data/reports: add 92 reports - data/reports/GO-2026-6097.yaml - data/reports/GO-2026-6098.yaml - data/reports/GO-2026-6099.yaml - data/reports/GO-2026-6100.yaml - data/reports/GO-2026-6101.yaml - data/reports/GO-2026-6102.yaml - data/reports/GO-2026-6103.yaml - data/reports/GO-2026-6104.yaml - data/reports/GO-2026-6105.yaml - data/reports/GO-2026-6106.yaml - data/reports/GO-2026-6108.yaml - data/reports/GO-2026-6109.yaml - data/reports/GO-2026-6110.yaml - data/reports/GO-2026-6111.yaml - data/reports/GO-2026-6113.yaml - data/reports/GO-2026-6117.yaml - data/reports/GO-2026-6118.yaml - data/reports/GO-2026-6119.yaml - data/reports/GO-2026-6120.yaml - data/reports/GO-2026-6121.yaml - data/reports/GO-2026-6122.yaml - data/reports/GO-2026-6123.yaml - data/reports/GO-2026-6124.yaml - data/reports/GO-2026-6125.yaml - data/reports/GO-2026-6126.yaml - data/reports/GO-2026-6127.yaml - data/reports/GO-2026-6128.yaml - data/reports/GO-2026-6129.yaml - data/reports/GO-2026-6130.yaml - data/reports/GO-2026-6131.yaml - data/reports/GO-2026-6132.yaml - data/reports/GO-2026-6133.yaml - data/reports/GO-2026-6134.yaml - data/reports/GO-2026-6135.yaml - data/reports/GO-2026-6136.yaml - data/reports/GO-2026-6137.yaml - data/reports/GO-2026-6140.yaml - data/reports/GO-2026-6141.yaml - data/reports/GO-2026-6142.yaml - data/reports/GO-2026-6143.yaml - data/reports/GO-2026-6144.yaml - data/reports/GO-2026-6145.yaml - data/reports/GO-2026-6146.yaml - data/reports/GO-2026-6147.yaml - data/reports/GO-2026-6148.yaml - data/reports/GO-2026-6151.yaml - data/reports/GO-2026-6152.yaml - data/reports/GO-2026-6153.yaml - data/reports/GO-2026-6154.yaml - data/reports/GO-2026-6155.yaml - data/reports/GO-2026-6156.yaml - data/reports/GO-2026-6157.yaml - data/reports/GO-2026-6158.yaml - data/reports/GO-2026-6159.yaml - data/reports/GO-2026-6160.yaml - data/reports/GO-2026-6161.yaml - data/reports/GO-2026-6162.yaml - data/reports/GO-2026-6164.yaml - data/reports/GO-2026-6192.yaml - data/reports/GO-2026-6198.yaml - data/reports/GO-2026-6201.yaml - data/reports/GO-2026-6202.yaml - data/reports/GO-2026-6203.yaml - data/reports/GO-2026-6204.yaml - data/reports/GO-2026-6205.yaml - data/reports/GO-2026-6207.yaml - data/reports/GO-2026-6208.yaml - data/reports/GO-2026-6209.yaml - data/reports/GO-2026-6211.yaml - data/reports/GO-2026-6212.yaml - data/reports/GO-2026-6219.yaml - data/reports/GO-2026-6220.yaml - data/reports/GO-2026-6221.yaml - data/reports/GO-2026-6223.yaml - data/reports/GO-2026-6224.yaml - data/reports/GO-2026-6227.yaml - data/reports/GO-2026-6228.yaml - data/reports/GO-2026-6229.yaml - data/reports/GO-2026-6230.yaml - data/reports/GO-2026-6231.yaml - data/reports/GO-2026-6232.yaml - data/reports/GO-2026-6233.yaml - data/reports/GO-2026-6240.yaml - data/reports/GO-2026-6241.yaml - data/reports/GO-2026-6242.yaml - data/reports/GO-2026-6243.yaml - data/reports/GO-2026-6244.yaml - data/reports/GO-2026-6245.yaml - data/reports/GO-2026-6246.yaml - data/reports/GO-2026-6247.yaml - data/reports/GO-2026-6248.yaml - data/reports/GO-2026-6249.yaml Fixes golang/vulndb#6097 Fixes golang/vulndb#6098 Fixes golang/vulndb#6099 Fixes golang/vulndb#6100 Fixes golang/vulndb#6101 Fixes golang/vulndb#6102 Fixes golang/vulndb#6103 Fixes golang/vulndb#6104 Fixes golang/vulndb#6105 Fixes golang/vulndb#6106 Fixes golang/vulndb#6108 Fixes golang/vulndb#6109 Fixes golang/vulndb#6110 Fixes golang/vulndb#6111 Fixes golang/vulndb#6113 Fixes golang/vulndb#6117 Fixes golang/vulndb#6118 Fixes golang/vulndb#6119 Fixes golang/vulndb#6120 Fixes golang/vulndb#6121 Fixes golang/vulndb#6122 Fixes golang/vulndb#6123 Fixes golang/vulndb#6124 Fixes golang/vulndb#6125 Fixes golang/vulndb#6126 Fixes golang/vulndb#6127 Fixes golang/vulndb#6128 Fixes golang/vulndb#6129 Fixes golang/vulndb#6130 Fixes golang/vulndb#6131 Fixes golang/vulndb#6132 Fixes golang/vulndb#6133 Fixes golang/vulndb#6134 Fixes golang/vulndb#6135 Fixes golang/vulndb#6136 Fixes golang/vulndb#6137 Fixes golang/vulndb#6140 Fixes golang/vulndb#6141 Fixes golang/vulndb#6142 Fixes golang/vulndb#6143 Fixes golang/vulndb#6144 Fixes golang/vulndb#6145 Fixes golang/vulndb#6146 Fixes golang/vulndb#6147 Fixes golang/vulndb#6148 Fixes golang/vulndb#6151 Fixes golang/vulndb#6152 Fixes golang/vulndb#6153 Fixes golang/vulndb#6154 Fixes golang/vulndb#6155 Fixes golang/vulndb#6156 Fixes golang/vulndb#6157 Fixes golang/vulndb#6158 Fixes golang/vulndb#6159 Fixes golang/vulndb#6160 Fixes golang/vulndb#6161 Fixes golang/vulndb#6162 Fixes golang/vulndb#6164 Fixes golang/vulndb#6192 Fixes golang/vulndb#6198 Fixes golang/vulndb#6201 Fixes golang/vulndb#6202 Fixes golang/vulndb#6203 Fixes golang/vulndb#6204 Fixes golang/vulndb#6205 Fixes golang/vulndb#6207 Fixes golang/vulndb#6208 Fixes golang/vulndb#6209 Fixes golang/vulndb#6211 Fixes golang/vulndb#6212 Fixes golang/vulndb#6219 Fixes golang/vulndb#6220 Fixes golang/vulndb#6221 Fixes golang/vulndb#6223 Fixes golang/vulndb#6224 Fixes golang/vulndb#6227 Fixes golang/vulndb#6228 Fixes golang/vulndb#6229 Fixes golang/vulndb#6230 Fixes golang/vulndb#6231 Fixes golang/vulndb#6232 Fixes golang/vulndb#6233 Fixes golang/vulndb#6240 Fixes golang/vulndb#6241 Fixes golang/vulndb#6242 Fixes golang/vulndb#6243 Fixes golang/vulndb#6244 Fixes golang/vulndb#6245 Fixes golang/vulndb#6246 Fixes golang/vulndb#6247 Fixes golang/vulndb#6248 Fixes golang/vulndb#6249 Change-Id: Ib272a4454aab41304af15e36c23bba5b6a207968 Reviewed-on: https://go-review.googlesource.com/c/vulndb/+/816760 SLSA-Policy-Verified: SLSA Policy Verification Service <devtools-gerritcodereview-exitgate@google.com> LUCI-TryBot-Result: golang-scoped@luci-project-accounts.iam.gserviceaccount.com <golang-scoped@luci-project-accounts.iam.gserviceaccount.com> Auto-Submit: Ian Alexander <jitsu@google.com> Reviewed-by: Ethan Lee <ethanalee@google.com>
diff --git a/data/osv/GO-2026-6097.json b/data/osv/GO-2026-6097.json new file mode 100644 index 0000000..73a548b --- /dev/null +++ b/data/osv/GO-2026-6097.json
@@ -0,0 +1,86 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6097", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-55495", + "GHSA-49h3-cwhj-4737" + ], + "summary": "Cloudreve: Path Traversal in WOPI PUT_RELATIVE Allows Arbitrary File Creation in Owner Account in github.com/cloudreve/Cloudreve", + "details": "Cloudreve: Path Traversal in WOPI PUT_RELATIVE Allows Arbitrary File Creation in Owner Account in github.com/cloudreve/Cloudreve", + "affected": [ + { + "package": { + "name": "github.com/cloudreve/Cloudreve", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": {} + }, + { + "package": { + "name": "github.com/cloudreve/Cloudreve/v3", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": {} + }, + { + "package": { + "name": "github.com/cloudreve/Cloudreve/v4", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "4.0.0-20260613023150-7968e50429ef" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/cloudreve/cloudreve/security/advisories/GHSA-49h3-cwhj-4737" + }, + { + "type": "WEB", + "url": "https://github.com/cloudreve/cloudreve/commit/7968e50429efab40ffa8f57fecdfbd5a73d23630" + }, + { + "type": "WEB", + "url": "https://github.com/cloudreve/cloudreve/releases/tag/4.17.0" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6097", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6098.json b/data/osv/GO-2026-6098.json new file mode 100644 index 0000000..9e7191f --- /dev/null +++ b/data/osv/GO-2026-6098.json
@@ -0,0 +1,86 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6098", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-55496", + "GHSA-8r7f-r8hj-r3rv" + ], + "summary": "Cloudreve: Information Exposure in `GET /api/v4/user/search`: `SearchActive` omits the active-status predicate, leaking inactive/banned account emails in github.com/cloudreve/Cloudreve", + "details": "Cloudreve: Information Exposure in `GET /api/v4/user/search`: `SearchActive` omits the active-status predicate, leaking inactive/banned account emails in github.com/cloudreve/Cloudreve", + "affected": [ + { + "package": { + "name": "github.com/cloudreve/Cloudreve", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": {} + }, + { + "package": { + "name": "github.com/cloudreve/Cloudreve/v3", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": {} + }, + { + "package": { + "name": "github.com/cloudreve/Cloudreve/v4", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "4.0.0-20260613023921-7e1289d55279" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/cloudreve/cloudreve/security/advisories/GHSA-8r7f-r8hj-r3rv" + }, + { + "type": "WEB", + "url": "https://github.com/cloudreve/cloudreve/commit/7e1289d552794bdbeb551be78456115c87dcb3da" + }, + { + "type": "WEB", + "url": "https://github.com/cloudreve/cloudreve/releases/tag/4.17.0" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6098", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6099.json b/data/osv/GO-2026-6099.json new file mode 100644 index 0000000..18ac1f2 --- /dev/null +++ b/data/osv/GO-2026-6099.json
@@ -0,0 +1,56 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6099", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-57497", + "GHSA-g35j-m5xg-vh3q" + ], + "summary": "webtransport-go: Memory Exhaustion Attack due to Buffering of Unknown Capsules in github.com/quic-go/webtransport-go", + "details": "webtransport-go: Memory Exhaustion Attack due to Buffering of Unknown Capsules in github.com/quic-go/webtransport-go", + "affected": [ + { + "package": { + "name": "github.com/quic-go/webtransport-go", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.11.1" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/quic-go/webtransport-go/security/advisories/GHSA-g35j-m5xg-vh3q" + }, + { + "type": "FIX", + "url": "https://github.com/quic-go/webtransport-go/commit/3aecd11736579530ff067651c30a543eb0b4b8c4" + }, + { + "type": "FIX", + "url": "https://github.com/quic-go/webtransport-go/pull/290" + }, + { + "type": "WEB", + "url": "https://github.com/quic-go/webtransport-go/releases/tag/v0.11.1" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6099", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6100.json b/data/osv/GO-2026-6100.json new file mode 100644 index 0000000..353afbc --- /dev/null +++ b/data/osv/GO-2026-6100.json
@@ -0,0 +1,86 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6100", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-55497", + "GHSA-g9j2-8w95-3vwv" + ], + "summary": "Cloudreve: Denial of Service - Image decompression / pixel bomb in thumbnail \u0026 avatar decoding crashes the server in github.com/cloudreve/Cloudreve", + "details": "Cloudreve: Denial of Service - Image decompression / pixel bomb in thumbnail \u0026 avatar decoding crashes the server in github.com/cloudreve/Cloudreve", + "affected": [ + { + "package": { + "name": "github.com/cloudreve/Cloudreve", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": {} + }, + { + "package": { + "name": "github.com/cloudreve/Cloudreve/v3", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": {} + }, + { + "package": { + "name": "github.com/cloudreve/Cloudreve/v4", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "4.0.0-20260613024411-3607f79bb44c" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/cloudreve/cloudreve/security/advisories/GHSA-g9j2-8w95-3vwv" + }, + { + "type": "WEB", + "url": "https://github.com/cloudreve/cloudreve/commit/3607f79bb44c35d0be4fa8b6e24c0502b51415a9" + }, + { + "type": "WEB", + "url": "https://github.com/cloudreve/cloudreve/releases/tag/4.17.0" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6100", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6101.json b/data/osv/GO-2026-6101.json new file mode 100644 index 0000000..0150403 --- /dev/null +++ b/data/osv/GO-2026-6101.json
@@ -0,0 +1,97 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6101", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-55502", + "GHSA-hq88-5x99-x3gf" + ], + "summary": "Cloudreve OAuth Admin.Read scope can update OneDrive storage policy credentials in github.com/cloudreve/Cloudreve", + "details": "Cloudreve OAuth Admin.Read scope can update OneDrive storage policy credentials in github.com/cloudreve/Cloudreve.\n\nNOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.\n\n(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)\n\nThe additional affected modules and versions are: github.com/cloudreve/Cloudreve/v4 before v4.17.0.", + "affected": [ + { + "package": { + "name": "github.com/cloudreve/Cloudreve", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": {} + }, + { + "package": { + "name": "github.com/cloudreve/Cloudreve/v3", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": {} + }, + { + "package": { + "name": "github.com/cloudreve/Cloudreve/v4", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "custom_ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "4.17.0" + } + ] + } + ] + } + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/cloudreve/cloudreve/security/advisories/GHSA-hq88-5x99-x3gf" + }, + { + "type": "WEB", + "url": "https://github.com/cloudreve/cloudreve/commit/9e9fb43e7288924cca052e5fdbb70d5365ef1ede" + }, + { + "type": "WEB", + "url": "https://github.com/cloudreve/cloudreve/releases/tag/4.17.0" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6101", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6102.json b/data/osv/GO-2026-6102.json new file mode 100644 index 0000000..333aa53 --- /dev/null +++ b/data/osv/GO-2026-6102.json
@@ -0,0 +1,86 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6102", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-55499", + "GHSA-w8x7-h2px-xmq8" + ], + "summary": "Cloudreve: Broken Access Control in file event stream: a single-file share recipient is subscribed to the owner's parent folder and receives activity events for unshared siblings in github.com/cloudreve/Cloudreve", + "details": "Cloudreve: Broken Access Control in file event stream: a single-file share recipient is subscribed to the owner's parent folder and receives activity events for unshared siblings in github.com/cloudreve/Cloudreve", + "affected": [ + { + "package": { + "name": "github.com/cloudreve/Cloudreve", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": {} + }, + { + "package": { + "name": "github.com/cloudreve/Cloudreve/v3", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": {} + }, + { + "package": { + "name": "github.com/cloudreve/Cloudreve/v4", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "4.0.0-20260613030215-0b00dd308f13" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/cloudreve/cloudreve/security/advisories/GHSA-w8x7-h2px-xmq8" + }, + { + "type": "WEB", + "url": "https://github.com/cloudreve/cloudreve/commit/0b00dd308f132d6e6e8476857ef79f4865600bbc" + }, + { + "type": "WEB", + "url": "https://github.com/cloudreve/cloudreve/releases/tag/4.17.0" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6102", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6103.json b/data/osv/GO-2026-6103.json new file mode 100644 index 0000000..498d493 --- /dev/null +++ b/data/osv/GO-2026-6103.json
@@ -0,0 +1,56 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6103", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-73564", + "GHSA-26gq-p25f-99cp" + ], + "summary": "frp: Unauthenticated Remote Denial of Service in the frp SSH Tunnel Gateway via Integer Overflow in github.com/fatedier/frp", + "details": "frp: Unauthenticated Remote Denial of Service in the frp SSH Tunnel Gateway via Integer Overflow in github.com/fatedier/frp", + "affected": [ + { + "package": { + "name": "github.com/fatedier/frp", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0.53.0" + }, + { + "fixed": "0.70.1" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/fatedier/frp/security/advisories/GHSA-26gq-p25f-99cp" + }, + { + "type": "FIX", + "url": "https://github.com/fatedier/frp/commit/7dc7be930e2452ae93fd32f2a77f8c6fcd0b652b" + }, + { + "type": "FIX", + "url": "https://github.com/fatedier/frp/pull/5428" + }, + { + "type": "WEB", + "url": "https://github.com/fatedier/frp/releases/tag/v0.70.1" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6103", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6104.json b/data/osv/GO-2026-6104.json new file mode 100644 index 0000000..7a3b4da --- /dev/null +++ b/data/osv/GO-2026-6104.json
@@ -0,0 +1,82 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6104", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-62323", + "GHSA-c3jm-gv5r-9wcp" + ], + "summary": "Cloudreve WOPI view sessions can write files and WOPI access token secret is ignored in github.com/cloudreve/Cloudreve", + "details": "Cloudreve WOPI view sessions can write files and WOPI access token secret is ignored in github.com/cloudreve/Cloudreve", + "affected": [ + { + "package": { + "name": "github.com/cloudreve/Cloudreve", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": {} + }, + { + "package": { + "name": "github.com/cloudreve/Cloudreve/v3", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": {} + }, + { + "package": { + "name": "github.com/cloudreve/Cloudreve/v4", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "4.0.0-20260626022433-f3347130ac48" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/cloudreve/cloudreve/security/advisories/GHSA-c3jm-gv5r-9wcp" + }, + { + "type": "WEB", + "url": "https://github.com/cloudreve/cloudreve/commit/f3347130ac48f2ff996af9ef66c97be2dda9cba9" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6104", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6105.json b/data/osv/GO-2026-6105.json new file mode 100644 index 0000000..ccf2a96 --- /dev/null +++ b/data/osv/GO-2026-6105.json
@@ -0,0 +1,59 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6105", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "GHSA-c534-2w9c-x7fm" + ], + "summary": "Kite Kubernetes proxy path traversal allows authenticated users to bypass RBAC and read cluster-wide resources in github.com/zxh326/kite", + "details": "Kite Kubernetes proxy path traversal allows authenticated users to bypass RBAC and read cluster-wide resources in github.com/zxh326/kite", + "affected": [ + { + "package": { + "name": "github.com/zxh326/kite", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0.6.9" + }, + { + "fixed": "0.14.1" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/kite-org/kite/security/advisories/GHSA-c534-2w9c-x7fm" + }, + { + "type": "WEB", + "url": "https://github.com/kite-org/kite/commit/08116eed557f8d6982cc83af0b02991e0f3577d5" + }, + { + "type": "WEB", + "url": "https://github.com/kite-org/kite/commit/69ad938937af8f375a2e183d1a331926ab851d98" + }, + { + "type": "WEB", + "url": "https://github.com/kite-org/kite/pull/638" + }, + { + "type": "WEB", + "url": "https://github.com/kite-org/kite/releases/tag/v0.14.1" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6105", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6106.json b/data/osv/GO-2026-6106.json new file mode 100644 index 0000000..a42394d --- /dev/null +++ b/data/osv/GO-2026-6106.json
@@ -0,0 +1,85 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6106", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "GHSA-v6w6-358x-2433" + ], + "summary": "Cloudreve Admin.Read OAuth tokens can trigger server-side node test requests in github.com/cloudreve/Cloudreve", + "details": "Cloudreve Admin.Read OAuth tokens can trigger server-side node test requests in github.com/cloudreve/Cloudreve", + "affected": [ + { + "package": { + "name": "github.com/cloudreve/Cloudreve", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": {} + }, + { + "package": { + "name": "github.com/cloudreve/Cloudreve/v3", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": {} + }, + { + "package": { + "name": "github.com/cloudreve/Cloudreve/v4", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "4.0.0-20260626022735-332a9d800205" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/cloudreve/cloudreve/security/advisories/GHSA-v6w6-358x-2433" + }, + { + "type": "WEB", + "url": "https://github.com/cloudreve/cloudreve/commit/332a9d800205082a2469e555fd66a63f18d9d5dc" + }, + { + "type": "WEB", + "url": "https://github.com/cloudreve/cloudreve/releases/tag/4.17.0" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6106", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6108.json b/data/osv/GO-2026-6108.json new file mode 100644 index 0000000..024a365 --- /dev/null +++ b/data/osv/GO-2026-6108.json
@@ -0,0 +1,56 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6108", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-73505", + "GHSA-6xj8-qv9j-xcjq" + ], + "summary": "Oh My Posh: Arbitrary command execution via template injection in the path segment in github.com/jandedobbeleer/oh-my-posh", + "details": "Oh My Posh: Arbitrary command execution via template injection in the path segment in github.com/jandedobbeleer/oh-my-posh", + "affected": [ + { + "package": { + "name": "github.com/jandedobbeleer/oh-my-posh", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "29.35.1+incompatible" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/JanDeDobbeleer/oh-my-posh/security/advisories/GHSA-6xj8-qv9j-xcjq" + }, + { + "type": "WEB", + "url": "https://github.com/JanDeDobbeleer/oh-my-posh/commit/88ddbe0b0a4dd13cc345996108c9869493f2c690" + }, + { + "type": "WEB", + "url": "https://github.com/JanDeDobbeleer/oh-my-posh/releases/tag/v29.35.1" + }, + { + "type": "WEB", + "url": "https://github.com/JanDeDobbeleer/oh-my-posh/releases/tag/v29.36.0" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6108", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6109.json b/data/osv/GO-2026-6109.json new file mode 100644 index 0000000..59e27a5 --- /dev/null +++ b/data/osv/GO-2026-6109.json
@@ -0,0 +1,85 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6109", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "GHSA-86cx-wwf4-phq4" + ], + "summary": "OpenList: Arbitrary File Read via Path Prefix Confusion in Share Creation API in github.com/OpenListTeam/OpenList", + "details": "OpenList: Arbitrary File Read via Path Prefix Confusion in Share Creation API in github.com/OpenListTeam/OpenList", + "affected": [ + { + "package": { + "name": "github.com/OpenListTeam/OpenList", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": {} + }, + { + "package": { + "name": "github.com/OpenListTeam/OpenList/v3", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": {} + }, + { + "package": { + "name": "github.com/OpenListTeam/OpenList/v4", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "4.2.4" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/OpenListTeam/OpenList/security/advisories/GHSA-86cx-wwf4-phq4" + }, + { + "type": "FIX", + "url": "https://github.com/OpenListTeam/OpenList/commit/59bd3431408578f420895457554700cc9a52375a" + }, + { + "type": "WEB", + "url": "https://github.com/OpenListTeam/OpenList/releases/tag/v4.2.4" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6109", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6110.json b/data/osv/GO-2026-6110.json new file mode 100644 index 0000000..474539b --- /dev/null +++ b/data/osv/GO-2026-6110.json
@@ -0,0 +1,86 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6110", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-73509", + "GHSA-95cv-r8x4-vh75" + ], + "summary": "OpenList: Authenticated users can rename files outside their base path via batch rename `src_name` traversal in github.com/OpenListTeam/OpenList", + "details": "OpenList: Authenticated users can rename files outside their base path via batch rename `src_name` traversal in github.com/OpenListTeam/OpenList", + "affected": [ + { + "package": { + "name": "github.com/OpenListTeam/OpenList", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": {} + }, + { + "package": { + "name": "github.com/OpenListTeam/OpenList/v3", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": {} + }, + { + "package": { + "name": "github.com/OpenListTeam/OpenList/v4", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "4.2.4" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/OpenListTeam/OpenList/security/advisories/GHSA-95cv-r8x4-vh75" + }, + { + "type": "FIX", + "url": "https://github.com/OpenListTeam/OpenList/commit/651da18da4c647d96648d4bb64462baac1c37e04" + }, + { + "type": "WEB", + "url": "https://github.com/OpenListTeam/OpenList/releases/tag/v4.2.4" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6110", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6111.json b/data/osv/GO-2026-6111.json new file mode 100644 index 0000000..cffe1ba --- /dev/null +++ b/data/osv/GO-2026-6111.json
@@ -0,0 +1,56 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6111", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-73506", + "GHSA-fwjx-9p69-h25h" + ], + "summary": "Oh My Posh: Terminal escape sequence injection via unsanitized prompt segment data in github.com/jandedobbeleer/oh-my-posh", + "details": "Oh My Posh: Terminal escape sequence injection via unsanitized prompt segment data in github.com/jandedobbeleer/oh-my-posh", + "affected": [ + { + "package": { + "name": "github.com/jandedobbeleer/oh-my-posh", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "29.35.1+incompatible" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/JanDeDobbeleer/oh-my-posh/security/advisories/GHSA-fwjx-9p69-h25h" + }, + { + "type": "WEB", + "url": "https://github.com/JanDeDobbeleer/oh-my-posh/commit/edcf3c88f3fb582e84358b385c49d33d04c04224" + }, + { + "type": "WEB", + "url": "https://github.com/JanDeDobbeleer/oh-my-posh/releases/tag/v29.35.1" + }, + { + "type": "WEB", + "url": "https://github.com/JanDeDobbeleer/oh-my-posh/releases/tag/v29.36.0" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6111", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6113.json b/data/osv/GO-2026-6113.json new file mode 100644 index 0000000..512fac9 --- /dev/null +++ b/data/osv/GO-2026-6113.json
@@ -0,0 +1,89 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6113", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "GHSA-p6ph-3jx2-3337" + ], + "summary": "OpenList: Search metadata/count disclosure via Non-Separator-Aware Path Check in Bleve Search in github.com/OpenListTeam/OpenList", + "details": "OpenList: Search metadata/count disclosure via Non-Separator-Aware Path Check in Bleve Search in github.com/OpenListTeam/OpenList", + "affected": [ + { + "package": { + "name": "github.com/OpenListTeam/OpenList", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": {} + }, + { + "package": { + "name": "github.com/OpenListTeam/OpenList/v3", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": {} + }, + { + "package": { + "name": "github.com/OpenListTeam/OpenList/v4", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "4.2.4" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/OpenListTeam/OpenList/security/advisories/GHSA-p6ph-3jx2-3337" + }, + { + "type": "FIX", + "url": "https://github.com/OpenListTeam/OpenList/commit/59bd3431408578f420895457554700cc9a52375a" + }, + { + "type": "FIX", + "url": "https://github.com/OpenListTeam/OpenList/commit/84ecda35aae2bd0020474086e6ddfd3aa2340679" + }, + { + "type": "WEB", + "url": "https://github.com/OpenListTeam/OpenList/releases/tag/v4.2.4" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6113", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6117.json b/data/osv/GO-2026-6117.json new file mode 100644 index 0000000..f973bae --- /dev/null +++ b/data/osv/GO-2026-6117.json
@@ -0,0 +1,51 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6117", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "GHSA-hp74-gm6m-2qm5" + ], + "summary": "Pocket ID has a reauthentication bypass via one-time access token login — passkey step-up requirement defeated by JWT freshness check that accepts any login method in github.com/pocket-id/pocket-id/backend", + "details": "Pocket ID has a reauthentication bypass via one-time access token login — passkey step-up requirement defeated by JWT freshness check that accepts any login method in github.com/pocket-id/pocket-id/backend", + "affected": [ + { + "package": { + "name": "github.com/pocket-id/pocket-id/backend", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.0.0-20260419162744-978ac87deffe" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/pocket-id/pocket-id/security/advisories/GHSA-hp74-gm6m-2qm5" + }, + { + "type": "WEB", + "url": "https://github.com/pocket-id/pocket-id/commit/978ac87deffec58beaccd15aead975e91b94c8a5" + }, + { + "type": "WEB", + "url": "https://github.com/pocket-id/pocket-id/releases/tag/v2.6.0" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6117", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6118.json b/data/osv/GO-2026-6118.json new file mode 100644 index 0000000..5a43618 --- /dev/null +++ b/data/osv/GO-2026-6118.json
