data/reports: add go1.25.13/go1.26.6/go1.27rc3 release reports For golang/vulndb#5026 For golang/vulndb#5942 Fixes golang/vulndb#5972 Fixes golang/vulndb#6088 Fixes golang/vulndb#6089 Fixes golang/vulndb#6090 Fixes golang/vulndb#6091 Fixes golang/vulndb#6179 Fixes golang/vulndb#6180 Fixes golang/vulndb#6218 Change-Id: I67925da2be55aa9bc169cc4f58d123375192f8f2 Reviewed-on: https://go-review.googlesource.com/c/vulndb/+/815200 Reviewed-by: Damien Neil <dneil@google.com> Auto-Submit: Neal Patel <nealpatel@google.com> LUCI-TryBot-Result: golang-scoped@luci-project-accounts.iam.gserviceaccount.com <golang-scoped@luci-project-accounts.iam.gserviceaccount.com>
diff --git a/data/cve/v5/GO-2026-5026.json b/data/cve/v5/GO-2026-5026.json index 25bf978..fa493e2 100644 --- a/data/cve/v5/GO-2026-5026.json +++ b/data/cve/v5/GO-2026-5026.json
@@ -18,6 +18,136 @@ ], "affected": [ { + "vendor": "Go standard library", + "product": "net/http", + "collectionURL": "https://pkg.go.dev", + "packageName": "net/http", + "versions": [ + { + "version": "0", + "lessThan": "1.25.13", + "status": "affected", + "versionType": "semver" + }, + { + "version": "1.26.0-0", + "lessThan": "1.26.6", + "status": "affected", + "versionType": "semver" + }, + { + "version": "1.27.0-0", + "lessThan": "1.27.0-rc.3", + "status": "affected", + "versionType": "semver" + } + ], + "programRoutines": [ + { + "name": "idnaASCII" + }, + { + "name": "Client.CloseIdleConnections" + }, + { + "name": "Client.Do" + }, + { + "name": "Client.Get" + }, + { + "name": "Client.Head" + }, + { + "name": "Client.Post" + }, + { + "name": "Client.PostForm" + }, + { + "name": "ClientConn.Close" + }, + { + "name": "ClientConn.RoundTrip" + }, + { + "name": "Get" + }, + { + "name": "Head" + }, + { + "name": "Post" + }, + { + "name": "PostForm" + }, + { + "name": "Transport.CloseIdleConnections" + }, + { + "name": "Transport.NewClientConn" + }, + { + "name": "Transport.RoundTrip" + }, + { + "name": "http1ClientConn.Close" + }, + { + "name": "http1ClientConn.RoundTrip" + }, + { + "name": "http2ClientConn.RoundTrip" + }, + { + "name": "http2RoundTripper.RoundTrip" + } + ], + "defaultStatus": "unaffected" + }, + { + "vendor": "Go standard library", + "product": "net/http/internal/http2", + "collectionURL": "https://pkg.go.dev", + "packageName": "net/http/internal/http2", + "versions": [ + { + "version": "0", + "lessThan": "1.25.13", + "status": "affected", + "versionType": "semver" + }, + { + "version": "1.26.0-0", + "lessThan": "1.26.6", + "status": "affected", + "versionType": "semver" + }, + { + "version": "1.27.0-0", + "lessThan": "1.27.0-rc.3", + "status": "affected", + "versionType": "semver" + } + ], + "programRoutines": [ + { + "name": "authorityAddr" + }, + { + "name": "Transport.AddConn" + }, + { + "name": "Transport.RoundTrip" + }, + { + "name": "Transport.RoundTripOpt" + } + ], + "defaultStatus": "unaffected" + }, + { "vendor": "golang.org/x/net", "product": "golang.org/x/net/idna", "collectionURL": "https://pkg.go.dev", @@ -71,6 +201,9 @@ "url": "https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8" }, { + "url": "https://groups.google.com/g/golang-announce/c/94pEornpRlI" + }, + { "url": "https://pkg.go.dev/vuln/GO-2026-5026" } ],
diff --git a/data/cve/v5/GO-2026-5942.json b/data/cve/v5/GO-2026-5942.json index 0e80a66..3b22dcb 100644 --- a/data/cve/v5/GO-2026-5942.json +++ b/data/cve/v5/GO-2026-5942.json
@@ -18,6 +18,38 @@ ], "affected": [ { + "vendor": "Go standard library", + "product": "net", + "collectionURL": "https://pkg.go.dev", + "packageName": "net", + "versions": [ + { + "version": "0", + "lessThan": "1.26.6", + "status": "affected", + "versionType": "semver" + }, + { + "version": "1.27.0-0", + "lessThan": "1.27.0-rc.3", + "status": "affected", + "versionType": "semver" + } + ], + "programRoutines": [ + { + "name": "cgoResSearch" + }, + { + "name": "LookupCNAME" + }, + { + "name": "Resolver.LookupCNAME" + } + ], + "defaultStatus": "unaffected" + }, + { "vendor": "golang.org/x/net", "product": "golang.org/x/net/dns/dnsmessage", "collectionURL": "https://pkg.go.dev", @@ -83,6 +115,9 @@ "url": "https://go.dev/issue/79795" }, { + "url": "https://groups.google.com/g/golang-announce/c/94pEornpRlI" + }, + { "url": "https://pkg.go.dev/vuln/GO-2026-5942" } ],
diff --git a/data/cve/v5/GO-2026-5972.json b/data/cve/v5/GO-2026-5972.json new file mode 100644 index 0000000..5cfd135 --- /dev/null +++ b/data/cve/v5/GO-2026-5972.json
@@ -0,0 +1,94 @@ +{ + "dataType": "CVE_RECORD", + "dataVersion": "5.0", + "cveMetadata": { + "cveId": "CVE-2026-33818" + }, + "containers": { + "cna": { + "providerMetadata": { + "orgId": "1bb62c36-49e3-4200-9d77-64a1400537cc" + }, + "title": "Enforce maximum recursion depth in encoding/asn1", + "descriptions": [ + { + "lang": "en", + "value": "Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures." + } + ], + "affected": [ + { + "vendor": "Go standard library", + "product": "encoding/asn1", + "collectionURL": "https://pkg.go.dev", + "packageName": "encoding/asn1", + "versions": [ + { + "version": "0", + "lessThan": "1.25.13", + "status": "affected", + "versionType": "semver" + }, + { + "version": "1.26.0-0", + "lessThan": "1.26.6", + "status": "affected", + "versionType": "semver" + }, + { + "version": "1.27.0-0", + "lessThan": "1.27.0-rc.3", + "status": "affected", + "versionType": "semver" + } + ], + "programRoutines": [ + { + "name": "parseSequenceOf" + }, + { + "name": "parseField" + }, + { + "name": "UnmarshalWithParams" + }, + { + "name": "Unmarshal" + } + ], + "defaultStatus": "unaffected" + } + ], + "problemTypes": [ + { + "descriptions": [ + { + "lang": "en", + "description": "CWE-400: Uncontrolled Resource Consumption" + } + ] + } + ], + "references": [ + { + "url": "https://go.dev/issue/80405" + }, + { + "url": "https://groups.google.com/g/golang-announce/c/94pEornpRlI" + }, + { + "url": "https://go.dev/cl/814980" + }, + { + "url": "https://pkg.go.dev/vuln/GO-2026-5972" + } + ], + "credits": [ + { + "lang": "en", + "value": "Marwan Atia (marwansamir688@gmail.com) " + } + ] + } + } +} \ No newline at end of file
