data/reports: add 43 reports - data/reports/GO-2026-6015.yaml - data/reports/GO-2026-6016.yaml - data/reports/GO-2026-6017.yaml - data/reports/GO-2026-6018.yaml - data/reports/GO-2026-6019.yaml - data/reports/GO-2026-6020.yaml - data/reports/GO-2026-6021.yaml - data/reports/GO-2026-6022.yaml - data/reports/GO-2026-6023.yaml - data/reports/GO-2026-6024.yaml - data/reports/GO-2026-6025.yaml - data/reports/GO-2026-6026.yaml - data/reports/GO-2026-6027.yaml - data/reports/GO-2026-6028.yaml - data/reports/GO-2026-6029.yaml - data/reports/GO-2026-6030.yaml - data/reports/GO-2026-6031.yaml - data/reports/GO-2026-6032.yaml - data/reports/GO-2026-6033.yaml - data/reports/GO-2026-6034.yaml - data/reports/GO-2026-6035.yaml - data/reports/GO-2026-6036.yaml - data/reports/GO-2026-6037.yaml - data/reports/GO-2026-6038.yaml - data/reports/GO-2026-6039.yaml - data/reports/GO-2026-6040.yaml - data/reports/GO-2026-6041.yaml - data/reports/GO-2026-6042.yaml - data/reports/GO-2026-6043.yaml - data/reports/GO-2026-6044.yaml - data/reports/GO-2026-6045.yaml - data/reports/GO-2026-6046.yaml - data/reports/GO-2026-6047.yaml - data/reports/GO-2026-6048.yaml - data/reports/GO-2026-6049.yaml - data/reports/GO-2026-6050.yaml - data/reports/GO-2026-6051.yaml - data/reports/GO-2026-6052.yaml - data/reports/GO-2026-6053.yaml - data/reports/GO-2026-6054.yaml - data/reports/GO-2026-6055.yaml - data/reports/GO-2026-6056.yaml - data/reports/GO-2026-6057.yaml Fixes golang/vulndb#6015 Fixes golang/vulndb#6016 Fixes golang/vulndb#6017 Fixes golang/vulndb#6018 Fixes golang/vulndb#6019 Fixes golang/vulndb#6020 Fixes golang/vulndb#6021 Fixes golang/vulndb#6022 Fixes golang/vulndb#6023 Fixes golang/vulndb#6024 Fixes golang/vulndb#6025 Fixes golang/vulndb#6026 Fixes golang/vulndb#6027 Fixes golang/vulndb#6028 Fixes golang/vulndb#6029 Fixes golang/vulndb#6030 Fixes golang/vulndb#6031 Fixes golang/vulndb#6032 Fixes golang/vulndb#6033 Fixes golang/vulndb#6034 Fixes golang/vulndb#6035 Fixes golang/vulndb#6036 Fixes golang/vulndb#6037 Fixes golang/vulndb#6038 Fixes golang/vulndb#6039 Fixes golang/vulndb#6040 Fixes golang/vulndb#6041 Fixes golang/vulndb#6042 Fixes golang/vulndb#6043 Fixes golang/vulndb#6044 Fixes golang/vulndb#6045 Fixes golang/vulndb#6046 Fixes golang/vulndb#6047 Fixes golang/vulndb#6048 Fixes golang/vulndb#6049 Fixes golang/vulndb#6050 Fixes golang/vulndb#6051 Fixes golang/vulndb#6052 Fixes golang/vulndb#6053 Fixes golang/vulndb#6054 Fixes golang/vulndb#6055 Fixes golang/vulndb#6056 Fixes golang/vulndb#6057 Change-Id: Ia4cf388021edbda8280e64f6fe176c65f1214426 Reviewed-on: https://go-review.googlesource.com/c/vulndb/+/803940 LUCI-TryBot-Result: golang-scoped@luci-project-accounts.iam.gserviceaccount.com <golang-scoped@luci-project-accounts.iam.gserviceaccount.com> Reviewed-by: Nicholas Husin <nsh@golang.org> Reviewed-by: Nicholas Husin <husin@google.com>
diff --git a/data/osv/GO-2026-6015.json b/data/osv/GO-2026-6015.json new file mode 100644 index 0000000..fb8e247 --- /dev/null +++ b/data/osv/GO-2026-6015.json
@@ -0,0 +1,48 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6015", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-54247", + "GHSA-cwxq-rc9x-2jvv" + ], + "summary": "Skipper: Unbounded Request Body Read in Admission Webhook Causes Memory Exhaustion DoS in github.com/zalando/skipper", + "details": "Skipper: Unbounded Request Body Read in Admission Webhook Causes Memory Exhaustion DoS in github.com/zalando/skipper", + "affected": [ + { + "package": { + "name": "github.com/zalando/skipper", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.26.22" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/zalando/skipper/security/advisories/GHSA-cwxq-rc9x-2jvv" + }, + { + "type": "WEB", + "url": "https://github.com/zalando/skipper/releases/tag/v0.26.22" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6015", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6016.json b/data/osv/GO-2026-6016.json new file mode 100644 index 0000000..8ee02e8 --- /dev/null +++ b/data/osv/GO-2026-6016.json
@@ -0,0 +1,68 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6016", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "GHSA-rjwr-m7qx-3fjr" + ], + "summary": "oapi-codegen: OpenAPI Server Description Escapes Generated Go Comment and Injects Executable Code in github.com/oapi-codegen/oapi-codegen", + "details": "oapi-codegen: OpenAPI Server Description Escapes Generated Go Comment and Injects Executable Code in github.com/oapi-codegen/oapi-codegen", + "affected": [ + { + "package": { + "name": "github.com/oapi-codegen/oapi-codegen", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": {} + }, + { + "package": { + "name": "github.com/oapi-codegen/oapi-codegen/v2", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "2.7.1" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/oapi-codegen/oapi-codegen/security/advisories/GHSA-rjwr-m7qx-3fjr" + }, + { + "type": "FIX", + "url": "https://github.com/oapi-codegen/oapi-codegen/commit/19c6282e9a6fb84b51aa92b12fad1f0b7e5f5ef6" + }, + { + "type": "WEB", + "url": "https://github.com/oapi-codegen/oapi-codegen/releases/tag/v2.7.1" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6016", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6017.json b/data/osv/GO-2026-6017.json new file mode 100644 index 0000000..90b752f --- /dev/null +++ b/data/osv/GO-2026-6017.json
@@ -0,0 +1,60 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6017", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-27771", + "GHSA-8qw8-rq86-9pc2" + ], + "summary": "Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea", + "details": "Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea", + "affected": [ + { + "package": { + "name": "code.gitea.io/gitea", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.26.2" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/go-gitea/gitea/security/advisories/GHSA-8qw8-rq86-9pc2" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27771" + }, + { + "type": "WEB", + "url": "https://blog.gitea.com/release-of-1.26.2" + }, + { + "type": "WEB", + "url": "https://github.com/go-gitea/gitea/pull/37610" + }, + { + "type": "WEB", + "url": "https://github.com/go-gitea/gitea/releases/tag/v1.26.2" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6017", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6018.json b/data/osv/GO-2026-6018.json new file mode 100644 index 0000000..0b846a7 --- /dev/null +++ b/data/osv/GO-2026-6018.json
@@ -0,0 +1,48 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6018", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-54246", + "GHSA-5587-2x54-jj6h" + ], + "summary": "Skipper's routesrv-no-auth component: All routesrv API Endpoints Lack Authentication in github.com/zalando/skipper", + "details": "Skipper's routesrv-no-auth component: All routesrv API Endpoints Lack Authentication in github.com/zalando/skipper", + "affected": [ + { + "package": { + "name": "github.com/zalando/skipper", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.27.13" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/zalando/skipper/security/advisories/GHSA-5587-2x54-jj6h" + }, + { + "type": "WEB", + "url": "https://github.com/zalando/skipper/releases/tag/v0.27.13" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6018", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6019.json b/data/osv/GO-2026-6019.json new file mode 100644 index 0000000..7ca3c52 --- /dev/null +++ b/data/osv/GO-2026-6019.json
@@ -0,0 +1,47 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6019", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "GHSA-8qqm-fp2q-v734" + ], + "summary": "Skipper: Incomplete fix for CVE-2026-50197: an oversized body can bypass OPA deny-on-presence Rego policies in github.com/zalando/skipper", + "details": "Skipper: Incomplete fix for CVE-2026-50197: an oversized body can bypass OPA deny-on-presence Rego policies in github.com/zalando/skipper", + "affected": [ + { + "package": { + "name": "github.com/zalando/skipper", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.27.26" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/zalando/skipper/security/advisories/GHSA-8qqm-fp2q-v734" + }, + { + "type": "WEB", + "url": "https://github.com/zalando/skipper/releases/tag/v0.27.26" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6019", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6020.json b/data/osv/GO-2026-6020.json new file mode 100644 index 0000000..43097f1 --- /dev/null +++ b/data/osv/GO-2026-6020.json
@@ -0,0 +1,73 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6020", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-55668", + "GHSA-8wc8-hf36-mjh9" + ], + "summary": "File Browser: ScopedFs follows a dangling symlink on write, letting a scoped user create files outside their scope in github.com/filebrowser/filebrowser", + "details": "File Browser: ScopedFs follows a dangling symlink on write, letting a scoped user create files outside their scope in github.com/filebrowser/filebrowser", + "affected": [ + { + "package": { + "name": "github.com/filebrowser/filebrowser", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": {} + }, + { + "package": { + "name": "github.com/filebrowser/filebrowser/v2", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "2.63.16" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/filebrowser/filebrowser/security/advisories/GHSA-8wc8-hf36-mjh9" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-55668" + }, + { + "type": "FIX", + "url": "https://github.com/filebrowser/filebrowser/commit/64511ce45e3be379e965f7f4fb0929a068d5bb81" + }, + { + "type": "WEB", + "url": "https://github.com/filebrowser/filebrowser/releases/tag/v2.63.16" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6020", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6021.json b/data/osv/GO-2026-6021.json new file mode 100644 index 0000000..1e54d5d --- /dev/null +++ b/data/osv/GO-2026-6021.json
@@ -0,0 +1,69 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6021", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-55667", + "GHSA-fmm7-x4gx-8jhr" + ], + "summary": "File Browser: Out-of-scope file deletion by a Create-only scoped user via symlink-following RemoveAll in upload failure-cleanup in github.com/filebrowser/filebrowser", + "details": "File Browser: Out-of-scope file deletion by a Create-only scoped user via symlink-following RemoveAll in upload failure-cleanup in github.com/filebrowser/filebrowser", + "affected": [ + { + "package": { + "name": "github.com/filebrowser/filebrowser", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": {} + }, + { + "package": { + "name": "github.com/filebrowser/filebrowser/v2", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "2.63.16" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/filebrowser/filebrowser/security/advisories/GHSA-fmm7-x4gx-8jhr" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-55667" + }, + { + "type": "WEB", + "url": "https://github.com/filebrowser/filebrowser/blob/be23ab3a15bf957928ecfed88de5ab67850c1b9c/http/resource.go#L172-L174" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6021", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6022.json b/data/osv/GO-2026-6022.json new file mode 100644 index 0000000..c7efc7d --- /dev/null +++ b/data/osv/GO-2026-6022.json