@@ -0,0 +1,56 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6118", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-47427", + "GHSA-w4q6-qw23-4rg7" + ], + "summary": "GitHub MCP Server has Nil Pointer Dereference DoS in completion/complete Handler in github.com/github/github-mcp-server", + "details": "GitHub MCP Server has Nil Pointer Dereference DoS in completion/complete Handler in github.com/github/github-mcp-server", + "affected": [ + { + "package": { + "name": "github.com/github/github-mcp-server", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.1.0" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/github/github-mcp-server/security/advisories/GHSA-w4q6-qw23-4rg7" + }, + { + "type": "FIX", + "url": "https://github.com/github/github-mcp-server/commit/c88d2ecdd3bb07f7bdd75296e3ee676febf14f58" + }, + { + "type": "FIX", + "url": "https://github.com/github/github-mcp-server/pull/2502" + }, + { + "type": "WEB", + "url": "https://github.com/github/github-mcp-server/releases/tag/v1.1.0" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6118", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6119.json b/data/osv/GO-2026-6119.json new file mode 100644 index 0000000..039a364 --- /dev/null +++ b/data/osv/GO-2026-6119.json
@@ -0,0 +1,56 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6119", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-43983", + "GHSA-w6p7-2fxx-4f44" + ], + "summary": "Pocket ID: OIDC refresh token flow bypasses authorization revocation, account disabling, and group restrictions in github.com/pocket-id/pocket-id/backend", + "details": "Pocket ID: OIDC refresh token flow bypasses authorization revocation, account disabling, and group restrictions in github.com/pocket-id/pocket-id/backend", + "affected": [ + { + "package": { + "name": "github.com/pocket-id/pocket-id/backend", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.0.0-20260419162744-978ac87deffe" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/pocket-id/pocket-id/security/advisories/GHSA-w6p7-2fxx-4f44" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-43983" + }, + { + "type": "WEB", + "url": "https://github.com/pocket-id/pocket-id/commit/978ac87deffec58beaccd15aead975e91b94c8a5" + }, + { + "type": "WEB", + "url": "https://github.com/pocket-id/pocket-id/releases/tag/v2.6.0" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6119", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6120.json b/data/osv/GO-2026-6120.json new file mode 100644 index 0000000..35ff729 --- /dev/null +++ b/data/osv/GO-2026-6120.json
@@ -0,0 +1,56 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6120", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-54593", + "GHSA-8r6w-3qq5-4p4r" + ], + "summary": "Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions in github.com/pterodactyl/wings", + "details": "Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions in github.com/pterodactyl/wings", + "affected": [ + { + "package": { + "name": "github.com/pterodactyl/wings", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.12.2" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/pterodactyl/panel/security/advisories/GHSA-8r6w-3qq5-4p4r" + }, + { + "type": "FIX", + "url": "https://github.com/pterodactyl/wings/commit/d0ddc80844479302abdaf9654de3bacd511c0f5c" + }, + { + "type": "WEB", + "url": "https://github.com/pterodactyl/panel/commit/7ffcd636310bb72b54bac3280d2a15e727feded7" + }, + { + "type": "WEB", + "url": "https://github.com/pterodactyl/panel/pull/5636" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6120", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6121.json b/data/osv/GO-2026-6121.json new file mode 100644 index 0000000..e9e330d --- /dev/null +++ b/data/osv/GO-2026-6121.json
@@ -0,0 +1,52 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6121", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-54345", + "GHSA-6r28-9ppf-4hj5" + ], + "summary": "GoPacket's Diameter AVP decoder: uint32 underflow on vendor header size leads to unbounded ~4 GiB allocation (unauthenticated remote DoS) in github.com/gopacket/gopacket", + "details": "GoPacket's Diameter AVP decoder: uint32 underflow on vendor header size leads to unbounded ~4 GiB allocation (unauthenticated remote DoS) in github.com/gopacket/gopacket", + "affected": [ + { + "package": { + "name": "github.com/gopacket/gopacket", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.6.1" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/gopacket/gopacket/security/advisories/GHSA-6r28-9ppf-4hj5" + }, + { + "type": "FIX", + "url": "https://github.com/gopacket/gopacket/commit/145859d0eaee1a6f5925ffb93851c976449c3311" + }, + { + "type": "WEB", + "url": "https://github.com/gopacket/gopacket/releases/tag/v1.6.1" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6121", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6122.json b/data/osv/GO-2026-6122.json new file mode 100644 index 0000000..ab37e67 --- /dev/null +++ b/data/osv/GO-2026-6122.json
@@ -0,0 +1,52 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6122", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-54332", + "GHSA-g6v3-7xmc-w563" + ], + "summary": "GoPacket's sFlow ExtendedGatewayFlow decoder: unbounded attacker-controlled allocation (104-byte UDP datagram -\u003e up to 16 GiB make) -\u003e unauthenticated remote DoS in github.com/gopacket/gopacket", + "details": "GoPacket's sFlow ExtendedGatewayFlow decoder: unbounded attacker-controlled allocation (104-byte UDP datagram -\u003e up to 16 GiB make) -\u003e unauthenticated remote DoS in github.com/gopacket/gopacket", + "affected": [ + { + "package": { + "name": "github.com/gopacket/gopacket", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.6.1" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/gopacket/gopacket/security/advisories/GHSA-g6v3-7xmc-w563" + }, + { + "type": "FIX", + "url": "https://github.com/gopacket/gopacket/commit/76119086f5936aacd7088bdf97d565501bb6c4cc" + }, + { + "type": "WEB", + "url": "https://github.com/gopacket/gopacket/releases/tag/v1.6.1" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6122", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6123.json b/data/osv/GO-2026-6123.json new file mode 100644 index 0000000..c5241a0 --- /dev/null +++ b/data/osv/GO-2026-6123.json
@@ -0,0 +1,48 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6123", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-49446", + "GHSA-2rx5-2g7j-2659" + ], + "summary": "Cosmos-Server has an authentication bypass via forward-auth header smuggling on Constellation tunnel in github.com/azukaar/cosmos-server", + "details": "Cosmos-Server has an authentication bypass via forward-auth header smuggling on Constellation tunnel in github.com/azukaar/cosmos-server", + "affected": [ + { + "package": { + "name": "github.com/azukaar/cosmos-server", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.22.19" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/azukaar/Cosmos-Server/security/advisories/GHSA-2rx5-2g7j-2659" + }, + { + "type": "WEB", + "url": "https://github.com/azukaar/Cosmos-Server/releases/tag/v0.22.19" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6123", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6124.json b/data/osv/GO-2026-6124.json new file mode 100644 index 0000000..ce8f1eb --- /dev/null +++ b/data/osv/GO-2026-6124.json
@@ -0,0 +1,52 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6124", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-49447", + "GHSA-5fqm-cc34-fcf5" + ], + "summary": "Cosmos-Server's constellation public-devices endpoint accepts arbitrary bearer tokens in github.com/azukaar/cosmos-server", + "details": "Cosmos-Server's constellation public-devices endpoint accepts arbitrary bearer tokens in github.com/azukaar/cosmos-server", + "affected": [ + { + "package": { + "name": "github.com/azukaar/cosmos-server", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0.22.18" + }, + { + "fixed": "0.22.19" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/azukaar/Cosmos-Server/security/advisories/GHSA-5fqm-cc34-fcf5" + }, + { + "type": "WEB", + "url": "https://github.com/azukaar/Cosmos-Server/commit/59c561d686c8f9843b3e092b50f6346c481d8bbf" + }, + { + "type": "WEB", + "url": "https://github.com/azukaar/Cosmos-Server/releases/tag/v0.22.19" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6124", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6125.json b/data/osv/GO-2026-6125.json new file mode 100644 index 0000000..a5090df --- /dev/null +++ b/data/osv/GO-2026-6125.json
@@ -0,0 +1,69 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6125", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-11479", + "GHSA-6h35-9p2w-3j3r" + ], + "summary": "grepai Uses a Broken or Risky Cryptographic Algorithm in github.com/yoanbernabeu/grepai", + "details": "grepai Uses a Broken or Risky Cryptographic Algorithm in github.com/yoanbernabeu/grepai", + "affected": [ + { + "package": { + "name": "github.com/yoanbernabeu/grepai", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-6h35-9p2w-3j3r" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-11479" + }, + { + "type": "FIX", + "url": "https://github.com/yoanbernabeu/grepai/pull/248" + }, + { + "type": "REPORT", + "url": "https://github.com/yoanbernabeu/grepai/issues/247" + }, + { + "type": "WEB", + "url": "https://vuldb.com/cve/CVE-2026-11479" + }, + { + "type": "WEB", + "url": "https://vuldb.com/submit/833971" + }, + { + "type": "WEB", + "url": "https://vuldb.com/vuln/369099" + }, + { + "type": "WEB", + "url": "https://vuldb.com/vuln/369099/cti" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6125", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6126.json b/data/osv/GO-2026-6126.json new file mode 100644 index 0000000..ed3a0e3 --- /dev/null +++ b/data/osv/GO-2026-6126.json
@@ -0,0 +1,80 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6126", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-11465", + "GHSA-7v3v-cp44-vc8m" + ], + "summary": "songquanpeng one-api has an issue that results in business logic errors", + "details": "songquanpeng one-api has an issue that results in business logic errors.\n\nNOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.\n\n(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)\n\nThe additional affected modules and versions are: .", + "affected": [ + { + "package": { + "name": "github.com/songquanpeng/one-api", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "custom_ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0.1.6-alpha" + } + ] + } + ] + } + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-7v3v-cp44-vc8m" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-11465" + }, + { + "type": "WEB", + "url": "https://github.com/songquanpeng/one-api/issues/2397" + }, + { + "type": "WEB", + "url": "https://github.com/songquanpeng/one-api/pull/2399" + }, + { + "type": "WEB", + "url": "https://vuldb.com/cve/CVE-2026-11465" + }, + { + "type": "WEB", + "url": "https://vuldb.com/submit/833320" + }, + { + "type": "WEB", + "url": "https://vuldb.com/vuln/369085" + }, + { + "type": "WEB", + "url": "https://vuldb.com/vuln/369085/cti" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6126", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6127.json b/data/osv/GO-2026-6127.json new file mode 100644 index 0000000..a5ead86 --- /dev/null +++ b/data/osv/GO-2026-6127.json
@@ -0,0 +1,56 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6127", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-50567", + "GHSA-q6vm-xqc9-v3ff" + ], + "summary": "Fission: Zip Slip in pkg/utils/zip.go:Unarchive allows fetcher to write outside the destination directory in github.com/fission/fission", + "details": "Fission: Zip Slip in pkg/utils/zip.go:Unarchive allows fetcher to write outside the destination directory in github.com/fission/fission", + "affected": [ + { + "package": { + "name": "github.com/fission/fission", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.25.0" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/fission/fission/security/advisories/GHSA-q6vm-xqc9-v3ff" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-50567" + }, + { + "type": "FIX", + "url": "https://github.com/fission/fission/pull/3444" + }, + { + "type": "WEB", + "url": "https://github.com/fission/fission/releases/tag/v1.25.0" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6127", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6128.json b/data/osv/GO-2026-6128.json new file mode 100644 index 0000000..7a2f98b --- /dev/null +++ b/data/osv/GO-2026-6128.json
@@ -0,0 +1,69 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6128", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-11481", + "GHSA-q76h-p6jh-9rw3" + ], + "summary": "grepai Uses a Broken or Risky Cryptographic Algorithm in github.com/yoanbernabeu/grepai", + "details": "grepai Uses a Broken or Risky Cryptographic Algorithm in github.com/yoanbernabeu/grepai", + "affected": [ + { + "package": { + "name": "github.com/yoanbernabeu/grepai", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-q76h-p6jh-9rw3" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-11481" + }, + { + "type": "FIX", + "url": "https://github.com/yoanbernabeu/grepai/pull/250" + }, + { + "type": "REPORT", + "url": "https://github.com/yoanbernabeu/grepai/issues/249" + }, + { + "type": "WEB", + "url": "https://vuldb.com/cve/CVE-2026-11481" + }, + { + "type": "WEB", + "url": "https://vuldb.com/submit/833997" + }, + { + "type": "WEB", + "url": "https://vuldb.com/vuln/369101" + }, + { + "type": "WEB", + "url": "https://vuldb.com/vuln/369101/cti" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6128", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6129.json b/data/osv/GO-2026-6129.json new file mode 100644 index 0000000..2a02b84 --- /dev/null +++ b/data/osv/GO-2026-6129.json
@@ -0,0 +1,60 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6129", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-50570", + "GHSA-qf5v-m7p4-95rp" + ], + "summary": "Fission: Incomplete capability denylist in Environment/Function PodSpec validation allows tenant-added CAP_SYS_TIME and cross-tenant node wall-clock corruption in github.com/fission/fission", + "details": "Fission: Incomplete capability denylist in Environment/Function PodSpec validation allows tenant-added CAP_SYS_TIME and cross-tenant node wall-clock corruption in github.com/fission/fission", + "affected": [ + { + "package": { + "name": "github.com/fission/fission", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.25.0" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/fission/fission/security/advisories/GHSA-qf5v-m7p4-95rp" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-50570" + }, + { + "type": "FIX", + "url": "https://github.com/fission/fission/commit/2569b42bfadbcb7d78b55a00a60f77937e522699" + }, + { + "type": "FIX", + "url": "https://github.com/fission/fission/pull/3465" + }, + { + "type": "WEB", + "url": "https://github.com/fission/fission/releases/tag/v1.25.0" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6129", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6130.json b/data/osv/GO-2026-6130.json new file mode 100644 index 0000000..b90b9a7 --- /dev/null +++ b/data/osv/GO-2026-6130.json
@@ -0,0 +1,68 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6130", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-50568", + "GHSA-r5jh-q2mw-gcx4" + ], + "summary": "Fission: SanitizeFilePath lexical HasPrefix bypass permits sibling-directory escape in github.com/fission/fission", + "details": "Fission: SanitizeFilePath lexical HasPrefix bypass permits sibling-directory escape in github.com/fission/fission", + "affected": [ + { + "package": { + "name": "github.com/fission/fission", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.25.0" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/fission/fission/security/advisories/GHSA-r5jh-q2mw-gcx4" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-50568" + }, + { + "type": "FIX", + "url": "https://github.com/fission/fission/commit/5aac6f0bcdf840e28f3f06c846ca7ae1866b3957" + }, + { + "type": "FIX", + "url": "https://github.com/fission/fission/commit/8298e33ea7457702f893eae11077987cf905edb4" + }, + { + "type": "FIX", + "url": "https://github.com/fission/fission/pull/3445" + }, + { + "type": "FIX", + "url": "https://github.com/fission/fission/pull/3446" + }, + { + "type": "WEB", + "url": "https://github.com/fission/fission/releases/tag/v1.25.0" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6130", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6131.json b/data/osv/GO-2026-6131.json new file mode 100644 index 0000000..932e564 --- /dev/null +++ b/data/osv/GO-2026-6131.json
@@ -0,0 +1,60 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6131", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-50569", + "GHSA-vchh-r53j-8mpw" + ], + "summary": "Fission: HTTPTrigger admission omits RelativeURL / Prefix validation; kubectl apply bypasses CLI checks in github.com/fission/fission", + "details": "Fission: HTTPTrigger admission omits RelativeURL / Prefix validation; kubectl apply bypasses CLI checks in github.com/fission/fission", + "affected": [ + { + "package": { + "name": "github.com/fission/fission", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.25.0" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/fission/fission/security/advisories/GHSA-vchh-r53j-8mpw" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-50569" + }, + { + "type": "FIX", + "url": "https://github.com/fission/fission/commit/0deed6bf3f26bc0f10e9130cd0d479b0b9f5f609" + }, + { + "type": "FIX", + "url": "https://github.com/fission/fission/pull/3464" + }, + { + "type": "WEB", + "url": "https://github.com/fission/fission/releases/tag/v1.25.0" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6131", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6132.json b/data/osv/GO-2026-6132.json new file mode 100644 index 0000000..3b87aaa --- /dev/null +++ b/data/osv/GO-2026-6132.json
@@ -0,0 +1,69 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6132", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-62325", + "GHSA-rjrw-mjq6-hpmm" + ], + "summary": "goshs SFTP authentication bypass via empty password (incomplete fix of CVE-2026-40884) in goshs.de/goshs", + "details": "goshs SFTP authentication bypass via empty password (incomplete fix of CVE-2026-40884) in goshs.de/goshs", + "affected": [ + { + "package": { + "name": "goshs.de/goshs", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": {} + }, + { + "package": { + "name": "goshs.de/goshs/v2", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "2.1.3" + }, + { + "fixed": "2.1.4" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/goshs-labs/goshs/security/advisories/GHSA-rjrw-mjq6-hpmm" + }, + { + "type": "WEB", + "url": "https://github.com/goshs-labs/goshs/commit/32f4a0e1790a709f722d0f3b2341f139d003180a" + }, + { + "type": "WEB", + "url": "https://github.com/goshs-labs/goshs/releases/tag/v2.1.4" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6132", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6133.json b/data/osv/GO-2026-6133.json new file mode 100644 index 0000000..17e0725 --- /dev/null +++ b/data/osv/GO-2026-6133.json
@@ -0,0 +1,86 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6133", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-54719", + "GHSA-rmxw-pq4x-3fvh" + ], + "summary": "goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx) in github.com/patrickhener/goshs", + "details": "goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx) in github.com/patrickhener/goshs", + "affected": [ + { + "package": { + "name": "github.com/patrickhener/goshs", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": {} + }, + { + "package": { + "name": "goshs.de/goshs", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": {} + }, + { + "package": { + "name": "goshs.de/goshs/v2", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "2.1.1" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/goshs-labs/goshs/security/advisories/GHSA-rmxw-pq4x-3fvh" + }, + { + "type": "WEB", + "url": "https://github.com/goshs-labs/goshs/commit/7cf911a26ace737e1a55b7dc073e307a25f7fd1d" + }, + { + "type": "WEB", + "url": "https://github.com/goshs-labs/goshs/releases/tag/v2.1.1" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6133", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6134.json b/data/osv/GO-2026-6134.json new file mode 100644 index 0000000..210278a --- /dev/null +++ b/data/osv/GO-2026-6134.json
@@ -0,0 +1,86 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6134", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-66064", + "GHSA-964w-f6gj-5236" + ], + "summary": "goshs has ACL Bypass \u0026 Path Traversal in github.com/patrickhener/goshs", + "details": "goshs has ACL Bypass \u0026 Path Traversal in github.com/patrickhener/goshs", + "affected": [ + { + "package": { + "name": "github.com/patrickhener/goshs", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": {} + }, + { + "package": { + "name": "goshs.de/goshs", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": {} + }, + { + "package": { + "name": "goshs.de/goshs/v2", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "2.1.5-0.20260727065949-f3ef599e4091" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/goshs-labs/goshs/security/advisories/GHSA-964w-f6gj-5236" + }, + { + "type": "WEB", + "url": "https://github.com/goshs-labs/goshs/commit/f3ef599e409151d1380866e47de8b1afb0bb54fa" + }, + { + "type": "WEB", + "url": "https://github.com/goshs-labs/goshs/pull/222" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6134", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6135.json b/data/osv/GO-2026-6135.json new file mode 100644 index 0000000..bdb95c1 --- /dev/null +++ b/data/osv/GO-2026-6135.json
@@ -0,0 +1,52 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6135", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-54650", + "GHSA-fh2f-xfxc-q9cc" + ], + "summary": "openhole-server vulnerable to path traversal via URL-decoded request path in github.com/bablilayoub/openhole", + "details": "openhole-server vulnerable to path traversal via URL-decoded request path in github.com/bablilayoub/openhole", + "affected": [ + { + "package": { + "name": "github.com/bablilayoub/openhole", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.1.2" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/bablilayoub/openhole/security/advisories/GHSA-fh2f-xfxc-q9cc" + }, + { + "type": "FIX", + "url": "https://github.com/bablilayoub/openhole/commit/a28c27adde2a7ed0c347b730c8707208c0f78ed3" + }, + { + "type": "WEB", + "url": "https://github.com/bablilayoub/openhole/releases/tag/v0.1.2" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6135", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6136.json b/data/osv/GO-2026-6136.json new file mode 100644 index 0000000..e9539bb --- /dev/null +++ b/data/osv/GO-2026-6136.json
@@ -0,0 +1,86 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6136", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-64863", + "GHSA-hq33-8jgp-8qq3" + ], + "summary": "goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite in github.com/patrickhener/goshs", + "details": "goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite in github.com/patrickhener/goshs", + "affected": [ + { + "package": { + "name": "github.com/patrickhener/goshs", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": {} + }, + { + "package": { + "name": "goshs.de/goshs", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": {} + }, + { + "package": { + "name": "goshs.de/goshs/v2", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "2.1.4" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/goshs-labs/goshs/security/advisories/GHSA-hq33-8jgp-8qq3" + }, + { + "type": "WEB", + "url": "https://github.com/goshs-labs/goshs/commit/0444ac6b1a8176ddae70d940adf7a26b2e5a6c29" + }, + { + "type": "WEB", + "url": "https://github.com/goshs-labs/goshs/releases/tag/v2.1.4" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6136", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6137.json b/data/osv/GO-2026-6137.json new file mode 100644 index 0000000..48468a9 --- /dev/null +++ b/data/osv/GO-2026-6137.json
@@ -0,0 +1,82 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6137", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-66063", + "GHSA-wg2q-39h6-66x9" + ], + "summary": "goshs has a Path Traversal issue in github.com/patrickhener/goshs", + "details": "goshs has a Path Traversal issue in github.com/patrickhener/goshs", + "affected": [ + { + "package": { + "name": "github.com/patrickhener/goshs", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": {} + }, + { + "package": { + "name": "goshs.de/goshs", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": {} + }, + { + "package": { + "name": "goshs.de/goshs/v2", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "2.1.5-0.20260727065949-f3ef599e4091" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/goshs-labs/goshs/security/advisories/GHSA-wg2q-39h6-66x9" + }, + { + "type": "WEB", + "url": "https://github.com/goshs-labs/goshs/commit/f3ef599e409151d1380866e47de8b1afb0bb54fa" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6137", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6140.json b/data/osv/GO-2026-6140.json new file mode 100644 index 0000000..6d47d3b --- /dev/null +++ b/data/osv/GO-2026-6140.json
@@ -0,0 +1,76 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6140", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-11500", + "GHSA-jqpm-wf57-qx5c" + ], + "summary": "Weaviate has an Improper Authorization issue in github.com/weaviate/weaviate", + "details": "Weaviate has an Improper Authorization issue in github.com/weaviate/weaviate", + "affected": [ + { + "package": { + "name": "github.com/weaviate/weaviate", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.38.0-rc.0" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-jqpm-wf57-qx5c" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-11500" + }, + { + "type": "FIX", + "url": "https://github.com/weaviate/weaviate/commit/40f2cc32279f0f8a51016c3c6870a2c0c808e6c0" + }, + { + "type": "REPORT", + "url": "https://github.com/weaviate/weaviate/issues/11392" + }, + { + "type": "WEB", + "url": "https://github.com/weaviate/weaviate/releases/tag/v1.38.0-rc.0" + }, + { + "type": "WEB", + "url": "https://vuldb.com/cve/CVE-2026-11500" + }, + { + "type": "WEB", + "url": "https://vuldb.com/submit/835080" + }, + { + "type": "WEB", + "url": "https://vuldb.com/vuln/369120" + }, + { + "type": "WEB", + "url": "https://vuldb.com/vuln/369120/cti" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6140", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6141.json b/data/osv/GO-2026-6141.json new file mode 100644 index 0000000..bffeae9 --- /dev/null +++ b/data/osv/GO-2026-6141.json
@@ -0,0 +1,120 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6141", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-54693", + "GHSA-jq8w-8q2f-ffm9" + ], + "summary": "ZITADEL Users Can Self-Verify Email/Phone via API in github.com/zitadel/zitadel", + "details": "ZITADEL Users Can Self-Verify Email/Phone via API in github.com/zitadel/zitadel.\n\nNOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.\n\n(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)\n\nThe additional affected modules and versions are: .", + "affected": [ + { + "package": { + "name": "github.com/zitadel/zitadel", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "custom_ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "2.43.0" + } + ] + } + ] + } + }, + { + "package": { + "name": "github.com/zitadel/zitadel", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "custom_ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "4.0.0" + } + ] + } + ] + } + }, + { + "package": { + "name": "github.com/zitadel/zitadel", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.80.0-v2.20.0.20260608144108-ed09b3df7f43" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/zitadel/zitadel/security/advisories/GHSA-jq8w-8q2f-ffm9" + }, + { + "type": "FIX", + "url": "https://github.com/zitadel/zitadel/commit/90f310212d3a5075084a603bf61fed549c92956d" + }, + { + "type": "FIX", + "url": "https://github.com/zitadel/zitadel/commit/a1748b2f0326ddf7be0de44b4f980ae2c07c0151" + }, + { + "type": "FIX", + "url": "https://github.com/zitadel/zitadel/commit/ed09b3df7f43e870423e4d8f2757e6894481604f" + }, + { + "type": "WEB", + "url": "https://github.com/zitadel/zitadel/releases/tag/v3.4.11" + }, + { + "type": "WEB", + "url": "https://github.com/zitadel/zitadel/releases/tag/v4.15.1" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6141", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6142.json b/data/osv/GO-2026-6142.json new file mode 100644 index 0000000..fb614d8 --- /dev/null +++ b/data/osv/GO-2026-6142.json
