data/reports: add 6 reports - data/reports/GO-2026-6348.yaml - data/reports/GO-2026-6356.yaml - data/reports/GO-2026-6366.yaml - data/reports/GO-2026-6372.yaml - data/reports/GO-2026-6441.yaml - data/reports/GO-2026-6443.yaml Fixes golang/vulndb#6348 Fixes golang/vulndb#6356 Fixes golang/vulndb#6366 Fixes golang/vulndb#6372 Fixes golang/vulndb#6441 Fixes golang/vulndb#6443 Change-Id: Id22a361c21a78aa0eb95d0b7d6fc05cf0d11e61a Reviewed-on: https://go-review.googlesource.com/c/vulndb/+/830784 Reviewed-by: Neal Patel <neal@golang.org> Reviewed-by: Nicholas Husin <husin@google.com> Auto-Submit: Ian Alexander <jitsu@google.com> Reviewed-by: Nicholas Husin <nsh@golang.org> LUCI-TryBot-Result: golang-scoped@luci-project-accounts.iam.gserviceaccount.com <golang-scoped@luci-project-accounts.iam.gserviceaccount.com>
diff --git a/data/osv/GO-2026-6348.json b/data/osv/GO-2026-6348.json new file mode 100644 index 0000000..5b9611f --- /dev/null +++ b/data/osv/GO-2026-6348.json
@@ -0,0 +1,107 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6348", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-84304", + "GHSA-vp52-pcj8-j9qc" + ], + "summary": "Heap Memory Exhaustion (OOM) via HTTP/2 DATA Frame Fragmentation in google.golang.org/grpc", + "details": "Heap Memory Exhaustion (OOM) via HTTP/2 DATA Frame Fragmentation in google.golang.org/grpc", + "affected": [ + { + "package": { + "name": "google.golang.org/grpc", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.83.1" + } + ] + } + ], + "ecosystem_specific": { + "imports": [ + { + "path": "google.golang.org/grpc/internal/transport", + "symbols": [ + "ClientStream.Close", + "ClientStream.Header", + "ClientStream.Read", + "ClientStream.RecvCompress", + "ClientStream.TrailersOnly", + "NewHTTP2Client", + "NewServerTransport", + "ServerStream.Read", + "Stream.ReadMessageHeader", + "http2Client.Close", + "http2Client.GracefulClose", + "http2Client.NewStream", + "http2Client.newStream", + "http2Server.Close", + "http2Server.HandleStreams", + "http2Server.operateHeaders", + "recvBuffer.init", + "recvBuffer.load", + "recvBuffer.put", + "recvBufferReader.Read", + "recvBufferReader.ReadMessageHeader", + "serverHandlerTransport.HandleStreams", + "transportReader.Read", + "transportReader.ReadMessageHeader" + ] + }, + { + "path": "google.golang.org/grpc/mem", + "symbols": [ + "BufferSlice.MaterializeToBuffer", + "Copy", + "IsBelowBufferPoolingThreshold", + "NewBuffer", + "ReadAll", + "writer.Write" + ] + } + ] + } + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/grpc/grpc-go/security/advisories/GHSA-vp52-pcj8-j9qc" + }, + { + "type": "FIX", + "url": "https://github.com/grpc/grpc-go/commit/7354d9c8debb4bcf2225bf429857078de310c176" + }, + { + "type": "WEB", + "url": "https://github.com/grpc/grpc-go/commit/8cfeca0e1ee5ea0980dcc320e20240fa1079ec77" + }, + { + "type": "WEB", + "url": "https://github.com/grpc/grpc-go/pull/9331" + }, + { + "type": "WEB", + "url": "https://github.com/grpc/grpc-go/pull/9333" + }, + { + "type": "WEB", + "url": "https://github.com/grpc/grpc-go/releases/tag/v1.83.1" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6348", + "review_status": "REVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6356.json b/data/osv/GO-2026-6356.json new file mode 100644 index 0000000..732128c --- /dev/null +++ b/data/osv/GO-2026-6356.json
