data/reports: add go1.25.13/go1.26.6/go1.27rc3 release reports

For golang/vulndb#5026
For golang/vulndb#5942
Fixes golang/vulndb#5972
Fixes golang/vulndb#6088
Fixes golang/vulndb#6089
Fixes golang/vulndb#6090
Fixes golang/vulndb#6091
Fixes golang/vulndb#6179
Fixes golang/vulndb#6180
Fixes golang/vulndb#6218

Change-Id: I67925da2be55aa9bc169cc4f58d123375192f8f2
Reviewed-on: https://go-review.googlesource.com/c/vulndb/+/815200
Reviewed-by: Damien Neil <dneil@google.com>
Auto-Submit: Neal Patel <nealpatel@google.com>
LUCI-TryBot-Result: golang-scoped@luci-project-accounts.iam.gserviceaccount.com <golang-scoped@luci-project-accounts.iam.gserviceaccount.com>
diff --git a/data/cve/v5/GO-2026-5026.json b/data/cve/v5/GO-2026-5026.json
index 25bf978..fa493e2 100644
--- a/data/cve/v5/GO-2026-5026.json
+++ b/data/cve/v5/GO-2026-5026.json
@@ -18,6 +18,136 @@
       ],
       "affected": [
         {
+          "vendor": "Go standard library",
+          "product": "net/http",
+          "collectionURL": "https://pkg.go.dev",
+          "packageName": "net/http",
+          "versions": [
+            {
+              "version": "0",
+              "lessThan": "1.25.13",
+              "status": "affected",
+              "versionType": "semver"
+            },
+            {
+              "version": "1.26.0-0",
+              "lessThan": "1.26.6",
+              "status": "affected",
+              "versionType": "semver"
+            },
+            {
+              "version": "1.27.0-0",
+              "lessThan": "1.27.0-rc.3",
+              "status": "affected",
+              "versionType": "semver"
+            }
+          ],
+          "programRoutines": [
+            {
+              "name": "idnaASCII"
+            },
+            {
+              "name": "Client.CloseIdleConnections"
+            },
+            {
+              "name": "Client.Do"
+            },
+            {
+              "name": "Client.Get"
+            },
+            {
+              "name": "Client.Head"
+            },
+            {
+              "name": "Client.Post"
+            },
+            {
+              "name": "Client.PostForm"
+            },
+            {
+              "name": "ClientConn.Close"
+            },
+            {
+              "name": "ClientConn.RoundTrip"
+            },
+            {
+              "name": "Get"
+            },
+            {
+              "name": "Head"
+            },
+            {
+              "name": "Post"
+            },
+            {
+              "name": "PostForm"
+            },
+            {
+              "name": "Transport.CloseIdleConnections"
+            },
+            {
+              "name": "Transport.NewClientConn"
+            },
+            {
+              "name": "Transport.RoundTrip"
+            },
+            {
+              "name": "http1ClientConn.Close"
+            },
+            {
+              "name": "http1ClientConn.RoundTrip"
+            },
+            {
+              "name": "http2ClientConn.RoundTrip"
+            },
+            {
+              "name": "http2RoundTripper.RoundTrip"
+            }
+          ],
+          "defaultStatus": "unaffected"
+        },
+        {
+          "vendor": "Go standard library",
+          "product": "net/http/internal/http2",
+          "collectionURL": "https://pkg.go.dev",
+          "packageName": "net/http/internal/http2",
+          "versions": [
+            {
+              "version": "0",
+              "lessThan": "1.25.13",
+              "status": "affected",
+              "versionType": "semver"
+            },
+            {
+              "version": "1.26.0-0",
+              "lessThan": "1.26.6",
+              "status": "affected",
+              "versionType": "semver"
+            },
+            {
+              "version": "1.27.0-0",
+              "lessThan": "1.27.0-rc.3",
+              "status": "affected",
+              "versionType": "semver"
+            }
+          ],
+          "programRoutines": [
+            {
+              "name": "authorityAddr"
+            },
+            {
+              "name": "Transport.AddConn"
+            },
+            {
+              "name": "Transport.RoundTrip"
+            },
+            {
+              "name": "Transport.RoundTripOpt"
+            }
+          ],
+          "defaultStatus": "unaffected"
+        },
+        {
           "vendor": "golang.org/x/net",
           "product": "golang.org/x/net/idna",
           "collectionURL": "https://pkg.go.dev",
@@ -71,6 +201,9 @@
           "url": "https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8"
         },
         {
+          "url": "https://groups.google.com/g/golang-announce/c/94pEornpRlI"
+        },
+        {
           "url": "https://pkg.go.dev/vuln/GO-2026-5026"
         }
       ],
diff --git a/data/cve/v5/GO-2026-5942.json b/data/cve/v5/GO-2026-5942.json
index 0e80a66..3b22dcb 100644
--- a/data/cve/v5/GO-2026-5942.json
+++ b/data/cve/v5/GO-2026-5942.json
@@ -18,6 +18,38 @@
       ],
       "affected": [
         {
+          "vendor": "Go standard library",
+          "product": "net",
+          "collectionURL": "https://pkg.go.dev",
+          "packageName": "net",
+          "versions": [
+            {
+              "version": "0",
+              "lessThan": "1.26.6",
+              "status": "affected",
+              "versionType": "semver"
+            },
+            {
+              "version": "1.27.0-0",
+              "lessThan": "1.27.0-rc.3",
+              "status": "affected",
+              "versionType": "semver"
+            }
+          ],
+          "programRoutines": [
+            {
+              "name": "cgoResSearch"
+            },
+            {
+              "name": "LookupCNAME"
+            },
+            {
+              "name": "Resolver.LookupCNAME"
+            }
+          ],
+          "defaultStatus": "unaffected"
+        },
+        {
           "vendor": "golang.org/x/net",
           "product": "golang.org/x/net/dns/dnsmessage",
           "collectionURL": "https://pkg.go.dev",
@@ -83,6 +115,9 @@
           "url": "https://go.dev/issue/79795"
         },
         {
+          "url": "https://groups.google.com/g/golang-announce/c/94pEornpRlI"
+        },
+        {
           "url": "https://pkg.go.dev/vuln/GO-2026-5942"
         }
       ],
diff --git a/data/cve/v5/GO-2026-5972.json b/data/cve/v5/GO-2026-5972.json
new file mode 100644
index 0000000..5cfd135
--- /dev/null
+++ b/data/cve/v5/GO-2026-5972.json
@@ -0,0 +1,94 @@
+{
+  "dataType": "CVE_RECORD",
+  "dataVersion": "5.0",
+  "cveMetadata": {
+    "cveId": "CVE-2026-33818"
+  },
+  "containers": {
+    "cna": {
+      "providerMetadata": {
+        "orgId": "1bb62c36-49e3-4200-9d77-64a1400537cc"
+      },
+      "title": "Enforce maximum recursion depth in encoding/asn1",
+      "descriptions": [
+        {
+          "lang": "en",
+          "value": "Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures."