@@ -0,0 +1,52 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6142", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-54680", + "GHSA-mjqf-28ph-426h" + ], + "summary": "Logging operator has Fluentd configuration injection that allows remote code execution in github.com/kube-logging/logging-operator", + "details": "Logging operator has Fluentd configuration injection that allows remote code execution in github.com/kube-logging/logging-operator", + "affected": [ + { + "package": { + "name": "github.com/kube-logging/logging-operator", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.0.0-20260608145523-cf437d7f1e05" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/kube-logging/logging-operator/security/advisories/GHSA-mjqf-28ph-426h" + }, + { + "type": "FIX", + "url": "https://github.com/kube-logging/logging-operator/commit/cf437d7f1e056c78740bf5716ac8bdebcf002425" + }, + { + "type": "WEB", + "url": "https://github.com/kube-logging/logging-operator/releases/tag/6.6.0" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6142", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6143.json b/data/osv/GO-2026-6143.json new file mode 100644 index 0000000..bb4c8fd --- /dev/null +++ b/data/osv/GO-2026-6143.json
@@ -0,0 +1,55 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6143", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "GHSA-xvg2-cgv6-6h7v" + ], + "summary": "netfoil: Incorrect block responses could lead to localhost traffic in github.com/tinfoil-factory/netfoil", + "details": "netfoil: Incorrect block responses could lead to localhost traffic in github.com/tinfoil-factory/netfoil", + "affected": [ + { + "package": { + "name": "github.com/tinfoil-factory/netfoil", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.4.0" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/tinfoil-factory/netfoil/security/advisories/GHSA-xvg2-cgv6-6h7v" + }, + { + "type": "FIX", + "url": "https://github.com/tinfoil-factory/netfoil/commit/891d3513c77999a9deef9f23506807d9653ee448" + }, + { + "type": "FIX", + "url": "https://github.com/tinfoil-factory/netfoil/pull/33" + }, + { + "type": "WEB", + "url": "https://github.com/tinfoil-factory/netfoil/releases/tag/v0.4.0" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6143", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6144.json b/data/osv/GO-2026-6144.json new file mode 100644 index 0000000..1d9f52f --- /dev/null +++ b/data/osv/GO-2026-6144.json
@@ -0,0 +1,56 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6144", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-67439", + "GHSA-jm28-2wcr-qf3h" + ], + "summary": "OliveTin: StartActionAndWait Endpoints Bypass `logs` Permission and Return Action Output in github.com/OliveTin/OliveTin", + "details": "OliveTin: StartActionAndWait Endpoints Bypass `logs` Permission and Return Action Output in github.com/OliveTin/OliveTin", + "affected": [ + { + "package": { + "name": "github.com/OliveTin/OliveTin", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.0.0-20260708085316-e421780c9885" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/OliveTin/OliveTin/security/advisories/GHSA-jm28-2wcr-qf3h" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-67439" + }, + { + "type": "FIX", + "url": "https://github.com/OliveTin/OliveTin/commit/e421780c9885aa5024d2f47b4ed4898f2f18eb90" + }, + { + "type": "WEB", + "url": "https://github.com/OliveTin/OliveTin/releases/tag/3000.17.0" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6144", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6145.json b/data/osv/GO-2026-6145.json new file mode 100644 index 0000000..7c2fd7e --- /dev/null +++ b/data/osv/GO-2026-6145.json
@@ -0,0 +1,56 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6145", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-67438", + "GHSA-xc5w-4v5w-7x65" + ], + "summary": "OliveTin OS Command Injection via Custom regex: Argument Type Bypassing Shell Safety Check in github.com/OliveTin/OliveTin", + "details": "OliveTin OS Command Injection via Custom regex: Argument Type Bypassing Shell Safety Check in github.com/OliveTin/OliveTin", + "affected": [ + { + "package": { + "name": "github.com/OliveTin/OliveTin", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0.0.0-20251025234746-ef5a67e7b8ea" + }, + { + "fixed": "0.0.0-20260708084548-995ff79736f2" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/OliveTin/OliveTin/security/advisories/GHSA-xc5w-4v5w-7x65" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-67438" + }, + { + "type": "FIX", + "url": "https://github.com/OliveTin/OliveTin/commit/995ff79736f2bccc364448a3ece84087b550b232" + }, + { + "type": "WEB", + "url": "https://github.com/OliveTin/OliveTin/releases/tag/3000.17.0" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6145", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6146.json b/data/osv/GO-2026-6146.json new file mode 100644 index 0000000..b73803e --- /dev/null +++ b/data/osv/GO-2026-6146.json
@@ -0,0 +1,56 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6146", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-67437", + "GHSA-xpxj-f2fm-rqch" + ], + "summary": "OliveTin: Unauthenticated DoS via OAuth2 State Memory Exhaustion (Unbounded Map Growth) in github.com/OliveTin/OliveTin", + "details": "OliveTin: Unauthenticated DoS via OAuth2 State Memory Exhaustion (Unbounded Map Growth) in github.com/OliveTin/OliveTin", + "affected": [ + { + "package": { + "name": "github.com/OliveTin/OliveTin", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0.0.0-20251024001301-45f9c18bc3ee" + }, + { + "fixed": "0.0.0-20260708075951-ec114e95d297" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/OliveTin/OliveTin/security/advisories/GHSA-xpxj-f2fm-rqch" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-67437" + }, + { + "type": "FIX", + "url": "https://github.com/OliveTin/OliveTin/commit/ec114e95d297b806c3ca0c37bc139b3c9c517b3f" + }, + { + "type": "WEB", + "url": "https://github.com/OliveTin/OliveTin/releases/tag/3000.17.0" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6146", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6147.json b/data/osv/GO-2026-6147.json new file mode 100644 index 0000000..cf1d118 --- /dev/null +++ b/data/osv/GO-2026-6147.json
@@ -0,0 +1,56 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6147", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-25688", + "GHSA-hmr2-99jm-8x45" + ], + "summary": "Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability in github.com/apache/answer", + "details": "Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability in github.com/apache/answer", + "affected": [ + { + "package": { + "name": "github.com/apache/answer", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.7.2-0.20260525024654-2746bf5b455f" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-hmr2-99jm-8x45" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25688" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2026/06/09/7" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/x42joj43rqb38ms5q60f7bgq3qbo7t5q" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6147", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6148.json b/data/osv/GO-2026-6148.json new file mode 100644 index 0000000..fb8b504 --- /dev/null +++ b/data/osv/GO-2026-6148.json
@@ -0,0 +1,64 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6148", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-25699", + "GHSA-w754-5646-xq9j" + ], + "summary": "Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer", + "details": "Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer", + "affected": [ + { + "package": { + "name": "github.com/apache/answer", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.7.2-0.20260206073245-92994b49976b" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-w754-5646-xq9j" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25699" + }, + { + "type": "FIX", + "url": "https://github.com/apache/answer/commit/92994b49976b6206a7000d045d924ec4fd5be1be" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2026/06/09/6" + }, + { + "type": "WEB", + "url": "https://github.com/apache/answer/releases/tag/v2.0.1" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/c36k4hzwhncqo0qfn5fg57f1gkjhyfv8" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6148", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6151.json b/data/osv/GO-2026-6151.json new file mode 100644 index 0000000..58f530d --- /dev/null +++ b/data/osv/GO-2026-6151.json
@@ -0,0 +1,64 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6151", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-34033", + "GHSA-6qwm-5fm9-cvjx" + ], + "summary": "Apache Answer vulnerable to Cross-site Scripting in github.com/apache/answer", + "details": "Apache Answer vulnerable to Cross-site Scripting in github.com/apache/answer", + "affected": [ + { + "package": { + "name": "github.com/apache/answer", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.7.2-0.20260509080709-d1a4092c61cc" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-6qwm-5fm9-cvjx" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-34033" + }, + { + "type": "FIX", + "url": "https://github.com/apache/answer/commit/d1a4092c61ccd41988d1033fce47eb513adb433e" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2026/06/09/3" + }, + { + "type": "WEB", + "url": "https://github.com/apache/answer/releases/tag/v2.0.1" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/wrfd9blbfotfg479jr8vlwfx6pwr9sgj" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6151", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6152.json b/data/osv/GO-2026-6152.json new file mode 100644 index 0000000..87ba332 --- /dev/null +++ b/data/osv/GO-2026-6152.json
@@ -0,0 +1,64 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6152", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-34905", + "GHSA-85r2-pvg8-89r9" + ], + "summary": "Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in github.com/apache/answer", + "details": "Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in github.com/apache/answer", + "affected": [ + { + "package": { + "name": "github.com/apache/answer", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.7.2-0.20260509071350-11c80384f13a" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-85r2-pvg8-89r9" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-34905" + }, + { + "type": "FIX", + "url": "https://github.com/apache/answer/commit/11c80384f13a27e27c871c05bb353489d1363ee2" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2026/06/09/2" + }, + { + "type": "WEB", + "url": "https://github.com/apache/answer/releases/tag/v2.0.1" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/khxoft96sptr2kh0cpzgw7f6qwv0ltcf" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6152", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6153.json b/data/osv/GO-2026-6153.json new file mode 100644 index 0000000..db342ef --- /dev/null +++ b/data/osv/GO-2026-6153.json
@@ -0,0 +1,64 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6153", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-33582", + "GHSA-v553-g2w6-295p" + ], + "summary": "Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer", + "details": "Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer", + "affected": [ + { + "package": { + "name": "github.com/apache/answer", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.7.2-0.20260325113131-cfc3e54f30cc" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-v553-g2w6-295p" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33582" + }, + { + "type": "FIX", + "url": "https://github.com/apache/answer/commit/cfc3e54f30cc5e01afb7110ecc1da9152d0a3a41" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2026/06/09/5" + }, + { + "type": "WEB", + "url": "https://github.com/apache/answer/releases/tag/v2.0.1" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/3sgpx4cwsgpnt66xv3cqvtc8z4st1kbq" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6153", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6154.json b/data/osv/GO-2026-6154.json new file mode 100644 index 0000000..8a5a990 --- /dev/null +++ b/data/osv/GO-2026-6154.json
@@ -0,0 +1,64 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6154", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-34031", + "GHSA-x4f6-mqg6-28xx" + ], + "summary": "Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer", + "details": "Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer", + "affected": [ + { + "package": { + "name": "github.com/apache/answer", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.7.2-0.20260511040518-11091244f64e" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-x4f6-mqg6-28xx" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-34031" + }, + { + "type": "FIX", + "url": "https://github.com/apache/answer/commit/11091244f64e5a7e472edcd477c1ff4124eca7c3" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2026/06/09/4" + }, + { + "type": "WEB", + "url": "https://github.com/apache/answer/releases/tag/v2.0.1" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/rwtxy39t54to9kv3dqtbjsbdpyk4jkd2" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6154", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6155.json b/data/osv/GO-2026-6155.json new file mode 100644 index 0000000..c4cdedd --- /dev/null +++ b/data/osv/GO-2026-6155.json
@@ -0,0 +1,52 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6155", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-65834", + "GHSA-68cj-mvg9-rgm2" + ], + "summary": "Capsule: CapsuleConfiguration NodeMetadata regex fields lack webhook validation, allowing MustCompile panic on all Node admission requests in github.com/projectcapsule/capsule", + "details": "Capsule: CapsuleConfiguration NodeMetadata regex fields lack webhook validation, allowing MustCompile panic on all Node admission requests in github.com/projectcapsule/capsule", + "affected": [ + { + "package": { + "name": "github.com/projectcapsule/capsule", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.13.8" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/projectcapsule/capsule/security/advisories/GHSA-68cj-mvg9-rgm2" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-65834" + }, + { + "type": "WEB", + "url": "https://github.com/projectcapsule/capsule/releases/tag/v0.13.8" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6155", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6156.json b/data/osv/GO-2026-6156.json new file mode 100644 index 0000000..effdcc2 --- /dev/null +++ b/data/osv/GO-2026-6156.json
@@ -0,0 +1,52 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6156", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-52856", + "GHSA-ghrq-5wpp-hxx5" + ], + "summary": "Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service in github.com/pterodactyl/wings", + "details": "Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service in github.com/pterodactyl/wings", + "affected": [ + { + "package": { + "name": "github.com/pterodactyl/wings", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.13.0" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/pterodactyl/wings/security/advisories/GHSA-ghrq-5wpp-hxx5" + }, + { + "type": "FIX", + "url": "https://github.com/pterodactyl/wings/commit/8e49c7c0eda815d3ada171831876a1c14c493026" + }, + { + "type": "WEB", + "url": "https://github.com/pterodactyl/wings/releases/tag/v1.13.0" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6156", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6157.json b/data/osv/GO-2026-6157.json new file mode 100644 index 0000000..558599b --- /dev/null +++ b/data/osv/GO-2026-6157.json
@@ -0,0 +1,52 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6157", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-65835", + "GHSA-jr6p-8pjj-mfx6" + ], + "summary": "Capsule has an incomplete fix of CVE-2026-22872: TenantResource RawItems and Generators still allow cluster-scoped resource creation (cross-tenant privilege escalation) in github.com/projectcapsule/capsule", + "details": "Capsule has an incomplete fix of CVE-2026-22872: TenantResource RawItems and Generators still allow cluster-scoped resource creation (cross-tenant privilege escalation) in github.com/projectcapsule/capsule", + "affected": [ + { + "package": { + "name": "github.com/projectcapsule/capsule", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0.13.0" + }, + { + "fixed": "0.13.8" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/projectcapsule/capsule/security/advisories/GHSA-jr6p-8pjj-mfx6" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-65835" + }, + { + "type": "WEB", + "url": "https://github.com/projectcapsule/capsule/releases/tag/v0.13.8" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6157", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6158.json b/data/osv/GO-2026-6158.json new file mode 100644 index 0000000..5c2fea2 --- /dev/null +++ b/data/osv/GO-2026-6158.json
@@ -0,0 +1,52 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6158", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-52855", + "GHSA-pfvc-3p5h-x7h6" + ], + "summary": "Wings exposes node configuration secrets through egg configuration-file templating in github.com/pterodactyl/wings", + "details": "Wings exposes node configuration secrets through egg configuration-file templating in github.com/pterodactyl/wings", + "affected": [ + { + "package": { + "name": "github.com/pterodactyl/wings", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.12.3" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/pterodactyl/wings/security/advisories/GHSA-pfvc-3p5h-x7h6" + }, + { + "type": "FIX", + "url": "https://github.com/pterodactyl/wings/commit/eb65e27ae077a63e38518c490768486af1cd86a9" + }, + { + "type": "WEB", + "url": "https://github.com/pterodactyl/wings/releases/tag/v1.12.3" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6158", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6159.json b/data/osv/GO-2026-6159.json new file mode 100644 index 0000000..ca9d124 --- /dev/null +++ b/data/osv/GO-2026-6159.json
@@ -0,0 +1,52 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6159", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-52857", + "GHSA-q6hh-gp44-4hcm" + ], + "summary": "Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM in github.com/pterodactyl/wings", + "details": "Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM in github.com/pterodactyl/wings", + "affected": [ + { + "package": { + "name": "github.com/pterodactyl/wings", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.13.0" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/pterodactyl/wings/security/advisories/GHSA-q6hh-gp44-4hcm" + }, + { + "type": "FIX", + "url": "https://github.com/pterodactyl/wings/commit/5f71f65711b6b9e6f913bec94a7b36d9a5eaae49" + }, + { + "type": "WEB", + "url": "https://github.com/pterodactyl/wings/releases/tag/v1.13.0" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6159", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6160.json b/data/osv/GO-2026-6160.json new file mode 100644 index 0000000..e2d5b14 --- /dev/null +++ b/data/osv/GO-2026-6160.json
@@ -0,0 +1,52 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6160", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-54725", + "GHSA-r2v3-8gwf-7ghm" + ], + "summary": "vault-addr annotation SSRF -- webhook makes outbound HTTP call to attacker URL during admission; vault-serviceaccount enables cluster-wide SA token theft via TokenRequest API in github.com/bank-vaults/vault-secrets-webhook", + "details": "vault-addr annotation SSRF -- webhook makes outbound HTTP call to attacker URL during admission; vault-serviceaccount enables cluster-wide SA token theft via TokenRequest API in github.com/bank-vaults/vault-secrets-webhook", + "affected": [ + { + "package": { + "name": "github.com/bank-vaults/vault-secrets-webhook", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.23.1" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/bank-vaults/vault-secrets-webhook/security/advisories/GHSA-r2v3-8gwf-7ghm" + }, + { + "type": "FIX", + "url": "https://github.com/bank-vaults/vault-secrets-webhook/commit/76db45976fee0f54cafd94dffa425e6b542f65a0" + }, + { + "type": "WEB", + "url": "https://github.com/bank-vaults/vault-secrets-webhook/releases/tag/v1.23.1" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6160", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6161.json b/data/osv/GO-2026-6161.json new file mode 100644 index 0000000..3738759 --- /dev/null +++ b/data/osv/GO-2026-6161.json
@@ -0,0 +1,84 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6161", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-53551", + "GHSA-qj55-47fp-p62j" + ], + "summary": "free5GC AUSF: null byte injection in supiOrSuci causes HTTP 500 internal service failure in github.com/free5gc/ausf", + "details": "free5GC AUSF: null byte injection in supiOrSuci causes HTTP 500 internal service failure in github.com/free5gc/ausf", + "affected": [ + { + "package": { + "name": "github.com/free5gc/ausf", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.4.5" + } + ] + } + ], + "ecosystem_specific": {} + }, + { + "package": { + "name": "github.com/free5gc/free5gc", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "4.2.2+incompatible" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/free5gc/free5gc/security/advisories/GHSA-qj55-47fp-p62j" + }, + { + "type": "FIX", + "url": "https://github.com/free5gc/ausf/commit/bfc4a10094dbacbd862baa4686829f3fcc06ce1e" + }, + { + "type": "FIX", + "url": "https://github.com/free5gc/ausf/pull/61" + }, + { + "type": "REPORT", + "url": "https://github.com/free5gc/free5gc/issues/1048" + }, + { + "type": "WEB", + "url": "https://github.com/free5gc/ausf/releases/tag/v1.4.5" + }, + { + "type": "WEB", + "url": "https://github.com/free5gc/free5gc/releases/tag/v4.2.2" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6161", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6162.json b/data/osv/GO-2026-6162.json new file mode 100644 index 0000000..7698b3a --- /dev/null +++ b/data/osv/GO-2026-6162.json
@@ -0,0 +1,56 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6162", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-54787", + "GHSA-wqqc-jjcq-vfxm" + ], + "summary": "sigstore-go fails to check signature timestamps against a signing key's validity period in github.com/sigstore/sigstore-go", + "details": "sigstore-go fails to check signature timestamps against a signing key's validity period in github.com/sigstore/sigstore-go", + "affected": [ + { + "package": { + "name": "github.com/sigstore/sigstore-go", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.2.1" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/sigstore/sigstore-go/security/advisories/GHSA-wqqc-jjcq-vfxm" + }, + { + "type": "FIX", + "url": "https://github.com/sigstore/sigstore-go/commit/4594ab4c779d08be1f4419803a8249188f35ed5f" + }, + { + "type": "FIX", + "url": "https://github.com/sigstore/sigstore-go/pull/642" + }, + { + "type": "WEB", + "url": "https://github.com/sigstore/sigstore-go/releases/tag/v1.2.1" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6162", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6164.json b/data/osv/GO-2026-6164.json new file mode 100644 index 0000000..dd0b710 --- /dev/null +++ b/data/osv/GO-2026-6164.json
@@ -0,0 +1,60 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6164", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-54910", + "GHSA-vvp7-h4fj-m28w" + ], + "summary": "FileBrowser Quantum's path traversal issue in subtitle handler allows any authenticated user to read arbitrary files in github.com/gtsteffaniak/filebrowser/backend", + "details": "FileBrowser Quantum's path traversal issue in subtitle handler allows any authenticated user to read arbitrary files in github.com/gtsteffaniak/filebrowser/backend", + "affected": [ + { + "package": { + "name": "github.com/gtsteffaniak/filebrowser/backend", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.0.0-20260608182036-f3f4bbe80cb5" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/gtsteffaniak/filebrowser/security/advisories/GHSA-vvp7-h4fj-m28w" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54910" + }, + { + "type": "WEB", + "url": "https://github.com/gtsteffaniak/filebrowser/commit/f3f4bbe80cb569d664174aea874d7bfa008c3b5a" + }, + { + "type": "WEB", + "url": "https://github.com/gtsteffaniak/filebrowser/pull/2524" + }, + { + "type": "WEB", + "url": "https://github.com/gtsteffaniak/filebrowser/releases/tag/v1.4.3-beta" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6164", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6192.json b/data/osv/GO-2026-6192.json new file mode 100644 index 0000000..ec769fd --- /dev/null +++ b/data/osv/GO-2026-6192.json
@@ -0,0 +1,108 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6192", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-65602", + "GHSA-42cj-m3vj-89wv" + ], + "summary": "Traefik CRD IngressRouteTCP ServersTransport Cross-Provider Namespace Bypass in github.com/traefik/traefik", + "details": "Traefik CRD IngressRouteTCP ServersTransport Cross-Provider Namespace Bypass in github.com/traefik/traefik", + "affected": [ + { + "package": { + "name": "github.com/traefik/traefik", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": {} + }, + { + "package": { + "name": "github.com/traefik/traefik/v2", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": {} + }, + { + "package": { + "name": "github.com/traefik/traefik/v3", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "3.6.0" + }, + { + "fixed": "3.6.23" + }, + { + "introduced": "3.7.0" + }, + { + "fixed": "3.7.7" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/traefik/traefik/security/advisories/GHSA-42cj-m3vj-89wv" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-65602" + }, + { + "type": "FIX", + "url": "https://github.com/traefik/traefik/commit/67501cbe7bc7774e26ecbd1c29af97f098e14b0b" + }, + { + "type": "FIX", + "url": "https://github.com/traefik/traefik/pull/13458" + }, + { + "type": "WEB", + "url": "https://github.com/traefik/traefik/releases/tag/v3.6.23" + }, + { + "type": "WEB", + "url": "https://github.com/traefik/traefik/releases/tag/v3.7.7" + }, + { + "type": "WEB", + "url": "https://www.vulncheck.com/advisories/traefik-before-ingressroutetcp-serverstransport-namespace-bypass" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6192", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6198.json b/data/osv/GO-2026-6198.json new file mode 100644 index 0000000..9b8f1b9 --- /dev/null +++ b/data/osv/GO-2026-6198.json
@@ -0,0 +1,71 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6198", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-65601", + "GHSA-qq9q-x9w4-chhj" + ], + "summary": "Traefik Gateway API HTTPRoute BackendRef ExtensionRef Namespace Confusion", + "details": "Traefik Gateway API HTTPRoute BackendRef ExtensionRef Namespace Confusion.\n\nNOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.\n\n(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)\n\nThe additional affected modules and versions are: github.com/traefik/traefik from v3.7.0 before v3.7.7.", + "affected": [ + { + "package": { + "name": "github.com/traefik/traefik", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "custom_ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "3.7.0" + }, + { + "fixed": "3.7.7" + } + ] + } + ] + } + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/traefik/traefik/security/advisories/GHSA-qq9q-x9w4-chhj" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-65601" + }, + { + "type": "WEB", + "url": "https://github.com/traefik/traefik/commit/655d6324ab4a1475892a958d4bae389720a67ea9" + }, + { + "type": "WEB", + "url": "https://github.com/traefik/traefik/pull/13462" + }, + { + "type": "WEB", + "url": "https://www.vulncheck.com/advisories/traefik-before-namespace-confusion-via-httproute-extensionref" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6198", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6201.json b/data/osv/GO-2026-6201.json new file mode 100644 index 0000000..dd04bc5 --- /dev/null +++ b/data/osv/GO-2026-6201.json