@@ -0,0 +1,90 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6022", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-54560", + "GHSA-vgj4-345g-jcf8" + ], + "summary": "Cloudreve: OAuth access tokens bypass scope enforcement due to missing client_id claim in github.com/cloudreve/Cloudreve", + "details": "Cloudreve: OAuth access tokens bypass scope enforcement due to missing client_id claim in github.com/cloudreve/Cloudreve", + "affected": [ + { + "package": { + "name": "github.com/cloudreve/Cloudreve", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": {} + }, + { + "package": { + "name": "github.com/cloudreve/Cloudreve/v3", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": {} + }, + { + "package": { + "name": "github.com/cloudreve/Cloudreve/v4", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "4.0.0-20260114075425-bc6845bd742c" + }, + { + "fixed": "4.0.0-20260606015557-ed20843dc3df" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/cloudreve/cloudreve/security/advisories/GHSA-vgj4-345g-jcf8" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54560" + }, + { + "type": "WEB", + "url": "https://github.com/cloudreve/cloudreve/commit/ed20843dc3df20a25fcaf6b538647e11c4d68d87" + }, + { + "type": "WEB", + "url": "https://github.com/cloudreve/cloudreve/releases/tag/4.16.1" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6022", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6023.json b/data/osv/GO-2026-6023.json new file mode 100644 index 0000000..ee88718 --- /dev/null +++ b/data/osv/GO-2026-6023.json
@@ -0,0 +1,90 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6023", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-54562", + "GHSA-x756-g4x3-c64m" + ], + "summary": "Cloudreve: Non-admin remote download users can SSRF loopback/internal services and read imported responses in github.com/cloudreve/Cloudreve", + "details": "Cloudreve: Non-admin remote download users can SSRF loopback/internal services and read imported responses in github.com/cloudreve/Cloudreve", + "affected": [ + { + "package": { + "name": "github.com/cloudreve/Cloudreve", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": {} + }, + { + "package": { + "name": "github.com/cloudreve/Cloudreve/v3", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": {} + }, + { + "package": { + "name": "github.com/cloudreve/Cloudreve/v4", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "4.0.0-20260606025411-aaebf317a78f" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/cloudreve/cloudreve/security/advisories/GHSA-x756-g4x3-c64m" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54562" + }, + { + "type": "WEB", + "url": "https://github.com/cloudreve/cloudreve/commit/aaebf317a78f2413d74afd66c21a1f3143711312" + }, + { + "type": "WEB", + "url": "https://github.com/cloudreve/cloudreve/releases/tag/4.16.1" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6023", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6024.json b/data/osv/GO-2026-6024.json new file mode 100644 index 0000000..b067cfa --- /dev/null +++ b/data/osv/GO-2026-6024.json
@@ -0,0 +1,73 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6024", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-62685", + "GHSA-7rc3-g7h6-22m7" + ], + "summary": "File Browser: Colliding username normalization gives two users the same home directory in github.com/filebrowser/filebrowser", + "details": "File Browser: Colliding username normalization gives two users the same home directory in github.com/filebrowser/filebrowser", + "affected": [ + { + "package": { + "name": "github.com/filebrowser/filebrowser", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": {} + }, + { + "package": { + "name": "github.com/filebrowser/filebrowser/v2", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "2.63.17" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/filebrowser/filebrowser/security/advisories/GHSA-7rc3-g7h6-22m7" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-62685" + }, + { + "type": "FIX", + "url": "https://github.com/filebrowser/filebrowser/commit/883a36f02fcb69566a8628cb47f18fdc73348387" + }, + { + "type": "WEB", + "url": "https://github.com/filebrowser/filebrowser/releases/tag/v2.63.17" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6024", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6025.json b/data/osv/GO-2026-6025.json new file mode 100644 index 0000000..c12fa0a --- /dev/null +++ b/data/osv/GO-2026-6025.json
@@ -0,0 +1,61 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6025", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-62684", + "GHSA-833g-cqhp-h72j" + ], + "summary": "File Browser: Share API exposes the password hash and bypass token in github.com/filebrowser/filebrowser", + "details": "File Browser: Share API exposes the password hash and bypass token in github.com/filebrowser/filebrowser", + "affected": [ + { + "package": { + "name": "github.com/filebrowser/filebrowser", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": {} + }, + { + "package": { + "name": "github.com/filebrowser/filebrowser/v2", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "2.63.17" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/filebrowser/filebrowser/security/advisories/GHSA-833g-cqhp-h72j" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6025", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6026.json b/data/osv/GO-2026-6026.json new file mode 100644 index 0000000..797b0f7 --- /dev/null +++ b/data/osv/GO-2026-6026.json
@@ -0,0 +1,73 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6026", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-62843", + "GHSA-83xp-526h-j3ww" + ], + "summary": "File Browser: Archive builder turns backslash filenames into path traversal (zip-slip) in github.com/filebrowser/filebrowser", + "details": "File Browser: Archive builder turns backslash filenames into path traversal (zip-slip) in github.com/filebrowser/filebrowser", + "affected": [ + { + "package": { + "name": "github.com/filebrowser/filebrowser", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": {} + }, + { + "package": { + "name": "github.com/filebrowser/filebrowser/v2", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "2.63.6" + }, + { + "fixed": "2.63.17" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/filebrowser/filebrowser/security/advisories/GHSA-83xp-526h-j3ww" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-62843" + }, + { + "type": "FIX", + "url": "https://github.com/filebrowser/filebrowser/commit/8503ba61ff51d48a7313896483d130eb6a5abfe0" + }, + { + "type": "WEB", + "url": "https://github.com/filebrowser/filebrowser/releases/tag/v2.63.17" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6026", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6027.json b/data/osv/GO-2026-6027.json new file mode 100644 index 0000000..9e372e4 --- /dev/null +++ b/data/osv/GO-2026-6027.json
@@ -0,0 +1,48 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6027", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-57894", + "GHSA-82f7-87hm-852x" + ], + "summary": "Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration in gitea.dev", + "details": "Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration in gitea.dev", + "affected": [ + { + "package": { + "name": "gitea.dev", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.27.0" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/go-gitea/gitea/security/advisories/GHSA-82f7-87hm-852x" + }, + { + "type": "WEB", + "url": "https://github.com/go-gitea/gitea/releases/tag/v1.27.0" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6027", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6028.json b/data/osv/GO-2026-6028.json new file mode 100644 index 0000000..54fa3ad --- /dev/null +++ b/data/osv/GO-2026-6028.json
@@ -0,0 +1,64 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6028", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-58428", + "GHSA-25gq-j9jx-43pg" + ], + "summary": "Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) in gitea.dev", + "details": "Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) in gitea.dev", + "affected": [ + { + "package": { + "name": "gitea.dev", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.27.0" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/go-gitea/gitea/security/advisories/GHSA-25gq-j9jx-43pg" + }, + { + "type": "WEB", + "url": "https://github.com/go-gitea/gitea/commit/de4b8277e9cb576f2315fb03b5ab6478b42a1d31" + }, + { + "type": "WEB", + "url": "https://github.com/go-gitea/gitea/commit/f69e15afe7496cc62e96dab244629c69eb31a7bf" + }, + { + "type": "WEB", + "url": "https://github.com/go-gitea/gitea/pull/38406" + }, + { + "type": "WEB", + "url": "https://github.com/go-gitea/gitea/pull/38426" + }, + { + "type": "WEB", + "url": "https://github.com/go-gitea/gitea/releases/tag/v1.27.0" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6028", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6029.json b/data/osv/GO-2026-6029.json new file mode 100644 index 0000000..c5baf03 --- /dev/null +++ b/data/osv/GO-2026-6029.json
@@ -0,0 +1,68 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6029", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-28740", + "GHSA-2m9v-5q2g-58vq" + ], + "summary": "Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea", + "details": "Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea", + "affected": [ + { + "package": { + "name": "code.gitea.io/gitea", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.26.3" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/go-gitea/gitea/security/advisories/GHSA-2m9v-5q2g-58vq" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-28740" + }, + { + "type": "WEB", + "url": "https://blog.gitea.com/release-of-1.26.3-and-1.26.4" + }, + { + "type": "WEB", + "url": "https://github.com/go-gitea/gitea/commit/1c7b7ea72df7cf81e88b8e09049608254d32e56e" + }, + { + "type": "WEB", + "url": "https://github.com/go-gitea/gitea/commit/7b4a1a1a118501b9d0260301dfed7f52dfc36ee9" + }, + { + "type": "WEB", + "url": "https://github.com/go-gitea/gitea/pull/38050" + }, + { + "type": "WEB", + "url": "https://github.com/go-gitea/gitea/releases/tag/v1.26.3" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6029", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6030.json b/data/osv/GO-2026-6030.json new file mode 100644 index 0000000..ec9680d --- /dev/null +++ b/data/osv/GO-2026-6030.json
@@ -0,0 +1,64 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6030", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-22874", + "GHSA-2r5c-gw76-rh3w" + ], + "summary": "Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea", + "details": "Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea", + "affected": [ + { + "package": { + "name": "code.gitea.io/gitea", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.26.3" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/go-gitea/gitea/security/advisories/GHSA-2r5c-gw76-rh3w" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-22874" + }, + { + "type": "WEB", + "url": "https://blog.gitea.com/release-of-1.26.3-and-1.26.4" + }, + { + "type": "WEB", + "url": "https://github.com/go-gitea/gitea/pull/38059" + }, + { + "type": "WEB", + "url": "https://github.com/go-gitea/gitea/pull/38173" + }, + { + "type": "WEB", + "url": "https://github.com/go-gitea/gitea/releases/tag/v1.26.3" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6030", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6031.json b/data/osv/GO-2026-6031.json new file mode 100644 index 0000000..3e1cd93 --- /dev/null +++ b/data/osv/GO-2026-6031.json
