data/reports: add 25 reports

  - data/reports/GO-2026-6253.yaml
  - data/reports/GO-2026-6254.yaml
  - data/reports/GO-2026-6258.yaml
  - data/reports/GO-2026-6259.yaml
  - data/reports/GO-2026-6260.yaml
  - data/reports/GO-2026-6262.yaml
  - data/reports/GO-2026-6263.yaml
  - data/reports/GO-2026-6265.yaml
  - data/reports/GO-2026-6266.yaml
  - data/reports/GO-2026-6267.yaml
  - data/reports/GO-2026-6270.yaml
  - data/reports/GO-2026-6271.yaml
  - data/reports/GO-2026-6272.yaml
  - data/reports/GO-2026-6277.yaml
  - data/reports/GO-2026-6279.yaml
  - data/reports/GO-2026-6280.yaml
  - data/reports/GO-2026-6281.yaml
  - data/reports/GO-2026-6282.yaml
  - data/reports/GO-2026-6283.yaml
  - data/reports/GO-2026-6284.yaml
  - data/reports/GO-2026-6285.yaml
  - data/reports/GO-2026-6286.yaml
  - data/reports/GO-2026-6287.yaml
  - data/reports/GO-2026-6288.yaml
  - data/reports/GO-2026-6289.yaml

Fixes golang/vulndb#6253
Fixes golang/vulndb#6254
Fixes golang/vulndb#6258
Fixes golang/vulndb#6259
Fixes golang/vulndb#6260
Fixes golang/vulndb#6262
Fixes golang/vulndb#6263
Fixes golang/vulndb#6265
Fixes golang/vulndb#6266
Fixes golang/vulndb#6267
Fixes golang/vulndb#6270
Fixes golang/vulndb#6271
Fixes golang/vulndb#6272
Fixes golang/vulndb#6277
Fixes golang/vulndb#6279
Fixes golang/vulndb#6280
Fixes golang/vulndb#6281
Fixes golang/vulndb#6282
Fixes golang/vulndb#6283
Fixes golang/vulndb#6284
Fixes golang/vulndb#6285
Fixes golang/vulndb#6286
Fixes golang/vulndb#6287
Fixes golang/vulndb#6288
Fixes golang/vulndb#6289

Change-Id: I1678ea89962a128e730bd132d91ba0a5983d7acb
Reviewed-on: https://go-review.googlesource.com/c/vulndb/+/820820
LUCI-TryBot-Result: golang-scoped@luci-project-accounts.iam.gserviceaccount.com <golang-scoped@luci-project-accounts.iam.gserviceaccount.com>
Reviewed-by: Nicholas Husin <nsh@golang.org>
Auto-Submit: Ian Alexander <jitsu@google.com>
Reviewed-by: Nicholas Husin <husin@google.com>
diff --git a/data/osv/GO-2026-6253.json b/data/osv/GO-2026-6253.json
new file mode 100644
index 0000000..f6b65a9
--- /dev/null
+++ b/data/osv/GO-2026-6253.json
@@ -0,0 +1,68 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6253",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-17106",
+    "GHSA-hfg8-hc9c-6c3h"
+  ],
+  "summary": "moby/go-archive: Crafted tar archive can write outside the extraction directory in github.com/moby/go-archive",
+  "details": "moby/go-archive: Crafted tar archive can write outside the extraction directory in github.com/moby/go-archive",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/moby/go-archive",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "0.3.0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/moby/go-archive/security/advisories/GHSA-hfg8-hc9c-6c3h"
+    },
+    {
+      "type": "WEB",
+      "url": "https://docs.docker.com/desktop/release-notes/#4860"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/bikini/exploitarium/tree/main/docker-cp-copyout-destination-escape"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/docker/cli/releases/tag/v29.7.0"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/moby/moby/issues/52948"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/moby/moby/releases/tag/docker-v29.7.0"
+    },
+    {
+      "type": "WEB",
+      "url": "https://www.imperva.com/blog/copyescape-taking-over-docker-hosts-with-docker-cp"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6253",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6254.json b/data/osv/GO-2026-6254.json
new file mode 100644
index 0000000..ad4511e
--- /dev/null
+++ b/data/osv/GO-2026-6254.json
@@ -0,0 +1,48 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6254",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-53941",
+    "GHSA-vjhx-2cqw-3q6q"
+  ],
+  "summary": "Uprobe gadgets: unprivileged container's ld.so.cache causes high CPU utilization and container startup DoS in github.com/inspektor-gadget/inspektor-gadget",
+  "details": "Uprobe gadgets: unprivileged container's ld.so.cache causes high CPU utilization and container startup DoS in github.com/inspektor-gadget/inspektor-gadget",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/inspektor-gadget/inspektor-gadget",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0.27.0"
+            },
+            {
+              "fixed": "0.53.1"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/inspektor-gadget/inspektor-gadget/security/advisories/GHSA-vjhx-2cqw-3q6q"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/inspektor-gadget/inspektor-gadget/releases/tag/v0.53.1"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6254",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6258.json b/data/osv/GO-2026-6258.json
new file mode 100644
index 0000000..f934b24
--- /dev/null
+++ b/data/osv/GO-2026-6258.json
@@ -0,0 +1,56 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6258",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-45404",
+    "GHSA-42cj-99w8-cp2p"
+  ],
+  "summary": "OpenTelemetry-Go: Unsynchronized baggage map can panic under concurrent access in go.opentelemetry.io/otel/bridge/opentracing",
+  "details": "OpenTelemetry-Go: Unsynchronized baggage map can panic under concurrent access in go.opentelemetry.io/otel/bridge/opentracing",
+  "affected": [
+    {
+      "package": {
+        "name": "go.opentelemetry.io/otel/bridge/opentracing",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0.11.0"
+            },
+            {
+              "fixed": "1.45.0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/open-telemetry/opentelemetry-go/security/advisories/GHSA-42cj-99w8-cp2p"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/open-telemetry/opentelemetry-go/commit/93a693edeed0e07ce5ebd1dfe67af42d1e2055d8"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/open-telemetry/opentelemetry-go/pull/8693"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/open-telemetry/opentelemetry-go/releases/tag/v1.45.0"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6258",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6259.json b/data/osv/GO-2026-6259.json
new file mode 100644
index 0000000..706cfe2
--- /dev/null
+++ b/data/osv/GO-2026-6259.json
@@ -0,0 +1,48 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6259",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-32637",
+    "GHSA-j2g6-362q-6qc6"
+  ],
+  "summary": "Velero vulnerable to file path traversal when extracting from backup's tarball in github.com/vmware-tanzu/velero",
+  "details": "Velero vulnerable to file path traversal when extracting from backup's tarball in github.com/vmware-tanzu/velero",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/vmware-tanzu/velero",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "1.18.1"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/velero-io/velero/security/advisories/GHSA-j2g6-362q-6qc6"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/securego/gosec/issues/324"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6259",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6260.json b/data/osv/GO-2026-6260.json
new file mode 100644
index 0000000..a8e5f66
--- /dev/null
+++ b/data/osv/GO-2026-6260.json
@@ -0,0 +1,52 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6260",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-55149",
+    "GHSA-qqff-5854-px68"
+  ],
+  "summary": "vouch-proxy has an Unbounded Multipart Cookie Allocation DoS in github.com/vouch/vouch-proxy",
+  "details": "vouch-proxy has an Unbounded Multipart Cookie Allocation DoS in github.com/vouch/vouch-proxy",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/vouch/vouch-proxy",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "0.48.0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/vouch/vouch-proxy/security/advisories/GHSA-qqff-5854-px68"
+    },
+    {
+      "type": "FIX",
+      "url": "https://github.com/vouch/vouch-proxy/commit/fa18ce30ba50a4863a436acad044c22965329c4f"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/vouch/vouch-proxy/releases/tag/v0.48.0"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6260",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6262.json b/data/osv/GO-2026-6262.json
new file mode 100644
index 0000000..d890ed8
--- /dev/null
+++ b/data/osv/GO-2026-6262.json
@@ -0,0 +1,69 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6262",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "GHSA-22w5-2fxg-vrwx"
+  ],
+  "summary": "OpenTofu has high CPU usage when using K8S remote state backend or when parsing specifically crafted TLS certificates from untrusted or compromised servers in github.com/opentofu/opentofu",
+  "details": "OpenTofu has high CPU usage when using K8S remote state backend or when parsing specifically crafted TLS certificates from untrusted or compromised servers in github.com/opentofu/opentofu",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/opentofu/opentofu",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "1.11.9"
+            },
+            {
+              "introduced": "1.12.0-beta1"
+            },
+            {
+              "fixed": "1.12.2"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/opentofu/opentofu/security/advisories/GHSA-22w5-2fxg-vrwx"
+    },
+    {
+      "type": "REPORT",
+      "url": "https://github.com/opentofu/opentofu/issues/4242"
+    },
+    {
+      "type": "REPORT",
+      "url": "https://github.com/opentofu/opentofu/issues/4243"
+    },
+    {
+      "type": "REPORT",
+      "url": "https://github.com/opentofu/opentofu/issues/4244"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/opentofu/opentofu/releases/tag/v1.11.9"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/opentofu/opentofu/releases/tag/v1.12.2"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6262",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6263.json b/data/osv/GO-2026-6263.json
new file mode 100644
index 0000000..24677c8
--- /dev/null
+++ b/data/osv/GO-2026-6263.json
@@ -0,0 +1,62 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6263",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-54168",
+    "GHSA-6f2p-296r-cc28"
+  ],
+  "summary": "Tekton Pipelines-as-Code: Unscoped GitHub App installation token allows unauthorized access to private repositories via remote task resolution in github.com/openshift-pipelines/pipelines-as-code",
+  "details": "Tekton Pipelines-as-Code: Unscoped GitHub App installation token allows unauthorized access to private repositories via remote task resolution in github.com/openshift-pipelines/pipelines-as-code",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/openshift-pipelines/pipelines-as-code",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "0.37.8"
+            },
+            {
+              "introduced": "0.38.0"
+            },
+            {
+              "fixed": "0.39.6"
+            },
+            {
+              "introduced": "0.40.0"
+            },
+            {
+              "fixed": "0.42.1"
+            },
+            {
+              "introduced": "0.43.0"
+            },
+            {