@@ -0,0 +1,123 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6201", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-71324", + "GHSA-3ccp-42pg-hgv6" + ], + "summary": "Traefik: Cross-user response poisoning via proxied CONNECT on Traefik's shared backend keep-alive pool in github.com/traefik/traefik", + "details": "Traefik: Cross-user response poisoning via proxied CONNECT on Traefik's shared backend keep-alive pool in github.com/traefik/traefik", + "affected": [ + { + "package": { + "name": "github.com/traefik/traefik", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": {} + }, + { + "package": { + "name": "github.com/traefik/traefik/v2", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "2.11.53" + } + ] + } + ], + "ecosystem_specific": {} + }, + { + "package": { + "name": "github.com/traefik/traefik/v3", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "3.6.24" + }, + { + "introduced": "3.7.0" + }, + { + "fixed": "3.7.9" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/traefik/traefik/security/advisories/GHSA-3ccp-42pg-hgv6" + }, + { + "type": "FIX", + "url": "https://github.com/traefik/traefik/commit/04d36f28e4eae7535e96a6351dd9f7bfb48a30e7" + }, + { + "type": "FIX", + "url": "https://github.com/traefik/traefik/commit/0807b6d5dd1da8b2f7f4076ea2392b5437bf2ab0" + }, + { + "type": "FIX", + "url": "https://github.com/traefik/traefik/commit/94a7508817d180f0ab2f1eae93df48d4ab19ecce" + }, + { + "type": "FIX", + "url": "https://github.com/traefik/traefik/pull/13542" + }, + { + "type": "FIX", + "url": "https://github.com/traefik/traefik/pull/13543" + }, + { + "type": "FIX", + "url": "https://github.com/traefik/traefik/pull/13556" + }, + { + "type": "WEB", + "url": "https://github.com/traefik/traefik/releases/tag/v2.11.53" + }, + { + "type": "WEB", + "url": "https://github.com/traefik/traefik/releases/tag/v3.6.24" + }, + { + "type": "WEB", + "url": "https://github.com/traefik/traefik/releases/tag/v3.7.9" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6201", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6202.json b/data/osv/GO-2026-6202.json new file mode 100644 index 0000000..4b69cc9 --- /dev/null +++ b/data/osv/GO-2026-6202.json
@@ -0,0 +1,111 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6202", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-54764", + "GHSA-3q9r-p662-5j8m" + ], + "summary": "Traefik: ForwardAuth middleware leaks X-Forwarded-Port spoofing via untrusted X-Forwarded-Proto when trustForwardHeader=false in github.com/traefik/traefik", + "details": "Traefik: ForwardAuth middleware leaks X-Forwarded-Port spoofing via untrusted X-Forwarded-Proto when trustForwardHeader=false in github.com/traefik/traefik", + "affected": [ + { + "package": { + "name": "github.com/traefik/traefik", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": {} + }, + { + "package": { + "name": "github.com/traefik/traefik/v2", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "2.11.51" + } + ] + } + ], + "ecosystem_specific": {} + }, + { + "package": { + "name": "github.com/traefik/traefik/v3", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "3.6.22" + }, + { + "introduced": "3.7.0" + }, + { + "fixed": "3.7.6" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/traefik/traefik/security/advisories/GHSA-3q9r-p662-5j8m" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54764" + }, + { + "type": "FIX", + "url": "https://github.com/traefik/traefik/commit/7ae92d8c2c10ac04ef5a03df0ed5019ce0f44b2d" + }, + { + "type": "FIX", + "url": "https://github.com/traefik/traefik/pull/13344" + }, + { + "type": "WEB", + "url": "https://github.com/traefik/traefik/releases/tag/v2.11.51" + }, + { + "type": "WEB", + "url": "https://github.com/traefik/traefik/releases/tag/v3.6.22" + }, + { + "type": "WEB", + "url": "https://github.com/traefik/traefik/releases/tag/v3.7.6" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6202", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6203.json b/data/osv/GO-2026-6203.json new file mode 100644 index 0000000..da47cb5 --- /dev/null +++ b/data/osv/GO-2026-6203.json
@@ -0,0 +1,103 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6203", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-71325", + "GHSA-62fc-8686-hfmq" + ], + "summary": "Traefik: `allowCrossNamespace=false` bypass via `@kubernetescrd` TraefikService backendRef in github.com/traefik/traefik", + "details": "Traefik: `allowCrossNamespace=false` bypass via `@kubernetescrd` TraefikService backendRef in github.com/traefik/traefik", + "affected": [ + { + "package": { + "name": "github.com/traefik/traefik", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": {} + }, + { + "package": { + "name": "github.com/traefik/traefik/v2", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "2.11.54" + } + ] + } + ], + "ecosystem_specific": {} + }, + { + "package": { + "name": "github.com/traefik/traefik/v3", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "3.0.0" + }, + { + "fixed": "3.6.25" + }, + { + "introduced": "3.7.0" + }, + { + "fixed": "3.7.10" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/traefik/traefik/security/advisories/GHSA-62fc-8686-hfmq" + }, + { + "type": "FIX", + "url": "https://github.com/traefik/traefik/commit/65ebf4b47fbdc33e3856803a5844a404e094d52d" + }, + { + "type": "WEB", + "url": "https://github.com/traefik/traefik/releases/tag/v2.11.54" + }, + { + "type": "WEB", + "url": "https://github.com/traefik/traefik/releases/tag/v3.6.25" + }, + { + "type": "WEB", + "url": "https://github.com/traefik/traefik/releases/tag/v3.7.10" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6203", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6204.json b/data/osv/GO-2026-6204.json new file mode 100644 index 0000000..ff2f520 --- /dev/null +++ b/data/osv/GO-2026-6204.json
@@ -0,0 +1,100 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6204", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-71326", + "GHSA-6765-c87h-8mrf" + ], + "summary": "Traefik: BasicAuth singleflight key collision allows authenticated identity spoofing in github.com/traefik/traefik", + "details": "Traefik: BasicAuth singleflight key collision allows authenticated identity spoofing in github.com/traefik/traefik", + "affected": [ + { + "package": { + "name": "github.com/traefik/traefik", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": {} + }, + { + "package": { + "name": "github.com/traefik/traefik/v2", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": {} + }, + { + "package": { + "name": "github.com/traefik/traefik/v3", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "3.6.11" + }, + { + "fixed": "3.6.25" + }, + { + "introduced": "3.7.0" + }, + { + "fixed": "3.7.10" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/traefik/traefik/security/advisories/GHSA-6765-c87h-8mrf" + }, + { + "type": "FIX", + "url": "https://github.com/traefik/traefik/commit/b5ace8eb5d6779980567f5e75efd2d9e08b7e350" + }, + { + "type": "FIX", + "url": "https://github.com/traefik/traefik/pull/13572" + }, + { + "type": "WEB", + "url": "https://github.com/traefik/traefik/releases/tag/v3.6.25" + }, + { + "type": "WEB", + "url": "https://github.com/traefik/traefik/releases/tag/v3.7.10" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6204", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6205.json b/data/osv/GO-2026-6205.json new file mode 100644 index 0000000..a89f6db --- /dev/null +++ b/data/osv/GO-2026-6205.json
@@ -0,0 +1,94 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6205", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-54765", + "GHSA-6p8f-p8j2-rqmv" + ], + "summary": "Traefik: Gateway HTTPRoute backendRef filters can leak backend context across routes sharing a Service:port in github.com/traefik/traefik", + "details": "Traefik: Gateway HTTPRoute backendRef filters can leak backend context across routes sharing a Service:port in github.com/traefik/traefik", + "affected": [ + { + "package": { + "name": "github.com/traefik/traefik", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": {} + }, + { + "package": { + "name": "github.com/traefik/traefik/v2", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": {} + }, + { + "package": { + "name": "github.com/traefik/traefik/v3", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "3.7.0" + }, + { + "fixed": "3.7.6" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/traefik/traefik/security/advisories/GHSA-6p8f-p8j2-rqmv" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54765" + }, + { + "type": "FIX", + "url": "https://github.com/traefik/traefik/commit/8aada7a7d52e4588a75386d8b86d270f6fe8d549" + }, + { + "type": "FIX", + "url": "https://github.com/traefik/traefik/pull/13367" + }, + { + "type": "WEB", + "url": "https://github.com/traefik/traefik/releases/tag/v3.7.6" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6205", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6207.json b/data/osv/GO-2026-6207.json new file mode 100644 index 0000000..bc07268 --- /dev/null +++ b/data/osv/GO-2026-6207.json
@@ -0,0 +1,90 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6207", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-67309", + "GHSA-8rxv-jg7p-wvg3" + ], + "summary": "Traefik: Kubernetes Ingress NGINX RewriteTarget Path Traversal Allows Route-Level Authentication Bypass in github.com/traefik/traefik", + "details": "Traefik: Kubernetes Ingress NGINX RewriteTarget Path Traversal Allows Route-Level Authentication Bypass in github.com/traefik/traefik", + "affected": [ + { + "package": { + "name": "github.com/traefik/traefik", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": {} + }, + { + "package": { + "name": "github.com/traefik/traefik/v2", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": {} + }, + { + "package": { + "name": "github.com/traefik/traefik/v3", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "3.7.0" + }, + { + "fixed": "3.7.8" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/traefik/traefik/security/advisories/GHSA-8rxv-jg7p-wvg3" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-67309" + }, + { + "type": "FIX", + "url": "https://github.com/traefik/traefik/commit/759515bec1b9f628b21ea8968ef63da853be5e29" + }, + { + "type": "WEB", + "url": "https://www.vulncheck.com/advisories/traefik-path-traversal-via-rewritetarget-authentication-bypass" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6207", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6208.json b/data/osv/GO-2026-6208.json new file mode 100644 index 0000000..a374c6d --- /dev/null +++ b/data/osv/GO-2026-6208.json
@@ -0,0 +1,111 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6208", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-65600", + "GHSA-cxjq-mrr5-89rv" + ], + "summary": "Traefik: Authentication Bypass via Path Traversal in ReplacePathRegex Middleware in github.com/traefik/traefik", + "details": "Traefik: Authentication Bypass via Path Traversal in ReplacePathRegex Middleware in github.com/traefik/traefik", + "affected": [ + { + "package": { + "name": "github.com/traefik/traefik", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": {} + }, + { + "package": { + "name": "github.com/traefik/traefik/v2", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "2.11.52" + } + ] + } + ], + "ecosystem_specific": {} + }, + { + "package": { + "name": "github.com/traefik/traefik/v3", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "3.6.23" + }, + { + "introduced": "3.7.0" + }, + { + "fixed": "3.7.7" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/traefik/traefik/security/advisories/GHSA-cxjq-mrr5-89rv" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-65600" + }, + { + "type": "FIX", + "url": "https://github.com/traefik/traefik/commit/3f10dd442479530560f010167cac2947676d9b29" + }, + { + "type": "WEB", + "url": "https://github.com/traefik/traefik/releases/tag/v2.11.52" + }, + { + "type": "WEB", + "url": "https://github.com/traefik/traefik/releases/tag/v3.6.23" + }, + { + "type": "WEB", + "url": "https://github.com/traefik/traefik/releases/tag/v3.7.7" + }, + { + "type": "WEB", + "url": "https://www.vulncheck.com/advisories/traefik-before-authentication-bypass-via-replacepathregex" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6208", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6209.json b/data/osv/GO-2026-6209.json new file mode 100644 index 0000000..edf42b1 --- /dev/null +++ b/data/osv/GO-2026-6209.json
@@ -0,0 +1,100 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6209", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-71327", + "GHSA-fgjj-px3w-67xx" + ], + "summary": "Traefik: Gateway API route identity collision allows cross-namespace backend hijacking in github.com/traefik/traefik", + "details": "Traefik: Gateway API route identity collision allows cross-namespace backend hijacking in github.com/traefik/traefik", + "affected": [ + { + "package": { + "name": "github.com/traefik/traefik", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": {} + }, + { + "package": { + "name": "github.com/traefik/traefik/v2", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": {} + }, + { + "package": { + "name": "github.com/traefik/traefik/v3", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "3.0.0" + }, + { + "fixed": "3.6.25" + }, + { + "introduced": "3.7.0" + }, + { + "fixed": "3.7.10" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/traefik/traefik/security/advisories/GHSA-fgjj-px3w-67xx" + }, + { + "type": "FIX", + "url": "https://github.com/traefik/traefik/commit/a764166656f0cd337f917ac76315c381cca844f9" + }, + { + "type": "FIX", + "url": "https://github.com/traefik/traefik/pull/13580" + }, + { + "type": "WEB", + "url": "https://github.com/traefik/traefik/releases/tag/v3.6.25" + }, + { + "type": "WEB", + "url": "https://github.com/traefik/traefik/releases/tag/v3.7.10" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6209", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6211.json b/data/osv/GO-2026-6211.json new file mode 100644 index 0000000..3b8b7bb --- /dev/null +++ b/data/osv/GO-2026-6211.json
@@ -0,0 +1,111 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6211", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-54763", + "GHSA-x677-9fxg-v5c5" + ], + "summary": "Traefik: Incomplete fix for CVE-2026-33433 + CVE-2026-39858 cross-cohort: headerField underscore-variant identity spoofing in BasicAuth / DigestAuth / ForwardAuth in github.com/traefik/traefik", + "details": "Traefik: Incomplete fix for CVE-2026-33433 + CVE-2026-39858 cross-cohort: headerField underscore-variant identity spoofing in BasicAuth / DigestAuth / ForwardAuth in github.com/traefik/traefik", + "affected": [ + { + "package": { + "name": "github.com/traefik/traefik", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": {} + }, + { + "package": { + "name": "github.com/traefik/traefik/v2", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "2.11.51" + } + ] + } + ], + "ecosystem_specific": {} + }, + { + "package": { + "name": "github.com/traefik/traefik/v3", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "3.6.22" + }, + { + "introduced": "3.7.0" + }, + { + "fixed": "3.7.6" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/traefik/traefik/security/advisories/GHSA-x677-9fxg-v5c5" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54763" + }, + { + "type": "FIX", + "url": "https://github.com/traefik/traefik/commit/108a5264473a2cbc8f12d6d691a3c6553cdf2c1b" + }, + { + "type": "FIX", + "url": "https://github.com/traefik/traefik/pull/13262" + }, + { + "type": "WEB", + "url": "https://github.com/traefik/traefik/releases/tag/v2.11.51" + }, + { + "type": "WEB", + "url": "https://github.com/traefik/traefik/releases/tag/v3.6.22" + }, + { + "type": "WEB", + "url": "https://github.com/traefik/traefik/releases/tag/v3.7.6" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6211", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6212.json b/data/osv/GO-2026-6212.json new file mode 100644 index 0000000..e7f7458 --- /dev/null +++ b/data/osv/GO-2026-6212.json
@@ -0,0 +1,49 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6212", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-39904", + "GHSA-42jc-v69j-g38f" + ], + "summary": "Gophish contains a denial of service vulnerability in github.com/gophish/gophish", + "details": "Gophish contains a denial of service vulnerability in github.com/gophish/gophish", + "affected": [ + { + "package": { + "name": "github.com/gophish/gophish", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-42jc-v69j-g38f" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39904" + }, + { + "type": "WEB", + "url": "https://www.vulncheck.com/advisories/gophish-denial-of-service-via-office-document-upload" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6212", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6219.json b/data/osv/GO-2026-6219.json new file mode 100644 index 0000000..d6f08ae --- /dev/null +++ b/data/osv/GO-2026-6219.json
@@ -0,0 +1,56 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6219", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-73080", + "GHSA-87fv-vqqr-m4jr" + ], + "summary": "SeaweedFS: Unauthenticated SSRF with response read-back via VolumeServer.FetchAndWriteNeedle in github.com/seaweedfs/seaweedfs", + "details": "SeaweedFS: Unauthenticated SSRF with response read-back via VolumeServer.FetchAndWriteNeedle in github.com/seaweedfs/seaweedfs", + "affected": [ + { + "package": { + "name": "github.com/seaweedfs/seaweedfs", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.0.0-20260512171120-69da20bdaec9" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/seaweedfs/seaweedfs/security/advisories/GHSA-87fv-vqqr-m4jr" + }, + { + "type": "FIX", + "url": "https://github.com/seaweedfs/seaweedfs/commit/69da20bdaec923e5a43d8aa71bf3c0a2051fc019" + }, + { + "type": "FIX", + "url": "https://github.com/seaweedfs/seaweedfs/pull/9441" + }, + { + "type": "WEB", + "url": "https://github.com/seaweedfs/seaweedfs/releases/tag/4.24" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6219", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6220.json b/data/osv/GO-2026-6220.json new file mode 100644 index 0000000..2f58f05 --- /dev/null +++ b/data/osv/GO-2026-6220.json
@@ -0,0 +1,48 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6220", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-48786", + "GHSA-88p2-jj8w-j8qg" + ], + "summary": "Fleet: Observer-class users can view team enroll secrets and credential-bearing configuration via target search endpoint in github.com/fleetdm/fleet", + "details": "Fleet: Observer-class users can view team enroll secrets and credential-bearing configuration via target search endpoint in github.com/fleetdm/fleet", + "affected": [ + { + "package": { + "name": "github.com/fleetdm/fleet/v4", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "4.87.0" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/fleetdm/fleet/security/advisories/GHSA-88p2-jj8w-j8qg" + }, + { + "type": "WEB", + "url": "https://github.com/fleetdm/fleet/releases/tag/fleet-v4.87.0" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6220", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6221.json b/data/osv/GO-2026-6221.json new file mode 100644 index 0000000..8838e3b --- /dev/null +++ b/data/osv/GO-2026-6221.json
@@ -0,0 +1,56 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6221", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-54917", + "GHSA-w62w-66v9-vvgv" + ], + "summary": "SeaweedFS: Path traversal in the S3 and Iceberg REST gateways allows cross-bucket access in github.com/seaweedfs/seaweedfs", + "details": "SeaweedFS: Path traversal in the S3 and Iceberg REST gateways allows cross-bucket access in github.com/seaweedfs/seaweedfs", + "affected": [ + { + "package": { + "name": "github.com/seaweedfs/seaweedfs", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.0.0-20260526080459-dd1b4287899e" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/seaweedfs/seaweedfs/security/advisories/GHSA-w62w-66v9-vvgv" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54917" + }, + { + "type": "FIX", + "url": "https://github.com/seaweedfs/seaweedfs/commit/dd1b4287899eed3dfd73c2f3b1de001996fda229" + }, + { + "type": "FIX", + "url": "https://github.com/seaweedfs/seaweedfs/pull/9687" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6221", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6223.json b/data/osv/GO-2026-6223.json new file mode 100644 index 0000000..0ac9380 --- /dev/null +++ b/data/osv/GO-2026-6223.json
@@ -0,0 +1,118 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6223", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-54526", + "GHSA-48p8-g2fx-3wwm" + ], + "summary": "Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows", + "details": "Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows", + "affected": [ + { + "package": { + "name": "github.com/argoproj/argo-workflows", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": {} + }, + { + "package": { + "name": "github.com/argoproj/argo-workflows/v2", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": {} + }, + { + "package": { + "name": "github.com/argoproj/argo-workflows/v3", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "3.7.15" + } + ] + } + ], + "ecosystem_specific": {} + }, + { + "package": { + "name": "github.com/argoproj/argo-workflows/v4", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "4.0.0" + }, + { + "fixed": "4.0.6" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/argoproj/argo-workflows/security/advisories/GHSA-48p8-g2fx-3wwm" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54526" + }, + { + "type": "FIX", + "url": "https://github.com/argoproj/argo-workflows/commit/277e9cef0ad16d7eaaab253573d0695951a65dbd" + }, + { + "type": "FIX", + "url": "https://github.com/argoproj/argo-workflows/commit/358cc3968c8f06f1be0967e41df191088db0b662" + }, + { + "type": "WEB", + "url": "https://github.com/argoproj/argo-workflows/releases/tag/v3.7.15" + }, + { + "type": "WEB", + "url": "https://github.com/argoproj/argo-workflows/releases/tag/v4.0.6" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6223", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6224.json b/data/osv/GO-2026-6224.json new file mode 100644 index 0000000..3b7774e --- /dev/null +++ b/data/osv/GO-2026-6224.json
@@ -0,0 +1,64 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6224", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-53469", + "GHSA-6xvf-9742-48w2" + ], + "summary": "Openshift Migration Advisor lacks proper authorization and filtering for its DELETE /api/v1/sources API in github.com/kubev2v/migration-planner", + "details": "Openshift Migration Advisor lacks proper authorization and filtering for its DELETE /api/v1/sources API in github.com/kubev2v/migration-planner", + "affected": [ + { + "package": { + "name": "github.com/kubev2v/migration-planner", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.13.5" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-6xvf-9742-48w2" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-53469" + }, + { + "type": "FIX", + "url": "https://github.com/kubev2v/migration-planner/commit/db4c7857bd8f8e04747a5ea0efca04b0235d6e4a" + }, + { + "type": "FIX", + "url": "https://github.com/kubev2v/migration-planner/pull/1227" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2026-53469" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2487065" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6224", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6227.json b/data/osv/GO-2026-6227.json new file mode 100644 index 0000000..97fd725 --- /dev/null +++ b/data/osv/GO-2026-6227.json
@@ -0,0 +1,52 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6227", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-35511", + "GHSA-29rf-f4vv-pvq6" + ], + "summary": "Authorizer: Zero-click account takeover via OAuth identity linking to unverified email accounts in github.com/authorizerdev/authorizer", + "details": "Authorizer: Zero-click account takeover via OAuth identity linking to unverified email accounts in github.com/authorizerdev/authorizer", + "affected": [ + { + "package": { + "name": "github.com/authorizerdev/authorizer", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.0.0-20260807033110-66fe488fd2a4" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/authorizerdev/authorizer/security/advisories/GHSA-29rf-f4vv-pvq6" + }, + { + "type": "FIX", + "url": "https://github.com/authorizerdev/authorizer/commit/66fe488fd2a4e7acf1e517334344d5e8f3ddd296" + }, + { + "type": "WEB", + "url": "https://github.com/authorizerdev/authorizer/releases/tag/2.4.0-rc.16" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6227", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6228.json b/data/osv/GO-2026-6228.json new file mode 100644 index 0000000..c55570a --- /dev/null +++ b/data/osv/GO-2026-6228.json
@@ -0,0 +1,64 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6228", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-53471", + "GHSA-2fqw-7c6r-2cq6" + ], + "summary": "Openshift Migration Advisor agent-API fails to validate JWT source_id claim, allowing cross-tenant data manipulation in github.com/kubev2v/migration-planner", + "details": "Openshift Migration Advisor agent-API fails to validate JWT source_id claim, allowing cross-tenant data manipulation in github.com/kubev2v/migration-planner", + "affected": [ + { + "package": { + "name": "github.com/kubev2v/migration-planner", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.13.5" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-2fqw-7c6r-2cq6" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-53471" + }, + { + "type": "FIX", + "url": "https://github.com/kubev2v/migration-planner/commit/fd21a239216f5eeec635d16c72be9c033bd5d1aa" + }, + { + "type": "FIX", + "url": "https://github.com/kubev2v/migration-planner/pull/1213" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2026-53471" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2487070" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6228", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6229.json b/data/osv/GO-2026-6229.json new file mode 100644 index 0000000..2a82ee3 --- /dev/null +++ b/data/osv/GO-2026-6229.json
@@ -0,0 +1,64 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6229", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-53470", + "GHSA-v5m8-5455-qw2x" + ], + "summary": "Openshift Migration Advisor: Broken access control in migration-planner image-url endpoint exposes other users' OVA images and agent JWTs in github.com/kubev2v/migration-planner", + "details": "Openshift Migration Advisor: Broken access control in migration-planner image-url endpoint exposes other users' OVA images and agent JWTs in github.com/kubev2v/migration-planner", + "affected": [ + { + "package": { + "name": "github.com/kubev2v/migration-planner", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.13.5" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-v5m8-5455-qw2x" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-53470" + }, + { + "type": "FIX", + "url": "https://github.com/kubev2v/migration-planner/commit/ec47a336a620f4a995f29c1c53e4e4bd70a26e00" + }, + { + "type": "FIX", + "url": "https://github.com/kubev2v/migration-planner/pull/1218" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2026-53470" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2487069" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6229", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6230.json b/data/osv/GO-2026-6230.json new file mode 100644 index 0000000..2f3875e --- /dev/null +++ b/data/osv/GO-2026-6230.json