diff --git a/data/cve/v5/GO-2026-6088.json b/data/cve/v5/GO-2026-6088.json new file mode 100644 index 0000000..ff5fd16 --- /dev/null +++ b/data/cve/v5/GO-2026-6088.json
@@ -0,0 +1,106 @@ +{ + "dataType": "CVE_RECORD", + "dataVersion": "5.0", + "cveMetadata": { + "cveId": "CVE-2026-56859" + }, + "containers": { + "cna": { + "providerMetadata": { + "orgId": "1bb62c36-49e3-4200-9d77-64a1400537cc" + }, + "title": "Add recursion depth guard during decode in encoding/xml", + "descriptions": [ + { + "lang": "en", + "value": "Previously, DecodeElement would reset the depth counter causing it to never fire; this could lead to stack exhaustion." + } + ], + "affected": [ + { + "vendor": "Go standard library", + "product": "encoding/xml", + "collectionURL": "https://pkg.go.dev", + "packageName": "encoding/xml", + "versions": [ + { + "version": "0", + "lessThan": "1.25.13", + "status": "affected", + "versionType": "semver" + }, + { + "version": "1.26.0-0", + "lessThan": "1.26.6", + "status": "affected", + "versionType": "semver" + }, + { + "version": "1.27.0-0", + "lessThan": "1.27.0-rc.3", + "status": "affected", + "versionType": "semver" + } + ], + "programRoutines": [ + { + "name": "Decoder.push" + }, + { + "name": "Decoder.pop" + }, + { + "name": "Decoder.RawToken" + }, + { + "name": "Decoder.unmarshalPath" + }, + { + "name": "Decoder.unmarshal" + }, + { + "name": "Decoder.Decode" + }, + { + "name": "Decoder.DecodeElement" + }, + { + "name": "Decoder.Skip" + }, + { + "name": "Decoder.Token" + }, + { + "name": "Unmarshal" + } + ], + "defaultStatus": "unaffected" + } + ], + "problemTypes": [ + { + "descriptions": [ + { + "lang": "en", + "description": "CWE-770: Allocation of Resources Without Limits or Throttling" + } + ] + } + ], + "references": [ + { + "url": "https://go.dev/issue/80481" + }, + { + "url": "https://go.dev/cl/803320" + }, + { + "url": "https://groups.google.com/g/golang-announce/c/94pEornpRlI" + }, + { + "url": "https://pkg.go.dev/vuln/GO-2026-6088" + } + ] + } + } +} \ No newline at end of file
diff --git a/data/cve/v5/GO-2026-6089.json b/data/cve/v5/GO-2026-6089.json new file mode 100644 index 0000000..bd034a3 --- /dev/null +++ b/data/cve/v5/GO-2026-6089.json
@@ -0,0 +1,106 @@ +{ + "dataType": "CVE_RECORD", + "dataVersion": "5.0", + "cveMetadata": { + "cveId": "CVE-2026-56853" + }, + "containers": { + "cna": { + "providerMetadata": { + "orgId": "1bb62c36-49e3-4200-9d77-64a1400537cc" + }, + "title": "Apply ReadHeaderTimeout when doing unencrypted HTTP/2 check in net/http", + "descriptions": [ + { + "lang": "en", + "value": "When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client preface. ReadHeaderTimeout is unexpectedly not being applied when doing this." + } + ], + "affected": [ + { + "vendor": "Go standard library", + "product": "net/http", + "collectionURL": "https://pkg.go.dev", + "packageName": "net/http", + "versions": [ + { + "version": "0", + "lessThan": "1.25.13", + "status": "affected", + "versionType": "semver" + }, + { + "version": "1.26.0-0", + "lessThan": "1.26.6", + "status": "affected", + "versionType": "semver" + }, + { + "version": "1.27.0-0", + "lessThan": "1.27.0-rc.3", + "status": "affected", + "versionType": "semver" + } + ], + "programRoutines": [ + { + "name": "conn.readRequest" + }, + { + "name": "conn.serve" + }, + { + "name": "ListenAndServe" + }, + { + "name": "ListenAndServeTLS" + }, + { + "name": "Serve" + }, + { + "name": "ServeTLS" + }, + { + "name": "Server.ListenAndServe" + }, + { + "name": "Server.ListenAndServeTLS" + }, + { + "name": "Server.Serve" + }, + { + "name": "Server.ServeTLS" + } + ], + "defaultStatus": "unaffected" + } + ], + "problemTypes": [ + { + "descriptions": [ + { + "lang": "en", + "description": "CWE-770: Allocation of Resources Without Limits or Throttling" + } + ] + } + ], + "references": [ + { + "url": "https://go.dev/issue/80205" + }, + { + "url": "https://go.dev/cl/795540" + }, + { + "url": "https://groups.google.com/g/golang-announce/c/94pEornpRlI" + }, + { + "url": "https://pkg.go.dev/vuln/GO-2026-6089" + } + ] + } + } +} \ No newline at end of file
diff --git a/data/cve/v5/GO-2026-6090.json b/data/cve/v5/GO-2026-6090.json new file mode 100644 index 0000000..f5fa0eb --- /dev/null +++ b/data/cve/v5/GO-2026-6090.json
@@ -0,0 +1,115 @@ +{ + "dataType": "CVE_RECORD", + "dataVersion": "5.0", + "cveMetadata": { + "cveId": "CVE-2026-56862" + }, + "containers": { + "cna": { + "providerMetadata": { + "orgId": "1bb62c36-49e3-4200-9d77-64a1400537cc" + }, + "title": "Limit handshake messages we are willing to accept post-handshake in crypto/tls", + "descriptions": [ + { + "lang": "en", + "value": "Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been completed or not. As a result, a malicious client can keep sending KeyUpdate messages to force the server to keep performing key derivation operations indefinitely." + } + ], + "affected": [ + { + "vendor": "Go standard library", + "product": "crypto/tls", + "collectionURL": "https://pkg.go.dev", + "packageName": "crypto/tls", + "versions": [ + { + "version": "0", + "lessThan": "1.25.13", + "status": "affected", + "versionType": "semver" + }, + { + "version": "1.26.0-0", + "lessThan": "1.26.6", + "status": "affected", + "versionType": "semver" + }, + { + "version": "1.27.0-0", + "lessThan": "1.27.0-rc.3", + "status": "affected", + "versionType": "semver" + } + ], + "programRoutines": [ + { + "name": "Conn.readRecordOrCCS" + }, + { + "name": "Conn.Handshake" + }, + { + "name": "Conn.HandshakeContext" + }, + { + "name": "Conn.Read" + }, + { + "name": "Conn.Write" + }, + { + "name": "Dial" + }, + { + "name": "DialWithDialer" + }, + { + "name": "Dialer.Dial" + }, + { + "name": "Dialer.DialContext" + }, + { + "name": "QUICConn.HandleData" + }, + { + "name": "QUICConn.Start" + } + ], + "defaultStatus": "unaffected" + } + ], + "problemTypes": [ + { + "descriptions": [ + { + "lang": "en", + "description": "CWE-770: Allocation of Resources Without Limits or Throttling" + } + ] + } + ], + "references": [ + { + "url": "https://go.dev/issue/80528" + }, + { + "url": "https://go.dev/cl/804261" + }, + { + "url": "https://groups.google.com/g/golang-announce/c/94pEornpRlI" + }, + { + "url": "https://pkg.go.dev/vuln/GO-2026-6090" + } + ], + "credits": [ + { + "lang": "en", + "value": "Qi Deng of Aurascape.ai" + } + ] + } + } +} \ No newline at end of file
