data/reports: add 43 reports

  - data/reports/GO-2026-6015.yaml
  - data/reports/GO-2026-6016.yaml
  - data/reports/GO-2026-6017.yaml
  - data/reports/GO-2026-6018.yaml
  - data/reports/GO-2026-6019.yaml
  - data/reports/GO-2026-6020.yaml
  - data/reports/GO-2026-6021.yaml
  - data/reports/GO-2026-6022.yaml
  - data/reports/GO-2026-6023.yaml
  - data/reports/GO-2026-6024.yaml
  - data/reports/GO-2026-6025.yaml
  - data/reports/GO-2026-6026.yaml
  - data/reports/GO-2026-6027.yaml
  - data/reports/GO-2026-6028.yaml
  - data/reports/GO-2026-6029.yaml
  - data/reports/GO-2026-6030.yaml
  - data/reports/GO-2026-6031.yaml
  - data/reports/GO-2026-6032.yaml
  - data/reports/GO-2026-6033.yaml
  - data/reports/GO-2026-6034.yaml
  - data/reports/GO-2026-6035.yaml
  - data/reports/GO-2026-6036.yaml
  - data/reports/GO-2026-6037.yaml
  - data/reports/GO-2026-6038.yaml
  - data/reports/GO-2026-6039.yaml
  - data/reports/GO-2026-6040.yaml
  - data/reports/GO-2026-6041.yaml
  - data/reports/GO-2026-6042.yaml
  - data/reports/GO-2026-6043.yaml
  - data/reports/GO-2026-6044.yaml
  - data/reports/GO-2026-6045.yaml
  - data/reports/GO-2026-6046.yaml
  - data/reports/GO-2026-6047.yaml
  - data/reports/GO-2026-6048.yaml
  - data/reports/GO-2026-6049.yaml
  - data/reports/GO-2026-6050.yaml
  - data/reports/GO-2026-6051.yaml
  - data/reports/GO-2026-6052.yaml
  - data/reports/GO-2026-6053.yaml
  - data/reports/GO-2026-6054.yaml
  - data/reports/GO-2026-6055.yaml
  - data/reports/GO-2026-6056.yaml
  - data/reports/GO-2026-6057.yaml

Fixes golang/vulndb#6015
Fixes golang/vulndb#6016
Fixes golang/vulndb#6017
Fixes golang/vulndb#6018
Fixes golang/vulndb#6019
Fixes golang/vulndb#6020
Fixes golang/vulndb#6021
Fixes golang/vulndb#6022
Fixes golang/vulndb#6023
Fixes golang/vulndb#6024
Fixes golang/vulndb#6025
Fixes golang/vulndb#6026
Fixes golang/vulndb#6027
Fixes golang/vulndb#6028
Fixes golang/vulndb#6029
Fixes golang/vulndb#6030
Fixes golang/vulndb#6031
Fixes golang/vulndb#6032
Fixes golang/vulndb#6033
Fixes golang/vulndb#6034
Fixes golang/vulndb#6035
Fixes golang/vulndb#6036
Fixes golang/vulndb#6037
Fixes golang/vulndb#6038
Fixes golang/vulndb#6039
Fixes golang/vulndb#6040
Fixes golang/vulndb#6041
Fixes golang/vulndb#6042
Fixes golang/vulndb#6043
Fixes golang/vulndb#6044
Fixes golang/vulndb#6045
Fixes golang/vulndb#6046
Fixes golang/vulndb#6047
Fixes golang/vulndb#6048
Fixes golang/vulndb#6049
Fixes golang/vulndb#6050
Fixes golang/vulndb#6051
Fixes golang/vulndb#6052
Fixes golang/vulndb#6053
Fixes golang/vulndb#6054
Fixes golang/vulndb#6055
Fixes golang/vulndb#6056
Fixes golang/vulndb#6057

Change-Id: Ia4cf388021edbda8280e64f6fe176c65f1214426
Reviewed-on: https://go-review.googlesource.com/c/vulndb/+/803940
LUCI-TryBot-Result: golang-scoped@luci-project-accounts.iam.gserviceaccount.com <golang-scoped@luci-project-accounts.iam.gserviceaccount.com>
Reviewed-by: Nicholas Husin <nsh@golang.org>
Reviewed-by: Nicholas Husin <husin@google.com>
diff --git a/data/osv/GO-2026-6015.json b/data/osv/GO-2026-6015.json
new file mode 100644
index 0000000..fb8e247
--- /dev/null
+++ b/data/osv/GO-2026-6015.json
@@ -0,0 +1,48 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6015",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-54247",
+    "GHSA-cwxq-rc9x-2jvv"
+  ],
+  "summary": "Skipper: Unbounded Request Body Read in Admission Webhook Causes Memory Exhaustion DoS in github.com/zalando/skipper",
+  "details": "Skipper: Unbounded Request Body Read in Admission Webhook Causes Memory Exhaustion DoS in github.com/zalando/skipper",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/zalando/skipper",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "0.26.22"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/zalando/skipper/security/advisories/GHSA-cwxq-rc9x-2jvv"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/zalando/skipper/releases/tag/v0.26.22"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6015",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6016.json b/data/osv/GO-2026-6016.json
new file mode 100644
index 0000000..8ee02e8
--- /dev/null
+++ b/data/osv/GO-2026-6016.json
@@ -0,0 +1,68 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6016",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "GHSA-rjwr-m7qx-3fjr"
+  ],
+  "summary": "oapi-codegen: OpenAPI Server Description Escapes Generated Go Comment and Injects Executable Code in github.com/oapi-codegen/oapi-codegen",
+  "details": "oapi-codegen: OpenAPI Server Description Escapes Generated Go Comment and Injects Executable Code in github.com/oapi-codegen/oapi-codegen",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/oapi-codegen/oapi-codegen",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    },
+    {
+      "package": {
+        "name": "github.com/oapi-codegen/oapi-codegen/v2",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "2.7.1"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/oapi-codegen/oapi-codegen/security/advisories/GHSA-rjwr-m7qx-3fjr"
+    },
+    {
+      "type": "FIX",
+      "url": "https://github.com/oapi-codegen/oapi-codegen/commit/19c6282e9a6fb84b51aa92b12fad1f0b7e5f5ef6"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/oapi-codegen/oapi-codegen/releases/tag/v2.7.1"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6016",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6017.json b/data/osv/GO-2026-6017.json
new file mode 100644
index 0000000..90b752f
--- /dev/null
+++ b/data/osv/GO-2026-6017.json
@@ -0,0 +1,60 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6017",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-27771",
+    "GHSA-8qw8-rq86-9pc2"
+  ],
+  "summary": "Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea",
+  "details": "Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea",
+  "affected": [
+    {
+      "package": {
+        "name": "code.gitea.io/gitea",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "1.26.2"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/go-gitea/gitea/security/advisories/GHSA-8qw8-rq86-9pc2"
+    },
+    {
+      "type": "ADVISORY",
+      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27771"
+    },
+    {
+      "type": "WEB",
+      "url": "https://blog.gitea.com/release-of-1.26.2"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/go-gitea/gitea/pull/37610"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/go-gitea/gitea/releases/tag/v1.26.2"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6017",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6018.json b/data/osv/GO-2026-6018.json
new file mode 100644
index 0000000..0b846a7
--- /dev/null
+++ b/data/osv/GO-2026-6018.json
@@ -0,0 +1,48 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6018",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-54246",
+    "GHSA-5587-2x54-jj6h"
+  ],
+  "summary": "Skipper's routesrv-no-auth component: All routesrv API Endpoints Lack Authentication in github.com/zalando/skipper",
+  "details": "Skipper's routesrv-no-auth component: All routesrv API Endpoints Lack Authentication in github.com/zalando/skipper",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/zalando/skipper",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "0.27.13"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/zalando/skipper/security/advisories/GHSA-5587-2x54-jj6h"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/zalando/skipper/releases/tag/v0.27.13"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6018",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6019.json b/data/osv/GO-2026-6019.json
new file mode 100644
index 0000000..7ca3c52
--- /dev/null
+++ b/data/osv/GO-2026-6019.json
@@ -0,0 +1,47 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6019",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "GHSA-8qqm-fp2q-v734"
+  ],
+  "summary": "Skipper: Incomplete fix for CVE-2026-50197: an oversized body can bypass OPA deny-on-presence Rego policies in github.com/zalando/skipper",
+  "details": "Skipper: Incomplete fix for CVE-2026-50197: an oversized body can bypass OPA deny-on-presence Rego policies in github.com/zalando/skipper",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/zalando/skipper",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "0.27.26"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/zalando/skipper/security/advisories/GHSA-8qqm-fp2q-v734"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/zalando/skipper/releases/tag/v0.27.26"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6019",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6020.json b/data/osv/GO-2026-6020.json
new file mode 100644
index 0000000..43097f1
--- /dev/null
+++ b/data/osv/GO-2026-6020.json
@@ -0,0 +1,73 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6020",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-55668",
+    "GHSA-8wc8-hf36-mjh9"
+  ],
+  "summary": "File Browser: ScopedFs follows a dangling symlink on write, letting a scoped user create files outside their scope in github.com/filebrowser/filebrowser",
+  "details": "File Browser: ScopedFs follows a dangling symlink on write, letting a scoped user create files outside their scope in github.com/filebrowser/filebrowser",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/filebrowser/filebrowser",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    },
+    {
+      "package": {
+        "name": "github.com/filebrowser/filebrowser/v2",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "2.63.16"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/filebrowser/filebrowser/security/advisories/GHSA-8wc8-hf36-mjh9"
+    },
+    {
+      "type": "ADVISORY",
+      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-55668"
+    },
+    {
+      "type": "FIX",
+      "url": "https://github.com/filebrowser/filebrowser/commit/64511ce45e3be379e965f7f4fb0929a068d5bb81"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/filebrowser/filebrowser/releases/tag/v2.63.16"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6020",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6021.json b/data/osv/GO-2026-6021.json
new file mode 100644
index 0000000..1e54d5d
--- /dev/null
+++ b/data/osv/GO-2026-6021.json
@@ -0,0 +1,69 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6021",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-55667",
+    "GHSA-fmm7-x4gx-8jhr"
+  ],
+  "summary": "File Browser: Out-of-scope file deletion by a Create-only scoped user via symlink-following RemoveAll in upload failure-cleanup in github.com/filebrowser/filebrowser",
+  "details": "File Browser: Out-of-scope file deletion by a Create-only scoped user via symlink-following RemoveAll in upload failure-cleanup in github.com/filebrowser/filebrowser",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/filebrowser/filebrowser",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    },
+    {
+      "package": {
+        "name": "github.com/filebrowser/filebrowser/v2",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "2.63.16"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/filebrowser/filebrowser/security/advisories/GHSA-fmm7-x4gx-8jhr"
+    },
+    {
+      "type": "ADVISORY",
+      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-55667"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/filebrowser/filebrowser/blob/be23ab3a15bf957928ecfed88de5ab67850c1b9c/http/resource.go#L172-L174"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6021",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6022.json b/data/osv/GO-2026-6022.json
new file mode 100644
index 0000000..c7efc7d
--- /dev/null
+++ b/data/osv/GO-2026-6022.json
@@ -0,0 +1,90 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6022",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-54560",
+    "GHSA-vgj4-345g-jcf8"
+  ],
+  "summary": "Cloudreve: OAuth access tokens bypass scope enforcement due to missing client_id claim in github.com/cloudreve/Cloudreve",