@@ -0,0 +1,105 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6356", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-65959", + "GHSA-mhc4-g3wh-cw7m" + ], + "summary": "Missing authorization on vttablet /debug/vrlog in vitess.io/vitess", + "details": "The vttablet /debug/vrlog HTTP endpoint streams live VReplication event data, including SQL statements and table row changes, without verifying authorization via acl.CheckAccessHTTP. An unauthenticated actor with network access to the debug endpoint can stream live replicated SQL data.", + "affected": [ + { + "package": { + "name": "vitess.io/vitess", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.23.6" + }, + { + "introduced": "0.24.0-rc1" + }, + { + "fixed": "0.24.3" + } + ] + } + ], + "ecosystem_specific": { + "imports": [ + { + "path": "vitess.io/vitess/go/vt/vttablet/tabletmanager/vreplication", + "symbols": [ + "AddStatusPart", + "Engine.Close", + "Engine.Exec", + "Engine.ExecWithDBA", + "Engine.Open", + "Engine.WaitForPos", + "InsertGenerator.AddRow", + "MatchTable", + "NewEngine", + "NewInsertGenerator", + "NewReplicaConnector", + "NewSimpleTestEngine", + "NewTestEngine", + "NewVrLogStats", + "ReplicaConnector.Close", + "ReplicaConnector.VStream", + "ReplicatorPlan.MarshalJSON", + "TablePlan.MarshalJSON", + "VrLogStats.Send", + "addHttpEndpoint", + "controller.Stop", + "externalConnector.Close", + "externalConnector.Get", + "mysqlConnector.VStream", + "mysqlConnector.VStreamRows", + "mysqlConnector.VStreamTables", + "relayLog.Fetch", + "relayLog.Send", + "tabletConnector.Open", + "vcopierCopyTaskState.String", + "vcopierCopyWorker.Close", + "vdbClient.AddQueryToTrxBatch", + "vdbClient.Begin", + "vdbClient.Commit", + "vdbClient.CommitTrxQueryBatch", + "vdbClient.Execute", + "vdbClient.ExecuteFetch", + "vdbClient.ExecuteTrxQueryBatch", + "vdbClient.ExecuteWithRetry", + "vdbClient.Retry", + "vdbClient.Rollback", + "vreplicator.Replicate", + "vrlogStatsHandler" + ] + } + ] + } + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/vitessio/vitess/security/advisories/GHSA-mhc4-g3wh-cw7m" + }, + { + "type": "FIX", + "url": "https://github.com/vitessio/vitess/pull/20467" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6356", + "review_status": "REVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6366.json b/data/osv/GO-2026-6366.json new file mode 100644 index 0000000..8afc056 --- /dev/null +++ b/data/osv/GO-2026-6366.json
@@ -0,0 +1,89 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6366", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-61625", + "GHSA-8q3c-rjr9-xxrp" + ], + "summary": "Path traversal via crafted backup part names escapes restore root in github.com/VictoriaMetrics/VictoriaMetrics", + "details": "Path traversal via crafted backup part names escapes restore root in github.com/VictoriaMetrics/VictoriaMetrics", + "affected": [ + { + "package": { + "name": "github.com/VictoriaMetrics/VictoriaMetrics", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.122.25" + }, + { + "introduced": "1.123.0" + }, + { + "fixed": "1.136.12" + }, + { + "introduced": "1.137.0" + }, + { + "fixed": "1.146.0" + } + ] + } + ], + "ecosystem_specific": { + "imports": [ + { + "path": "github.com/VictoriaMetrics/VictoriaMetrics/lib/backup/actions", + "symbols": [ + "Backup.Run", + "RemoteBackupCopy.Run", + "Restore.Run" + ] + }, + { + "path": "github.com/VictoriaMetrics/VictoriaMetrics/lib/backup/fslocal", + "symbols": [ + "FS.NewDirectWriteCloser" + ] + } + ] + } + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/VictoriaMetrics/VictoriaMetrics/security/advisories/GHSA-8q3c-rjr9-xxrp" + }, + { + "type": "FIX", + "url": "https://github.com/VictoriaMetrics/VictoriaMetrics/commit/710c920d6083327042a309e449fae4383617d817" + }, + { + "type": "WEB", + "url": "https://github.com/VictoriaMetrics/VictoriaMetrics/releases/tag/v1.122.25" + }, + { + "type": "WEB", + "url": "https://github.com/VictoriaMetrics/VictoriaMetrics/releases/tag/v1.136.12" + }, + { + "type": "WEB", + "url": "https://github.com/VictoriaMetrics/VictoriaMetrics/releases/tag/v1.146.0" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6366", + "review_status": "REVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6372.json b/data/osv/GO-2026-6372.json new file mode 100644 index 0000000..dcbbbdf --- /dev/null +++ b/data/osv/GO-2026-6372.json