@@ -0,0 +1,64 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6031", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-27761", + "GHSA-3pww-vcvm-3gmj" + ], + "summary": "Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea", + "details": "Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea", + "affected": [ + { + "package": { + "name": "code.gitea.io/gitea", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.26.3" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/go-gitea/gitea/security/advisories/GHSA-3pww-vcvm-3gmj" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27761" + }, + { + "type": "WEB", + "url": "https://blog.gitea.com/release-of-1.26.3-and-1.26.4" + }, + { + "type": "WEB", + "url": "https://github.com/go-gitea/gitea/commit/9e84deb969aff5c1115c2984e41250f28c78451f" + }, + { + "type": "WEB", + "url": "https://github.com/go-gitea/gitea/pull/38147" + }, + { + "type": "WEB", + "url": "https://github.com/go-gitea/gitea/releases/tag/v1.26.3" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6031", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6032.json b/data/osv/GO-2026-6032.json new file mode 100644 index 0000000..c932d55 --- /dev/null +++ b/data/osv/GO-2026-6032.json
@@ -0,0 +1,44 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6032", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-58420", + "GHSA-5ggr-2f2h-jmvm" + ], + "summary": "Gitea: Local File Inclusion via file:// URI in Migration Restore in gitea.dev", + "details": "Gitea: Local File Inclusion via file:// URI in Migration Restore in gitea.dev", + "affected": [ + { + "package": { + "name": "gitea.dev", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.27.0" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/go-gitea/gitea/security/advisories/GHSA-5ggr-2f2h-jmvm" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6032", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6033.json b/data/osv/GO-2026-6033.json new file mode 100644 index 0000000..ab057d4 --- /dev/null +++ b/data/osv/GO-2026-6033.json
@@ -0,0 +1,64 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6033", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-58440", + "GHSA-66m4-5jjr-2rg5" + ], + "summary": "Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content in gitea.dev", + "details": "Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content in gitea.dev", + "affected": [ + { + "package": { + "name": "gitea.dev", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.27.0" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/go-gitea/gitea/security/advisories/GHSA-66m4-5jjr-2rg5" + }, + { + "type": "WEB", + "url": "https://github.com/go-gitea/gitea/commit/de4b8277e9cb576f2315fb03b5ab6478b42a1d31" + }, + { + "type": "WEB", + "url": "https://github.com/go-gitea/gitea/commit/f69e15afe7496cc62e96dab244629c69eb31a7bf" + }, + { + "type": "WEB", + "url": "https://github.com/go-gitea/gitea/pull/38406" + }, + { + "type": "WEB", + "url": "https://github.com/go-gitea/gitea/pull/38426" + }, + { + "type": "WEB", + "url": "https://github.com/go-gitea/gitea/releases/tag/v1.27.0" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6033", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6034.json b/data/osv/GO-2026-6034.json new file mode 100644 index 0000000..428a392 --- /dev/null +++ b/data/osv/GO-2026-6034.json
@@ -0,0 +1,64 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6034", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-56654", + "GHSA-683j-3ff6-hh2x" + ], + "summary": "Gitea: Privilege Escalation via Access Token Scope Escalation in API in gitea.dev", + "details": "Gitea: Privilege Escalation via Access Token Scope Escalation in API in gitea.dev", + "affected": [ + { + "package": { + "name": "gitea.dev", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.27.0" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/go-gitea/gitea/security/advisories/GHSA-683j-3ff6-hh2x" + }, + { + "type": "WEB", + "url": "https://github.com/go-gitea/gitea/commit/de4b8277e9cb576f2315fb03b5ab6478b42a1d31" + }, + { + "type": "WEB", + "url": "https://github.com/go-gitea/gitea/commit/f69e15afe7496cc62e96dab244629c69eb31a7bf" + }, + { + "type": "WEB", + "url": "https://github.com/go-gitea/gitea/pull/38406" + }, + { + "type": "WEB", + "url": "https://github.com/go-gitea/gitea/pull/38426" + }, + { + "type": "WEB", + "url": "https://github.com/go-gitea/gitea/releases/tag/v1.27.0" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6034", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6035.json b/data/osv/GO-2026-6035.json new file mode 100644 index 0000000..31f1712 --- /dev/null +++ b/data/osv/GO-2026-6035.json
@@ -0,0 +1,64 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6035", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-57886", + "GHSA-6c6r-5xr4-cr5m" + ], + "summary": "Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content in gitea.dev", + "details": "Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content in gitea.dev", + "affected": [ + { + "package": { + "name": "gitea.dev", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.27.0" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/go-gitea/gitea/security/advisories/GHSA-6c6r-5xr4-cr5m" + }, + { + "type": "WEB", + "url": "https://github.com/go-gitea/gitea/commit/de4b8277e9cb576f2315fb03b5ab6478b42a1d31" + }, + { + "type": "WEB", + "url": "https://github.com/go-gitea/gitea/commit/f69e15afe7496cc62e96dab244629c69eb31a7bf" + }, + { + "type": "WEB", + "url": "https://github.com/go-gitea/gitea/pull/38406" + }, + { + "type": "WEB", + "url": "https://github.com/go-gitea/gitea/pull/38426" + }, + { + "type": "WEB", + "url": "https://github.com/go-gitea/gitea/releases/tag/v1.27.0" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6035", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6036.json b/data/osv/GO-2026-6036.json new file mode 100644 index 0000000..6363f82 --- /dev/null +++ b/data/osv/GO-2026-6036.json
@@ -0,0 +1,48 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6036", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-50105", + "GHSA-6cqf-375w-639g" + ], + "summary": "Gitea: RSS/Atom feed handlers bypass API-token scope \u0026 public-only confinement (incomplete fix of #37698) in gitea.dev", + "details": "Gitea: RSS/Atom feed handlers bypass API-token scope \u0026 public-only confinement (incomplete fix of #37698) in gitea.dev", + "affected": [ + { + "package": { + "name": "gitea.dev", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.27.0" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/go-gitea/gitea/security/advisories/GHSA-6cqf-375w-639g" + }, + { + "type": "WEB", + "url": "https://github.com/go-gitea/gitea/releases/tag/v1.27.0" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6036", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6037.json b/data/osv/GO-2026-6037.json new file mode 100644 index 0000000..628b7ed --- /dev/null +++ b/data/osv/GO-2026-6037.json
@@ -0,0 +1,64 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6037", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-56755", + "GHSA-6hm7-3pwj-22rm" + ], + "summary": "Gitea: Denial of Service (CPU \u0026 Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload in gitea.dev", + "details": "Gitea: Denial of Service (CPU \u0026 Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload in gitea.dev", + "affected": [ + { + "package": { + "name": "gitea.dev", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.27.0" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/go-gitea/gitea/security/advisories/GHSA-6hm7-3pwj-22rm" + }, + { + "type": "WEB", + "url": "https://github.com/go-gitea/gitea/commit/de4b8277e9cb576f2315fb03b5ab6478b42a1d31" + }, + { + "type": "WEB", + "url": "https://github.com/go-gitea/gitea/commit/f69e15afe7496cc62e96dab244629c69eb31a7bf" + }, + { + "type": "WEB", + "url": "https://github.com/go-gitea/gitea/pull/38406" + }, + { + "type": "WEB", + "url": "https://github.com/go-gitea/gitea/pull/38426" + }, + { + "type": "WEB", + "url": "https://github.com/go-gitea/gitea/releases/tag/v1.27.0" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6037", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6038.json b/data/osv/GO-2026-6038.json new file mode 100644 index 0000000..df0b832 --- /dev/null +++ b/data/osv/GO-2026-6038.json
@@ -0,0 +1,48 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6038", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-58314", + "GHSA-2fcr-jfvc-vgg2" + ], + "summary": "Gitea: Two SSRF findings in gitea.dev", + "details": "Gitea: Two SSRF findings in gitea.dev", + "affected": [ + { + "package": { + "name": "gitea.dev", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.27.0" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/go-gitea/gitea/security/advisories/GHSA-2fcr-jfvc-vgg2" + }, + { + "type": "WEB", + "url": "https://github.com/go-gitea/gitea/releases/tag/v1.27.0" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6038", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6039.json b/data/osv/GO-2026-6039.json new file mode 100644 index 0000000..9053531 --- /dev/null +++ b/data/osv/GO-2026-6039.json
@@ -0,0 +1,48 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6039", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-59765", + "GHSA-2wm4-vwp6-v7xc" + ], + "summary": "Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev", + "details": "Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev", + "affected": [ + { + "package": { + "name": "gitea.dev", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.27.0" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/go-gitea/gitea/security/advisories/GHSA-2wm4-vwp6-v7xc" + }, + { + "type": "WEB", + "url": "https://github.com/go-gitea/gitea/releases/tag/v1.27.0" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6039", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6040.json b/data/osv/GO-2026-6040.json new file mode 100644 index 0000000..5a73731 --- /dev/null +++ b/data/osv/GO-2026-6040.json
@@ -0,0 +1,48 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6040", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-58511", + "GHSA-3r5c-2xxx-h872" + ], + "summary": "Gitea: Webhook Authorization Header Returned in Plaintext via API in gitea.dev", + "details": "Gitea: Webhook Authorization Header Returned in Plaintext via API in gitea.dev", + "affected": [ + { + "package": { + "name": "gitea.dev", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.27.0" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/go-gitea/gitea/security/advisories/GHSA-3r5c-2xxx-h872" + }, + { + "type": "WEB", + "url": "https://github.com/go-gitea/gitea/releases/tag/v1.27.0" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6040", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6041.json b/data/osv/GO-2026-6041.json new file mode 100644 index 0000000..e1b191e --- /dev/null +++ b/data/osv/GO-2026-6041.json
@@ -0,0 +1,64 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6041", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-58419", + "GHSA-44qc-pgvp-wx7v" + ], + "summary": "Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea", + "details": "Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea", + "affected": [ + { + "package": { + "name": "code.gitea.io/gitea", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.26.4" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/go-gitea/gitea/security/advisories/GHSA-44qc-pgvp-wx7v" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-58419" + }, + { + "type": "WEB", + "url": "https://blog.gitea.com/release-of-1.26.3-and-1.26.4" + }, + { + "type": "WEB", + "url": "https://github.com/go-gitea/gitea/commit/9e84deb969aff5c1115c2984e41250f28c78451f" + }, + { + "type": "WEB", + "url": "https://github.com/go-gitea/gitea/pull/38108" + }, + { + "type": "WEB", + "url": "https://github.com/go-gitea/gitea/releases/tag/v1.26.4" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6041", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6042.json b/data/osv/GO-2026-6042.json new file mode 100644 index 0000000..b47ee08 --- /dev/null +++ b/data/osv/GO-2026-6042.json