+  "details": "Cloudreve: OAuth access tokens bypass scope enforcement due to missing client_id claim in github.com/cloudreve/Cloudreve",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/cloudreve/Cloudreve",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    },
+    {
+      "package": {
+        "name": "github.com/cloudreve/Cloudreve/v3",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    },
+    {
+      "package": {
+        "name": "github.com/cloudreve/Cloudreve/v4",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "4.0.0-20260114075425-bc6845bd742c"
+            },
+            {
+              "fixed": "4.0.0-20260606015557-ed20843dc3df"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/cloudreve/cloudreve/security/advisories/GHSA-vgj4-345g-jcf8"
+    },
+    {
+      "type": "ADVISORY",
+      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54560"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/cloudreve/cloudreve/commit/ed20843dc3df20a25fcaf6b538647e11c4d68d87"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/cloudreve/cloudreve/releases/tag/4.16.1"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6022",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6023.json b/data/osv/GO-2026-6023.json
new file mode 100644
index 0000000..ee88718
--- /dev/null
+++ b/data/osv/GO-2026-6023.json
@@ -0,0 +1,90 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6023",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-54562",
+    "GHSA-x756-g4x3-c64m"
+  ],
+  "summary": "Cloudreve: Non-admin remote download users can SSRF loopback/internal services and read imported responses in github.com/cloudreve/Cloudreve",
+  "details": "Cloudreve: Non-admin remote download users can SSRF loopback/internal services and read imported responses in github.com/cloudreve/Cloudreve",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/cloudreve/Cloudreve",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    },
+    {
+      "package": {
+        "name": "github.com/cloudreve/Cloudreve/v3",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    },
+    {
+      "package": {
+        "name": "github.com/cloudreve/Cloudreve/v4",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "4.0.0-20260606025411-aaebf317a78f"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/cloudreve/cloudreve/security/advisories/GHSA-x756-g4x3-c64m"
+    },
+    {
+      "type": "ADVISORY",
+      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54562"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/cloudreve/cloudreve/commit/aaebf317a78f2413d74afd66c21a1f3143711312"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/cloudreve/cloudreve/releases/tag/4.16.1"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6023",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6024.json b/data/osv/GO-2026-6024.json
new file mode 100644
index 0000000..b067cfa
--- /dev/null
+++ b/data/osv/GO-2026-6024.json
@@ -0,0 +1,73 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6024",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-62685",
+    "GHSA-7rc3-g7h6-22m7"
+  ],
+  "summary": "File Browser: Colliding username normalization gives two users the same home directory in github.com/filebrowser/filebrowser",
+  "details": "File Browser: Colliding username normalization gives two users the same home directory in github.com/filebrowser/filebrowser",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/filebrowser/filebrowser",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    },
+    {
+      "package": {
+        "name": "github.com/filebrowser/filebrowser/v2",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "2.63.17"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/filebrowser/filebrowser/security/advisories/GHSA-7rc3-g7h6-22m7"
+    },
+    {
+      "type": "ADVISORY",
+      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-62685"
+    },
+    {
+      "type": "FIX",
+      "url": "https://github.com/filebrowser/filebrowser/commit/883a36f02fcb69566a8628cb47f18fdc73348387"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/filebrowser/filebrowser/releases/tag/v2.63.17"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6024",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6025.json b/data/osv/GO-2026-6025.json
new file mode 100644
index 0000000..c12fa0a
--- /dev/null
+++ b/data/osv/GO-2026-6025.json
@@ -0,0 +1,61 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6025",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-62684",
+    "GHSA-833g-cqhp-h72j"
+  ],
+  "summary": "File Browser: Share API exposes the password hash and bypass token in github.com/filebrowser/filebrowser",
+  "details": "File Browser: Share API exposes the password hash and bypass token in github.com/filebrowser/filebrowser",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/filebrowser/filebrowser",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    },
+    {
+      "package": {
+        "name": "github.com/filebrowser/filebrowser/v2",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "2.63.17"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/filebrowser/filebrowser/security/advisories/GHSA-833g-cqhp-h72j"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6025",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6026.json b/data/osv/GO-2026-6026.json
new file mode 100644
index 0000000..797b0f7
--- /dev/null
+++ b/data/osv/GO-2026-6026.json
@@ -0,0 +1,73 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6026",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-62843",
+    "GHSA-83xp-526h-j3ww"
+  ],
+  "summary": "File Browser: Archive builder turns backslash filenames into path traversal (zip-slip) in github.com/filebrowser/filebrowser",
+  "details": "File Browser: Archive builder turns backslash filenames into path traversal (zip-slip) in github.com/filebrowser/filebrowser",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/filebrowser/filebrowser",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    },
+    {
+      "package": {
+        "name": "github.com/filebrowser/filebrowser/v2",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "2.63.6"
+            },
+            {
+              "fixed": "2.63.17"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/filebrowser/filebrowser/security/advisories/GHSA-83xp-526h-j3ww"
+    },
+    {
+      "type": "ADVISORY",
+      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-62843"
+    },
+    {
+      "type": "FIX",
+      "url": "https://github.com/filebrowser/filebrowser/commit/8503ba61ff51d48a7313896483d130eb6a5abfe0"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/filebrowser/filebrowser/releases/tag/v2.63.17"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6026",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6027.json b/data/osv/GO-2026-6027.json
new file mode 100644
index 0000000..9e372e4
--- /dev/null
+++ b/data/osv/GO-2026-6027.json
@@ -0,0 +1,48 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6027",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-57894",
+    "GHSA-82f7-87hm-852x"
+  ],
+  "summary": "Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration in gitea.dev",
+  "details": "Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration in gitea.dev",
+  "affected": [
+    {
+      "package": {
+        "name": "gitea.dev",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "1.27.0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/go-gitea/gitea/security/advisories/GHSA-82f7-87hm-852x"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/go-gitea/gitea/releases/tag/v1.27.0"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6027",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6028.json b/data/osv/GO-2026-6028.json
new file mode 100644
index 0000000..54fa3ad
--- /dev/null
+++ b/data/osv/GO-2026-6028.json
@@ -0,0 +1,64 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6028",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-58428",
+    "GHSA-25gq-j9jx-43pg"
+  ],
+  "summary": "Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) in gitea.dev",
+  "details": "Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) in gitea.dev",
+  "affected": [
+    {
+      "package": {
+        "name": "gitea.dev",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "1.27.0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/go-gitea/gitea/security/advisories/GHSA-25gq-j9jx-43pg"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/go-gitea/gitea/commit/de4b8277e9cb576f2315fb03b5ab6478b42a1d31"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/go-gitea/gitea/commit/f69e15afe7496cc62e96dab244629c69eb31a7bf"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/go-gitea/gitea/pull/38406"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/go-gitea/gitea/pull/38426"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/go-gitea/gitea/releases/tag/v1.27.0"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6028",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6029.json b/data/osv/GO-2026-6029.json
new file mode 100644
index 0000000..c5baf03
--- /dev/null
+++ b/data/osv/GO-2026-6029.json
@@ -0,0 +1,68 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6029",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-28740",
+    "GHSA-2m9v-5q2g-58vq"
+  ],
+  "summary": "Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea",
+  "details": "Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea",
+  "affected": [
+    {
+      "package": {
+        "name": "code.gitea.io/gitea",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "1.26.3"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/go-gitea/gitea/security/advisories/GHSA-2m9v-5q2g-58vq"
+    },
+    {
+      "type": "ADVISORY",
+      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-28740"
+    },
+    {
+      "type": "WEB",
+      "url": "https://blog.gitea.com/release-of-1.26.3-and-1.26.4"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/go-gitea/gitea/commit/1c7b7ea72df7cf81e88b8e09049608254d32e56e"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/go-gitea/gitea/commit/7b4a1a1a118501b9d0260301dfed7f52dfc36ee9"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/go-gitea/gitea/pull/38050"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/go-gitea/gitea/releases/tag/v1.26.3"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6029",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6030.json b/data/osv/GO-2026-6030.json
new file mode 100644
index 0000000..ec9680d
--- /dev/null
+++ b/data/osv/GO-2026-6030.json
@@ -0,0 +1,64 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6030",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-22874",
+    "GHSA-2r5c-gw76-rh3w"
+  ],
+  "summary": "Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea",
+  "details": "Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea",
+  "affected": [
+    {
+      "package": {
+        "name": "code.gitea.io/gitea",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "1.26.3"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/go-gitea/gitea/security/advisories/GHSA-2r5c-gw76-rh3w"
+    },
+    {
+      "type": "ADVISORY",
+      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-22874"
+    },
+    {
+      "type": "WEB",
+      "url": "https://blog.gitea.com/release-of-1.26.3-and-1.26.4"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/go-gitea/gitea/pull/38059"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/go-gitea/gitea/pull/38173"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/go-gitea/gitea/releases/tag/v1.26.3"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6030",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6031.json b/data/osv/GO-2026-6031.json
new file mode 100644
index 0000000..3e1cd93
--- /dev/null
+++ b/data/osv/GO-2026-6031.json
@@ -0,0 +1,64 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6031",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-27761",
+    "GHSA-3pww-vcvm-3gmj"
+  ],
+  "summary": "Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea",
+  "details": "Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea",
+  "affected": [