+              "fixed": "0.48.0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/tektoncd/pipelines-as-code/security/advisories/GHSA-6f2p-296r-cc28"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6263",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6265.json b/data/osv/GO-2026-6265.json
new file mode 100644
index 0000000..f9a6928
--- /dev/null
+++ b/data/osv/GO-2026-6265.json
@@ -0,0 +1,102 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6265",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "GHSA-8fxq-53rx-ph5f"
+  ],
+  "summary": "Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder",
+  "details": "Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/coder/coder",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    },
+    {
+      "package": {
+        "name": "github.com/coder/coder/v2",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "2.29.17"
+            },
+            {
+              "introduced": "2.30.0"
+            },
+            {
+              "fixed": "2.32.7"
+            },
+            {
+              "introduced": "2.33.0"
+            },
+            {
+              "fixed": "2.33.8"
+            },
+            {
+              "introduced": "2.34.0"
+            },
+            {
+              "fixed": "2.34.2"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/coder/coder/security/advisories/GHSA-8fxq-53rx-ph5f"
+    },
+    {
+      "type": "FIX",
+      "url": "https://github.com/coder/coder/commit/35a7dc8ab9c7f15ce05d963947823ee31224512f"
+    },
+    {
+      "type": "FIX",
+      "url": "https://github.com/coder/coder/pull/26205"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/coder/coder/releases/tag/v2.29.17"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/coder/coder/releases/tag/v2.32.7"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/coder/coder/releases/tag/v2.33.8"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/coder/coder/releases/tag/v2.34.2"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6265",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6266.json b/data/osv/GO-2026-6266.json
new file mode 100644
index 0000000..344237f
--- /dev/null
+++ b/data/osv/GO-2026-6266.json
@@ -0,0 +1,62 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6266",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-54167",
+    "GHSA-f5f4-3hh4-f54m"
+  ],
+  "summary": "Pipelines-as-Code GitHub App token request can be redirected via untrusted Enterprise Host header in github.com/openshift-pipelines/pipelines-as-code",
+  "details": "Pipelines-as-Code GitHub App token request can be redirected via untrusted Enterprise Host header in github.com/openshift-pipelines/pipelines-as-code",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/openshift-pipelines/pipelines-as-code",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "0.37.8"
+            },
+            {
+              "introduced": "0.38.0"
+            },
+            {
+              "fixed": "0.39.6"
+            },
+            {
+              "introduced": "0.40.0"
+            },
+            {
+              "fixed": "0.42.1"
+            },
+            {
+              "introduced": "0.43.0"
+            },
+            {
+              "fixed": "0.48.0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/tektoncd/pipelines-as-code/security/advisories/GHSA-f5f4-3hh4-f54m"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6266",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6267.json b/data/osv/GO-2026-6267.json
new file mode 100644
index 0000000..915c6b9
--- /dev/null
+++ b/data/osv/GO-2026-6267.json
@@ -0,0 +1,102 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6267",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "GHSA-h58c-xccx-75m3"
+  ],
+  "summary": "Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder",
+  "details": "Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/coder/coder",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    },
+    {
+      "package": {
+        "name": "github.com/coder/coder/v2",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "2.29.17"
+            },
+            {
+              "introduced": "2.30.0"
+            },
+            {
+              "fixed": "2.32.7"
+            },
+            {
+              "introduced": "2.33.0"
+            },
+            {
+              "fixed": "2.33.8"
+            },
+            {
+              "introduced": "2.34.0"
+            },
+            {
+              "fixed": "2.34.2"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/coder/coder/security/advisories/GHSA-h58c-xccx-75m3"
+    },
+    {
+      "type": "FIX",
+      "url": "https://github.com/coder/coder/commit/ec19bc41d80568c0eb9f74b526e8cc8ffbe3be9a"
+    },
+    {
+      "type": "FIX",
+      "url": "https://github.com/coder/coder/pull/25804"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/coder/coder/releases/tag/v2.29.17"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/coder/coder/releases/tag/v2.32.7"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/coder/coder/releases/tag/v2.33.8"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/coder/coder/releases/tag/v2.34.2"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6267",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6270.json b/data/osv/GO-2026-6270.json
new file mode 100644
index 0000000..feb1ead
--- /dev/null
+++ b/data/osv/GO-2026-6270.json
@@ -0,0 +1,52 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6270",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-54162",
+    "GHSA-x3g7-qrwc-f6c5"
+  ],
+  "summary": "Ember has unneutralized terminal escape/control sequences from Caddy logs injected into the operator's TUI in github.com/alexandre-daubois/ember",
+  "details": "Ember has unneutralized terminal escape/control sequences from Caddy logs injected into the operator's TUI in github.com/alexandre-daubois/ember",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/alexandre-daubois/ember",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "1.4.2"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/alexandre-daubois/ember/security/advisories/GHSA-x3g7-qrwc-f6c5"
+    },
+    {
+      "type": "FIX",
+      "url": "https://github.com/alexandre-daubois/ember/commit/fcb7160e58dba58d6f9b5033cc312fdedc8c9f6b"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/alexandre-daubois/ember/releases/tag/v1.4.2"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6270",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6271.json b/data/osv/GO-2026-6271.json
new file mode 100644
index 0000000..3cebd10
--- /dev/null
+++ b/data/osv/GO-2026-6271.json
@@ -0,0 +1,52 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6271",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-67448",
+    "GHSA-8r62-w5wh-fc5m"
+  ],
+  "summary": "Mailpit: WebSocket origin check bypass via percent-encoded path (regression of CVE-2026-22689) in github.com/axllent/mailpit",
+  "details": "Mailpit: WebSocket origin check bypass via percent-encoded path (regression of CVE-2026-22689) in github.com/axllent/mailpit",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/axllent/mailpit",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "1.29.0"
+            },
+            {
+              "fixed": "1.30.6"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/axllent/mailpit/security/advisories/GHSA-8r62-w5wh-fc5m"
+    },
+    {
+      "type": "FIX",
+      "url": "https://github.com/axllent/mailpit/commit/fbe5e006c3f1682b819df58b4a932d7a84920be9"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/axllent/mailpit/releases/tag/v1.30.6"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6271",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6272.json b/data/osv/GO-2026-6272.json
new file mode 100644
index 0000000..c23168a
--- /dev/null
+++ b/data/osv/GO-2026-6272.json
@@ -0,0 +1,52 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6272",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-67447",
+    "GHSA-r553-m4fv-5v97"
+  ],
+  "summary": "Mailpit: SMTP DATA line reader buffers over-limit input before size enforcement in github.com/axllent/mailpit",
+  "details": "Mailpit: SMTP DATA line reader buffers over-limit input before size enforcement in github.com/axllent/mailpit",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/axllent/mailpit",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "1.30.0"
+            },
+            {
+              "fixed": "1.30.5"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/axllent/mailpit/security/advisories/GHSA-r553-m4fv-5v97"
+    },
+    {
+      "type": "FIX",
+      "url": "https://github.com/axllent/mailpit/commit/8720c6bd8281fc00d458081908f1dbef8e59a98c"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/axllent/mailpit/releases/tag/v1.30.5"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6272",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6277.json b/data/osv/GO-2026-6277.json
new file mode 100644
index 0000000..397bc0b
--- /dev/null
+++ b/data/osv/GO-2026-6277.json
@@ -0,0 +1,55 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6277",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "GHSA-4ph6-mjv7-3fq6"
+  ],
+  "summary": "netfoil vulnerable to improper handling of untrusted DoH response data in github.com/tinfoil-factory/netfoil",
+  "details": "netfoil vulnerable to improper handling of untrusted DoH response data in github.com/tinfoil-factory/netfoil",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/tinfoil-factory/netfoil",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "0.5.0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/tinfoil-factory/netfoil/security/advisories/GHSA-4ph6-mjv7-3fq6"
+    },
+    {
+      "type": "FIX",
+      "url": "https://github.com/tinfoil-factory/netfoil/commit/58cfb0cb16b824e02bf53c2d67707e5e4bd9f59b"
+    },
+    {
+      "type": "FIX",
+      "url": "https://github.com/tinfoil-factory/netfoil/commit/817f664c61aa64cbe0dbfcdfc05c16602b422e5b"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/tinfoil-factory/netfoil/releases/tag/v0.5.0"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6277",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6279.json b/data/osv/GO-2026-6279.json
new file mode 100644
index 0000000..e4bc1a8
--- /dev/null
+++ b/data/osv/GO-2026-6279.json
@@ -0,0 +1,174 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6279",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-6046",
+    "GHSA-3vmp-whvv-5v9v"
+  ],
+  "summary": "Mattermost doesn't validate that a username returned during bot registration belongs to a bot account in github.com/mattermost/mattermost-server",
+  "details": "Mattermost doesn't validate that a username returned during bot registration belongs to a bot account in github.com/mattermost/mattermost-server",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/mattermost/mattermost-server",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "10.11.0+incompatible"
+            },
+            {
+              "fixed": "10.11.17+incompatible"
+            },
+            {
+              "introduced": "11.5.0+incompatible"
+            },
+            {