diff --git a/data/cve/v5/GO-2026-6091.json b/data/cve/v5/GO-2026-6091.json new file mode 100644 index 0000000..1f1d606 --- /dev/null +++ b/data/cve/v5/GO-2026-6091.json
@@ -0,0 +1,91 @@ +{ + "dataType": "CVE_RECORD", + "dataVersion": "5.0", + "cveMetadata": { + "cveId": "CVE-2026-56858" + }, + "containers": { + "cna": { + "providerMetadata": { + "orgId": "1bb62c36-49e3-4200-9d77-64a1400537cc" + }, + "title": "Fix Javascript regexp context tracking in html/template", + "descriptions": [ + { + "lang": "en", + "value": "Previously, pathological inputs could close an unescaped '/' early, allowing for attack-controlled data to inject arbitrary content, potentially leading to XSS." + } + ], + "affected": [ + { + "vendor": "Go standard library", + "product": "html/template", + "collectionURL": "https://pkg.go.dev", + "packageName": "html/template", + "versions": [ + { + "version": "0", + "lessThan": "1.25.13", + "status": "affected", + "versionType": "semver" + }, + { + "version": "1.26.0-0", + "lessThan": "1.26.6", + "status": "affected", + "versionType": "semver" + }, + { + "version": "1.27.0-0", + "lessThan": "1.27.0-rc.3", + "status": "affected", + "versionType": "semver" + } + ], + "programRoutines": [ + { + "name": "tJS" + }, + { + "name": "Template.Execute" + }, + { + "name": "Template.ExecuteTemplate" + } + ], + "defaultStatus": "unaffected" + } + ], + "problemTypes": [ + { + "descriptions": [ + { + "lang": "en", + "description": "CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')" + } + ] + } + ], + "references": [ + { + "url": "https://go.dev/issue/80435" + }, + { + "url": "https://go.dev/cl/807100" + }, + { + "url": "https://groups.google.com/g/golang-announce/c/94pEornpRlI" + }, + { + "url": "https://pkg.go.dev/vuln/GO-2026-6091" + } + ], + "credits": [ + { + "lang": "en", + "value": "Ali Sherif" + } + ] + } + } +} \ No newline at end of file
diff --git a/data/cve/v5/GO-2026-6179.json b/data/cve/v5/GO-2026-6179.json new file mode 100644 index 0000000..e098da7 --- /dev/null +++ b/data/cve/v5/GO-2026-6179.json
@@ -0,0 +1,103 @@ +{ + "dataType": "CVE_RECORD", + "dataVersion": "5.0", + "cveMetadata": { + "cveId": "CVE-2026-56865" + }, + "containers": { + "cna": { + "providerMetadata": { + "orgId": "1bb62c36-49e3-4200-9d77-64a1400537cc" + }, + "title": "Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog", + "descriptions": [ + { + "lang": "en", + "value": "A malicious GOPROXY was previously capable of forging up to two sumdb tiles that allow for a requested module to bypass the GOSUMDB check and persist attacker-controlled module content to a local Go module cache. This attack allows for a malicious GOPROXY to serve malicious module content that cannot be detected by evaluating the transparency log. All tiles are now correctly verified against their parents. In order to determine if you have been affected: rm -r go.sum go.work.sum vendor/ \u0026\u0026 go mod tidy" + } + ], + "affected": [ + { + "vendor": "Go toolchain", + "product": "cmd/go", + "collectionURL": "https://pkg.go.dev", + "packageName": "cmd/go", + "versions": [ + { + "version": "0", + "lessThan": "1.25.13", + "status": "affected", + "versionType": "semver" + }, + { + "version": "1.26.0-0", + "lessThan": "1.26.6", + "status": "affected", + "versionType": "semver" + }, + { + "version": "1.27.0-0", + "lessThan": "1.27.0-rc.3", + "status": "affected", + "versionType": "semver" + } + ], + "defaultStatus": "unaffected" + }, + { + "vendor": "golang.org/x/mod", + "product": "golang.org/x/mod/sumdb/tlog", + "collectionURL": "https://pkg.go.dev", + "packageName": "golang.org/x/mod/sumdb/tlog", + "versions": [ + { + "version": "0", + "lessThan": "0.40.0", + "status": "affected", + "versionType": "semver" + } + ], + "programRoutines": [ + { + "name": "tileHashReader.ReadHashes" + } + ], + "defaultStatus": "unaffected" + } + ], + "problemTypes": [ + { + "descriptions": [ + { + "lang": "en", + "description": "CWE-347: Improper Verification of Cryptographic Signature" + } + ] + } + ], + "references": [ + { + "url": "https://go.dev/issue/80744" + }, + { + "url": "https://groups.google.com/g/golang-announce/c/94pEornpRlI" + }, + { + "url": "https://go.dev/cl/814960" + }, + { + "url": "https://go.dev/cl/815020" + }, + { + "url": "https://pkg.go.dev/vuln/GO-2026-6179" + } + ], + "credits": [ + { + "lang": "en", + "value": "Filippo Valsorda (Geomys)" + } + ] + } + } +} \ No newline at end of file
diff --git a/data/cve/v5/GO-2026-6180.json b/data/cve/v5/GO-2026-6180.json new file mode 100644 index 0000000..429b2c0 --- /dev/null +++ b/data/cve/v5/GO-2026-6180.json
@@ -0,0 +1,103 @@ +{ + "dataType": "CVE_RECORD", + "dataVersion": "5.0", + "cveMetadata": { + "cveId": "CVE-2026-56864" + }, + "containers": { + "cna": { + "providerMetadata": { + "orgId": "1bb62c36-49e3-4200-9d77-64a1400537cc" + }, + "title": "Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb", + "descriptions": [ + { + "lang": "en", + "value": "A malicious GOSUMDB was capable of serving arbitrary module content not contained within the transparency log. This attack allows for a coordinating GOPROXY and GOSUMDB to serve a client malicious module content that cannot be detected by evaluating the transparency log. In order to determine if you have been affected: rm -r go.sum go.work.sum vendor/ \u0026\u0026 go mod tidy" + } + ], + "affected": [ + { + "vendor": "Go toolchain", + "product": "cmd/go", + "collectionURL": "https://pkg.go.dev", + "packageName": "cmd/go", + "versions": [ + { + "version": "0", + "lessThan": "1.25.13", + "status": "affected", + "versionType": "semver" + }, + { + "version": "1.26.0-0", + "lessThan": "1.26.6", + "status": "affected", + "versionType": "semver" + }, + { + "version": "1.27.0-0", + "lessThan": "1.27.0-rc.3", + "status": "affected", + "versionType": "semver" + } + ], + "defaultStatus": "unaffected" + }, + { + "vendor": "golang.org/x/mod", + "product": "golang.org/x/mod/sumdb", + "collectionURL": "https://pkg.go.dev", + "packageName": "golang.org/x/mod/sumdb", + "versions": [ + { + "version": "0", + "lessThan": "0.40.0", + "status": "affected", + "versionType": "semver" + } + ], + "programRoutines": [ + { + "name": "Client.Lookup" + } + ], + "defaultStatus": "unaffected" + } + ], + "problemTypes": [ + { + "descriptions": [ + { + "lang": "en", + "description": "CWE-347: Improper Verification of Cryptographic Signature" + } + ] + } + ], + "references": [ + { + "url": "https://go.dev/issue/80745" + }, + { + "url": "https://groups.google.com/g/golang-announce/c/94pEornpRlI" + }, + { + "url": "https://go.dev/cl/815000" + }, + { + "url": "https://go.dev/cl/815020" + }, + { + "url": "https://pkg.go.dev/vuln/GO-2026-6180" + } + ], + "credits": [ + { + "lang": "en", + "value": "mundur" + } + ] + } + } +} \ No newline at end of file
diff --git a/data/cve/v5/GO-2026-6218.json b/data/cve/v5/GO-2026-6218.json new file mode 100644 index 0000000..e97f202 --- /dev/null +++ b/data/cve/v5/GO-2026-6218.json
@@ -0,0 +1,85 @@ +{ + "dataType": "CVE_RECORD", + "dataVersion": "5.0", + "cveMetadata": { + "cveId": "CVE-2026-56860" + }, + "containers": { + "cna": { + "providerMetadata": { + "orgId": "1bb62c36-49e3-4200-9d77-64a1400537cc" + }, + "title": "Avoid quadratic complexity in resolvePath in net/url", + "descriptions": [ + { + "lang": "en", + "value": "Previously, resolving relative paths containing parent directory ('..') segments performed string conversions and buffer rewrites on each step, resulting in quadratic time complexity and high memory allocation overhead. Now, path resolution operates on a byte buffer using index-based backtracking for '..' segments, eliminating the quadratic time complexity and significantly reducing memory allocations." + } + ], + "affected": [ + { + "vendor": "Go standard library", + "product": "net/url", + "collectionURL": "https://pkg.go.dev", + "packageName": "net/url", + "versions": [ + { + "version": "0", + "lessThan": "1.25.13", + "status": "affected", + "versionType": "semver" + }, + { + "version": "1.26.0-0", + "lessThan": "1.26.6", + "status": "affected", + "versionType": "semver" + }, + { + "version": "1.27.0-0", + "lessThan": "1.27.0-rc.3", + "status": "affected", + "versionType": "semver" + } + ], + "programRoutines": [ + { + "name": "resolvePath" + }, + { + "name": "URL.Parse" + }, + { + "name": "URL.ResolveReference" + } + ], + "defaultStatus": "unaffected" + } + ], + "problemTypes": [ + { + "descriptions": [ + { + "lang": "en", + "description": "CWE-407: Inefficient Algorithmic Complexity" + } + ] + } + ], + "references": [ + { + "url": "https://go.dev/cl/803681" + }, + { + "url": "https://go.dev/issue/80494" + }, + { + "url": "https://groups.google.com/g/golang-announce/c/94pEornpRlI" + }, + { + "url": "https://pkg.go.dev/vuln/GO-2026-6218" + } + ] + } + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-5026.json b/data/osv/GO-2026-5026.json index e854bdc..6b1f0de 100644 --- a/data/osv/GO-2026-5026.json +++ b/data/osv/GO-2026-5026.json
@@ -11,6 +11,75 @@ "affected": [ { "package": { + "name": "stdlib", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.25.13" + }, + { + "introduced": "1.26.0-0" + }, + { + "fixed": "1.26.6" + }, + { + "introduced": "1.27.0-0" + }, + { + "fixed": "1.27.0-rc.3" + } + ] + } + ], + "ecosystem_specific": { + "imports": [ + { + "path": "net/http", + "symbols": [ + "Client.CloseIdleConnections", + "Client.Do", + "Client.Get", + "Client.Head", + "Client.Post", + "Client.PostForm", + "ClientConn.Close", + "ClientConn.RoundTrip", + "Get", + "Head", + "Post", + "PostForm", + "Transport.CloseIdleConnections", + "Transport.NewClientConn", + "Transport.RoundTrip", + "http1ClientConn.Close", + "http1ClientConn.RoundTrip", + "http2ClientConn.RoundTrip", + "http2RoundTripper.RoundTrip", + "idnaASCII" + ] + }, + { + "path": "net/http/internal/http2", + "symbols": [ + "Transport.AddConn", + "Transport.RoundTrip", + "Transport.RoundTripOpt", + "authorityAddr" + ] + } + ] + } + }, + { + "package": { "name": "golang.org/x/net", "ecosystem": "Go" }, @@ -55,6 +124,10 @@ { "type": "WEB", "url": "https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8" + }, + { + "type": "WEB", + "url": "https://groups.google.com/g/golang-announce/c/94pEornpRlI" } ], "credits": [
diff --git a/data/osv/GO-2026-5942.json b/data/osv/GO-2026-5942.json index 82710d1..39bd49b 100644 --- a/data/osv/GO-2026-5942.json +++ b/data/osv/GO-2026-5942.json
@@ -11,6 +11,43 @@ "affected": [ { "package": { + "name": "stdlib", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.26.6" + }, + { + "introduced": "1.27.0-0" + }, + { + "fixed": "1.27.0-rc.3" + } + ] + } + ], + "ecosystem_specific": { + "imports": [ + { + "path": "net", + "symbols": [ + "LookupCNAME", + "Resolver.LookupCNAME", + "cgoResSearch" + ] + } + ] + } + }, + { + "package": { "name": "golang.org/x/net", "ecosystem": "Go" }, @@ -56,6 +93,10 @@ { "type": "REPORT", "url": "https://go.dev/issue/79795" + }, + { + "type": "WEB", + "url": "https://groups.google.com/g/golang-announce/c/94pEornpRlI" } ], "credits": [
diff --git a/data/osv/GO-2026-5972.json b/data/osv/GO-2026-5972.json new file mode 100644 index 0000000..ac4d970 --- /dev/null +++ b/data/osv/GO-2026-5972.json
@@ -0,0 +1,80 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-5972", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-33818" + ], + "summary": "Enforce maximum recursion depth in encoding/asn1", + "details": "Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures.", + "affected": [ + { + "package": { + "name": "stdlib", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.25.13" + }, + { + "introduced": "1.26.0-0" + }, + { + "fixed": "1.26.6" + }, + { + "introduced": "1.27.0-0" + }, + { + "fixed": "1.27.0-rc.3" + } + ] + } + ], + "ecosystem_specific": { + "imports": [ + { + "path": "encoding/asn1", + "symbols": [ + "Unmarshal", + "UnmarshalWithParams", + "parseField", + "parseSequenceOf" + ] + } + ] + } + } + ], + "references": [ + { + "type": "REPORT", + "url": "https://go.dev/issue/80405" + }, + { + "type": "WEB", + "url": "https://groups.google.com/g/golang-announce/c/94pEornpRlI" + }, + { + "type": "FIX", + "url": "https://go.dev/cl/814980" + } + ], + "credits": [ + { + "name": "Marwan Atia (marwansamir688@gmail.com) " + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-5972", + "review_status": "REVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6088.json b/data/osv/GO-2026-6088.json new file mode 100644 index 0000000..de28d37 --- /dev/null +++ b/data/osv/GO-2026-6088.json
