2026-07-17T13:17:31.805897218-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-5959.yaml b/data/reports/GO-2026-5959.yaml
new file mode 100644
index 0000000..bade9d2
--- /dev/null
+++ b/data/reports/GO-2026-5959.yaml
@@ -0,0 +1,20 @@
+id: GO-2026-5959
+modules:
+    - module: github.com/authorizerdev/authorizer
+      versions:
+        - fixed: 0.0.0-20260409051328-bd3f5baf6d3d
+summary: |-
+    Authorizer: Unvalidated redirect_uri in /authorize leaks OAuth2 tokens to
+    attacker-controlled URL in github.com/authorizerdev/authorizer
+cves:
+    - CVE-2026-54072
+ghsas:
+    - GHSA-h29v-hj44-q8cv
+references:
+    - advisory: https://github.com/authorizerdev/authorizer/security/advisories/GHSA-h29v-hj44-q8cv
+notes:
+    - fix: 'github.com/authorizerdev/authorizer: could not add vulnerable_at: cannot auto-guess when fixed version is 0.0.0 pseudo-version'
+source:
+    id: GHSA-h29v-hj44-q8cv
+    created: 2026-07-17T13:17:26.988929471-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-5961.yaml b/data/reports/GO-2026-5961.yaml
new file mode 100644
index 0000000..82ab6c6
--- /dev/null
+++ b/data/reports/GO-2026-5961.yaml
@@ -0,0 +1,21 @@
+id: GO-2026-5961
+modules:
+    - module: github.com/siyuan-note/siyuan/kernel
+      versions:
+        - fixed: 0.0.0-20260628153353-2d5d72223df4
+summary: |-
+    SiYuan: Unauthenticated Admin API Access via Blanket chrome-extension:// Origin
+    Allowlist in github.com/siyuan-note/siyuan/kernel
+cves:
+    - CVE-2026-54069
+ghsas:
+    - GHSA-hvr9-72v2-fff3
+references:
+    - advisory: https://github.com/siyuan-note/siyuan/security/advisories/GHSA-hvr9-72v2-fff3
+    - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-54069
+notes:
+    - fix: 'github.com/siyuan-note/siyuan/kernel: could not add vulnerable_at: cannot auto-guess when fixed version is 0.0.0 pseudo-version'
+source:
+    id: GHSA-hvr9-72v2-fff3
+    created: 2026-07-17T13:17:16.088927976-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-5962.yaml b/data/reports/GO-2026-5962.yaml
new file mode 100644
index 0000000..48dc7ff
--- /dev/null
+++ b/data/reports/GO-2026-5962.yaml
@@ -0,0 +1,22 @@
+id: GO-2026-5962
+modules:
+    - module: github.com/filebrowser/filebrowser
+      vulnerable_at: 1.11.0
+    - module: github.com/filebrowser/filebrowser/v2
+      versions:
+        - fixed: 2.63.6
+      vulnerable_at: 2.63.5
+summary: |-
+    File Browser: Command Injection via Authentication Hook Shell Substitution
+    (Pre-Authentication RCE) in github.com/filebrowser/filebrowser
+cves:
+    - CVE-2026-54088
+ghsas:
+    - GHSA-m93h-4hw7-5qcm
+references:
+    - advisory: https://github.com/filebrowser/filebrowser/security/advisories/GHSA-m93h-4hw7-5qcm
+    - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-54088
+source:
+    id: GHSA-m93h-4hw7-5qcm
+    created: 2026-07-17T13:17:11.190450163-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-5963.yaml b/data/reports/GO-2026-5963.yaml
new file mode 100644
index 0000000..1aac277
--- /dev/null
+++ b/data/reports/GO-2026-5963.yaml
@@ -0,0 +1,19 @@
+id: GO-2026-5963
+modules:
+    - module: github.com/siyuan-note/siyuan/kernel
+      versions:
+        - fixed: 0.0.0-20260628153353-2d5d72223df4
+summary: 'SiYuan: Stored XSS to RCE via CSS-snippet <style> breakout in renderSnippet() in github.com/siyuan-note/siyuan/kernel'
+cves:
+    - CVE-2026-54067
+ghsas:
+    - GHSA-mvjr-vv3c-w4qv
+references:
+    - advisory: https://github.com/siyuan-note/siyuan/security/advisories/GHSA-mvjr-vv3c-w4qv
+    - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-54067
+notes:
+    - fix: 'github.com/siyuan-note/siyuan/kernel: could not add vulnerable_at: cannot auto-guess when fixed version is 0.0.0 pseudo-version'
+source:
+    id: GHSA-mvjr-vv3c-w4qv
+    created: 2026-07-17T13:17:06.125966306-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-5964.yaml b/data/reports/GO-2026-5964.yaml
new file mode 100644
index 0000000..d347224
--- /dev/null
+++ b/data/reports/GO-2026-5964.yaml
@@ -0,0 +1,21 @@
+id: GO-2026-5964
+modules:
+    - module: github.com/siyuan-note/siyuan/kernel
+      versions:
+        - fixed: 0.0.0-20260628153353-2d5d72223df4
+summary: |-
+    SiYuan: Path Traversal via Double URL Encoding in /assets/*path (publish mode
+    arbitrary file─read), Incomplete fix of CVE-2026-41894 in github.com/siyuan-note/siyuan/kernel
+cves:
+    - CVE-2026-54066
+ghsas:
+    - GHSA-p4m3-mgmm-c664
+references:
+    - advisory: https://github.com/siyuan-note/siyuan/security/advisories/GHSA-p4m3-mgmm-c664
+    - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-54066
+notes:
+    - fix: 'github.com/siyuan-note/siyuan/kernel: could not add vulnerable_at: cannot auto-guess when fixed version is 0.0.0 pseudo-version'
+source:
+    id: GHSA-p4m3-mgmm-c664
+    created: 2026-07-17T13:17:01.423761786-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-5965.yaml b/data/reports/GO-2026-5965.yaml
new file mode 100644
index 0000000..aa980ef
--- /dev/null
+++ b/data/reports/GO-2026-5965.yaml
@@ -0,0 +1,19 @@
+id: GO-2026-5965
+modules:
+    - module: github.com/siyuan-note/siyuan/kernel
+      versions:
+        - fixed: 0.0.0-20260628153353-2d5d72223df4
+summary: 'SiYuan: Stored XSS in Bazaar marketplace via package README event handlers in github.com/siyuan-note/siyuan/kernel'
+cves:
+    - CVE-2026-54070
+ghsas:
+    - GHSA-w7cg-whh7-xp28
+references:
+    - advisory: https://github.com/siyuan-note/siyuan/security/advisories/GHSA-w7cg-whh7-xp28
+    - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-54070
+notes:
+    - fix: 'github.com/siyuan-note/siyuan/kernel: could not add vulnerable_at: cannot auto-guess when fixed version is 0.0.0 pseudo-version'
+source:
+    id: GHSA-w7cg-whh7-xp28
+    created: 2026-07-17T13:16:56.853723037-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-5966.yaml b/data/reports/GO-2026-5966.yaml
new file mode 100644
index 0000000..ae72642
--- /dev/null
+++ b/data/reports/GO-2026-5966.yaml
@@ -0,0 +1,22 @@
+id: GO-2026-5966
+modules:
+    - module: github.com/filebrowser/filebrowser
+      vulnerable_at: 1.11.0
+    - module: github.com/filebrowser/filebrowser/v2
+      versions:
+        - introduced: 2.0.0-rc.1
+      unsupported_versions:
+        - last_affected: 2.63.18
+      vulnerable_at: 2.63.18
+summary: 'File Browser: Authentication Bypass via Proxy Auth Header Forgery in github.com/filebrowser/filebrowser'
+cves:
+    - CVE-2026-54089
+ghsas:
+    - GHSA-xqp3-jq6g-x3qm
+references:
+    - advisory: https://github.com/filebrowser/filebrowser/security/advisories/GHSA-xqp3-jq6g-x3qm
+    - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-54089
+source:
+    id: GHSA-xqp3-jq6g-x3qm
+    created: 2026-07-17T13:16:51.312554402-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-5967.yaml b/data/reports/GO-2026-5967.yaml
new file mode 100644
index 0000000..5aa2873
--- /dev/null
+++ b/data/reports/GO-2026-5967.yaml
@@ -0,0 +1,19 @@
+id: GO-2026-5967
+modules:
+    - module: github.com/siyuan-note/siyuan/kernel
+      versions:
+        - fixed: 0.0.0-20260628153353-2d5d72223df4
+summary: 'SiYuan: Stored XSS to RCE via Unsanitized Attribute View Asset Cell Content in github.com/siyuan-note/siyuan/kernel'
+cves:
+    - CVE-2026-50551
+ghsas:
+    - GHSA-56mp-4f3v-fgj2
+references:
+    - advisory: https://github.com/siyuan-note/siyuan/security/advisories/GHSA-56mp-4f3v-fgj2
+    - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-50551
+notes:
+    - fix: 'github.com/siyuan-note/siyuan/kernel: could not add vulnerable_at: cannot auto-guess when fixed version is 0.0.0 pseudo-version'
+source:
+    id: GHSA-56mp-4f3v-fgj2
+    created: 2026-07-17T13:16:46.233853889-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-5968.yaml b/data/reports/GO-2026-5968.yaml
new file mode 100644
index 0000000..7a902cb
--- /dev/null
+++ b/data/reports/GO-2026-5968.yaml
@@ -0,0 +1,23 @@
+id: GO-2026-5968
+modules:
+    - module: chainguard.dev/apko
+      versions:
+        - fixed: 1.2.9
+      vulnerable_at: 1.2.8
+    - module: chainguard.dev/melange
+      versions:
+        - fixed: 0.50.4
+      vulnerable_at: 0.50.3
+summary: |-
+    melange: Incomplete package integrity verification allows data section
+    substitution in chainguard.dev/apko
+cves:
+    - CVE-2026-54174
+ghsas:
+    - GHSA-fpg8-7664-jc5q
+references:
+    - advisory: https://github.com/chainguard-dev/melange/security/advisories/GHSA-fpg8-7664-jc5q
+source:
+    id: GHSA-fpg8-7664-jc5q
+    created: 2026-07-17T13:16:41.524961494-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-5969.yaml b/data/reports/GO-2026-5969.yaml
new file mode 100644
index 0000000..f4bfbe1
--- /dev/null
+++ b/data/reports/GO-2026-5969.yaml
@@ -0,0 +1,17 @@
+id: GO-2026-5969
+modules:
+    - module: github.com/almeidapaulopt/tsdproxy
+      versions:
+        - fixed: 1.4.4-0.20260603142855-434819b4421e
+      vulnerable_at: 1.4.3
+summary: |-
+    TSDProxy: Internal proxy auth token forwarded to backend services enables
+    management API escalation in github.com/almeidapaulopt/tsdproxy
+ghsas:
+    - GHSA-g936-7jqj-mwv8
+references:
+    - advisory: https://github.com/almeidapaulopt/tsdproxy/security/advisories/GHSA-g936-7jqj-mwv8
+source:
+    id: GHSA-g936-7jqj-mwv8
+    created: 2026-07-17T13:16:39.187749739-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-5973.yaml b/data/reports/GO-2026-5973.yaml