+    {
+      "package": {
+        "name": "code.gitea.io/gitea",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "1.26.3"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/go-gitea/gitea/security/advisories/GHSA-3pww-vcvm-3gmj"
+    },
+    {
+      "type": "ADVISORY",
+      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27761"
+    },
+    {
+      "type": "WEB",
+      "url": "https://blog.gitea.com/release-of-1.26.3-and-1.26.4"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/go-gitea/gitea/commit/9e84deb969aff5c1115c2984e41250f28c78451f"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/go-gitea/gitea/pull/38147"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/go-gitea/gitea/releases/tag/v1.26.3"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6031",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6032.json b/data/osv/GO-2026-6032.json
new file mode 100644
index 0000000..c932d55
--- /dev/null
+++ b/data/osv/GO-2026-6032.json
@@ -0,0 +1,44 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6032",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-58420",
+    "GHSA-5ggr-2f2h-jmvm"
+  ],
+  "summary": "Gitea: Local File Inclusion via file:// URI in Migration Restore in gitea.dev",
+  "details": "Gitea: Local File Inclusion via file:// URI in Migration Restore in gitea.dev",
+  "affected": [
+    {
+      "package": {
+        "name": "gitea.dev",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "1.27.0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/go-gitea/gitea/security/advisories/GHSA-5ggr-2f2h-jmvm"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6032",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6033.json b/data/osv/GO-2026-6033.json
new file mode 100644
index 0000000..ab057d4
--- /dev/null
+++ b/data/osv/GO-2026-6033.json
@@ -0,0 +1,64 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6033",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-58440",
+    "GHSA-66m4-5jjr-2rg5"
+  ],
+  "summary": "Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content in gitea.dev",
+  "details": "Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content in gitea.dev",
+  "affected": [
+    {
+      "package": {
+        "name": "gitea.dev",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "1.27.0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/go-gitea/gitea/security/advisories/GHSA-66m4-5jjr-2rg5"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/go-gitea/gitea/commit/de4b8277e9cb576f2315fb03b5ab6478b42a1d31"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/go-gitea/gitea/commit/f69e15afe7496cc62e96dab244629c69eb31a7bf"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/go-gitea/gitea/pull/38406"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/go-gitea/gitea/pull/38426"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/go-gitea/gitea/releases/tag/v1.27.0"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6033",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6034.json b/data/osv/GO-2026-6034.json
new file mode 100644
index 0000000..428a392
--- /dev/null
+++ b/data/osv/GO-2026-6034.json
@@ -0,0 +1,64 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6034",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-56654",
+    "GHSA-683j-3ff6-hh2x"
+  ],
+  "summary": "Gitea: Privilege Escalation via Access Token Scope Escalation in API in gitea.dev",
+  "details": "Gitea: Privilege Escalation via Access Token Scope Escalation in API in gitea.dev",
+  "affected": [
+    {
+      "package": {
+        "name": "gitea.dev",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "1.27.0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/go-gitea/gitea/security/advisories/GHSA-683j-3ff6-hh2x"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/go-gitea/gitea/commit/de4b8277e9cb576f2315fb03b5ab6478b42a1d31"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/go-gitea/gitea/commit/f69e15afe7496cc62e96dab244629c69eb31a7bf"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/go-gitea/gitea/pull/38406"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/go-gitea/gitea/pull/38426"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/go-gitea/gitea/releases/tag/v1.27.0"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6034",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6035.json b/data/osv/GO-2026-6035.json
new file mode 100644
index 0000000..31f1712
--- /dev/null
+++ b/data/osv/GO-2026-6035.json
@@ -0,0 +1,64 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6035",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-57886",
+    "GHSA-6c6r-5xr4-cr5m"
+  ],
+  "summary": "Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content in gitea.dev",
+  "details": "Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content in gitea.dev",
+  "affected": [
+    {
+      "package": {
+        "name": "gitea.dev",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "1.27.0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/go-gitea/gitea/security/advisories/GHSA-6c6r-5xr4-cr5m"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/go-gitea/gitea/commit/de4b8277e9cb576f2315fb03b5ab6478b42a1d31"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/go-gitea/gitea/commit/f69e15afe7496cc62e96dab244629c69eb31a7bf"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/go-gitea/gitea/pull/38406"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/go-gitea/gitea/pull/38426"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/go-gitea/gitea/releases/tag/v1.27.0"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6035",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6036.json b/data/osv/GO-2026-6036.json
new file mode 100644
index 0000000..6363f82
--- /dev/null
+++ b/data/osv/GO-2026-6036.json
@@ -0,0 +1,48 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6036",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-50105",
+    "GHSA-6cqf-375w-639g"
+  ],
+  "summary": "Gitea: RSS/Atom feed handlers bypass API-token scope \u0026 public-only confinement (incomplete fix of #37698) in gitea.dev",
+  "details": "Gitea: RSS/Atom feed handlers bypass API-token scope \u0026 public-only confinement (incomplete fix of #37698) in gitea.dev",
+  "affected": [
+    {
+      "package": {
+        "name": "gitea.dev",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "1.27.0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/go-gitea/gitea/security/advisories/GHSA-6cqf-375w-639g"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/go-gitea/gitea/releases/tag/v1.27.0"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6036",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6037.json b/data/osv/GO-2026-6037.json
new file mode 100644
index 0000000..628b7ed
--- /dev/null
+++ b/data/osv/GO-2026-6037.json
@@ -0,0 +1,64 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6037",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-56755",
+    "GHSA-6hm7-3pwj-22rm"
+  ],
+  "summary": "Gitea: Denial of Service (CPU \u0026 Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload in gitea.dev",
+  "details": "Gitea: Denial of Service (CPU \u0026 Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload in gitea.dev",
+  "affected": [
+    {
+      "package": {
+        "name": "gitea.dev",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "1.27.0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/go-gitea/gitea/security/advisories/GHSA-6hm7-3pwj-22rm"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/go-gitea/gitea/commit/de4b8277e9cb576f2315fb03b5ab6478b42a1d31"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/go-gitea/gitea/commit/f69e15afe7496cc62e96dab244629c69eb31a7bf"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/go-gitea/gitea/pull/38406"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/go-gitea/gitea/pull/38426"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/go-gitea/gitea/releases/tag/v1.27.0"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6037",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6038.json b/data/osv/GO-2026-6038.json
new file mode 100644
index 0000000..df0b832
--- /dev/null
+++ b/data/osv/GO-2026-6038.json
@@ -0,0 +1,48 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6038",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-58314",
+    "GHSA-2fcr-jfvc-vgg2"
+  ],
+  "summary": "Gitea: Two SSRF findings in gitea.dev",
+  "details": "Gitea: Two SSRF findings in gitea.dev",
+  "affected": [
+    {
+      "package": {
+        "name": "gitea.dev",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "1.27.0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/go-gitea/gitea/security/advisories/GHSA-2fcr-jfvc-vgg2"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/go-gitea/gitea/releases/tag/v1.27.0"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6038",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6039.json b/data/osv/GO-2026-6039.json
new file mode 100644
index 0000000..9053531
--- /dev/null
+++ b/data/osv/GO-2026-6039.json
@@ -0,0 +1,48 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6039",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-59765",
+    "GHSA-2wm4-vwp6-v7xc"
+  ],
+  "summary": "Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev",
+  "details": "Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev",
+  "affected": [
+    {
+      "package": {
+        "name": "gitea.dev",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "1.27.0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/go-gitea/gitea/security/advisories/GHSA-2wm4-vwp6-v7xc"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/go-gitea/gitea/releases/tag/v1.27.0"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6039",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6040.json b/data/osv/GO-2026-6040.json
new file mode 100644
index 0000000..5a73731
--- /dev/null
+++ b/data/osv/GO-2026-6040.json
@@ -0,0 +1,48 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6040",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-58511",
+    "GHSA-3r5c-2xxx-h872"
+  ],
+  "summary": "Gitea: Webhook Authorization Header Returned in Plaintext via API in gitea.dev",
+  "details": "Gitea: Webhook Authorization Header Returned in Plaintext via API in gitea.dev",
+  "affected": [
+    {
+      "package": {
+        "name": "gitea.dev",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "1.27.0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/go-gitea/gitea/security/advisories/GHSA-3r5c-2xxx-h872"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/go-gitea/gitea/releases/tag/v1.27.0"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6040",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6041.json b/data/osv/GO-2026-6041.json
new file mode 100644
index 0000000..e1b191e
--- /dev/null
+++ b/data/osv/GO-2026-6041.json
@@ -0,0 +1,64 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6041",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-58419",
+    "GHSA-44qc-pgvp-wx7v"
+  ],
+  "summary": "Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea",
+  "details": "Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea",
+  "affected": [
+    {
+      "package": {
+        "name": "code.gitea.io/gitea",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "1.26.4"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/go-gitea/gitea/security/advisories/GHSA-44qc-pgvp-wx7v"
+    },
+    {
+      "type": "ADVISORY",
+      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-58419"
+    },
+    {
+      "type": "WEB",
+      "url": "https://blog.gitea.com/release-of-1.26.3-and-1.26.4"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/go-gitea/gitea/commit/9e84deb969aff5c1115c2984e41250f28c78451f"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/go-gitea/gitea/pull/38108"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/go-gitea/gitea/releases/tag/v1.26.4"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6041",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6042.json b/data/osv/GO-2026-6042.json