@@ -0,0 +1,81 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6088", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-56859" + ], + "summary": "Add recursion depth guard during decode in encoding/xml", + "details": "Previously, DecodeElement would reset the depth counter causing it to never fire; this could lead to stack exhaustion.", + "affected": [ + { + "package": { + "name": "stdlib", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.25.13" + }, + { + "introduced": "1.26.0-0" + }, + { + "fixed": "1.26.6" + }, + { + "introduced": "1.27.0-0" + }, + { + "fixed": "1.27.0-rc.3" + } + ] + } + ], + "ecosystem_specific": { + "imports": [ + { + "path": "encoding/xml", + "symbols": [ + "Decoder.Decode", + "Decoder.DecodeElement", + "Decoder.RawToken", + "Decoder.Skip", + "Decoder.Token", + "Decoder.pop", + "Decoder.push", + "Decoder.unmarshal", + "Decoder.unmarshalPath", + "Unmarshal" + ] + } + ] + } + } + ], + "references": [ + { + "type": "REPORT", + "url": "https://go.dev/issue/80481" + }, + { + "type": "FIX", + "url": "https://go.dev/cl/803320" + }, + { + "type": "WEB", + "url": "https://groups.google.com/g/golang-announce/c/94pEornpRlI" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6088", + "review_status": "REVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6089.json b/data/osv/GO-2026-6089.json new file mode 100644 index 0000000..eac0d71 --- /dev/null +++ b/data/osv/GO-2026-6089.json
@@ -0,0 +1,81 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6089", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-56853" + ], + "summary": "Apply ReadHeaderTimeout when doing unencrypted HTTP/2 check in net/http", + "details": "When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client preface. ReadHeaderTimeout is unexpectedly not being applied when doing this.", + "affected": [ + { + "package": { + "name": "stdlib", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.25.13" + }, + { + "introduced": "1.26.0-0" + }, + { + "fixed": "1.26.6" + }, + { + "introduced": "1.27.0-0" + }, + { + "fixed": "1.27.0-rc.3" + } + ] + } + ], + "ecosystem_specific": { + "imports": [ + { + "path": "net/http", + "symbols": [ + "ListenAndServe", + "ListenAndServeTLS", + "Serve", + "ServeTLS", + "Server.ListenAndServe", + "Server.ListenAndServeTLS", + "Server.Serve", + "Server.ServeTLS", + "conn.readRequest", + "conn.serve" + ] + } + ] + } + } + ], + "references": [ + { + "type": "REPORT", + "url": "https://go.dev/issue/80205" + }, + { + "type": "FIX", + "url": "https://go.dev/cl/795540" + }, + { + "type": "WEB", + "url": "https://groups.google.com/g/golang-announce/c/94pEornpRlI" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6089", + "review_status": "REVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6090.json b/data/osv/GO-2026-6090.json new file mode 100644 index 0000000..ca54051 --- /dev/null +++ b/data/osv/GO-2026-6090.json
@@ -0,0 +1,87 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6090", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-56862" + ], + "summary": "Limit handshake messages we are willing to accept post-handshake in crypto/tls", + "details": "Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been completed or not. As a result, a malicious client can keep sending KeyUpdate messages to force the server to keep performing key derivation operations indefinitely.", + "affected": [ + { + "package": { + "name": "stdlib", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.25.13" + }, + { + "introduced": "1.26.0-0" + }, + { + "fixed": "1.26.6" + }, + { + "introduced": "1.27.0-0" + }, + { + "fixed": "1.27.0-rc.3" + } + ] + } + ], + "ecosystem_specific": { + "imports": [ + { + "path": "crypto/tls", + "symbols": [ + "Conn.Handshake", + "Conn.HandshakeContext", + "Conn.Read", + "Conn.Write", + "Conn.readRecordOrCCS", + "Dial", + "DialWithDialer", + "Dialer.Dial", + "Dialer.DialContext", + "QUICConn.HandleData", + "QUICConn.Start" + ] + } + ] + } + } + ], + "references": [ + { + "type": "REPORT", + "url": "https://go.dev/issue/80528" + }, + { + "type": "FIX", + "url": "https://go.dev/cl/804261" + }, + { + "type": "WEB", + "url": "https://groups.google.com/g/golang-announce/c/94pEornpRlI" + } + ], + "credits": [ + { + "name": "Qi Deng of Aurascape.ai" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6090", + "review_status": "REVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6091.json b/data/osv/GO-2026-6091.json new file mode 100644 index 0000000..11025a2 --- /dev/null +++ b/data/osv/GO-2026-6091.json
@@ -0,0 +1,79 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6091", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-56858" + ], + "summary": "Fix Javascript regexp context tracking in html/template", + "details": "Previously, pathological inputs could close an unescaped '/' early, allowing for attack-controlled data to inject arbitrary content, potentially leading to XSS.", + "affected": [ + { + "package": { + "name": "stdlib", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.25.13" + }, + { + "introduced": "1.26.0-0" + }, + { + "fixed": "1.26.6" + }, + { + "introduced": "1.27.0-0" + }, + { + "fixed": "1.27.0-rc.3" + } + ] + } + ], + "ecosystem_specific": { + "imports": [ + { + "path": "html/template", + "symbols": [ + "Template.Execute", + "Template.ExecuteTemplate", + "tJS" + ] + } + ] + } + } + ], + "references": [ + { + "type": "REPORT", + "url": "https://go.dev/issue/80435" + }, + { + "type": "FIX", + "url": "https://go.dev/cl/807100" + }, + { + "type": "WEB", + "url": "https://groups.google.com/g/golang-announce/c/94pEornpRlI" + } + ], + "credits": [ + { + "name": "Ali Sherif" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6091", + "review_status": "REVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6179.json b/data/osv/GO-2026-6179.json new file mode 100644 index 0000000..9350972 --- /dev/null +++ b/data/osv/GO-2026-6179.json