+        }
+      ],
+      "affected": [
+        {
+          "vendor": "Go standard library",
+          "product": "encoding/asn1",
+          "collectionURL": "https://pkg.go.dev",
+          "packageName": "encoding/asn1",
+          "versions": [
+            {
+              "version": "0",
+              "lessThan": "1.25.13",
+              "status": "affected",
+              "versionType": "semver"
+            },
+            {
+              "version": "1.26.0-0",
+              "lessThan": "1.26.6",
+              "status": "affected",
+              "versionType": "semver"
+            },
+            {
+              "version": "1.27.0-0",
+              "lessThan": "1.27.0-rc.3",
+              "status": "affected",
+              "versionType": "semver"
+            }
+          ],
+          "programRoutines": [
+            {
+              "name": "parseSequenceOf"
+            },
+            {
+              "name": "parseField"
+            },
+            {
+              "name": "UnmarshalWithParams"
+            },
+            {
+              "name": "Unmarshal"
+            }
+          ],
+          "defaultStatus": "unaffected"
+        }
+      ],
+      "problemTypes": [
+        {
+          "descriptions": [
+            {
+              "lang": "en",
+              "description": "CWE-400: Uncontrolled Resource Consumption"
+            }
+          ]
+        }
+      ],
+      "references": [
+        {
+          "url": "https://go.dev/issue/80405"
+        },
+        {
+          "url": "https://groups.google.com/g/golang-announce/c/94pEornpRlI"
+        },
+        {
+          "url": "https://go.dev/cl/814980"
+        },
+        {
+          "url": "https://pkg.go.dev/vuln/GO-2026-5972"
+        }
+      ],
+      "credits": [
+        {
+          "lang": "en",
+          "value": "Marwan Atia (marwansamir688@gmail.com) "
+        }
+      ]
+    }
+  }
+}
\ No newline at end of file
diff --git a/data/cve/v5/GO-2026-6088.json b/data/cve/v5/GO-2026-6088.json
new file mode 100644
index 0000000..ff5fd16
--- /dev/null
+++ b/data/cve/v5/GO-2026-6088.json
@@ -0,0 +1,106 @@
+{
+  "dataType": "CVE_RECORD",
+  "dataVersion": "5.0",
+  "cveMetadata": {
+    "cveId": "CVE-2026-56859"
+  },
+  "containers": {
+    "cna": {
+      "providerMetadata": {
+        "orgId": "1bb62c36-49e3-4200-9d77-64a1400537cc"
+      },
+      "title": "Add recursion depth guard during decode in encoding/xml",
+      "descriptions": [
+        {
+          "lang": "en",
+          "value": "Previously, DecodeElement would reset the depth counter causing it to never fire; this could lead to stack exhaustion."
+        }
+      ],
+      "affected": [
+        {
+          "vendor": "Go standard library",
+          "product": "encoding/xml",
+          "collectionURL": "https://pkg.go.dev",
+          "packageName": "encoding/xml",
+          "versions": [
+            {
+              "version": "0",
+              "lessThan": "1.25.13",
+              "status": "affected",
+              "versionType": "semver"
+            },
+            {
+              "version": "1.26.0-0",
+              "lessThan": "1.26.6",
+              "status": "affected",
+              "versionType": "semver"
+            },
+            {
+              "version": "1.27.0-0",
+              "lessThan": "1.27.0-rc.3",
+              "status": "affected",
+              "versionType": "semver"
+            }
+          ],
+          "programRoutines": [
+            {
+              "name": "Decoder.push"
+            },
+            {
+              "name": "Decoder.pop"
+            },
+            {
+              "name": "Decoder.RawToken"
+            },
+            {
+              "name": "Decoder.unmarshalPath"
+            },
+            {
+              "name": "Decoder.unmarshal"
+            },
+            {
+              "name": "Decoder.Decode"
+            },
+            {
+              "name": "Decoder.DecodeElement"
+            },
+            {
+              "name": "Decoder.Skip"
+            },
+            {
+              "name": "Decoder.Token"
+            },
+            {
+              "name": "Unmarshal"
+            }
+          ],
+          "defaultStatus": "unaffected"
+        }
+      ],
+      "problemTypes": [
+        {
+          "descriptions": [
+            {
+              "lang": "en",
+              "description": "CWE-770: Allocation of Resources Without Limits or Throttling"
+            }
+          ]
+        }
+      ],
+      "references": [
+        {
+          "url": "https://go.dev/issue/80481"
+        },
+        {
+          "url": "https://go.dev/cl/803320"
+        },
+        {
+          "url": "https://groups.google.com/g/golang-announce/c/94pEornpRlI"
+        },
+        {
+          "url": "https://pkg.go.dev/vuln/GO-2026-6088"
+        }
+      ]
+    }
+  }
+}
\ No newline at end of file
diff --git a/data/cve/v5/GO-2026-6089.json b/data/cve/v5/GO-2026-6089.json
new file mode 100644
index 0000000..bd034a3
--- /dev/null
+++ b/data/cve/v5/GO-2026-6089.json
@@ -0,0 +1,106 @@
+{
+  "dataType": "CVE_RECORD",
+  "dataVersion": "5.0",
+  "cveMetadata": {
+    "cveId": "CVE-2026-56853"
+  },
+  "containers": {
+    "cna": {
+      "providerMetadata": {
+        "orgId": "1bb62c36-49e3-4200-9d77-64a1400537cc"
+      },
+      "title": "Apply ReadHeaderTimeout when doing unencrypted HTTP/2 check in net/http",
+      "descriptions": [
+        {
+          "lang": "en",
+          "value": "When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client preface. ReadHeaderTimeout is unexpectedly not being applied when doing this."
+        }
+      ],
+      "affected": [
+        {
+          "vendor": "Go standard library",
+          "product": "net/http",
+          "collectionURL": "https://pkg.go.dev",
+          "packageName": "net/http",
+          "versions": [
+            {
+              "version": "0",
+              "lessThan": "1.25.13",
+              "status": "affected",
+              "versionType": "semver"
+            },
+            {
+              "version": "1.26.0-0",
+              "lessThan": "1.26.6",
+              "status": "affected",
+              "versionType": "semver"
+            },
+            {
+              "version": "1.27.0-0",
+              "lessThan": "1.27.0-rc.3",
+              "status": "affected",
+              "versionType": "semver"
+            }
+          ],
+          "programRoutines": [
+            {
+              "name": "conn.readRequest"
+            },
+            {
+              "name": "conn.serve"
+            },
+            {
+              "name": "ListenAndServe"
+            },
+            {
+              "name": "ListenAndServeTLS"
+            },
+            {
+              "name": "Serve"
+            },
+            {
+              "name": "ServeTLS"
+            },
+            {
+              "name": "Server.ListenAndServe"
+            },
+            {
+              "name": "Server.ListenAndServeTLS"
+            },
+            {
+              "name": "Server.Serve"
+            },
+            {
+              "name": "Server.ServeTLS"
+            }
+          ],
+          "defaultStatus": "unaffected"
+        }
+      ],
+      "problemTypes": [
+        {
+          "descriptions": [
+            {
+              "lang": "en",
+              "description": "CWE-770: Allocation of Resources Without Limits or Throttling"
+            }
+          ]
+        }
+      ],
+      "references": [
+        {
+          "url": "https://go.dev/issue/80205"
+        },
+        {
+          "url": "https://go.dev/cl/795540"
+        },
+        {
+          "url": "https://groups.google.com/g/golang-announce/c/94pEornpRlI"
+        },
+        {
+          "url": "https://pkg.go.dev/vuln/GO-2026-6089"
+        }
+      ]
+    }
+  }
+}
\ No newline at end of file
diff --git a/data/cve/v5/GO-2026-6090.json b/data/cve/v5/GO-2026-6090.json
new file mode 100644
index 0000000..f5fa0eb
--- /dev/null
+++ b/data/cve/v5/GO-2026-6090.json
@@ -0,0 +1,115 @@
+{
+  "dataType": "CVE_RECORD",
+  "dataVersion": "5.0",
+  "cveMetadata": {
+    "cveId": "CVE-2026-56862"
+  },
+  "containers": {
+    "cna": {
+      "providerMetadata": {
+        "orgId": "1bb62c36-49e3-4200-9d77-64a1400537cc"
+      },
+      "title": "Limit handshake messages we are willing to accept post-handshake in crypto/tls",
+      "descriptions": [
+        {
+          "lang": "en",
+          "value": "Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been completed or not. As a result, a malicious client can keep sending KeyUpdate messages to force the server to keep performing key derivation operations indefinitely."