+              "fixed": "11.5.5+incompatible"
+            },
+            {
+              "introduced": "11.6.0+incompatible"
+            },
+            {
+              "fixed": "11.6.1+incompatible"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    },
+    {
+      "package": {
+        "name": "github.com/mattermost/mattermost-server/v5",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    },
+    {
+      "package": {
+        "name": "github.com/mattermost/mattermost-server/v6",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    },
+    {
+      "package": {
+        "name": "github.com/mattermost/mattermost/server/v8",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "8.0.0-20250731163400-5b955468ea1e"
+            },
+            {
+              "fixed": "8.0.0-20260428151657-c79c3831061a"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/advisories/GHSA-3vmp-whvv-5v9v"
+    },
+    {
+      "type": "ADVISORY",
+      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6046"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/mattermost/mattermost/commit/3be10297c14d272f273d747af70728f9d03c60ec"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/mattermost/mattermost/commit/98f9778cec1e7f3d97b3d4692fb91f8e7b659972"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/mattermost/mattermost/commit/aba9339a24d4b287edd77377c19901d6e341bb96"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/mattermost/mattermost/commit/c79c3831061a0880c0962c7d567c9e24dd35f44c"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/mattermost/mattermost/commit/f706d1f01e6dfe62cab86c1d257f237daa78106a"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/mattermost/mattermost/pull/36064"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/mattermost/mattermost/pull/36305"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/mattermost/mattermost/pull/36317"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/mattermost/mattermost/pull/36318"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/mattermost/mattermost/pull/36320"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/mattermost/mattermost/releases/tag/v10.11.16"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/mattermost/mattermost/releases/tag/v11.5.5"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/mattermost/mattermost/releases/tag/v11.6.2"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/mattermost/mattermost/releases/tag/v11.7.0"
+    },
+    {
+      "type": "WEB",
+      "url": "https://mattermost.com/security-updates"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6279",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6280.json b/data/osv/GO-2026-6280.json
new file mode 100644
index 0000000..cc0536e
--- /dev/null
+++ b/data/osv/GO-2026-6280.json
@@ -0,0 +1,174 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6280",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-7387",
+    "GHSA-6hxm-w4hv-vgvw"
+  ],
+  "summary": "Mattermost doesn't require role-management authorization when setting the scheme_admin flag on group syncable link and patch endpoints in github.com/mattermost/mattermost-server",
+  "details": "Mattermost doesn't require role-management authorization when setting the scheme_admin flag on group syncable link and patch endpoints in github.com/mattermost/mattermost-server",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/mattermost/mattermost-server",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "10.11.0+incompatible"
+            },
+            {
+              "fixed": "10.11.17+incompatible"
+            },
+            {
+              "introduced": "11.5.0+incompatible"
+            },
+            {
+              "fixed": "11.5.5+incompatible"
+            },
+            {
+              "introduced": "11.6.0+incompatible"
+            },
+            {
+              "fixed": "11.6.1+incompatible"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    },
+    {
+      "package": {
+        "name": "github.com/mattermost/mattermost-server/v5",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    },
+    {
+      "package": {
+        "name": "github.com/mattermost/mattermost-server/v6",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    },
+    {
+      "package": {
+        "name": "github.com/mattermost/mattermost/server/v8",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "8.0.0-20250731163400-5b955468ea1e"
+            },
+            {
+              "fixed": "8.0.0-20260506065351-202d125afa87"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/advisories/GHSA-6hxm-w4hv-vgvw"
+    },
+    {
+      "type": "ADVISORY",
+      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-7387"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/mattermost/mattermost/commit/1ce2484a00c9821ee19708d2c46720e4855033a9"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/mattermost/mattermost/commit/202d125afa87fe39611686850fd82590c99ca344"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/mattermost/mattermost/commit/8c72083414e675c97987374395e36d1f36b4bd8a"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/mattermost/mattermost/commit/a9e574a82633915f22071f0d7ca2b006f249ec2a"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/mattermost/mattermost/commit/d5f29c8ebbeb04460d16d9e2635ce50deeb78428"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/mattermost/mattermost/pull/36316"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/mattermost/mattermost/pull/36423"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/mattermost/mattermost/pull/36431"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/mattermost/mattermost/pull/36432"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/mattermost/mattermost/pull/36434"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/mattermost/mattermost/releases/tag/v10.11.16"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/mattermost/mattermost/releases/tag/v11.5.5"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/mattermost/mattermost/releases/tag/v11.6.2"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/mattermost/mattermost/releases/tag/v11.7.0"
+    },
+    {
+      "type": "WEB",
+      "url": "https://mattermost.com/security-updates"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6280",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6281.json b/data/osv/GO-2026-6281.json
new file mode 100644
index 0000000..1ec031d
--- /dev/null
+++ b/data/osv/GO-2026-6281.json
@@ -0,0 +1,174 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6281",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-6961",
+    "GHSA-8qq9-cqj8-82w4"
+  ],
+  "summary": "Mattermost doesn't sanitize FileInfo.Name received from federated peers during shared channel file sync in github.com/mattermost/mattermost-server",
+  "details": "Mattermost doesn't sanitize FileInfo.Name received from federated peers during shared channel file sync in github.com/mattermost/mattermost-server",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/mattermost/mattermost-server",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "10.11.0+incompatible"
+            },
+            {
+              "fixed": "10.11.17+incompatible"
+            },
+            {
+              "introduced": "11.5.0+incompatible"
+            },
+            {
+              "fixed": "11.5.5+incompatible"
+            },
+            {
+              "introduced": "11.6.0+incompatible"
+            },
+            {
+              "fixed": "11.6.1+incompatible"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    },
+    {
+      "package": {
+        "name": "github.com/mattermost/mattermost-server/v5",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    },
+    {
+      "package": {
+        "name": "github.com/mattermost/mattermost-server/v6",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    },
+    {
+      "package": {
+        "name": "github.com/mattermost/mattermost/server/v8",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "8.0.0-20250731163400-5b955468ea1e"
+            },
+            {
+              "fixed": "8.0.0-20260423180926-c021eeaff8f0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/advisories/GHSA-8qq9-cqj8-82w4"
+    },
+    {
+      "type": "ADVISORY",
+      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6961"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/mattermost/mattermost/commit/61d68d2d6ee81a5919597d91c736c502d7156859"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/mattermost/mattermost/commit/a0056ed68d95f64d7c4586985e7b7f16b96b3bec"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/mattermost/mattermost/commit/a9f3868e1eee9ec61855cd7277f39937385efffd"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/mattermost/mattermost/commit/c021eeaff8f003034ab40f82c552cc26a710a8fd"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/mattermost/mattermost/commit/c896a63dc44c2f9c081a0a15bfddc4e6eb50e753"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/mattermost/mattermost/pull/36223"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/mattermost/mattermost/pull/36251"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/mattermost/mattermost/pull/36252"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/mattermost/mattermost/pull/36253"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/mattermost/mattermost/pull/36255"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/mattermost/mattermost/releases/tag/v10.11.16"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/mattermost/mattermost/releases/tag/v11.5.5"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/mattermost/mattermost/releases/tag/v11.6.2"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/mattermost/mattermost/releases/tag/v11.7.0"
+    },
+    {
+      "type": "WEB",
+      "url": "https://mattermost.com/security-updates"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6281",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6282.json b/data/osv/GO-2026-6282.json
new file mode 100644
index 0000000..3417b38
--- /dev/null
+++ b/data/osv/GO-2026-6282.json
@@ -0,0 +1,174 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6282",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-7184",
+    "GHSA-9p44-r552-4wp9"
+  ],
+  "summary": "Mattermost doesn't sanitize the Remote Cluster API response on PATCH operations in github.com/mattermost/mattermost-server",
+  "details": "Mattermost doesn't sanitize the Remote Cluster API response on PATCH operations in github.com/mattermost/mattermost-server",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/mattermost/mattermost-server",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "10.11.0+incompatible"
+            },
+            {
+              "fixed": "10.11.16+incompatible"
+            },
+            {
+              "introduced": "11.5.0+incompatible"
+            },
+            {
+              "fixed": "11.5.5+incompatible"
+            },
+            {
+              "introduced": "11.6.0+incompatible"
+            },
+            {
