data/reports: add GO-2026-6664 - data/reports/GO-2026-6664.yaml Fixes golang/vulndb#6664 Change-Id: I61ec72ba866e58db190ebf271c43368808ba751d Reviewed-on: https://go-review.googlesource.com/c/vulndb/+/845865 Auto-Submit: Ian Alexander <jitsu@google.com> LUCI-TryBot-Result: golang-scoped@luci-project-accounts.iam.gserviceaccount.com <golang-scoped@luci-project-accounts.iam.gserviceaccount.com> Reviewed-by: Nicholas Husin <nsh@golang.org> Reviewed-by: Nicholas Husin <husin@google.com>
diff --git a/data/osv/GO-2026-6664.json b/data/osv/GO-2026-6664.json new file mode 100644 index 0000000..eacb9ec --- /dev/null +++ b/data/osv/GO-2026-6664.json
@@ -0,0 +1,87 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6664", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-21727", + "GHSA-p5x9-j974-rpfp" + ], + "summary": "Grafana legacy correlations allow cross-tenant disclosure and deletion in github.com/grafana/grafana", + "details": "Grafana legacy correlations allow cross-tenant disclosure and deletion in github.com/grafana/grafana.\n\nNOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.\n\n(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)\n\nThe additional affected modules and versions are: github.com/grafana/grafana before v1.9.2-0.20260127141016-e702db6096e0.", + "affected": [ + { + "package": { + "name": "github.com/grafana/grafana", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "custom_ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.9.2-0.20260127141016-e702db6096e0" + } + ] + } + ] + } + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-p5x9-j974-rpfp" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-21727" + }, + { + "type": "FIX", + "url": "https://github.com/grafana/grafana/commit/2b2847625b8a77ba47128ccb5ecbcd72542cb9bc" + }, + { + "type": "FIX", + "url": "https://github.com/grafana/grafana/commit/2cf0dd6fde3f5a2b92864e2376ae5378c7df45e2" + }, + { + "type": "FIX", + "url": "https://github.com/grafana/grafana/commit/4010ee30bb441bc399a1f37bdc8ab55ec909f3b7" + }, + { + "type": "FIX", + "url": "https://github.com/grafana/grafana/commit/8e7ea333991d913298bd68d4787da9c6977a0a8c" + }, + { + "type": "FIX", + "url": "https://github.com/grafana/grafana/commit/a9a98fc4327182d1bdb9a74b5c2938d5c127e764" + }, + { + "type": "FIX", + "url": "https://github.com/grafana/grafana/commit/e702db6096e0509ff2825f732697f077e9e6289f" + }, + { + "type": "WEB", + "url": "https://grafana.com/security/security-advisories/cve-2026-21727" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6664", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/reports/GO-2026-6664.yaml b/data/reports/GO-2026-6664.yaml new file mode 100644 index 0000000..528f88a --- /dev/null +++ b/data/reports/GO-2026-6664.yaml
@@ -0,0 +1,25 @@ +id: GO-2026-6664 +modules: + - module: github.com/grafana/grafana + non_go_versions: + - fixed: 1.9.2-0.20260127141016-e702db6096e0 + vulnerable_at: 5.4.5+incompatible +summary: Grafana legacy correlations allow cross-tenant disclosure and deletion in github.com/grafana/grafana +cves: + - CVE-2026-21727 +ghsas: + - GHSA-p5x9-j974-rpfp +references: + - advisory: https://github.com/advisories/GHSA-p5x9-j974-rpfp + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-21727 + - fix: https://github.com/grafana/grafana/commit/2b2847625b8a77ba47128ccb5ecbcd72542cb9bc + - fix: https://github.com/grafana/grafana/commit/2cf0dd6fde3f5a2b92864e2376ae5378c7df45e2 + - fix: https://github.com/grafana/grafana/commit/4010ee30bb441bc399a1f37bdc8ab55ec909f3b7 + - fix: https://github.com/grafana/grafana/commit/8e7ea333991d913298bd68d4787da9c6977a0a8c + - fix: https://github.com/grafana/grafana/commit/a9a98fc4327182d1bdb9a74b5c2938d5c127e764 + - fix: https://github.com/grafana/grafana/commit/e702db6096e0509ff2825f732697f077e9e6289f + - web: https://grafana.com/security/security-advisories/cve-2026-21727 +source: + id: GHSA-p5x9-j974-rpfp + created: 2026-10-06T10:12:24.958485-04:00 +review_status: UNREVIEWED