data/reports: add GO-2026-6629 - data/reports/GO-2026-6629.yaml Fixes golang/vulndb#6629 Change-Id: I2897086830cedcbc1fe88da0f45bc4b983d7e1e7 Reviewed-on: https://go-review.googlesource.com/c/vulndb/+/842946 Reviewed-by: Nicholas Husin <husin@google.com> Reviewed-by: Nicholas Husin <nsh@golang.org> Auto-Submit: Ian Alexander <jitsu@google.com> LUCI-TryBot-Result: golang-scoped@luci-project-accounts.iam.gserviceaccount.com <golang-scoped@luci-project-accounts.iam.gserviceaccount.com>
diff --git a/data/cve/v5/GO-2026-6629.json b/data/cve/v5/GO-2026-6629.json new file mode 100644 index 0000000..8e1aff9 --- /dev/null +++ b/data/cve/v5/GO-2026-6629.json
@@ -0,0 +1,100 @@ +{ + "dataType": "CVE_RECORD", + "dataVersion": "5.0", + "cveMetadata": { + "cveId": "CVE-2026-56851" + }, + "containers": { + "cna": { + "providerMetadata": { + "orgId": "1bb62c36-49e3-4200-9d77-64a1400537cc" + }, + "title": "Panic parsing crafted input in x/text/secure/precis in golang.org/x/text", + "descriptions": [ + { + "lang": "en", + "value": "The Nickname profile can panic with an out-of-bounds slice error when transforming crafted input into a short destination buffer." + } + ], + "affected": [ + { + "vendor": "golang.org/x/text", + "product": "golang.org/x/text/secure/precis", + "collectionURL": "https://pkg.go.dev", + "packageName": "golang.org/x/text/secure/precis", + "versions": [ + { + "version": "0", + "lessThan": "0.41.0", + "status": "affected", + "versionType": "semver" + } + ], + "programRoutines": [ + { + "name": "nickAdditionalMapping.Transform" + }, + { + "name": "Profile.Append" + }, + { + "name": "Profile.AppendCompareKey" + }, + { + "name": "Profile.Bytes" + }, + { + "name": "Profile.Compare" + }, + { + "name": "Profile.CompareKey" + }, + { + "name": "Profile.NewTransformer" + }, + { + "name": "Profile.String" + }, + { + "name": "Transformer.Bytes" + }, + { + "name": "Transformer.String" + }, + { + "name": "Transformer.Transform" + } + ], + "defaultStatus": "unaffected" + } + ], + "problemTypes": [ + { + "descriptions": [ + { + "lang": "en", + "description": "CWE-787: Out-of-bounds Write" + } + ] + } + ], + "references": [ + { + "url": "https://go.dev/cl/793360" + }, + { + "url": "https://go.dev/issue/80112" + }, + { + "url": "https://pkg.go.dev/vuln/GO-2026-6629" + } + ], + "credits": [ + { + "lang": "en", + "value": "Omkhar Arasaratnam (GitHub: omkhar)" + } + ] + } + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6629.json b/data/osv/GO-2026-6629.json new file mode 100644 index 0000000..0a40d6c --- /dev/null +++ b/data/osv/GO-2026-6629.json
@@ -0,0 +1,71 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6629", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-56851" + ], + "summary": "Panic parsing crafted input in x/text/secure/precis in golang.org/x/text", + "details": "The Nickname profile can panic with an out-of-bounds slice error when transforming crafted input into a short destination buffer.", + "affected": [ + { + "package": { + "name": "golang.org/x/text", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.41.0" + } + ] + } + ], + "ecosystem_specific": { + "imports": [ + { + "path": "golang.org/x/text/secure/precis", + "symbols": [ + "Profile.Append", + "Profile.AppendCompareKey", + "Profile.Bytes", + "Profile.Compare", + "Profile.CompareKey", + "Profile.NewTransformer", + "Profile.String", + "Transformer.Bytes", + "Transformer.String", + "Transformer.Transform", + "nickAdditionalMapping.Transform" + ] + } + ] + } + } + ], + "references": [ + { + "type": "FIX", + "url": "https://go.dev/cl/793360" + }, + { + "type": "REPORT", + "url": "https://go.dev/issue/80112" + } + ], + "credits": [ + { + "name": "Omkhar Arasaratnam (GitHub: omkhar)" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6629", + "review_status": "REVIEWED" + } +} \ No newline at end of file
diff --git a/data/reports/GO-2026-6629.yaml b/data/reports/GO-2026-6629.yaml new file mode 100644 index 0000000..ef7277b --- /dev/null +++ b/data/reports/GO-2026-6629.yaml
@@ -0,0 +1,36 @@ +id: GO-2026-6629 +modules: + - module: golang.org/x/text + versions: + - fixed: 0.41.0 + vulnerable_at: 0.40.0 + packages: + - package: golang.org/x/text/secure/precis + symbols: + - nickAdditionalMapping.Transform + derived_symbols: + - Profile.Append + - Profile.AppendCompareKey + - Profile.Bytes + - Profile.Compare + - Profile.CompareKey + - Profile.NewTransformer + - Profile.String + - Transformer.Bytes + - Transformer.String + - Transformer.Transform +summary: Panic parsing crafted input in x/text/secure/precis in golang.org/x/text +description: |- + The Nickname profile can panic with an out-of-bounds slice error when + transforming crafted input into a short destination buffer. +credits: + - 'Omkhar Arasaratnam (GitHub: omkhar)' +references: + - fix: https://go.dev/cl/793360 + - report: https://go.dev/issue/80112 +cve_metadata: + id: CVE-2026-56851 + cwe: 'CWE-787: Out-of-bounds Write' +source: + id: go-security-team +review_status: REVIEWED