@@ -0,0 +1,56 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6372", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-79921", + "GHSA-6c5v-hqjr-5xxp" + ], + "summary": "Potential Memory Exhaustion/Protocol Violation via Broker-Controlled Oversized Payload in github.com/rabbitmq/amqp091-go", + "details": "Potential Memory Exhaustion/Protocol Violation via Broker-Controlled Oversized Payload in github.com/rabbitmq/amqp091-go", + "affected": [ + { + "package": { + "name": "github.com/rabbitmq/amqp091-go", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.13.0" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/rabbitmq/amqp091-go/security/advisories/GHSA-6c5v-hqjr-5xxp" + }, + { + "type": "FIX", + "url": "https://github.com/rabbitmq/amqp091-go/commit/6beb7b51f59e46ddcf8066ad498dad32491d3be0" + }, + { + "type": "FIX", + "url": "https://github.com/rabbitmq/amqp091-go/pull/353" + }, + { + "type": "WEB", + "url": "https://github.com/rabbitmq/amqp091-go/releases/tag/v1.13.0" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6372", + "review_status": "REVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6441.json b/data/osv/GO-2026-6441.json new file mode 100644 index 0000000..86c5bfc --- /dev/null +++ b/data/osv/GO-2026-6441.json
@@ -0,0 +1,59 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6441", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-84303", + "GHSA-qc2q-p7wx-3px3" + ], + "summary": "Bypass of xDS RBAC HTTP filter header matching in google.golang.org/grpc", + "details": "In google.golang.org/grpc, the xDS RBAC HTTP filter does not lowercase header matcher names before evaluating them against incoming request metadata. When an RBAC policy defines rules (such as DENY) referencing headers with uppercase or mixed-case characters, the rule fails to match, causing authorization policies to fail open. Additionally, callers can evade gRFC A41 validation blocking \"grpc-\" prefixed headers and \":scheme\" via variations in casing.", + "affected": [ + { + "package": { + "name": "google.golang.org/grpc", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.83.1" + } + ] + } + ], + "ecosystem_specific": { + "imports": [ + { + "path": "google.golang.org/grpc/internal/xds/httpfilter/rbac", + "symbols": [ + "builder.ParseFilterConfig", + "builder.ParseFilterConfigOverride", + "parseConfig" + ] + } + ] + } + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/grpc/grpc-go/security/advisories/GHSA-qc2q-p7wx-3px3" + }, + { + "type": "FIX", + "url": "https://github.com/grpc/grpc-go/pull/9332" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6441", + "review_status": "REVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6443.json b/data/osv/GO-2026-6443.json new file mode 100644 index 0000000..20b2873 --- /dev/null +++ b/data/osv/GO-2026-6443.json