+        }
+      ],
+      "affected": [
+        {
+          "vendor": "Go standard library",
+          "product": "crypto/tls",
+          "collectionURL": "https://pkg.go.dev",
+          "packageName": "crypto/tls",
+          "versions": [
+            {
+              "version": "0",
+              "lessThan": "1.25.13",
+              "status": "affected",
+              "versionType": "semver"
+            },
+            {
+              "version": "1.26.0-0",
+              "lessThan": "1.26.6",
+              "status": "affected",
+              "versionType": "semver"
+            },
+            {
+              "version": "1.27.0-0",
+              "lessThan": "1.27.0-rc.3",
+              "status": "affected",
+              "versionType": "semver"
+            }
+          ],
+          "programRoutines": [
+            {
+              "name": "Conn.readRecordOrCCS"
+            },
+            {
+              "name": "Conn.Handshake"
+            },
+            {
+              "name": "Conn.HandshakeContext"
+            },
+            {
+              "name": "Conn.Read"
+            },
+            {
+              "name": "Conn.Write"
+            },
+            {
+              "name": "Dial"
+            },
+            {
+              "name": "DialWithDialer"
+            },
+            {
+              "name": "Dialer.Dial"
+            },
+            {
+              "name": "Dialer.DialContext"
+            },
+            {
+              "name": "QUICConn.HandleData"
+            },
+            {
+              "name": "QUICConn.Start"
+            }
+          ],
+          "defaultStatus": "unaffected"
+        }
+      ],
+      "problemTypes": [
+        {
+          "descriptions": [
+            {
+              "lang": "en",
+              "description": "CWE-770: Allocation of Resources Without Limits or Throttling"
+            }
+          ]
+        }
+      ],
+      "references": [
+        {
+          "url": "https://go.dev/issue/80528"
+        },
+        {
+          "url": "https://go.dev/cl/804261"
+        },
+        {
+          "url": "https://groups.google.com/g/golang-announce/c/94pEornpRlI"
+        },
+        {
+          "url": "https://pkg.go.dev/vuln/GO-2026-6090"
+        }
+      ],
+      "credits": [
+        {
+          "lang": "en",
+          "value": "Qi Deng of Aurascape.ai"
+        }
+      ]
+    }
+  }
+}
\ No newline at end of file
diff --git a/data/cve/v5/GO-2026-6091.json b/data/cve/v5/GO-2026-6091.json
new file mode 100644
index 0000000..1f1d606
--- /dev/null
+++ b/data/cve/v5/GO-2026-6091.json
@@ -0,0 +1,91 @@
+{
+  "dataType": "CVE_RECORD",
+  "dataVersion": "5.0",
+  "cveMetadata": {
+    "cveId": "CVE-2026-56858"
+  },
+  "containers": {
+    "cna": {
+      "providerMetadata": {
+        "orgId": "1bb62c36-49e3-4200-9d77-64a1400537cc"
+      },
+      "title": "Fix Javascript regexp context tracking in html/template",
+      "descriptions": [
+        {
+          "lang": "en",
+          "value": "Previously, pathological inputs could close an unescaped '/' early, allowing for attack-controlled data to inject arbitrary content, potentially leading to XSS."
+        }
+      ],
+      "affected": [
+        {
+          "vendor": "Go standard library",
+          "product": "html/template",
+          "collectionURL": "https://pkg.go.dev",
+          "packageName": "html/template",
+          "versions": [
+            {
+              "version": "0",
+              "lessThan": "1.25.13",
+              "status": "affected",
+              "versionType": "semver"
+            },
+            {
+              "version": "1.26.0-0",
+              "lessThan": "1.26.6",
+              "status": "affected",
+              "versionType": "semver"
+            },
+            {
+              "version": "1.27.0-0",
+              "lessThan": "1.27.0-rc.3",
+              "status": "affected",
+              "versionType": "semver"
+            }
+          ],
+          "programRoutines": [
+            {
+              "name": "tJS"
+            },
+            {
+              "name": "Template.Execute"
+            },
+            {
+              "name": "Template.ExecuteTemplate"
+            }
+          ],
+          "defaultStatus": "unaffected"
+        }
+      ],
+      "problemTypes": [
+        {
+          "descriptions": [
+            {
+              "lang": "en",
+              "description": "CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')"
+            }
+          ]
+        }
+      ],
+      "references": [
+        {
+          "url": "https://go.dev/issue/80435"
+        },
+        {
+          "url": "https://go.dev/cl/807100"
+        },
+        {
+          "url": "https://groups.google.com/g/golang-announce/c/94pEornpRlI"
+        },
+        {
+          "url": "https://pkg.go.dev/vuln/GO-2026-6091"
+        }
+      ],
+      "credits": [
+        {
+          "lang": "en",
+          "value": "Ali Sherif"
+        }
+      ]
+    }
+  }
+}
\ No newline at end of file
diff --git a/data/cve/v5/GO-2026-6179.json b/data/cve/v5/GO-2026-6179.json
new file mode 100644
index 0000000..e098da7
--- /dev/null
+++ b/data/cve/v5/GO-2026-6179.json
@@ -0,0 +1,103 @@
+{
+  "dataType": "CVE_RECORD",
+  "dataVersion": "5.0",
+  "cveMetadata": {
+    "cveId": "CVE-2026-56865"
+  },
+  "containers": {
+    "cna": {
+      "providerMetadata": {
+        "orgId": "1bb62c36-49e3-4200-9d77-64a1400537cc"
+      },
+      "title": "Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog",
+      "descriptions": [
+        {
+          "lang": "en",
+          "value": "A malicious GOPROXY was previously capable of forging up to two sumdb tiles that allow for a requested module to bypass the GOSUMDB check and persist attacker-controlled module content to a local Go module cache. This attack allows for a malicious GOPROXY to serve malicious module content that cannot be detected by evaluating the transparency log. All tiles are now correctly verified against their parents. In order to determine if you have been affected:   rm -r go.sum go.work.sum vendor/ \u0026\u0026 go mod tidy"
+        }
+      ],
+      "affected": [
+        {
+          "vendor": "Go toolchain",
+          "product": "cmd/go",
+          "collectionURL": "https://pkg.go.dev",
+          "packageName": "cmd/go",
+          "versions": [
+            {
+              "version": "0",
+              "lessThan": "1.25.13",
+              "status": "affected",
+              "versionType": "semver"
+            },
+            {
+              "version": "1.26.0-0",
+              "lessThan": "1.26.6",
+              "status": "affected",
+              "versionType": "semver"
+            },
+            {
+              "version": "1.27.0-0",
+              "lessThan": "1.27.0-rc.3",
+              "status": "affected",
+              "versionType": "semver"
+            }
+          ],
+          "defaultStatus": "unaffected"
+        },
+        {
+          "vendor": "golang.org/x/mod",
+          "product": "golang.org/x/mod/sumdb/tlog",
+          "collectionURL": "https://pkg.go.dev",
+          "packageName": "golang.org/x/mod/sumdb/tlog",
+          "versions": [
+            {
+              "version": "0",
+              "lessThan": "0.40.0",
+              "status": "affected",
+              "versionType": "semver"
+            }
+          ],
+          "programRoutines": [
+            {
+              "name": "tileHashReader.ReadHashes"
+            }
+          ],
+          "defaultStatus": "unaffected"
+        }
+      ],
+      "problemTypes": [
+        {
+          "descriptions": [
+            {
+              "lang": "en",
+              "description": "CWE-347: Improper Verification of Cryptographic Signature"
+            }
+          ]
+        }
+      ],
+      "references": [
+        {
+          "url": "https://go.dev/issue/80744"
+        },
+        {
+          "url": "https://groups.google.com/g/golang-announce/c/94pEornpRlI"
+        },
+        {
+          "url": "https://go.dev/cl/814960"
+        },
+        {
+          "url": "https://go.dev/cl/815020"
+        },
+        {
+          "url": "https://pkg.go.dev/vuln/GO-2026-6179"
+        }