new file mode 100644
index 0000000..39902bd
--- /dev/null
+++ b/data/reports/GO-2026-5973.yaml
@@ -0,0 +1,22 @@
+id: GO-2026-5973
+modules:
+    - module: github.com/k3s-io/k3s
+      non_go_versions:
+        - fixed: 1.33.10
+        - introduced: 1.34.0-rc1
+        - fixed: 1.34.6
+        - introduced: 1.35.0-rc1
+        - fixed: 1.35.3
+      vulnerable_at: 1.0.1
+summary: 'K3s: ZIP Archive Path Traversal Vulnerability in etcd Snapshot Decompression in github.com/k3s-io/k3s'
+cves:
+    - CVE-2026-54250
+ghsas:
+    - GHSA-jxr7-mqhw-9p98
+references:
+    - advisory: https://github.com/k3s-io/k3s/security/advisories/GHSA-jxr7-mqhw-9p98
+    - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-54250
+source:
+    id: GHSA-jxr7-mqhw-9p98
+    created: 2026-07-17T13:16:08.825294119-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-5974.yaml b/data/reports/GO-2026-5974.yaml
new file mode 100644
index 0000000..9b27d69
--- /dev/null
+++ b/data/reports/GO-2026-5974.yaml
@@ -0,0 +1,17 @@
+id: GO-2026-5974
+modules:
+    - module: github.com/opencost/opencost
+      versions:
+        - fixed: 1.119.1
+      vulnerable_at: 1.119.0
+summary: OpenCost ServiceKey Endpoint Unauthorized Credential Overwrite/Injection in github.com/opencost/opencost
+cves:
+    - CVE-2026-44300
+ghsas:
+    - GHSA-wmj8-9953-vff5
+references:
+    - advisory: https://github.com/opencost/opencost/security/advisories/GHSA-wmj8-9953-vff5
+source:
+    id: GHSA-wmj8-9953-vff5
+    created: 2026-07-17T13:16:03.917454189-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-5975.yaml b/data/reports/GO-2026-5975.yaml
new file mode 100644
index 0000000..de459f2
--- /dev/null
+++ b/data/reports/GO-2026-5975.yaml
@@ -0,0 +1,19 @@
+id: GO-2026-5975
+modules:
+    - module: github.com/SpectoLabs/hoverfly
+      versions:
+        - fixed: 1.12.8
+      vulnerable_at: 1.12.7
+summary: 'Hoverfly: Denial of Service via Goroutine Leak in Remote Post-Serve Actions in github.com/SpectoLabs/hoverfly'
+cves:
+    - CVE-2026-50018
+ghsas:
+    - GHSA-42j2-w334-qxw7
+references:
+    - advisory: https://github.com/SpectoLabs/hoverfly/security/advisories/GHSA-42j2-w334-qxw7
+    - fix: https://github.com/SpectoLabs/hoverfly/pull/1228
+    - web: https://github.com/SpectoLabs/hoverfly/releases/tag/v1.12.8
+source:
+    id: GHSA-42j2-w334-qxw7
+    created: 2026-07-17T13:15:58.690978288-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-5976.yaml b/data/reports/GO-2026-5976.yaml
new file mode 100644
index 0000000..be86303
--- /dev/null
+++ b/data/reports/GO-2026-5976.yaml
@@ -0,0 +1,28 @@
+id: GO-2026-5976
+modules:
+    - module: go.woodpecker-ci.org/woodpecker
+      vulnerable_at: 1.0.5
+    - module: go.woodpecker-ci.org/woodpecker/v2
+      vulnerable_at: 2.8.3
+    - module: go.woodpecker-ci.org/woodpecker/v3
+      versions:
+        - introduced: 3.0.0
+        - fixed: 3.14.1
+      vulnerable_at: 3.14.0
+summary: |-
+    Woodpecker gRPC agent_id metadata can be spoofed- cross-tenant agent
+    impersonation in go.woodpecker-ci.org/woodpecker
+cves:
+    - CVE-2026-50141
+ghsas:
+    - GHSA-g7mm-9vx7-jm7h
+references:
+    - advisory: https://github.com/woodpecker-ci/woodpecker/security/advisories/GHSA-g7mm-9vx7-jm7h
+    - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-50141
+    - web: https://github.com/woodpecker-ci/woodpecker/issues/6541
+    - web: https://github.com/woodpecker-ci/woodpecker/pull/6567
+    - web: https://github.com/woodpecker-ci/woodpecker/pull/6569
+source:
+    id: GHSA-g7mm-9vx7-jm7h
+    created: 2026-07-17T13:15:51.618203702-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-5977.yaml b/data/reports/GO-2026-5977.yaml
new file mode 100644
index 0000000..f99c84c
--- /dev/null
+++ b/data/reports/GO-2026-5977.yaml
@@ -0,0 +1,19 @@
+id: GO-2026-5977
+modules:
+    - module: github.com/SpectoLabs/hoverfly
+      versions:
+        - fixed: 1.12.8
+      vulnerable_at: 1.12.7
+summary: 'Hoverfly: Process Crash via Concurrent Map Write Race Condition in Diff Mode in github.com/SpectoLabs/hoverfly'
+cves:
+    - CVE-2026-50013
+ghsas:
+    - GHSA-qrh4-p6v4-mrfg
+references:
+    - advisory: https://github.com/SpectoLabs/hoverfly/security/advisories/GHSA-qrh4-p6v4-mrfg
+    - fix: https://github.com/SpectoLabs/hoverfly/pull/1227
+    - web: https://github.com/SpectoLabs/hoverfly/releases/tag/v1.12.8
+source:
+    id: GHSA-qrh4-p6v4-mrfg
+    created: 2026-07-17T13:15:46.114723335-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-5978.yaml b/data/reports/GO-2026-5978.yaml
new file mode 100644
index 0000000..61d5ad6
--- /dev/null