@@ -0,0 +1,77 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6230", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-53657", + "GHSA-2j9v-p4xj-cjw2" + ], + "summary": "Lima: An arbitrary user in a QEMU VM could gain the root privilege in the VM via the guest agent socket in github.com/lima-vm/lima", + "details": "Lima: An arbitrary user in a QEMU VM could gain the root privilege in the VM via the guest agent socket in github.com/lima-vm/lima", + "affected": [ + { + "package": { + "name": "github.com/lima-vm/lima", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": {} + }, + { + "package": { + "name": "github.com/lima-vm/lima/v2", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "2.1.3" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/lima-vm/lima/security/advisories/GHSA-2j9v-p4xj-cjw2" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-53657" + }, + { + "type": "FIX", + "url": "https://github.com/lima-vm/lima/commit/8a45892378d22f40505c31a38f786a07701b6d50" + }, + { + "type": "FIX", + "url": "https://github.com/lima-vm/lima/commit/b08cae8a670cf916d5da11c48a6de76dabd89678" + }, + { + "type": "WEB", + "url": "https://github.com/lima-vm/lima/releases/tag/v2.1.3" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6230", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6231.json b/data/osv/GO-2026-6231.json new file mode 100644 index 0000000..cc2bdad --- /dev/null +++ b/data/osv/GO-2026-6231.json
@@ -0,0 +1,64 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6231", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-53476", + "GHSA-7j4w-x8x8-5mvg" + ], + "summary": "Assisted Migration Agent: Path traversal in gzipped tarball handling enables arbitrary file write and remote code execution in github.com/kubev2v/assisted-migration-agent", + "details": "Assisted Migration Agent: Path traversal in gzipped tarball handling enables arbitrary file write and remote code execution in github.com/kubev2v/assisted-migration-agent", + "affected": [ + { + "package": { + "name": "github.com/kubev2v/assisted-migration-agent", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.16.0" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-7j4w-x8x8-5mvg" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-53476" + }, + { + "type": "FIX", + "url": "https://github.com/kubev2v/assisted-migration-agent/commit/bcae0438ad8386321a300413d71c982a11b7b5b7" + }, + { + "type": "FIX", + "url": "https://github.com/kubev2v/assisted-migration-agent/pull/256" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2026-53476" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2487233" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6231", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6232.json b/data/osv/GO-2026-6232.json new file mode 100644 index 0000000..9c54796 --- /dev/null +++ b/data/osv/GO-2026-6232.json
@@ -0,0 +1,64 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6232", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-53475", + "GHSA-8g5p-jxp9-457c" + ], + "summary": "Assisted Migration Agent: Hardcoded insecure Transport Layer Security (TLS) connections during vCenter communication in github.com/kubev2v/assisted-migration-agent", + "details": "Assisted Migration Agent: Hardcoded insecure Transport Layer Security (TLS) connections during vCenter communication in github.com/kubev2v/assisted-migration-agent", + "affected": [ + { + "package": { + "name": "github.com/kubev2v/assisted-migration-agent", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.16.0" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-8g5p-jxp9-457c" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-53475" + }, + { + "type": "FIX", + "url": "https://github.com/kubev2v/assisted-migration-agent/commit/b940fec9f5032a0801e994054d30e81d64b2942a" + }, + { + "type": "FIX", + "url": "https://github.com/kubev2v/assisted-migration-agent/pull/268" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2026-53475" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2487232" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6232", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6233.json b/data/osv/GO-2026-6233.json new file mode 100644 index 0000000..d892cad --- /dev/null +++ b/data/osv/GO-2026-6233.json
@@ -0,0 +1,64 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6233", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-53474", + "GHSA-vf2h-7x3w-97fr" + ], + "summary": "Openshift Migration Advisor: Improper input sanitization allows specially crafted RVTools .xlsx files to include malicious SQL commands in github.com/kubev2v/migration-planner", + "details": "Openshift Migration Advisor: Improper input sanitization allows specially crafted RVTools .xlsx files to include malicious SQL commands in github.com/kubev2v/migration-planner", + "affected": [ + { + "package": { + "name": "github.com/kubev2v/migration-planner", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.13.5" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-vf2h-7x3w-97fr" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-53474" + }, + { + "type": "FIX", + "url": "https://github.com/kubev2v/migration-planner/commit/6110711b1b71bb0d15348b934a490a5932b41f83" + }, + { + "type": "FIX", + "url": "https://github.com/kubev2v/migration-planner/pull/1231" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2026-53474" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2487231" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6233", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6240.json b/data/osv/GO-2026-6240.json new file mode 100644 index 0000000..cc06c94 --- /dev/null +++ b/data/osv/GO-2026-6240.json
@@ -0,0 +1,56 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6240", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-64859", + "GHSA-6x2c-phff-wx57" + ], + "summary": "New API: User List API Leaks Root User Access Token Leading to Privilege Escalation in github.com/QuantumNous/new-api", + "details": "New API: User List API Leaks Root User Access Token Leading to Privilege Escalation in github.com/QuantumNous/new-api", + "affected": [ + { + "package": { + "name": "github.com/QuantumNous/new-api", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.0.0-rc.7" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/QuantumNous/new-api/security/advisories/GHSA-6x2c-phff-wx57" + }, + { + "type": "FIX", + "url": "https://github.com/QuantumNous/new-api/commit/0936e2504655a5cbf7bc3c388f6d3e2bb24916d3" + }, + { + "type": "FIX", + "url": "https://github.com/QuantumNous/new-api/pull/4929" + }, + { + "type": "WEB", + "url": "https://github.com/QuantumNous/new-api/releases/tag/v1.0.0-rc.7" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6240", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6241.json b/data/osv/GO-2026-6241.json new file mode 100644 index 0000000..d3090b1 --- /dev/null +++ b/data/osv/GO-2026-6241.json
@@ -0,0 +1,48 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6241", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-45099", + "GHSA-8394-6f8r-whxg" + ], + "summary": "Terragrunt: Arbitrary File Deletion via Malicious Module Manifest in github.com/gruntwork-io/terragrunt", + "details": "Terragrunt: Arbitrary File Deletion via Malicious Module Manifest in github.com/gruntwork-io/terragrunt", + "affected": [ + { + "package": { + "name": "github.com/gruntwork-io/terragrunt", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.0.4" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/gruntwork-io/terragrunt/security/advisories/GHSA-8394-6f8r-whxg" + }, + { + "type": "WEB", + "url": "https://github.com/gruntwork-io/terragrunt/releases/tag/v1.0.4" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6241", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6242.json b/data/osv/GO-2026-6242.json new file mode 100644 index 0000000..2e7c3b7 --- /dev/null +++ b/data/osv/GO-2026-6242.json
@@ -0,0 +1,56 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6242", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-71479", + "GHSA-8r8v-xf7q-rcpr" + ], + "summary": "New API: Integer overflow in quota billing yields negative charges (self-crediting) in github.com/QuantumNous/new-api", + "details": "New API: Integer overflow in quota billing yields negative charges (self-crediting) in github.com/QuantumNous/new-api", + "affected": [ + { + "package": { + "name": "github.com/QuantumNous/new-api", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.0.0-rc.18" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/QuantumNous/new-api/security/advisories/GHSA-8r8v-xf7q-rcpr" + }, + { + "type": "FIX", + "url": "https://github.com/QuantumNous/new-api/commit/c9943d37ad93477dd937fc4901cc3c4e0fd8aaab" + }, + { + "type": "FIX", + "url": "https://github.com/QuantumNous/new-api/commit/d0bd8aac742d1e160a5ca61743fe35f4fff880e8" + }, + { + "type": "WEB", + "url": "https://github.com/QuantumNous/new-api/releases/tag/v1.0.0-rc.18" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6242", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6243.json b/data/osv/GO-2026-6243.json new file mode 100644 index 0000000..4dc6af9 --- /dev/null +++ b/data/osv/GO-2026-6243.json
@@ -0,0 +1,52 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6243", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-64865", + "GHSA-j6gc-4893-qwmp" + ], + "summary": "New API: Redis user quota cache overwrite via PUT /api/user/self allows quota bypass in github.com/QuantumNous/new-api", + "details": "New API: Redis user quota cache overwrite via PUT /api/user/self allows quota bypass in github.com/QuantumNous/new-api", + "affected": [ + { + "package": { + "name": "github.com/QuantumNous/new-api", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.0.0-rc.16" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/QuantumNous/new-api/security/advisories/GHSA-j6gc-4893-qwmp" + }, + { + "type": "FIX", + "url": "https://github.com/QuantumNous/new-api/commit/dfc0d6324b40c1d6c2972e524409f933541bfb0f" + }, + { + "type": "WEB", + "url": "https://github.com/QuantumNous/new-api/releases/tag/v1.0.0-rc.16" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6243", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6244.json b/data/osv/GO-2026-6244.json new file mode 100644 index 0000000..70a1014 --- /dev/null +++ b/data/osv/GO-2026-6244.json
@@ -0,0 +1,67 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6244", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-64866", + "GHSA-p845-629j-rcj6" + ], + "summary": "New API: Admin can reset passkeys for same-level or higher-privileged users in github.com/QuantumNous/new-api", + "details": "New API: Admin can reset passkeys for same-level or higher-privileged users in github.com/QuantumNous/new-api.\n\nNOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.\n\n(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)\n\nThe additional affected modules and versions are: .", + "affected": [ + { + "package": { + "name": "github.com/QuantumNous/new-api", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.0.0-rc.7" + } + ] + } + ], + "ecosystem_specific": { + "custom_ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0.9.1.3" + } + ] + } + ] + } + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/QuantumNous/new-api/security/advisories/GHSA-p845-629j-rcj6" + }, + { + "type": "FIX", + "url": "https://github.com/QuantumNous/new-api/commit/0936e2504655a5cbf7bc3c388f6d3e2bb24916d3" + }, + { + "type": "FIX", + "url": "https://github.com/QuantumNous/new-api/pull/4929" + }, + { + "type": "WEB", + "url": "https://github.com/QuantumNous/new-api/releases/tag/v1.0.0-rc.7" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6244", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6245.json b/data/osv/GO-2026-6245.json new file mode 100644 index 0000000..040fcd2 --- /dev/null +++ b/data/osv/GO-2026-6245.json
@@ -0,0 +1,56 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6245", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-64868", + "GHSA-v828-m3pf-vq9q" + ], + "summary": "New API: Unauthenticated payment webhooks allow memory and disk DoS via unbounded body reads and full-body logging in github.com/QuantumNous/new-api", + "details": "New API: Unauthenticated payment webhooks allow memory and disk DoS via unbounded body reads and full-body logging in github.com/QuantumNous/new-api", + "affected": [ + { + "package": { + "name": "github.com/QuantumNous/new-api", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.0.0-rc.11" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/QuantumNous/new-api/security/advisories/GHSA-v828-m3pf-vq9q" + }, + { + "type": "FIX", + "url": "https://github.com/QuantumNous/new-api/commit/d2f7f9ee3adf3ef66798783a60d7bc712451c85c" + }, + { + "type": "FIX", + "url": "https://github.com/QuantumNous/new-api/pull/5244" + }, + { + "type": "WEB", + "url": "https://github.com/QuantumNous/new-api/releases/tag/v1.0.0-rc.11" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6245", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6246.json b/data/osv/GO-2026-6246.json new file mode 100644 index 0000000..667f35b --- /dev/null +++ b/data/osv/GO-2026-6246.json
@@ -0,0 +1,47 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6246", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "GHSA-fhgh-wq4q-r37x" + ], + "summary": "uniget CLI: Metadata signature verification only runs when UNIGET_IGNORE_METADATA_SIGNATURE is set in gitlab.com/uniget-org/cli", + "details": "uniget CLI: Metadata signature verification only runs when UNIGET_IGNORE_METADATA_SIGNATURE is set in gitlab.com/uniget-org/cli", + "affected": [ + { + "package": { + "name": "gitlab.com/uniget-org/cli", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0.27.4" + }, + { + "fixed": "0.28.9" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/uniget-org/cli/security/advisories/GHSA-fhgh-wq4q-r37x" + }, + { + "type": "WEB", + "url": "https://github.com/uniget-org/cli/releases/tag/v0.28.9" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6246", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6247.json b/data/osv/GO-2026-6247.json new file mode 100644 index 0000000..e963cc6 --- /dev/null +++ b/data/osv/GO-2026-6247.json
@@ -0,0 +1,52 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6247", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-55062", + "GHSA-m6jg-wr9m-cg2f" + ], + "summary": "uniget CLI has Path Traversal in Hook Files - Directory Escape Vulnerability in gitlab.com/uniget-org/cli", + "details": "uniget CLI has Path Traversal in Hook Files - Directory Escape Vulnerability in gitlab.com/uniget-org/cli", + "affected": [ + { + "package": { + "name": "gitlab.com/uniget-org/cli", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.27.6" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/uniget-org/cli/security/advisories/GHSA-m6jg-wr9m-cg2f" + }, + { + "type": "WEB", + "url": "https://github.com/uniget-org/cli/commit/7b4f18a9f00f0955f830c7ccf266ed0de5f9fd91" + }, + { + "type": "WEB", + "url": "https://github.com/uniget-org/cli/releases/tag/v0.27.6" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6247", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6248.json b/data/osv/GO-2026-6248.json new file mode 100644 index 0000000..0ad2c1f --- /dev/null +++ b/data/osv/GO-2026-6248.json
@@ -0,0 +1,52 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6248", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-55061", + "GHSA-qmcq-xw74-w667" + ], + "summary": "uniget CLI has an EDITOR Command Injection in gitlab.com/uniget-org/cli", + "details": "uniget CLI has an EDITOR Command Injection in gitlab.com/uniget-org/cli", + "affected": [ + { + "package": { + "name": "gitlab.com/uniget-org/cli", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.27.6" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/uniget-org/cli/security/advisories/GHSA-qmcq-xw74-w667" + }, + { + "type": "WEB", + "url": "https://github.com/uniget-org/cli/commit/7b4f18a9f00f0955f830c7ccf266ed0de5f9fd91" + }, + { + "type": "WEB", + "url": "https://github.com/uniget-org/cli/releases/tag/v0.27.6" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6248", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6249.json b/data/osv/GO-2026-6249.json new file mode 100644 index 0000000..08b46be --- /dev/null +++ b/data/osv/GO-2026-6249.json
@@ -0,0 +1,102 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6249", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-25700", + "GHSA-4gw2-vg4x-7p29" + ], + "summary": "Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer", + "details": "Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer.\n\nNOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.\n\n(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)\n\nThe additional affected modules and versions are: github.com/apache/answer before v2.0.1; github.com/apache/incubator-answer before v2.0.1.", + "affected": [ + { + "package": { + "name": "github.com/apache/answer", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "custom_ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "2.0.1" + } + ] + } + ] + } + }, + { + "package": { + "name": "github.com/apache/incubator-answer", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "custom_ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "2.0.1" + } + ] + } + ] + } + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-4gw2-vg4x-7p29" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25700" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2026/06/10/10" + }, + { + "type": "WEB", + "url": "https://github.com/apache/answer/releases/tag/v2.0.1" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/ftw52mlxknjm29vo1mnqovj53z2kh96y" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6249", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/reports/GO-2026-6097.yaml b/data/reports/GO-2026-6097.yaml new file mode 100644 index 0000000..ec14035 --- /dev/null +++ b/data/reports/GO-2026-6097.yaml
@@ -0,0 +1,28 @@ +id: GO-2026-6097 +modules: + - module: github.com/cloudreve/Cloudreve + vulnerable_at: 0.0.0-20201026073328-746aa3e8ef26 + - module: github.com/cloudreve/Cloudreve/v3 + unsupported_versions: + - last_affected: 3.0.0-20250225100611-da4e44b77af4 + vulnerable_at: 3.0.0-20250225100611-da4e44b77af4 + - module: github.com/cloudreve/Cloudreve/v4 + versions: + - fixed: 4.0.0-20260613023150-7968e50429ef +summary: |- + Cloudreve: Path Traversal in WOPI PUT_RELATIVE Allows Arbitrary File Creation in + Owner Account in github.com/cloudreve/Cloudreve +cves: + - CVE-2026-55495 +ghsas: + - GHSA-49h3-cwhj-4737 +references: + - advisory: https://github.com/cloudreve/cloudreve/security/advisories/GHSA-49h3-cwhj-4737 + - web: https://github.com/cloudreve/cloudreve/commit/7968e50429efab40ffa8f57fecdfbd5a73d23630 + - web: https://github.com/cloudreve/cloudreve/releases/tag/4.17.0 +notes: + - fix: 'github.com/cloudreve/Cloudreve/v4: could not add vulnerable_at: could not find tagged version between introduced and fixed' +source: + id: GHSA-49h3-cwhj-4737 + created: 2026-08-17T23:18:26.965715-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6098.yaml b/data/reports/GO-2026-6098.yaml new file mode 100644 index 0000000..fd6f084 --- /dev/null +++ b/data/reports/GO-2026-6098.yaml
@@ -0,0 +1,28 @@ +id: GO-2026-6098 +modules: + - module: github.com/cloudreve/Cloudreve + vulnerable_at: 0.0.0-20201026073328-746aa3e8ef26 + - module: github.com/cloudreve/Cloudreve/v3 + unsupported_versions: + - last_affected: 3.0.0-20250225100611-da4e44b77af4 + vulnerable_at: 3.0.0-20250225100611-da4e44b77af4 + - module: github.com/cloudreve/Cloudreve/v4 + versions: + - fixed: 4.0.0-20260613023921-7e1289d55279 +summary: |- + Cloudreve: Information Exposure in `GET /api/v4/user/search`: `SearchActive` + omits the active-status predicate, leaking inactive/banned account emails in github.com/cloudreve/Cloudreve +cves: + - CVE-2026-55496 +ghsas: + - GHSA-8r7f-r8hj-r3rv +references: + - advisory: https://github.com/cloudreve/cloudreve/security/advisories/GHSA-8r7f-r8hj-r3rv + - web: https://github.com/cloudreve/cloudreve/commit/7e1289d552794bdbeb551be78456115c87dcb3da + - web: https://github.com/cloudreve/cloudreve/releases/tag/4.17.0 +notes: + - fix: 'github.com/cloudreve/Cloudreve/v4: could not add vulnerable_at: could not find tagged version between introduced and fixed' +source: + id: GHSA-8r7f-r8hj-r3rv + created: 2026-08-17T23:18:20.930187-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6099.yaml b/data/reports/GO-2026-6099.yaml new file mode 100644 index 0000000..c32cec5 --- /dev/null +++ b/data/reports/GO-2026-6099.yaml
@@ -0,0 +1,20 @@ +id: GO-2026-6099 +modules: + - module: github.com/quic-go/webtransport-go + versions: + - fixed: 0.11.1 + vulnerable_at: 0.11.0 +summary: 'webtransport-go: Memory Exhaustion Attack due to Buffering of Unknown Capsules in github.com/quic-go/webtransport-go' +cves: + - CVE-2026-57497 +ghsas: + - GHSA-g35j-m5xg-vh3q +references: + - advisory: https://github.com/quic-go/webtransport-go/security/advisories/GHSA-g35j-m5xg-vh3q + - fix: https://github.com/quic-go/webtransport-go/commit/3aecd11736579530ff067651c30a543eb0b4b8c4 + - fix: https://github.com/quic-go/webtransport-go/pull/290 + - web: https://github.com/quic-go/webtransport-go/releases/tag/v0.11.1 +source: + id: GHSA-g35j-m5xg-vh3q + created: 2026-08-17T23:18:14.080237-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6100.yaml b/data/reports/GO-2026-6100.yaml new file mode 100644 index 0000000..9667122 --- /dev/null +++ b/data/reports/GO-2026-6100.yaml
@@ -0,0 +1,28 @@ +id: GO-2026-6100 +modules: + - module: github.com/cloudreve/Cloudreve + vulnerable_at: 0.0.0-20201026073328-746aa3e8ef26 + - module: github.com/cloudreve/Cloudreve/v3 + unsupported_versions: + - last_affected: 3.0.0-20250225100611-da4e44b77af4 + vulnerable_at: 3.0.0-20250225100611-da4e44b77af4 + - module: github.com/cloudreve/Cloudreve/v4 + versions: + - fixed: 4.0.0-20260613024411-3607f79bb44c +summary: |- + Cloudreve: Denial of Service - Image decompression / pixel bomb in thumbnail & + avatar decoding crashes the server in github.com/cloudreve/Cloudreve +cves: + - CVE-2026-55497 +ghsas: + - GHSA-g9j2-8w95-3vwv +references: + - advisory: https://github.com/cloudreve/cloudreve/security/advisories/GHSA-g9j2-8w95-3vwv + - web: https://github.com/cloudreve/cloudreve/commit/3607f79bb44c35d0be4fa8b6e24c0502b51415a9 + - web: https://github.com/cloudreve/cloudreve/releases/tag/4.17.0 +notes: + - fix: 'github.com/cloudreve/Cloudreve/v4: could not add vulnerable_at: could not find tagged version between introduced and fixed' +source: + id: GHSA-g9j2-8w95-3vwv + created: 2026-08-17T23:18:08.298747-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6101.yaml b/data/reports/GO-2026-6101.yaml new file mode 100644 index 0000000..a3b05d6 --- /dev/null +++ b/data/reports/GO-2026-6101.yaml
@@ -0,0 +1,25 @@ +id: GO-2026-6101 +modules: + - module: github.com/cloudreve/Cloudreve + vulnerable_at: 0.0.0-20201026073328-746aa3e8ef26 + - module: github.com/cloudreve/Cloudreve/v3 + unsupported_versions: + - last_affected: 3.0.0-20250225100611-da4e44b77af4 + vulnerable_at: 3.0.0-20250225100611-da4e44b77af4 + - module: github.com/cloudreve/Cloudreve/v4 + non_go_versions: + - fixed: 4.17.0 + vulnerable_at: 4.0.0-20260802015950-20c95ad73f3a +summary: Cloudreve OAuth Admin.Read scope can update OneDrive storage policy credentials in github.com/cloudreve/Cloudreve +cves: + - CVE-2026-55502 +ghsas: + - GHSA-hq88-5x99-x3gf +references: + - advisory: https://github.com/cloudreve/cloudreve/security/advisories/GHSA-hq88-5x99-x3gf + - web: https://github.com/cloudreve/cloudreve/commit/9e9fb43e7288924cca052e5fdbb70d5365ef1ede + - web: https://github.com/cloudreve/cloudreve/releases/tag/4.17.0 +source: + id: GHSA-hq88-5x99-x3gf + created: 2026-08-17T23:18:01.224462-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6102.yaml b/data/reports/GO-2026-6102.yaml new file mode 100644 index 0000000..862b9e1 --- /dev/null +++ b/data/reports/GO-2026-6102.yaml
@@ -0,0 +1,29 @@ +id: GO-2026-6102 +modules: + - module: github.com/cloudreve/Cloudreve + vulnerable_at: 0.0.0-20201026073328-746aa3e8ef26 + - module: github.com/cloudreve/Cloudreve/v3 + unsupported_versions: + - last_affected: 3.0.0-20250225100611-da4e44b77af4 + vulnerable_at: 3.0.0-20250225100611-da4e44b77af4 + - module: github.com/cloudreve/Cloudreve/v4 + versions: + - fixed: 4.0.0-20260613030215-0b00dd308f13 +summary: |- + Cloudreve: Broken Access Control in file event stream: a single-file share + recipient is subscribed to the owner's parent folder and receives activity + events for unshared siblings in github.com/cloudreve/Cloudreve +cves: + - CVE-2026-55499 +ghsas: + - GHSA-w8x7-h2px-xmq8 +references: + - advisory: https://github.com/cloudreve/cloudreve/security/advisories/GHSA-w8x7-h2px-xmq8 + - web: https://github.com/cloudreve/cloudreve/commit/0b00dd308f132d6e6e8476857ef79f4865600bbc + - web: https://github.com/cloudreve/cloudreve/releases/tag/4.17.0 +notes: + - fix: 'github.com/cloudreve/Cloudreve/v4: could not add vulnerable_at: could not find tagged version between introduced and fixed' +source: + id: GHSA-w8x7-h2px-xmq8 + created: 2026-08-17T23:17:55.023655-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6103.yaml b/data/reports/GO-2026-6103.yaml new file mode 100644 index 0000000..e230c82 --- /dev/null +++ b/data/reports/GO-2026-6103.yaml
@@ -0,0 +1,23 @@ +id: GO-2026-6103 +modules: + - module: github.com/fatedier/frp + versions: + - introduced: 0.53.0 + - fixed: 0.70.1 + vulnerable_at: 0.70.0 +summary: |- + frp: Unauthenticated Remote Denial of Service in the frp SSH Tunnel Gateway via + Integer Overflow in github.com/fatedier/frp +cves: + - CVE-2026-73564 +ghsas: + - GHSA-26gq-p25f-99cp +references: + - advisory: https://github.com/fatedier/frp/security/advisories/GHSA-26gq-p25f-99cp + - fix: https://github.com/fatedier/frp/commit/7dc7be930e2452ae93fd32f2a77f8c6fcd0b652b + - fix: https://github.com/fatedier/frp/pull/5428 + - web: https://github.com/fatedier/frp/releases/tag/v0.70.1 +source: + id: GHSA-26gq-p25f-99cp + created: 2026-08-17T23:17:48.174689-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6104.yaml b/data/reports/GO-2026-6104.yaml new file mode 100644 index 0000000..5839bf7 --- /dev/null +++ b/data/reports/GO-2026-6104.yaml
@@ -0,0 +1,27 @@ +id: GO-2026-6104 +modules: + - module: github.com/cloudreve/Cloudreve + vulnerable_at: 0.0.0-20201026073328-746aa3e8ef26 + - module: github.com/cloudreve/Cloudreve/v3 + unsupported_versions: + - last_affected: 3.0.0-20250225100611-da4e44b77af4 + vulnerable_at: 3.0.0-20250225100611-da4e44b77af4 + - module: github.com/cloudreve/Cloudreve/v4 + versions: + - fixed: 4.0.0-20260626022433-f3347130ac48 +summary: |- + Cloudreve WOPI view sessions can write files and WOPI access token secret is + ignored in github.com/cloudreve/Cloudreve +cves: + - CVE-2026-62323 +ghsas: + - GHSA-c3jm-gv5r-9wcp +references: + - advisory: https://github.com/cloudreve/cloudreve/security/advisories/GHSA-c3jm-gv5r-9wcp + - web: https://github.com/cloudreve/cloudreve/commit/f3347130ac48f2ff996af9ef66c97be2dda9cba9 +notes: + - fix: 'github.com/cloudreve/Cloudreve/v4: could not add vulnerable_at: could not find tagged version between introduced and fixed' +source: + id: GHSA-c3jm-gv5r-9wcp + created: 2026-08-17T23:17:42.338791-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6105.yaml b/data/reports/GO-2026-6105.yaml new file mode 100644 index 0000000..a817cc3 --- /dev/null +++ b/data/reports/GO-2026-6105.yaml
@@ -0,0 +1,22 @@ +id: GO-2026-6105 +modules: + - module: github.com/zxh326/kite + versions: + - introduced: 0.6.9 + - fixed: 0.14.1 + vulnerable_at: 0.14.0 +summary: |- + Kite Kubernetes proxy path traversal allows authenticated users to bypass RBAC + and read cluster-wide resources in github.com/zxh326/kite +ghsas: + - GHSA-c534-2w9c-x7fm +references: + - advisory: https://github.com/kite-org/kite/security/advisories/GHSA-c534-2w9c-x7fm + - web: https://github.com/kite-org/kite/commit/08116eed557f8d6982cc83af0b02991e0f3577d5 + - web: https://github.com/kite-org/kite/commit/69ad938937af8f375a2e183d1a331926ab851d98 + - web: https://github.com/kite-org/kite/pull/638 + - web: https://github.com/kite-org/kite/releases/tag/v0.14.1 +source: + id: GHSA-c534-2w9c-x7fm + created: 2026-08-17T23:17:37.54052-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6106.yaml b/data/reports/GO-2026-6106.yaml new file mode 100644 index 0000000..c2ce0fe --- /dev/null +++ b/data/reports/GO-2026-6106.yaml