+              "fixed": "11.6.1+incompatible"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    },
+    {
+      "package": {
+        "name": "github.com/mattermost/mattermost-server/v5",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    },
+    {
+      "package": {
+        "name": "github.com/mattermost/mattermost-server/v6",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    },
+    {
+      "package": {
+        "name": "github.com/mattermost/mattermost/server/v8",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "8.0.0-20250731163400-5b955468ea1e"
+            },
+            {
+              "fixed": "8.0.0-20260428142921-bd8fc9222672"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/advisories/GHSA-9p44-r552-4wp9"
+    },
+    {
+      "type": "ADVISORY",
+      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-7184"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/mattermost/mattermost/commit/1a0643df00c1f51a3b7e919eec034eaf955f612f"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/mattermost/mattermost/commit/6fd49f56b5920569218fd2fc76d8ae802942f274"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/mattermost/mattermost/commit/bd8fc92226726da06c8fabaef568cc9ebaee1cb8"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/mattermost/mattermost/commit/c5e67e28271c23cb585fe1a30ae81defcde848d6"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/mattermost/mattermost/commit/cad3e8e51a4d8627af6442f9df8ae3667fac7fc1"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/mattermost/mattermost/pull/36288"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/mattermost/mattermost/pull/36306"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/mattermost/mattermost/pull/36310"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/mattermost/mattermost/pull/36311"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/mattermost/mattermost/pull/36313"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/mattermost/mattermost/releases/tag/v10.11.16"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/mattermost/mattermost/releases/tag/v11.5.5"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/mattermost/mattermost/releases/tag/v11.6.2"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/mattermost/mattermost/releases/tag/v11.7.0"
+    },
+    {
+      "type": "WEB",
+      "url": "https://mattermost.com/security-updates"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6282",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6283.json b/data/osv/GO-2026-6283.json
new file mode 100644
index 0000000..0e1b095
--- /dev/null
+++ b/data/osv/GO-2026-6283.json
@@ -0,0 +1,174 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6283",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-6689",
+    "GHSA-c28q-m4gf-vg4q"
+  ],
+  "summary": "Mattermost doesn't enforce PermissionInviteUser when setting AllowOpenInvite or AllowedDomains during team creation in github.com/mattermost/mattermost-server",
+  "details": "Mattermost doesn't enforce PermissionInviteUser when setting AllowOpenInvite or AllowedDomains during team creation in github.com/mattermost/mattermost-server",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/mattermost/mattermost-server",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "10.11.0+incompatible"
+            },
+            {
+              "fixed": "10.11.17+incompatible"
+            },
+            {
+              "introduced": "11.5.0+incompatible"
+            },
+            {
+              "fixed": "11.5.5+incompatible"
+            },
+            {
+              "introduced": "11.6.0+incompatible"
+            },
+            {
+              "fixed": "11.6.1+incompatible"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    },
+    {
+      "package": {
+        "name": "github.com/mattermost/mattermost-server/v5",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    },
+    {
+      "package": {
+        "name": "github.com/mattermost/mattermost-server/v6",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    },
+    {
+      "package": {
+        "name": "github.com/mattermost/mattermost/server/v8",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "8.0.0-20250731163400-5b955468ea1e"
+            },
+            {
+              "fixed": "8.0.0-20260501144115-7d6816abdfd1"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/advisories/GHSA-c28q-m4gf-vg4q"
+    },
+    {
+      "type": "ADVISORY",
+      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6689"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/mattermost/mattermost/commit/2dea05864024b3254fb28c5ed679592e2b7cd672"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/mattermost/mattermost/commit/3a96344214b1a84df70d97052d46b6f2b40b0caa"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/mattermost/mattermost/commit/479fc42d0ec6da48e76b59608233d90bfc69769d"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/mattermost/mattermost/commit/7d6816abdfd170169f717aea43c5716a1f9ef6b0"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/mattermost/mattermost/commit/977c791e5b54bc14fdb96a2b3dacc85da5d8c623"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/mattermost/mattermost/pull/36188"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/mattermost/mattermost/pull/36375"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/mattermost/mattermost/pull/36383"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/mattermost/mattermost/pull/36384"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/mattermost/mattermost/pull/36402"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/mattermost/mattermost/releases/tag/v10.11.16"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/mattermost/mattermost/releases/tag/v11.5.5"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/mattermost/mattermost/releases/tag/v11.6.2"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/mattermost/mattermost/releases/tag/v11.7.0"
+    },
+    {
+      "type": "WEB",
+      "url": "https://mattermost.com/security-updates"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6283",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6284.json b/data/osv/GO-2026-6284.json
new file mode 100644
index 0000000..fbf22e2
--- /dev/null
+++ b/data/osv/GO-2026-6284.json
@@ -0,0 +1,90 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6284",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-55477",
+    "GHSA-jm48-m3rr-9hgg"
+  ],
+  "summary": "3X-UI Vulnerable to Authenticated Arbitrary File Write via Database Import and Xray Log Path Manipulation in github.com/mhsanaei/3x-ui",
+  "details": "3X-UI Vulnerable to Authenticated Arbitrary File Write via Database Import and Xray Log Path Manipulation in github.com/mhsanaei/3x-ui",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/mhsanaei/3x-ui",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    },
+    {
+      "package": {
+        "name": "github.com/mhsanaei/3x-ui/v2",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    },
+    {
+      "package": {
+        "name": "github.com/mhsanaei/3x-ui/v3",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "3.3.1"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/MHSanaei/3x-ui/security/advisories/GHSA-jm48-m3rr-9hgg"
+    },
+    {
+      "type": "ADVISORY",
+      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-55477"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/MHSanaei/3x-ui/commit/80e168787ed608e83a065033ee94c8bfc3025ce7"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/MHSanaei/3x-ui/releases/tag/v3.3.1"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6284",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6285.json b/data/osv/GO-2026-6285.json
new file mode 100644
index 0000000..624792d
--- /dev/null
+++ b/data/osv/GO-2026-6285.json
@@ -0,0 +1,170 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6285",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-6739",
+    "GHSA-m2w9-h2mm-79qr"
+  ],
+  "summary": "Mattermost doesn't require system-level permission when patching protected default system roles in github.com/mattermost/mattermost-server",
+  "details": "Mattermost doesn't require system-level permission when patching protected default system roles in github.com/mattermost/mattermost-server",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/mattermost/mattermost-server",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "10.11.0+incompatible"
+            },
+            {
+              "fixed": "10.11.17+incompatible"
+            },
+            {
+              "introduced": "11.5.0+incompatible"
+            },
+            {
+              "fixed": "11.5.5+incompatible"
+            },
+            {
+              "introduced": "11.6.0+incompatible"
+            },
+            {
+              "fixed": "11.6.1+incompatible"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    },
+    {
+      "package": {
+        "name": "github.com/mattermost/mattermost-server/v5",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    },
+    {
+      "package": {
+        "name": "github.com/mattermost/mattermost-server/v6",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    },
+    {
+      "package": {
+        "name": "github.com/mattermost/mattermost/server/v8",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "8.0.0-20250731163400-5b955468ea1e"
+            },
+            {
+              "fixed": "8.0.0-20260501142004-99b73d4c4acf"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/advisories/GHSA-m2w9-h2mm-79qr"
+    },
+    {
+      "type": "ADVISORY",
+      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6739"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/mattermost/mattermost/commit/2c89c2f6768fbe4dfd57a21ca38c0aecead8d4a8"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/mattermost/mattermost/commit/5e159647b16e571b327ac6882f32eae42971f540"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/mattermost/mattermost/commit/8000e5933526f4fd66b92131db3a1b1f4520dbae"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/mattermost/mattermost/commit/f0a390b96e4c730daedbaf5190684776730218c7"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/mattermost/mattermost/pull/36197"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/mattermost/mattermost/pull/36377"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/mattermost/mattermost/pull/36379"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/mattermost/mattermost/pull/36380"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/mattermost/mattermost/pull/36382"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/mattermost/mattermost/releases/tag/v10.11.16"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/mattermost/mattermost/releases/tag/v11.5.5"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/mattermost/mattermost/releases/tag/v11.6.2"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/mattermost/mattermost/releases/tag/v11.7.0"
+    },
+    {
+      "type": "WEB",
+      "url": "https://mattermost.com/security-updates"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6285",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6286.json b/data/osv/GO-2026-6286.json