+      ],
+      "credits": [
+        {
+          "lang": "en",
+          "value": "Filippo Valsorda (Geomys)"
+        }
+      ]
+    }
+  }
+}
\ No newline at end of file
diff --git a/data/cve/v5/GO-2026-6180.json b/data/cve/v5/GO-2026-6180.json
new file mode 100644
index 0000000..429b2c0
--- /dev/null
+++ b/data/cve/v5/GO-2026-6180.json
@@ -0,0 +1,103 @@
+{
+  "dataType": "CVE_RECORD",
+  "dataVersion": "5.0",
+  "cveMetadata": {
+    "cveId": "CVE-2026-56864"
+  },
+  "containers": {
+    "cna": {
+      "providerMetadata": {
+        "orgId": "1bb62c36-49e3-4200-9d77-64a1400537cc"
+      },
+      "title": "Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb",
+      "descriptions": [
+        {
+          "lang": "en",
+          "value": "A malicious GOSUMDB was capable of serving arbitrary module content not contained within the transparency log. This attack allows for a coordinating GOPROXY and GOSUMDB to serve a client malicious module content that cannot be detected by evaluating the transparency log. In order to determine if you have been affected:   rm -r go.sum go.work.sum vendor/ \u0026\u0026 go mod tidy"
+        }
+      ],
+      "affected": [
+        {
+          "vendor": "Go toolchain",
+          "product": "cmd/go",
+          "collectionURL": "https://pkg.go.dev",
+          "packageName": "cmd/go",
+          "versions": [
+            {
+              "version": "0",
+              "lessThan": "1.25.13",
+              "status": "affected",
+              "versionType": "semver"
+            },
+            {
+              "version": "1.26.0-0",
+              "lessThan": "1.26.6",
+              "status": "affected",
+              "versionType": "semver"
+            },
+            {
+              "version": "1.27.0-0",
+              "lessThan": "1.27.0-rc.3",
+              "status": "affected",
+              "versionType": "semver"
+            }
+          ],
+          "defaultStatus": "unaffected"
+        },
+        {
+          "vendor": "golang.org/x/mod",
+          "product": "golang.org/x/mod/sumdb",
+          "collectionURL": "https://pkg.go.dev",
+          "packageName": "golang.org/x/mod/sumdb",
+          "versions": [
+            {
+              "version": "0",
+              "lessThan": "0.40.0",
+              "status": "affected",
+              "versionType": "semver"
+            }
+          ],
+          "programRoutines": [
+            {
+              "name": "Client.Lookup"
+            }
+          ],
+          "defaultStatus": "unaffected"
+        }
+      ],
+      "problemTypes": [
+        {
+          "descriptions": [
+            {
+              "lang": "en",
+              "description": "CWE-347: Improper Verification of Cryptographic Signature"
+            }
+          ]
+        }
+      ],
+      "references": [
+        {
+          "url": "https://go.dev/issue/80745"
+        },
+        {
+          "url": "https://groups.google.com/g/golang-announce/c/94pEornpRlI"
+        },
+        {
+          "url": "https://go.dev/cl/815000"
+        },
+        {
+          "url": "https://go.dev/cl/815020"
+        },
+        {
+          "url": "https://pkg.go.dev/vuln/GO-2026-6180"
+        }
+      ],
+      "credits": [
+        {
+          "lang": "en",
+          "value": "mundur"
+        }
+      ]
+    }
+  }
+}
\ No newline at end of file
diff --git a/data/cve/v5/GO-2026-6218.json b/data/cve/v5/GO-2026-6218.json
new file mode 100644
index 0000000..e97f202
--- /dev/null
+++ b/data/cve/v5/GO-2026-6218.json
@@ -0,0 +1,85 @@
+{
+  "dataType": "CVE_RECORD",
+  "dataVersion": "5.0",
+  "cveMetadata": {
+    "cveId": "CVE-2026-56860"
+  },
+  "containers": {
+    "cna": {
+      "providerMetadata": {
+        "orgId": "1bb62c36-49e3-4200-9d77-64a1400537cc"
+      },
+      "title": "Avoid quadratic complexity in resolvePath in net/url",
+      "descriptions": [
+        {
+          "lang": "en",
+          "value": "Previously, resolving relative paths containing parent directory ('..') segments performed string conversions and buffer rewrites on each step, resulting in quadratic time complexity and high memory allocation overhead. Now, path resolution operates on a byte buffer using index-based backtracking for '..' segments, eliminating the quadratic time complexity and significantly reducing memory allocations."
+        }
+      ],
+      "affected": [
+        {
+          "vendor": "Go standard library",
+          "product": "net/url",
+          "collectionURL": "https://pkg.go.dev",
+          "packageName": "net/url",
+          "versions": [
+            {
+              "version": "0",
+              "lessThan": "1.25.13",
+              "status": "affected",
+              "versionType": "semver"
+            },
+            {
+              "version": "1.26.0-0",
+              "lessThan": "1.26.6",
+              "status": "affected",
+              "versionType": "semver"
+            },
+            {
+              "version": "1.27.0-0",
+              "lessThan": "1.27.0-rc.3",
+              "status": "affected",
+              "versionType": "semver"
+            }
+          ],
+          "programRoutines": [
+            {
+              "name": "resolvePath"
+            },
+            {
+              "name": "URL.Parse"
+            },
+            {
+              "name": "URL.ResolveReference"
+            }
+          ],
+          "defaultStatus": "unaffected"
+        }
+      ],
+      "problemTypes": [
+        {
+          "descriptions": [
+            {
+              "lang": "en",
+              "description": "CWE-407: Inefficient Algorithmic Complexity"
+            }
+          ]
+        }
+      ],
+      "references": [
+        {
+          "url": "https://go.dev/cl/803681"
+        },
+        {
+          "url": "https://go.dev/issue/80494"
+        },
+        {
+          "url": "https://groups.google.com/g/golang-announce/c/94pEornpRlI"
+        },
+        {
+          "url": "https://pkg.go.dev/vuln/GO-2026-6218"
+        }
+      ]
+    }
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-5026.json b/data/osv/GO-2026-5026.json
index e854bdc..6b1f0de 100644
--- a/data/osv/GO-2026-5026.json
+++ b/data/osv/GO-2026-5026.json
@@ -11,6 +11,75 @@
   "affected": [
     {
       "package": {
+        "name": "stdlib",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "1.25.13"
+            },
+            {
+              "introduced": "1.26.0-0"
+            },
+            {
+              "fixed": "1.26.6"
+            },
+            {
+              "introduced": "1.27.0-0"
+            },
+            {
+              "fixed": "1.27.0-rc.3"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {
+        "imports": [
+          {
+            "path": "net/http",
+            "symbols": [
+              "Client.CloseIdleConnections",
+              "Client.Do",
+              "Client.Get",
+              "Client.Head",
+              "Client.Post",
+              "Client.PostForm",
+              "ClientConn.Close",
+              "ClientConn.RoundTrip",
+              "Get",
+              "Head",
+              "Post",
+              "PostForm",
+              "Transport.CloseIdleConnections",
+              "Transport.NewClientConn",
+              "Transport.RoundTrip",
+              "http1ClientConn.Close",
+              "http1ClientConn.RoundTrip",
+              "http2ClientConn.RoundTrip",
+              "http2RoundTripper.RoundTrip",
+              "idnaASCII"
+            ]
+          },
+          {
+            "path": "net/http/internal/http2",
+            "symbols": [
+              "Transport.AddConn",
+              "Transport.RoundTrip",
+              "Transport.RoundTripOpt",
+              "authorityAddr"
+            ]
+          }
+        ]
+      }
+    },
+    {
+      "package": {
         "name": "golang.org/x/net",
         "ecosystem": "Go"
       },
@@ -55,6 +124,10 @@
     {
       "type": "WEB",
       "url": "https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8"
+    },
+    {
+      "type": "WEB",
+      "url": "https://groups.google.com/g/golang-announce/c/94pEornpRlI"
     }
   ],
   "credits": [
diff --git a/data/osv/GO-2026-5942.json b/data/osv/GO-2026-5942.json
