data/reports: add 25 reports - data/reports/GO-2026-6253.yaml - data/reports/GO-2026-6254.yaml - data/reports/GO-2026-6258.yaml - data/reports/GO-2026-6259.yaml - data/reports/GO-2026-6260.yaml - data/reports/GO-2026-6262.yaml - data/reports/GO-2026-6263.yaml - data/reports/GO-2026-6265.yaml - data/reports/GO-2026-6266.yaml - data/reports/GO-2026-6267.yaml - data/reports/GO-2026-6270.yaml - data/reports/GO-2026-6271.yaml - data/reports/GO-2026-6272.yaml - data/reports/GO-2026-6277.yaml - data/reports/GO-2026-6279.yaml - data/reports/GO-2026-6280.yaml - data/reports/GO-2026-6281.yaml - data/reports/GO-2026-6282.yaml - data/reports/GO-2026-6283.yaml - data/reports/GO-2026-6284.yaml - data/reports/GO-2026-6285.yaml - data/reports/GO-2026-6286.yaml - data/reports/GO-2026-6287.yaml - data/reports/GO-2026-6288.yaml - data/reports/GO-2026-6289.yaml Fixes golang/vulndb#6253 Fixes golang/vulndb#6254 Fixes golang/vulndb#6258 Fixes golang/vulndb#6259 Fixes golang/vulndb#6260 Fixes golang/vulndb#6262 Fixes golang/vulndb#6263 Fixes golang/vulndb#6265 Fixes golang/vulndb#6266 Fixes golang/vulndb#6267 Fixes golang/vulndb#6270 Fixes golang/vulndb#6271 Fixes golang/vulndb#6272 Fixes golang/vulndb#6277 Fixes golang/vulndb#6279 Fixes golang/vulndb#6280 Fixes golang/vulndb#6281 Fixes golang/vulndb#6282 Fixes golang/vulndb#6283 Fixes golang/vulndb#6284 Fixes golang/vulndb#6285 Fixes golang/vulndb#6286 Fixes golang/vulndb#6287 Fixes golang/vulndb#6288 Fixes golang/vulndb#6289 Change-Id: I1678ea89962a128e730bd132d91ba0a5983d7acb Reviewed-on: https://go-review.googlesource.com/c/vulndb/+/820820 LUCI-TryBot-Result: golang-scoped@luci-project-accounts.iam.gserviceaccount.com <golang-scoped@luci-project-accounts.iam.gserviceaccount.com> Reviewed-by: Nicholas Husin <nsh@golang.org> Auto-Submit: Ian Alexander <jitsu@google.com> Reviewed-by: Nicholas Husin <husin@google.com>
diff --git a/data/osv/GO-2026-6253.json b/data/osv/GO-2026-6253.json new file mode 100644 index 0000000..f6b65a9 --- /dev/null +++ b/data/osv/GO-2026-6253.json
@@ -0,0 +1,68 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6253", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-17106", + "GHSA-hfg8-hc9c-6c3h" + ], + "summary": "moby/go-archive: Crafted tar archive can write outside the extraction directory in github.com/moby/go-archive", + "details": "moby/go-archive: Crafted tar archive can write outside the extraction directory in github.com/moby/go-archive", + "affected": [ + { + "package": { + "name": "github.com/moby/go-archive", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.3.0" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/moby/go-archive/security/advisories/GHSA-hfg8-hc9c-6c3h" + }, + { + "type": "WEB", + "url": "https://docs.docker.com/desktop/release-notes/#4860" + }, + { + "type": "WEB", + "url": "https://github.com/bikini/exploitarium/tree/main/docker-cp-copyout-destination-escape" + }, + { + "type": "WEB", + "url": "https://github.com/docker/cli/releases/tag/v29.7.0" + }, + { + "type": "WEB", + "url": "https://github.com/moby/moby/issues/52948" + }, + { + "type": "WEB", + "url": "https://github.com/moby/moby/releases/tag/docker-v29.7.0" + }, + { + "type": "WEB", + "url": "https://www.imperva.com/blog/copyescape-taking-over-docker-hosts-with-docker-cp" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6253", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6254.json b/data/osv/GO-2026-6254.json new file mode 100644 index 0000000..ad4511e --- /dev/null +++ b/data/osv/GO-2026-6254.json
@@ -0,0 +1,48 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6254", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-53941", + "GHSA-vjhx-2cqw-3q6q" + ], + "summary": "Uprobe gadgets: unprivileged container's ld.so.cache causes high CPU utilization and container startup DoS in github.com/inspektor-gadget/inspektor-gadget", + "details": "Uprobe gadgets: unprivileged container's ld.so.cache causes high CPU utilization and container startup DoS in github.com/inspektor-gadget/inspektor-gadget", + "affected": [ + { + "package": { + "name": "github.com/inspektor-gadget/inspektor-gadget", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0.27.0" + }, + { + "fixed": "0.53.1" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/inspektor-gadget/inspektor-gadget/security/advisories/GHSA-vjhx-2cqw-3q6q" + }, + { + "type": "WEB", + "url": "https://github.com/inspektor-gadget/inspektor-gadget/releases/tag/v0.53.1" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6254", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6258.json b/data/osv/GO-2026-6258.json new file mode 100644 index 0000000..f934b24 --- /dev/null +++ b/data/osv/GO-2026-6258.json