new file mode 100644
index 0000000..e14b844
--- /dev/null
+++ b/data/osv/GO-2026-6286.json
@@ -0,0 +1,166 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6286",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-3433",
+    "GHSA-rp4v-qc77-phm4"
+  ],
+  "summary": "Mattermost doesn't restrict role_updated websocket event broadcasts to members of the affected team or channel in github.com/mattermost/mattermost-server",
+  "details": "Mattermost doesn't restrict role_updated websocket event broadcasts to members of the affected team or channel in github.com/mattermost/mattermost-server",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/mattermost/mattermost-server",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "10.11.0+incompatible"
+            },
+            {
+              "fixed": "10.11.17+incompatible"
+            },
+            {
+              "introduced": "11.5.0+incompatible"
+            },
+            {
+              "fixed": "11.5.5+incompatible"
+            },
+            {
+              "introduced": "11.6.0+incompatible"
+            },
+            {
+              "fixed": "11.6.1+incompatible"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    },
+    {
+      "package": {
+        "name": "github.com/mattermost/mattermost-server/v5",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    },
+    {
+      "package": {
+        "name": "github.com/mattermost/mattermost-server/v6",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    },
+    {
+      "package": {
+        "name": "github.com/mattermost/mattermost/server/v8",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "8.0.0-20250731163400-5b955468ea1e"
+            },
+            {
+              "fixed": "8.0.0-20260504071740-9408b98025d7"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/advisories/GHSA-rp4v-qc77-phm4"
+    },
+    {
+      "type": "ADVISORY",
+      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-3433"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/mattermost/mattermost/commit/0a0ab0d54d899d308bd1352cc577036917500318"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/mattermost/mattermost/commit/7425c6817bf244f976c729f8a73cecac8039a1e1"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/mattermost/mattermost/commit/9408b98025d7364d7dfe7cdb28fcd109b1b595a6"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/mattermost/mattermost/commit/a30a331a29b9766d46716d4252056d7b74e66da0"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/mattermost/mattermost/pull/35497"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/mattermost/mattermost/pull/36256"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/mattermost/mattermost/pull/36257"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/mattermost/mattermost/pull/36341"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/mattermost/mattermost/releases/tag/v10.11.16"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/mattermost/mattermost/releases/tag/v11.5.5"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/mattermost/mattermost/releases/tag/v11.6.2"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/mattermost/mattermost/releases/tag/v11.7.0"
+    },
+    {
+      "type": "WEB",
+      "url": "https://mattermost.com/security-updates"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6286",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6287.json b/data/osv/GO-2026-6287.json
new file mode 100644
index 0000000..bfe0d06
--- /dev/null
+++ b/data/osv/GO-2026-6287.json
@@ -0,0 +1,74 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6287",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "GHSA-vx2m-jpxr-xv7w"
+  ],
+  "summary": "Cloudreve has Broken Access Control - Revoked Share Access Still Allows Signed File URL Generation via Cached context_hint in github.com/cloudreve/Cloudreve",
+  "details": "Cloudreve has Broken Access Control - Revoked Share Access Still Allows Signed File URL Generation via Cached context_hint in github.com/cloudreve/Cloudreve",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/cloudreve/Cloudreve",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    },
+    {
+      "package": {
+        "name": "github.com/cloudreve/Cloudreve/v3",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    },
+    {
+      "package": {
+        "name": "github.com/cloudreve/Cloudreve/v4",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/cloudreve/cloudreve/security/advisories/GHSA-vx2m-jpxr-xv7w"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6287",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6288.json b/data/osv/GO-2026-6288.json
new file mode 100644
index 0000000..a0ef11f
--- /dev/null
+++ b/data/osv/GO-2026-6288.json
@@ -0,0 +1,60 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6288",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-11624",
+    "GHSA-76g7-m3xw-x9gr"
+  ],
+  "summary": "MCP Toolbox for Databases has an Origin Validation Error in github.com/googleapis/genai-toolbox",
+  "details": "MCP Toolbox for Databases has an Origin Validation Error in github.com/googleapis/genai-toolbox",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/googleapis/genai-toolbox",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "0.25.0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/advisories/GHSA-76g7-m3xw-x9gr"
+    },
+    {
+      "type": "ADVISORY",
+      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-11624"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/googleapis/mcp-toolbox/commit/17b41f64531b8fe417c28ada45d1992ba430dc1b"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/googleapis/mcp-toolbox/issues/3113"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/googleapis/mcp-toolbox/pull/2254"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6288",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6289.json b/data/osv/GO-2026-6289.json
new file mode 100644
index 0000000..c2e8ce6
--- /dev/null
+++ b/data/osv/GO-2026-6289.json
@@ -0,0 +1,74 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6289",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "GHSA-w8j7-39hp-8x59"
+  ],
+  "summary": "Cloudreve's remote download file paths can escape the selected destination directory in github.com/cloudreve/Cloudreve",
+  "details": "Cloudreve's remote download file paths can escape the selected destination directory in github.com/cloudreve/Cloudreve",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/cloudreve/Cloudreve",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    },
+    {
+      "package": {
+        "name": "github.com/cloudreve/Cloudreve/v3",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    },
+    {
+      "package": {
+        "name": "github.com/cloudreve/Cloudreve/v4",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/cloudreve/cloudreve/security/advisories/GHSA-w8j7-39hp-8x59"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6289",
+    "review_status": "UNREVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/reports/GO-2026-6253.yaml b/data/reports/GO-2026-6253.yaml
new file mode 100644
index 0000000..e380b07
--- /dev/null
+++ b/data/reports/GO-2026-6253.yaml
@@ -0,0 +1,23 @@
+id: GO-2026-6253
+modules:
+    - module: github.com/moby/go-archive
+      versions:
+        - fixed: 0.3.0
+      vulnerable_at: 0.2.1
+summary: 'moby/go-archive: Crafted tar archive can write outside the extraction directory in github.com/moby/go-archive'
+cves:
+    - CVE-2026-17106
+ghsas:
+    - GHSA-hfg8-hc9c-6c3h
+references:
+    - advisory: https://github.com/moby/go-archive/security/advisories/GHSA-hfg8-hc9c-6c3h
+    - web: https://docs.docker.com/desktop/release-notes/#4860
+    - web: https://github.com/bikini/exploitarium/tree/main/docker-cp-copyout-destination-escape
+    - web: https://github.com/docker/cli/releases/tag/v29.7.0
+    - web: https://github.com/moby/moby/issues/52948
+    - web: https://github.com/moby/moby/releases/tag/docker-v29.7.0
+    - web: https://www.imperva.com/blog/copyescape-taking-over-docker-hosts-with-docker-cp
+source:
+    id: GHSA-hfg8-hc9c-6c3h
+    created: 2026-08-24T21:38:53.334308-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6254.yaml b/data/reports/GO-2026-6254.yaml
new file mode 100644
index 0000000..cd1efb8
--- /dev/null
+++ b/data/reports/GO-2026-6254.yaml
@@ -0,0 +1,21 @@
+id: GO-2026-6254
+modules:
+    - module: github.com/inspektor-gadget/inspektor-gadget
+      versions:
+        - introduced: 0.27.0
+        - fixed: 0.53.1
+      vulnerable_at: 0.53.0
+summary: |-
+    Uprobe gadgets: unprivileged container's ld.so.cache causes high CPU utilization
+    and container startup DoS in github.com/inspektor-gadget/inspektor-gadget
+cves:
+    - CVE-2026-53941
+ghsas:
+    - GHSA-vjhx-2cqw-3q6q
+references:
+    - advisory: https://github.com/inspektor-gadget/inspektor-gadget/security/advisories/GHSA-vjhx-2cqw-3q6q
+    - web: https://github.com/inspektor-gadget/inspektor-gadget/releases/tag/v0.53.1
+source:
+    id: GHSA-vjhx-2cqw-3q6q
+    created: 2026-08-24T21:38:47.793237-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6258.yaml b/data/reports/GO-2026-6258.yaml
new file mode 100644
index 0000000..008c9f2
--- /dev/null
+++ b/data/reports/GO-2026-6258.yaml
@@ -0,0 +1,21 @@
+id: GO-2026-6258
+modules:
+    - module: go.opentelemetry.io/otel/bridge/opentracing
+      versions:
+        - introduced: 0.11.0
+        - fixed: 1.45.0
+      vulnerable_at: 1.44.0
+summary: 'OpenTelemetry-Go: Unsynchronized baggage map can panic under concurrent access in go.opentelemetry.io/otel/bridge/opentracing'
+cves:
+    - CVE-2026-45404
+ghsas:
+    - GHSA-42cj-99w8-cp2p
+references:
+    - advisory: https://github.com/open-telemetry/opentelemetry-go/security/advisories/GHSA-42cj-99w8-cp2p
+    - web: https://github.com/open-telemetry/opentelemetry-go/commit/93a693edeed0e07ce5ebd1dfe67af42d1e2055d8
+    - web: https://github.com/open-telemetry/opentelemetry-go/pull/8693
+    - web: https://github.com/open-telemetry/opentelemetry-go/releases/tag/v1.45.0
+source:
+    id: GHSA-42cj-99w8-cp2p
+    created: 2026-08-24T21:37:03.480167-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6259.yaml b/data/reports/GO-2026-6259.yaml
new file mode 100644
index 0000000..b58025a
--- /dev/null
+++ b/data/reports/GO-2026-6259.yaml
@@ -0,0 +1,18 @@
+id: GO-2026-6259
+modules:
+    - module: github.com/vmware-tanzu/velero
+      versions:
+        - fixed: 1.18.1
+      vulnerable_at: 1.18.1-rc.2
+summary: Velero vulnerable to file path traversal when extracting from backup's tarball in github.com/vmware-tanzu/velero
+cves:
+    - CVE-2026-32637
+ghsas:
+    - GHSA-j2g6-362q-6qc6
+references:
+    - advisory: https://github.com/velero-io/velero/security/advisories/GHSA-j2g6-362q-6qc6
+    - web: https://github.com/securego/gosec/issues/324
+source:
+    id: GHSA-j2g6-362q-6qc6
+    created: 2026-08-24T21:36:57.513666-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6260.yaml b/data/reports/GO-2026-6260.yaml
new file mode 100644
index 0000000..3cc1930
--- /dev/null
