data/reports: review GO-2026-6596 - data/reports/GO-2026-6596.yaml Updates golang/vulndb#6596 Fixes golang/vulndb#6646 Change-Id: I564d6056b8bfb64bf8e36bdaf9fb185f9625445b Reviewed-on: https://go-review.googlesource.com/c/vulndb/+/844945 LUCI-TryBot-Result: golang-scoped@luci-project-accounts.iam.gserviceaccount.com <golang-scoped@luci-project-accounts.iam.gserviceaccount.com> Reviewed-by: Nicholas Husin <nsh@golang.org> Reviewed-by: Nicholas Husin <husin@google.com> Auto-Submit: Ian Alexander <jitsu@google.com>
diff --git a/data/osv/GO-2026-6596.json b/data/osv/GO-2026-6596.json index e677290..27771e6 100644 --- a/data/osv/GO-2026-6596.json +++ b/data/osv/GO-2026-6596.json
@@ -8,7 +8,7 @@ "GHSA-w7c2-w76w-5hmj" ], "summary": "Cilium: Namespaced HTTPRoutes can redirect traffic to other namespaces in github.com/cilium/cilium", - "details": "Cilium: Namespaced HTTPRoutes can redirect traffic to other namespaces in github.com/cilium/cilium.\n\nNOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.\n\n(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)\n\nThe additional affected modules and versions are: github.com/cilium/cilium from v1.18.0 before v1.18.11.", + "details": "Cilium: Namespaced HTTPRoutes can redirect traffic to other namespaces in github.com/cilium/cilium", "affected": [ { "package": { @@ -26,6 +26,12 @@ "fixed": "1.17.17" }, { + "introduced": "1.18.0" + }, + { + "fixed": "1.18.11" + }, + { "introduced": "1.19.0" }, { @@ -35,37 +41,6 @@ } ], "ecosystem_specific": {} - }, - { - "package": { - "name": "github.com/cilium/cilium", - "ecosystem": "Go" - }, - "ranges": [ - { - "type": "SEMVER", - "events": [ - { - "introduced": "0" - } - ] - } - ], - "ecosystem_specific": { - "custom_ranges": [ - { - "type": "ECOSYSTEM", - "events": [ - { - "introduced": "1.18.0" - }, - { - "fixed": "1.18.11" - } - ] - } - ] - } } ], "references": [ @@ -74,10 +49,6 @@ "url": "https://github.com/cilium/cilium/security/advisories/GHSA-w7c2-w76w-5hmj" }, { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56742" - }, - { "type": "FIX", "url": "https://github.com/cilium/cilium/commit/7422068aff67ac77c7dcc57aa5b9240c91333deb" }, @@ -108,6 +79,6 @@ ], "database_specific": { "url": "https://pkg.go.dev/vuln/GO-2026-6596", - "review_status": "UNREVIEWED" + "review_status": "REVIEWED" } } \ No newline at end of file
diff --git a/data/reports/GO-2026-6596.yaml b/data/reports/GO-2026-6596.yaml index f4fa191..1e55ec1 100644 --- a/data/reports/GO-2026-6596.yaml +++ b/data/reports/GO-2026-6596.yaml
@@ -3,13 +3,11 @@ - module: github.com/cilium/cilium versions: - fixed: 1.17.17 + - introduced: 1.18.0 + - fixed: 1.18.11 - introduced: 1.19.0 - fixed: 1.19.5 vulnerable_at: 1.19.4 - - module: github.com/cilium/cilium - non_go_versions: - - introduced: 1.18.0 - - fixed: 1.18.11 summary: |- Cilium: Namespaced HTTPRoutes can redirect traffic to other namespaces in github.com/cilium/cilium @@ -19,7 +17,6 @@ - GHSA-w7c2-w76w-5hmj references: - advisory: https://github.com/cilium/cilium/security/advisories/GHSA-w7c2-w76w-5hmj - - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-56742 - fix: https://github.com/cilium/cilium/commit/7422068aff67ac77c7dcc57aa5b9240c91333deb - fix: https://github.com/cilium/cilium/commit/e0b1cef513ff910323f3743e9f3e3d86721e4857 - fix: https://github.com/cilium/cilium/commit/f23929cff682d6ed0dc158070812cb302fc0032b @@ -27,10 +24,7 @@ - web: https://github.com/cilium/cilium/releases/tag/v1.17.17 - web: https://github.com/cilium/cilium/releases/tag/v1.18.11 - web: https://github.com/cilium/cilium/releases/tag/v1.19.5 -notes: - - lint: 'modules[1] "github.com/cilium/ciliumCilium": module github.com/cilium/ciliumCilium not known to proxy' - - fix: 'github.com/cilium/ciliumCilium: could not add vulnerable_at: module github.com/cilium/ciliumCilium not known to proxy' source: id: GHSA-w7c2-w76w-5hmj created: 2026-09-28T14:03:18.145588-04:00 -review_status: UNREVIEWED +review_status: REVIEWED