@@ -0,0 +1,80 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6443", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-84445", + "GHSA-2v4p-qf9q-27wj" + ], + "summary": "Server panic via missing authority or Host headers in google.golang.org/grpc", + "details": "In google.golang.org/grpc, servers configured with xDS routing can panic when processing requests that lack both :authority and Host headers. The HTTP/2 transport layer accepted requests missing these headers, and the xDS server routing interceptor attempted to index the empty authority slice, causing an unhandled panic and terminating the server.", + "affected": [ + { + "package": { + "name": "google.golang.org/grpc", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.82.2" + }, + { + "introduced": "1.83.0" + }, + { + "fixed": "1.83.2" + }, + { + "introduced": "1.84.0-dev" + }, + { + "fixed": "1.85.0-dev.0.20260825072537-93e31b48545e" + } + ] + } + ], + "ecosystem_specific": { + "imports": [ + { + "path": "google.golang.org/grpc/internal/transport", + "symbols": [ + "http2Server.HandleStreams", + "http2Server.operateHeaders" + ] + }, + { + "path": "google.golang.org/grpc/internal/xds/server", + "symbols": [ + "RouteAndProcess" + ] + } + ] + } + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/grpc/grpc-go/security/advisories/GHSA-2v4p-qf9q-27wj" + }, + { + "type": "REPORT", + "url": "https://github.com/grpc/grpc-go/issues/9354" + }, + { + "type": "FIX", + "url": "https://github.com/grpc/grpc-go/pull/9365" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6443", + "review_status": "REVIEWED" + } +} \ No newline at end of file
diff --git a/data/reports/GO-2026-6348.yaml b/data/reports/GO-2026-6348.yaml new file mode 100644 index 0000000..98039ae --- /dev/null +++ b/data/reports/GO-2026-6348.yaml
@@ -0,0 +1,61 @@ +id: GO-2026-6348 +modules: + - module: google.golang.org/grpc + versions: + - fixed: 1.83.1 + vulnerable_at: 1.83.0 + packages: + - package: google.golang.org/grpc/internal/transport + symbols: + - recvBuffer.load + - http2Server.operateHeaders + - recvBuffer.put + - serverHandlerTransport.HandleStreams + - recvBuffer.init + - http2Client.newStream + derived_symbols: + - ClientStream.Close + - ClientStream.Header + - ClientStream.Read + - ClientStream.RecvCompress + - ClientStream.TrailersOnly + - NewHTTP2Client + - NewServerTransport + - ServerStream.Read + - Stream.ReadMessageHeader + - http2Client.Close + - http2Client.GracefulClose + - http2Client.NewStream + - http2Server.Close + - http2Server.HandleStreams + - recvBufferReader.Read + - recvBufferReader.ReadMessageHeader + - transportReader.Read + - transportReader.ReadMessageHeader + - package: google.golang.org/grpc/mem + symbols: + - IsBelowBufferPoolingThreshold + derived_symbols: + - BufferSlice.MaterializeToBuffer + - Copy + - NewBuffer + - ReadAll + - writer.Write +summary: |- + Heap Memory Exhaustion (OOM) via HTTP/2 DATA Frame Fragmentation in + google.golang.org/grpc +cves: + - CVE-2026-84304 +ghsas: + - GHSA-vp52-pcj8-j9qc +references: + - advisory: https://github.com/grpc/grpc-go/security/advisories/GHSA-vp52-pcj8-j9qc + - fix: https://github.com/grpc/grpc-go/commit/7354d9c8debb4bcf2225bf429857078de310c176 + - web: https://github.com/grpc/grpc-go/commit/8cfeca0e1ee5ea0980dcc320e20240fa1079ec77 + - web: https://github.com/grpc/grpc-go/pull/9331 + - web: https://github.com/grpc/grpc-go/pull/9333 + - web: https://github.com/grpc/grpc-go/releases/tag/v1.83.1 +source: + id: GHSA-vp52-pcj8-j9qc + created: 2026-09-09T13:25:05.497543-04:00 +review_status: REVIEWED
diff --git a/data/reports/GO-2026-6356.yaml b/data/reports/GO-2026-6356.yaml new file mode 100644 index 0000000..1c95c78 --- /dev/null +++ b/data/reports/GO-2026-6356.yaml