@@ -0,0 +1,48 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6042", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-56657", + "GHSA-4xjf-493q-98p3" + ], + "summary": "Gitea SSH Key Parser Denial of Service in gitea.dev", + "details": "Gitea SSH Key Parser Denial of Service in gitea.dev", + "affected": [ + { + "package": { + "name": "gitea.dev", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.27.0" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/go-gitea/gitea/security/advisories/GHSA-4xjf-493q-98p3" + }, + { + "type": "WEB", + "url": "https://github.com/go-gitea/gitea/releases/tag/v1.27.0" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6042", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6043.json b/data/osv/GO-2026-6043.json new file mode 100644 index 0000000..d9e0572 --- /dev/null +++ b/data/osv/GO-2026-6043.json
@@ -0,0 +1,64 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6043", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-27775", + "GHSA-649p-mmhf-85c7" + ], + "summary": "Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea", + "details": "Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea", + "affected": [ + { + "package": { + "name": "code.gitea.io/gitea", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.26.3" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/go-gitea/gitea/security/advisories/GHSA-649p-mmhf-85c7" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27775" + }, + { + "type": "WEB", + "url": "https://blog.gitea.com/release-of-1.26.3-and-1.26.4" + }, + { + "type": "WEB", + "url": "https://github.com/go-gitea/gitea/commit/99f8b3d9a1d32f4c39828e07971455a18191e0b9" + }, + { + "type": "WEB", + "url": "https://github.com/go-gitea/gitea/pull/38151" + }, + { + "type": "WEB", + "url": "https://github.com/go-gitea/gitea/releases/tag/v1.26.3" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6043", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6044.json b/data/osv/GO-2026-6044.json new file mode 100644 index 0000000..b76a2fb --- /dev/null +++ b/data/osv/GO-2026-6044.json
@@ -0,0 +1,68 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6044", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-58424", + "GHSA-777r-4v59-6486" + ], + "summary": "Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea", + "details": "Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea", + "affected": [ + { + "package": { + "name": "code.gitea.io/gitea", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.26.3" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/go-gitea/gitea/security/advisories/GHSA-777r-4v59-6486" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-58424" + }, + { + "type": "WEB", + "url": "https://blog.gitea.com/release-of-1.26.3-and-1.26.4" + }, + { + "type": "WEB", + "url": "https://github.com/go-gitea/gitea/commit/699fe2ef43b9466ac1b0cb857029f91fd5b0056d" + }, + { + "type": "WEB", + "url": "https://github.com/go-gitea/gitea/commit/e107498f3b6fccff35455ef17430ca68df665297" + }, + { + "type": "WEB", + "url": "https://github.com/go-gitea/gitea/pull/38010" + }, + { + "type": "WEB", + "url": "https://github.com/go-gitea/gitea/releases/tag/v1.26.4" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6044", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6045.json b/data/osv/GO-2026-6045.json new file mode 100644 index 0000000..e39feb1 --- /dev/null +++ b/data/osv/GO-2026-6045.json
@@ -0,0 +1,48 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6045", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-56443", + "GHSA-7p4h-3gxq-x3h3" + ], + "summary": "Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository\n+ Package categories) — residual after CVE-2026-25714 / PR #37118 in gitea.dev", + "details": "Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository\n+ Package categories) — residual after CVE-2026-25714 / PR #37118 in gitea.dev", + "affected": [ + { + "package": { + "name": "gitea.dev", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.27.0" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/go-gitea/gitea/security/advisories/GHSA-7p4h-3gxq-x3h3" + }, + { + "type": "WEB", + "url": "https://github.com/go-gitea/gitea/releases/tag/v1.27.0" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6045", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6046.json b/data/osv/GO-2026-6046.json new file mode 100644 index 0000000..2f88b70 --- /dev/null +++ b/data/osv/GO-2026-6046.json
@@ -0,0 +1,68 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6046", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-58423", + "GHSA-7wvc-rvp7-w99x" + ], + "summary": "Gitea: LFS authentication bypass via malformed SSH sub-verb allows unauthorized read access to private repositories in code.gitea.io/gitea", + "details": "Gitea: LFS authentication bypass via malformed SSH sub-verb allows unauthorized read access to private repositories in code.gitea.io/gitea", + "affected": [ + { + "package": { + "name": "code.gitea.io/gitea", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "1.23.0" + }, + { + "fixed": "1.26.3" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/go-gitea/gitea/security/advisories/GHSA-7wvc-rvp7-w99x" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-58423" + }, + { + "type": "WEB", + "url": "https://blog.gitea.com/release-of-1.26.3-and-1.26.4" + }, + { + "type": "WEB", + "url": "https://github.com/go-gitea/gitea/commit/42513398c05ca6bdf71da76cb6f9baaebe8cb924" + }, + { + "type": "WEB", + "url": "https://github.com/go-gitea/gitea/commit/8f4b7ebbf6061bd44b1ab3824f17f37b87fb1740" + }, + { + "type": "WEB", + "url": "https://github.com/go-gitea/gitea/pull/38008" + }, + { + "type": "WEB", + "url": "https://github.com/go-gitea/gitea/releases/tag/v1.26.4" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6046", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6047.json b/data/osv/GO-2026-6047.json new file mode 100644 index 0000000..a7c61ae --- /dev/null +++ b/data/osv/GO-2026-6047.json
@@ -0,0 +1,48 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6047", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-58437", + "GHSA-8p9h-49rc-qgxj" + ], + "summary": "Gitea: Repository Visibility Manipulation via Git Push Options in gitea.dev", + "details": "Gitea: Repository Visibility Manipulation via Git Push Options in gitea.dev", + "affected": [ + { + "package": { + "name": "gitea.dev", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.27.0" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/go-gitea/gitea/security/advisories/GHSA-8p9h-49rc-qgxj" + }, + { + "type": "WEB", + "url": "https://github.com/go-gitea/gitea/releases/tag/v1.27.0" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6047", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6048.json b/data/osv/GO-2026-6048.json new file mode 100644 index 0000000..723bcf9 --- /dev/null +++ b/data/osv/GO-2026-6048.json
@@ -0,0 +1,48 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6048", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-54481", + "GHSA-94v3-77j7-vm48" + ], + "summary": "Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override in gitea.dev", + "details": "Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override in gitea.dev", + "affected": [ + { + "package": { + "name": "gitea.dev", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.27.0" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/go-gitea/gitea/security/advisories/GHSA-94v3-77j7-vm48" + }, + { + "type": "WEB", + "url": "https://github.com/go-gitea/gitea/releases/tag/v1.27.0" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6048", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6049.json b/data/osv/GO-2026-6049.json new file mode 100644 index 0000000..70f99db --- /dev/null +++ b/data/osv/GO-2026-6049.json
@@ -0,0 +1,64 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6049", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-59763", + "GHSA-9mq6-mqjj-c2c5" + ], + "summary": "Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads in gitea.dev", + "details": "Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads in gitea.dev", + "affected": [ + { + "package": { + "name": "gitea.dev", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.27.0" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/go-gitea/gitea/security/advisories/GHSA-9mq6-mqjj-c2c5" + }, + { + "type": "WEB", + "url": "https://github.com/go-gitea/gitea/commit/de4b8277e9cb576f2315fb03b5ab6478b42a1d31" + }, + { + "type": "WEB", + "url": "https://github.com/go-gitea/gitea/commit/f69e15afe7496cc62e96dab244629c69eb31a7bf" + }, + { + "type": "WEB", + "url": "https://github.com/go-gitea/gitea/pull/38406" + }, + { + "type": "WEB", + "url": "https://github.com/go-gitea/gitea/pull/38426" + }, + { + "type": "WEB", + "url": "https://github.com/go-gitea/gitea/releases/tag/v1.27.0" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6049", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6050.json b/data/osv/GO-2026-6050.json new file mode 100644 index 0000000..298abbe --- /dev/null +++ b/data/osv/GO-2026-6050.json
@@ -0,0 +1,48 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6050", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-58444", + "GHSA-cp3q-vrj2-ghhh" + ], + "summary": "Gitea: Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents in gitea.dev", + "details": "Gitea: Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents in gitea.dev", + "affected": [ + { + "package": { + "name": "gitea.dev", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.27.0" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/go-gitea/gitea/security/advisories/GHSA-cp3q-vrj2-ghhh" + }, + { + "type": "WEB", + "url": "https://github.com/go-gitea/gitea/releases/tag/v1.27.0" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6050", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6051.json b/data/osv/GO-2026-6051.json new file mode 100644 index 0000000..a7681ca --- /dev/null +++ b/data/osv/GO-2026-6051.json
@@ -0,0 +1,64 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6051", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-20896", + "GHSA-f75j-4cw6-rmx4" + ], + "summary": "Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea", + "details": "Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea", + "affected": [ + { + "package": { + "name": "code.gitea.io/gitea", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.26.3" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/go-gitea/gitea/security/advisories/GHSA-f75j-4cw6-rmx4" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-20896" + }, + { + "type": "WEB", + "url": "https://blog.gitea.com/release-of-1.26.3-and-1.26.4" + }, + { + "type": "WEB", + "url": "https://github.com/go-gitea/gitea/commit/99f8b3d9a1d32f4c39828e07971455a18191e0b9" + }, + { + "type": "WEB", + "url": "https://github.com/go-gitea/gitea/pull/38151" + }, + { + "type": "WEB", + "url": "https://github.com/go-gitea/gitea/releases/tag/v1.26.3" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6051", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6052.json b/data/osv/GO-2026-6052.json new file mode 100644 index 0000000..622b63f --- /dev/null +++ b/data/osv/GO-2026-6052.json