new file mode 100644
index 0000000..b47ee08
--- /dev/null
+++ b/data/osv/GO-2026-6042.json
@@ -0,0 +1,48 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6042",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-56657",
+    "GHSA-4xjf-493q-98p3"
+  ],
+  "summary": "Gitea SSH Key Parser Denial of Service in gitea.dev",
+  "details": "Gitea SSH Key Parser Denial of Service in gitea.dev",
+  "affected": [
+    {
+      "package": {
+        "name": "gitea.dev",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "1.27.0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/go-gitea/gitea/security/advisories/GHSA-4xjf-493q-98p3"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/go-gitea/gitea/releases/tag/v1.27.0"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6042",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6043.json b/data/osv/GO-2026-6043.json
new file mode 100644
index 0000000..d9e0572
--- /dev/null
+++ b/data/osv/GO-2026-6043.json
@@ -0,0 +1,64 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6043",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-27775",
+    "GHSA-649p-mmhf-85c7"
+  ],
+  "summary": "Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea",
+  "details": "Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea",
+  "affected": [
+    {
+      "package": {
+        "name": "code.gitea.io/gitea",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "1.26.3"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/go-gitea/gitea/security/advisories/GHSA-649p-mmhf-85c7"
+    },
+    {
+      "type": "ADVISORY",
+      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27775"
+    },
+    {
+      "type": "WEB",
+      "url": "https://blog.gitea.com/release-of-1.26.3-and-1.26.4"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/go-gitea/gitea/commit/99f8b3d9a1d32f4c39828e07971455a18191e0b9"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/go-gitea/gitea/pull/38151"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/go-gitea/gitea/releases/tag/v1.26.3"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6043",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6044.json b/data/osv/GO-2026-6044.json
new file mode 100644
index 0000000..b76a2fb
--- /dev/null
+++ b/data/osv/GO-2026-6044.json
@@ -0,0 +1,68 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6044",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-58424",
+    "GHSA-777r-4v59-6486"
+  ],
+  "summary": "Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea",
+  "details": "Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea",
+  "affected": [
+    {
+      "package": {
+        "name": "code.gitea.io/gitea",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "1.26.3"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/go-gitea/gitea/security/advisories/GHSA-777r-4v59-6486"
+    },
+    {
+      "type": "ADVISORY",
+      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-58424"
+    },
+    {
+      "type": "WEB",
+      "url": "https://blog.gitea.com/release-of-1.26.3-and-1.26.4"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/go-gitea/gitea/commit/699fe2ef43b9466ac1b0cb857029f91fd5b0056d"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/go-gitea/gitea/commit/e107498f3b6fccff35455ef17430ca68df665297"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/go-gitea/gitea/pull/38010"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/go-gitea/gitea/releases/tag/v1.26.4"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6044",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6045.json b/data/osv/GO-2026-6045.json
new file mode 100644
index 0000000..e39feb1
--- /dev/null
+++ b/data/osv/GO-2026-6045.json
@@ -0,0 +1,48 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6045",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-56443",
+    "GHSA-7p4h-3gxq-x3h3"
+  ],
+  "summary": "Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository\n+ Package categories) — residual after CVE-2026-25714 / PR #37118 in gitea.dev",
+  "details": "Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository\n+ Package categories) — residual after CVE-2026-25714 / PR #37118 in gitea.dev",
+  "affected": [
+    {
+      "package": {
+        "name": "gitea.dev",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "1.27.0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/go-gitea/gitea/security/advisories/GHSA-7p4h-3gxq-x3h3"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/go-gitea/gitea/releases/tag/v1.27.0"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6045",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6046.json b/data/osv/GO-2026-6046.json
new file mode 100644
index 0000000..2f88b70
--- /dev/null
+++ b/data/osv/GO-2026-6046.json
@@ -0,0 +1,68 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6046",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-58423",
+    "GHSA-7wvc-rvp7-w99x"
+  ],
+  "summary": "Gitea: LFS authentication bypass via malformed SSH sub-verb allows unauthorized read access to private repositories in code.gitea.io/gitea",
+  "details": "Gitea: LFS authentication bypass via malformed SSH sub-verb allows unauthorized read access to private repositories in code.gitea.io/gitea",
+  "affected": [
+    {
+      "package": {
+        "name": "code.gitea.io/gitea",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "1.23.0"
+            },
+            {
+              "fixed": "1.26.3"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/go-gitea/gitea/security/advisories/GHSA-7wvc-rvp7-w99x"
+    },
+    {
+      "type": "ADVISORY",
+      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-58423"
+    },
+    {
+      "type": "WEB",
+      "url": "https://blog.gitea.com/release-of-1.26.3-and-1.26.4"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/go-gitea/gitea/commit/42513398c05ca6bdf71da76cb6f9baaebe8cb924"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/go-gitea/gitea/commit/8f4b7ebbf6061bd44b1ab3824f17f37b87fb1740"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/go-gitea/gitea/pull/38008"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/go-gitea/gitea/releases/tag/v1.26.4"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6046",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6047.json b/data/osv/GO-2026-6047.json
new file mode 100644
index 0000000..a7c61ae
--- /dev/null
+++ b/data/osv/GO-2026-6047.json
@@ -0,0 +1,48 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6047",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-58437",
+    "GHSA-8p9h-49rc-qgxj"
+  ],
+  "summary": "Gitea: Repository Visibility Manipulation via Git Push Options in gitea.dev",
+  "details": "Gitea: Repository Visibility Manipulation via Git Push Options in gitea.dev",
+  "affected": [
+    {
+      "package": {
+        "name": "gitea.dev",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "1.27.0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/go-gitea/gitea/security/advisories/GHSA-8p9h-49rc-qgxj"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/go-gitea/gitea/releases/tag/v1.27.0"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6047",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6048.json b/data/osv/GO-2026-6048.json
new file mode 100644
index 0000000..723bcf9
--- /dev/null
+++ b/data/osv/GO-2026-6048.json
@@ -0,0 +1,48 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6048",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-54481",
+    "GHSA-94v3-77j7-vm48"
+  ],
+  "summary": "Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override in gitea.dev",
+  "details": "Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override in gitea.dev",
+  "affected": [
+    {
+      "package": {
+        "name": "gitea.dev",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "1.27.0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/go-gitea/gitea/security/advisories/GHSA-94v3-77j7-vm48"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/go-gitea/gitea/releases/tag/v1.27.0"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6048",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6049.json b/data/osv/GO-2026-6049.json
new file mode 100644
index 0000000..70f99db
--- /dev/null
+++ b/data/osv/GO-2026-6049.json
@@ -0,0 +1,64 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6049",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-59763",
+    "GHSA-9mq6-mqjj-c2c5"
+  ],
+  "summary": "Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads in gitea.dev",
+  "details": "Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads in gitea.dev",
+  "affected": [
+    {
+      "package": {
+        "name": "gitea.dev",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "1.27.0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/go-gitea/gitea/security/advisories/GHSA-9mq6-mqjj-c2c5"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/go-gitea/gitea/commit/de4b8277e9cb576f2315fb03b5ab6478b42a1d31"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/go-gitea/gitea/commit/f69e15afe7496cc62e96dab244629c69eb31a7bf"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/go-gitea/gitea/pull/38406"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/go-gitea/gitea/pull/38426"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/go-gitea/gitea/releases/tag/v1.27.0"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6049",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6050.json b/data/osv/GO-2026-6050.json
new file mode 100644
index 0000000..298abbe
--- /dev/null
+++ b/data/osv/GO-2026-6050.json
@@ -0,0 +1,48 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6050",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-58444",
+    "GHSA-cp3q-vrj2-ghhh"
+  ],
+  "summary": "Gitea: Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents in gitea.dev",
+  "details": "Gitea: Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents in gitea.dev",
+  "affected": [
+    {
+      "package": {
+        "name": "gitea.dev",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "1.27.0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/go-gitea/gitea/security/advisories/GHSA-cp3q-vrj2-ghhh"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/go-gitea/gitea/releases/tag/v1.27.0"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6050",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6051.json b/data/osv/GO-2026-6051.json
new file mode 100644
index 0000000..a7681ca
--- /dev/null
+++ b/data/osv/GO-2026-6051.json
@@ -0,0 +1,64 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6051",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-20896",
+    "GHSA-f75j-4cw6-rmx4"
+  ],
+  "summary": "Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea",
+  "details": "Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea",
+  "affected": [
+    {
+      "package": {
+        "name": "code.gitea.io/gitea",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "1.26.3"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/go-gitea/gitea/security/advisories/GHSA-f75j-4cw6-rmx4"
+    },
+    {
+      "type": "ADVISORY",
+      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-20896"
+    },
+    {
+      "type": "WEB",
+      "url": "https://blog.gitea.com/release-of-1.26.3-and-1.26.4"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/go-gitea/gitea/commit/99f8b3d9a1d32f4c39828e07971455a18191e0b9"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/go-gitea/gitea/pull/38151"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/go-gitea/gitea/releases/tag/v1.26.3"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6051",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6052.json b/data/osv/GO-2026-6052.json
new file mode 100644
index 0000000..622b63f
--- /dev/null
+++ b/data/osv/GO-2026-6052.json
@@ -0,0 +1,56 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6052",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-58416",
+    "GHSA-fj8v-hjwv-qm88"
+  ],
+  "summary": "Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) in gitea.dev",