+++ b/data/reports/GO-2026-6260.yaml
@@ -0,0 +1,19 @@
+id: GO-2026-6260
+modules:
+    - module: github.com/vouch/vouch-proxy
+      versions:
+        - fixed: 0.48.0
+      vulnerable_at: 0.47.2
+summary: vouch-proxy has an Unbounded Multipart Cookie Allocation DoS in github.com/vouch/vouch-proxy
+cves:
+    - CVE-2026-55149
+ghsas:
+    - GHSA-qqff-5854-px68
+references:
+    - advisory: https://github.com/vouch/vouch-proxy/security/advisories/GHSA-qqff-5854-px68
+    - fix: https://github.com/vouch/vouch-proxy/commit/fa18ce30ba50a4863a436acad044c22965329c4f
+    - web: https://github.com/vouch/vouch-proxy/releases/tag/v0.48.0
+source:
+    id: GHSA-qqff-5854-px68
+    created: 2026-08-24T21:36:51.179521-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6262.yaml b/data/reports/GO-2026-6262.yaml
new file mode 100644
index 0000000..df2b3da
--- /dev/null
+++ b/data/reports/GO-2026-6262.yaml
@@ -0,0 +1,24 @@
+id: GO-2026-6262
+modules:
+    - module: github.com/opentofu/opentofu
+      versions:
+        - fixed: 1.11.9
+        - introduced: 1.12.0-beta1
+        - fixed: 1.12.2
+      vulnerable_at: 1.12.1
+summary: |-
+    OpenTofu has high CPU usage when using K8S remote state backend or when parsing
+    specifically crafted TLS certificates from untrusted or compromised servers in github.com/opentofu/opentofu
+ghsas:
+    - GHSA-22w5-2fxg-vrwx
+references:
+    - advisory: https://github.com/opentofu/opentofu/security/advisories/GHSA-22w5-2fxg-vrwx
+    - report: https://github.com/opentofu/opentofu/issues/4242
+    - report: https://github.com/opentofu/opentofu/issues/4243
+    - report: https://github.com/opentofu/opentofu/issues/4244
+    - web: https://github.com/opentofu/opentofu/releases/tag/v1.11.9
+    - web: https://github.com/opentofu/opentofu/releases/tag/v1.12.2
+source:
+    id: GHSA-22w5-2fxg-vrwx
+    created: 2026-08-24T21:22:17.062569-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6263.yaml b/data/reports/GO-2026-6263.yaml
new file mode 100644
index 0000000..c797e37
--- /dev/null
+++ b/data/reports/GO-2026-6263.yaml
@@ -0,0 +1,25 @@
+id: GO-2026-6263
+modules:
+    - module: github.com/openshift-pipelines/pipelines-as-code
+      versions:
+        - fixed: 0.37.8
+        - introduced: 0.38.0
+        - fixed: 0.39.6
+        - introduced: 0.40.0
+        - fixed: 0.42.1
+        - introduced: 0.43.0
+        - fixed: 0.48.0
+      vulnerable_at: 0.47.0
+summary: |-
+    Tekton Pipelines-as-Code: Unscoped GitHub App installation token allows
+    unauthorized access to private repositories via remote task resolution in github.com/openshift-pipelines/pipelines-as-code
+cves:
+    - CVE-2026-54168
+ghsas:
+    - GHSA-6f2p-296r-cc28
+references:
+    - advisory: https://github.com/tektoncd/pipelines-as-code/security/advisories/GHSA-6f2p-296r-cc28
+source:
+    id: GHSA-6f2p-296r-cc28
+    created: 2026-08-24T21:22:13.304323-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6265.yaml b/data/reports/GO-2026-6265.yaml
new file mode 100644
index 0000000..2226da9
--- /dev/null
+++ b/data/reports/GO-2026-6265.yaml
@@ -0,0 +1,31 @@
+id: GO-2026-6265
+modules:
+    - module: github.com/coder/coder
+      vulnerable_at: 0.27.3
+    - module: github.com/coder/coder/v2
+      versions:
+        - fixed: 2.29.17
+        - introduced: 2.30.0
+        - fixed: 2.32.7
+        - introduced: 2.33.0
+        - fixed: 2.33.8
+        - introduced: 2.34.0
+        - fixed: 2.34.2
+      vulnerable_at: 2.34.1
+summary: |-
+    Coder: Login endpoint user enumeration via timing-defense placeholder in
+    password comparison in github.com/coder/coder
+ghsas:
+    - GHSA-8fxq-53rx-ph5f
+references:
+    - advisory: https://github.com/coder/coder/security/advisories/GHSA-8fxq-53rx-ph5f
+    - fix: https://github.com/coder/coder/commit/35a7dc8ab9c7f15ce05d963947823ee31224512f
+    - fix: https://github.com/coder/coder/pull/26205
+    - web: https://github.com/coder/coder/releases/tag/v2.29.17
+    - web: https://github.com/coder/coder/releases/tag/v2.32.7
+    - web: https://github.com/coder/coder/releases/tag/v2.33.8
+    - web: https://github.com/coder/coder/releases/tag/v2.34.2
+source:
+    id: GHSA-8fxq-53rx-ph5f
+    created: 2026-08-24T21:21:06.952342-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6266.yaml b/data/reports/GO-2026-6266.yaml
new file mode 100644
index 0000000..a54f654
--- /dev/null
+++ b/data/reports/GO-2026-6266.yaml
@@ -0,0 +1,25 @@
+id: GO-2026-6266
+modules:
+    - module: github.com/openshift-pipelines/pipelines-as-code
+      versions:
+        - fixed: 0.37.8
+        - introduced: 0.38.0
+        - fixed: 0.39.6
+        - introduced: 0.40.0
+        - fixed: 0.42.1
+        - introduced: 0.43.0
+        - fixed: 0.48.0
+      vulnerable_at: 0.47.0
+summary: |-
+    Pipelines-as-Code GitHub App token request can be redirected via untrusted
+    Enterprise Host header in github.com/openshift-pipelines/pipelines-as-code
+cves:
+    - CVE-2026-54167
+ghsas:
+    - GHSA-f5f4-3hh4-f54m
+references:
+    - advisory: https://github.com/tektoncd/pipelines-as-code/security/advisories/GHSA-f5f4-3hh4-f54m
+source:
+    id: GHSA-f5f4-3hh4-f54m
+    created: 2026-08-24T21:21:02.953327-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6267.yaml b/data/reports/GO-2026-6267.yaml
new file mode 100644
index 0000000..47b9954
--- /dev/null
+++ b/data/reports/GO-2026-6267.yaml
@@ -0,0 +1,31 @@
+id: GO-2026-6267
+modules:
+    - module: github.com/coder/coder
+      vulnerable_at: 0.27.3
+    - module: github.com/coder/coder/v2
+      versions:
+        - fixed: 2.29.17
+        - introduced: 2.30.0
+        - fixed: 2.32.7
+        - introduced: 2.33.0
+        - fixed: 2.33.8
+        - introduced: 2.34.0
+        - fixed: 2.34.2
+      vulnerable_at: 2.34.1
+summary: |-
+    Coder: Stored HTML injection via unescaped ApplicationName and LogoURL
+    appearance settings in github.com/coder/coder
+ghsas:
+    - GHSA-h58c-xccx-75m3
+references:
+    - advisory: https://github.com/coder/coder/security/advisories/GHSA-h58c-xccx-75m3
+    - fix: https://github.com/coder/coder/commit/ec19bc41d80568c0eb9f74b526e8cc8ffbe3be9a
+    - fix: https://github.com/coder/coder/pull/25804
+    - web: https://github.com/coder/coder/releases/tag/v2.29.17
+    - web: https://github.com/coder/coder/releases/tag/v2.32.7
+    - web: https://github.com/coder/coder/releases/tag/v2.33.8
+    - web: https://github.com/coder/coder/releases/tag/v2.34.2
+source:
+    id: GHSA-h58c-xccx-75m3
+    created: 2026-08-24T21:20:57.250057-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6270.yaml b/data/reports/GO-2026-6270.yaml
new file mode 100644
index 0000000..8d6f52a
--- /dev/null
+++ b/data/reports/GO-2026-6270.yaml
@@ -0,0 +1,21 @@
+id: GO-2026-6270
+modules:
+    - module: github.com/alexandre-daubois/ember
+      versions:
+        - fixed: 1.4.2
+      vulnerable_at: 1.4.1
+summary: |-
+    Ember has unneutralized terminal escape/control sequences from Caddy logs
+    injected into the operator's TUI in github.com/alexandre-daubois/ember
+cves:
+    - CVE-2026-54162
+ghsas:
+    - GHSA-x3g7-qrwc-f6c5
+references:
+    - advisory: https://github.com/alexandre-daubois/ember/security/advisories/GHSA-x3g7-qrwc-f6c5
+    - fix: https://github.com/alexandre-daubois/ember/commit/fcb7160e58dba58d6f9b5033cc312fdedc8c9f6b
+    - web: https://github.com/alexandre-daubois/ember/releases/tag/v1.4.2
+source:
+    id: GHSA-x3g7-qrwc-f6c5
+    created: 2026-08-24T21:16:04.593049-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6271.yaml b/data/reports/GO-2026-6271.yaml
new file mode 100644
index 0000000..17c71ce
--- /dev/null
+++ b/data/reports/GO-2026-6271.yaml
@@ -0,0 +1,22 @@
+id: GO-2026-6271
+modules:
+    - module: github.com/axllent/mailpit
+      versions:
+        - introduced: 1.29.0
+        - fixed: 1.30.6
+      vulnerable_at: 1.30.5
+summary: |-
+    Mailpit: WebSocket origin check bypass via percent-encoded path (regression of
+    CVE-2026-22689) in github.com/axllent/mailpit
+cves:
+    - CVE-2026-67448
+ghsas:
+    - GHSA-8r62-w5wh-fc5m
+references:
+    - advisory: https://github.com/axllent/mailpit/security/advisories/GHSA-8r62-w5wh-fc5m
+    - fix: https://github.com/axllent/mailpit/commit/fbe5e006c3f1682b819df58b4a932d7a84920be9
+    - web: https://github.com/axllent/mailpit/releases/tag/v1.30.6
+source:
+    id: GHSA-8r62-w5wh-fc5m
+    created: 2026-08-24T21:15:57.916821-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6272.yaml b/data/reports/GO-2026-6272.yaml
new file mode 100644
index 0000000..99b629b
--- /dev/null
+++ b/data/reports/GO-2026-6272.yaml
@@ -0,0 +1,20 @@
+id: GO-2026-6272
+modules:
+    - module: github.com/axllent/mailpit
+      versions:
+        - introduced: 1.30.0
+        - fixed: 1.30.5
+      vulnerable_at: 1.30.4
+summary: 'Mailpit: SMTP DATA line reader buffers over-limit input before size enforcement in github.com/axllent/mailpit'
+cves:
+    - CVE-2026-67447
+ghsas:
+    - GHSA-r553-m4fv-5v97
+references:
+    - advisory: https://github.com/axllent/mailpit/security/advisories/GHSA-r553-m4fv-5v97
+    - fix: https://github.com/axllent/mailpit/commit/8720c6bd8281fc00d458081908f1dbef8e59a98c
+    - web: https://github.com/axllent/mailpit/releases/tag/v1.30.5
+source:
+    id: GHSA-r553-m4fv-5v97
+    created: 2026-08-24T21:15:51.523482-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6277.yaml b/data/reports/GO-2026-6277.yaml
new file mode 100644
index 0000000..0c68c5e
--- /dev/null
+++ b/data/reports/GO-2026-6277.yaml
@@ -0,0 +1,18 @@
+id: GO-2026-6277
+modules:
+    - module: github.com/tinfoil-factory/netfoil
+      versions:
+        - fixed: 0.5.0
+      vulnerable_at: 0.4.0
+summary: netfoil vulnerable to improper handling of untrusted DoH response data in github.com/tinfoil-factory/netfoil
+ghsas:
+    - GHSA-4ph6-mjv7-3fq6
+references:
+    - advisory: https://github.com/tinfoil-factory/netfoil/security/advisories/GHSA-4ph6-mjv7-3fq6
+    - fix: https://github.com/tinfoil-factory/netfoil/commit/58cfb0cb16b824e02bf53c2d67707e5e4bd9f59b
+    - fix: https://github.com/tinfoil-factory/netfoil/commit/817f664c61aa64cbe0dbfcdfc05c16602b422e5b
+    - web: https://github.com/tinfoil-factory/netfoil/releases/tag/v0.5.0
+source:
+    id: GHSA-4ph6-mjv7-3fq6
+    created: 2026-08-24T21:14:22.613785-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6279.yaml b/data/reports/GO-2026-6279.yaml
new file mode 100644
index 0000000..7a1c6f4
--- /dev/null
+++ b/data/reports/GO-2026-6279.yaml
@@ -0,0 +1,50 @@
+id: GO-2026-6279
+modules:
+    - module: github.com/mattermost/mattermost-server
+      versions:
+        - introduced: 10.11.0+incompatible
+        - fixed: 10.11.17+incompatible
+        - introduced: 11.5.0+incompatible
+        - fixed: 11.5.5+incompatible
+        - introduced: 11.6.0+incompatible
+        - fixed: 11.6.1+incompatible
+      vulnerable_at: 11.6.1-rc1+incompatible
+    - module: github.com/mattermost/mattermost-server/v5
+      vulnerable_at: 5.39.3
+    - module: github.com/mattermost/mattermost-server/v6
+      vulnerable_at: 6.7.2
+    - module: github.com/mattermost/mattermost/server/v8