+++ b/data/reports/GO-2026-5978.yaml
@@ -0,0 +1,19 @@
+id: GO-2026-5978
+modules:
+    - module: github.com/StacklokLabs/mkp
+      versions:
+        - fixed: 0.4.1
+      vulnerable_at: 0.4.0
+summary: |-
+    MKP: Unbounded Pod Log Read via Attacker-Controlled `limitBytes`/`tailLines`
+    Causes Memory Exhaustion in github.com/StacklokLabs/mkp
+cves:
+    - CVE-2026-50125
+ghsas:
+    - GHSA-qw5r-ppcg-f8rj
+references:
+    - advisory: https://github.com/StacklokLabs/mkp/security/advisories/GHSA-qw5r-ppcg-f8rj
+source:
+    id: GHSA-qw5r-ppcg-f8rj
+    created: 2026-07-17T13:15:41.561561877-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-5979.yaml b/data/reports/GO-2026-5979.yaml
new file mode 100644
index 0000000..822a8a9
--- /dev/null
+++ b/data/reports/GO-2026-5979.yaml
@@ -0,0 +1,18 @@
+id: GO-2026-5979
+modules:
+    - module: github.com/julien040/anyquery
+      vulnerable_at: 0.1.6
+summary: |-
+    Anyquery: Arbitrary File Write (AFW) which could lead to Remote Code Execution
+    (RCE) via Unrestricted ATTACH DATABASE in Server Mode in github.com/julien040/anyquery
+cves:
+    - CVE-2026-50006
+ghsas:
+    - GHSA-xrcf-6jh3-ggvx
+references:
+    - advisory: https://github.com/julien040/anyquery/security/advisories/GHSA-xrcf-6jh3-ggvx
+    - web: https://github.com/julien040/anyquery/releases/tag/0.4.5
+source:
+    id: GHSA-xrcf-6jh3-ggvx
+    created: 2026-07-17T13:15:36.616011219-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-5980.yaml b/data/reports/GO-2026-5980.yaml
new file mode 100644
index 0000000..75494fb
--- /dev/null
+++ b/data/reports/GO-2026-5980.yaml
@@ -0,0 +1,19 @@
+id: GO-2026-5980
+modules:
+    - module: github.com/eat-pray-ai/yutu
+      versions:
+        - fixed: 0.10.9-dev1
+      vulnerable_at: 0.10.8
+summary: 'yutu: Arbitrary File Write via MCP `caption-download` Tool in github.com/eat-pray-ai/yutu'
+cves:
+    - CVE-2026-50158
+ghsas:
+    - GHSA-2c7f-fxww-6w6c
+references:
+    - advisory: https://github.com/eat-pray-ai/yutu/security/advisories/GHSA-2c7f-fxww-6w6c
+    - fix: https://github.com/eat-pray-ai/yutu/commit/87026c4eee1ed28775383807087343a750707bf3
+    - web: https://github.com/eat-pray-ai/yutu/releases/tag/v0.10.9-dev1
+source:
+    id: GHSA-2c7f-fxww-6w6c
+    created: 2026-07-17T13:15:30.861260392-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-5981.yaml b/data/reports/GO-2026-5981.yaml
new file mode 100644
index 0000000..951437d
--- /dev/null
+++ b/data/reports/GO-2026-5981.yaml
@@ -0,0 +1,15 @@
+id: GO-2026-5981
+modules:
+    - module: github.com/lin-snow/ech0
+      vulnerable_at: 1.4.7
+summary: |-
+    Ech0: ParseAcceptLanguage `_` separator bypass enables ~70x CPU amplification
+    via Accept-Language header in i18n.Middleware in github.com/lin-snow/ech0
+ghsas:
+    - GHSA-mqxv-9rm6-w8qc
+references:
+    - advisory: https://github.com/lin-snow/Ech0/security/advisories/GHSA-mqxv-9rm6-w8qc
+source:
+    id: GHSA-mqxv-9rm6-w8qc
+    created: 2026-07-17T13:15:28.723814873-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-5982.yaml b/data/reports/GO-2026-5982.yaml
new file mode 100644
index 0000000..b6e30fc
--- /dev/null
+++ b/data/reports/GO-2026-5982.yaml
@@ -0,0 +1,16 @@
+id: GO-2026-5982
+modules:
+    - module: github.com/almeidapaulopt/tsdproxy
+      vulnerable_at: 1.4.7
+summary: |-
+    TsDProxy: X-Forwarded-For header injection allows IP spoofing in proxied
+    requests to backend services in github.com/almeidapaulopt/tsdproxy
+ghsas:
+    - GHSA-pqg7-v6wh-3pfp
+references:
+    - advisory: https://github.com/almeidapaulopt/tsdproxy/security/advisories/GHSA-pqg7-v6wh-3pfp
+    - fix: https://github.com/almeidapaulopt/tsdproxy/commit/e8200b7947719e5e7fbbbdb9c34f459a4c285e77
+source:
+    id: GHSA-pqg7-v6wh-3pfp
+    created: 2026-07-17T13:15:27.053143674-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-5984.yaml b/data/reports/GO-2026-5984.yaml
new file mode 100644
index 0000000..f161e7b
--- /dev/null
+++ b/data/reports/GO-2026-5984.yaml
@@ -0,0 +1,19 @@
+id: GO-2026-5984
+modules:
+    - module: github.com/forgekeep/nebula-mesh
+      versions:
+        - fixed: 0.3.8
+      vulnerable_at: 0.3.7
+summary: 'nebula-mesh: CA private key not zeroized on web mobile-bundle error paths in github.com/forgekeep/nebula-mesh'
+cves:
+    - CVE-2026-53604
+ghsas:
+    - GHSA-2p2f-px33-4vv5
+references:
+    - advisory: https://github.com/forgekeep/nebula-mesh/security/advisories/GHSA-2p2f-px33-4vv5
+    - fix: https://github.com/forgekeep/nebula-mesh/commit/1f1ab9aa8472239763d967e3d50a3cd53a1a79b9
+    - web: https://github.com/forgekeep/nebula-mesh/releases/tag/v0.3.8
+source:
+    id: GHSA-2p2f-px33-4vv5