+  "details": "Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) in gitea.dev",
+  "affected": [
+    {
+      "package": {
+        "name": "gitea.dev",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "1.27.0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/go-gitea/gitea/security/advisories/GHSA-fj8v-hjwv-qm88"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/go-gitea/gitea/commit/1d43b736b5a16c5f80cfdcd9a9448a9c983ddaa0"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/go-gitea/gitea/pull/38214"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/go-gitea/gitea/releases/tag/v1.27.0"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6052",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6053.json b/data/osv/GO-2026-6053.json
new file mode 100644
index 0000000..5c57f76
--- /dev/null
+++ b/data/osv/GO-2026-6053.json
@@ -0,0 +1,64 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6053",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-58429",
+    "GHSA-fq2p-5p22-8g6j"
+  ],
+  "summary": "Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints in gitea.dev",
+  "details": "Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints in gitea.dev",
+  "affected": [
+    {
+      "package": {
+        "name": "gitea.dev",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "1.27.0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/go-gitea/gitea/security/advisories/GHSA-fq2p-5p22-8g6j"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/go-gitea/gitea/commit/a34eac5ef42ada433a7c7dafb98f15c13d7ad74e"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/go-gitea/gitea/commit/f2a1271f164569264c378fad720b0c000fff3336"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/go-gitea/gitea/pull/37118"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/go-gitea/gitea/pull/37773"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/go-gitea/gitea/releases/tag/v1.27.0"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6053",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6054.json b/data/osv/GO-2026-6054.json
new file mode 100644
index 0000000..867d620
--- /dev/null
+++ b/data/osv/GO-2026-6054.json
@@ -0,0 +1,48 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6054",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-57897",
+    "GHSA-frpw-3h2q-4jj6"
+  ],
+  "summary": "Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs in gitea.dev",
+  "details": "Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs in gitea.dev",
+  "affected": [
+    {
+      "package": {
+        "name": "gitea.dev",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "1.27.0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/go-gitea/gitea/security/advisories/GHSA-frpw-3h2q-4jj6"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/go-gitea/gitea/releases/tag/v1.27.0"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6054",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6055.json b/data/osv/GO-2026-6055.json
new file mode 100644
index 0000000..568f4e7
--- /dev/null
+++ b/data/osv/GO-2026-6055.json
@@ -0,0 +1,52 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6055",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-58436",
+    "GHSA-fw57-jgch-pgf3"
+  ],
+  "summary": "Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests in gitea.dev",
+  "details": "Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests in gitea.dev",
+  "affected": [
+    {
+      "package": {
+        "name": "gitea.dev",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "1.27.0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/go-gitea/gitea/security/advisories/GHSA-fw57-jgch-pgf3"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/go-gitea/gitea/commit/f452c369acc9f1bd05ec6ef9c2e4399062dd6da1"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/go-gitea/gitea/pull/38323"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6055",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6056.json b/data/osv/GO-2026-6056.json
new file mode 100644
index 0000000..872cfed
--- /dev/null
+++ b/data/osv/GO-2026-6056.json
@@ -0,0 +1,64 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6056",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-58422",
+    "GHSA-g9g6-qhrc-p3qc"
+  ],
+  "summary": "Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea",
+  "details": "Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea",
+  "affected": [
+    {
+      "package": {
+        "name": "code.gitea.io/gitea",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "1.26.4"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/go-gitea/gitea/security/advisories/GHSA-g9g6-qhrc-p3qc"
+    },
+    {
+      "type": "ADVISORY",
+      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-58422"
+    },
+    {
+      "type": "WEB",
+      "url": "https://blog.gitea.com/release-of-1.26.3-and-1.26.4"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/go-gitea/gitea/commit/c43eb7c33a100ffc7b2367adf165f7085e0ccdc5"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/go-gitea/gitea/pull/38009"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/go-gitea/gitea/releases/tag/v1.26.4"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6056",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6057.json b/data/osv/GO-2026-6057.json
new file mode 100644
index 0000000..f033981
--- /dev/null
+++ b/data/osv/GO-2026-6057.json
@@ -0,0 +1,64 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6057",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-20779",
+    "GHSA-gx3v-q759-g323"
+  ],
+  "summary": "Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea",
+  "details": "Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea",
+  "affected": [
+    {
+      "package": {
+        "name": "code.gitea.io/gitea",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "1.5.0"
+            },
+            {
+              "fixed": "1.26.3"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/go-gitea/gitea/security/advisories/GHSA-gx3v-q759-g323"
+    },
+    {
+      "type": "ADVISORY",
+      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-20779"
+    },
+    {
+      "type": "WEB",
+      "url": "https://blog.gitea.com/release-of-1.26.3-and-1.26.4"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/go-gitea/gitea/commit/99f8b3d9a1d32f4c39828e07971455a18191e0b9"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/go-gitea/gitea/pull/38151"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/go-gitea/gitea/releases/tag/v1.26.3"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6057",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/reports/GO-2026-6015.yaml b/data/reports/GO-2026-6015.yaml
new file mode 100644
index 0000000..ab7035b
--- /dev/null
+++ b/data/reports/GO-2026-6015.yaml
@@ -0,0 +1,20 @@
+id: GO-2026-6015
+modules:
+    - module: github.com/zalando/skipper
+      versions:
+        - fixed: 0.26.22
+      vulnerable_at: 0.26.21
+summary: |-
+    Skipper: Unbounded Request Body Read in Admission Webhook Causes Memory
+    Exhaustion DoS in github.com/zalando/skipper
+cves:
+    - CVE-2026-54247
+ghsas:
+    - GHSA-cwxq-rc9x-2jvv
+references:
+    - advisory: https://github.com/zalando/skipper/security/advisories/GHSA-cwxq-rc9x-2jvv
+    - web: https://github.com/zalando/skipper/releases/tag/v0.26.22
+source:
+    id: GHSA-cwxq-rc9x-2jvv
+    created: 2026-07-21T19:09:44.975741-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6016.yaml b/data/reports/GO-2026-6016.yaml
new file mode 100644
index 0000000..5bd674b
--- /dev/null
+++ b/data/reports/GO-2026-6016.yaml
@@ -0,0 +1,21 @@
+id: GO-2026-6016
+modules:
+    - module: github.com/oapi-codegen/oapi-codegen
+      vulnerable_at: 1.16.3
+    - module: github.com/oapi-codegen/oapi-codegen/v2
+      versions:
+        - fixed: 2.7.1
+      vulnerable_at: 2.7.0
+summary: |-
+    oapi-codegen: OpenAPI Server Description Escapes Generated Go Comment and
+    Injects Executable Code in github.com/oapi-codegen/oapi-codegen
+ghsas:
+    - GHSA-rjwr-m7qx-3fjr
+references:
+    - advisory: https://github.com/oapi-codegen/oapi-codegen/security/advisories/GHSA-rjwr-m7qx-3fjr
+    - fix: https://github.com/oapi-codegen/oapi-codegen/commit/19c6282e9a6fb84b51aa92b12fad1f0b7e5f5ef6
+    - web: https://github.com/oapi-codegen/oapi-codegen/releases/tag/v2.7.1
+source:
+    id: GHSA-rjwr-m7qx-3fjr
+    created: 2026-07-21T19:09:41.353671-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6017.yaml b/data/reports/GO-2026-6017.yaml
new file mode 100644
index 0000000..bed7968
--- /dev/null
+++ b/data/reports/GO-2026-6017.yaml
@@ -0,0 +1,21 @@
+id: GO-2026-6017
+modules:
+    - module: code.gitea.io/gitea
+      versions:
+        - fixed: 1.26.2
+      vulnerable_at: 1.26.1
+summary: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
+cves:
+    - CVE-2026-27771
+ghsas:
+    - GHSA-8qw8-rq86-9pc2
+references:
+    - advisory: https://github.com/go-gitea/gitea/security/advisories/GHSA-8qw8-rq86-9pc2
+    - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-27771
+    - web: https://blog.gitea.com/release-of-1.26.2
+    - web: https://github.com/go-gitea/gitea/pull/37610
+    - web: https://github.com/go-gitea/gitea/releases/tag/v1.26.2
+source:
+    id: GHSA-8qw8-rq86-9pc2
+    created: 2026-07-21T19:09:34.692475-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6018.yaml b/data/reports/GO-2026-6018.yaml
new file mode 100644
index 0000000..a428ca4
--- /dev/null
+++ b/data/reports/GO-2026-6018.yaml
@@ -0,0 +1,20 @@
+id: GO-2026-6018
+modules:
+    - module: github.com/zalando/skipper
+      versions:
+        - fixed: 0.27.13
+      vulnerable_at: 0.27.12
+summary: |-
+    Skipper's routesrv-no-auth component: All routesrv API Endpoints Lack
+    Authentication in github.com/zalando/skipper
+cves:
+    - CVE-2026-54246
+ghsas:
+    - GHSA-5587-2x54-jj6h
+references:
+    - advisory: https://github.com/zalando/skipper/security/advisories/GHSA-5587-2x54-jj6h
+    - web: https://github.com/zalando/skipper/releases/tag/v0.27.13
+source:
+    id: GHSA-5587-2x54-jj6h
+    created: 2026-07-21T19:09:29.508125-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6019.yaml b/data/reports/GO-2026-6019.yaml
new file mode 100644
index 0000000..63ad9f8
--- /dev/null
+++ b/data/reports/GO-2026-6019.yaml
@@ -0,0 +1,18 @@
+id: GO-2026-6019
+modules:
+    - module: github.com/zalando/skipper
+      versions:
+        - fixed: 0.27.26
+      vulnerable_at: 0.27.25
+summary: |-
+    Skipper: Incomplete fix for CVE-2026-50197: an oversized body can bypass OPA
+    deny-on-presence Rego policies in github.com/zalando/skipper
+ghsas:
+    - GHSA-8qqm-fp2q-v734
+references:
+    - advisory: https://github.com/zalando/skipper/security/advisories/GHSA-8qqm-fp2q-v734
+    - web: https://github.com/zalando/skipper/releases/tag/v0.27.26
+source:
+    id: GHSA-8qqm-fp2q-v734
+    created: 2026-07-21T19:09:26.332829-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6020.yaml b/data/reports/GO-2026-6020.yaml
new file mode 100644
index 0000000..1f5fa78
--- /dev/null
+++ b/data/reports/GO-2026-6020.yaml
@@ -0,0 +1,24 @@
+id: GO-2026-6020
+modules:
+    - module: github.com/filebrowser/filebrowser
+      vulnerable_at: 1.11.0
+    - module: github.com/filebrowser/filebrowser/v2
+      versions:
+        - fixed: 2.63.16
+      vulnerable_at: 2.63.15
+summary: |-
+    File Browser: ScopedFs follows a dangling symlink on write, letting a scoped
+    user create files outside their scope in github.com/filebrowser/filebrowser
+cves:
+    - CVE-2026-55668
+ghsas:
+    - GHSA-8wc8-hf36-mjh9
+references:
+    - advisory: https://github.com/filebrowser/filebrowser/security/advisories/GHSA-8wc8-hf36-mjh9
+    - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-55668
+    - fix: https://github.com/filebrowser/filebrowser/commit/64511ce45e3be379e965f7f4fb0929a068d5bb81
+    - web: https://github.com/filebrowser/filebrowser/releases/tag/v2.63.16
+source:
+    id: GHSA-8wc8-hf36-mjh9
+    created: 2026-07-21T19:09:21.758293-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6021.yaml b/data/reports/GO-2026-6021.yaml