@@ -0,0 +1,56 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6052", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-58416", + "GHSA-fj8v-hjwv-qm88" + ], + "summary": "Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) in gitea.dev", + "details": "Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) in gitea.dev", + "affected": [ + { + "package": { + "name": "gitea.dev", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.27.0" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/go-gitea/gitea/security/advisories/GHSA-fj8v-hjwv-qm88" + }, + { + "type": "WEB", + "url": "https://github.com/go-gitea/gitea/commit/1d43b736b5a16c5f80cfdcd9a9448a9c983ddaa0" + }, + { + "type": "WEB", + "url": "https://github.com/go-gitea/gitea/pull/38214" + }, + { + "type": "WEB", + "url": "https://github.com/go-gitea/gitea/releases/tag/v1.27.0" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6052", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6053.json b/data/osv/GO-2026-6053.json new file mode 100644 index 0000000..5c57f76 --- /dev/null +++ b/data/osv/GO-2026-6053.json
@@ -0,0 +1,64 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6053", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-58429", + "GHSA-fq2p-5p22-8g6j" + ], + "summary": "Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints in gitea.dev", + "details": "Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints in gitea.dev", + "affected": [ + { + "package": { + "name": "gitea.dev", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.27.0" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/go-gitea/gitea/security/advisories/GHSA-fq2p-5p22-8g6j" + }, + { + "type": "WEB", + "url": "https://github.com/go-gitea/gitea/commit/a34eac5ef42ada433a7c7dafb98f15c13d7ad74e" + }, + { + "type": "WEB", + "url": "https://github.com/go-gitea/gitea/commit/f2a1271f164569264c378fad720b0c000fff3336" + }, + { + "type": "WEB", + "url": "https://github.com/go-gitea/gitea/pull/37118" + }, + { + "type": "WEB", + "url": "https://github.com/go-gitea/gitea/pull/37773" + }, + { + "type": "WEB", + "url": "https://github.com/go-gitea/gitea/releases/tag/v1.27.0" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6053", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6054.json b/data/osv/GO-2026-6054.json new file mode 100644 index 0000000..867d620 --- /dev/null +++ b/data/osv/GO-2026-6054.json
@@ -0,0 +1,48 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6054", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-57897", + "GHSA-frpw-3h2q-4jj6" + ], + "summary": "Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs in gitea.dev", + "details": "Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs in gitea.dev", + "affected": [ + { + "package": { + "name": "gitea.dev", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.27.0" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/go-gitea/gitea/security/advisories/GHSA-frpw-3h2q-4jj6" + }, + { + "type": "WEB", + "url": "https://github.com/go-gitea/gitea/releases/tag/v1.27.0" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6054", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6055.json b/data/osv/GO-2026-6055.json new file mode 100644 index 0000000..568f4e7 --- /dev/null +++ b/data/osv/GO-2026-6055.json
@@ -0,0 +1,52 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6055", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-58436", + "GHSA-fw57-jgch-pgf3" + ], + "summary": "Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests in gitea.dev", + "details": "Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests in gitea.dev", + "affected": [ + { + "package": { + "name": "gitea.dev", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.27.0" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/go-gitea/gitea/security/advisories/GHSA-fw57-jgch-pgf3" + }, + { + "type": "WEB", + "url": "https://github.com/go-gitea/gitea/commit/f452c369acc9f1bd05ec6ef9c2e4399062dd6da1" + }, + { + "type": "WEB", + "url": "https://github.com/go-gitea/gitea/pull/38323" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6055", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6056.json b/data/osv/GO-2026-6056.json new file mode 100644 index 0000000..872cfed --- /dev/null +++ b/data/osv/GO-2026-6056.json
@@ -0,0 +1,64 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6056", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-58422", + "GHSA-g9g6-qhrc-p3qc" + ], + "summary": "Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea", + "details": "Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea", + "affected": [ + { + "package": { + "name": "code.gitea.io/gitea", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.26.4" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/go-gitea/gitea/security/advisories/GHSA-g9g6-qhrc-p3qc" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-58422" + }, + { + "type": "WEB", + "url": "https://blog.gitea.com/release-of-1.26.3-and-1.26.4" + }, + { + "type": "WEB", + "url": "https://github.com/go-gitea/gitea/commit/c43eb7c33a100ffc7b2367adf165f7085e0ccdc5" + }, + { + "type": "WEB", + "url": "https://github.com/go-gitea/gitea/pull/38009" + }, + { + "type": "WEB", + "url": "https://github.com/go-gitea/gitea/releases/tag/v1.26.4" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6056", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6057.json b/data/osv/GO-2026-6057.json new file mode 100644 index 0000000..f033981 --- /dev/null +++ b/data/osv/GO-2026-6057.json
@@ -0,0 +1,64 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6057", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-20779", + "GHSA-gx3v-q759-g323" + ], + "summary": "Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea", + "details": "Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea", + "affected": [ + { + "package": { + "name": "code.gitea.io/gitea", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "1.5.0" + }, + { + "fixed": "1.26.3" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/go-gitea/gitea/security/advisories/GHSA-gx3v-q759-g323" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-20779" + }, + { + "type": "WEB", + "url": "https://blog.gitea.com/release-of-1.26.3-and-1.26.4" + }, + { + "type": "WEB", + "url": "https://github.com/go-gitea/gitea/commit/99f8b3d9a1d32f4c39828e07971455a18191e0b9" + }, + { + "type": "WEB", + "url": "https://github.com/go-gitea/gitea/pull/38151" + }, + { + "type": "WEB", + "url": "https://github.com/go-gitea/gitea/releases/tag/v1.26.3" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6057", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/reports/GO-2026-6015.yaml b/data/reports/GO-2026-6015.yaml new file mode 100644 index 0000000..ab7035b --- /dev/null +++ b/data/reports/GO-2026-6015.yaml
@@ -0,0 +1,20 @@ +id: GO-2026-6015 +modules: + - module: github.com/zalando/skipper + versions: + - fixed: 0.26.22 + vulnerable_at: 0.26.21 +summary: |- + Skipper: Unbounded Request Body Read in Admission Webhook Causes Memory + Exhaustion DoS in github.com/zalando/skipper +cves: + - CVE-2026-54247 +ghsas: + - GHSA-cwxq-rc9x-2jvv +references: + - advisory: https://github.com/zalando/skipper/security/advisories/GHSA-cwxq-rc9x-2jvv + - web: https://github.com/zalando/skipper/releases/tag/v0.26.22 +source: + id: GHSA-cwxq-rc9x-2jvv + created: 2026-07-21T19:09:44.975741-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6016.yaml b/data/reports/GO-2026-6016.yaml new file mode 100644 index 0000000..5bd674b --- /dev/null +++ b/data/reports/GO-2026-6016.yaml
@@ -0,0 +1,21 @@ +id: GO-2026-6016 +modules: + - module: github.com/oapi-codegen/oapi-codegen + vulnerable_at: 1.16.3 + - module: github.com/oapi-codegen/oapi-codegen/v2 + versions: + - fixed: 2.7.1 + vulnerable_at: 2.7.0 +summary: |- + oapi-codegen: OpenAPI Server Description Escapes Generated Go Comment and + Injects Executable Code in github.com/oapi-codegen/oapi-codegen +ghsas: + - GHSA-rjwr-m7qx-3fjr +references: + - advisory: https://github.com/oapi-codegen/oapi-codegen/security/advisories/GHSA-rjwr-m7qx-3fjr + - fix: https://github.com/oapi-codegen/oapi-codegen/commit/19c6282e9a6fb84b51aa92b12fad1f0b7e5f5ef6 + - web: https://github.com/oapi-codegen/oapi-codegen/releases/tag/v2.7.1 +source: + id: GHSA-rjwr-m7qx-3fjr + created: 2026-07-21T19:09:41.353671-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6017.yaml b/data/reports/GO-2026-6017.yaml new file mode 100644 index 0000000..bed7968 --- /dev/null +++ b/data/reports/GO-2026-6017.yaml
@@ -0,0 +1,21 @@ +id: GO-2026-6017 +modules: + - module: code.gitea.io/gitea + versions: + - fixed: 1.26.2 + vulnerable_at: 1.26.1 +summary: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea +cves: + - CVE-2026-27771 +ghsas: + - GHSA-8qw8-rq86-9pc2 +references: + - advisory: https://github.com/go-gitea/gitea/security/advisories/GHSA-8qw8-rq86-9pc2 + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-27771 + - web: https://blog.gitea.com/release-of-1.26.2 + - web: https://github.com/go-gitea/gitea/pull/37610 + - web: https://github.com/go-gitea/gitea/releases/tag/v1.26.2 +source: + id: GHSA-8qw8-rq86-9pc2 + created: 2026-07-21T19:09:34.692475-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6018.yaml b/data/reports/GO-2026-6018.yaml new file mode 100644 index 0000000..a428ca4 --- /dev/null +++ b/data/reports/GO-2026-6018.yaml
@@ -0,0 +1,20 @@ +id: GO-2026-6018 +modules: + - module: github.com/zalando/skipper + versions: + - fixed: 0.27.13 + vulnerable_at: 0.27.12 +summary: |- + Skipper's routesrv-no-auth component: All routesrv API Endpoints Lack + Authentication in github.com/zalando/skipper +cves: + - CVE-2026-54246 +ghsas: + - GHSA-5587-2x54-jj6h +references: + - advisory: https://github.com/zalando/skipper/security/advisories/GHSA-5587-2x54-jj6h + - web: https://github.com/zalando/skipper/releases/tag/v0.27.13 +source: + id: GHSA-5587-2x54-jj6h + created: 2026-07-21T19:09:29.508125-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6019.yaml b/data/reports/GO-2026-6019.yaml new file mode 100644 index 0000000..63ad9f8 --- /dev/null +++ b/data/reports/GO-2026-6019.yaml
@@ -0,0 +1,18 @@ +id: GO-2026-6019 +modules: + - module: github.com/zalando/skipper + versions: + - fixed: 0.27.26 + vulnerable_at: 0.27.25 +summary: |- + Skipper: Incomplete fix for CVE-2026-50197: an oversized body can bypass OPA + deny-on-presence Rego policies in github.com/zalando/skipper +ghsas: + - GHSA-8qqm-fp2q-v734 +references: + - advisory: https://github.com/zalando/skipper/security/advisories/GHSA-8qqm-fp2q-v734 + - web: https://github.com/zalando/skipper/releases/tag/v0.27.26 +source: + id: GHSA-8qqm-fp2q-v734 + created: 2026-07-21T19:09:26.332829-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6020.yaml b/data/reports/GO-2026-6020.yaml new file mode 100644 index 0000000..1f5fa78 --- /dev/null +++ b/data/reports/GO-2026-6020.yaml
@@ -0,0 +1,24 @@ +id: GO-2026-6020 +modules: + - module: github.com/filebrowser/filebrowser + vulnerable_at: 1.11.0 + - module: github.com/filebrowser/filebrowser/v2 + versions: + - fixed: 2.63.16 + vulnerable_at: 2.63.15 +summary: |- + File Browser: ScopedFs follows a dangling symlink on write, letting a scoped + user create files outside their scope in github.com/filebrowser/filebrowser +cves: + - CVE-2026-55668 +ghsas: + - GHSA-8wc8-hf36-mjh9 +references: + - advisory: https://github.com/filebrowser/filebrowser/security/advisories/GHSA-8wc8-hf36-mjh9 + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-55668 + - fix: https://github.com/filebrowser/filebrowser/commit/64511ce45e3be379e965f7f4fb0929a068d5bb81 + - web: https://github.com/filebrowser/filebrowser/releases/tag/v2.63.16 +source: + id: GHSA-8wc8-hf36-mjh9 + created: 2026-07-21T19:09:21.758293-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6021.yaml b/data/reports/GO-2026-6021.yaml new file mode 100644 index 0000000..d13db4e --- /dev/null +++ b/data/reports/GO-2026-6021.yaml