+    created: 2026-07-17T13:14:41.433244565-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-5985.yaml b/data/reports/GO-2026-5985.yaml
new file mode 100644
index 0000000..ca6a451
--- /dev/null
+++ b/data/reports/GO-2026-5985.yaml
@@ -0,0 +1,20 @@
+id: GO-2026-5985
+modules:
+    - module: github.com/forgekeep/nebula-mesh
+      versions:
+        - introduced: 0.6.0
+        - fixed: 0.7.2
+      vulnerable_at: 0.7.1
+summary: |-
+    Nebula-mesh allows non-admin operators to disable webhook SSRF protection via
+    `allow_private` in github.com/forgekeep/nebula-mesh
+ghsas:
+    - GHSA-7rx3-5wx3-5v76
+references:
+    - advisory: https://github.com/forgekeep/nebula-mesh/security/advisories/GHSA-7rx3-5wx3-5v76
+    - fix: https://github.com/forgekeep/nebula-mesh/commit/f3c54530e388dd21763e548923426e60a8e93ff0
+    - web: https://github.com/forgekeep/nebula-mesh/releases/tag/v0.7.2
+source:
+    id: GHSA-7rx3-5wx3-5v76
+    created: 2026-07-17T13:14:38.435173061-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-5986.yaml b/data/reports/GO-2026-5986.yaml
new file mode 100644
index 0000000..838308b
--- /dev/null
+++ b/data/reports/GO-2026-5986.yaml
@@ -0,0 +1,19 @@
+id: GO-2026-5986
+modules:
+    - module: github.com/forgekeep/nebula-mesh
+      versions:
+        - fixed: 0.7.1
+      vulnerable_at: 0.7.0
+summary: 'nebula-mesh: Certificate revocation is never enforced at the mesh in github.com/forgekeep/nebula-mesh'
+cves:
+    - CVE-2026-61699
+ghsas:
+    - GHSA-cm26-5974-52h8
+references:
+    - advisory: https://github.com/forgekeep/nebula-mesh/security/advisories/GHSA-cm26-5974-52h8
+    - fix: https://github.com/forgekeep/nebula-mesh/commit/0426e2f224a9b1e2029029bf923c93ed39d21cdb
+    - web: https://github.com/forgekeep/nebula-mesh/releases/tag/v0.7.1
+source:
+    id: GHSA-cm26-5974-52h8
+    created: 2026-07-17T13:14:33.659440248-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-5988.yaml b/data/reports/GO-2026-5988.yaml
new file mode 100644
index 0000000..12a0490
--- /dev/null
+++ b/data/reports/GO-2026-5988.yaml
@@ -0,0 +1,18 @@
+id: GO-2026-5988
+modules:
+    - module: github.com/julien040/anyquery
+      vulnerable_at: 0.1.6
+summary: |-
+    Anyquery: Server-Side Request Forgery (SSRF) via Unrestricted SQLite Virtual
+    Table Modules in Server Mode in github.com/julien040/anyquery
+cves:
+    - CVE-2026-54628
+ghsas:
+    - GHSA-hwrq-8wxh-q4xv
+references:
+    - advisory: https://github.com/julien040/anyquery/security/advisories/GHSA-hwrq-8wxh-q4xv
+    - web: https://github.com/julien040/anyquery/releases/tag/0.4.5
+source:
+    id: GHSA-hwrq-8wxh-q4xv
+    created: 2026-07-17T13:14:23.478386682-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-5990.yaml b/data/reports/GO-2026-5990.yaml
new file mode 100644
index 0000000..0b40d3f
--- /dev/null
+++ b/data/reports/GO-2026-5990.yaml
@@ -0,0 +1,18 @@
+id: GO-2026-5990
+modules:
+    - module: github.com/julien040/anyquery
+      vulnerable_at: 0.1.6
+summary: |-
+    Anyquery: Local File Read (LFR) via Unrestricted SQLite Virtual Table Modules in
+    Server Mode in github.com/julien040/anyquery
+cves:
+    - CVE-2026-54629
+ghsas:
+    - GHSA-mf78-3rpf-r784
+references:
+    - advisory: https://github.com/julien040/anyquery/security/advisories/GHSA-mf78-3rpf-r784
+    - web: https://github.com/julien040/anyquery/releases/tag/0.4.5
+source:
+    id: GHSA-mf78-3rpf-r784
+    created: 2026-07-17T13:14:12.420326578-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-5991.yaml b/data/reports/GO-2026-5991.yaml
new file mode 100644
index 0000000..877cdff
--- /dev/null
+++ b/data/reports/GO-2026-5991.yaml
@@ -0,0 +1,19 @@
+id: GO-2026-5991
+modules:
+    - module: github.com/forgekeep/nebula-mesh
+      versions:
+        - fixed: 0.3.8
+      vulnerable_at: 0.3.7
+summary: 'nebula-mesh: Operator session tokens stored in plaintext in the database in github.com/forgekeep/nebula-mesh'
+cves:
+    - CVE-2026-53603
+ghsas:
+    - GHSA-q4vm-pq3q-8wgq
+references:
+    - advisory: https://github.com/forgekeep/nebula-mesh/security/advisories/GHSA-q4vm-pq3q-8wgq
+    - fix: https://github.com/forgekeep/nebula-mesh/commit/7cb01bab281ded557f8b6c81dab5f48d4c10182e
+    - web: https://github.com/forgekeep/nebula-mesh/releases/tag/v0.3.8
+source:
+    id: GHSA-q4vm-pq3q-8wgq
+    created: 2026-07-17T13:14:06.538356163-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-5992.yaml b/data/reports/GO-2026-5992.yaml
new file mode 100644
index 0000000..fdeb8f0
--- /dev/null
+++ b/data/reports/GO-2026-5992.yaml
@@ -0,0 +1,32 @@
+id: GO-2026-5992
+modules:
+    - module: github.com/woodpecker-ci/woodpecker
+      versions:
+        - introduced: 1.0.0
