blob: 1065838122a4c70e24a919030b3cbd7d067de00b [file] [log] [blame]
id: GO-2025-3509
modules:
- module: github.com/go-vela/server
versions:
- fixed: 0.25.3
- introduced: 0.26.0
- fixed: 0.26.3
vulnerable_at: 0.26.2
summary: Vela Server Has Insufficient Webhook Payload Data Verification in github.com/go-vela/server
cves:
- CVE-2025-27616
ghsas:
- GHSA-9m63-33q3-xq5x
references:
- advisory: https://github.com/go-vela/server/security/advisories/GHSA-9m63-33q3-xq5x
- advisory: https://nvd.nist.gov/vuln/detail/CVE-2025-27616
- fix: https://github.com/go-vela/server/commit/257886e5a3eea518548387885894e239668584f5
- fix: https://github.com/go-vela/server/commit/67c1892e2464dc54b8d2588815dfb7819222500b
- web: https://github.com/go-vela/server/releases/tag/v0.25.3
- web: https://github.com/go-vela/server/releases/tag/v0.26.3
source:
id: GHSA-9m63-33q3-xq5x
created: 2025-03-12T13:12:01.325354-04:00
review_status: UNREVIEWED