+      versions:
+        - introduced: 8.0.0-20250731163400-5b955468ea1e
+        - fixed: 8.0.0-20260428151657-c79c3831061a
+summary: |-
+    Mattermost doesn't validate that a username returned during bot registration
+    belongs to a bot account in github.com/mattermost/mattermost-server
+cves:
+    - CVE-2026-6046
+ghsas:
+    - GHSA-3vmp-whvv-5v9v
+references:
+    - advisory: https://github.com/advisories/GHSA-3vmp-whvv-5v9v
+    - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-6046
+    - web: https://github.com/mattermost/mattermost/commit/3be10297c14d272f273d747af70728f9d03c60ec
+    - web: https://github.com/mattermost/mattermost/commit/98f9778cec1e7f3d97b3d4692fb91f8e7b659972
+    - web: https://github.com/mattermost/mattermost/commit/aba9339a24d4b287edd77377c19901d6e341bb96
+    - web: https://github.com/mattermost/mattermost/commit/c79c3831061a0880c0962c7d567c9e24dd35f44c
+    - web: https://github.com/mattermost/mattermost/commit/f706d1f01e6dfe62cab86c1d257f237daa78106a
+    - web: https://github.com/mattermost/mattermost/pull/36064
+    - web: https://github.com/mattermost/mattermost/pull/36305
+    - web: https://github.com/mattermost/mattermost/pull/36317
+    - web: https://github.com/mattermost/mattermost/pull/36318
+    - web: https://github.com/mattermost/mattermost/pull/36320
+    - web: https://github.com/mattermost/mattermost/releases/tag/v10.11.16
+    - web: https://github.com/mattermost/mattermost/releases/tag/v11.5.5
+    - web: https://github.com/mattermost/mattermost/releases/tag/v11.6.2
+    - web: https://github.com/mattermost/mattermost/releases/tag/v11.7.0
+    - web: https://mattermost.com/security-updates
+notes:
+    - fix: 'github.com/mattermost/mattermost/server/v8: could not add vulnerable_at: could not find tagged version between introduced and fixed'
+source:
+    id: GHSA-3vmp-whvv-5v9v
+    created: 2026-08-24T21:14:05.042562-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6280.yaml b/data/reports/GO-2026-6280.yaml
new file mode 100644
index 0000000..cb291c0
--- /dev/null
+++ b/data/reports/GO-2026-6280.yaml
@@ -0,0 +1,50 @@
+id: GO-2026-6280
+modules:
+    - module: github.com/mattermost/mattermost-server
+      versions:
+        - introduced: 10.11.0+incompatible
+        - fixed: 10.11.17+incompatible
+        - introduced: 11.5.0+incompatible
+        - fixed: 11.5.5+incompatible
+        - introduced: 11.6.0+incompatible
+        - fixed: 11.6.1+incompatible
+      vulnerable_at: 11.6.1-rc1+incompatible
+    - module: github.com/mattermost/mattermost-server/v5
+      vulnerable_at: 5.39.3
+    - module: github.com/mattermost/mattermost-server/v6
+      vulnerable_at: 6.7.2
+    - module: github.com/mattermost/mattermost/server/v8
+      versions:
+        - introduced: 8.0.0-20250731163400-5b955468ea1e
+        - fixed: 8.0.0-20260506065351-202d125afa87
+summary: |-
+    Mattermost doesn't require role-management authorization when setting the
+    scheme_admin flag on group syncable link and patch endpoints in github.com/mattermost/mattermost-server
+cves:
+    - CVE-2026-7387
+ghsas:
+    - GHSA-6hxm-w4hv-vgvw
+references:
+    - advisory: https://github.com/advisories/GHSA-6hxm-w4hv-vgvw
+    - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-7387
+    - web: https://github.com/mattermost/mattermost/commit/1ce2484a00c9821ee19708d2c46720e4855033a9
+    - web: https://github.com/mattermost/mattermost/commit/202d125afa87fe39611686850fd82590c99ca344
+    - web: https://github.com/mattermost/mattermost/commit/8c72083414e675c97987374395e36d1f36b4bd8a
+    - web: https://github.com/mattermost/mattermost/commit/a9e574a82633915f22071f0d7ca2b006f249ec2a
+    - web: https://github.com/mattermost/mattermost/commit/d5f29c8ebbeb04460d16d9e2635ce50deeb78428
+    - web: https://github.com/mattermost/mattermost/pull/36316
+    - web: https://github.com/mattermost/mattermost/pull/36423
+    - web: https://github.com/mattermost/mattermost/pull/36431
+    - web: https://github.com/mattermost/mattermost/pull/36432
+    - web: https://github.com/mattermost/mattermost/pull/36434
+    - web: https://github.com/mattermost/mattermost/releases/tag/v10.11.16
+    - web: https://github.com/mattermost/mattermost/releases/tag/v11.5.5
+    - web: https://github.com/mattermost/mattermost/releases/tag/v11.6.2
+    - web: https://github.com/mattermost/mattermost/releases/tag/v11.7.0
+    - web: https://mattermost.com/security-updates
+notes:
+    - fix: 'github.com/mattermost/mattermost/server/v8: could not add vulnerable_at: could not find tagged version between introduced and fixed'
+source:
+    id: GHSA-6hxm-w4hv-vgvw
+    created: 2026-08-24T21:13:52.372095-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6281.yaml b/data/reports/GO-2026-6281.yaml
new file mode 100644
index 0000000..479d632
--- /dev/null
+++ b/data/reports/GO-2026-6281.yaml
@@ -0,0 +1,50 @@
+id: GO-2026-6281
+modules:
+    - module: github.com/mattermost/mattermost-server
+      versions:
+        - introduced: 10.11.0+incompatible
+        - fixed: 10.11.17+incompatible
+        - introduced: 11.5.0+incompatible
+        - fixed: 11.5.5+incompatible
+        - introduced: 11.6.0+incompatible
+        - fixed: 11.6.1+incompatible
+      vulnerable_at: 11.6.1-rc1+incompatible
+    - module: github.com/mattermost/mattermost-server/v5
+      vulnerable_at: 5.39.3
+    - module: github.com/mattermost/mattermost-server/v6
+      vulnerable_at: 6.7.2
+    - module: github.com/mattermost/mattermost/server/v8
+      versions:
+        - introduced: 8.0.0-20250731163400-5b955468ea1e
+        - fixed: 8.0.0-20260423180926-c021eeaff8f0
+summary: |-
+    Mattermost doesn't sanitize FileInfo.Name received from federated peers during
+    shared channel file sync in github.com/mattermost/mattermost-server
+cves:
+    - CVE-2026-6961
+ghsas:
+    - GHSA-8qq9-cqj8-82w4
+references:
+    - advisory: https://github.com/advisories/GHSA-8qq9-cqj8-82w4
+    - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-6961
+    - web: https://github.com/mattermost/mattermost/commit/61d68d2d6ee81a5919597d91c736c502d7156859
+    - web: https://github.com/mattermost/mattermost/commit/a0056ed68d95f64d7c4586985e7b7f16b96b3bec
+    - web: https://github.com/mattermost/mattermost/commit/a9f3868e1eee9ec61855cd7277f39937385efffd
+    - web: https://github.com/mattermost/mattermost/commit/c021eeaff8f003034ab40f82c552cc26a710a8fd
+    - web: https://github.com/mattermost/mattermost/commit/c896a63dc44c2f9c081a0a15bfddc4e6eb50e753
+    - web: https://github.com/mattermost/mattermost/pull/36223
+    - web: https://github.com/mattermost/mattermost/pull/36251
+    - web: https://github.com/mattermost/mattermost/pull/36252
+    - web: https://github.com/mattermost/mattermost/pull/36253
+    - web: https://github.com/mattermost/mattermost/pull/36255
+    - web: https://github.com/mattermost/mattermost/releases/tag/v10.11.16
+    - web: https://github.com/mattermost/mattermost/releases/tag/v11.5.5
+    - web: https://github.com/mattermost/mattermost/releases/tag/v11.6.2
+    - web: https://github.com/mattermost/mattermost/releases/tag/v11.7.0
+    - web: https://mattermost.com/security-updates
+notes:
+    - fix: 'github.com/mattermost/mattermost/server/v8: could not add vulnerable_at: could not find tagged version between introduced and fixed'
+source:
+    id: GHSA-8qq9-cqj8-82w4
+    created: 2026-08-24T21:13:39.56039-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6282.yaml b/data/reports/GO-2026-6282.yaml
new file mode 100644
index 0000000..cf8182e
--- /dev/null
+++ b/data/reports/GO-2026-6282.yaml
@@ -0,0 +1,48 @@
+id: GO-2026-6282
+modules:
+    - module: github.com/mattermost/mattermost-server
+      versions:
+        - introduced: 10.11.0+incompatible
+        - fixed: 10.11.16+incompatible
+        - introduced: 11.5.0+incompatible
+        - fixed: 11.5.5+incompatible
+        - introduced: 11.6.0+incompatible
+        - fixed: 11.6.1+incompatible
+      vulnerable_at: 11.6.1-rc1+incompatible
+    - module: github.com/mattermost/mattermost-server/v5
+      vulnerable_at: 5.39.3
+    - module: github.com/mattermost/mattermost-server/v6
+      vulnerable_at: 6.7.2
+    - module: github.com/mattermost/mattermost/server/v8
+      versions:
+        - introduced: 8.0.0-20250731163400-5b955468ea1e
+        - fixed: 8.0.0-20260428142921-bd8fc9222672
+summary: Mattermost doesn't sanitize the Remote Cluster API response on PATCH operations in github.com/mattermost/mattermost-server
+cves:
+    - CVE-2026-7184
+ghsas:
+    - GHSA-9p44-r552-4wp9
+references:
+    - advisory: https://github.com/advisories/GHSA-9p44-r552-4wp9
+    - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-7184
+    - web: https://github.com/mattermost/mattermost/commit/1a0643df00c1f51a3b7e919eec034eaf955f612f
+    - web: https://github.com/mattermost/mattermost/commit/6fd49f56b5920569218fd2fc76d8ae802942f274
+    - web: https://github.com/mattermost/mattermost/commit/bd8fc92226726da06c8fabaef568cc9ebaee1cb8
+    - web: https://github.com/mattermost/mattermost/commit/c5e67e28271c23cb585fe1a30ae81defcde848d6
+    - web: https://github.com/mattermost/mattermost/commit/cad3e8e51a4d8627af6442f9df8ae3667fac7fc1
+    - web: https://github.com/mattermost/mattermost/pull/36288
+    - web: https://github.com/mattermost/mattermost/pull/36306
+    - web: https://github.com/mattermost/mattermost/pull/36310
+    - web: https://github.com/mattermost/mattermost/pull/36311
+    - web: https://github.com/mattermost/mattermost/pull/36313
+    - web: https://github.com/mattermost/mattermost/releases/tag/v10.11.16
+    - web: https://github.com/mattermost/mattermost/releases/tag/v11.5.5
+    - web: https://github.com/mattermost/mattermost/releases/tag/v11.6.2
+    - web: https://github.com/mattermost/mattermost/releases/tag/v11.7.0
+    - web: https://mattermost.com/security-updates
+notes:
+    - fix: 'github.com/mattermost/mattermost/server/v8: could not add vulnerable_at: could not find tagged version between introduced and fixed'
+source:
+    id: GHSA-9p44-r552-4wp9
+    created: 2026-08-24T21:13:27.738755-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6283.yaml b/data/reports/GO-2026-6283.yaml
new file mode 100644
index 0000000..e858517
--- /dev/null
+++ b/data/reports/GO-2026-6283.yaml
@@ -0,0 +1,50 @@
+id: GO-2026-6283
+modules:
+    - module: github.com/mattermost/mattermost-server
+      versions:
+        - introduced: 10.11.0+incompatible
+        - fixed: 10.11.17+incompatible
+        - introduced: 11.5.0+incompatible
+        - fixed: 11.5.5+incompatible
+        - introduced: 11.6.0+incompatible
+        - fixed: 11.6.1+incompatible
+      vulnerable_at: 11.6.1-rc1+incompatible
+    - module: github.com/mattermost/mattermost-server/v5
+      vulnerable_at: 5.39.3
+    - module: github.com/mattermost/mattermost-server/v6
+      vulnerable_at: 6.7.2
+    - module: github.com/mattermost/mattermost/server/v8
+      versions:
+        - introduced: 8.0.0-20250731163400-5b955468ea1e
+        - fixed: 8.0.0-20260501144115-7d6816abdfd1
+summary: |-
+    Mattermost doesn't enforce PermissionInviteUser when setting AllowOpenInvite or