new file mode 100644
index 0000000..d13db4e
--- /dev/null
+++ b/data/reports/GO-2026-6021.yaml
@@ -0,0 +1,23 @@
+id: GO-2026-6021
+modules:
+    - module: github.com/filebrowser/filebrowser
+      vulnerable_at: 1.11.0
+    - module: github.com/filebrowser/filebrowser/v2
+      versions:
+        - fixed: 2.63.16
+      vulnerable_at: 2.63.15
+summary: |-
+    File Browser: Out-of-scope file deletion by a Create-only scoped user via
+    symlink-following RemoveAll in upload failure-cleanup in github.com/filebrowser/filebrowser
+cves:
+    - CVE-2026-55667
+ghsas:
+    - GHSA-fmm7-x4gx-8jhr
+references:
+    - advisory: https://github.com/filebrowser/filebrowser/security/advisories/GHSA-fmm7-x4gx-8jhr
+    - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-55667
+    - web: https://github.com/filebrowser/filebrowser/blob/be23ab3a15bf957928ecfed88de5ab67850c1b9c/http/resource.go#L172-L174
+source:
+    id: GHSA-fmm7-x4gx-8jhr
+    created: 2026-07-21T19:09:15.805822-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6022.yaml b/data/reports/GO-2026-6022.yaml
new file mode 100644
index 0000000..e45958c
--- /dev/null
+++ b/data/reports/GO-2026-6022.yaml
@@ -0,0 +1,28 @@
+id: GO-2026-6022
+modules:
+    - module: github.com/cloudreve/Cloudreve
+      vulnerable_at: 0.0.0-20201026073328-746aa3e8ef26
+    - module: github.com/cloudreve/Cloudreve/v3
+      vulnerable_at: 3.0.0-20250225100611-da4e44b77af4
+    - module: github.com/cloudreve/Cloudreve/v4
+      versions:
+        - introduced: 4.0.0-20260114075425-bc6845bd742c
+        - fixed: 4.0.0-20260606015557-ed20843dc3df
+summary: |-
+    Cloudreve: OAuth access tokens bypass scope enforcement due to missing client_id
+    claim in github.com/cloudreve/Cloudreve
+cves:
+    - CVE-2026-54560
+ghsas:
+    - GHSA-vgj4-345g-jcf8
+references:
+    - advisory: https://github.com/cloudreve/cloudreve/security/advisories/GHSA-vgj4-345g-jcf8
+    - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-54560
+    - web: https://github.com/cloudreve/cloudreve/commit/ed20843dc3df20a25fcaf6b538647e11c4d68d87
+    - web: https://github.com/cloudreve/cloudreve/releases/tag/4.16.1
+notes:
+    - fix: 'github.com/cloudreve/Cloudreve/v4: could not add vulnerable_at: could not find tagged version between introduced and fixed'
+source:
+    id: GHSA-vgj4-345g-jcf8
+    created: 2026-07-21T19:09:09.816558-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6023.yaml b/data/reports/GO-2026-6023.yaml
new file mode 100644
index 0000000..34b5ab5
--- /dev/null
+++ b/data/reports/GO-2026-6023.yaml
@@ -0,0 +1,29 @@
+id: GO-2026-6023
+modules:
+    - module: github.com/cloudreve/Cloudreve
+      vulnerable_at: 0.0.0-20201026073328-746aa3e8ef26
+    - module: github.com/cloudreve/Cloudreve/v3
+      unsupported_versions:
+        - last_affected: 3.0.0-20250225100611-da4e44b77af4
+      vulnerable_at: 3.0.0-20250225100611-da4e44b77af4
+    - module: github.com/cloudreve/Cloudreve/v4
+      versions:
+        - fixed: 4.0.0-20260606025411-aaebf317a78f
+summary: |-
+    Cloudreve: Non-admin remote download users can SSRF loopback/internal services
+    and read imported responses in github.com/cloudreve/Cloudreve
+cves:
+    - CVE-2026-54562
+ghsas:
+    - GHSA-x756-g4x3-c64m
+references:
+    - advisory: https://github.com/cloudreve/cloudreve/security/advisories/GHSA-x756-g4x3-c64m
+    - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-54562
+    - web: https://github.com/cloudreve/cloudreve/commit/aaebf317a78f2413d74afd66c21a1f3143711312
+    - web: https://github.com/cloudreve/cloudreve/releases/tag/4.16.1
+notes:
+    - fix: 'github.com/cloudreve/Cloudreve/v4: could not add vulnerable_at: could not find tagged version between introduced and fixed'
+source:
+    id: GHSA-x756-g4x3-c64m
+    created: 2026-07-21T19:09:00.619308-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6024.yaml b/data/reports/GO-2026-6024.yaml
new file mode 100644
index 0000000..e2ff5d7
--- /dev/null
+++ b/data/reports/GO-2026-6024.yaml
@@ -0,0 +1,24 @@
+id: GO-2026-6024
+modules:
+    - module: github.com/filebrowser/filebrowser
+      vulnerable_at: 1.11.0
+    - module: github.com/filebrowser/filebrowser/v2
+      versions:
+        - fixed: 2.63.17
+      vulnerable_at: 2.63.16
+summary: |-
+    File Browser: Colliding username normalization gives two users the same home
+    directory in github.com/filebrowser/filebrowser
+cves:
+    - CVE-2026-62685
+ghsas:
+    - GHSA-7rc3-g7h6-22m7
+references:
+    - advisory: https://github.com/filebrowser/filebrowser/security/advisories/GHSA-7rc3-g7h6-22m7
+    - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-62685
+    - fix: https://github.com/filebrowser/filebrowser/commit/883a36f02fcb69566a8628cb47f18fdc73348387
+    - web: https://github.com/filebrowser/filebrowser/releases/tag/v2.63.17
+source:
+    id: GHSA-7rc3-g7h6-22m7
+    created: 2026-07-21T19:08:55.082005-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6025.yaml b/data/reports/GO-2026-6025.yaml
new file mode 100644
index 0000000..562fd56
--- /dev/null
+++ b/data/reports/GO-2026-6025.yaml
@@ -0,0 +1,19 @@
+id: GO-2026-6025
+modules:
+    - module: github.com/filebrowser/filebrowser
+      vulnerable_at: 1.11.0
+    - module: github.com/filebrowser/filebrowser/v2
+      versions:
+        - fixed: 2.63.17
+      vulnerable_at: 2.63.16
+summary: 'File Browser: Share API exposes the password hash and bypass token in github.com/filebrowser/filebrowser'
+cves:
+    - CVE-2026-62684
+ghsas:
+    - GHSA-833g-cqhp-h72j
+references:
+    - advisory: https://github.com/filebrowser/filebrowser/security/advisories/GHSA-833g-cqhp-h72j
+source:
+    id: GHSA-833g-cqhp-h72j
+    created: 2026-07-21T19:08:50.07563-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6026.yaml b/data/reports/GO-2026-6026.yaml
new file mode 100644
index 0000000..e566396
--- /dev/null
+++ b/data/reports/GO-2026-6026.yaml
@@ -0,0 +1,25 @@
+id: GO-2026-6026
+modules:
+    - module: github.com/filebrowser/filebrowser
+      vulnerable_at: 1.11.0
+    - module: github.com/filebrowser/filebrowser/v2
+      versions:
+        - introduced: 2.63.6
+        - fixed: 2.63.17
+      vulnerable_at: 2.63.16
+summary: |-
+    File Browser: Archive builder turns backslash filenames into path traversal
+    (zip-slip) in github.com/filebrowser/filebrowser
+cves:
+    - CVE-2026-62843
+ghsas:
+    - GHSA-83xp-526h-j3ww
+references:
+    - advisory: https://github.com/filebrowser/filebrowser/security/advisories/GHSA-83xp-526h-j3ww
+    - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-62843
+    - fix: https://github.com/filebrowser/filebrowser/commit/8503ba61ff51d48a7313896483d130eb6a5abfe0
+    - web: https://github.com/filebrowser/filebrowser/releases/tag/v2.63.17
+source:
+    id: GHSA-83xp-526h-j3ww
+    created: 2026-07-21T19:08:43.674341-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6027.yaml b/data/reports/GO-2026-6027.yaml
new file mode 100644
index 0000000..3f0b8ae
--- /dev/null
+++ b/data/reports/GO-2026-6027.yaml
@@ -0,0 +1,20 @@
+id: GO-2026-6027
+modules:
+    - module: gitea.dev
+      versions:
+        - fixed: 1.27.0
+      vulnerable_at: 1.27.0-rc0
+summary: |-
+    Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block
+    Validation, Enabling Internal Git Repository Exfiltration in gitea.dev
+cves:
+    - CVE-2026-57894
+ghsas:
+    - GHSA-82f7-87hm-852x
+references:
+    - advisory: https://github.com/go-gitea/gitea/security/advisories/GHSA-82f7-87hm-852x
+    - web: https://github.com/go-gitea/gitea/releases/tag/v1.27.0
+source:
+    id: GHSA-82f7-87hm-852x
+    created: 2026-07-21T19:08:38.805318-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6028.yaml b/data/reports/GO-2026-6028.yaml
new file mode 100644
index 0000000..5eba17f
--- /dev/null
+++ b/data/reports/GO-2026-6028.yaml
@@ -0,0 +1,24 @@
+id: GO-2026-6028
+modules:
+    - module: gitea.dev
+      versions:
+        - fixed: 1.27.0
+      vulnerable_at: 1.27.0-rc0
+summary: |-
+    Gitea: Release attachment extension allowlist bypass via web release edit form
+    (variant of CVE-2025-68939) in gitea.dev
+cves:
+    - CVE-2026-58428
+ghsas:
+    - GHSA-25gq-j9jx-43pg
+references:
+    - advisory: https://github.com/go-gitea/gitea/security/advisories/GHSA-25gq-j9jx-43pg
+    - web: https://github.com/go-gitea/gitea/commit/de4b8277e9cb576f2315fb03b5ab6478b42a1d31
+    - web: https://github.com/go-gitea/gitea/commit/f69e15afe7496cc62e96dab244629c69eb31a7bf
+    - web: https://github.com/go-gitea/gitea/pull/38406
+    - web: https://github.com/go-gitea/gitea/pull/38426
+    - web: https://github.com/go-gitea/gitea/releases/tag/v1.27.0
+source:
+    id: GHSA-25gq-j9jx-43pg
+    created: 2026-07-21T19:08:32.35586-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6029.yaml b/data/reports/GO-2026-6029.yaml
new file mode 100644
index 0000000..6ff6318
--- /dev/null
+++ b/data/reports/GO-2026-6029.yaml
@@ -0,0 +1,25 @@
+id: GO-2026-6029
+modules:
+    - module: code.gitea.io/gitea
+      versions:
+        - fixed: 1.26.3
+      vulnerable_at: 1.26.2
+summary: |-
+    Gitea: Git LFS object reuse allows non-Code access to authorize private source
+    objects in code.gitea.io/gitea
+cves:
+    - CVE-2026-28740
+ghsas:
+    - GHSA-2m9v-5q2g-58vq
+references:
+    - advisory: https://github.com/go-gitea/gitea/security/advisories/GHSA-2m9v-5q2g-58vq
+    - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-28740
+    - web: https://blog.gitea.com/release-of-1.26.3-and-1.26.4
+    - web: https://github.com/go-gitea/gitea/commit/1c7b7ea72df7cf81e88b8e09049608254d32e56e
+    - web: https://github.com/go-gitea/gitea/commit/7b4a1a1a118501b9d0260301dfed7f52dfc36ee9
+    - web: https://github.com/go-gitea/gitea/pull/38050
+    - web: https://github.com/go-gitea/gitea/releases/tag/v1.26.3
+source:
+    id: GHSA-2m9v-5q2g-58vq
+    created: 2026-07-21T19:08:25.527492-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6030.yaml b/data/reports/GO-2026-6030.yaml
new file mode 100644
index 0000000..b2c67ba
--- /dev/null
+++ b/data/reports/GO-2026-6030.yaml
@@ -0,0 +1,24 @@
+id: GO-2026-6030
+modules:
+    - module: code.gitea.io/gitea
+      versions:
+        - fixed: 1.26.3
+      vulnerable_at: 1.26.2
+summary: |-
+    Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default
+    Filter in code.gitea.io/gitea
+cves:
+    - CVE-2026-22874
+ghsas:
+    - GHSA-2r5c-gw76-rh3w
+references:
+    - advisory: https://github.com/go-gitea/gitea/security/advisories/GHSA-2r5c-gw76-rh3w
+    - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-22874
+    - web: https://blog.gitea.com/release-of-1.26.3-and-1.26.4
+    - web: https://github.com/go-gitea/gitea/pull/38059
+    - web: https://github.com/go-gitea/gitea/pull/38173
+    - web: https://github.com/go-gitea/gitea/releases/tag/v1.26.3
+source:
+    id: GHSA-2r5c-gw76-rh3w
+    created: 2026-07-21T19:08:18.301993-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6031.yaml b/data/reports/GO-2026-6031.yaml
new file mode 100644
index 0000000..c1b4195
--- /dev/null
+++ b/data/reports/GO-2026-6031.yaml
@@ -0,0 +1,24 @@
+id: GO-2026-6031
+modules:
+    - module: code.gitea.io/gitea
+      versions:
+        - fixed: 1.26.3
+      vulnerable_at: 1.26.2
+summary: |-
+    Gitea: API access token scope enforcement bypass on repository RSS/Atom feed
+    endpoints leaks private repository commit data in code.gitea.io/gitea
+cves:
+    - CVE-2026-27761
+ghsas:
+    - GHSA-3pww-vcvm-3gmj
+references:
+    - advisory: https://github.com/go-gitea/gitea/security/advisories/GHSA-3pww-vcvm-3gmj
+    - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-27761
+    - web: https://blog.gitea.com/release-of-1.26.3-and-1.26.4
+    - web: https://github.com/go-gitea/gitea/commit/9e84deb969aff5c1115c2984e41250f28c78451f
+    - web: https://github.com/go-gitea/gitea/pull/38147
+    - web: https://github.com/go-gitea/gitea/releases/tag/v1.26.3
+source:
+    id: GHSA-3pww-vcvm-3gmj
+    created: 2026-07-21T19:08:10.963015-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6032.yaml b/data/reports/GO-2026-6032.yaml