@@ -0,0 +1,23 @@ +id: GO-2026-6021 +modules: + - module: github.com/filebrowser/filebrowser + vulnerable_at: 1.11.0 + - module: github.com/filebrowser/filebrowser/v2 + versions: + - fixed: 2.63.16 + vulnerable_at: 2.63.15 +summary: |- + File Browser: Out-of-scope file deletion by a Create-only scoped user via + symlink-following RemoveAll in upload failure-cleanup in github.com/filebrowser/filebrowser +cves: + - CVE-2026-55667 +ghsas: + - GHSA-fmm7-x4gx-8jhr +references: + - advisory: https://github.com/filebrowser/filebrowser/security/advisories/GHSA-fmm7-x4gx-8jhr + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-55667 + - web: https://github.com/filebrowser/filebrowser/blob/be23ab3a15bf957928ecfed88de5ab67850c1b9c/http/resource.go#L172-L174 +source: + id: GHSA-fmm7-x4gx-8jhr + created: 2026-07-21T19:09:15.805822-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6022.yaml b/data/reports/GO-2026-6022.yaml new file mode 100644 index 0000000..e45958c --- /dev/null +++ b/data/reports/GO-2026-6022.yaml
@@ -0,0 +1,28 @@ +id: GO-2026-6022 +modules: + - module: github.com/cloudreve/Cloudreve + vulnerable_at: 0.0.0-20201026073328-746aa3e8ef26 + - module: github.com/cloudreve/Cloudreve/v3 + vulnerable_at: 3.0.0-20250225100611-da4e44b77af4 + - module: github.com/cloudreve/Cloudreve/v4 + versions: + - introduced: 4.0.0-20260114075425-bc6845bd742c + - fixed: 4.0.0-20260606015557-ed20843dc3df +summary: |- + Cloudreve: OAuth access tokens bypass scope enforcement due to missing client_id + claim in github.com/cloudreve/Cloudreve +cves: + - CVE-2026-54560 +ghsas: + - GHSA-vgj4-345g-jcf8 +references: + - advisory: https://github.com/cloudreve/cloudreve/security/advisories/GHSA-vgj4-345g-jcf8 + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-54560 + - web: https://github.com/cloudreve/cloudreve/commit/ed20843dc3df20a25fcaf6b538647e11c4d68d87 + - web: https://github.com/cloudreve/cloudreve/releases/tag/4.16.1 +notes: + - fix: 'github.com/cloudreve/Cloudreve/v4: could not add vulnerable_at: could not find tagged version between introduced and fixed' +source: + id: GHSA-vgj4-345g-jcf8 + created: 2026-07-21T19:09:09.816558-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6023.yaml b/data/reports/GO-2026-6023.yaml new file mode 100644 index 0000000..34b5ab5 --- /dev/null +++ b/data/reports/GO-2026-6023.yaml
@@ -0,0 +1,29 @@ +id: GO-2026-6023 +modules: + - module: github.com/cloudreve/Cloudreve + vulnerable_at: 0.0.0-20201026073328-746aa3e8ef26 + - module: github.com/cloudreve/Cloudreve/v3 + unsupported_versions: + - last_affected: 3.0.0-20250225100611-da4e44b77af4 + vulnerable_at: 3.0.0-20250225100611-da4e44b77af4 + - module: github.com/cloudreve/Cloudreve/v4 + versions: + - fixed: 4.0.0-20260606025411-aaebf317a78f +summary: |- + Cloudreve: Non-admin remote download users can SSRF loopback/internal services + and read imported responses in github.com/cloudreve/Cloudreve +cves: + - CVE-2026-54562 +ghsas: + - GHSA-x756-g4x3-c64m +references: + - advisory: https://github.com/cloudreve/cloudreve/security/advisories/GHSA-x756-g4x3-c64m + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-54562 + - web: https://github.com/cloudreve/cloudreve/commit/aaebf317a78f2413d74afd66c21a1f3143711312 + - web: https://github.com/cloudreve/cloudreve/releases/tag/4.16.1 +notes: + - fix: 'github.com/cloudreve/Cloudreve/v4: could not add vulnerable_at: could not find tagged version between introduced and fixed' +source: + id: GHSA-x756-g4x3-c64m + created: 2026-07-21T19:09:00.619308-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6024.yaml b/data/reports/GO-2026-6024.yaml new file mode 100644 index 0000000..e2ff5d7 --- /dev/null +++ b/data/reports/GO-2026-6024.yaml
@@ -0,0 +1,24 @@ +id: GO-2026-6024 +modules: + - module: github.com/filebrowser/filebrowser + vulnerable_at: 1.11.0 + - module: github.com/filebrowser/filebrowser/v2 + versions: + - fixed: 2.63.17 + vulnerable_at: 2.63.16 +summary: |- + File Browser: Colliding username normalization gives two users the same home + directory in github.com/filebrowser/filebrowser +cves: + - CVE-2026-62685 +ghsas: + - GHSA-7rc3-g7h6-22m7 +references: + - advisory: https://github.com/filebrowser/filebrowser/security/advisories/GHSA-7rc3-g7h6-22m7 + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-62685 + - fix: https://github.com/filebrowser/filebrowser/commit/883a36f02fcb69566a8628cb47f18fdc73348387 + - web: https://github.com/filebrowser/filebrowser/releases/tag/v2.63.17 +source: + id: GHSA-7rc3-g7h6-22m7 + created: 2026-07-21T19:08:55.082005-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6025.yaml b/data/reports/GO-2026-6025.yaml new file mode 100644 index 0000000..562fd56 --- /dev/null +++ b/data/reports/GO-2026-6025.yaml
@@ -0,0 +1,19 @@ +id: GO-2026-6025 +modules: + - module: github.com/filebrowser/filebrowser + vulnerable_at: 1.11.0 + - module: github.com/filebrowser/filebrowser/v2 + versions: + - fixed: 2.63.17 + vulnerable_at: 2.63.16 +summary: 'File Browser: Share API exposes the password hash and bypass token in github.com/filebrowser/filebrowser' +cves: + - CVE-2026-62684 +ghsas: + - GHSA-833g-cqhp-h72j +references: + - advisory: https://github.com/filebrowser/filebrowser/security/advisories/GHSA-833g-cqhp-h72j +source: + id: GHSA-833g-cqhp-h72j + created: 2026-07-21T19:08:50.07563-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6026.yaml b/data/reports/GO-2026-6026.yaml new file mode 100644 index 0000000..e566396 --- /dev/null +++ b/data/reports/GO-2026-6026.yaml
@@ -0,0 +1,25 @@ +id: GO-2026-6026 +modules: + - module: github.com/filebrowser/filebrowser + vulnerable_at: 1.11.0 + - module: github.com/filebrowser/filebrowser/v2 + versions: + - introduced: 2.63.6 + - fixed: 2.63.17 + vulnerable_at: 2.63.16 +summary: |- + File Browser: Archive builder turns backslash filenames into path traversal + (zip-slip) in github.com/filebrowser/filebrowser +cves: + - CVE-2026-62843 +ghsas: + - GHSA-83xp-526h-j3ww +references: + - advisory: https://github.com/filebrowser/filebrowser/security/advisories/GHSA-83xp-526h-j3ww + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-62843 + - fix: https://github.com/filebrowser/filebrowser/commit/8503ba61ff51d48a7313896483d130eb6a5abfe0 + - web: https://github.com/filebrowser/filebrowser/releases/tag/v2.63.17 +source: + id: GHSA-83xp-526h-j3ww + created: 2026-07-21T19:08:43.674341-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6027.yaml b/data/reports/GO-2026-6027.yaml new file mode 100644 index 0000000..3f0b8ae --- /dev/null +++ b/data/reports/GO-2026-6027.yaml
@@ -0,0 +1,20 @@ +id: GO-2026-6027 +modules: + - module: gitea.dev + versions: + - fixed: 1.27.0 + vulnerable_at: 1.27.0-rc0 +summary: |- + Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block + Validation, Enabling Internal Git Repository Exfiltration in gitea.dev +cves: + - CVE-2026-57894 +ghsas: + - GHSA-82f7-87hm-852x +references: + - advisory: https://github.com/go-gitea/gitea/security/advisories/GHSA-82f7-87hm-852x + - web: https://github.com/go-gitea/gitea/releases/tag/v1.27.0 +source: + id: GHSA-82f7-87hm-852x + created: 2026-07-21T19:08:38.805318-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6028.yaml b/data/reports/GO-2026-6028.yaml new file mode 100644 index 0000000..5eba17f --- /dev/null +++ b/data/reports/GO-2026-6028.yaml
@@ -0,0 +1,24 @@ +id: GO-2026-6028 +modules: + - module: gitea.dev + versions: + - fixed: 1.27.0 + vulnerable_at: 1.27.0-rc0 +summary: |- + Gitea: Release attachment extension allowlist bypass via web release edit form + (variant of CVE-2025-68939) in gitea.dev +cves: + - CVE-2026-58428 +ghsas: + - GHSA-25gq-j9jx-43pg +references: + - advisory: https://github.com/go-gitea/gitea/security/advisories/GHSA-25gq-j9jx-43pg + - web: https://github.com/go-gitea/gitea/commit/de4b8277e9cb576f2315fb03b5ab6478b42a1d31 + - web: https://github.com/go-gitea/gitea/commit/f69e15afe7496cc62e96dab244629c69eb31a7bf + - web: https://github.com/go-gitea/gitea/pull/38406 + - web: https://github.com/go-gitea/gitea/pull/38426 + - web: https://github.com/go-gitea/gitea/releases/tag/v1.27.0 +source: + id: GHSA-25gq-j9jx-43pg + created: 2026-07-21T19:08:32.35586-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6029.yaml b/data/reports/GO-2026-6029.yaml new file mode 100644 index 0000000..6ff6318 --- /dev/null +++ b/data/reports/GO-2026-6029.yaml
@@ -0,0 +1,25 @@ +id: GO-2026-6029 +modules: + - module: code.gitea.io/gitea + versions: + - fixed: 1.26.3 + vulnerable_at: 1.26.2 +summary: |- + Gitea: Git LFS object reuse allows non-Code access to authorize private source + objects in code.gitea.io/gitea +cves: + - CVE-2026-28740 +ghsas: + - GHSA-2m9v-5q2g-58vq +references: + - advisory: https://github.com/go-gitea/gitea/security/advisories/GHSA-2m9v-5q2g-58vq + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-28740 + - web: https://blog.gitea.com/release-of-1.26.3-and-1.26.4 + - web: https://github.com/go-gitea/gitea/commit/1c7b7ea72df7cf81e88b8e09049608254d32e56e + - web: https://github.com/go-gitea/gitea/commit/7b4a1a1a118501b9d0260301dfed7f52dfc36ee9 + - web: https://github.com/go-gitea/gitea/pull/38050 + - web: https://github.com/go-gitea/gitea/releases/tag/v1.26.3 +source: + id: GHSA-2m9v-5q2g-58vq + created: 2026-07-21T19:08:25.527492-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6030.yaml b/data/reports/GO-2026-6030.yaml new file mode 100644 index 0000000..b2c67ba --- /dev/null +++ b/data/reports/GO-2026-6030.yaml
@@ -0,0 +1,24 @@ +id: GO-2026-6030 +modules: + - module: code.gitea.io/gitea + versions: + - fixed: 1.26.3 + vulnerable_at: 1.26.2 +summary: |- + Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default + Filter in code.gitea.io/gitea +cves: + - CVE-2026-22874 +ghsas: + - GHSA-2r5c-gw76-rh3w +references: + - advisory: https://github.com/go-gitea/gitea/security/advisories/GHSA-2r5c-gw76-rh3w + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-22874 + - web: https://blog.gitea.com/release-of-1.26.3-and-1.26.4 + - web: https://github.com/go-gitea/gitea/pull/38059 + - web: https://github.com/go-gitea/gitea/pull/38173 + - web: https://github.com/go-gitea/gitea/releases/tag/v1.26.3 +source: + id: GHSA-2r5c-gw76-rh3w + created: 2026-07-21T19:08:18.301993-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6031.yaml b/data/reports/GO-2026-6031.yaml new file mode 100644 index 0000000..c1b4195 --- /dev/null +++ b/data/reports/GO-2026-6031.yaml
@@ -0,0 +1,24 @@ +id: GO-2026-6031 +modules: + - module: code.gitea.io/gitea + versions: + - fixed: 1.26.3 + vulnerable_at: 1.26.2 +summary: |- + Gitea: API access token scope enforcement bypass on repository RSS/Atom feed + endpoints leaks private repository commit data in code.gitea.io/gitea +cves: + - CVE-2026-27761 +ghsas: + - GHSA-3pww-vcvm-3gmj +references: + - advisory: https://github.com/go-gitea/gitea/security/advisories/GHSA-3pww-vcvm-3gmj + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-27761 + - web: https://blog.gitea.com/release-of-1.26.3-and-1.26.4 + - web: https://github.com/go-gitea/gitea/commit/9e84deb969aff5c1115c2984e41250f28c78451f + - web: https://github.com/go-gitea/gitea/pull/38147 + - web: https://github.com/go-gitea/gitea/releases/tag/v1.26.3 +source: + id: GHSA-3pww-vcvm-3gmj + created: 2026-07-21T19:08:10.963015-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6032.yaml b/data/reports/GO-2026-6032.yaml new file mode 100644 index 0000000..1cdaa96 --- /dev/null +++ b/data/reports/GO-2026-6032.yaml