+    AllowedDomains during team creation in github.com/mattermost/mattermost-server
+cves:
+    - CVE-2026-6689
+ghsas:
+    - GHSA-c28q-m4gf-vg4q
+references:
+    - advisory: https://github.com/advisories/GHSA-c28q-m4gf-vg4q
+    - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-6689
+    - web: https://github.com/mattermost/mattermost/commit/2dea05864024b3254fb28c5ed679592e2b7cd672
+    - web: https://github.com/mattermost/mattermost/commit/3a96344214b1a84df70d97052d46b6f2b40b0caa
+    - web: https://github.com/mattermost/mattermost/commit/479fc42d0ec6da48e76b59608233d90bfc69769d
+    - web: https://github.com/mattermost/mattermost/commit/7d6816abdfd170169f717aea43c5716a1f9ef6b0
+    - web: https://github.com/mattermost/mattermost/commit/977c791e5b54bc14fdb96a2b3dacc85da5d8c623
+    - web: https://github.com/mattermost/mattermost/pull/36188
+    - web: https://github.com/mattermost/mattermost/pull/36375
+    - web: https://github.com/mattermost/mattermost/pull/36383
+    - web: https://github.com/mattermost/mattermost/pull/36384
+    - web: https://github.com/mattermost/mattermost/pull/36402
+    - web: https://github.com/mattermost/mattermost/releases/tag/v10.11.16
+    - web: https://github.com/mattermost/mattermost/releases/tag/v11.5.5
+    - web: https://github.com/mattermost/mattermost/releases/tag/v11.6.2
+    - web: https://github.com/mattermost/mattermost/releases/tag/v11.7.0
+    - web: https://mattermost.com/security-updates
+notes:
+    - fix: 'github.com/mattermost/mattermost/server/v8: could not add vulnerable_at: could not find tagged version between introduced and fixed'
+source:
+    id: GHSA-c28q-m4gf-vg4q
+    created: 2026-08-24T21:13:14.65208-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6284.yaml b/data/reports/GO-2026-6284.yaml
new file mode 100644
index 0000000..c7fb4b6
--- /dev/null
+++ b/data/reports/GO-2026-6284.yaml
@@ -0,0 +1,28 @@
+id: GO-2026-6284
+modules:
+    - module: github.com/mhsanaei/3x-ui
+      vulnerable_at: 1.7.9
+    - module: github.com/mhsanaei/3x-ui/v2
+      unsupported_versions:
+        - last_affected: 2.9.4
+      vulnerable_at: 2.9.4
+    - module: github.com/mhsanaei/3x-ui/v3
+      versions:
+        - fixed: 3.3.1
+      vulnerable_at: 3.3.0
+summary: |-
+    3X-UI Vulnerable to Authenticated Arbitrary File Write via Database Import and
+    Xray Log Path Manipulation in github.com/mhsanaei/3x-ui
+cves:
+    - CVE-2026-55477
+ghsas:
+    - GHSA-jm48-m3rr-9hgg
+references:
+    - advisory: https://github.com/MHSanaei/3x-ui/security/advisories/GHSA-jm48-m3rr-9hgg
+    - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-55477
+    - web: https://github.com/MHSanaei/3x-ui/commit/80e168787ed608e83a065033ee94c8bfc3025ce7
+    - web: https://github.com/MHSanaei/3x-ui/releases/tag/v3.3.1
+source:
+    id: GHSA-jm48-m3rr-9hgg
+    created: 2026-08-24T21:13:06.930922-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6285.yaml b/data/reports/GO-2026-6285.yaml
new file mode 100644
index 0000000..a204f29
--- /dev/null
+++ b/data/reports/GO-2026-6285.yaml
@@ -0,0 +1,49 @@
+id: GO-2026-6285
+modules:
+    - module: github.com/mattermost/mattermost-server
+      versions:
+        - introduced: 10.11.0+incompatible
+        - fixed: 10.11.17+incompatible
+        - introduced: 11.5.0+incompatible
+        - fixed: 11.5.5+incompatible
+        - introduced: 11.6.0+incompatible
+        - fixed: 11.6.1+incompatible
+      vulnerable_at: 11.6.1-rc1+incompatible
+    - module: github.com/mattermost/mattermost-server/v5
+      vulnerable_at: 5.39.3
+    - module: github.com/mattermost/mattermost-server/v6
+      vulnerable_at: 6.7.2
+    - module: github.com/mattermost/mattermost/server/v8
+      versions:
+        - introduced: 8.0.0-20250731163400-5b955468ea1e
+        - fixed: 8.0.0-20260501142004-99b73d4c4acf
+summary: |-
+    Mattermost doesn't require system-level permission when patching protected
+    default system roles in github.com/mattermost/mattermost-server
+cves:
+    - CVE-2026-6739
+ghsas:
+    - GHSA-m2w9-h2mm-79qr
+references:
+    - advisory: https://github.com/advisories/GHSA-m2w9-h2mm-79qr
+    - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-6739
+    - web: https://github.com/mattermost/mattermost/commit/2c89c2f6768fbe4dfd57a21ca38c0aecead8d4a8
+    - web: https://github.com/mattermost/mattermost/commit/5e159647b16e571b327ac6882f32eae42971f540
+    - web: https://github.com/mattermost/mattermost/commit/8000e5933526f4fd66b92131db3a1b1f4520dbae
+    - web: https://github.com/mattermost/mattermost/commit/f0a390b96e4c730daedbaf5190684776730218c7
+    - web: https://github.com/mattermost/mattermost/pull/36197
+    - web: https://github.com/mattermost/mattermost/pull/36377
+    - web: https://github.com/mattermost/mattermost/pull/36379
+    - web: https://github.com/mattermost/mattermost/pull/36380
+    - web: https://github.com/mattermost/mattermost/pull/36382
+    - web: https://github.com/mattermost/mattermost/releases/tag/v10.11.16
+    - web: https://github.com/mattermost/mattermost/releases/tag/v11.5.5
+    - web: https://github.com/mattermost/mattermost/releases/tag/v11.6.2
+    - web: https://github.com/mattermost/mattermost/releases/tag/v11.7.0
+    - web: https://mattermost.com/security-updates
+notes:
+    - fix: 'github.com/mattermost/mattermost/server/v8: could not add vulnerable_at: could not find tagged version between introduced and fixed'
+source:
+    id: GHSA-m2w9-h2mm-79qr
+    created: 2026-08-24T21:12:54.88112-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6286.yaml b/data/reports/GO-2026-6286.yaml
new file mode 100644
index 0000000..e1ab93f
--- /dev/null
+++ b/data/reports/GO-2026-6286.yaml
@@ -0,0 +1,48 @@
+id: GO-2026-6286
+modules:
+    - module: github.com/mattermost/mattermost-server
+      versions:
+        - introduced: 10.11.0+incompatible
+        - fixed: 10.11.17+incompatible
+        - introduced: 11.5.0+incompatible
+        - fixed: 11.5.5+incompatible
+        - introduced: 11.6.0+incompatible
+        - fixed: 11.6.1+incompatible
+      vulnerable_at: 11.6.1-rc1+incompatible
+    - module: github.com/mattermost/mattermost-server/v5
+      vulnerable_at: 5.39.3
+    - module: github.com/mattermost/mattermost-server/v6
+      vulnerable_at: 6.7.2
+    - module: github.com/mattermost/mattermost/server/v8
+      versions:
+        - introduced: 8.0.0-20250731163400-5b955468ea1e
+        - fixed: 8.0.0-20260504071740-9408b98025d7
+summary: |-
+    Mattermost doesn't restrict role_updated websocket event broadcasts to members
+    of the affected team or channel in github.com/mattermost/mattermost-server
+cves:
+    - CVE-2026-3433
+ghsas:
+    - GHSA-rp4v-qc77-phm4
+references:
+    - advisory: https://github.com/advisories/GHSA-rp4v-qc77-phm4
+    - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-3433
+    - web: https://github.com/mattermost/mattermost/commit/0a0ab0d54d899d308bd1352cc577036917500318
+    - web: https://github.com/mattermost/mattermost/commit/7425c6817bf244f976c729f8a73cecac8039a1e1
+    - web: https://github.com/mattermost/mattermost/commit/9408b98025d7364d7dfe7cdb28fcd109b1b595a6
+    - web: https://github.com/mattermost/mattermost/commit/a30a331a29b9766d46716d4252056d7b74e66da0
+    - web: https://github.com/mattermost/mattermost/pull/35497
+    - web: https://github.com/mattermost/mattermost/pull/36256
+    - web: https://github.com/mattermost/mattermost/pull/36257
+    - web: https://github.com/mattermost/mattermost/pull/36341
+    - web: https://github.com/mattermost/mattermost/releases/tag/v10.11.16
+    - web: https://github.com/mattermost/mattermost/releases/tag/v11.5.5
+    - web: https://github.com/mattermost/mattermost/releases/tag/v11.6.2
+    - web: https://github.com/mattermost/mattermost/releases/tag/v11.7.0
+    - web: https://mattermost.com/security-updates
+notes:
+    - fix: 'github.com/mattermost/mattermost/server/v8: could not add vulnerable_at: could not find tagged version between introduced and fixed'
+source:
+    id: GHSA-rp4v-qc77-phm4
+    created: 2026-08-24T21:11:39.367569-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6287.yaml b/data/reports/GO-2026-6287.yaml
new file mode 100644
index 0000000..a5e5c43
--- /dev/null
+++ b/data/reports/GO-2026-6287.yaml
@@ -0,0 +1,21 @@
+id: GO-2026-6287
+modules:
+    - module: github.com/cloudreve/Cloudreve
+      vulnerable_at: 0.0.0-20201026073328-746aa3e8ef26
+    - module: github.com/cloudreve/Cloudreve/v3
+      vulnerable_at: 3.0.0-20250225100611-da4e44b77af4
+    - module: github.com/cloudreve/Cloudreve/v4
+      unsupported_versions:
+        - last_affected: 4.0.0-20260606032813-26b6b1044b02
+      vulnerable_at: 4.0.0-20260802015950-20c95ad73f3a
+summary: |-
+    Cloudreve has Broken Access Control - Revoked Share Access Still Allows Signed
+    File URL Generation via Cached context_hint in github.com/cloudreve/Cloudreve
+ghsas:
+    - GHSA-vx2m-jpxr-xv7w
+references:
+    - advisory: https://github.com/cloudreve/cloudreve/security/advisories/GHSA-vx2m-jpxr-xv7w
+source:
+    id: GHSA-vx2m-jpxr-xv7w
+    created: 2026-08-24T21:11:36.871164-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6288.yaml b/data/reports/GO-2026-6288.yaml
new file mode 100644
index 0000000..ec49bd5
--- /dev/null
+++ b/data/reports/GO-2026-6288.yaml
@@ -0,0 +1,21 @@
+id: GO-2026-6288
+modules:
+    - module: github.com/googleapis/genai-toolbox
+      versions:
+        - fixed: 0.25.0
+      vulnerable_at: 0.24.0
+summary: MCP Toolbox for Databases has an Origin Validation Error in github.com/googleapis/genai-toolbox
+cves:
+    - CVE-2026-11624
+ghsas:
+    - GHSA-76g7-m3xw-x9gr
+references:
+    - advisory: https://github.com/advisories/GHSA-76g7-m3xw-x9gr
+    - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-11624
+    - web: https://github.com/googleapis/mcp-toolbox/commit/17b41f64531b8fe417c28ada45d1992ba430dc1b
+    - web: https://github.com/googleapis/mcp-toolbox/issues/3113
+    - web: https://github.com/googleapis/mcp-toolbox/pull/2254
+source:
+    id: GHSA-76g7-m3xw-x9gr
+    created: 2026-08-24T21:11:27.656174-04:00
+review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6289.yaml b/data/reports/GO-2026-6289.yaml
new file mode 100644
index 0000000..7ced993
--- /dev/null
+++ b/data/reports/GO-2026-6289.yaml
@@ -0,0 +1,21 @@
+id: GO-2026-6289
+modules:
+    - module: github.com/cloudreve/Cloudreve
+      vulnerable_at: 0.0.0-20201026073328-746aa3e8ef26
+    - module: github.com/cloudreve/Cloudreve/v3
+      vulnerable_at: 3.0.0-20250225100611-da4e44b77af4
+    - module: github.com/cloudreve/Cloudreve/v4
+      unsupported_versions:
+        - last_affected: 4.0.0-20260606032813-26b6b1044b02
+      vulnerable_at: 4.0.0-20260802015950-20c95ad73f3a
+summary: |-
+    Cloudreve's remote download file paths can escape the selected destination
+    directory in github.com/cloudreve/Cloudreve
+ghsas:
+    - GHSA-w8j7-39hp-8x59
+references:
+    - advisory: https://github.com/cloudreve/cloudreve/security/advisories/GHSA-w8j7-39hp-8x59
+source:
+    id: GHSA-w8j7-39hp-8x59
+    created: 2026-08-24T21:11:22.388565-04:00
+review_status: UNREVIEWED