@@ -0,0 +1,72 @@ +id: GO-2026-6356 +modules: + - module: vitess.io/vitess + versions: + - fixed: 0.23.6 + - introduced: 0.24.0-rc1 + - fixed: 0.24.3 + vulnerable_at: 0.24.2 + packages: + - package: vitess.io/vitess/go/vt/vttablet/tabletmanager/vreplication + symbols: + - NewVrLogStats + - VrLogStats.Send + - addHttpEndpoint + - vrlogStatsHandler + derived_symbols: + - AddStatusPart + - Engine.Close + - Engine.Exec + - Engine.ExecWithDBA + - Engine.Open + - Engine.WaitForPos + - InsertGenerator.AddRow + - MatchTable + - NewEngine + - NewInsertGenerator + - NewReplicaConnector + - NewSimpleTestEngine + - NewTestEngine + - ReplicaConnector.Close + - ReplicaConnector.VStream + - ReplicatorPlan.MarshalJSON + - TablePlan.MarshalJSON + - controller.Stop + - externalConnector.Close + - externalConnector.Get + - mysqlConnector.VStream + - mysqlConnector.VStreamRows + - mysqlConnector.VStreamTables + - relayLog.Fetch + - relayLog.Send + - tabletConnector.Open + - vcopierCopyTaskState.String + - vcopierCopyWorker.Close + - vdbClient.AddQueryToTrxBatch + - vdbClient.Begin + - vdbClient.Commit + - vdbClient.CommitTrxQueryBatch + - vdbClient.Execute + - vdbClient.ExecuteFetch + - vdbClient.ExecuteTrxQueryBatch + - vdbClient.ExecuteWithRetry + - vdbClient.Retry + - vdbClient.Rollback + - vreplicator.Replicate +summary: Missing authorization on vttablet /debug/vrlog in vitess.io/vitess +description: |- + The vttablet /debug/vrlog HTTP endpoint streams live VReplication event data, + including SQL statements and table row changes, without verifying + authorization via acl.CheckAccessHTTP. An unauthenticated actor with network + access to the debug endpoint can stream live replicated SQL data. +cves: + - CVE-2026-65959 +ghsas: + - GHSA-mhc4-g3wh-cw7m +references: + - advisory: https://github.com/vitessio/vitess/security/advisories/GHSA-mhc4-g3wh-cw7m + - fix: https://github.com/vitessio/vitess/pull/20467 +source: + id: GHSA-mhc4-g3wh-cw7m + created: 2026-09-09T13:24:30.087722-04:00 +review_status: REVIEWED
diff --git a/data/reports/GO-2026-6366.yaml b/data/reports/GO-2026-6366.yaml new file mode 100644 index 0000000..b7212de --- /dev/null +++ b/data/reports/GO-2026-6366.yaml
@@ -0,0 +1,37 @@ +id: GO-2026-6366 +modules: + - module: github.com/VictoriaMetrics/VictoriaMetrics + versions: + - fixed: 1.122.25 + - introduced: 1.123.0 + - fixed: 1.136.12 + - introduced: 1.137.0 + - fixed: 1.146.0 + vulnerable_at: 1.146.0-cluster + packages: + - package: github.com/VictoriaMetrics/VictoriaMetrics/lib/backup/actions + symbols: + - Restore.Run + derived_symbols: + - Backup.Run + - RemoteBackupCopy.Run + - package: github.com/VictoriaMetrics/VictoriaMetrics/lib/backup/fslocal + symbols: + - FS.NewDirectWriteCloser +summary: |- + Path traversal via crafted backup part names escapes restore root in + github.com/VictoriaMetrics/VictoriaMetrics +cves: + - CVE-2026-61625 +ghsas: + - GHSA-8q3c-rjr9-xxrp +references: + - advisory: https://github.com/VictoriaMetrics/VictoriaMetrics/security/advisories/GHSA-8q3c-rjr9-xxrp + - fix: https://github.com/VictoriaMetrics/VictoriaMetrics/commit/710c920d6083327042a309e449fae4383617d817 + - web: https://github.com/VictoriaMetrics/VictoriaMetrics/releases/tag/v1.122.25 + - web: https://github.com/VictoriaMetrics/VictoriaMetrics/releases/tag/v1.136.12 + - web: https://github.com/VictoriaMetrics/VictoriaMetrics/releases/tag/v1.146.0 +source: + id: GHSA-8q3c-rjr9-xxrp + created: 2026-09-09T13:22:04.354513-04:00 +review_status: REVIEWED
diff --git a/data/reports/GO-2026-6372.yaml b/data/reports/GO-2026-6372.yaml new file mode 100644 index 0000000..08b02af --- /dev/null +++ b/data/reports/GO-2026-6372.yaml