@@ -0,0 +1,24 @@ +id: GO-2026-6106 +modules: + - module: github.com/cloudreve/Cloudreve + vulnerable_at: 0.0.0-20201026073328-746aa3e8ef26 + - module: github.com/cloudreve/Cloudreve/v3 + unsupported_versions: + - last_affected: 3.0.0-20250225100611-da4e44b77af4 + vulnerable_at: 3.0.0-20250225100611-da4e44b77af4 + - module: github.com/cloudreve/Cloudreve/v4 + versions: + - fixed: 4.0.0-20260626022735-332a9d800205 +summary: Cloudreve Admin.Read OAuth tokens can trigger server-side node test requests in github.com/cloudreve/Cloudreve +ghsas: + - GHSA-v6w6-358x-2433 +references: + - advisory: https://github.com/cloudreve/cloudreve/security/advisories/GHSA-v6w6-358x-2433 + - web: https://github.com/cloudreve/cloudreve/commit/332a9d800205082a2469e555fd66a63f18d9d5dc + - web: https://github.com/cloudreve/cloudreve/releases/tag/4.17.0 +notes: + - fix: 'github.com/cloudreve/Cloudreve/v4: could not add vulnerable_at: could not find tagged version between introduced and fixed' +source: + id: GHSA-v6w6-358x-2433 + created: 2026-08-17T23:17:25.60289-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6108.yaml b/data/reports/GO-2026-6108.yaml new file mode 100644 index 0000000..b8e33a1 --- /dev/null +++ b/data/reports/GO-2026-6108.yaml
@@ -0,0 +1,22 @@ +id: GO-2026-6108 +modules: + - module: github.com/jandedobbeleer/oh-my-posh + versions: + - fixed: 29.35.1+incompatible + vulnerable_at: 29.35.0+incompatible +summary: |- + Oh My Posh: Arbitrary command execution via template injection in the path + segment in github.com/jandedobbeleer/oh-my-posh +cves: + - CVE-2026-73505 +ghsas: + - GHSA-6xj8-qv9j-xcjq +references: + - advisory: https://github.com/JanDeDobbeleer/oh-my-posh/security/advisories/GHSA-6xj8-qv9j-xcjq + - web: https://github.com/JanDeDobbeleer/oh-my-posh/commit/88ddbe0b0a4dd13cc345996108c9869493f2c690 + - web: https://github.com/JanDeDobbeleer/oh-my-posh/releases/tag/v29.35.1 + - web: https://github.com/JanDeDobbeleer/oh-my-posh/releases/tag/v29.36.0 +source: + id: GHSA-6xj8-qv9j-xcjq + created: 2026-08-17T23:17:11.743102-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6109.yaml b/data/reports/GO-2026-6109.yaml new file mode 100644 index 0000000..1dc77be --- /dev/null +++ b/data/reports/GO-2026-6109.yaml
@@ -0,0 +1,21 @@ +id: GO-2026-6109 +modules: + - module: github.com/OpenListTeam/OpenList + vulnerable_at: 1.0.6 + - module: github.com/OpenListTeam/OpenList/v3 + vulnerable_at: 3.45.0 + - module: github.com/OpenListTeam/OpenList/v4 + versions: + - fixed: 4.2.4 + vulnerable_at: 4.2.3 +summary: 'OpenList: Arbitrary File Read via Path Prefix Confusion in Share Creation API in github.com/OpenListTeam/OpenList' +ghsas: + - GHSA-86cx-wwf4-phq4 +references: + - advisory: https://github.com/OpenListTeam/OpenList/security/advisories/GHSA-86cx-wwf4-phq4 + - fix: https://github.com/OpenListTeam/OpenList/commit/59bd3431408578f420895457554700cc9a52375a + - web: https://github.com/OpenListTeam/OpenList/releases/tag/v4.2.4 +source: + id: GHSA-86cx-wwf4-phq4 + created: 2026-08-17T23:17:09.17238-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6110.yaml b/data/reports/GO-2026-6110.yaml new file mode 100644 index 0000000..fd9466d --- /dev/null +++ b/data/reports/GO-2026-6110.yaml
@@ -0,0 +1,25 @@ +id: GO-2026-6110 +modules: + - module: github.com/OpenListTeam/OpenList + vulnerable_at: 1.0.6 + - module: github.com/OpenListTeam/OpenList/v3 + vulnerable_at: 3.45.0 + - module: github.com/OpenListTeam/OpenList/v4 + versions: + - fixed: 4.2.4 + vulnerable_at: 4.2.3 +summary: |- + OpenList: Authenticated users can rename files outside their base path via batch + rename `src_name` traversal in github.com/OpenListTeam/OpenList +cves: + - CVE-2026-73509 +ghsas: + - GHSA-95cv-r8x4-vh75 +references: + - advisory: https://github.com/OpenListTeam/OpenList/security/advisories/GHSA-95cv-r8x4-vh75 + - fix: https://github.com/OpenListTeam/OpenList/commit/651da18da4c647d96648d4bb64462baac1c37e04 + - web: https://github.com/OpenListTeam/OpenList/releases/tag/v4.2.4 +source: + id: GHSA-95cv-r8x4-vh75 + created: 2026-08-17T23:17:04.517246-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6111.yaml b/data/reports/GO-2026-6111.yaml new file mode 100644 index 0000000..5343285 --- /dev/null +++ b/data/reports/GO-2026-6111.yaml
@@ -0,0 +1,22 @@ +id: GO-2026-6111 +modules: + - module: github.com/jandedobbeleer/oh-my-posh + versions: + - fixed: 29.35.1+incompatible + vulnerable_at: 29.35.0+incompatible +summary: |- + Oh My Posh: Terminal escape sequence injection via unsanitized prompt segment + data in github.com/jandedobbeleer/oh-my-posh +cves: + - CVE-2026-73506 +ghsas: + - GHSA-fwjx-9p69-h25h +references: + - advisory: https://github.com/JanDeDobbeleer/oh-my-posh/security/advisories/GHSA-fwjx-9p69-h25h + - web: https://github.com/JanDeDobbeleer/oh-my-posh/commit/edcf3c88f3fb582e84358b385c49d33d04c04224 + - web: https://github.com/JanDeDobbeleer/oh-my-posh/releases/tag/v29.35.1 + - web: https://github.com/JanDeDobbeleer/oh-my-posh/releases/tag/v29.36.0 +source: + id: GHSA-fwjx-9p69-h25h + created: 2026-08-17T23:16:51.041323-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6113.yaml b/data/reports/GO-2026-6113.yaml new file mode 100644 index 0000000..415498b --- /dev/null +++ b/data/reports/GO-2026-6113.yaml
@@ -0,0 +1,24 @@ +id: GO-2026-6113 +modules: + - module: github.com/OpenListTeam/OpenList + vulnerable_at: 1.0.6 + - module: github.com/OpenListTeam/OpenList/v3 + vulnerable_at: 3.45.0 + - module: github.com/OpenListTeam/OpenList/v4 + versions: + - fixed: 4.2.4 + vulnerable_at: 4.2.3 +summary: |- + OpenList: Search metadata/count disclosure via Non-Separator-Aware Path Check in + Bleve Search in github.com/OpenListTeam/OpenList +ghsas: + - GHSA-p6ph-3jx2-3337 +references: + - advisory: https://github.com/OpenListTeam/OpenList/security/advisories/GHSA-p6ph-3jx2-3337 + - fix: https://github.com/OpenListTeam/OpenList/commit/59bd3431408578f420895457554700cc9a52375a + - fix: https://github.com/OpenListTeam/OpenList/commit/84ecda35aae2bd0020474086e6ddfd3aa2340679 + - web: https://github.com/OpenListTeam/OpenList/releases/tag/v4.2.4 +source: + id: GHSA-p6ph-3jx2-3337 + created: 2026-08-17T23:16:29.665396-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6117.yaml b/data/reports/GO-2026-6117.yaml new file mode 100644 index 0000000..22e4faf --- /dev/null +++ b/data/reports/GO-2026-6117.yaml
@@ -0,0 +1,21 @@ +id: GO-2026-6117 +modules: + - module: github.com/pocket-id/pocket-id/backend + versions: + - fixed: 0.0.0-20260419162744-978ac87deffe +summary: |- + Pocket ID has a reauthentication bypass via one-time access token login — + passkey step-up requirement defeated by JWT freshness check that accepts any + login method in github.com/pocket-id/pocket-id/backend +ghsas: + - GHSA-hp74-gm6m-2qm5 +references: + - advisory: https://github.com/pocket-id/pocket-id/security/advisories/GHSA-hp74-gm6m-2qm5 + - web: https://github.com/pocket-id/pocket-id/commit/978ac87deffec58beaccd15aead975e91b94c8a5 + - web: https://github.com/pocket-id/pocket-id/releases/tag/v2.6.0 +notes: + - fix: 'github.com/pocket-id/pocket-id/backend: could not add vulnerable_at: cannot auto-guess when fixed version is 0.0.0 pseudo-version' +source: + id: GHSA-hp74-gm6m-2qm5 + created: 2026-08-17T23:16:16.306787-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6118.yaml b/data/reports/GO-2026-6118.yaml new file mode 100644 index 0000000..b633478 --- /dev/null +++ b/data/reports/GO-2026-6118.yaml
@@ -0,0 +1,20 @@ +id: GO-2026-6118 +modules: + - module: github.com/github/github-mcp-server + versions: + - fixed: 1.1.0 + vulnerable_at: 1.0.5 +summary: GitHub MCP Server has Nil Pointer Dereference DoS in completion/complete Handler in github.com/github/github-mcp-server +cves: + - CVE-2026-47427 +ghsas: + - GHSA-w4q6-qw23-4rg7 +references: + - advisory: https://github.com/github/github-mcp-server/security/advisories/GHSA-w4q6-qw23-4rg7 + - fix: https://github.com/github/github-mcp-server/commit/c88d2ecdd3bb07f7bdd75296e3ee676febf14f58 + - fix: https://github.com/github/github-mcp-server/pull/2502 + - web: https://github.com/github/github-mcp-server/releases/tag/v1.1.0 +source: + id: GHSA-w4q6-qw23-4rg7 + created: 2026-08-17T23:16:10.477827-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6119.yaml b/data/reports/GO-2026-6119.yaml new file mode 100644 index 0000000..4bbce34 --- /dev/null +++ b/data/reports/GO-2026-6119.yaml
@@ -0,0 +1,23 @@ +id: GO-2026-6119 +modules: + - module: github.com/pocket-id/pocket-id/backend + versions: + - fixed: 0.0.0-20260419162744-978ac87deffe +summary: |- + Pocket ID: OIDC refresh token flow bypasses authorization revocation, account + disabling, and group restrictions in github.com/pocket-id/pocket-id/backend +cves: + - CVE-2026-43983 +ghsas: + - GHSA-w6p7-2fxx-4f44 +references: + - advisory: https://github.com/pocket-id/pocket-id/security/advisories/GHSA-w6p7-2fxx-4f44 + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-43983 + - web: https://github.com/pocket-id/pocket-id/commit/978ac87deffec58beaccd15aead975e91b94c8a5 + - web: https://github.com/pocket-id/pocket-id/releases/tag/v2.6.0 +notes: + - fix: 'github.com/pocket-id/pocket-id/backend: could not add vulnerable_at: cannot auto-guess when fixed version is 0.0.0 pseudo-version' +source: + id: GHSA-w6p7-2fxx-4f44 + created: 2026-08-17T23:16:04.13974-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6120.yaml b/data/reports/GO-2026-6120.yaml new file mode 100644 index 0000000..6888c45 --- /dev/null +++ b/data/reports/GO-2026-6120.yaml
@@ -0,0 +1,22 @@ +id: GO-2026-6120 +modules: + - module: github.com/pterodactyl/wings + versions: + - fixed: 1.12.2 + vulnerable_at: 1.12.1 +summary: |- + Pterodactyl's improper JWT scoping allows subuser to upload files when not + explicitly granted `file.create` permissions in github.com/pterodactyl/wings +cves: + - CVE-2026-54593 +ghsas: + - GHSA-8r6w-3qq5-4p4r +references: + - advisory: https://github.com/pterodactyl/panel/security/advisories/GHSA-8r6w-3qq5-4p4r + - fix: https://github.com/pterodactyl/wings/commit/d0ddc80844479302abdaf9654de3bacd511c0f5c + - web: https://github.com/pterodactyl/panel/commit/7ffcd636310bb72b54bac3280d2a15e727feded7 + - web: https://github.com/pterodactyl/panel/pull/5636 +source: + id: GHSA-8r6w-3qq5-4p4r + created: 2026-08-17T23:15:56.678772-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6121.yaml b/data/reports/GO-2026-6121.yaml new file mode 100644 index 0000000..d798b21 --- /dev/null +++ b/data/reports/GO-2026-6121.yaml
@@ -0,0 +1,21 @@ +id: GO-2026-6121 +modules: + - module: github.com/gopacket/gopacket + versions: + - fixed: 1.6.1 + vulnerable_at: 1.6.0 +summary: |- + GoPacket's Diameter AVP decoder: uint32 underflow on vendor header size leads to + unbounded ~4 GiB allocation (unauthenticated remote DoS) in github.com/gopacket/gopacket +cves: + - CVE-2026-54345 +ghsas: + - GHSA-6r28-9ppf-4hj5 +references: + - advisory: https://github.com/gopacket/gopacket/security/advisories/GHSA-6r28-9ppf-4hj5 + - fix: https://github.com/gopacket/gopacket/commit/145859d0eaee1a6f5925ffb93851c976449c3311 + - web: https://github.com/gopacket/gopacket/releases/tag/v1.6.1 +source: + id: GHSA-6r28-9ppf-4hj5 + created: 2026-08-17T23:15:51.121205-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6122.yaml b/data/reports/GO-2026-6122.yaml new file mode 100644 index 0000000..893a080 --- /dev/null +++ b/data/reports/GO-2026-6122.yaml
@@ -0,0 +1,22 @@ +id: GO-2026-6122 +modules: + - module: github.com/gopacket/gopacket + versions: + - fixed: 1.6.1 + vulnerable_at: 1.6.0 +summary: |- + GoPacket's sFlow ExtendedGatewayFlow decoder: unbounded attacker-controlled + allocation (104-byte UDP datagram -> up to 16 GiB make) -> unauthenticated + remote DoS in github.com/gopacket/gopacket +cves: + - CVE-2026-54332 +ghsas: + - GHSA-g6v3-7xmc-w563 +references: + - advisory: https://github.com/gopacket/gopacket/security/advisories/GHSA-g6v3-7xmc-w563 + - fix: https://github.com/gopacket/gopacket/commit/76119086f5936aacd7088bdf97d565501bb6c4cc + - web: https://github.com/gopacket/gopacket/releases/tag/v1.6.1 +source: + id: GHSA-g6v3-7xmc-w563 + created: 2026-08-17T23:15:45.068795-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6123.yaml b/data/reports/GO-2026-6123.yaml new file mode 100644 index 0000000..7fab783 --- /dev/null +++ b/data/reports/GO-2026-6123.yaml
@@ -0,0 +1,20 @@ +id: GO-2026-6123 +modules: + - module: github.com/azukaar/cosmos-server + versions: + - fixed: 0.22.19 + vulnerable_at: 0.22.18 +summary: |- + Cosmos-Server has an authentication bypass via forward-auth header smuggling on + Constellation tunnel in github.com/azukaar/cosmos-server +cves: + - CVE-2026-49446 +ghsas: + - GHSA-2rx5-2g7j-2659 +references: + - advisory: https://github.com/azukaar/Cosmos-Server/security/advisories/GHSA-2rx5-2g7j-2659 + - web: https://github.com/azukaar/Cosmos-Server/releases/tag/v0.22.19 +source: + id: GHSA-2rx5-2g7j-2659 + created: 2026-08-17T23:15:39.624708-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6124.yaml b/data/reports/GO-2026-6124.yaml new file mode 100644 index 0000000..58f7279 --- /dev/null +++ b/data/reports/GO-2026-6124.yaml
@@ -0,0 +1,22 @@ +id: GO-2026-6124 +modules: + - module: github.com/azukaar/cosmos-server + versions: + - introduced: 0.22.18 + - fixed: 0.22.19 + vulnerable_at: 0.22.18 +summary: |- + Cosmos-Server's constellation public-devices endpoint accepts arbitrary bearer + tokens in github.com/azukaar/cosmos-server +cves: + - CVE-2026-49447 +ghsas: + - GHSA-5fqm-cc34-fcf5 +references: + - advisory: https://github.com/azukaar/Cosmos-Server/security/advisories/GHSA-5fqm-cc34-fcf5 + - web: https://github.com/azukaar/Cosmos-Server/commit/59c561d686c8f9843b3e092b50f6346c481d8bbf + - web: https://github.com/azukaar/Cosmos-Server/releases/tag/v0.22.19 +source: + id: GHSA-5fqm-cc34-fcf5 + created: 2026-08-17T23:15:33.094295-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6125.yaml b/data/reports/GO-2026-6125.yaml new file mode 100644 index 0000000..72dce3b --- /dev/null +++ b/data/reports/GO-2026-6125.yaml
@@ -0,0 +1,24 @@ +id: GO-2026-6125 +modules: + - module: github.com/yoanbernabeu/grepai + unsupported_versions: + - last_affected: 0.35.0 + vulnerable_at: 0.35.0 +summary: grepai Uses a Broken or Risky Cryptographic Algorithm in github.com/yoanbernabeu/grepai +cves: + - CVE-2026-11479 +ghsas: + - GHSA-6h35-9p2w-3j3r +references: + - advisory: https://github.com/advisories/GHSA-6h35-9p2w-3j3r + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-11479 + - fix: https://github.com/yoanbernabeu/grepai/pull/248 + - report: https://github.com/yoanbernabeu/grepai/issues/247 + - web: https://vuldb.com/cve/CVE-2026-11479 + - web: https://vuldb.com/submit/833971 + - web: https://vuldb.com/vuln/369099 + - web: https://vuldb.com/vuln/369099/cti +source: + id: GHSA-6h35-9p2w-3j3r + created: 2026-08-17T23:15:24.759058-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6126.yaml b/data/reports/GO-2026-6126.yaml new file mode 100644 index 0000000..055d720 --- /dev/null +++ b/data/reports/GO-2026-6126.yaml
@@ -0,0 +1,28 @@ +id: GO-2026-6126 +modules: + - module: github.com/songquanpeng/one-api + non_go_versions: + - introduced: 0.1.6-alpha + unsupported_versions: + - last_affected: 0.6.11-preview.7 +summary: songquanpeng one-api has an issue that results in business logic errors +cves: + - CVE-2026-11465 +ghsas: + - GHSA-7v3v-cp44-vc8m +references: + - advisory: https://github.com/advisories/GHSA-7v3v-cp44-vc8m + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-11465 + - web: https://github.com/songquanpeng/one-api/issues/2397 + - web: https://github.com/songquanpeng/one-api/pull/2399 + - web: https://vuldb.com/cve/CVE-2026-11465 + - web: https://vuldb.com/submit/833320 + - web: https://vuldb.com/vuln/369085 + - web: https://vuldb.com/vuln/369085/cti +notes: + - lint: 'modules[0] "one-api": module one-api not known to proxy' + - fix: 'one-api: could not add vulnerable_at: module one-api not known to proxy' +source: + id: GHSA-7v3v-cp44-vc8m + created: 2026-08-17T23:15:17.954777-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6127.yaml b/data/reports/GO-2026-6127.yaml new file mode 100644 index 0000000..697aa7a --- /dev/null +++ b/data/reports/GO-2026-6127.yaml
@@ -0,0 +1,22 @@ +id: GO-2026-6127 +modules: + - module: github.com/fission/fission + versions: + - fixed: 1.25.0 + vulnerable_at: 1.25.0-rc1 +summary: |- + Fission: Zip Slip in pkg/utils/zip.go:Unarchive allows fetcher to write outside + the destination directory in github.com/fission/fission +cves: + - CVE-2026-50567 +ghsas: + - GHSA-q6vm-xqc9-v3ff +references: + - advisory: https://github.com/fission/fission/security/advisories/GHSA-q6vm-xqc9-v3ff + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-50567 + - fix: https://github.com/fission/fission/pull/3444 + - web: https://github.com/fission/fission/releases/tag/v1.25.0 +source: + id: GHSA-q6vm-xqc9-v3ff + created: 2026-08-17T23:15:11.564374-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6128.yaml b/data/reports/GO-2026-6128.yaml new file mode 100644 index 0000000..5c1ef9b --- /dev/null +++ b/data/reports/GO-2026-6128.yaml
@@ -0,0 +1,24 @@ +id: GO-2026-6128 +modules: + - module: github.com/yoanbernabeu/grepai + unsupported_versions: + - last_affected: 0.35.0 + vulnerable_at: 0.35.0 +summary: grepai Uses a Broken or Risky Cryptographic Algorithm in github.com/yoanbernabeu/grepai +cves: + - CVE-2026-11481 +ghsas: + - GHSA-q76h-p6jh-9rw3 +references: + - advisory: https://github.com/advisories/GHSA-q76h-p6jh-9rw3 + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-11481 + - fix: https://github.com/yoanbernabeu/grepai/pull/250 + - report: https://github.com/yoanbernabeu/grepai/issues/249 + - web: https://vuldb.com/cve/CVE-2026-11481 + - web: https://vuldb.com/submit/833997 + - web: https://vuldb.com/vuln/369101 + - web: https://vuldb.com/vuln/369101/cti +source: + id: GHSA-q76h-p6jh-9rw3 + created: 2026-08-17T23:15:05.385494-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6129.yaml b/data/reports/GO-2026-6129.yaml new file mode 100644 index 0000000..710b3d0 --- /dev/null +++ b/data/reports/GO-2026-6129.yaml
@@ -0,0 +1,24 @@ +id: GO-2026-6129 +modules: + - module: github.com/fission/fission + versions: + - fixed: 1.25.0 + vulnerable_at: 1.25.0-rc1 +summary: |- + Fission: Incomplete capability denylist in Environment/Function PodSpec + validation allows tenant-added CAP_SYS_TIME and cross-tenant node wall-clock + corruption in github.com/fission/fission +cves: + - CVE-2026-50570 +ghsas: + - GHSA-qf5v-m7p4-95rp +references: + - advisory: https://github.com/fission/fission/security/advisories/GHSA-qf5v-m7p4-95rp + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-50570 + - fix: https://github.com/fission/fission/commit/2569b42bfadbcb7d78b55a00a60f77937e522699 + - fix: https://github.com/fission/fission/pull/3465 + - web: https://github.com/fission/fission/releases/tag/v1.25.0 +source: + id: GHSA-qf5v-m7p4-95rp + created: 2026-08-17T23:14:57.025684-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6130.yaml b/data/reports/GO-2026-6130.yaml new file mode 100644 index 0000000..f8cbdb3 --- /dev/null +++ b/data/reports/GO-2026-6130.yaml
@@ -0,0 +1,25 @@ +id: GO-2026-6130 +modules: + - module: github.com/fission/fission + versions: + - fixed: 1.25.0 + vulnerable_at: 1.25.0-rc1 +summary: |- + Fission: SanitizeFilePath lexical HasPrefix bypass permits sibling-directory + escape in github.com/fission/fission +cves: + - CVE-2026-50568 +ghsas: + - GHSA-r5jh-q2mw-gcx4 +references: + - advisory: https://github.com/fission/fission/security/advisories/GHSA-r5jh-q2mw-gcx4 + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-50568 + - fix: https://github.com/fission/fission/commit/5aac6f0bcdf840e28f3f06c846ca7ae1866b3957 + - fix: https://github.com/fission/fission/commit/8298e33ea7457702f893eae11077987cf905edb4 + - fix: https://github.com/fission/fission/pull/3445 + - fix: https://github.com/fission/fission/pull/3446 + - web: https://github.com/fission/fission/releases/tag/v1.25.0 +source: + id: GHSA-r5jh-q2mw-gcx4 + created: 2026-08-17T23:14:48.118907-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6131.yaml b/data/reports/GO-2026-6131.yaml new file mode 100644 index 0000000..9987b8a --- /dev/null +++ b/data/reports/GO-2026-6131.yaml
@@ -0,0 +1,23 @@ +id: GO-2026-6131 +modules: + - module: github.com/fission/fission + versions: + - fixed: 1.25.0 + vulnerable_at: 1.25.0-rc1 +summary: |- + Fission: HTTPTrigger admission omits RelativeURL / Prefix validation; kubectl + apply bypasses CLI checks in github.com/fission/fission +cves: + - CVE-2026-50569 +ghsas: + - GHSA-vchh-r53j-8mpw +references: + - advisory: https://github.com/fission/fission/security/advisories/GHSA-vchh-r53j-8mpw + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-50569 + - fix: https://github.com/fission/fission/commit/0deed6bf3f26bc0f10e9130cd0d479b0b9f5f609 + - fix: https://github.com/fission/fission/pull/3464 + - web: https://github.com/fission/fission/releases/tag/v1.25.0 +source: + id: GHSA-vchh-r53j-8mpw + created: 2026-08-17T23:14:40.949478-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6132.yaml b/data/reports/GO-2026-6132.yaml new file mode 100644 index 0000000..76c3775 --- /dev/null +++ b/data/reports/GO-2026-6132.yaml
@@ -0,0 +1,24 @@ +id: GO-2026-6132 +modules: + - module: goshs.de/goshs + vulnerable_at: 1.1.4 + - module: goshs.de/goshs/v2 + versions: + - introduced: 2.1.3 + - fixed: 2.1.4 + vulnerable_at: 2.1.3 +summary: |- + goshs SFTP authentication bypass via empty password (incomplete fix of + CVE-2026-40884) in goshs.de/goshs +cves: + - CVE-2026-62325 +ghsas: + - GHSA-rjrw-mjq6-hpmm +references: + - advisory: https://github.com/goshs-labs/goshs/security/advisories/GHSA-rjrw-mjq6-hpmm + - web: https://github.com/goshs-labs/goshs/commit/32f4a0e1790a709f722d0f3b2341f139d003180a + - web: https://github.com/goshs-labs/goshs/releases/tag/v2.1.4 +source: + id: GHSA-rjrw-mjq6-hpmm + created: 2026-08-17T23:14:35.165853-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6133.yaml b/data/reports/GO-2026-6133.yaml new file mode 100644 index 0000000..8e5d946 --- /dev/null +++ b/data/reports/GO-2026-6133.yaml
@@ -0,0 +1,29 @@ +id: GO-2026-6133 +modules: + - module: github.com/patrickhener/goshs + unsupported_versions: + - last_affected: 1.1.4 + vulnerable_at: 1.1.4 + - module: goshs.de/goshs + unsupported_versions: + - last_affected: 1.1.4 + vulnerable_at: 1.1.4 + - module: goshs.de/goshs/v2 + versions: + - fixed: 2.1.1 + vulnerable_at: 2.1.0 +summary: |- + goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download + route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx) in github.com/patrickhener/goshs +cves: + - CVE-2026-54719 +ghsas: + - GHSA-rmxw-pq4x-3fvh +references: + - advisory: https://github.com/goshs-labs/goshs/security/advisories/GHSA-rmxw-pq4x-3fvh + - web: https://github.com/goshs-labs/goshs/commit/7cf911a26ace737e1a55b7dc073e307a25f7fd1d + - web: https://github.com/goshs-labs/goshs/releases/tag/v2.1.1 +source: + id: GHSA-rmxw-pq4x-3fvh + created: 2026-08-17T23:14:29.000423-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6134.yaml b/data/reports/GO-2026-6134.yaml new file mode 100644 index 0000000..f727156 --- /dev/null +++ b/data/reports/GO-2026-6134.yaml
@@ -0,0 +1,27 @@ +id: GO-2026-6134 +modules: + - module: github.com/patrickhener/goshs + unsupported_versions: + - last_affected: 1.1.4 + vulnerable_at: 1.1.4 + - module: goshs.de/goshs + unsupported_versions: + - last_affected: 1.1.4 + vulnerable_at: 1.1.4 + - module: goshs.de/goshs/v2 + versions: + - fixed: 2.1.5-0.20260727065949-f3ef599e4091 + vulnerable_at: 2.1.4 +summary: goshs has ACL Bypass & Path Traversal in github.com/patrickhener/goshs +cves: + - CVE-2026-66064 +ghsas: + - GHSA-964w-f6gj-5236 +references: + - advisory: https://github.com/goshs-labs/goshs/security/advisories/GHSA-964w-f6gj-5236 + - web: https://github.com/goshs-labs/goshs/commit/f3ef599e409151d1380866e47de8b1afb0bb54fa + - web: https://github.com/goshs-labs/goshs/pull/222 +source: + id: GHSA-964w-f6gj-5236 + created: 2026-08-17T23:14:23.260024-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6135.yaml b/data/reports/GO-2026-6135.yaml new file mode 100644 index 0000000..e1674de --- /dev/null +++ b/data/reports/GO-2026-6135.yaml
@@ -0,0 +1,19 @@ +id: GO-2026-6135 +modules: + - module: github.com/bablilayoub/openhole + versions: + - fixed: 0.1.2 + vulnerable_at: 0.1.1 +summary: openhole-server vulnerable to path traversal via URL-decoded request path in github.com/bablilayoub/openhole +cves: + - CVE-2026-54650 +ghsas: + - GHSA-fh2f-xfxc-q9cc +references: + - advisory: https://github.com/bablilayoub/openhole/security/advisories/GHSA-fh2f-xfxc-q9cc + - fix: https://github.com/bablilayoub/openhole/commit/a28c27adde2a7ed0c347b730c8707208c0f78ed3 + - web: https://github.com/bablilayoub/openhole/releases/tag/v0.1.2 +source: + id: GHSA-fh2f-xfxc-q9cc + created: 2026-08-17T23:14:16.764033-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6136.yaml b/data/reports/GO-2026-6136.yaml new file mode 100644 index 0000000..b3015ff --- /dev/null +++ b/data/reports/GO-2026-6136.yaml
@@ -0,0 +1,27 @@ +id: GO-2026-6136 +modules: + - module: github.com/patrickhener/goshs + unsupported_versions: + - last_affected: 1.1.4 + vulnerable_at: 1.1.4 + - module: goshs.de/goshs + unsupported_versions: + - last_affected: 1.1.4 + vulnerable_at: 1.1.4 + - module: goshs.de/goshs/v2 + versions: + - fixed: 2.1.4 + vulnerable_at: 2.1.3 +summary: goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite in github.com/patrickhener/goshs +cves: + - CVE-2026-64863 +ghsas: + - GHSA-hq33-8jgp-8qq3 +references: + - advisory: https://github.com/goshs-labs/goshs/security/advisories/GHSA-hq33-8jgp-8qq3 + - web: https://github.com/goshs-labs/goshs/commit/0444ac6b1a8176ddae70d940adf7a26b2e5a6c29 + - web: https://github.com/goshs-labs/goshs/releases/tag/v2.1.4 +source: + id: GHSA-hq33-8jgp-8qq3 + created: 2026-08-17T23:14:08.884721-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6137.yaml b/data/reports/GO-2026-6137.yaml new file mode 100644 index 0000000..5e8fa48 --- /dev/null +++ b/data/reports/GO-2026-6137.yaml
@@ -0,0 +1,26 @@ +id: GO-2026-6137 +modules: + - module: github.com/patrickhener/goshs + unsupported_versions: + - last_affected: 1.1.4 + vulnerable_at: 1.1.4 + - module: goshs.de/goshs + unsupported_versions: + - last_affected: 1.1.4 + vulnerable_at: 1.1.4 + - module: goshs.de/goshs/v2 + versions: + - fixed: 2.1.5-0.20260727065949-f3ef599e4091 + vulnerable_at: 2.1.4 +summary: goshs has a Path Traversal issue in github.com/patrickhener/goshs +cves: + - CVE-2026-66063 +ghsas: + - GHSA-wg2q-39h6-66x9 +references: + - advisory: https://github.com/goshs-labs/goshs/security/advisories/GHSA-wg2q-39h6-66x9 + - web: https://github.com/goshs-labs/goshs/commit/f3ef599e409151d1380866e47de8b1afb0bb54fa +source: + id: GHSA-wg2q-39h6-66x9 + created: 2026-08-17T23:14:02.630672-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6140.yaml b/data/reports/GO-2026-6140.yaml new file mode 100644 index 0000000..c9c3a55 --- /dev/null +++ b/data/reports/GO-2026-6140.yaml
@@ -0,0 +1,25 @@ +id: GO-2026-6140 +modules: + - module: github.com/weaviate/weaviate + versions: + - fixed: 1.38.0-rc.0 + vulnerable_at: 1.37.14 +summary: Weaviate has an Improper Authorization issue in github.com/weaviate/weaviate +cves: + - CVE-2026-11500 +ghsas: + - GHSA-jqpm-wf57-qx5c +references: + - advisory: https://github.com/advisories/GHSA-jqpm-wf57-qx5c + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-11500 + - fix: https://github.com/weaviate/weaviate/commit/40f2cc32279f0f8a51016c3c6870a2c0c808e6c0 + - report: https://github.com/weaviate/weaviate/issues/11392 + - web: https://github.com/weaviate/weaviate/releases/tag/v1.38.0-rc.0 + - web: https://vuldb.com/cve/CVE-2026-11500 + - web: https://vuldb.com/submit/835080 + - web: https://vuldb.com/vuln/369120 + - web: https://vuldb.com/vuln/369120/cti +source: + id: GHSA-jqpm-wf57-qx5c + created: 2026-08-17T23:13:00.970815-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6141.yaml b/data/reports/GO-2026-6141.yaml new file mode 100644 index 0000000..54b149e --- /dev/null +++ b/data/reports/GO-2026-6141.yaml
@@ -0,0 +1,32 @@ +id: GO-2026-6141 +modules: + - module: github.com/zitadel/zitadel + non_go_versions: + - introduced: 2.43.0 + vulnerable_at: 1.87.5 + - module: github.com/zitadel/zitadel + non_go_versions: + - introduced: 4.0.0 + vulnerable_at: 1.87.5 + - module: github.com/zitadel/zitadel + versions: + - fixed: 1.80.0-v2.20.0.20260608144108-ed09b3df7f43 + vulnerable_at: 1.80.0-v2.20 +summary: ZITADEL Users Can Self-Verify Email/Phone via API in github.com/zitadel/zitadel +cves: + - CVE-2026-54693 +ghsas: + - GHSA-jq8w-8q2f-ffm9 +references: + - advisory: https://github.com/zitadel/zitadel/security/advisories/GHSA-jq8w-8q2f-ffm9 + - fix: https://github.com/zitadel/zitadel/commit/90f310212d3a5075084a603bf61fed549c92956d + - fix: https://github.com/zitadel/zitadel/commit/a1748b2f0326ddf7be0de44b4f980ae2c07c0151 + - fix: https://github.com/zitadel/zitadel/commit/ed09b3df7f43e870423e4d8f2757e6894481604f + - web: https://github.com/zitadel/zitadel/releases/tag/v3.4.11 + - web: https://github.com/zitadel/zitadel/releases/tag/v4.15.1 +notes: + - fix: 'module merge error: could not merge versions of module github.com/zitadel/zitadel: introduced and fixed versions must alternate' +source: + id: GHSA-jq8w-8q2f-ffm9 + created: 2026-08-17T23:12:33.492258-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6142.yaml b/data/reports/GO-2026-6142.yaml new file mode 100644 index 0000000..a0ecfbc --- /dev/null +++ b/data/reports/GO-2026-6142.yaml