@@ -0,0 +1,17 @@ +id: GO-2026-6032 +modules: + - module: gitea.dev + versions: + - fixed: 1.27.0 + vulnerable_at: 1.27.0-rc0 +summary: 'Gitea: Local File Inclusion via file:// URI in Migration Restore in gitea.dev' +cves: + - CVE-2026-58420 +ghsas: + - GHSA-5ggr-2f2h-jmvm +references: + - advisory: https://github.com/go-gitea/gitea/security/advisories/GHSA-5ggr-2f2h-jmvm +source: + id: GHSA-5ggr-2f2h-jmvm + created: 2026-07-21T19:08:06.067915-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6033.yaml b/data/reports/GO-2026-6033.yaml new file mode 100644 index 0000000..e3c8252 --- /dev/null +++ b/data/reports/GO-2026-6033.yaml
@@ -0,0 +1,24 @@ +id: GO-2026-6033 +modules: + - module: gitea.dev + versions: + - fixed: 1.27.0 + vulnerable_at: 1.27.0-rc0 +summary: |- + Gitea: Webhooks created by a collaborator keep firing after their repo access is + revoked → ongoing real-time exfiltration of private repo content in gitea.dev +cves: + - CVE-2026-58440 +ghsas: + - GHSA-66m4-5jjr-2rg5 +references: + - advisory: https://github.com/go-gitea/gitea/security/advisories/GHSA-66m4-5jjr-2rg5 + - web: https://github.com/go-gitea/gitea/commit/de4b8277e9cb576f2315fb03b5ab6478b42a1d31 + - web: https://github.com/go-gitea/gitea/commit/f69e15afe7496cc62e96dab244629c69eb31a7bf + - web: https://github.com/go-gitea/gitea/pull/38406 + - web: https://github.com/go-gitea/gitea/pull/38426 + - web: https://github.com/go-gitea/gitea/releases/tag/v1.27.0 +source: + id: GHSA-66m4-5jjr-2rg5 + created: 2026-07-21T19:08:01.110305-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6034.yaml b/data/reports/GO-2026-6034.yaml new file mode 100644 index 0000000..d2f925a --- /dev/null +++ b/data/reports/GO-2026-6034.yaml
@@ -0,0 +1,22 @@ +id: GO-2026-6034 +modules: + - module: gitea.dev + versions: + - fixed: 1.27.0 + vulnerable_at: 1.27.0-rc0 +summary: 'Gitea: Privilege Escalation via Access Token Scope Escalation in API in gitea.dev' +cves: + - CVE-2026-56654 +ghsas: + - GHSA-683j-3ff6-hh2x +references: + - advisory: https://github.com/go-gitea/gitea/security/advisories/GHSA-683j-3ff6-hh2x + - web: https://github.com/go-gitea/gitea/commit/de4b8277e9cb576f2315fb03b5ab6478b42a1d31 + - web: https://github.com/go-gitea/gitea/commit/f69e15afe7496cc62e96dab244629c69eb31a7bf + - web: https://github.com/go-gitea/gitea/pull/38406 + - web: https://github.com/go-gitea/gitea/pull/38426 + - web: https://github.com/go-gitea/gitea/releases/tag/v1.27.0 +source: + id: GHSA-683j-3ff6-hh2x + created: 2026-07-21T19:07:56.075807-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6035.yaml b/data/reports/GO-2026-6035.yaml new file mode 100644 index 0000000..f54ed78 --- /dev/null +++ b/data/reports/GO-2026-6035.yaml
@@ -0,0 +1,24 @@ +id: GO-2026-6035 +modules: + - module: gitea.dev + versions: + - fixed: 1.27.0 + vulnerable_at: 1.27.0-rc0 +summary: |- + Gitea: Cross-repository issue/comment attachment re-linking can expose private + attachment content in gitea.dev +cves: + - CVE-2026-57886 +ghsas: + - GHSA-6c6r-5xr4-cr5m +references: + - advisory: https://github.com/go-gitea/gitea/security/advisories/GHSA-6c6r-5xr4-cr5m + - web: https://github.com/go-gitea/gitea/commit/de4b8277e9cb576f2315fb03b5ab6478b42a1d31 + - web: https://github.com/go-gitea/gitea/commit/f69e15afe7496cc62e96dab244629c69eb31a7bf + - web: https://github.com/go-gitea/gitea/pull/38406 + - web: https://github.com/go-gitea/gitea/pull/38426 + - web: https://github.com/go-gitea/gitea/releases/tag/v1.27.0 +source: + id: GHSA-6c6r-5xr4-cr5m + created: 2026-07-21T19:07:51.238689-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6036.yaml b/data/reports/GO-2026-6036.yaml new file mode 100644 index 0000000..9285051 --- /dev/null +++ b/data/reports/GO-2026-6036.yaml
@@ -0,0 +1,20 @@ +id: GO-2026-6036 +modules: + - module: gitea.dev + versions: + - fixed: 1.27.0 + vulnerable_at: 1.27.0-rc0 +summary: |- + Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement + (incomplete fix of #37698) in gitea.dev +cves: + - CVE-2026-50105 +ghsas: + - GHSA-6cqf-375w-639g +references: + - advisory: https://github.com/go-gitea/gitea/security/advisories/GHSA-6cqf-375w-639g + - web: https://github.com/go-gitea/gitea/releases/tag/v1.27.0 +source: + id: GHSA-6cqf-375w-639g + created: 2026-07-21T19:07:46.305851-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6037.yaml b/data/reports/GO-2026-6037.yaml new file mode 100644 index 0000000..08cfab7 --- /dev/null +++ b/data/reports/GO-2026-6037.yaml
@@ -0,0 +1,24 @@ +id: GO-2026-6037 +modules: + - module: gitea.dev + versions: + - fixed: 1.27.0 + vulnerable_at: 1.27.0-rc0 +summary: |- + Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String + Concatenation in Debian Package Upload in gitea.dev +cves: + - CVE-2026-56755 +ghsas: + - GHSA-6hm7-3pwj-22rm +references: + - advisory: https://github.com/go-gitea/gitea/security/advisories/GHSA-6hm7-3pwj-22rm + - web: https://github.com/go-gitea/gitea/commit/de4b8277e9cb576f2315fb03b5ab6478b42a1d31 + - web: https://github.com/go-gitea/gitea/commit/f69e15afe7496cc62e96dab244629c69eb31a7bf + - web: https://github.com/go-gitea/gitea/pull/38406 + - web: https://github.com/go-gitea/gitea/pull/38426 + - web: https://github.com/go-gitea/gitea/releases/tag/v1.27.0 +source: + id: GHSA-6hm7-3pwj-22rm + created: 2026-07-21T19:07:38.125244-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6038.yaml b/data/reports/GO-2026-6038.yaml new file mode 100644 index 0000000..792a6f0 --- /dev/null +++ b/data/reports/GO-2026-6038.yaml
@@ -0,0 +1,18 @@ +id: GO-2026-6038 +modules: + - module: gitea.dev + versions: + - fixed: 1.27.0 + vulnerable_at: 1.27.0-rc0 +summary: 'Gitea: Two SSRF findings in gitea.dev' +cves: + - CVE-2026-58314 +ghsas: + - GHSA-2fcr-jfvc-vgg2 +references: + - advisory: https://github.com/go-gitea/gitea/security/advisories/GHSA-2fcr-jfvc-vgg2 + - web: https://github.com/go-gitea/gitea/releases/tag/v1.27.0 +source: + id: GHSA-2fcr-jfvc-vgg2 + created: 2026-07-21T19:07:33.401416-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6039.yaml b/data/reports/GO-2026-6039.yaml new file mode 100644 index 0000000..770f394 --- /dev/null +++ b/data/reports/GO-2026-6039.yaml
@@ -0,0 +1,20 @@ +id: GO-2026-6039 +modules: + - module: gitea.dev + versions: + - fixed: 1.27.0 + vulnerable_at: 1.27.0-rc0 +summary: |- + Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads + Internal Files and Cloud Metadata in gitea.dev +cves: + - CVE-2026-59765 +ghsas: + - GHSA-2wm4-vwp6-v7xc +references: + - advisory: https://github.com/go-gitea/gitea/security/advisories/GHSA-2wm4-vwp6-v7xc + - web: https://github.com/go-gitea/gitea/releases/tag/v1.27.0 +source: + id: GHSA-2wm4-vwp6-v7xc + created: 2026-07-21T19:07:28.515219-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6040.yaml b/data/reports/GO-2026-6040.yaml new file mode 100644 index 0000000..403c4fb --- /dev/null +++ b/data/reports/GO-2026-6040.yaml
@@ -0,0 +1,18 @@ +id: GO-2026-6040 +modules: + - module: gitea.dev + versions: + - fixed: 1.27.0 + vulnerable_at: 1.27.0-rc0 +summary: 'Gitea: Webhook Authorization Header Returned in Plaintext via API in gitea.dev' +cves: + - CVE-2026-58511 +ghsas: + - GHSA-3r5c-2xxx-h872 +references: + - advisory: https://github.com/go-gitea/gitea/security/advisories/GHSA-3r5c-2xxx-h872 + - web: https://github.com/go-gitea/gitea/releases/tag/v1.27.0 +source: + id: GHSA-3r5c-2xxx-h872 + created: 2026-07-21T19:07:23.617659-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6041.yaml b/data/reports/GO-2026-6041.yaml new file mode 100644 index 0000000..61a276a --- /dev/null +++ b/data/reports/GO-2026-6041.yaml
@@ -0,0 +1,22 @@ +id: GO-2026-6041 +modules: + - module: code.gitea.io/gitea + versions: + - fixed: 1.26.4 + vulnerable_at: 1.26.3 +summary: 'Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea' +cves: + - CVE-2026-58419 +ghsas: + - GHSA-44qc-pgvp-wx7v +references: + - advisory: https://github.com/go-gitea/gitea/security/advisories/GHSA-44qc-pgvp-wx7v + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-58419 + - web: https://blog.gitea.com/release-of-1.26.3-and-1.26.4 + - web: https://github.com/go-gitea/gitea/commit/9e84deb969aff5c1115c2984e41250f28c78451f + - web: https://github.com/go-gitea/gitea/pull/38108 + - web: https://github.com/go-gitea/gitea/releases/tag/v1.26.4 +source: + id: GHSA-44qc-pgvp-wx7v + created: 2026-07-21T19:07:16.257071-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6042.yaml b/data/reports/GO-2026-6042.yaml new file mode 100644 index 0000000..585472f --- /dev/null +++ b/data/reports/GO-2026-6042.yaml
@@ -0,0 +1,18 @@ +id: GO-2026-6042 +modules: + - module: gitea.dev + versions: + - fixed: 1.27.0 + vulnerable_at: 1.27.0-rc0 +summary: Gitea SSH Key Parser Denial of Service in gitea.dev +cves: + - CVE-2026-56657 +ghsas: + - GHSA-4xjf-493q-98p3 +references: + - advisory: https://github.com/go-gitea/gitea/security/advisories/GHSA-4xjf-493q-98p3 + - web: https://github.com/go-gitea/gitea/releases/tag/v1.27.0 +source: + id: GHSA-4xjf-493q-98p3 + created: 2026-07-21T19:07:11.398497-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6043.yaml b/data/reports/GO-2026-6043.yaml new file mode 100644 index 0000000..fbb74fc --- /dev/null +++ b/data/reports/GO-2026-6043.yaml
@@ -0,0 +1,24 @@ +id: GO-2026-6043 +modules: + - module: code.gitea.io/gitea + versions: + - fixed: 1.26.3 + vulnerable_at: 1.26.2 +summary: |- + Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full + Repository Write in code.gitea.io/gitea +cves: + - CVE-2026-27775 +ghsas: + - GHSA-649p-mmhf-85c7 +references: + - advisory: https://github.com/go-gitea/gitea/security/advisories/GHSA-649p-mmhf-85c7 + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-27775 + - web: https://blog.gitea.com/release-of-1.26.3-and-1.26.4 + - web: https://github.com/go-gitea/gitea/commit/99f8b3d9a1d32f4c39828e07971455a18191e0b9 + - web: https://github.com/go-gitea/gitea/pull/38151 + - web: https://github.com/go-gitea/gitea/releases/tag/v1.26.3 +source: + id: GHSA-649p-mmhf-85c7 + created: 2026-07-21T19:07:04.029266-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6044.yaml b/data/reports/GO-2026-6044.yaml new file mode 100644 index 0000000..d925b01 --- /dev/null +++ b/data/reports/GO-2026-6044.yaml
@@ -0,0 +1,23 @@ +id: GO-2026-6044 +modules: + - module: code.gitea.io/gitea + versions: + - fixed: 1.26.3 + vulnerable_at: 1.26.2 +summary: 'Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea' +cves: + - CVE-2026-58424 +ghsas: + - GHSA-777r-4v59-6486 +references: + - advisory: https://github.com/go-gitea/gitea/security/advisories/GHSA-777r-4v59-6486 + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-58424 + - web: https://blog.gitea.com/release-of-1.26.3-and-1.26.4 + - web: https://github.com/go-gitea/gitea/commit/699fe2ef43b9466ac1b0cb857029f91fd5b0056d + - web: https://github.com/go-gitea/gitea/commit/e107498f3b6fccff35455ef17430ca68df665297 + - web: https://github.com/go-gitea/gitea/pull/38010 + - web: https://github.com/go-gitea/gitea/releases/tag/v1.26.4 +source: + id: GHSA-777r-4v59-6486 + created: 2026-07-21T19:06:55.624407-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6045.yaml b/data/reports/GO-2026-6045.yaml new file mode 100644 index 0000000..0071ba7 --- /dev/null +++ b/data/reports/GO-2026-6045.yaml