@@ -0,0 +1,56 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6258", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-45404", + "GHSA-42cj-99w8-cp2p" + ], + "summary": "OpenTelemetry-Go: Unsynchronized baggage map can panic under concurrent access in go.opentelemetry.io/otel/bridge/opentracing", + "details": "OpenTelemetry-Go: Unsynchronized baggage map can panic under concurrent access in go.opentelemetry.io/otel/bridge/opentracing", + "affected": [ + { + "package": { + "name": "go.opentelemetry.io/otel/bridge/opentracing", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0.11.0" + }, + { + "fixed": "1.45.0" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/open-telemetry/opentelemetry-go/security/advisories/GHSA-42cj-99w8-cp2p" + }, + { + "type": "WEB", + "url": "https://github.com/open-telemetry/opentelemetry-go/commit/93a693edeed0e07ce5ebd1dfe67af42d1e2055d8" + }, + { + "type": "WEB", + "url": "https://github.com/open-telemetry/opentelemetry-go/pull/8693" + }, + { + "type": "WEB", + "url": "https://github.com/open-telemetry/opentelemetry-go/releases/tag/v1.45.0" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6258", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6259.json b/data/osv/GO-2026-6259.json new file mode 100644 index 0000000..706cfe2 --- /dev/null +++ b/data/osv/GO-2026-6259.json
@@ -0,0 +1,48 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6259", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-32637", + "GHSA-j2g6-362q-6qc6" + ], + "summary": "Velero vulnerable to file path traversal when extracting from backup's tarball in github.com/vmware-tanzu/velero", + "details": "Velero vulnerable to file path traversal when extracting from backup's tarball in github.com/vmware-tanzu/velero", + "affected": [ + { + "package": { + "name": "github.com/vmware-tanzu/velero", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.18.1" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/velero-io/velero/security/advisories/GHSA-j2g6-362q-6qc6" + }, + { + "type": "WEB", + "url": "https://github.com/securego/gosec/issues/324" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6259", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6260.json b/data/osv/GO-2026-6260.json new file mode 100644 index 0000000..a8e5f66 --- /dev/null +++ b/data/osv/GO-2026-6260.json
@@ -0,0 +1,52 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6260", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-55149", + "GHSA-qqff-5854-px68" + ], + "summary": "vouch-proxy has an Unbounded Multipart Cookie Allocation DoS in github.com/vouch/vouch-proxy", + "details": "vouch-proxy has an Unbounded Multipart Cookie Allocation DoS in github.com/vouch/vouch-proxy", + "affected": [ + { + "package": { + "name": "github.com/vouch/vouch-proxy", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.48.0" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/vouch/vouch-proxy/security/advisories/GHSA-qqff-5854-px68" + }, + { + "type": "FIX", + "url": "https://github.com/vouch/vouch-proxy/commit/fa18ce30ba50a4863a436acad044c22965329c4f" + }, + { + "type": "WEB", + "url": "https://github.com/vouch/vouch-proxy/releases/tag/v0.48.0" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6260", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6262.json b/data/osv/GO-2026-6262.json new file mode 100644 index 0000000..d890ed8 --- /dev/null +++ b/data/osv/GO-2026-6262.json