@@ -0,0 +1,22 @@ +id: GO-2026-6142 +modules: + - module: github.com/kube-logging/logging-operator + versions: + - fixed: 0.0.0-20260608145523-cf437d7f1e05 +summary: |- + Logging operator has Fluentd configuration injection that allows remote code + execution in github.com/kube-logging/logging-operator +cves: + - CVE-2026-54680 +ghsas: + - GHSA-mjqf-28ph-426h +references: + - advisory: https://github.com/kube-logging/logging-operator/security/advisories/GHSA-mjqf-28ph-426h + - fix: https://github.com/kube-logging/logging-operator/commit/cf437d7f1e056c78740bf5716ac8bdebcf002425 + - web: https://github.com/kube-logging/logging-operator/releases/tag/6.6.0 +notes: + - fix: 'github.com/kube-logging/logging-operator: could not add vulnerable_at: cannot auto-guess when fixed version is 0.0.0 pseudo-version' +source: + id: GHSA-mjqf-28ph-426h + created: 2026-08-17T23:12:27.008412-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6143.yaml b/data/reports/GO-2026-6143.yaml new file mode 100644 index 0000000..87887a9 --- /dev/null +++ b/data/reports/GO-2026-6143.yaml
@@ -0,0 +1,18 @@ +id: GO-2026-6143 +modules: + - module: github.com/tinfoil-factory/netfoil + versions: + - fixed: 0.4.0 + vulnerable_at: 0.3.1 +summary: 'netfoil: Incorrect block responses could lead to localhost traffic in github.com/tinfoil-factory/netfoil' +ghsas: + - GHSA-xvg2-cgv6-6h7v +references: + - advisory: https://github.com/tinfoil-factory/netfoil/security/advisories/GHSA-xvg2-cgv6-6h7v + - fix: https://github.com/tinfoil-factory/netfoil/commit/891d3513c77999a9deef9f23506807d9653ee448 + - fix: https://github.com/tinfoil-factory/netfoil/pull/33 + - web: https://github.com/tinfoil-factory/netfoil/releases/tag/v0.4.0 +source: + id: GHSA-xvg2-cgv6-6h7v + created: 2026-08-17T23:12:22.83954-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6144.yaml b/data/reports/GO-2026-6144.yaml new file mode 100644 index 0000000..07b90ad --- /dev/null +++ b/data/reports/GO-2026-6144.yaml
@@ -0,0 +1,23 @@ +id: GO-2026-6144 +modules: + - module: github.com/OliveTin/OliveTin + versions: + - fixed: 0.0.0-20260708085316-e421780c9885 +summary: |- + OliveTin: StartActionAndWait Endpoints Bypass `logs` Permission and Return + Action Output in github.com/OliveTin/OliveTin +cves: + - CVE-2026-67439 +ghsas: + - GHSA-jm28-2wcr-qf3h +references: + - advisory: https://github.com/OliveTin/OliveTin/security/advisories/GHSA-jm28-2wcr-qf3h + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-67439 + - fix: https://github.com/OliveTin/OliveTin/commit/e421780c9885aa5024d2f47b4ed4898f2f18eb90 + - web: https://github.com/OliveTin/OliveTin/releases/tag/3000.17.0 +notes: + - fix: 'github.com/OliveTin/OliveTin: could not add vulnerable_at: cannot auto-guess when fixed version is 0.0.0 pseudo-version' +source: + id: GHSA-jm28-2wcr-qf3h + created: 2026-08-17T23:12:17.788343-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6145.yaml b/data/reports/GO-2026-6145.yaml new file mode 100644 index 0000000..8b01979 --- /dev/null +++ b/data/reports/GO-2026-6145.yaml
@@ -0,0 +1,24 @@ +id: GO-2026-6145 +modules: + - module: github.com/OliveTin/OliveTin + versions: + - introduced: 0.0.0-20251025234746-ef5a67e7b8ea + - fixed: 0.0.0-20260708084548-995ff79736f2 +summary: |- + OliveTin OS Command Injection via Custom regex: Argument Type Bypassing Shell + Safety Check in github.com/OliveTin/OliveTin +cves: + - CVE-2026-67438 +ghsas: + - GHSA-xc5w-4v5w-7x65 +references: + - advisory: https://github.com/OliveTin/OliveTin/security/advisories/GHSA-xc5w-4v5w-7x65 + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-67438 + - fix: https://github.com/OliveTin/OliveTin/commit/995ff79736f2bccc364448a3ece84087b550b232 + - web: https://github.com/OliveTin/OliveTin/releases/tag/3000.17.0 +notes: + - fix: 'github.com/OliveTin/OliveTin: could not add vulnerable_at: cannot auto-guess when fixed version is 0.0.0 pseudo-version' +source: + id: GHSA-xc5w-4v5w-7x65 + created: 2026-08-17T23:12:11.689-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6146.yaml b/data/reports/GO-2026-6146.yaml new file mode 100644 index 0000000..ceafde6 --- /dev/null +++ b/data/reports/GO-2026-6146.yaml
@@ -0,0 +1,24 @@ +id: GO-2026-6146 +modules: + - module: github.com/OliveTin/OliveTin + versions: + - introduced: 0.0.0-20251024001301-45f9c18bc3ee + - fixed: 0.0.0-20260708075951-ec114e95d297 +summary: |- + OliveTin: Unauthenticated DoS via OAuth2 State Memory Exhaustion (Unbounded Map + Growth) in github.com/OliveTin/OliveTin +cves: + - CVE-2026-67437 +ghsas: + - GHSA-xpxj-f2fm-rqch +references: + - advisory: https://github.com/OliveTin/OliveTin/security/advisories/GHSA-xpxj-f2fm-rqch + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-67437 + - fix: https://github.com/OliveTin/OliveTin/commit/ec114e95d297b806c3ca0c37bc139b3c9c517b3f + - web: https://github.com/OliveTin/OliveTin/releases/tag/3000.17.0 +notes: + - fix: 'github.com/OliveTin/OliveTin: could not add vulnerable_at: cannot auto-guess when fixed version is 0.0.0 pseudo-version' +source: + id: GHSA-xpxj-f2fm-rqch + created: 2026-08-17T23:12:04.938847-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6147.yaml b/data/reports/GO-2026-6147.yaml new file mode 100644 index 0000000..3256104 --- /dev/null +++ b/data/reports/GO-2026-6147.yaml
@@ -0,0 +1,22 @@ +id: GO-2026-6147 +modules: + - module: github.com/apache/answer + versions: + - fixed: 1.7.2-0.20260525024654-2746bf5b455f + vulnerable_at: 1.7.1 +summary: |- + Apache Answer has an Improper Neutralization of Alternate XSS Syntax + vulnerability in github.com/apache/answer +cves: + - CVE-2026-25688 +ghsas: + - GHSA-hmr2-99jm-8x45 +references: + - advisory: https://github.com/advisories/GHSA-hmr2-99jm-8x45 + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-25688 + - web: http://www.openwall.com/lists/oss-security/2026/06/09/7 + - web: https://lists.apache.org/thread/x42joj43rqb38ms5q60f7bgq3qbo7t5q +source: + id: GHSA-hmr2-99jm-8x45 + created: 2026-08-17T23:11:58.629789-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6148.yaml b/data/reports/GO-2026-6148.yaml new file mode 100644 index 0000000..6a2cc6e --- /dev/null +++ b/data/reports/GO-2026-6148.yaml
@@ -0,0 +1,24 @@ +id: GO-2026-6148 +modules: + - module: github.com/apache/answer + versions: + - fixed: 1.7.2-0.20260206073245-92994b49976b + vulnerable_at: 1.7.1 +summary: |- + Apache Answer has an Exposure of Private Personal Information to an Unauthorized + Actor vulnerability in github.com/apache/answer +cves: + - CVE-2026-25699 +ghsas: + - GHSA-w754-5646-xq9j +references: + - advisory: https://github.com/advisories/GHSA-w754-5646-xq9j + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-25699 + - fix: https://github.com/apache/answer/commit/92994b49976b6206a7000d045d924ec4fd5be1be + - web: http://www.openwall.com/lists/oss-security/2026/06/09/6 + - web: https://github.com/apache/answer/releases/tag/v2.0.1 + - web: https://lists.apache.org/thread/c36k4hzwhncqo0qfn5fg57f1gkjhyfv8 +source: + id: GHSA-w754-5646-xq9j + created: 2026-08-17T23:11:51.72613-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6151.yaml b/data/reports/GO-2026-6151.yaml new file mode 100644 index 0000000..bd19af9 --- /dev/null +++ b/data/reports/GO-2026-6151.yaml
@@ -0,0 +1,22 @@ +id: GO-2026-6151 +modules: + - module: github.com/apache/answer + versions: + - fixed: 1.7.2-0.20260509080709-d1a4092c61cc + vulnerable_at: 1.7.1 +summary: Apache Answer vulnerable to Cross-site Scripting in github.com/apache/answer +cves: + - CVE-2026-34033 +ghsas: + - GHSA-6qwm-5fm9-cvjx +references: + - advisory: https://github.com/advisories/GHSA-6qwm-5fm9-cvjx + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-34033 + - fix: https://github.com/apache/answer/commit/d1a4092c61ccd41988d1033fce47eb513adb433e + - web: http://www.openwall.com/lists/oss-security/2026/06/09/3 + - web: https://github.com/apache/answer/releases/tag/v2.0.1 + - web: https://lists.apache.org/thread/wrfd9blbfotfg479jr8vlwfx6pwr9sgj +source: + id: GHSA-6qwm-5fm9-cvjx + created: 2026-08-17T23:11:45.232955-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6152.yaml b/data/reports/GO-2026-6152.yaml new file mode 100644 index 0000000..f2ac6f3 --- /dev/null +++ b/data/reports/GO-2026-6152.yaml
@@ -0,0 +1,24 @@ +id: GO-2026-6152 +modules: + - module: github.com/apache/answer + versions: + - fixed: 1.7.2-0.20260509071350-11c80384f13a + vulnerable_at: 1.7.1 +summary: |- + Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor + vulnerability in github.com/apache/answer +cves: + - CVE-2026-34905 +ghsas: + - GHSA-85r2-pvg8-89r9 +references: + - advisory: https://github.com/advisories/GHSA-85r2-pvg8-89r9 + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-34905 + - fix: https://github.com/apache/answer/commit/11c80384f13a27e27c871c05bb353489d1363ee2 + - web: http://www.openwall.com/lists/oss-security/2026/06/09/2 + - web: https://github.com/apache/answer/releases/tag/v2.0.1 + - web: https://lists.apache.org/thread/khxoft96sptr2kh0cpzgw7f6qwv0ltcf +source: + id: GHSA-85r2-pvg8-89r9 + created: 2026-08-17T23:11:37.921058-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6153.yaml b/data/reports/GO-2026-6153.yaml new file mode 100644 index 0000000..8f420ee --- /dev/null +++ b/data/reports/GO-2026-6153.yaml
@@ -0,0 +1,24 @@ +id: GO-2026-6153 +modules: + - module: github.com/apache/answer + versions: + - fixed: 1.7.2-0.20260325113131-cfc3e54f30cc + vulnerable_at: 1.7.1 +summary: |- + Apache Answer has an Unrestricted Upload of File with Dangerous Type + vulnerability in github.com/apache/answer +cves: + - CVE-2026-33582 +ghsas: + - GHSA-v553-g2w6-295p +references: + - advisory: https://github.com/advisories/GHSA-v553-g2w6-295p + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-33582 + - fix: https://github.com/apache/answer/commit/cfc3e54f30cc5e01afb7110ecc1da9152d0a3a41 + - web: http://www.openwall.com/lists/oss-security/2026/06/09/5 + - web: https://github.com/apache/answer/releases/tag/v2.0.1 + - web: https://lists.apache.org/thread/3sgpx4cwsgpnt66xv3cqvtc8z4st1kbq +source: + id: GHSA-v553-g2w6-295p + created: 2026-08-17T23:11:30.9786-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6154.yaml b/data/reports/GO-2026-6154.yaml new file mode 100644 index 0000000..a402cf5 --- /dev/null +++ b/data/reports/GO-2026-6154.yaml
@@ -0,0 +1,24 @@ +id: GO-2026-6154 +modules: + - module: github.com/apache/answer + versions: + - fixed: 1.7.2-0.20260511040518-11091244f64e + vulnerable_at: 1.7.1 +summary: |- + Apache Answer has an Unrestricted Upload of File with Dangerous Type + vulnerability in github.com/apache/answer +cves: + - CVE-2026-34031 +ghsas: + - GHSA-x4f6-mqg6-28xx +references: + - advisory: https://github.com/advisories/GHSA-x4f6-mqg6-28xx + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-34031 + - fix: https://github.com/apache/answer/commit/11091244f64e5a7e472edcd477c1ff4124eca7c3 + - web: http://www.openwall.com/lists/oss-security/2026/06/09/4 + - web: https://github.com/apache/answer/releases/tag/v2.0.1 + - web: https://lists.apache.org/thread/rwtxy39t54to9kv3dqtbjsbdpyk4jkd2 +source: + id: GHSA-x4f6-mqg6-28xx + created: 2026-08-17T23:11:22.831724-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6155.yaml b/data/reports/GO-2026-6155.yaml new file mode 100644 index 0000000..69620e3 --- /dev/null +++ b/data/reports/GO-2026-6155.yaml
@@ -0,0 +1,21 @@ +id: GO-2026-6155 +modules: + - module: github.com/projectcapsule/capsule + versions: + - fixed: 0.13.8 + vulnerable_at: 0.13.7 +summary: |- + Capsule: CapsuleConfiguration NodeMetadata regex fields lack webhook validation, + allowing MustCompile panic on all Node admission requests in github.com/projectcapsule/capsule +cves: + - CVE-2026-65834 +ghsas: + - GHSA-68cj-mvg9-rgm2 +references: + - advisory: https://github.com/projectcapsule/capsule/security/advisories/GHSA-68cj-mvg9-rgm2 + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-65834 + - web: https://github.com/projectcapsule/capsule/releases/tag/v0.13.8 +source: + id: GHSA-68cj-mvg9-rgm2 + created: 2026-08-17T23:11:17.580316-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6156.yaml b/data/reports/GO-2026-6156.yaml new file mode 100644 index 0000000..fd39e9e --- /dev/null +++ b/data/reports/GO-2026-6156.yaml
@@ -0,0 +1,21 @@ +id: GO-2026-6156 +modules: + - module: github.com/pterodactyl/wings + versions: + - fixed: 1.13.0 + vulnerable_at: 1.12.3 +summary: |- + Wings: Maliciously crafted packet during SFTP connection handshake causes denial + of service in github.com/pterodactyl/wings +cves: + - CVE-2026-52856 +ghsas: + - GHSA-ghrq-5wpp-hxx5 +references: + - advisory: https://github.com/pterodactyl/wings/security/advisories/GHSA-ghrq-5wpp-hxx5 + - fix: https://github.com/pterodactyl/wings/commit/8e49c7c0eda815d3ada171831876a1c14c493026 + - web: https://github.com/pterodactyl/wings/releases/tag/v1.13.0 +source: + id: GHSA-ghrq-5wpp-hxx5 + created: 2026-08-17T23:11:12.006375-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6157.yaml b/data/reports/GO-2026-6157.yaml new file mode 100644 index 0000000..48748c0 --- /dev/null +++ b/data/reports/GO-2026-6157.yaml
@@ -0,0 +1,23 @@ +id: GO-2026-6157 +modules: + - module: github.com/projectcapsule/capsule + versions: + - introduced: 0.13.0 + - fixed: 0.13.8 + vulnerable_at: 0.13.7 +summary: |- + Capsule has an incomplete fix of CVE-2026-22872: TenantResource RawItems and + Generators still allow cluster-scoped resource creation (cross-tenant privilege + escalation) in github.com/projectcapsule/capsule +cves: + - CVE-2026-65835 +ghsas: + - GHSA-jr6p-8pjj-mfx6 +references: + - advisory: https://github.com/projectcapsule/capsule/security/advisories/GHSA-jr6p-8pjj-mfx6 + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-65835 + - web: https://github.com/projectcapsule/capsule/releases/tag/v0.13.8 +source: + id: GHSA-jr6p-8pjj-mfx6 + created: 2026-08-17T23:11:05.690353-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6158.yaml b/data/reports/GO-2026-6158.yaml new file mode 100644 index 0000000..4d70060 --- /dev/null +++ b/data/reports/GO-2026-6158.yaml
@@ -0,0 +1,21 @@ +id: GO-2026-6158 +modules: + - module: github.com/pterodactyl/wings + versions: + - fixed: 1.12.3 + vulnerable_at: 1.12.2 +summary: |- + Wings exposes node configuration secrets through egg configuration-file + templating in github.com/pterodactyl/wings +cves: + - CVE-2026-52855 +ghsas: + - GHSA-pfvc-3p5h-x7h6 +references: + - advisory: https://github.com/pterodactyl/wings/security/advisories/GHSA-pfvc-3p5h-x7h6 + - fix: https://github.com/pterodactyl/wings/commit/eb65e27ae077a63e38518c490768486af1cd86a9 + - web: https://github.com/pterodactyl/wings/releases/tag/v1.12.3 +source: + id: GHSA-pfvc-3p5h-x7h6 + created: 2026-08-17T23:10:59.749943-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6159.yaml b/data/reports/GO-2026-6159.yaml new file mode 100644 index 0000000..55eed0c --- /dev/null +++ b/data/reports/GO-2026-6159.yaml
@@ -0,0 +1,21 @@ +id: GO-2026-6159 +modules: + - module: github.com/pterodactyl/wings + versions: + - fixed: 1.13.0 + vulnerable_at: 1.12.3 +summary: |- + Wings: Maliciously or erroneously created parsed config files can cause wings + process to OOM in github.com/pterodactyl/wings +cves: + - CVE-2026-52857 +ghsas: + - GHSA-q6hh-gp44-4hcm +references: + - advisory: https://github.com/pterodactyl/wings/security/advisories/GHSA-q6hh-gp44-4hcm + - fix: https://github.com/pterodactyl/wings/commit/5f71f65711b6b9e6f913bec94a7b36d9a5eaae49 + - web: https://github.com/pterodactyl/wings/releases/tag/v1.13.0 +source: + id: GHSA-q6hh-gp44-4hcm + created: 2026-08-17T23:10:53.637066-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6160.yaml b/data/reports/GO-2026-6160.yaml new file mode 100644 index 0000000..7d9bed4 --- /dev/null +++ b/data/reports/GO-2026-6160.yaml
@@ -0,0 +1,22 @@ +id: GO-2026-6160 +modules: + - module: github.com/bank-vaults/vault-secrets-webhook + versions: + - fixed: 1.23.1 + vulnerable_at: 1.23.0 +summary: |- + vault-addr annotation SSRF -- webhook makes outbound HTTP call to attacker URL + during admission; vault-serviceaccount enables cluster-wide SA token theft via + TokenRequest API in github.com/bank-vaults/vault-secrets-webhook +cves: + - CVE-2026-54725 +ghsas: + - GHSA-r2v3-8gwf-7ghm +references: + - advisory: https://github.com/bank-vaults/vault-secrets-webhook/security/advisories/GHSA-r2v3-8gwf-7ghm + - fix: https://github.com/bank-vaults/vault-secrets-webhook/commit/76db45976fee0f54cafd94dffa425e6b542f65a0 + - web: https://github.com/bank-vaults/vault-secrets-webhook/releases/tag/v1.23.1 +source: + id: GHSA-r2v3-8gwf-7ghm + created: 2026-08-17T23:10:47.293689-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6161.yaml b/data/reports/GO-2026-6161.yaml new file mode 100644 index 0000000..3ddcf8d --- /dev/null +++ b/data/reports/GO-2026-6161.yaml
@@ -0,0 +1,28 @@ +id: GO-2026-6161 +modules: + - module: github.com/free5gc/ausf + versions: + - fixed: 1.4.5 + vulnerable_at: 1.4.4 + - module: github.com/free5gc/free5gc + versions: + - fixed: 4.2.2+incompatible + vulnerable_at: 4.2.1+incompatible +summary: |- + free5GC AUSF: null byte injection in supiOrSuci causes HTTP 500 internal service + failure in github.com/free5gc/ausf +cves: + - CVE-2026-53551 +ghsas: + - GHSA-qj55-47fp-p62j +references: + - advisory: https://github.com/free5gc/free5gc/security/advisories/GHSA-qj55-47fp-p62j + - fix: https://github.com/free5gc/ausf/commit/bfc4a10094dbacbd862baa4686829f3fcc06ce1e + - fix: https://github.com/free5gc/ausf/pull/61 + - report: https://github.com/free5gc/free5gc/issues/1048 + - web: https://github.com/free5gc/ausf/releases/tag/v1.4.5 + - web: https://github.com/free5gc/free5gc/releases/tag/v4.2.2 +source: + id: GHSA-qj55-47fp-p62j + created: 2026-08-17T23:10:34.342251-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6162.yaml b/data/reports/GO-2026-6162.yaml new file mode 100644 index 0000000..b550780 --- /dev/null +++ b/data/reports/GO-2026-6162.yaml
@@ -0,0 +1,22 @@ +id: GO-2026-6162 +modules: + - module: github.com/sigstore/sigstore-go + versions: + - fixed: 1.2.1 + vulnerable_at: 1.2.0 +summary: |- + sigstore-go fails to check signature timestamps against a signing key's validity + period in github.com/sigstore/sigstore-go +cves: + - CVE-2026-54787 +ghsas: + - GHSA-wqqc-jjcq-vfxm +references: + - advisory: https://github.com/sigstore/sigstore-go/security/advisories/GHSA-wqqc-jjcq-vfxm + - fix: https://github.com/sigstore/sigstore-go/commit/4594ab4c779d08be1f4419803a8249188f35ed5f + - fix: https://github.com/sigstore/sigstore-go/pull/642 + - web: https://github.com/sigstore/sigstore-go/releases/tag/v1.2.1 +source: + id: GHSA-wqqc-jjcq-vfxm + created: 2026-08-17T23:10:26.906566-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6164.yaml b/data/reports/GO-2026-6164.yaml new file mode 100644 index 0000000..f947e1f --- /dev/null +++ b/data/reports/GO-2026-6164.yaml
@@ -0,0 +1,24 @@ +id: GO-2026-6164 +modules: + - module: github.com/gtsteffaniak/filebrowser/backend + versions: + - fixed: 0.0.0-20260608182036-f3f4bbe80cb5 +summary: |- + FileBrowser Quantum's path traversal issue in subtitle handler allows any + authenticated user to read arbitrary files in github.com/gtsteffaniak/filebrowser/backend +cves: + - CVE-2026-54910 +ghsas: + - GHSA-vvp7-h4fj-m28w +references: + - advisory: https://github.com/gtsteffaniak/filebrowser/security/advisories/GHSA-vvp7-h4fj-m28w + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-54910 + - web: https://github.com/gtsteffaniak/filebrowser/commit/f3f4bbe80cb569d664174aea874d7bfa008c3b5a + - web: https://github.com/gtsteffaniak/filebrowser/pull/2524 + - web: https://github.com/gtsteffaniak/filebrowser/releases/tag/v1.4.3-beta +notes: + - fix: 'github.com/gtsteffaniak/filebrowser/backend: could not add vulnerable_at: cannot auto-guess when fixed version is 0.0.0 pseudo-version' +source: + id: GHSA-vvp7-h4fj-m28w + created: 2026-08-17T23:10:11.174839-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6192.yaml b/data/reports/GO-2026-6192.yaml new file mode 100644 index 0000000..89c977b --- /dev/null +++ b/data/reports/GO-2026-6192.yaml
@@ -0,0 +1,30 @@ +id: GO-2026-6192 +modules: + - module: github.com/traefik/traefik + vulnerable_at: 1.7.34 + - module: github.com/traefik/traefik/v2 + vulnerable_at: 2.11.54 + - module: github.com/traefik/traefik/v3 + versions: + - introduced: 3.6.0 + - fixed: 3.6.23 + - introduced: 3.7.0 + - fixed: 3.7.7 + vulnerable_at: 3.7.6 +summary: Traefik CRD IngressRouteTCP ServersTransport Cross-Provider Namespace Bypass in github.com/traefik/traefik +cves: + - CVE-2026-65602 +ghsas: + - GHSA-42cj-m3vj-89wv +references: + - advisory: https://github.com/traefik/traefik/security/advisories/GHSA-42cj-m3vj-89wv + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-65602 + - fix: https://github.com/traefik/traefik/commit/67501cbe7bc7774e26ecbd1c29af97f098e14b0b + - fix: https://github.com/traefik/traefik/pull/13458 + - web: https://github.com/traefik/traefik/releases/tag/v3.6.23 + - web: https://github.com/traefik/traefik/releases/tag/v3.7.7 + - web: https://www.vulncheck.com/advisories/traefik-before-ingressroutetcp-serverstransport-namespace-bypass +source: + id: GHSA-42cj-m3vj-89wv + created: 2026-08-17T23:02:42.598191-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6198.yaml b/data/reports/GO-2026-6198.yaml new file mode 100644 index 0000000..a92befe --- /dev/null +++ b/data/reports/GO-2026-6198.yaml
@@ -0,0 +1,21 @@ +id: GO-2026-6198 +modules: + - module: github.com/traefik/traefik + non_go_versions: + - introduced: 3.7.0 + - fixed: 3.7.7 +summary: Traefik Gateway API HTTPRoute BackendRef ExtensionRef Namespace Confusion +cves: + - CVE-2026-65601 +ghsas: + - GHSA-qq9q-x9w4-chhj +references: + - advisory: https://github.com/traefik/traefik/security/advisories/GHSA-qq9q-x9w4-chhj + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-65601 + - web: https://github.com/traefik/traefik/commit/655d6324ab4a1475892a958d4bae389720a67ea9 + - web: https://github.com/traefik/traefik/pull/13462 + - web: https://www.vulncheck.com/advisories/traefik-before-namespace-confusion-via-httproute-extensionref +source: + id: GHSA-qq9q-x9w4-chhj + created: 2026-08-17T23:00:30.032477-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6201.yaml b/data/reports/GO-2026-6201.yaml new file mode 100644 index 0000000..87de4af --- /dev/null +++ b/data/reports/GO-2026-6201.yaml
@@ -0,0 +1,38 @@ +id: GO-2026-6201 +modules: + - module: github.com/traefik/traefik + unsupported_versions: + - last_affected: 1.7.34 + vulnerable_at: 1.7.34 + - module: github.com/traefik/traefik/v2 + versions: + - fixed: 2.11.53 + vulnerable_at: 2.11.52 + - module: github.com/traefik/traefik/v3 + versions: + - fixed: 3.6.24 + - introduced: 3.7.0 + - fixed: 3.7.9 + vulnerable_at: 3.7.8 +summary: |- + Traefik: Cross-user response poisoning via proxied CONNECT on Traefik's shared + backend keep-alive pool in github.com/traefik/traefik +cves: + - CVE-2026-71324 +ghsas: + - GHSA-3ccp-42pg-hgv6 +references: + - advisory: https://github.com/traefik/traefik/security/advisories/GHSA-3ccp-42pg-hgv6 + - fix: https://github.com/traefik/traefik/commit/04d36f28e4eae7535e96a6351dd9f7bfb48a30e7 + - fix: https://github.com/traefik/traefik/commit/0807b6d5dd1da8b2f7f4076ea2392b5437bf2ab0 + - fix: https://github.com/traefik/traefik/commit/94a7508817d180f0ab2f1eae93df48d4ab19ecce + - fix: https://github.com/traefik/traefik/pull/13542 + - fix: https://github.com/traefik/traefik/pull/13543 + - fix: https://github.com/traefik/traefik/pull/13556 + - web: https://github.com/traefik/traefik/releases/tag/v2.11.53 + - web: https://github.com/traefik/traefik/releases/tag/v3.6.24 + - web: https://github.com/traefik/traefik/releases/tag/v3.7.9 +source: + id: GHSA-3ccp-42pg-hgv6 + created: 2026-08-17T22:59:46.437494-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6202.yaml b/data/reports/GO-2026-6202.yaml new file mode 100644 index 0000000..e49682f --- /dev/null +++ b/data/reports/GO-2026-6202.yaml
@@ -0,0 +1,35 @@ +id: GO-2026-6202 +modules: + - module: github.com/traefik/traefik + unsupported_versions: + - last_affected: 1.7.34 + vulnerable_at: 1.7.34 + - module: github.com/traefik/traefik/v2 + versions: + - fixed: 2.11.51 + vulnerable_at: 2.11.50 + - module: github.com/traefik/traefik/v3 + versions: + - fixed: 3.6.22 + - introduced: 3.7.0 + - fixed: 3.7.6 + vulnerable_at: 3.7.5 +summary: |- + Traefik: ForwardAuth middleware leaks X-Forwarded-Port spoofing via untrusted + X-Forwarded-Proto when trustForwardHeader=false in github.com/traefik/traefik +cves: + - CVE-2026-54764 +ghsas: + - GHSA-3q9r-p662-5j8m +references: + - advisory: https://github.com/traefik/traefik/security/advisories/GHSA-3q9r-p662-5j8m + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-54764 + - fix: https://github.com/traefik/traefik/commit/7ae92d8c2c10ac04ef5a03df0ed5019ce0f44b2d + - fix: https://github.com/traefik/traefik/pull/13344 + - web: https://github.com/traefik/traefik/releases/tag/v2.11.51 + - web: https://github.com/traefik/traefik/releases/tag/v3.6.22 + - web: https://github.com/traefik/traefik/releases/tag/v3.7.6 +source: + id: GHSA-3q9r-p662-5j8m + created: 2026-08-17T22:59:38.721415-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6203.yaml b/data/reports/GO-2026-6203.yaml new file mode 100644 index 0000000..09688f1 --- /dev/null +++ b/data/reports/GO-2026-6203.yaml
@@ -0,0 +1,34 @@ +id: GO-2026-6203 +modules: + - module: github.com/traefik/traefik + unsupported_versions: + - last_affected: 1.7.34 + vulnerable_at: 1.7.34 + - module: github.com/traefik/traefik/v2 + versions: + - fixed: 2.11.54 + vulnerable_at: 2.11.53 + - module: github.com/traefik/traefik/v3 + versions: + - introduced: 3.0.0 + - fixed: 3.6.25 + - introduced: 3.7.0 + - fixed: 3.7.10 + vulnerable_at: 3.7.9 +summary: |- + Traefik: `allowCrossNamespace=false` bypass via `@kubernetescrd` TraefikService + backendRef in github.com/traefik/traefik +cves: + - CVE-2026-71325 +ghsas: + - GHSA-62fc-8686-hfmq +references: + - advisory: https://github.com/traefik/traefik/security/advisories/GHSA-62fc-8686-hfmq + - fix: https://github.com/traefik/traefik/commit/65ebf4b47fbdc33e3856803a5844a404e094d52d + - web: https://github.com/traefik/traefik/releases/tag/v2.11.54 + - web: https://github.com/traefik/traefik/releases/tag/v3.6.25 + - web: https://github.com/traefik/traefik/releases/tag/v3.7.10 +source: + id: GHSA-62fc-8686-hfmq + created: 2026-08-17T22:59:32.422966-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6204.yaml b/data/reports/GO-2026-6204.yaml new file mode 100644 index 0000000..e1ca733 --- /dev/null +++ b/data/reports/GO-2026-6204.yaml
@@ -0,0 +1,30 @@ +id: GO-2026-6204 +modules: + - module: github.com/traefik/traefik + vulnerable_at: 1.7.34 + - module: github.com/traefik/traefik/v2 + vulnerable_at: 2.11.54 + - module: github.com/traefik/traefik/v3 + versions: + - introduced: 3.6.11 + - fixed: 3.6.25 + - introduced: 3.7.0 + - fixed: 3.7.10 + vulnerable_at: 3.7.9 +summary: |- + Traefik: BasicAuth singleflight key collision allows authenticated identity + spoofing in github.com/traefik/traefik +cves: + - CVE-2026-71326 +ghsas: + - GHSA-6765-c87h-8mrf +references: + - advisory: https://github.com/traefik/traefik/security/advisories/GHSA-6765-c87h-8mrf + - fix: https://github.com/traefik/traefik/commit/b5ace8eb5d6779980567f5e75efd2d9e08b7e350 + - fix: https://github.com/traefik/traefik/pull/13572 + - web: https://github.com/traefik/traefik/releases/tag/v3.6.25 + - web: https://github.com/traefik/traefik/releases/tag/v3.7.10 +source: + id: GHSA-6765-c87h-8mrf + created: 2026-08-17T22:59:25.501313-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6205.yaml b/data/reports/GO-2026-6205.yaml new file mode 100644 index 0000000..4a16f50 --- /dev/null +++ b/data/reports/GO-2026-6205.yaml