index 82710d1..39bd49b 100644
--- a/data/osv/GO-2026-5942.json
+++ b/data/osv/GO-2026-5942.json
@@ -11,6 +11,43 @@
   "affected": [
     {
       "package": {
+        "name": "stdlib",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "1.26.6"
+            },
+            {
+              "introduced": "1.27.0-0"
+            },
+            {
+              "fixed": "1.27.0-rc.3"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {
+        "imports": [
+          {
+            "path": "net",
+            "symbols": [
+              "LookupCNAME",
+              "Resolver.LookupCNAME",
+              "cgoResSearch"
+            ]
+          }
+        ]
+      }
+    },
+    {
+      "package": {
         "name": "golang.org/x/net",
         "ecosystem": "Go"
       },
@@ -56,6 +93,10 @@
     {
       "type": "REPORT",
       "url": "https://go.dev/issue/79795"
+    },
+    {
+      "type": "WEB",
+      "url": "https://groups.google.com/g/golang-announce/c/94pEornpRlI"
     }
   ],
   "credits": [
diff --git a/data/osv/GO-2026-5972.json b/data/osv/GO-2026-5972.json
new file mode 100644
index 0000000..ac4d970
--- /dev/null
+++ b/data/osv/GO-2026-5972.json
@@ -0,0 +1,80 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-5972",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-33818"
+  ],
+  "summary": "Enforce maximum recursion depth in encoding/asn1",
+  "details": "Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures.",
+  "affected": [
+    {
+      "package": {
+        "name": "stdlib",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "1.25.13"
+            },
+            {
+              "introduced": "1.26.0-0"
+            },
+            {
+              "fixed": "1.26.6"
+            },
+            {
+              "introduced": "1.27.0-0"
+            },
+            {
+              "fixed": "1.27.0-rc.3"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {
+        "imports": [
+          {
+            "path": "encoding/asn1",
+            "symbols": [
+              "Unmarshal",
+              "UnmarshalWithParams",
+              "parseField",
+              "parseSequenceOf"
+            ]
+          }
+        ]
+      }
+    }
+  ],
+  "references": [
+    {
+      "type": "REPORT",
+      "url": "https://go.dev/issue/80405"
+    },
+    {
+      "type": "WEB",
+      "url": "https://groups.google.com/g/golang-announce/c/94pEornpRlI"
+    },
+    {
+      "type": "FIX",
+      "url": "https://go.dev/cl/814980"
+    }
+  ],
+  "credits": [
+    {
+      "name": "Marwan Atia (marwansamir688@gmail.com) "
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-5972",
+    "review_status": "REVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6088.json b/data/osv/GO-2026-6088.json
new file mode 100644
index 0000000..de28d37
--- /dev/null
+++ b/data/osv/GO-2026-6088.json
@@ -0,0 +1,81 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6088",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-56859"
+  ],
+  "summary": "Add recursion depth guard during decode in encoding/xml",
+  "details": "Previously, DecodeElement would reset the depth counter causing it to never fire; this could lead to stack exhaustion.",
+  "affected": [
+    {
+      "package": {
+        "name": "stdlib",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "1.25.13"
+            },
+            {
+              "introduced": "1.26.0-0"
+            },
+            {
+              "fixed": "1.26.6"
+            },
+            {
+              "introduced": "1.27.0-0"
+            },
+            {
+              "fixed": "1.27.0-rc.3"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {
+        "imports": [
+          {
+            "path": "encoding/xml",
+            "symbols": [
+              "Decoder.Decode",
+              "Decoder.DecodeElement",
+              "Decoder.RawToken",
+              "Decoder.Skip",
+              "Decoder.Token",
+              "Decoder.pop",
+              "Decoder.push",
+              "Decoder.unmarshal",
+              "Decoder.unmarshalPath",
+              "Unmarshal"
+            ]
+          }
+        ]
+      }
+    }
+  ],
+  "references": [
+    {
+      "type": "REPORT",
+      "url": "https://go.dev/issue/80481"
+    },
+    {
+      "type": "FIX",
+      "url": "https://go.dev/cl/803320"
+    },
+    {
+      "type": "WEB",
+      "url": "https://groups.google.com/g/golang-announce/c/94pEornpRlI"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6088",
+    "review_status": "REVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6089.json b/data/osv/GO-2026-6089.json
new file mode 100644
index 0000000..eac0d71
--- /dev/null
+++ b/data/osv/GO-2026-6089.json
@@ -0,0 +1,81 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6089",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-56853"
+  ],
+  "summary": "Apply ReadHeaderTimeout when doing unencrypted HTTP/2 check in net/http",
+  "details": "When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client preface. ReadHeaderTimeout is unexpectedly not being applied when doing this.",
+  "affected": [
+    {
+      "package": {
+        "name": "stdlib",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "1.25.13"
+            },
+            {
+              "introduced": "1.26.0-0"
+            },
+            {
+              "fixed": "1.26.6"
+            },
+            {
+              "introduced": "1.27.0-0"
+            },
+            {
+              "fixed": "1.27.0-rc.3"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {
+        "imports": [
+          {
+            "path": "net/http",
+            "symbols": [
+              "ListenAndServe",
+              "ListenAndServeTLS",
+              "Serve",
+              "ServeTLS",
+              "Server.ListenAndServe",
+              "Server.ListenAndServeTLS",
+              "Server.Serve",
+              "Server.ServeTLS",
+              "conn.readRequest",
+              "conn.serve"
+            ]
+          }
+        ]
+      }
+    }
+  ],
+  "references": [
+    {
+      "type": "REPORT",
+      "url": "https://go.dev/issue/80205"
+    },
+    {
+      "type": "FIX",
+      "url": "https://go.dev/cl/795540"
+    },
+    {
+      "type": "WEB",
+      "url": "https://groups.google.com/g/golang-announce/c/94pEornpRlI"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6089",
+    "review_status": "REVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6090.json b/data/osv/GO-2026-6090.json
new file mode 100644
index 0000000..ca54051
--- /dev/null
+++ b/data/osv/GO-2026-6090.json
@@ -0,0 +1,87 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6090",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-56862"
+  ],
+  "summary": "Limit handshake messages we are willing to accept post-handshake in crypto/tls",
+  "details": "Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been completed or not. As a result, a malicious client can keep sending KeyUpdate messages to force the server to keep performing key derivation operations indefinitely.",
+  "affected": [
+    {
+      "package": {
+        "name": "stdlib",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "1.25.13"
+            },
+            {
+              "introduced": "1.26.0-0"
+            },
+            {
+              "fixed": "1.26.6"
+            },
+            {
+              "introduced": "1.27.0-0"
+            },
+            {
+              "fixed": "1.27.0-rc.3"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {
+        "imports": [
+          {
+            "path": "crypto/tls",
+            "symbols": [
+              "Conn.Handshake",
+              "Conn.HandshakeContext",
+              "Conn.Read",
+              "Conn.Write",
+              "Conn.readRecordOrCCS",
+              "Dial",
+              "DialWithDialer",
+              "Dialer.Dial",
+              "Dialer.DialContext",
+              "QUICConn.HandleData",
+              "QUICConn.Start"
+            ]
+          }
+        ]
+      }
+    }
+  ],
+  "references": [
+    {
+      "type": "REPORT",
+      "url": "https://go.dev/issue/80528"
+    },
+    {
+      "type": "FIX",
+      "url": "https://go.dev/cl/804261"
+    },
+    {
+      "type": "WEB",
+      "url": "https://groups.google.com/g/golang-announce/c/94pEornpRlI"