@@ -0,0 +1,69 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6262", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "GHSA-22w5-2fxg-vrwx" + ], + "summary": "OpenTofu has high CPU usage when using K8S remote state backend or when parsing specifically crafted TLS certificates from untrusted or compromised servers in github.com/opentofu/opentofu", + "details": "OpenTofu has high CPU usage when using K8S remote state backend or when parsing specifically crafted TLS certificates from untrusted or compromised servers in github.com/opentofu/opentofu", + "affected": [ + { + "package": { + "name": "github.com/opentofu/opentofu", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.11.9" + }, + { + "introduced": "1.12.0-beta1" + }, + { + "fixed": "1.12.2" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/opentofu/opentofu/security/advisories/GHSA-22w5-2fxg-vrwx" + }, + { + "type": "REPORT", + "url": "https://github.com/opentofu/opentofu/issues/4242" + }, + { + "type": "REPORT", + "url": "https://github.com/opentofu/opentofu/issues/4243" + }, + { + "type": "REPORT", + "url": "https://github.com/opentofu/opentofu/issues/4244" + }, + { + "type": "WEB", + "url": "https://github.com/opentofu/opentofu/releases/tag/v1.11.9" + }, + { + "type": "WEB", + "url": "https://github.com/opentofu/opentofu/releases/tag/v1.12.2" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6262", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6263.json b/data/osv/GO-2026-6263.json new file mode 100644 index 0000000..24677c8 --- /dev/null +++ b/data/osv/GO-2026-6263.json
@@ -0,0 +1,62 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6263", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-54168", + "GHSA-6f2p-296r-cc28" + ], + "summary": "Tekton Pipelines-as-Code: Unscoped GitHub App installation token allows unauthorized access to private repositories via remote task resolution in github.com/openshift-pipelines/pipelines-as-code", + "details": "Tekton Pipelines-as-Code: Unscoped GitHub App installation token allows unauthorized access to private repositories via remote task resolution in github.com/openshift-pipelines/pipelines-as-code", + "affected": [ + { + "package": { + "name": "github.com/openshift-pipelines/pipelines-as-code", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.37.8" + }, + { + "introduced": "0.38.0" + }, + { + "fixed": "0.39.6" + }, + { + "introduced": "0.40.0" + }, + { + "fixed": "0.42.1" + }, + { + "introduced": "0.43.0" + }, + { + "fixed": "0.48.0" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/tektoncd/pipelines-as-code/security/advisories/GHSA-6f2p-296r-cc28" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6263", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6265.json b/data/osv/GO-2026-6265.json new file mode 100644 index 0000000..f9a6928 --- /dev/null +++ b/data/osv/GO-2026-6265.json
@@ -0,0 +1,102 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6265", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "GHSA-8fxq-53rx-ph5f" + ], + "summary": "Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder", + "details": "Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder", + "affected": [ + { + "package": { + "name": "github.com/coder/coder", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": {} + }, + { + "package": { + "name": "github.com/coder/coder/v2", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "2.29.17" + }, + { + "introduced": "2.30.0" + }, + { + "fixed": "2.32.7" + }, + { + "introduced": "2.33.0" + }, + { + "fixed": "2.33.8" + }, + { + "introduced": "2.34.0" + }, + { + "fixed": "2.34.2" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/coder/coder/security/advisories/GHSA-8fxq-53rx-ph5f" + }, + { + "type": "FIX", + "url": "https://github.com/coder/coder/commit/35a7dc8ab9c7f15ce05d963947823ee31224512f" + }, + { + "type": "FIX", + "url": "https://github.com/coder/coder/pull/26205" + }, + { + "type": "WEB", + "url": "https://github.com/coder/coder/releases/tag/v2.29.17" + }, + { + "type": "WEB", + "url": "https://github.com/coder/coder/releases/tag/v2.32.7" + }, + { + "type": "WEB", + "url": "https://github.com/coder/coder/releases/tag/v2.33.8" + }, + { + "type": "WEB", + "url": "https://github.com/coder/coder/releases/tag/v2.34.2" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6265", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6266.json b/data/osv/GO-2026-6266.json new file mode 100644 index 0000000..344237f --- /dev/null +++ b/data/osv/GO-2026-6266.json