@@ -0,0 +1,107 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6179", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-56865" + ], + "summary": "Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog", + "details": "A malicious GOPROXY was previously capable of forging up to two sumdb tiles that allow for a requested module to bypass the GOSUMDB check and persist attacker-controlled module content to a local Go module cache.\n\nThis attack allows for a malicious GOPROXY to serve malicious module content that cannot be detected by evaluating the transparency log.\n\nAll tiles are now correctly verified against their parents.\n\nIn order to determine if you have been affected:\n\nrm -r go.sum go.work.sum vendor/ \u0026\u0026 go mod tidy", + "affected": [ + { + "package": { + "name": "toolchain", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.25.13" + }, + { + "introduced": "1.26.0-0" + }, + { + "fixed": "1.26.6" + }, + { + "introduced": "1.27.0-0" + }, + { + "fixed": "1.27.0-rc.3" + } + ] + } + ], + "ecosystem_specific": { + "imports": [ + { + "path": "cmd/go" + } + ] + } + }, + { + "package": { + "name": "golang.org/x/mod", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.40.0" + } + ] + } + ], + "ecosystem_specific": { + "imports": [ + { + "path": "golang.org/x/mod/sumdb/tlog", + "symbols": [ + "tileHashReader.ReadHashes" + ] + } + ] + } + } + ], + "references": [ + { + "type": "REPORT", + "url": "https://go.dev/issue/80744" + }, + { + "type": "WEB", + "url": "https://groups.google.com/g/golang-announce/c/94pEornpRlI" + }, + { + "type": "FIX", + "url": "https://go.dev/cl/814960" + }, + { + "type": "FIX", + "url": "https://go.dev/cl/815020" + } + ], + "credits": [ + { + "name": "Filippo Valsorda (Geomys)" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6179", + "review_status": "REVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6180.json b/data/osv/GO-2026-6180.json new file mode 100644 index 0000000..05b1be8 --- /dev/null +++ b/data/osv/GO-2026-6180.json
@@ -0,0 +1,107 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6180", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-56864" + ], + "summary": "Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb", + "details": "A malicious GOSUMDB was capable of serving arbitrary module content not contained within the transparency log.\n\nThis attack allows for a coordinating GOPROXY and GOSUMDB to serve a client malicious module content that cannot be detected by evaluating the transparency log.\n\nIn order to determine if you have been affected:\n\nrm -r go.sum go.work.sum vendor/ \u0026\u0026 go mod tidy", + "affected": [ + { + "package": { + "name": "toolchain", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.25.13" + }, + { + "introduced": "1.26.0-0" + }, + { + "fixed": "1.26.6" + }, + { + "introduced": "1.27.0-0" + }, + { + "fixed": "1.27.0-rc.3" + } + ] + } + ], + "ecosystem_specific": { + "imports": [ + { + "path": "cmd/go" + } + ] + } + }, + { + "package": { + "name": "golang.org/x/mod", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.40.0" + } + ] + } + ], + "ecosystem_specific": { + "imports": [ + { + "path": "golang.org/x/mod/sumdb", + "symbols": [ + "Client.Lookup" + ] + } + ] + } + } + ], + "references": [ + { + "type": "REPORT", + "url": "https://go.dev/issue/80745" + }, + { + "type": "WEB", + "url": "https://groups.google.com/g/golang-announce/c/94pEornpRlI" + }, + { + "type": "FIX", + "url": "https://go.dev/cl/815000" + }, + { + "type": "FIX", + "url": "https://go.dev/cl/815020" + } + ], + "credits": [ + { + "name": "mundur" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6180", + "review_status": "REVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6218.json b/data/osv/GO-2026-6218.json new file mode 100644 index 0000000..a00c528 --- /dev/null +++ b/data/osv/GO-2026-6218.json
@@ -0,0 +1,74 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6218", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-56860" + ], + "summary": "Avoid quadratic complexity in resolvePath in net/url", + "details": "Previously, resolving relative paths containing parent directory ('..') segments performed string conversions and buffer rewrites on each step, resulting in quadratic time complexity and high memory allocation overhead.\n\nNow, path resolution operates on a byte buffer using index-based backtracking for '..' segments, eliminating the quadratic time complexity and significantly reducing memory allocations.", + "affected": [ + { + "package": { + "name": "stdlib", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.25.13" + }, + { + "introduced": "1.26.0-0" + }, + { + "fixed": "1.26.6" + }, + { + "introduced": "1.27.0-0" + }, + { + "fixed": "1.27.0-rc.3" + } + ] + } + ], + "ecosystem_specific": { + "imports": [ + { + "path": "net/url", + "symbols": [ + "URL.Parse", + "URL.ResolveReference", + "resolvePath" + ] + } + ] + } + } + ], + "references": [ + { + "type": "FIX", + "url": "https://go.dev/cl/803681" + }, + { + "type": "REPORT", + "url": "https://go.dev/issue/80494" + }, + { + "type": "WEB", + "url": "https://groups.google.com/g/golang-announce/c/94pEornpRlI" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6218", + "review_status": "REVIEWED" + } +} \ No newline at end of file
diff --git a/data/reports/GO-2026-5026.yaml b/data/reports/GO-2026-5026.yaml index ddc16ee..f8d0bcb 100644 --- a/data/reports/GO-2026-5026.yaml +++ b/data/reports/GO-2026-5026.yaml