@@ -0,0 +1,28 @@ +id: GO-2026-6205 +modules: + - module: github.com/traefik/traefik + vulnerable_at: 1.7.34 + - module: github.com/traefik/traefik/v2 + vulnerable_at: 2.11.54 + - module: github.com/traefik/traefik/v3 + versions: + - introduced: 3.7.0 + - fixed: 3.7.6 + vulnerable_at: 3.7.5 +summary: |- + Traefik: Gateway HTTPRoute backendRef filters can leak backend context across + routes sharing a Service:port in github.com/traefik/traefik +cves: + - CVE-2026-54765 +ghsas: + - GHSA-6p8f-p8j2-rqmv +references: + - advisory: https://github.com/traefik/traefik/security/advisories/GHSA-6p8f-p8j2-rqmv + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-54765 + - fix: https://github.com/traefik/traefik/commit/8aada7a7d52e4588a75386d8b86d270f6fe8d549 + - fix: https://github.com/traefik/traefik/pull/13367 + - web: https://github.com/traefik/traefik/releases/tag/v3.7.6 +source: + id: GHSA-6p8f-p8j2-rqmv + created: 2026-08-17T22:59:19.146126-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6207.yaml b/data/reports/GO-2026-6207.yaml new file mode 100644 index 0000000..5b78184 --- /dev/null +++ b/data/reports/GO-2026-6207.yaml
@@ -0,0 +1,27 @@ +id: GO-2026-6207 +modules: + - module: github.com/traefik/traefik + vulnerable_at: 1.7.34 + - module: github.com/traefik/traefik/v2 + vulnerable_at: 2.11.54 + - module: github.com/traefik/traefik/v3 + versions: + - introduced: 3.7.0 + - fixed: 3.7.8 + vulnerable_at: 3.7.7 +summary: |- + Traefik: Kubernetes Ingress NGINX RewriteTarget Path Traversal Allows + Route-Level Authentication Bypass in github.com/traefik/traefik +cves: + - CVE-2026-67309 +ghsas: + - GHSA-8rxv-jg7p-wvg3 +references: + - advisory: https://github.com/traefik/traefik/security/advisories/GHSA-8rxv-jg7p-wvg3 + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-67309 + - fix: https://github.com/traefik/traefik/commit/759515bec1b9f628b21ea8968ef63da853be5e29 + - web: https://www.vulncheck.com/advisories/traefik-path-traversal-via-rewritetarget-authentication-bypass +source: + id: GHSA-8rxv-jg7p-wvg3 + created: 2026-08-17T22:59:10.935774-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6208.yaml b/data/reports/GO-2026-6208.yaml new file mode 100644 index 0000000..4fe4de6 --- /dev/null +++ b/data/reports/GO-2026-6208.yaml
@@ -0,0 +1,33 @@ +id: GO-2026-6208 +modules: + - module: github.com/traefik/traefik + unsupported_versions: + - last_affected: 1.7.34 + vulnerable_at: 1.7.34 + - module: github.com/traefik/traefik/v2 + versions: + - fixed: 2.11.52 + vulnerable_at: 2.11.51 + - module: github.com/traefik/traefik/v3 + versions: + - fixed: 3.6.23 + - introduced: 3.7.0 + - fixed: 3.7.7 + vulnerable_at: 3.7.6 +summary: 'Traefik: Authentication Bypass via Path Traversal in ReplacePathRegex Middleware in github.com/traefik/traefik' +cves: + - CVE-2026-65600 +ghsas: + - GHSA-cxjq-mrr5-89rv +references: + - advisory: https://github.com/traefik/traefik/security/advisories/GHSA-cxjq-mrr5-89rv + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-65600 + - fix: https://github.com/traefik/traefik/commit/3f10dd442479530560f010167cac2947676d9b29 + - web: https://github.com/traefik/traefik/releases/tag/v2.11.52 + - web: https://github.com/traefik/traefik/releases/tag/v3.6.23 + - web: https://github.com/traefik/traefik/releases/tag/v3.7.7 + - web: https://www.vulncheck.com/advisories/traefik-before-authentication-bypass-via-replacepathregex +source: + id: GHSA-cxjq-mrr5-89rv + created: 2026-08-17T22:59:03.370989-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6209.yaml b/data/reports/GO-2026-6209.yaml new file mode 100644 index 0000000..a2016cb --- /dev/null +++ b/data/reports/GO-2026-6209.yaml
@@ -0,0 +1,30 @@ +id: GO-2026-6209 +modules: + - module: github.com/traefik/traefik + vulnerable_at: 1.7.34 + - module: github.com/traefik/traefik/v2 + vulnerable_at: 2.11.54 + - module: github.com/traefik/traefik/v3 + versions: + - introduced: 3.0.0 + - fixed: 3.6.25 + - introduced: 3.7.0 + - fixed: 3.7.10 + vulnerable_at: 3.7.9 +summary: |- + Traefik: Gateway API route identity collision allows cross-namespace backend + hijacking in github.com/traefik/traefik +cves: + - CVE-2026-71327 +ghsas: + - GHSA-fgjj-px3w-67xx +references: + - advisory: https://github.com/traefik/traefik/security/advisories/GHSA-fgjj-px3w-67xx + - fix: https://github.com/traefik/traefik/commit/a764166656f0cd337f917ac76315c381cca844f9 + - fix: https://github.com/traefik/traefik/pull/13580 + - web: https://github.com/traefik/traefik/releases/tag/v3.6.25 + - web: https://github.com/traefik/traefik/releases/tag/v3.7.10 +source: + id: GHSA-fgjj-px3w-67xx + created: 2026-08-17T22:58:55.944702-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6211.yaml b/data/reports/GO-2026-6211.yaml new file mode 100644 index 0000000..76b607a --- /dev/null +++ b/data/reports/GO-2026-6211.yaml
@@ -0,0 +1,34 @@ +id: GO-2026-6211 +modules: + - module: github.com/traefik/traefik + vulnerable_at: 1.7.34 + - module: github.com/traefik/traefik/v2 + versions: + - fixed: 2.11.51 + vulnerable_at: 2.11.50 + - module: github.com/traefik/traefik/v3 + versions: + - fixed: 3.6.22 + - introduced: 3.7.0 + - fixed: 3.7.6 + vulnerable_at: 3.7.5 +summary: |- + Traefik: Incomplete fix for CVE-2026-33433 + CVE-2026-39858 cross-cohort: + headerField underscore-variant identity spoofing in BasicAuth / DigestAuth / + ForwardAuth in github.com/traefik/traefik +cves: + - CVE-2026-54763 +ghsas: + - GHSA-x677-9fxg-v5c5 +references: + - advisory: https://github.com/traefik/traefik/security/advisories/GHSA-x677-9fxg-v5c5 + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-54763 + - fix: https://github.com/traefik/traefik/commit/108a5264473a2cbc8f12d6d691a3c6553cdf2c1b + - fix: https://github.com/traefik/traefik/pull/13262 + - web: https://github.com/traefik/traefik/releases/tag/v2.11.51 + - web: https://github.com/traefik/traefik/releases/tag/v3.6.22 + - web: https://github.com/traefik/traefik/releases/tag/v3.7.6 +source: + id: GHSA-x677-9fxg-v5c5 + created: 2026-08-17T22:58:46.149987-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6212.yaml b/data/reports/GO-2026-6212.yaml new file mode 100644 index 0000000..b4a383d --- /dev/null +++ b/data/reports/GO-2026-6212.yaml
@@ -0,0 +1,19 @@ +id: GO-2026-6212 +modules: + - module: github.com/gophish/gophish + unsupported_versions: + - last_affected: 0.12.1 + vulnerable_at: 0.12.1 +summary: Gophish contains a denial of service vulnerability in github.com/gophish/gophish +cves: + - CVE-2026-39904 +ghsas: + - GHSA-42jc-v69j-g38f +references: + - advisory: https://github.com/advisories/GHSA-42jc-v69j-g38f + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-39904 + - web: https://www.vulncheck.com/advisories/gophish-denial-of-service-via-office-document-upload +source: + id: GHSA-42jc-v69j-g38f + created: 2026-08-17T22:58:39.945202-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6219.yaml b/data/reports/GO-2026-6219.yaml new file mode 100644 index 0000000..18ea078 --- /dev/null +++ b/data/reports/GO-2026-6219.yaml
@@ -0,0 +1,23 @@ +id: GO-2026-6219 +modules: + - module: github.com/seaweedfs/seaweedfs + versions: + - fixed: 0.0.0-20260512171120-69da20bdaec9 +summary: |- + SeaweedFS: Unauthenticated SSRF with response read-back via + VolumeServer.FetchAndWriteNeedle in github.com/seaweedfs/seaweedfs +cves: + - CVE-2026-73080 +ghsas: + - GHSA-87fv-vqqr-m4jr +references: + - advisory: https://github.com/seaweedfs/seaweedfs/security/advisories/GHSA-87fv-vqqr-m4jr + - fix: https://github.com/seaweedfs/seaweedfs/commit/69da20bdaec923e5a43d8aa71bf3c0a2051fc019 + - fix: https://github.com/seaweedfs/seaweedfs/pull/9441 + - web: https://github.com/seaweedfs/seaweedfs/releases/tag/4.24 +notes: + - fix: 'github.com/seaweedfs/seaweedfs: could not add vulnerable_at: cannot auto-guess when fixed version is 0.0.0 pseudo-version' +source: + id: GHSA-87fv-vqqr-m4jr + created: 2026-08-17T22:57:54.326931-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6220.yaml b/data/reports/GO-2026-6220.yaml new file mode 100644 index 0000000..d9ff493 --- /dev/null +++ b/data/reports/GO-2026-6220.yaml
@@ -0,0 +1,20 @@ +id: GO-2026-6220 +modules: + - module: github.com/fleetdm/fleet/v4 + versions: + - fixed: 4.87.0 + vulnerable_at: 4.86.2 +summary: |- + Fleet: Observer-class users can view team enroll secrets and credential-bearing + configuration via target search endpoint in github.com/fleetdm/fleet +cves: + - CVE-2026-48786 +ghsas: + - GHSA-88p2-jj8w-j8qg +references: + - advisory: https://github.com/fleetdm/fleet/security/advisories/GHSA-88p2-jj8w-j8qg + - web: https://github.com/fleetdm/fleet/releases/tag/fleet-v4.87.0 +source: + id: GHSA-88p2-jj8w-j8qg + created: 2026-08-17T22:54:53.888287-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6221.yaml b/data/reports/GO-2026-6221.yaml new file mode 100644 index 0000000..f6762b6 --- /dev/null +++ b/data/reports/GO-2026-6221.yaml
@@ -0,0 +1,23 @@ +id: GO-2026-6221 +modules: + - module: github.com/seaweedfs/seaweedfs + versions: + - fixed: 0.0.0-20260526080459-dd1b4287899e +summary: |- + SeaweedFS: Path traversal in the S3 and Iceberg REST gateways allows + cross-bucket access in github.com/seaweedfs/seaweedfs +cves: + - CVE-2026-54917 +ghsas: + - GHSA-w62w-66v9-vvgv +references: + - advisory: https://github.com/seaweedfs/seaweedfs/security/advisories/GHSA-w62w-66v9-vvgv + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-54917 + - fix: https://github.com/seaweedfs/seaweedfs/commit/dd1b4287899eed3dfd73c2f3b1de001996fda229 + - fix: https://github.com/seaweedfs/seaweedfs/pull/9687 +notes: + - fix: 'github.com/seaweedfs/seaweedfs: could not add vulnerable_at: cannot auto-guess when fixed version is 0.0.0 pseudo-version' +source: + id: GHSA-w62w-66v9-vvgv + created: 2026-08-17T22:53:51.063973-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6223.yaml b/data/reports/GO-2026-6223.yaml new file mode 100644 index 0000000..aa94582 --- /dev/null +++ b/data/reports/GO-2026-6223.yaml
@@ -0,0 +1,35 @@ +id: GO-2026-6223 +modules: + - module: github.com/argoproj/argo-workflows + vulnerable_at: 0.4.7 + - module: github.com/argoproj/argo-workflows/v2 + unsupported_versions: + - last_affected: 2.5.3-rc4 + vulnerable_at: 2.12.13 + - module: github.com/argoproj/argo-workflows/v3 + versions: + - fixed: 3.7.15 + vulnerable_at: 3.7.14 + - module: github.com/argoproj/argo-workflows/v4 + versions: + - introduced: 4.0.0 + - fixed: 4.0.6 + vulnerable_at: 4.0.5 +summary: |- + Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template + reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows +cves: + - CVE-2026-54526 +ghsas: + - GHSA-48p8-g2fx-3wwm +references: + - advisory: https://github.com/argoproj/argo-workflows/security/advisories/GHSA-48p8-g2fx-3wwm + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-54526 + - fix: https://github.com/argoproj/argo-workflows/commit/277e9cef0ad16d7eaaab253573d0695951a65dbd + - fix: https://github.com/argoproj/argo-workflows/commit/358cc3968c8f06f1be0967e41df191088db0b662 + - web: https://github.com/argoproj/argo-workflows/releases/tag/v3.7.15 + - web: https://github.com/argoproj/argo-workflows/releases/tag/v4.0.6 +source: + id: GHSA-48p8-g2fx-3wwm + created: 2026-08-17T22:53:43.285012-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6224.yaml b/data/reports/GO-2026-6224.yaml new file mode 100644 index 0000000..f7d8c9f --- /dev/null +++ b/data/reports/GO-2026-6224.yaml
@@ -0,0 +1,24 @@ +id: GO-2026-6224 +modules: + - module: github.com/kubev2v/migration-planner + versions: + - fixed: 0.13.5 + vulnerable_at: 0.13.4 +summary: |- + Openshift Migration Advisor lacks proper authorization and filtering for its + DELETE /api/v1/sources API in github.com/kubev2v/migration-planner +cves: + - CVE-2026-53469 +ghsas: + - GHSA-6xvf-9742-48w2 +references: + - advisory: https://github.com/advisories/GHSA-6xvf-9742-48w2 + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-53469 + - fix: https://github.com/kubev2v/migration-planner/commit/db4c7857bd8f8e04747a5ea0efca04b0235d6e4a + - fix: https://github.com/kubev2v/migration-planner/pull/1227 + - web: https://access.redhat.com/security/cve/CVE-2026-53469 + - web: https://bugzilla.redhat.com/show_bug.cgi?id=2487065 +source: + id: GHSA-6xvf-9742-48w2 + created: 2026-08-17T22:53:30.57482-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6227.yaml b/data/reports/GO-2026-6227.yaml new file mode 100644 index 0000000..3b968e7 --- /dev/null +++ b/data/reports/GO-2026-6227.yaml
@@ -0,0 +1,22 @@ +id: GO-2026-6227 +modules: + - module: github.com/authorizerdev/authorizer + versions: + - fixed: 0.0.0-20260807033110-66fe488fd2a4 +summary: |- + Authorizer: Zero-click account takeover via OAuth identity linking to unverified + email accounts in github.com/authorizerdev/authorizer +cves: + - CVE-2026-35511 +ghsas: + - GHSA-29rf-f4vv-pvq6 +references: + - advisory: https://github.com/authorizerdev/authorizer/security/advisories/GHSA-29rf-f4vv-pvq6 + - fix: https://github.com/authorizerdev/authorizer/commit/66fe488fd2a4e7acf1e517334344d5e8f3ddd296 + - web: https://github.com/authorizerdev/authorizer/releases/tag/2.4.0-rc.16 +notes: + - fix: 'github.com/authorizerdev/authorizer: could not add vulnerable_at: cannot auto-guess when fixed version is 0.0.0 pseudo-version' +source: + id: GHSA-29rf-f4vv-pvq6 + created: 2026-08-17T22:53:24.130529-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6228.yaml b/data/reports/GO-2026-6228.yaml new file mode 100644 index 0000000..e261594 --- /dev/null +++ b/data/reports/GO-2026-6228.yaml
@@ -0,0 +1,24 @@ +id: GO-2026-6228 +modules: + - module: github.com/kubev2v/migration-planner + versions: + - fixed: 0.13.5 + vulnerable_at: 0.13.4 +summary: |- + Openshift Migration Advisor agent-API fails to validate JWT source_id claim, + allowing cross-tenant data manipulation in github.com/kubev2v/migration-planner +cves: + - CVE-2026-53471 +ghsas: + - GHSA-2fqw-7c6r-2cq6 +references: + - advisory: https://github.com/advisories/GHSA-2fqw-7c6r-2cq6 + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-53471 + - fix: https://github.com/kubev2v/migration-planner/commit/fd21a239216f5eeec635d16c72be9c033bd5d1aa + - fix: https://github.com/kubev2v/migration-planner/pull/1213 + - web: https://access.redhat.com/security/cve/CVE-2026-53471 + - web: https://bugzilla.redhat.com/show_bug.cgi?id=2487070 +source: + id: GHSA-2fqw-7c6r-2cq6 + created: 2026-08-17T22:53:13.898165-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6229.yaml b/data/reports/GO-2026-6229.yaml new file mode 100644 index 0000000..1394bef --- /dev/null +++ b/data/reports/GO-2026-6229.yaml
@@ -0,0 +1,24 @@ +id: GO-2026-6229 +modules: + - module: github.com/kubev2v/migration-planner + versions: + - fixed: 0.13.5 + vulnerable_at: 0.13.4 +summary: |- + Openshift Migration Advisor: Broken access control in migration-planner + image-url endpoint exposes other users' OVA images and agent JWTs in github.com/kubev2v/migration-planner +cves: + - CVE-2026-53470 +ghsas: + - GHSA-v5m8-5455-qw2x +references: + - advisory: https://github.com/advisories/GHSA-v5m8-5455-qw2x + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-53470 + - fix: https://github.com/kubev2v/migration-planner/commit/ec47a336a620f4a995f29c1c53e4e4bd70a26e00 + - fix: https://github.com/kubev2v/migration-planner/pull/1218 + - web: https://access.redhat.com/security/cve/CVE-2026-53470 + - web: https://bugzilla.redhat.com/show_bug.cgi?id=2487069 +source: + id: GHSA-v5m8-5455-qw2x + created: 2026-08-17T22:53:02.922381-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6230.yaml b/data/reports/GO-2026-6230.yaml new file mode 100644 index 0000000..9efa58c --- /dev/null +++ b/data/reports/GO-2026-6230.yaml
@@ -0,0 +1,25 @@ +id: GO-2026-6230 +modules: + - module: github.com/lima-vm/lima + vulnerable_at: 1.2.3 + - module: github.com/lima-vm/lima/v2 + versions: + - fixed: 2.1.3 + vulnerable_at: 2.1.2 +summary: |- + Lima: An arbitrary user in a QEMU VM could gain the root privilege in the VM via + the guest agent socket in github.com/lima-vm/lima +cves: + - CVE-2026-53657 +ghsas: + - GHSA-2j9v-p4xj-cjw2 +references: + - advisory: https://github.com/lima-vm/lima/security/advisories/GHSA-2j9v-p4xj-cjw2 + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-53657 + - fix: https://github.com/lima-vm/lima/commit/8a45892378d22f40505c31a38f786a07701b6d50 + - fix: https://github.com/lima-vm/lima/commit/b08cae8a670cf916d5da11c48a6de76dabd89678 + - web: https://github.com/lima-vm/lima/releases/tag/v2.1.3 +source: + id: GHSA-2j9v-p4xj-cjw2 + created: 2026-08-17T22:52:51.077388-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6231.yaml b/data/reports/GO-2026-6231.yaml new file mode 100644 index 0000000..45e7027 --- /dev/null +++ b/data/reports/GO-2026-6231.yaml
@@ -0,0 +1,24 @@ +id: GO-2026-6231 +modules: + - module: github.com/kubev2v/assisted-migration-agent + versions: + - fixed: 0.16.0 + vulnerable_at: 0.12.0 +summary: |- + Assisted Migration Agent: Path traversal in gzipped tarball handling enables + arbitrary file write and remote code execution in github.com/kubev2v/assisted-migration-agent +cves: + - CVE-2026-53476 +ghsas: + - GHSA-7j4w-x8x8-5mvg +references: + - advisory: https://github.com/advisories/GHSA-7j4w-x8x8-5mvg + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-53476 + - fix: https://github.com/kubev2v/assisted-migration-agent/commit/bcae0438ad8386321a300413d71c982a11b7b5b7 + - fix: https://github.com/kubev2v/assisted-migration-agent/pull/256 + - web: https://access.redhat.com/security/cve/CVE-2026-53476 + - web: https://bugzilla.redhat.com/show_bug.cgi?id=2487233 +source: + id: GHSA-7j4w-x8x8-5mvg + created: 2026-08-17T22:52:38.759771-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6232.yaml b/data/reports/GO-2026-6232.yaml new file mode 100644 index 0000000..00ab98c --- /dev/null +++ b/data/reports/GO-2026-6232.yaml
@@ -0,0 +1,24 @@ +id: GO-2026-6232 +modules: + - module: github.com/kubev2v/assisted-migration-agent + versions: + - fixed: 0.16.0 + vulnerable_at: 0.12.0 +summary: |- + Assisted Migration Agent: Hardcoded insecure Transport Layer Security (TLS) + connections during vCenter communication in github.com/kubev2v/assisted-migration-agent +cves: + - CVE-2026-53475 +ghsas: + - GHSA-8g5p-jxp9-457c +references: + - advisory: https://github.com/advisories/GHSA-8g5p-jxp9-457c + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-53475 + - fix: https://github.com/kubev2v/assisted-migration-agent/commit/b940fec9f5032a0801e994054d30e81d64b2942a + - fix: https://github.com/kubev2v/assisted-migration-agent/pull/268 + - web: https://access.redhat.com/security/cve/CVE-2026-53475 + - web: https://bugzilla.redhat.com/show_bug.cgi?id=2487232 +source: + id: GHSA-8g5p-jxp9-457c + created: 2026-08-17T22:52:26.211068-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6233.yaml b/data/reports/GO-2026-6233.yaml new file mode 100644 index 0000000..332a295 --- /dev/null +++ b/data/reports/GO-2026-6233.yaml
@@ -0,0 +1,24 @@ +id: GO-2026-6233 +modules: + - module: github.com/kubev2v/migration-planner + versions: + - fixed: 0.13.5 + vulnerable_at: 0.13.4 +summary: |- + Openshift Migration Advisor: Improper input sanitization allows specially + crafted RVTools .xlsx files to include malicious SQL commands in github.com/kubev2v/migration-planner +cves: + - CVE-2026-53474 +ghsas: + - GHSA-vf2h-7x3w-97fr +references: + - advisory: https://github.com/advisories/GHSA-vf2h-7x3w-97fr + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-53474 + - fix: https://github.com/kubev2v/migration-planner/commit/6110711b1b71bb0d15348b934a490a5932b41f83 + - fix: https://github.com/kubev2v/migration-planner/pull/1231 + - web: https://access.redhat.com/security/cve/CVE-2026-53474 + - web: https://bugzilla.redhat.com/show_bug.cgi?id=2487231 +source: + id: GHSA-vf2h-7x3w-97fr + created: 2026-08-17T22:52:12.438777-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6240.yaml b/data/reports/GO-2026-6240.yaml new file mode 100644 index 0000000..ef47afc --- /dev/null +++ b/data/reports/GO-2026-6240.yaml
@@ -0,0 +1,22 @@ +id: GO-2026-6240 +modules: + - module: github.com/QuantumNous/new-api + versions: + - fixed: 1.0.0-rc.7 + vulnerable_at: 1.0.0-rc.6 +summary: |- + New API: User List API Leaks Root User Access Token Leading to Privilege + Escalation in github.com/QuantumNous/new-api +cves: + - CVE-2026-64859 +ghsas: + - GHSA-6x2c-phff-wx57 +references: + - advisory: https://github.com/QuantumNous/new-api/security/advisories/GHSA-6x2c-phff-wx57 + - fix: https://github.com/QuantumNous/new-api/commit/0936e2504655a5cbf7bc3c388f6d3e2bb24916d3 + - fix: https://github.com/QuantumNous/new-api/pull/4929 + - web: https://github.com/QuantumNous/new-api/releases/tag/v1.0.0-rc.7 +source: + id: GHSA-6x2c-phff-wx57 + created: 2026-08-17T22:51:31.455429-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6241.yaml b/data/reports/GO-2026-6241.yaml new file mode 100644 index 0000000..a23243a --- /dev/null +++ b/data/reports/GO-2026-6241.yaml
@@ -0,0 +1,18 @@ +id: GO-2026-6241 +modules: + - module: github.com/gruntwork-io/terragrunt + versions: + - fixed: 1.0.4 + vulnerable_at: 1.0.3 +summary: 'Terragrunt: Arbitrary File Deletion via Malicious Module Manifest in github.com/gruntwork-io/terragrunt' +cves: + - CVE-2026-45099 +ghsas: + - GHSA-8394-6f8r-whxg +references: + - advisory: https://github.com/gruntwork-io/terragrunt/security/advisories/GHSA-8394-6f8r-whxg + - web: https://github.com/gruntwork-io/terragrunt/releases/tag/v1.0.4 +source: + id: GHSA-8394-6f8r-whxg + created: 2026-08-17T22:51:25.870049-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6242.yaml b/data/reports/GO-2026-6242.yaml new file mode 100644 index 0000000..bfd87ff --- /dev/null +++ b/data/reports/GO-2026-6242.yaml
@@ -0,0 +1,22 @@ +id: GO-2026-6242 +modules: + - module: github.com/QuantumNous/new-api + versions: + - fixed: 1.0.0-rc.18 + vulnerable_at: 1.0.0-rc.17 +summary: |- + New API: Integer overflow in quota billing yields negative charges + (self-crediting) in github.com/QuantumNous/new-api +cves: + - CVE-2026-71479 +ghsas: + - GHSA-8r8v-xf7q-rcpr +references: + - advisory: https://github.com/QuantumNous/new-api/security/advisories/GHSA-8r8v-xf7q-rcpr + - fix: https://github.com/QuantumNous/new-api/commit/c9943d37ad93477dd937fc4901cc3c4e0fd8aaab + - fix: https://github.com/QuantumNous/new-api/commit/d0bd8aac742d1e160a5ca61743fe35f4fff880e8 + - web: https://github.com/QuantumNous/new-api/releases/tag/v1.0.0-rc.18 +source: + id: GHSA-8r8v-xf7q-rcpr + created: 2026-08-17T22:51:19.090267-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6243.yaml b/data/reports/GO-2026-6243.yaml new file mode 100644 index 0000000..13ce8bb --- /dev/null +++ b/data/reports/GO-2026-6243.yaml
@@ -0,0 +1,21 @@ +id: GO-2026-6243 +modules: + - module: github.com/QuantumNous/new-api + versions: + - fixed: 1.0.0-rc.16 + vulnerable_at: 1.0.0-rc.15 +summary: |- + New API: Redis user quota cache overwrite via PUT /api/user/self allows quota + bypass in github.com/QuantumNous/new-api +cves: + - CVE-2026-64865 +ghsas: + - GHSA-j6gc-4893-qwmp +references: + - advisory: https://github.com/QuantumNous/new-api/security/advisories/GHSA-j6gc-4893-qwmp + - fix: https://github.com/QuantumNous/new-api/commit/dfc0d6324b40c1d6c2972e524409f933541bfb0f + - web: https://github.com/QuantumNous/new-api/releases/tag/v1.0.0-rc.16 +source: + id: GHSA-j6gc-4893-qwmp + created: 2026-08-17T22:51:12.842988-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6244.yaml b/data/reports/GO-2026-6244.yaml new file mode 100644 index 0000000..b3a6f55 --- /dev/null +++ b/data/reports/GO-2026-6244.yaml
@@ -0,0 +1,22 @@ +id: GO-2026-6244 +modules: + - module: github.com/QuantumNous/new-api + versions: + - fixed: 1.0.0-rc.7 + non_go_versions: + - introduced: 0.9.1.3 + vulnerable_at: 1.0.0-rc.6 +summary: 'New API: Admin can reset passkeys for same-level or higher-privileged users in github.com/QuantumNous/new-api' +cves: + - CVE-2026-64866 +ghsas: + - GHSA-p845-629j-rcj6 +references: + - advisory: https://github.com/QuantumNous/new-api/security/advisories/GHSA-p845-629j-rcj6 + - fix: https://github.com/QuantumNous/new-api/commit/0936e2504655a5cbf7bc3c388f6d3e2bb24916d3 + - fix: https://github.com/QuantumNous/new-api/pull/4929 + - web: https://github.com/QuantumNous/new-api/releases/tag/v1.0.0-rc.7 +source: + id: GHSA-p845-629j-rcj6 + created: 2026-08-17T22:51:06.004313-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6245.yaml b/data/reports/GO-2026-6245.yaml new file mode 100644 index 0000000..e3963b9 --- /dev/null +++ b/data/reports/GO-2026-6245.yaml
@@ -0,0 +1,22 @@ +id: GO-2026-6245 +modules: + - module: github.com/QuantumNous/new-api + versions: + - fixed: 1.0.0-rc.11 + vulnerable_at: 1.0.0-rc.10 +summary: |- + New API: Unauthenticated payment webhooks allow memory and disk DoS via + unbounded body reads and full-body logging in github.com/QuantumNous/new-api +cves: + - CVE-2026-64868 +ghsas: + - GHSA-v828-m3pf-vq9q +references: + - advisory: https://github.com/QuantumNous/new-api/security/advisories/GHSA-v828-m3pf-vq9q + - fix: https://github.com/QuantumNous/new-api/commit/d2f7f9ee3adf3ef66798783a60d7bc712451c85c + - fix: https://github.com/QuantumNous/new-api/pull/5244 + - web: https://github.com/QuantumNous/new-api/releases/tag/v1.0.0-rc.11 +source: + id: GHSA-v828-m3pf-vq9q + created: 2026-08-17T22:50:58.219377-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6246.yaml b/data/reports/GO-2026-6246.yaml new file mode 100644 index 0000000..4a0cec3 --- /dev/null +++ b/data/reports/GO-2026-6246.yaml
@@ -0,0 +1,19 @@ +id: GO-2026-6246 +modules: + - module: gitlab.com/uniget-org/cli + versions: + - introduced: 0.27.4 + - fixed: 0.28.9 + vulnerable_at: 0.28.8 +summary: |- + uniget CLI: Metadata signature verification only runs when + UNIGET_IGNORE_METADATA_SIGNATURE is set in gitlab.com/uniget-org/cli +ghsas: + - GHSA-fhgh-wq4q-r37x +references: + - advisory: https://github.com/uniget-org/cli/security/advisories/GHSA-fhgh-wq4q-r37x + - web: https://github.com/uniget-org/cli/releases/tag/v0.28.9 +source: + id: GHSA-fhgh-wq4q-r37x + created: 2026-08-17T22:50:55.102843-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6247.yaml b/data/reports/GO-2026-6247.yaml new file mode 100644 index 0000000..c592652 --- /dev/null +++ b/data/reports/GO-2026-6247.yaml
@@ -0,0 +1,19 @@ +id: GO-2026-6247 +modules: + - module: gitlab.com/uniget-org/cli + versions: + - fixed: 0.27.6 + vulnerable_at: 0.27.5 +summary: uniget CLI has Path Traversal in Hook Files - Directory Escape Vulnerability in gitlab.com/uniget-org/cli +cves: + - CVE-2026-55062 +ghsas: + - GHSA-m6jg-wr9m-cg2f +references: + - advisory: https://github.com/uniget-org/cli/security/advisories/GHSA-m6jg-wr9m-cg2f + - web: https://github.com/uniget-org/cli/commit/7b4f18a9f00f0955f830c7ccf266ed0de5f9fd91 + - web: https://github.com/uniget-org/cli/releases/tag/v0.27.6 +source: + id: GHSA-m6jg-wr9m-cg2f + created: 2026-08-17T22:50:51.293952-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6248.yaml b/data/reports/GO-2026-6248.yaml new file mode 100644 index 0000000..2e9a527 --- /dev/null +++ b/data/reports/GO-2026-6248.yaml
@@ -0,0 +1,19 @@ +id: GO-2026-6248 +modules: + - module: gitlab.com/uniget-org/cli + versions: + - fixed: 0.27.6 + vulnerable_at: 0.27.5 +summary: uniget CLI has an EDITOR Command Injection in gitlab.com/uniget-org/cli +cves: + - CVE-2026-55061 +ghsas: + - GHSA-qmcq-xw74-w667 +references: + - advisory: https://github.com/uniget-org/cli/security/advisories/GHSA-qmcq-xw74-w667 + - web: https://github.com/uniget-org/cli/commit/7b4f18a9f00f0955f830c7ccf266ed0de5f9fd91 + - web: https://github.com/uniget-org/cli/releases/tag/v0.27.6 +source: + id: GHSA-qmcq-xw74-w667 + created: 2026-08-17T22:50:45.095629-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6249.yaml b/data/reports/GO-2026-6249.yaml new file mode 100644 index 0000000..fecb06a --- /dev/null +++ b/data/reports/GO-2026-6249.yaml
@@ -0,0 +1,25 @@ +id: GO-2026-6249 +modules: + - module: github.com/apache/answer + non_go_versions: + - fixed: 2.0.1 + vulnerable_at: 1.7.1 + - module: github.com/apache/incubator-answer + non_go_versions: + - fixed: 2.0.1 + vulnerable_at: 1.7.1 +summary: 'Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer' +cves: + - CVE-2026-25700 +ghsas: + - GHSA-4gw2-vg4x-7p29 +references: + - advisory: https://github.com/advisories/GHSA-4gw2-vg4x-7p29 + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-25700 + - web: http://www.openwall.com/lists/oss-security/2026/06/10/10 + - web: https://github.com/apache/answer/releases/tag/v2.0.1 + - web: https://lists.apache.org/thread/ftw52mlxknjm29vo1mnqovj53z2kh96y +source: + id: GHSA-4gw2-vg4x-7p29 + created: 2026-08-17T22:50:25.245698-04:00 +review_status: UNREVIEWED