+    }
+  ],
+  "credits": [
+    {
+      "name": "Qi Deng of Aurascape.ai"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6090",
+    "review_status": "REVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6091.json b/data/osv/GO-2026-6091.json
new file mode 100644
index 0000000..11025a2
--- /dev/null
+++ b/data/osv/GO-2026-6091.json
@@ -0,0 +1,79 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6091",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-56858"
+  ],
+  "summary": "Fix Javascript regexp context tracking in html/template",
+  "details": "Previously, pathological inputs could close an unescaped '/' early, allowing for attack-controlled data to inject arbitrary content, potentially leading to XSS.",
+  "affected": [
+    {
+      "package": {
+        "name": "stdlib",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "1.25.13"
+            },
+            {
+              "introduced": "1.26.0-0"
+            },
+            {
+              "fixed": "1.26.6"
+            },
+            {
+              "introduced": "1.27.0-0"
+            },
+            {
+              "fixed": "1.27.0-rc.3"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {
+        "imports": [
+          {
+            "path": "html/template",
+            "symbols": [
+              "Template.Execute",
+              "Template.ExecuteTemplate",
+              "tJS"
+            ]
+          }
+        ]
+      }
+    }
+  ],
+  "references": [
+    {
+      "type": "REPORT",
+      "url": "https://go.dev/issue/80435"
+    },
+    {
+      "type": "FIX",
+      "url": "https://go.dev/cl/807100"
+    },
+    {
+      "type": "WEB",
+      "url": "https://groups.google.com/g/golang-announce/c/94pEornpRlI"
+    }
+  ],
+  "credits": [
+    {
+      "name": "Ali Sherif"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6091",
+    "review_status": "REVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6179.json b/data/osv/GO-2026-6179.json
new file mode 100644
index 0000000..9350972
--- /dev/null
+++ b/data/osv/GO-2026-6179.json
@@ -0,0 +1,107 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6179",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-56865"
+  ],
+  "summary": "Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog",
+  "details": "A malicious GOPROXY was previously capable of forging up to two sumdb tiles that allow for a requested module to bypass the GOSUMDB check and persist attacker-controlled module content to a local Go module cache.\n\nThis attack allows for a malicious GOPROXY to serve malicious module content that cannot be detected by evaluating the transparency log.\n\nAll tiles are now correctly verified against their parents.\n\nIn order to determine if you have been affected:\n\nrm -r go.sum go.work.sum vendor/ \u0026\u0026 go mod tidy",
+  "affected": [
+    {
+      "package": {
+        "name": "toolchain",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "1.25.13"
+            },
+            {
+              "introduced": "1.26.0-0"
+            },
+            {
+              "fixed": "1.26.6"
+            },
+            {
+              "introduced": "1.27.0-0"
+            },
+            {
+              "fixed": "1.27.0-rc.3"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {
+        "imports": [
+          {
+            "path": "cmd/go"
+          }
+        ]
+      }
+    },
+    {
+      "package": {
+        "name": "golang.org/x/mod",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "0.40.0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {
+        "imports": [
+          {
+            "path": "golang.org/x/mod/sumdb/tlog",
+            "symbols": [
+              "tileHashReader.ReadHashes"
+            ]
+          }
+        ]
+      }
+    }
+  ],
+  "references": [
+    {
+      "type": "REPORT",
+      "url": "https://go.dev/issue/80744"
+    },
+    {
+      "type": "WEB",
+      "url": "https://groups.google.com/g/golang-announce/c/94pEornpRlI"
+    },
+    {
+      "type": "FIX",
+      "url": "https://go.dev/cl/814960"
+    },
+    {
+      "type": "FIX",
+      "url": "https://go.dev/cl/815020"
+    }
+  ],
+  "credits": [
+    {
+      "name": "Filippo Valsorda (Geomys)"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6179",
+    "review_status": "REVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6180.json b/data/osv/GO-2026-6180.json
new file mode 100644
index 0000000..05b1be8
--- /dev/null
+++ b/data/osv/GO-2026-6180.json
@@ -0,0 +1,107 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6180",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-56864"
+  ],
+  "summary": "Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb",
+  "details": "A malicious GOSUMDB was capable of serving arbitrary module content not contained within the transparency log.\n\nThis attack allows for a coordinating GOPROXY and GOSUMDB to serve a client malicious module content that cannot be detected by evaluating the transparency log.\n\nIn order to determine if you have been affected:\n\nrm -r go.sum go.work.sum vendor/ \u0026\u0026 go mod tidy",
+  "affected": [
+    {
+      "package": {
+        "name": "toolchain",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "1.25.13"
+            },
+            {
+              "introduced": "1.26.0-0"
+            },
+            {
+              "fixed": "1.26.6"
+            },
+            {
+              "introduced": "1.27.0-0"
+            },
+            {
+              "fixed": "1.27.0-rc.3"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {
+        "imports": [
+          {
+            "path": "cmd/go"
+          }
+        ]
+      }
+    },
+    {
+      "package": {
+        "name": "golang.org/x/mod",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "0.40.0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {
+        "imports": [
+          {
+            "path": "golang.org/x/mod/sumdb",
+            "symbols": [
+              "Client.Lookup"
+            ]
+          }
+        ]
+      }
+    }
+  ],
+  "references": [
+    {
+      "type": "REPORT",
+      "url": "https://go.dev/issue/80745"
+    },
+    {
+      "type": "WEB",
+      "url": "https://groups.google.com/g/golang-announce/c/94pEornpRlI"
+    },
+    {
+      "type": "FIX",
+      "url": "https://go.dev/cl/815000"
+    },
+    {
+      "type": "FIX",
+      "url": "https://go.dev/cl/815020"
+    }
+  ],
+  "credits": [
+    {
+      "name": "mundur"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6180",
+    "review_status": "REVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6218.json b/data/osv/GO-2026-6218.json
new file mode 100644
index 0000000..a00c528
--- /dev/null
+++ b/data/osv/GO-2026-6218.json
@@ -0,0 +1,74 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6218",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-56860"
+  ],
+  "summary": "Avoid quadratic complexity in resolvePath in net/url",
+  "details": "Previously, resolving relative paths containing parent directory ('..') segments performed string conversions and buffer rewrites on each step, resulting in quadratic time complexity and high memory allocation overhead.\n\nNow, path resolution operates on a byte buffer using index-based backtracking for '..' segments, eliminating the quadratic time complexity and significantly reducing memory allocations.",
+  "affected": [
+    {
+      "package": {
+        "name": "stdlib",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "1.25.13"
+            },
+            {
+              "introduced": "1.26.0-0"
+            },
+            {
+              "fixed": "1.26.6"
+            },
+            {
+              "introduced": "1.27.0-0"
+            },
+            {
+              "fixed": "1.27.0-rc.3"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {
+        "imports": [
+          {
+            "path": "net/url",
+            "symbols": [
+              "URL.Parse",
+              "URL.ResolveReference",
+              "resolvePath"
+            ]
+          }
+        ]
+      }
+    }
+  ],
+  "references": [
+    {
+      "type": "FIX",
+      "url": "https://go.dev/cl/803681"
+    },
+    {
+      "type": "REPORT",
+      "url": "https://go.dev/issue/80494"
+    },
+    {
+      "type": "WEB",