@@ -0,0 +1,24 @@ +id: GO-2026-6372 +modules: + - module: github.com/rabbitmq/amqp091-go + versions: + - fixed: 1.13.0 + vulnerable_at: 1.12.0 +summary: |- + Potential Memory Exhaustion/Protocol Violation via Broker-Controlled + Oversized Payload in github.com/rabbitmq/amqp091-go +cves: + - CVE-2026-79921 +ghsas: + - GHSA-6c5v-hqjr-5xxp +references: + - advisory: https://github.com/rabbitmq/amqp091-go/security/advisories/GHSA-6c5v-hqjr-5xxp + - fix: https://github.com/rabbitmq/amqp091-go/commit/6beb7b51f59e46ddcf8066ad498dad32491d3be0 + - fix: https://github.com/rabbitmq/amqp091-go/pull/353 + - web: https://github.com/rabbitmq/amqp091-go/releases/tag/v1.13.0 +notes: + - create: failed to auto-populate symbols +source: + id: GHSA-6c5v-hqjr-5xxp + created: 2026-09-09T13:21:03.193889-04:00 +review_status: REVIEWED
diff --git a/data/reports/GO-2026-6441.yaml b/data/reports/GO-2026-6441.yaml new file mode 100644 index 0000000..b498d92 --- /dev/null +++ b/data/reports/GO-2026-6441.yaml
@@ -0,0 +1,33 @@ +id: GO-2026-6441 +modules: + - module: google.golang.org/grpc + versions: + - fixed: 1.83.1 + vulnerable_at: 1.83.0 + packages: + - package: google.golang.org/grpc/internal/xds/httpfilter/rbac + symbols: + - parseConfig + derived_symbols: + - builder.ParseFilterConfig + - builder.ParseFilterConfigOverride +summary: Bypass of xDS RBAC HTTP filter header matching in google.golang.org/grpc +description: |- + In google.golang.org/grpc, the xDS RBAC HTTP filter does not lowercase + header matcher names before evaluating them against incoming request + metadata. When an RBAC policy defines rules (such as DENY) referencing + headers with uppercase or mixed-case characters, the rule fails to match, + causing authorization policies to fail open. Additionally, callers can evade + gRFC A41 validation blocking "grpc-" prefixed headers and ":scheme" via + variations in casing. +cves: + - CVE-2026-84303 +ghsas: + - GHSA-qc2q-p7wx-3px3 +references: + - advisory: https://github.com/grpc/grpc-go/security/advisories/GHSA-qc2q-p7wx-3px3 + - fix: https://github.com/grpc/grpc-go/pull/9332 +source: + id: GHSA-qc2q-p7wx-3px3 + created: 2026-09-09T13:13:37.378756-04:00 +review_status: REVIEWED
diff --git a/data/reports/GO-2026-6443.yaml b/data/reports/GO-2026-6443.yaml new file mode 100644 index 0000000..a7f22fc --- /dev/null +++ b/data/reports/GO-2026-6443.yaml
@@ -0,0 +1,38 @@ +id: GO-2026-6443 +modules: + - module: google.golang.org/grpc + versions: + - fixed: 1.82.2 + - introduced: 1.83.0 + - fixed: 1.83.2 + - introduced: 1.84.0-dev + - fixed: 1.85.0-dev.0.20260825072537-93e31b48545e + vulnerable_at: 1.85.0-dev + packages: + - package: google.golang.org/grpc/internal/transport + symbols: + - http2Server.operateHeaders + derived_symbols: + - http2Server.HandleStreams + - package: google.golang.org/grpc/internal/xds/server + symbols: + - RouteAndProcess +summary: Server panic via missing authority or Host headers in google.golang.org/grpc +description: |- + In google.golang.org/grpc, servers configured with xDS routing can panic when + processing requests that lack both :authority and Host headers. The HTTP/2 + transport layer accepted requests missing these headers, and the xDS server + routing interceptor attempted to index the empty authority slice, causing an + unhandled panic and terminating the server. +cves: + - CVE-2026-84445 +ghsas: + - GHSA-2v4p-qf9q-27wj +references: + - advisory: https://github.com/grpc/grpc-go/security/advisories/GHSA-2v4p-qf9q-27wj + - report: https://github.com/grpc/grpc-go/issues/9354 + - fix: https://github.com/grpc/grpc-go/pull/9365 +source: + id: GHSA-2v4p-qf9q-27wj + created: 2026-09-09T13:13:25.064202-04:00 +review_status: REVIEWED