data/reports: add GO-2026-6261 - data/reports/GO-2026-6261.yaml Fixes golang/vulndb#6261 Change-Id: Ieca516670b4ac6f61a5121b33529ab36d213bc33 Reviewed-on: https://go-review.googlesource.com/c/vulndb/+/820900 Reviewed-by: Nicholas Husin <husin@google.com> Auto-Submit: Ian Alexander <jitsu@google.com> LUCI-TryBot-Result: golang-scoped@luci-project-accounts.iam.gserviceaccount.com <golang-scoped@luci-project-accounts.iam.gserviceaccount.com> Reviewed-by: Nicholas Husin <nsh@golang.org>
diff --git a/data/osv/GO-2026-6261.json b/data/osv/GO-2026-6261.json new file mode 100644 index 0000000..d6e39cf --- /dev/null +++ b/data/osv/GO-2026-6261.json
@@ -0,0 +1,87 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6261", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-54061", + "GHSA-rrwh-6jrq-wp5v" + ], + "summary": "Dgraph Alpha group stores can be replaced via unauthenticated external snapshot import in github.com/dgraph-io/dgraph", + "details": "Dgraph Alpha exposes the RPCs used for external snapshot import on the public gRPC port without authentication or authorization. An unauthenticated network client can call StreamExtSnapshot and send Badger stream data to replace a target group's store, which drops and replaces the existing database data.", + "affected": [ + { + "package": { + "name": "github.com/dgraph-io/dgraph", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "imports": [ + { + "path": "github.com/dgraph-io/dgraph" + } + ] + } + }, + { + "package": { + "name": "github.com/dgraph-io/dgraph/v25", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "25.3.5" + } + ] + } + ], + "ecosystem_specific": { + "imports": [ + { + "path": "github.com/dgraph-io/dgraph/v25/edgraph", + "symbols": [ + "Server.StreamExtSnapshot", + "Server.UpdateExtSnapshotStreamingState" + ] + }, + { + "path": "github.com/dgraph-io/dgraph/v25/worker", + "symbols": [ + "InStream" + ] + } + ] + } + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/dgraph-io/dgraph/security/advisories/GHSA-rrwh-6jrq-wp5v" + }, + { + "type": "WEB", + "url": "https://github.com/dgraph-io/dgraph/releases/tag/v25.3.5" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6261", + "review_status": "REVIEWED" + } +} \ No newline at end of file
diff --git a/data/reports/GO-2026-6261.yaml b/data/reports/GO-2026-6261.yaml new file mode 100644 index 0000000..19a0239 --- /dev/null +++ b/data/reports/GO-2026-6261.yaml
@@ -0,0 +1,37 @@ +id: GO-2026-6261 +modules: + - module: github.com/dgraph-io/dgraph + vulnerable_at: 1.2.8 + packages: + - package: github.com/dgraph-io/dgraph + - module: github.com/dgraph-io/dgraph/v25 + versions: + - fixed: 25.3.5 + vulnerable_at: 25.3.4 + packages: + - package: github.com/dgraph-io/dgraph/v25/edgraph + symbols: + - Server.StreamExtSnapshot + - Server.UpdateExtSnapshotStreamingState + - package: github.com/dgraph-io/dgraph/v25/worker + symbols: + - InStream +summary: |- + Dgraph Alpha group stores can be replaced via unauthenticated external snapshot + import in github.com/dgraph-io/dgraph +description: |- + Dgraph Alpha exposes the RPCs used for external snapshot import on the public + gRPC port without authentication or authorization. An unauthenticated network + client can call StreamExtSnapshot and send Badger stream data to replace a + target group's store, which drops and replaces the existing database data. +cves: + - CVE-2026-54061 +ghsas: + - GHSA-rrwh-6jrq-wp5v +references: + - advisory: https://github.com/dgraph-io/dgraph/security/advisories/GHSA-rrwh-6jrq-wp5v + - web: https://github.com/dgraph-io/dgraph/releases/tag/v25.3.5 +source: + id: GHSA-rrwh-6jrq-wp5v + created: 2026-08-24T21:22:22.868998-04:00 +review_status: REVIEWED