+      unsupported_versions:
+        - last_affected: 1.0.4
+      vulnerable_at: 1.0.5
+    - module: go.woodpecker-ci.org/woodpecker
+      vulnerable_at: 1.0.5
+    - module: go.woodpecker-ci.org/woodpecker/v2
+      unsupported_versions:
+        - last_affected: 2.8.3
+      vulnerable_at: 2.8.3
+    - module: go.woodpecker-ci.org/woodpecker/v3
+      versions:
+        - fixed: 3.16.0
+      vulnerable_at: 3.15.0
+summary: |-
+    Woodpecker: Privilege escalation via unrestricted serviceAccountName in the
+    Kubernetes backend in github.com/woodpecker-ci/woodpecker
+cves:
+    - CVE-2026-61549
+ghsas:
+    - GHSA-qf34-295c-26v8
+references:
+    - advisory: https://github.com/woodpecker-ci/woodpecker/security/advisories/GHSA-qf34-295c-26v8
+    - fix: https://github.com/woodpecker-ci/woodpecker/pull/6792
+source:
+    id: GHSA-qf34-295c-26v8
+    created: 2026-07-17T13:14:00.917758217-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-5996.yaml b/data/reports/GO-2026-5996.yaml
new file mode 100644
index 0000000..c28343e
--- /dev/null
+++ b/data/reports/GO-2026-5996.yaml
@@ -0,0 +1,19 @@
+id: GO-2026-5996
+modules:
+    - module: github.com/stacklok/toolhive
+      versions:
+        - fixed: 0.29.1
+      vulnerable_at: 0.29.0
+summary: |-
+    ToolHive: SSRF guard misses IPv6 NAT64 ranges (64:ff9b::/96, 64:ff9b:1::/48),
+    allowing metadata/internal access behind a NAT64 gateway in github.com/stacklok/toolhive
+cves:
+    - CVE-2026-54450
+ghsas:
+    - GHSA-pph6-vfjv-vpjw
+references:
+    - advisory: https://github.com/stacklok/toolhive/security/advisories/GHSA-pph6-vfjv-vpjw
+source:
+    id: GHSA-pph6-vfjv-vpjw
+    created: 2026-07-17T13:13:56.016755013-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-5997.yaml b/data/reports/GO-2026-5997.yaml
new file mode 100644
index 0000000..41ab289
--- /dev/null
+++ b/data/reports/GO-2026-5997.yaml
@@ -0,0 +1,18 @@
+id: GO-2026-5997
+modules:
+    - module: github.com/doyensec/safeurl
+      versions:
+        - fixed: 0.2.4
+      vulnerable_at: 0.2.3
+summary: safeurl is Missing IPv6 CIDR Ranges in Blocklist in github.com/doyensec/safeurl
+cves:
+    - CVE-2026-54452
+ghsas:
+    - GHSA-xgch-x3mx-cm3c
+references:
+    - advisory: https://github.com/doyensec/safeurl/security/advisories/GHSA-xgch-x3mx-cm3c
+    - web: https://github.com/doyensec/safeurl/releases/tag/v0.2.4
+source:
+    id: GHSA-xgch-x3mx-cm3c
+    created: 2026-07-17T13:13:50.874663558-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-5998.yaml b/data/reports/GO-2026-5998.yaml
new file mode 100644
index 0000000..5d33eeb
--- /dev/null
+++ b/data/reports/GO-2026-5998.yaml
@@ -0,0 +1,20 @@
+id: GO-2026-5998
+modules:
+    - module: github.com/open-feature/open-feature-operator
+      unsupported_versions:
+        - last_affected: 0.9.2
+      vulnerable_at: 0.9.2
+summary: |-
+    open-feature-operator: Cross-namespace FeatureFlagSource and
+    InProcessConfiguration resolution exposes spec contents on multi-tenant clusters in github.com/open-feature/open-feature-operator
+cves:
+    - CVE-2026-54495
+ghsas:
+    - GHSA-398h-7f66-3h4p
+references:
+    - advisory: https://github.com/open-feature/open-feature-operator/security/advisories/GHSA-398h-7f66-3h4p
+    - report: https://github.com/open-feature/open-feature-operator/issues/847
+source:
+    id: GHSA-398h-7f66-3h4p
+    created: 2026-07-17T13:13:45.606780633-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-5999.yaml b/data/reports/GO-2026-5999.yaml
new file mode 100644
index 0000000..f325890
--- /dev/null
+++ b/data/reports/GO-2026-5999.yaml
@@ -0,0 +1,27 @@
+id: GO-2026-5999
+modules:
+    - module: github.com/milvus-io/milvus
+      versions:
+        - fixed: 0.10.3-0.20260602041816-3d932f1c3e06
+      vulnerable_at: 0.10.2
+summary: |-
+    milvus: RBAC grantee-id uses truncated MD5 (64-bit), enabling privilege-binding
+    collisions and cross-role privilege forgery in github.com/milvus-io/milvus
+cves:
+    - CVE-2026-10814
+ghsas:
+    - GHSA-jh6h-v6mp-h22v
+references:
+    - advisory: https://github.com/advisories/GHSA-jh6h-v6mp-h22v
+    - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-10814
+    - fix: https://github.com/milvus-io/milvus/commit/3d932f1c3e065351c4440c27abe1e6479752544d
+    - fix: https://github.com/milvus-io/milvus/pull/50060
+    - report: https://github.com/milvus-io/milvus/issues/49857
+    - web: https://vuldb.com/cve/CVE-2026-10814
+    - web: https://vuldb.com/submit/831645
+    - web: https://vuldb.com/vuln/368262
+    - web: https://vuldb.com/vuln/368262/cti
+source:
+    id: GHSA-jh6h-v6mp-h22v