new file mode 100644
index 0000000..1cdaa96
--- /dev/null
+++ b/data/reports/GO-2026-6032.yaml
@@ -0,0 +1,17 @@
+id: GO-2026-6032
+modules:
+    - module: gitea.dev
+      versions:
+        - fixed: 1.27.0
+      vulnerable_at: 1.27.0-rc0
+summary: 'Gitea: Local File Inclusion via file:// URI in Migration Restore in gitea.dev'
+cves:
+    - CVE-2026-58420
+ghsas:
+    - GHSA-5ggr-2f2h-jmvm
+references:
+    - advisory: https://github.com/go-gitea/gitea/security/advisories/GHSA-5ggr-2f2h-jmvm
+source:
+    id: GHSA-5ggr-2f2h-jmvm
+    created: 2026-07-21T19:08:06.067915-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6033.yaml b/data/reports/GO-2026-6033.yaml
new file mode 100644
index 0000000..e3c8252
--- /dev/null
+++ b/data/reports/GO-2026-6033.yaml
@@ -0,0 +1,24 @@
+id: GO-2026-6033
+modules:
+    - module: gitea.dev
+      versions:
+        - fixed: 1.27.0
+      vulnerable_at: 1.27.0-rc0
+summary: |-
+    Gitea: Webhooks created by a collaborator keep firing after their repo access is
+    revoked → ongoing real-time exfiltration of private repo content in gitea.dev
+cves:
+    - CVE-2026-58440
+ghsas:
+    - GHSA-66m4-5jjr-2rg5
+references:
+    - advisory: https://github.com/go-gitea/gitea/security/advisories/GHSA-66m4-5jjr-2rg5
+    - web: https://github.com/go-gitea/gitea/commit/de4b8277e9cb576f2315fb03b5ab6478b42a1d31
+    - web: https://github.com/go-gitea/gitea/commit/f69e15afe7496cc62e96dab244629c69eb31a7bf
+    - web: https://github.com/go-gitea/gitea/pull/38406
+    - web: https://github.com/go-gitea/gitea/pull/38426
+    - web: https://github.com/go-gitea/gitea/releases/tag/v1.27.0
+source:
+    id: GHSA-66m4-5jjr-2rg5
+    created: 2026-07-21T19:08:01.110305-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6034.yaml b/data/reports/GO-2026-6034.yaml
new file mode 100644
index 0000000..d2f925a
--- /dev/null
+++ b/data/reports/GO-2026-6034.yaml
@@ -0,0 +1,22 @@
+id: GO-2026-6034
+modules:
+    - module: gitea.dev
+      versions:
+        - fixed: 1.27.0
+      vulnerable_at: 1.27.0-rc0
+summary: 'Gitea: Privilege Escalation via Access Token Scope Escalation in API in gitea.dev'
+cves:
+    - CVE-2026-56654
+ghsas:
+    - GHSA-683j-3ff6-hh2x
+references:
+    - advisory: https://github.com/go-gitea/gitea/security/advisories/GHSA-683j-3ff6-hh2x
+    - web: https://github.com/go-gitea/gitea/commit/de4b8277e9cb576f2315fb03b5ab6478b42a1d31
+    - web: https://github.com/go-gitea/gitea/commit/f69e15afe7496cc62e96dab244629c69eb31a7bf
+    - web: https://github.com/go-gitea/gitea/pull/38406
+    - web: https://github.com/go-gitea/gitea/pull/38426
+    - web: https://github.com/go-gitea/gitea/releases/tag/v1.27.0
+source:
+    id: GHSA-683j-3ff6-hh2x
+    created: 2026-07-21T19:07:56.075807-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6035.yaml b/data/reports/GO-2026-6035.yaml
new file mode 100644
index 0000000..f54ed78
--- /dev/null
+++ b/data/reports/GO-2026-6035.yaml
@@ -0,0 +1,24 @@
+id: GO-2026-6035
+modules:
+    - module: gitea.dev
+      versions:
+        - fixed: 1.27.0
+      vulnerable_at: 1.27.0-rc0
+summary: |-
+    Gitea: Cross-repository issue/comment attachment re-linking can expose private
+    attachment content in gitea.dev
+cves:
+    - CVE-2026-57886
+ghsas:
+    - GHSA-6c6r-5xr4-cr5m
+references:
+    - advisory: https://github.com/go-gitea/gitea/security/advisories/GHSA-6c6r-5xr4-cr5m
+    - web: https://github.com/go-gitea/gitea/commit/de4b8277e9cb576f2315fb03b5ab6478b42a1d31
+    - web: https://github.com/go-gitea/gitea/commit/f69e15afe7496cc62e96dab244629c69eb31a7bf
+    - web: https://github.com/go-gitea/gitea/pull/38406
+    - web: https://github.com/go-gitea/gitea/pull/38426
+    - web: https://github.com/go-gitea/gitea/releases/tag/v1.27.0
+source:
+    id: GHSA-6c6r-5xr4-cr5m
+    created: 2026-07-21T19:07:51.238689-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6036.yaml b/data/reports/GO-2026-6036.yaml
new file mode 100644
index 0000000..9285051
--- /dev/null
+++ b/data/reports/GO-2026-6036.yaml
@@ -0,0 +1,20 @@
+id: GO-2026-6036
+modules:
+    - module: gitea.dev
+      versions:
+        - fixed: 1.27.0
+      vulnerable_at: 1.27.0-rc0
+summary: |-
+    Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement
+    (incomplete fix of #37698) in gitea.dev
+cves:
+    - CVE-2026-50105
+ghsas:
+    - GHSA-6cqf-375w-639g
+references:
+    - advisory: https://github.com/go-gitea/gitea/security/advisories/GHSA-6cqf-375w-639g
+    - web: https://github.com/go-gitea/gitea/releases/tag/v1.27.0
+source:
+    id: GHSA-6cqf-375w-639g
+    created: 2026-07-21T19:07:46.305851-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6037.yaml b/data/reports/GO-2026-6037.yaml
new file mode 100644
index 0000000..08cfab7
--- /dev/null
+++ b/data/reports/GO-2026-6037.yaml
@@ -0,0 +1,24 @@
+id: GO-2026-6037
+modules:
+    - module: gitea.dev
+      versions:
+        - fixed: 1.27.0
+      vulnerable_at: 1.27.0-rc0
+summary: |-
+    Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String
+    Concatenation in Debian Package Upload in gitea.dev
+cves:
+    - CVE-2026-56755
+ghsas:
+    - GHSA-6hm7-3pwj-22rm
+references:
+    - advisory: https://github.com/go-gitea/gitea/security/advisories/GHSA-6hm7-3pwj-22rm
+    - web: https://github.com/go-gitea/gitea/commit/de4b8277e9cb576f2315fb03b5ab6478b42a1d31
+    - web: https://github.com/go-gitea/gitea/commit/f69e15afe7496cc62e96dab244629c69eb31a7bf
+    - web: https://github.com/go-gitea/gitea/pull/38406
+    - web: https://github.com/go-gitea/gitea/pull/38426
+    - web: https://github.com/go-gitea/gitea/releases/tag/v1.27.0
+source:
+    id: GHSA-6hm7-3pwj-22rm
+    created: 2026-07-21T19:07:38.125244-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6038.yaml b/data/reports/GO-2026-6038.yaml
new file mode 100644
index 0000000..792a6f0
--- /dev/null
+++ b/data/reports/GO-2026-6038.yaml
@@ -0,0 +1,18 @@
+id: GO-2026-6038
+modules:
+    - module: gitea.dev
+      versions:
+        - fixed: 1.27.0
+      vulnerable_at: 1.27.0-rc0
+summary: 'Gitea: Two SSRF findings in gitea.dev'
+cves:
+    - CVE-2026-58314
+ghsas:
+    - GHSA-2fcr-jfvc-vgg2
+references:
+    - advisory: https://github.com/go-gitea/gitea/security/advisories/GHSA-2fcr-jfvc-vgg2
+    - web: https://github.com/go-gitea/gitea/releases/tag/v1.27.0
+source:
+    id: GHSA-2fcr-jfvc-vgg2
+    created: 2026-07-21T19:07:33.401416-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6039.yaml b/data/reports/GO-2026-6039.yaml
new file mode 100644
index 0000000..770f394
--- /dev/null
+++ b/data/reports/GO-2026-6039.yaml
@@ -0,0 +1,20 @@
+id: GO-2026-6039
+modules:
+    - module: gitea.dev
+      versions:
+        - fixed: 1.27.0
+      vulnerable_at: 1.27.0-rc0
+summary: |-
+    Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads
+    Internal Files and Cloud Metadata in gitea.dev
+cves:
+    - CVE-2026-59765
+ghsas:
+    - GHSA-2wm4-vwp6-v7xc
+references:
+    - advisory: https://github.com/go-gitea/gitea/security/advisories/GHSA-2wm4-vwp6-v7xc
+    - web: https://github.com/go-gitea/gitea/releases/tag/v1.27.0
+source:
+    id: GHSA-2wm4-vwp6-v7xc
+    created: 2026-07-21T19:07:28.515219-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6040.yaml b/data/reports/GO-2026-6040.yaml
new file mode 100644
index 0000000..403c4fb
--- /dev/null
+++ b/data/reports/GO-2026-6040.yaml
@@ -0,0 +1,18 @@
+id: GO-2026-6040
+modules:
+    - module: gitea.dev
+      versions:
+        - fixed: 1.27.0
+      vulnerable_at: 1.27.0-rc0
+summary: 'Gitea: Webhook Authorization Header Returned in Plaintext via API in gitea.dev'
+cves:
+    - CVE-2026-58511
+ghsas:
+    - GHSA-3r5c-2xxx-h872
+references:
+    - advisory: https://github.com/go-gitea/gitea/security/advisories/GHSA-3r5c-2xxx-h872
+    - web: https://github.com/go-gitea/gitea/releases/tag/v1.27.0
+source:
+    id: GHSA-3r5c-2xxx-h872
+    created: 2026-07-21T19:07:23.617659-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6041.yaml b/data/reports/GO-2026-6041.yaml
new file mode 100644
index 0000000..61a276a
--- /dev/null
+++ b/data/reports/GO-2026-6041.yaml
@@ -0,0 +1,22 @@
+id: GO-2026-6041
+modules:
+    - module: code.gitea.io/gitea
+      versions:
+        - fixed: 1.26.4
+      vulnerable_at: 1.26.3
+summary: 'Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea'
+cves:
+    - CVE-2026-58419
+ghsas:
+    - GHSA-44qc-pgvp-wx7v
+references:
+    - advisory: https://github.com/go-gitea/gitea/security/advisories/GHSA-44qc-pgvp-wx7v
+    - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-58419
+    - web: https://blog.gitea.com/release-of-1.26.3-and-1.26.4
+    - web: https://github.com/go-gitea/gitea/commit/9e84deb969aff5c1115c2984e41250f28c78451f
+    - web: https://github.com/go-gitea/gitea/pull/38108
+    - web: https://github.com/go-gitea/gitea/releases/tag/v1.26.4
+source:
+    id: GHSA-44qc-pgvp-wx7v
+    created: 2026-07-21T19:07:16.257071-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6042.yaml b/data/reports/GO-2026-6042.yaml
new file mode 100644
index 0000000..585472f
--- /dev/null
+++ b/data/reports/GO-2026-6042.yaml
@@ -0,0 +1,18 @@
+id: GO-2026-6042
+modules:
+    - module: gitea.dev
+      versions:
+        - fixed: 1.27.0
+      vulnerable_at: 1.27.0-rc0
+summary: Gitea SSH Key Parser Denial of Service in gitea.dev
+cves:
+    - CVE-2026-56657
+ghsas:
+    - GHSA-4xjf-493q-98p3
+references:
+    - advisory: https://github.com/go-gitea/gitea/security/advisories/GHSA-4xjf-493q-98p3
+    - web: https://github.com/go-gitea/gitea/releases/tag/v1.27.0
+source:
+    id: GHSA-4xjf-493q-98p3
+    created: 2026-07-21T19:07:11.398497-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6043.yaml b/data/reports/GO-2026-6043.yaml
new file mode 100644
index 0000000..fbb74fc
--- /dev/null
+++ b/data/reports/GO-2026-6043.yaml
@@ -0,0 +1,24 @@
+id: GO-2026-6043
+modules:
+    - module: code.gitea.io/gitea
+      versions:
+        - fixed: 1.26.3
+      vulnerable_at: 1.26.2
+summary: |-
+    Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full
+    Repository Write in code.gitea.io/gitea
+cves:
+    - CVE-2026-27775
+ghsas:
+    - GHSA-649p-mmhf-85c7
+references:
+    - advisory: https://github.com/go-gitea/gitea/security/advisories/GHSA-649p-mmhf-85c7
+    - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-27775
+    - web: https://blog.gitea.com/release-of-1.26.3-and-1.26.4
+    - web: https://github.com/go-gitea/gitea/commit/99f8b3d9a1d32f4c39828e07971455a18191e0b9
+    - web: https://github.com/go-gitea/gitea/pull/38151
+    - web: https://github.com/go-gitea/gitea/releases/tag/v1.26.3
+source:
+    id: GHSA-649p-mmhf-85c7
+    created: 2026-07-21T19:07:04.029266-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6044.yaml b/data/reports/GO-2026-6044.yaml
new file mode 100644
index 0000000..d925b01
--- /dev/null
+++ b/data/reports/GO-2026-6044.yaml
@@ -0,0 +1,23 @@
+id: GO-2026-6044
+modules:
+    - module: code.gitea.io/gitea
+      versions:
+        - fixed: 1.26.3
+      vulnerable_at: 1.26.2
+summary: 'Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea'
+cves:
+    - CVE-2026-58424
+ghsas:
+    - GHSA-777r-4v59-6486
+references:
+    - advisory: https://github.com/go-gitea/gitea/security/advisories/GHSA-777r-4v59-6486
+    - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-58424
+    - web: https://blog.gitea.com/release-of-1.26.3-and-1.26.4
+    - web: https://github.com/go-gitea/gitea/commit/699fe2ef43b9466ac1b0cb857029f91fd5b0056d
+    - web: https://github.com/go-gitea/gitea/commit/e107498f3b6fccff35455ef17430ca68df665297
+    - web: https://github.com/go-gitea/gitea/pull/38010
+    - web: https://github.com/go-gitea/gitea/releases/tag/v1.26.4
+source:
+    id: GHSA-777r-4v59-6486
+    created: 2026-07-21T19:06:55.624407-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6045.yaml b/data/reports/GO-2026-6045.yaml
new file mode 100644
index 0000000..0071ba7
--- /dev/null
+++ b/data/reports/GO-2026-6045.yaml
@@ -0,0 +1,20 @@
+id: GO-2026-6045
+modules:
+    - module: gitea.dev