+      "url": "https://groups.google.com/g/golang-announce/c/94pEornpRlI"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6218",
+    "review_status": "REVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/reports/GO-2026-5026.yaml b/data/reports/GO-2026-5026.yaml
index ddc16ee..f8d0bcb 100644
--- a/data/reports/GO-2026-5026.yaml
+++ b/data/reports/GO-2026-5026.yaml
@@ -1,5 +1,44 @@
 id: GO-2026-5026
 modules:
+    - module: std
+      versions:
+        - fixed: 1.25.13
+        - introduced: 1.26.0-0
+        - fixed: 1.26.6
+        - introduced: 1.27.0-0
+        - fixed: 1.27.0-rc.3
+      vulnerable_at: 1.27.0-rc.2
+      packages:
+        - package: net/http
+          symbols:
+            - idnaASCII
+          derived_symbols:
+            - Client.CloseIdleConnections
+            - Client.Do
+            - Client.Get
+            - Client.Head
+            - Client.Post
+            - Client.PostForm
+            - ClientConn.Close
+            - ClientConn.RoundTrip
+            - Get
+            - Head
+            - Post
+            - PostForm
+            - Transport.CloseIdleConnections
+            - Transport.NewClientConn
+            - Transport.RoundTrip
+            - http1ClientConn.Close
+            - http1ClientConn.RoundTrip
+            - http2ClientConn.RoundTrip
+            - http2RoundTripper.RoundTrip
+        - package: net/http/internal/http2
+          symbols:
+            - authorityAddr
+          derived_symbols:
+            - Transport.AddConn
+            - Transport.RoundTrip
+            - Transport.RoundTripOpt
     - module: golang.org/x/net
       versions:
         - fixed: 0.55.0
@@ -32,6 +71,7 @@
     - fix: https://go.dev/cl/767220
     - report: https://go.dev/issue/78760
     - web: https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8
+    - web: https://groups.google.com/g/golang-announce/c/94pEornpRlI
 cve_metadata:
     id: CVE-2026-39821
     cwe: 'CWE-1289: Improper Validation of Unsafe Equivalence in Input'
diff --git a/data/reports/GO-2026-5942.yaml b/data/reports/GO-2026-5942.yaml
index 0994314..ea360c5 100644
--- a/data/reports/GO-2026-5942.yaml
+++ b/data/reports/GO-2026-5942.yaml
@@ -1,5 +1,18 @@
 id: GO-2026-5942
 modules:
+    - module: std
+      versions:
+        - fixed: 1.26.6
+        - introduced: 1.27.0-0
+        - fixed: 1.27.0-rc.3
+      vulnerable_at: 1.27.0-rc.2
+      packages:
+        - package: net
+          symbols:
+            - cgoResSearch
+          derived_symbols:
+            - LookupCNAME
+            - Resolver.LookupCNAME
     - module: golang.org/x/net
       versions:
         - fixed: 0.56.0
@@ -27,6 +40,7 @@
 references:
     - fix: https://go.dev/cl/786345
     - report: https://go.dev/issue/79795
+    - web: https://groups.google.com/g/golang-announce/c/94pEornpRlI
 cve_metadata:
     id: CVE-2026-46600
     cwe: 'CWE-125: Out-of-bounds Read'
diff --git a/data/reports/GO-2026-5972.yaml b/data/reports/GO-2026-5972.yaml
new file mode 100644
index 0000000..0353964
--- /dev/null
+++ b/data/reports/GO-2026-5972.yaml
@@ -0,0 +1,34 @@
+id: GO-2026-5972
+modules:
+    - module: std
+      versions:
+        - fixed: 1.25.13
+        - introduced: 1.26.0-0
+        - fixed: 1.26.6
+        - introduced: 1.27.0-0
+        - fixed: 1.27.0-rc.3
+      vulnerable_at: 1.27.0-rc.2
+      packages:
+        - package: encoding/asn1
+          symbols:
+            - parseSequenceOf
+            - parseField
+            - UnmarshalWithParams
+          derived_symbols:
+            - Unmarshal
+summary: Enforce maximum recursion depth in encoding/asn1
+description: |
+    Enforce a recursion limit in Unmarshal to prevent stack exhaustion
+    when parsing deeply-nested, recursive structures.
+credits:
+    - 'Marwan Atia (marwansamir688@gmail.com) '
+references:
+    - report: https://go.dev/issue/80405
+    - web: https://groups.google.com/g/golang-announce/c/94pEornpRlI
+    - fix: https://go.dev/cl/814980
+cve_metadata:
+    id: CVE-2026-33818
+    cwe: 'CWE-400: Uncontrolled Resource Consumption'
+source:
+    id: go-security-team
+review_status: REVIEWED
diff --git a/data/reports/GO-2026-6088.yaml b/data/reports/GO-2026-6088.yaml
new file mode 100644
index 0000000..82710a1
--- /dev/null
+++ b/data/reports/GO-2026-6088.yaml
@@ -0,0 +1,39 @@
+id: GO-2026-6088
+modules:
+    - module: std
+      versions:
+        - fixed: 1.25.13
+        - introduced: 1.26.0-0
+        - fixed: 1.26.6
+        - introduced: 1.27.0-0
+        - fixed: 1.27.0-rc.3
+      vulnerable_at: 1.27.0-rc.2
+      packages:
+        - package: encoding/xml
+          symbols:
+            - Decoder.push
+            - Decoder.pop
+            - Decoder.RawToken
+            - Decoder.unmarshalPath
+            - Decoder.unmarshal
+          derived_symbols:
+            - Decoder.Decode
+            - Decoder.DecodeElement
+            - Decoder.Skip
+            - Decoder.Token
+            - Unmarshal
+summary: Add recursion depth guard during decode in encoding/xml
+description: |
+    Previously, DecodeElement would reset the depth counter
+    causing it to never fire; this could lead to stack
+    exhaustion.
+references:
+    - report: https://go.dev/issue/80481
+    - fix: https://go.dev/cl/803320
+    - web: https://groups.google.com/g/golang-announce/c/94pEornpRlI
+cve_metadata:
+    id: CVE-2026-56859
+    cwe: 'CWE-770: Allocation of Resources Without Limits or Throttling'
+source:
+    id: go-security-team
+review_status: REVIEWED
diff --git a/data/reports/GO-2026-6089.yaml b/data/reports/GO-2026-6089.yaml
new file mode 100644
index 0000000..e5fb72a
--- /dev/null
+++ b/data/reports/GO-2026-6089.yaml
@@ -0,0 +1,40 @@
+id: GO-2026-6089
+modules:
+    - module: std
+      versions:
+        - fixed: 1.25.13
+        - introduced: 1.26.0-0
+        - fixed: 1.26.6
+        - introduced: 1.27.0-0
+        - fixed: 1.27.0-rc.3
+      vulnerable_at: 1.27.0-rc.2
+      packages:
+        - package: net/http
+          symbols:
+            - conn.readRequest
+            - conn.serve
+          derived_symbols:
+            - ListenAndServe
+            - ListenAndServeTLS
+            - Serve
+            - ServeTLS
+            - Server.ListenAndServe
+            - Server.ListenAndServeTLS
+            - Server.Serve
+            - Server.ServeTLS
+summary: Apply ReadHeaderTimeout when doing unencrypted HTTP/2 check in net/http
+description: |
+    When a server is configured to support unencrypted HTTP/2, it reads a
+    few bytes from each new connection to see if they contain the HTTP/2
+    client preface. ReadHeaderTimeout is unexpectedly not being applied
+    when doing this.
+references:
+    - report: https://go.dev/issue/80205
+    - fix: https://go.dev/cl/795540
+    - web: https://groups.google.com/g/golang-announce/c/94pEornpRlI
+cve_metadata:
+    id: CVE-2026-56853
+    cwe: 'CWE-770: Allocation of Resources Without Limits or Throttling'
+source:
+    id: go-security-team
+review_status: REVIEWED
diff --git a/data/reports/GO-2026-6090.yaml b/data/reports/GO-2026-6090.yaml
new file mode 100644
index 0000000..b6703cc
--- /dev/null
+++ b/data/reports/GO-2026-6090.yaml
@@ -0,0 +1,44 @@
+id: GO-2026-6090
+modules:
+    - module: std
+      versions:
+        - fixed: 1.25.13
+        - introduced: 1.26.0-0
+        - fixed: 1.26.6
+        - introduced: 1.27.0-0
+        - fixed: 1.27.0-rc.3
+      vulnerable_at: 1.27.0-rc.2
+      packages:
+        - package: crypto/tls
+          symbols:
+            - Conn.readRecordOrCCS
+          derived_symbols:
+            - Conn.Handshake
+            - Conn.HandshakeContext
+            - Conn.Read
+            - Conn.Write
+            - Dial
+            - DialWithDialer
+            - Dialer.Dial
+            - Dialer.DialContext
+            - QUICConn.HandleData
+            - QUICConn.Start
+summary: Limit handshake messages we are willing to accept post-handshake in crypto/tls
+description: |
+    Handshake messages, such as KeyUpdate, are always considered as
+    state-advancing, regardless of whether a handshake has been completed or
+    not. As a result, a malicious client can keep sending KeyUpdate messages
+    to force the server to keep performing key derivation operations
+    indefinitely.