+    created: 2026-07-17T13:13:38.813671366-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6002.yaml b/data/reports/GO-2026-6002.yaml
new file mode 100644
index 0000000..606508c
--- /dev/null
+++ b/data/reports/GO-2026-6002.yaml
@@ -0,0 +1,19 @@
+id: GO-2026-6002
+modules:
+    - module: github.com/stacklok/toolhive
+      versions:
+        - fixed: 0.31.0
+      vulnerable_at: 0.30.1
+summary: |-
+    ToolHive: SSRF in remote MCP server authentication discovery (host-side,
+    bypasses container isolation) in github.com/stacklok/toolhive
+cves:
+    - CVE-2026-58196
+ghsas:
+    - GHSA-pr64-jmmf-jp54
+references:
+    - advisory: https://github.com/stacklok/toolhive/security/advisories/GHSA-pr64-jmmf-jp54
+source:
+    id: GHSA-pr64-jmmf-jp54
+    created: 2026-07-17T13:13:28.786261645-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6003.yaml b/data/reports/GO-2026-6003.yaml
new file mode 100644
index 0000000..7d8ed9d
--- /dev/null
+++ b/data/reports/GO-2026-6003.yaml
@@ -0,0 +1,21 @@
+id: GO-2026-6003
+modules:
+    - module: github.com/envoyproxy/gateway
+      versions:
+        - fixed: 1.7.4
+        - introduced: 1.8.0-rc.0
+        - fixed: 1.8.1
+      vulnerable_at: 1.8.0
+summary: |-
+    Envoy Gateway: xDS Control Plane Information Disclosure when operating in
+    GatewayNamespaceMode in github.com/envoyproxy/gateway
+cves:
+    - CVE-2026-53714
+ghsas:
+    - GHSA-22xc-xg2r-9j7v
+references:
+    - advisory: https://github.com/envoyproxy/gateway/security/advisories/GHSA-22xc-xg2r-9j7v
+source:
+    id: GHSA-22xc-xg2r-9j7v
+    created: 2026-07-17T13:13:24.159007384-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6004.yaml b/data/reports/GO-2026-6004.yaml
new file mode 100644
index 0000000..27df446
--- /dev/null
+++ b/data/reports/GO-2026-6004.yaml
@@ -0,0 +1,22 @@
+id: GO-2026-6004
+modules:
+    - module: github.com/nuclio/nuclio
+      non_go_versions:
+        - fixed: 1.16.5
+      vulnerable_at: 1.14.2
+summary: |-
+    Nuclio: Unsanitized runtimeAttributes.repositories injected into Groovy
+    build.gradle leads to build-time RCE in github.com/nuclio/nuclio
+cves:
+    - CVE-2026-52833
+ghsas:
+    - GHSA-3v79-m2cg-89ww
+references:
+    - advisory: https://github.com/nuclio/nuclio/security/advisories/GHSA-3v79-m2cg-89ww
+    - fix: https://github.com/nuclio/nuclio/commit/4c78040c759068e927f3ed7c6507543c15d4ae56
+    - fix: https://github.com/nuclio/nuclio/pull/4149
+    - web: https://github.com/nuclio/nuclio/releases/tag/1.16.5
+source:
+    id: GHSA-3v79-m2cg-89ww
+    created: 2026-07-17T13:13:17.730178407-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6005.yaml b/data/reports/GO-2026-6005.yaml
new file mode 100644
index 0000000..1601450
--- /dev/null
+++ b/data/reports/GO-2026-6005.yaml
@@ -0,0 +1,19 @@
+id: GO-2026-6005
+modules:
+    - module: github.com/envoyproxy/gateway
+      versions:
+        - fixed: 1.7.4
+        - introduced: 1.8.0-rc.0
+        - fixed: 1.8.1
+      vulnerable_at: 1.8.0
+summary: 'Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock in github.com/envoyproxy/gateway'
+cves:
+    - CVE-2026-53715
+ghsas:
+    - GHSA-8fv2-88gg-hm7q
+references:
+    - advisory: https://github.com/envoyproxy/gateway/security/advisories/GHSA-8fv2-88gg-hm7q
+source:
+    id: GHSA-8fv2-88gg-hm7q
+    created: 2026-07-17T13:13:12.766137212-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6006.yaml b/data/reports/GO-2026-6006.yaml
new file mode 100644
index 0000000..70c730e
--- /dev/null
+++ b/data/reports/GO-2026-6006.yaml
@@ -0,0 +1,19 @@
+id: GO-2026-6006
+modules:
+    - module: github.com/envoyproxy/gateway
+      versions:
+        - fixed: 1.7.4
+        - introduced: 1.8.0-rc.0
+        - fixed: 1.8.1
+      vulnerable_at: 1.8.0
+summary: 'Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit in github.com/envoyproxy/gateway'
+cves:
+    - CVE-2026-53716
+ghsas:
+    - GHSA-cxpq-8v7q-cg56
+references:
+    - advisory: https://github.com/envoyproxy/gateway/security/advisories/GHSA-cxpq-8v7q-cg56
+source:
+    id: GHSA-cxpq-8v7q-cg56
+    created: 2026-07-17T13:13:08.071643908-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6007.yaml b/data/reports/GO-2026-6007.yaml
new file mode 100644
index 0000000..3e1ef85
--- /dev/null
+++ b/data/reports/GO-2026-6007.yaml
@@ -0,0 +1,19 @@
+id: GO-2026-6007
+modules:
+    - module: github.com/envoyproxy/gateway
+      versions:
+        - fixed: 1.7.4
+        - introduced: 1.8.0-rc.0
+        - fixed: 1.8.1
+      vulnerable_at: 1.8.0
+summary: Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass in github.com/envoyproxy/gateway
+cves:
+    - CVE-2026-53718
+ghsas:
+    - GHSA-fcrp-7gc2-93g7
+references:
+    - advisory: https://github.com/envoyproxy/gateway/security/advisories/GHSA-fcrp-7gc2-93g7
+source:
+    id: GHSA-fcrp-7gc2-93g7
+    created: 2026-07-17T13:13:03.426486286-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6008.yaml b/data/reports/GO-2026-6008.yaml
new file mode 100644
index 0000000..116e69b
--- /dev/null
+++ b/data/reports/GO-2026-6008.yaml
@@ -0,0 +1,21 @@
+id: GO-2026-6008
+modules:
+    - module: github.com/envoyproxy/gateway
+      versions:
+        - fixed: 1.7.4
+        - introduced: 1.8.0-rc.0
+        - fixed: 1.8.1
+      vulnerable_at: 1.8.0
+summary: |-
+    Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from
+    untrusted tar header in github.com/envoyproxy/gateway
+cves:
+    - CVE-2026-53717
+ghsas:
+    - GHSA-h7pq-86h8-rp5x
+references:
+    - advisory: https://github.com/envoyproxy/gateway/security/advisories/GHSA-h7pq-86h8-rp5x
+source:
+    id: GHSA-h7pq-86h8-rp5x
+    created: 2026-07-17T13:12:58.694810659-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6009.yaml b/data/reports/GO-2026-6009.yaml
new file mode 100644
index 0000000..581589e
--- /dev/null
+++ b/data/reports/GO-2026-6009.yaml
@@ -0,0 +1,21 @@
+id: GO-2026-6009
+modules:
+    - module: github.com/envoyproxy/gateway
+      versions:
+        - fixed: 1.7.4
+        - introduced: 1.8.0-rc.0
+        - fixed: 1.8.1
+      vulnerable_at: 1.8.0
+summary: |-
+    Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without
+    spec.authorization in github.com/envoyproxy/gateway
+cves:
+    - CVE-2026-53719
+ghsas:
+    - GHSA-m2v6-2jmh-4c68
+references:
+    - advisory: https://github.com/envoyproxy/gateway/security/advisories/GHSA-m2v6-2jmh-4c68
+source:
+    id: GHSA-m2v6-2jmh-4c68
+    created: 2026-07-17T13:12:54.188292688-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6011.yaml b/data/reports/GO-2026-6011.yaml
new file mode 100644
index 0000000..cde07b9
--- /dev/null
+++ b/data/reports/GO-2026-6011.yaml
@@ -0,0 +1,21 @@
+id: GO-2026-6011
+modules:
+    - module: github.com/envoyproxy/gateway
+      versions:
+        - fixed: 1.7.4
+        - introduced: 1.8.0-rc.0
+        - fixed: 1.8.1
+      vulnerable_at: 1.8.0
+summary: |-
+    Envoy Gateway: Authentication Bypass via Improper Input Validation in
+    EnvoyExtensionPolicy Lua Allows Secret Disclosure in github.com/envoyproxy/gateway
+cves:
+    - CVE-2026-53713
+ghsas:
+    - GHSA-wcrf-9vrr-854f
+references:
+    - advisory: https://github.com/envoyproxy/gateway/security/advisories/GHSA-wcrf-9vrr-854f
+source:
+    id: GHSA-wcrf-9vrr-854f
+    created: 2026-07-17T13:12:44.700642063-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6012.yaml b/data/reports/GO-2026-6012.yaml
new file mode 100644
index 0000000..21a079a
--- /dev/null
+++ b/data/reports/GO-2026-6012.yaml
@@ -0,0 +1,22 @@
+id: GO-2026-6012
+modules:
+    - module: github.com/nuclio/nuclio
+      non_go_versions:
+        - fixed: 1.16.5
+      vulnerable_at: 1.14.2
+summary: |-
+    Nuclio: Unauthenticated path traversal in spec.handler allows arbitrary file
+    write in Dashboard container in github.com/nuclio/nuclio
+cves:
+    - CVE-2026-52832
+ghsas:
+    - GHSA-wpcj-rmv4-86qg
+references:
+    - advisory: https://github.com/nuclio/nuclio/security/advisories/GHSA-wpcj-rmv4-86qg
+    - fix: https://github.com/nuclio/nuclio/commit/2a55d3a8bd4d49226cb4742020303f5bf2a0931d
+    - fix: https://github.com/nuclio/nuclio/pull/4143
+    - web: https://github.com/nuclio/nuclio/releases/tag/1.16.5
+source:
+    id: GHSA-wpcj-rmv4-86qg
+    created: 2026-07-17T13:12:37.152813427-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6014.yaml b/data/reports/GO-2026-6014.yaml
new file mode 100644
index 0000000..1695f84
--- /dev/null
+++ b/data/reports/GO-2026-6014.yaml
@@ -0,0 +1,25 @@
+id: GO-2026-6014
+modules:
+    - module: github.com/saltbo/zpan
+      versions:
+        - fixed: 1.6.6
+      vulnerable_at: 1.6.5
+summary: ZPan Uses Hard-Coded Password in github.com/saltbo/zpan
+cves:
+    - CVE-2025-7453
+ghsas:
+    - GHSA-2hfh-94w5-wxvf
+references:
+    - advisory: https://github.com/advisories/GHSA-2hfh-94w5-wxvf
+    - advisory: https://nvd.nist.gov/vuln/detail/CVE-2025-7453
+    - fix: https://github.com/saltbo/zpan/commit/8662db8d4b06057631faf3deba4132e66705e947
+    - fix: https://github.com/saltbo/zpan/pull/410
+    - report: https://github.com/saltbo/zpan/issues/219
+    - web: https://github.com/saltbo/zpan/releases/tag/v1.6.6
+    - web: https://vuldb.com/?ctiid.316097
+    - web: https://vuldb.com/?id.316097
+    - web: https://vuldb.com/?submit.608447
+source:
+    id: GHSA-2hfh-94w5-wxvf
+    created: 2026-07-17T13:12:17.850164996-04:00
+review_status: UNREVIEWED