+      versions:
+        - fixed: 1.27.0
+      vulnerable_at: 1.27.0-rc0
+summary: |-
+    Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository
+    + Package categories) — residual after CVE-2026-25714 / PR #37118 in gitea.dev
+cves:
+    - CVE-2026-56443
+ghsas:
+    - GHSA-7p4h-3gxq-x3h3
+references:
+    - advisory: https://github.com/go-gitea/gitea/security/advisories/GHSA-7p4h-3gxq-x3h3
+    - web: https://github.com/go-gitea/gitea/releases/tag/v1.27.0
+source:
+    id: GHSA-7p4h-3gxq-x3h3
+    created: 2026-07-21T19:06:50.86854-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6046.yaml b/data/reports/GO-2026-6046.yaml
new file mode 100644
index 0000000..c4a042f
--- /dev/null
+++ b/data/reports/GO-2026-6046.yaml
@@ -0,0 +1,26 @@
+id: GO-2026-6046
+modules:
+    - module: code.gitea.io/gitea
+      versions:
+        - introduced: 1.23.0
+        - fixed: 1.26.3
+      vulnerable_at: 1.26.2
+summary: |-
+    Gitea: LFS authentication bypass via malformed SSH sub-verb allows unauthorized
+    read access to private repositories in code.gitea.io/gitea
+cves:
+    - CVE-2026-58423
+ghsas:
+    - GHSA-7wvc-rvp7-w99x
+references:
+    - advisory: https://github.com/go-gitea/gitea/security/advisories/GHSA-7wvc-rvp7-w99x
+    - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-58423
+    - web: https://blog.gitea.com/release-of-1.26.3-and-1.26.4
+    - web: https://github.com/go-gitea/gitea/commit/42513398c05ca6bdf71da76cb6f9baaebe8cb924
+    - web: https://github.com/go-gitea/gitea/commit/8f4b7ebbf6061bd44b1ab3824f17f37b87fb1740
+    - web: https://github.com/go-gitea/gitea/pull/38008
+    - web: https://github.com/go-gitea/gitea/releases/tag/v1.26.4
+source:
+    id: GHSA-7wvc-rvp7-w99x
+    created: 2026-07-21T19:06:42.944565-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6047.yaml b/data/reports/GO-2026-6047.yaml
new file mode 100644
index 0000000..ea59cff
--- /dev/null
+++ b/data/reports/GO-2026-6047.yaml
@@ -0,0 +1,18 @@
+id: GO-2026-6047
+modules:
+    - module: gitea.dev
+      versions:
+        - fixed: 1.27.0
+      vulnerable_at: 1.27.0-rc0
+summary: 'Gitea: Repository Visibility Manipulation via Git Push Options in gitea.dev'
+cves:
+    - CVE-2026-58437
+ghsas:
+    - GHSA-8p9h-49rc-qgxj
+references:
+    - advisory: https://github.com/go-gitea/gitea/security/advisories/GHSA-8p9h-49rc-qgxj
+    - web: https://github.com/go-gitea/gitea/releases/tag/v1.27.0
+source:
+    id: GHSA-8p9h-49rc-qgxj
+    created: 2026-07-21T19:06:37.832989-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6048.yaml b/data/reports/GO-2026-6048.yaml
new file mode 100644
index 0000000..a1c19cb
--- /dev/null
+++ b/data/reports/GO-2026-6048.yaml
@@ -0,0 +1,20 @@
+id: GO-2026-6048
+modules:
+    - module: gitea.dev
+      versions:
+        - fixed: 1.27.0
+      vulnerable_at: 1.27.0-rc0
+summary: |-
+    Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config
+    override in gitea.dev
+cves:
+    - CVE-2026-54481
+ghsas:
+    - GHSA-94v3-77j7-vm48
+references:
+    - advisory: https://github.com/go-gitea/gitea/security/advisories/GHSA-94v3-77j7-vm48
+    - web: https://github.com/go-gitea/gitea/releases/tag/v1.27.0
+source:
+    id: GHSA-94v3-77j7-vm48
+    created: 2026-07-21T19:06:32.924611-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6049.yaml b/data/reports/GO-2026-6049.yaml
new file mode 100644
index 0000000..574506f
--- /dev/null
+++ b/data/reports/GO-2026-6049.yaml
@@ -0,0 +1,24 @@
+id: GO-2026-6049
+modules:
+    - module: gitea.dev
+      versions:
+        - fixed: 1.27.0
+      vulnerable_at: 1.27.0-rc0
+summary: |-
+    Gitea: Unbounded Arch package file metadata can cause resource amplification in
+    Gitea package uploads in gitea.dev
+cves:
+    - CVE-2026-59763
+ghsas:
+    - GHSA-9mq6-mqjj-c2c5
+references:
+    - advisory: https://github.com/go-gitea/gitea/security/advisories/GHSA-9mq6-mqjj-c2c5
+    - web: https://github.com/go-gitea/gitea/commit/de4b8277e9cb576f2315fb03b5ab6478b42a1d31
+    - web: https://github.com/go-gitea/gitea/commit/f69e15afe7496cc62e96dab244629c69eb31a7bf
+    - web: https://github.com/go-gitea/gitea/pull/38406
+    - web: https://github.com/go-gitea/gitea/pull/38426
+    - web: https://github.com/go-gitea/gitea/releases/tag/v1.27.0
+source:
+    id: GHSA-9mq6-mqjj-c2c5
+    created: 2026-07-21T19:06:24.708317-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6050.yaml b/data/reports/GO-2026-6050.yaml
new file mode 100644
index 0000000..a6af640
--- /dev/null
+++ b/data/reports/GO-2026-6050.yaml
@@ -0,0 +1,20 @@
+id: GO-2026-6050
+modules:
+    - module: gitea.dev
+      versions:
+        - fixed: 1.27.0
+      vulnerable_at: 1.27.0-rc0
+summary: |-
+    Gitea: Personal access token scope enforcement bypass on the repository home
+    page (`GET /{owner}/{repo}`) discloses private repository contents in gitea.dev
+cves:
+    - CVE-2026-58444
+ghsas:
+    - GHSA-cp3q-vrj2-ghhh
+references:
+    - advisory: https://github.com/go-gitea/gitea/security/advisories/GHSA-cp3q-vrj2-ghhh
+    - web: https://github.com/go-gitea/gitea/releases/tag/v1.27.0
+source:
+    id: GHSA-cp3q-vrj2-ghhh
+    created: 2026-07-21T19:06:19.4357-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6051.yaml b/data/reports/GO-2026-6051.yaml
new file mode 100644
index 0000000..6c2d905
--- /dev/null
+++ b/data/reports/GO-2026-6051.yaml
@@ -0,0 +1,24 @@
+id: GO-2026-6051
+modules:
+    - module: code.gitea.io/gitea
+      versions:
+        - fixed: 1.26.3
+      vulnerable_at: 1.26.2
+summary: |-
+    Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source
+    IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
+cves:
+    - CVE-2026-20896
+ghsas:
+    - GHSA-f75j-4cw6-rmx4
+references:
+    - advisory: https://github.com/go-gitea/gitea/security/advisories/GHSA-f75j-4cw6-rmx4
+    - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-20896
+    - web: https://blog.gitea.com/release-of-1.26.3-and-1.26.4
+    - web: https://github.com/go-gitea/gitea/commit/99f8b3d9a1d32f4c39828e07971455a18191e0b9
+    - web: https://github.com/go-gitea/gitea/pull/38151
+    - web: https://github.com/go-gitea/gitea/releases/tag/v1.26.3
+source:
+    id: GHSA-f75j-4cw6-rmx4
+    created: 2026-07-21T19:06:12.343038-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6052.yaml b/data/reports/GO-2026-6052.yaml
new file mode 100644
index 0000000..9d66d67
--- /dev/null
+++ b/data/reports/GO-2026-6052.yaml
@@ -0,0 +1,22 @@
+id: GO-2026-6052
+modules:
+    - module: gitea.dev
+      versions:
+        - fixed: 1.27.0
+      vulnerable_at: 1.27.0-rc0
+summary: |-
+    Gitea: Fork-PR Actions task can read a third private repository via the
+    collaborative-owner branch (missing fork-PR guard) in gitea.dev
+cves:
+    - CVE-2026-58416
+ghsas:
+    - GHSA-fj8v-hjwv-qm88
+references:
+    - advisory: https://github.com/go-gitea/gitea/security/advisories/GHSA-fj8v-hjwv-qm88
+    - web: https://github.com/go-gitea/gitea/commit/1d43b736b5a16c5f80cfdcd9a9448a9c983ddaa0
+    - web: https://github.com/go-gitea/gitea/pull/38214
+    - web: https://github.com/go-gitea/gitea/releases/tag/v1.27.0
+source:
+    id: GHSA-fj8v-hjwv-qm88
+    created: 2026-07-21T19:06:06.896845-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6053.yaml b/data/reports/GO-2026-6053.yaml
new file mode 100644
index 0000000..384b66b
--- /dev/null
+++ b/data/reports/GO-2026-6053.yaml
@@ -0,0 +1,24 @@
+id: GO-2026-6053
+modules:
+    - module: gitea.dev
+      versions:
+        - fixed: 1.27.0
+      vulnerable_at: 1.27.0-rc0
+summary: |-
+    Gitea: Public-Only Personal access tokens scope bypass in Organization and
+    Permission Endpoints in gitea.dev
+cves:
+    - CVE-2026-58429
+ghsas:
+    - GHSA-fq2p-5p22-8g6j
+references:
+    - advisory: https://github.com/go-gitea/gitea/security/advisories/GHSA-fq2p-5p22-8g6j
+    - web: https://github.com/go-gitea/gitea/commit/a34eac5ef42ada433a7c7dafb98f15c13d7ad74e
+    - web: https://github.com/go-gitea/gitea/commit/f2a1271f164569264c378fad720b0c000fff3336
+    - web: https://github.com/go-gitea/gitea/pull/37118
+    - web: https://github.com/go-gitea/gitea/pull/37773
+    - web: https://github.com/go-gitea/gitea/releases/tag/v1.27.0
+source:
+    id: GHSA-fq2p-5p22-8g6j
+    created: 2026-07-21T19:05:57.417501-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6054.yaml b/data/reports/GO-2026-6054.yaml
new file mode 100644
index 0000000..ab72a04
--- /dev/null
+++ b/data/reports/GO-2026-6054.yaml
@@ -0,0 +1,18 @@
+id: GO-2026-6054
+modules:
+    - module: gitea.dev
+      versions:
+        - fixed: 1.27.0
+      vulnerable_at: 1.27.0-rc0
+summary: 'Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs in gitea.dev'
+cves:
+    - CVE-2026-57897
+ghsas:
+    - GHSA-frpw-3h2q-4jj6
+references:
+    - advisory: https://github.com/go-gitea/gitea/security/advisories/GHSA-frpw-3h2q-4jj6
+    - web: https://github.com/go-gitea/gitea/releases/tag/v1.27.0
+source:
+    id: GHSA-frpw-3h2q-4jj6
+    created: 2026-07-21T19:05:51.969425-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6055.yaml b/data/reports/GO-2026-6055.yaml
new file mode 100644
index 0000000..8c9eaac
--- /dev/null
+++ b/data/reports/GO-2026-6055.yaml
@@ -0,0 +1,21 @@
+id: GO-2026-6055
+modules:
+    - module: gitea.dev
+      versions:
+        - fixed: 1.27.0
+      vulnerable_at: 1.27.0-rc0
+summary: |-
+    Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on
+    unauthenticated requests in gitea.dev
+cves:
+    - CVE-2026-58436
+ghsas:
+    - GHSA-fw57-jgch-pgf3
+references:
+    - advisory: https://github.com/go-gitea/gitea/security/advisories/GHSA-fw57-jgch-pgf3
+    - web: https://github.com/go-gitea/gitea/commit/f452c369acc9f1bd05ec6ef9c2e4399062dd6da1
+    - web: https://github.com/go-gitea/gitea/pull/38323
+source:
+    id: GHSA-fw57-jgch-pgf3
+    created: 2026-07-21T19:05:45.263686-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6056.yaml b/data/reports/GO-2026-6056.yaml
new file mode 100644
index 0000000..712818d
--- /dev/null
+++ b/data/reports/GO-2026-6056.yaml
@@ -0,0 +1,24 @@
+id: GO-2026-6056
+modules:
+    - module: code.gitea.io/gitea
+      versions:
+        - fixed: 1.26.4
+      vulnerable_at: 1.26.3
+summary: |-
+    Gitea: Improper authorization on OAuth sign-in callback silently re-enables
+    administrator-disabled accounts in code.gitea.io/gitea
+cves:
+    - CVE-2026-58422
+ghsas:
+    - GHSA-g9g6-qhrc-p3qc
+references:
+    - advisory: https://github.com/go-gitea/gitea/security/advisories/GHSA-g9g6-qhrc-p3qc
+    - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-58422
+    - web: https://blog.gitea.com/release-of-1.26.3-and-1.26.4
+    - web: https://github.com/go-gitea/gitea/commit/c43eb7c33a100ffc7b2367adf165f7085e0ccdc5
+    - web: https://github.com/go-gitea/gitea/pull/38009
+    - web: https://github.com/go-gitea/gitea/releases/tag/v1.26.4
+source:
+    id: GHSA-g9g6-qhrc-p3qc
+    created: 2026-07-21T19:05:37.595171-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6057.yaml b/data/reports/GO-2026-6057.yaml
new file mode 100644
index 0000000..ee279d7
--- /dev/null
+++ b/data/reports/GO-2026-6057.yaml
@@ -0,0 +1,25 @@
+id: GO-2026-6057
+modules:
+    - module: code.gitea.io/gitea
+      versions:
+        - introduced: 1.5.0
+        - fixed: 1.26.3
+      vulnerable_at: 1.26.2
+summary: |-
+    Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth
+    `X-Gitea-OTP` surface in code.gitea.io/gitea
+cves:
+    - CVE-2026-20779
+ghsas:
+    - GHSA-gx3v-q759-g323
+references:
+    - advisory: https://github.com/go-gitea/gitea/security/advisories/GHSA-gx3v-q759-g323
+    - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-20779
+    - web: https://blog.gitea.com/release-of-1.26.3-and-1.26.4
+    - web: https://github.com/go-gitea/gitea/commit/99f8b3d9a1d32f4c39828e07971455a18191e0b9
+    - web: https://github.com/go-gitea/gitea/pull/38151
+    - web: https://github.com/go-gitea/gitea/releases/tag/v1.26.3
+source:
+    id: GHSA-gx3v-q759-g323
+    created: 2026-07-21T19:53:53.941294-04:00
+review_status: UNREVIEWED