@@ -0,0 +1,20 @@ +id: GO-2026-6045 +modules: + - module: gitea.dev + versions: + - fixed: 1.27.0 + vulnerable_at: 1.27.0-rc0 +summary: |- + Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository + + Package categories) — residual after CVE-2026-25714 / PR #37118 in gitea.dev +cves: + - CVE-2026-56443 +ghsas: + - GHSA-7p4h-3gxq-x3h3 +references: + - advisory: https://github.com/go-gitea/gitea/security/advisories/GHSA-7p4h-3gxq-x3h3 + - web: https://github.com/go-gitea/gitea/releases/tag/v1.27.0 +source: + id: GHSA-7p4h-3gxq-x3h3 + created: 2026-07-21T19:06:50.86854-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6046.yaml b/data/reports/GO-2026-6046.yaml new file mode 100644 index 0000000..c4a042f --- /dev/null +++ b/data/reports/GO-2026-6046.yaml
@@ -0,0 +1,26 @@ +id: GO-2026-6046 +modules: + - module: code.gitea.io/gitea + versions: + - introduced: 1.23.0 + - fixed: 1.26.3 + vulnerable_at: 1.26.2 +summary: |- + Gitea: LFS authentication bypass via malformed SSH sub-verb allows unauthorized + read access to private repositories in code.gitea.io/gitea +cves: + - CVE-2026-58423 +ghsas: + - GHSA-7wvc-rvp7-w99x +references: + - advisory: https://github.com/go-gitea/gitea/security/advisories/GHSA-7wvc-rvp7-w99x + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-58423 + - web: https://blog.gitea.com/release-of-1.26.3-and-1.26.4 + - web: https://github.com/go-gitea/gitea/commit/42513398c05ca6bdf71da76cb6f9baaebe8cb924 + - web: https://github.com/go-gitea/gitea/commit/8f4b7ebbf6061bd44b1ab3824f17f37b87fb1740 + - web: https://github.com/go-gitea/gitea/pull/38008 + - web: https://github.com/go-gitea/gitea/releases/tag/v1.26.4 +source: + id: GHSA-7wvc-rvp7-w99x + created: 2026-07-21T19:06:42.944565-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6047.yaml b/data/reports/GO-2026-6047.yaml new file mode 100644 index 0000000..ea59cff --- /dev/null +++ b/data/reports/GO-2026-6047.yaml
@@ -0,0 +1,18 @@ +id: GO-2026-6047 +modules: + - module: gitea.dev + versions: + - fixed: 1.27.0 + vulnerable_at: 1.27.0-rc0 +summary: 'Gitea: Repository Visibility Manipulation via Git Push Options in gitea.dev' +cves: + - CVE-2026-58437 +ghsas: + - GHSA-8p9h-49rc-qgxj +references: + - advisory: https://github.com/go-gitea/gitea/security/advisories/GHSA-8p9h-49rc-qgxj + - web: https://github.com/go-gitea/gitea/releases/tag/v1.27.0 +source: + id: GHSA-8p9h-49rc-qgxj + created: 2026-07-21T19:06:37.832989-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6048.yaml b/data/reports/GO-2026-6048.yaml new file mode 100644 index 0000000..a1c19cb --- /dev/null +++ b/data/reports/GO-2026-6048.yaml
@@ -0,0 +1,20 @@ +id: GO-2026-6048 +modules: + - module: gitea.dev + versions: + - fixed: 1.27.0 + vulnerable_at: 1.27.0-rc0 +summary: |- + Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config + override in gitea.dev +cves: + - CVE-2026-54481 +ghsas: + - GHSA-94v3-77j7-vm48 +references: + - advisory: https://github.com/go-gitea/gitea/security/advisories/GHSA-94v3-77j7-vm48 + - web: https://github.com/go-gitea/gitea/releases/tag/v1.27.0 +source: + id: GHSA-94v3-77j7-vm48 + created: 2026-07-21T19:06:32.924611-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6049.yaml b/data/reports/GO-2026-6049.yaml new file mode 100644 index 0000000..574506f --- /dev/null +++ b/data/reports/GO-2026-6049.yaml
@@ -0,0 +1,24 @@ +id: GO-2026-6049 +modules: + - module: gitea.dev + versions: + - fixed: 1.27.0 + vulnerable_at: 1.27.0-rc0 +summary: |- + Gitea: Unbounded Arch package file metadata can cause resource amplification in + Gitea package uploads in gitea.dev +cves: + - CVE-2026-59763 +ghsas: + - GHSA-9mq6-mqjj-c2c5 +references: + - advisory: https://github.com/go-gitea/gitea/security/advisories/GHSA-9mq6-mqjj-c2c5 + - web: https://github.com/go-gitea/gitea/commit/de4b8277e9cb576f2315fb03b5ab6478b42a1d31 + - web: https://github.com/go-gitea/gitea/commit/f69e15afe7496cc62e96dab244629c69eb31a7bf + - web: https://github.com/go-gitea/gitea/pull/38406 + - web: https://github.com/go-gitea/gitea/pull/38426 + - web: https://github.com/go-gitea/gitea/releases/tag/v1.27.0 +source: + id: GHSA-9mq6-mqjj-c2c5 + created: 2026-07-21T19:06:24.708317-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6050.yaml b/data/reports/GO-2026-6050.yaml new file mode 100644 index 0000000..a6af640 --- /dev/null +++ b/data/reports/GO-2026-6050.yaml
@@ -0,0 +1,20 @@ +id: GO-2026-6050 +modules: + - module: gitea.dev + versions: + - fixed: 1.27.0 + vulnerable_at: 1.27.0-rc0 +summary: |- + Gitea: Personal access token scope enforcement bypass on the repository home + page (`GET /{owner}/{repo}`) discloses private repository contents in gitea.dev +cves: + - CVE-2026-58444 +ghsas: + - GHSA-cp3q-vrj2-ghhh +references: + - advisory: https://github.com/go-gitea/gitea/security/advisories/GHSA-cp3q-vrj2-ghhh + - web: https://github.com/go-gitea/gitea/releases/tag/v1.27.0 +source: + id: GHSA-cp3q-vrj2-ghhh + created: 2026-07-21T19:06:19.4357-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6051.yaml b/data/reports/GO-2026-6051.yaml new file mode 100644 index 0000000..6c2d905 --- /dev/null +++ b/data/reports/GO-2026-6051.yaml
@@ -0,0 +1,24 @@ +id: GO-2026-6051 +modules: + - module: code.gitea.io/gitea + versions: + - fixed: 1.26.3 + vulnerable_at: 1.26.2 +summary: |- + Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source + IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea +cves: + - CVE-2026-20896 +ghsas: + - GHSA-f75j-4cw6-rmx4 +references: + - advisory: https://github.com/go-gitea/gitea/security/advisories/GHSA-f75j-4cw6-rmx4 + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-20896 + - web: https://blog.gitea.com/release-of-1.26.3-and-1.26.4 + - web: https://github.com/go-gitea/gitea/commit/99f8b3d9a1d32f4c39828e07971455a18191e0b9 + - web: https://github.com/go-gitea/gitea/pull/38151 + - web: https://github.com/go-gitea/gitea/releases/tag/v1.26.3 +source: + id: GHSA-f75j-4cw6-rmx4 + created: 2026-07-21T19:06:12.343038-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6052.yaml b/data/reports/GO-2026-6052.yaml new file mode 100644 index 0000000..9d66d67 --- /dev/null +++ b/data/reports/GO-2026-6052.yaml
@@ -0,0 +1,22 @@ +id: GO-2026-6052 +modules: + - module: gitea.dev + versions: + - fixed: 1.27.0 + vulnerable_at: 1.27.0-rc0 +summary: |- + Gitea: Fork-PR Actions task can read a third private repository via the + collaborative-owner branch (missing fork-PR guard) in gitea.dev +cves: + - CVE-2026-58416 +ghsas: + - GHSA-fj8v-hjwv-qm88 +references: + - advisory: https://github.com/go-gitea/gitea/security/advisories/GHSA-fj8v-hjwv-qm88 + - web: https://github.com/go-gitea/gitea/commit/1d43b736b5a16c5f80cfdcd9a9448a9c983ddaa0 + - web: https://github.com/go-gitea/gitea/pull/38214 + - web: https://github.com/go-gitea/gitea/releases/tag/v1.27.0 +source: + id: GHSA-fj8v-hjwv-qm88 + created: 2026-07-21T19:06:06.896845-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6053.yaml b/data/reports/GO-2026-6053.yaml new file mode 100644 index 0000000..384b66b --- /dev/null +++ b/data/reports/GO-2026-6053.yaml
@@ -0,0 +1,24 @@ +id: GO-2026-6053 +modules: + - module: gitea.dev + versions: + - fixed: 1.27.0 + vulnerable_at: 1.27.0-rc0 +summary: |- + Gitea: Public-Only Personal access tokens scope bypass in Organization and + Permission Endpoints in gitea.dev +cves: + - CVE-2026-58429 +ghsas: + - GHSA-fq2p-5p22-8g6j +references: + - advisory: https://github.com/go-gitea/gitea/security/advisories/GHSA-fq2p-5p22-8g6j + - web: https://github.com/go-gitea/gitea/commit/a34eac5ef42ada433a7c7dafb98f15c13d7ad74e + - web: https://github.com/go-gitea/gitea/commit/f2a1271f164569264c378fad720b0c000fff3336 + - web: https://github.com/go-gitea/gitea/pull/37118 + - web: https://github.com/go-gitea/gitea/pull/37773 + - web: https://github.com/go-gitea/gitea/releases/tag/v1.27.0 +source: + id: GHSA-fq2p-5p22-8g6j + created: 2026-07-21T19:05:57.417501-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6054.yaml b/data/reports/GO-2026-6054.yaml new file mode 100644 index 0000000..ab72a04 --- /dev/null +++ b/data/reports/GO-2026-6054.yaml
@@ -0,0 +1,18 @@ +id: GO-2026-6054 +modules: + - module: gitea.dev + versions: + - fixed: 1.27.0 + vulnerable_at: 1.27.0-rc0 +summary: 'Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs in gitea.dev' +cves: + - CVE-2026-57897 +ghsas: + - GHSA-frpw-3h2q-4jj6 +references: + - advisory: https://github.com/go-gitea/gitea/security/advisories/GHSA-frpw-3h2q-4jj6 + - web: https://github.com/go-gitea/gitea/releases/tag/v1.27.0 +source: + id: GHSA-frpw-3h2q-4jj6 + created: 2026-07-21T19:05:51.969425-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6055.yaml b/data/reports/GO-2026-6055.yaml new file mode 100644 index 0000000..8c9eaac --- /dev/null +++ b/data/reports/GO-2026-6055.yaml
@@ -0,0 +1,21 @@ +id: GO-2026-6055 +modules: + - module: gitea.dev + versions: + - fixed: 1.27.0 + vulnerable_at: 1.27.0-rc0 +summary: |- + Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on + unauthenticated requests in gitea.dev +cves: + - CVE-2026-58436 +ghsas: + - GHSA-fw57-jgch-pgf3 +references: + - advisory: https://github.com/go-gitea/gitea/security/advisories/GHSA-fw57-jgch-pgf3 + - web: https://github.com/go-gitea/gitea/commit/f452c369acc9f1bd05ec6ef9c2e4399062dd6da1 + - web: https://github.com/go-gitea/gitea/pull/38323 +source: + id: GHSA-fw57-jgch-pgf3 + created: 2026-07-21T19:05:45.263686-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6056.yaml b/data/reports/GO-2026-6056.yaml new file mode 100644 index 0000000..712818d --- /dev/null +++ b/data/reports/GO-2026-6056.yaml
@@ -0,0 +1,24 @@ +id: GO-2026-6056 +modules: + - module: code.gitea.io/gitea + versions: + - fixed: 1.26.4 + vulnerable_at: 1.26.3 +summary: |- + Gitea: Improper authorization on OAuth sign-in callback silently re-enables + administrator-disabled accounts in code.gitea.io/gitea +cves: + - CVE-2026-58422 +ghsas: + - GHSA-g9g6-qhrc-p3qc +references: + - advisory: https://github.com/go-gitea/gitea/security/advisories/GHSA-g9g6-qhrc-p3qc + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-58422 + - web: https://blog.gitea.com/release-of-1.26.3-and-1.26.4 + - web: https://github.com/go-gitea/gitea/commit/c43eb7c33a100ffc7b2367adf165f7085e0ccdc5 + - web: https://github.com/go-gitea/gitea/pull/38009 + - web: https://github.com/go-gitea/gitea/releases/tag/v1.26.4 +source: + id: GHSA-g9g6-qhrc-p3qc + created: 2026-07-21T19:05:37.595171-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6057.yaml b/data/reports/GO-2026-6057.yaml new file mode 100644 index 0000000..ee279d7 --- /dev/null +++ b/data/reports/GO-2026-6057.yaml
@@ -0,0 +1,25 @@ +id: GO-2026-6057 +modules: + - module: code.gitea.io/gitea + versions: + - introduced: 1.5.0 + - fixed: 1.26.3 + vulnerable_at: 1.26.2 +summary: |- + Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth + `X-Gitea-OTP` surface in code.gitea.io/gitea +cves: + - CVE-2026-20779 +ghsas: + - GHSA-gx3v-q759-g323 +references: + - advisory: https://github.com/go-gitea/gitea/security/advisories/GHSA-gx3v-q759-g323 + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-20779 + - web: https://blog.gitea.com/release-of-1.26.3-and-1.26.4 + - web: https://github.com/go-gitea/gitea/commit/99f8b3d9a1d32f4c39828e07971455a18191e0b9 + - web: https://github.com/go-gitea/gitea/pull/38151 + - web: https://github.com/go-gitea/gitea/releases/tag/v1.26.3 +source: + id: GHSA-gx3v-q759-g323 + created: 2026-07-21T19:53:53.941294-04:00 +review_status: UNREVIEWED