@@ -1,5 +1,44 @@ id: GO-2026-5026 modules: + - module: std + versions: + - fixed: 1.25.13 + - introduced: 1.26.0-0 + - fixed: 1.26.6 + - introduced: 1.27.0-0 + - fixed: 1.27.0-rc.3 + vulnerable_at: 1.27.0-rc.2 + packages: + - package: net/http + symbols: + - idnaASCII + derived_symbols: + - Client.CloseIdleConnections + - Client.Do + - Client.Get + - Client.Head + - Client.Post + - Client.PostForm + - ClientConn.Close + - ClientConn.RoundTrip + - Get + - Head + - Post + - PostForm + - Transport.CloseIdleConnections + - Transport.NewClientConn + - Transport.RoundTrip + - http1ClientConn.Close + - http1ClientConn.RoundTrip + - http2ClientConn.RoundTrip + - http2RoundTripper.RoundTrip + - package: net/http/internal/http2 + symbols: + - authorityAddr + derived_symbols: + - Transport.AddConn + - Transport.RoundTrip + - Transport.RoundTripOpt - module: golang.org/x/net versions: - fixed: 0.55.0 @@ -32,6 +71,7 @@ - fix: https://go.dev/cl/767220 - report: https://go.dev/issue/78760 - web: https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8 + - web: https://groups.google.com/g/golang-announce/c/94pEornpRlI cve_metadata: id: CVE-2026-39821 cwe: 'CWE-1289: Improper Validation of Unsafe Equivalence in Input'
diff --git a/data/reports/GO-2026-5942.yaml b/data/reports/GO-2026-5942.yaml index 0994314..ea360c5 100644 --- a/data/reports/GO-2026-5942.yaml +++ b/data/reports/GO-2026-5942.yaml
@@ -1,5 +1,18 @@ id: GO-2026-5942 modules: + - module: std + versions: + - fixed: 1.26.6 + - introduced: 1.27.0-0 + - fixed: 1.27.0-rc.3 + vulnerable_at: 1.27.0-rc.2 + packages: + - package: net + symbols: + - cgoResSearch + derived_symbols: + - LookupCNAME + - Resolver.LookupCNAME - module: golang.org/x/net versions: - fixed: 0.56.0 @@ -27,6 +40,7 @@ references: - fix: https://go.dev/cl/786345 - report: https://go.dev/issue/79795 + - web: https://groups.google.com/g/golang-announce/c/94pEornpRlI cve_metadata: id: CVE-2026-46600 cwe: 'CWE-125: Out-of-bounds Read'
diff --git a/data/reports/GO-2026-5972.yaml b/data/reports/GO-2026-5972.yaml new file mode 100644 index 0000000..0353964 --- /dev/null +++ b/data/reports/GO-2026-5972.yaml
@@ -0,0 +1,34 @@ +id: GO-2026-5972 +modules: + - module: std + versions: + - fixed: 1.25.13 + - introduced: 1.26.0-0 + - fixed: 1.26.6 + - introduced: 1.27.0-0 + - fixed: 1.27.0-rc.3 + vulnerable_at: 1.27.0-rc.2 + packages: + - package: encoding/asn1 + symbols: + - parseSequenceOf + - parseField + - UnmarshalWithParams + derived_symbols: + - Unmarshal +summary: Enforce maximum recursion depth in encoding/asn1 +description: | + Enforce a recursion limit in Unmarshal to prevent stack exhaustion + when parsing deeply-nested, recursive structures. +credits: + - 'Marwan Atia (marwansamir688@gmail.com) ' +references: + - report: https://go.dev/issue/80405 + - web: https://groups.google.com/g/golang-announce/c/94pEornpRlI + - fix: https://go.dev/cl/814980 +cve_metadata: + id: CVE-2026-33818 + cwe: 'CWE-400: Uncontrolled Resource Consumption' +source: + id: go-security-team +review_status: REVIEWED
diff --git a/data/reports/GO-2026-6088.yaml b/data/reports/GO-2026-6088.yaml new file mode 100644 index 0000000..82710a1 --- /dev/null +++ b/data/reports/GO-2026-6088.yaml
@@ -0,0 +1,39 @@ +id: GO-2026-6088 +modules: + - module: std + versions: + - fixed: 1.25.13 + - introduced: 1.26.0-0 + - fixed: 1.26.6 + - introduced: 1.27.0-0 + - fixed: 1.27.0-rc.3 + vulnerable_at: 1.27.0-rc.2 + packages: + - package: encoding/xml + symbols: + - Decoder.push + - Decoder.pop + - Decoder.RawToken + - Decoder.unmarshalPath + - Decoder.unmarshal + derived_symbols: + - Decoder.Decode + - Decoder.DecodeElement + - Decoder.Skip + - Decoder.Token + - Unmarshal +summary: Add recursion depth guard during decode in encoding/xml +description: | + Previously, DecodeElement would reset the depth counter + causing it to never fire; this could lead to stack + exhaustion. +references: + - report: https://go.dev/issue/80481 + - fix: https://go.dev/cl/803320 + - web: https://groups.google.com/g/golang-announce/c/94pEornpRlI +cve_metadata: + id: CVE-2026-56859 + cwe: 'CWE-770: Allocation of Resources Without Limits or Throttling' +source: + id: go-security-team +review_status: REVIEWED
diff --git a/data/reports/GO-2026-6089.yaml b/data/reports/GO-2026-6089.yaml new file mode 100644 index 0000000..e5fb72a --- /dev/null +++ b/data/reports/GO-2026-6089.yaml
@@ -0,0 +1,40 @@ +id: GO-2026-6089 +modules: + - module: std + versions: + - fixed: 1.25.13 + - introduced: 1.26.0-0 + - fixed: 1.26.6 + - introduced: 1.27.0-0 + - fixed: 1.27.0-rc.3 + vulnerable_at: 1.27.0-rc.2 + packages: + - package: net/http + symbols: + - conn.readRequest + - conn.serve + derived_symbols: + - ListenAndServe + - ListenAndServeTLS + - Serve + - ServeTLS + - Server.ListenAndServe + - Server.ListenAndServeTLS + - Server.Serve + - Server.ServeTLS +summary: Apply ReadHeaderTimeout when doing unencrypted HTTP/2 check in net/http +description: | + When a server is configured to support unencrypted HTTP/2, it reads a + few bytes from each new connection to see if they contain the HTTP/2 + client preface. ReadHeaderTimeout is unexpectedly not being applied + when doing this. +references: + - report: https://go.dev/issue/80205 + - fix: https://go.dev/cl/795540 + - web: https://groups.google.com/g/golang-announce/c/94pEornpRlI +cve_metadata: + id: CVE-2026-56853 + cwe: 'CWE-770: Allocation of Resources Without Limits or Throttling' +source: + id: go-security-team +review_status: REVIEWED
diff --git a/data/reports/GO-2026-6090.yaml b/data/reports/GO-2026-6090.yaml new file mode 100644 index 0000000..b6703cc --- /dev/null +++ b/data/reports/GO-2026-6090.yaml