+credits:
+    - Qi Deng of Aurascape.ai
+references:
+    - report: https://go.dev/issue/80528
+    - fix: https://go.dev/cl/804261
+    - web: https://groups.google.com/g/golang-announce/c/94pEornpRlI
+cve_metadata:
+    id: CVE-2026-56862
+    cwe: 'CWE-770: Allocation of Resources Without Limits or Throttling'
+source:
+    id: go-security-team
+review_status: REVIEWED
diff --git a/data/reports/GO-2026-6091.yaml b/data/reports/GO-2026-6091.yaml
new file mode 100644
index 0000000..e7c2ad1
--- /dev/null
+++ b/data/reports/GO-2026-6091.yaml
@@ -0,0 +1,35 @@
+id: GO-2026-6091
+modules:
+    - module: std
+      versions:
+        - fixed: 1.25.13
+        - introduced: 1.26.0-0
+        - fixed: 1.26.6
+        - introduced: 1.27.0-0
+        - fixed: 1.27.0-rc.3
+      vulnerable_at: 1.27.0-rc.2
+      packages:
+        - package: html/template
+          symbols:
+            - tJS
+          derived_symbols:
+            - Template.Execute
+            - Template.ExecuteTemplate
+summary: Fix Javascript regexp context tracking in html/template
+description: |
+    Previously, pathological inputs could close an
+    unescaped '/' early, allowing for attack-controlled
+    data to inject arbitrary content, potentially
+    leading to XSS.
+credits:
+    - Ali Sherif
+references:
+    - report: https://go.dev/issue/80435
+    - fix: https://go.dev/cl/807100
+    - web: https://groups.google.com/g/golang-announce/c/94pEornpRlI
+cve_metadata:
+    id: CVE-2026-56858
+    cwe: 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site Scripting'')'
+source:
+    id: go-security-team
+review_status: REVIEWED
diff --git a/data/reports/GO-2026-6179.yaml b/data/reports/GO-2026-6179.yaml
new file mode 100644
index 0000000..2f54b16
--- /dev/null
+++ b/data/reports/GO-2026-6179.yaml
@@ -0,0 +1,49 @@
+id: GO-2026-6179
+modules:
+    - module: cmd
+      versions:
+        - fixed: 1.25.13
+        - introduced: 1.26.0-0
+        - fixed: 1.26.6
+        - introduced: 1.27.0-0
+        - fixed: 1.27.0-rc.3
+      vulnerable_at: 1.27.0-rc.2
+      packages:
+        - package: cmd/go
+    - module: golang.org/x/mod
+      versions:
+        - fixed: 0.40.0
+      vulnerable_at: 0.39.0
+      packages:
+        - package: golang.org/x/mod/sumdb/tlog
+          symbols:
+            - tileHashReader.ReadHashes
+summary: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
+description: |
+    A malicious GOPROXY was previously capable of forging
+    up to two sumdb tiles that allow for a requested module
+    to bypass the GOSUMDB check and persist attacker-controlled
+    module content to a local Go module cache.
+
+    This attack allows for a malicious GOPROXY to serve
+    malicious module content that cannot be detected
+    by evaluating the transparency log.
+
+    All tiles are now correctly verified against their parents.
+
+    In order to determine if you have been affected:
+
+      rm -r go.sum go.work.sum vendor/ && go mod tidy
+credits:
+    - Filippo Valsorda (Geomys)
+references:
+    - report: https://go.dev/issue/80744
+    - web: https://groups.google.com/g/golang-announce/c/94pEornpRlI
+    - fix: https://go.dev/cl/814960
+    - fix: https://go.dev/cl/815020
+cve_metadata:
+    id: CVE-2026-56865
+    cwe: 'CWE-347: Improper Verification of Cryptographic Signature'
+source:
+    id: go-security-team
+review_status: REVIEWED
diff --git a/data/reports/GO-2026-6180.yaml b/data/reports/GO-2026-6180.yaml
new file mode 100644
index 0000000..93ff0ee
--- /dev/null
+++ b/data/reports/GO-2026-6180.yaml
@@ -0,0 +1,47 @@
+id: GO-2026-6180
+modules:
+    - module: cmd
+      versions:
+        - fixed: 1.25.13
+        - introduced: 1.26.0-0
+        - fixed: 1.26.6
+        - introduced: 1.27.0-0
+        - fixed: 1.27.0-rc.3
+      vulnerable_at: 1.27.0-rc.2
+      packages:
+        - package: cmd/go
+    - module: golang.org/x/mod
+      versions:
+        - fixed: 0.40.0
+      vulnerable_at: 0.39.0
+      packages:
+        - package: golang.org/x/mod/sumdb
+          symbols:
+            - Client.Lookup
+summary: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
+description: |
+    A malicious GOSUMDB was capable of serving arbitrary
+    module content not contained within the transparency
+    log.
+
+    This attack allows for a coordinating GOPROXY and
+    GOSUMDB to serve a client malicious module content
+    that cannot be detected by evaluating the transparency
+    log.
+
+    In order to determine if you have been affected:
+
+      rm -r go.sum go.work.sum vendor/ && go mod tidy
+credits:
+    - mundur
+references:
+    - report: https://go.dev/issue/80745
+    - web: https://groups.google.com/g/golang-announce/c/94pEornpRlI
+    - fix: https://go.dev/cl/815000
+    - fix: https://go.dev/cl/815020
+cve_metadata:
+    id: CVE-2026-56864
+    cwe: 'CWE-347: Improper Verification of Cryptographic Signature'
+source:
+    id: go-security-team
+review_status: REVIEWED
diff --git a/data/reports/GO-2026-6218.yaml b/data/reports/GO-2026-6218.yaml
new file mode 100644
index 0000000..161bbb7
--- /dev/null
+++ b/data/reports/GO-2026-6218.yaml
@@ -0,0 +1,36 @@
+id: GO-2026-6218
+modules:
+    - module: std
+      versions:
+        - fixed: 1.25.13
+        - introduced: 1.26.0-0
+        - fixed: 1.26.6
+        - introduced: 1.27.0-0
+        - fixed: 1.27.0-rc.3
+      vulnerable_at: 1.27.0-rc.2
+      packages:
+        - package: net/url
+          symbols:
+            - resolvePath
+          derived_symbols:
+            - URL.Parse
+            - URL.ResolveReference
+summary: Avoid quadratic complexity in resolvePath in net/url
+description: |-
+    Previously, resolving relative paths containing parent directory ('..') segments
+    performed string conversions and buffer rewrites on each step, resulting in
+    quadratic time complexity and high memory allocation overhead.
+
+    Now, path resolution operates on a byte buffer using index-based backtracking
+    for '..' segments, eliminating the quadratic time complexity and significantly
+    reducing memory allocations.
+references:
+    - fix: https://go.dev/cl/803681
+    - report: https://go.dev/issue/80494
+    - web: https://groups.google.com/g/golang-announce/c/94pEornpRlI
+cve_metadata:
+    id: CVE-2026-56860
+    cwe: 'CWE-407: Inefficient Algorithmic Complexity'
+source:
+    id: go-security-team
+review_status: REVIEWED