@@ -0,0 +1,44 @@ +id: GO-2026-6090 +modules: + - module: std + versions: + - fixed: 1.25.13 + - introduced: 1.26.0-0 + - fixed: 1.26.6 + - introduced: 1.27.0-0 + - fixed: 1.27.0-rc.3 + vulnerable_at: 1.27.0-rc.2 + packages: + - package: crypto/tls + symbols: + - Conn.readRecordOrCCS + derived_symbols: + - Conn.Handshake + - Conn.HandshakeContext + - Conn.Read + - Conn.Write + - Dial + - DialWithDialer + - Dialer.Dial + - Dialer.DialContext + - QUICConn.HandleData + - QUICConn.Start +summary: Limit handshake messages we are willing to accept post-handshake in crypto/tls +description: | + Handshake messages, such as KeyUpdate, are always considered as + state-advancing, regardless of whether a handshake has been completed or + not. As a result, a malicious client can keep sending KeyUpdate messages + to force the server to keep performing key derivation operations + indefinitely. +credits: + - Qi Deng of Aurascape.ai +references: + - report: https://go.dev/issue/80528 + - fix: https://go.dev/cl/804261 + - web: https://groups.google.com/g/golang-announce/c/94pEornpRlI +cve_metadata: + id: CVE-2026-56862 + cwe: 'CWE-770: Allocation of Resources Without Limits or Throttling' +source: + id: go-security-team +review_status: REVIEWED
diff --git a/data/reports/GO-2026-6091.yaml b/data/reports/GO-2026-6091.yaml new file mode 100644 index 0000000..e7c2ad1 --- /dev/null +++ b/data/reports/GO-2026-6091.yaml
@@ -0,0 +1,35 @@ +id: GO-2026-6091 +modules: + - module: std + versions: + - fixed: 1.25.13 + - introduced: 1.26.0-0 + - fixed: 1.26.6 + - introduced: 1.27.0-0 + - fixed: 1.27.0-rc.3 + vulnerable_at: 1.27.0-rc.2 + packages: + - package: html/template + symbols: + - tJS + derived_symbols: + - Template.Execute + - Template.ExecuteTemplate +summary: Fix Javascript regexp context tracking in html/template +description: | + Previously, pathological inputs could close an + unescaped '/' early, allowing for attack-controlled + data to inject arbitrary content, potentially + leading to XSS. +credits: + - Ali Sherif +references: + - report: https://go.dev/issue/80435 + - fix: https://go.dev/cl/807100 + - web: https://groups.google.com/g/golang-announce/c/94pEornpRlI +cve_metadata: + id: CVE-2026-56858 + cwe: 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site Scripting'')' +source: + id: go-security-team +review_status: REVIEWED
diff --git a/data/reports/GO-2026-6179.yaml b/data/reports/GO-2026-6179.yaml new file mode 100644 index 0000000..2f54b16 --- /dev/null +++ b/data/reports/GO-2026-6179.yaml
@@ -0,0 +1,49 @@ +id: GO-2026-6179 +modules: + - module: cmd + versions: + - fixed: 1.25.13 + - introduced: 1.26.0-0 + - fixed: 1.26.6 + - introduced: 1.27.0-0 + - fixed: 1.27.0-rc.3 + vulnerable_at: 1.27.0-rc.2 + packages: + - package: cmd/go + - module: golang.org/x/mod + versions: + - fixed: 0.40.0 + vulnerable_at: 0.39.0 + packages: + - package: golang.org/x/mod/sumdb/tlog + symbols: + - tileHashReader.ReadHashes +summary: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog +description: | + A malicious GOPROXY was previously capable of forging + up to two sumdb tiles that allow for a requested module + to bypass the GOSUMDB check and persist attacker-controlled + module content to a local Go module cache. + + This attack allows for a malicious GOPROXY to serve + malicious module content that cannot be detected + by evaluating the transparency log. + + All tiles are now correctly verified against their parents. + + In order to determine if you have been affected: + + rm -r go.sum go.work.sum vendor/ && go mod tidy +credits: + - Filippo Valsorda (Geomys) +references: + - report: https://go.dev/issue/80744 + - web: https://groups.google.com/g/golang-announce/c/94pEornpRlI + - fix: https://go.dev/cl/814960 + - fix: https://go.dev/cl/815020 +cve_metadata: + id: CVE-2026-56865 + cwe: 'CWE-347: Improper Verification of Cryptographic Signature' +source: + id: go-security-team +review_status: REVIEWED
diff --git a/data/reports/GO-2026-6180.yaml b/data/reports/GO-2026-6180.yaml new file mode 100644 index 0000000..93ff0ee --- /dev/null +++ b/data/reports/GO-2026-6180.yaml
@@ -0,0 +1,47 @@ +id: GO-2026-6180 +modules: + - module: cmd + versions: + - fixed: 1.25.13 + - introduced: 1.26.0-0 + - fixed: 1.26.6 + - introduced: 1.27.0-0 + - fixed: 1.27.0-rc.3 + vulnerable_at: 1.27.0-rc.2 + packages: + - package: cmd/go + - module: golang.org/x/mod + versions: + - fixed: 0.40.0 + vulnerable_at: 0.39.0 + packages: + - package: golang.org/x/mod/sumdb + symbols: + - Client.Lookup +summary: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb +description: | + A malicious GOSUMDB was capable of serving arbitrary + module content not contained within the transparency + log. + + This attack allows for a coordinating GOPROXY and + GOSUMDB to serve a client malicious module content + that cannot be detected by evaluating the transparency + log. + + In order to determine if you have been affected: + + rm -r go.sum go.work.sum vendor/ && go mod tidy +credits: + - mundur +references: + - report: https://go.dev/issue/80745 + - web: https://groups.google.com/g/golang-announce/c/94pEornpRlI + - fix: https://go.dev/cl/815000 + - fix: https://go.dev/cl/815020 +cve_metadata: + id: CVE-2026-56864 + cwe: 'CWE-347: Improper Verification of Cryptographic Signature' +source: + id: go-security-team +review_status: REVIEWED
diff --git a/data/reports/GO-2026-6218.yaml b/data/reports/GO-2026-6218.yaml new file mode 100644 index 0000000..161bbb7 --- /dev/null +++ b/data/reports/GO-2026-6218.yaml
@@ -0,0 +1,36 @@ +id: GO-2026-6218 +modules: + - module: std + versions: + - fixed: 1.25.13 + - introduced: 1.26.0-0 + - fixed: 1.26.6 + - introduced: 1.27.0-0 + - fixed: 1.27.0-rc.3 + vulnerable_at: 1.27.0-rc.2 + packages: + - package: net/url + symbols: + - resolvePath + derived_symbols: + - URL.Parse + - URL.ResolveReference +summary: Avoid quadratic complexity in resolvePath in net/url +description: |- + Previously, resolving relative paths containing parent directory ('..') segments + performed string conversions and buffer rewrites on each step, resulting in + quadratic time complexity and high memory allocation overhead. + + Now, path resolution operates on a byte buffer using index-based backtracking + for '..' segments, eliminating the quadratic time complexity and significantly + reducing memory allocations. +references: + - fix: https://go.dev/cl/803681 + - report: https://go.dev/issue/80494 + - web: https://groups.google.com/g/golang-announce/c/94pEornpRlI +cve_metadata: + id: CVE-2026-56860 + cwe: 'CWE-407: Inefficient Algorithmic Complexity' +source: + id: go-security-team +review_status: REVIEWED