@@ -0,0 +1,62 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6266", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-54167", + "GHSA-f5f4-3hh4-f54m" + ], + "summary": "Pipelines-as-Code GitHub App token request can be redirected via untrusted Enterprise Host header in github.com/openshift-pipelines/pipelines-as-code", + "details": "Pipelines-as-Code GitHub App token request can be redirected via untrusted Enterprise Host header in github.com/openshift-pipelines/pipelines-as-code", + "affected": [ + { + "package": { + "name": "github.com/openshift-pipelines/pipelines-as-code", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.37.8" + }, + { + "introduced": "0.38.0" + }, + { + "fixed": "0.39.6" + }, + { + "introduced": "0.40.0" + }, + { + "fixed": "0.42.1" + }, + { + "introduced": "0.43.0" + }, + { + "fixed": "0.48.0" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/tektoncd/pipelines-as-code/security/advisories/GHSA-f5f4-3hh4-f54m" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6266", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6267.json b/data/osv/GO-2026-6267.json new file mode 100644 index 0000000..915c6b9 --- /dev/null +++ b/data/osv/GO-2026-6267.json
@@ -0,0 +1,102 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6267", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "GHSA-h58c-xccx-75m3" + ], + "summary": "Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder", + "details": "Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder", + "affected": [ + { + "package": { + "name": "github.com/coder/coder", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": {} + }, + { + "package": { + "name": "github.com/coder/coder/v2", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "2.29.17" + }, + { + "introduced": "2.30.0" + }, + { + "fixed": "2.32.7" + }, + { + "introduced": "2.33.0" + }, + { + "fixed": "2.33.8" + }, + { + "introduced": "2.34.0" + }, + { + "fixed": "2.34.2" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/coder/coder/security/advisories/GHSA-h58c-xccx-75m3" + }, + { + "type": "FIX", + "url": "https://github.com/coder/coder/commit/ec19bc41d80568c0eb9f74b526e8cc8ffbe3be9a" + }, + { + "type": "FIX", + "url": "https://github.com/coder/coder/pull/25804" + }, + { + "type": "WEB", + "url": "https://github.com/coder/coder/releases/tag/v2.29.17" + }, + { + "type": "WEB", + "url": "https://github.com/coder/coder/releases/tag/v2.32.7" + }, + { + "type": "WEB", + "url": "https://github.com/coder/coder/releases/tag/v2.33.8" + }, + { + "type": "WEB", + "url": "https://github.com/coder/coder/releases/tag/v2.34.2" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6267", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6270.json b/data/osv/GO-2026-6270.json new file mode 100644 index 0000000..feb1ead --- /dev/null +++ b/data/osv/GO-2026-6270.json
@@ -0,0 +1,52 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6270", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-54162", + "GHSA-x3g7-qrwc-f6c5" + ], + "summary": "Ember has unneutralized terminal escape/control sequences from Caddy logs injected into the operator's TUI in github.com/alexandre-daubois/ember", + "details": "Ember has unneutralized terminal escape/control sequences from Caddy logs injected into the operator's TUI in github.com/alexandre-daubois/ember", + "affected": [ + { + "package": { + "name": "github.com/alexandre-daubois/ember", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.4.2" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/alexandre-daubois/ember/security/advisories/GHSA-x3g7-qrwc-f6c5" + }, + { + "type": "FIX", + "url": "https://github.com/alexandre-daubois/ember/commit/fcb7160e58dba58d6f9b5033cc312fdedc8c9f6b" + }, + { + "type": "WEB", + "url": "https://github.com/alexandre-daubois/ember/releases/tag/v1.4.2" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6270", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6271.json b/data/osv/GO-2026-6271.json new file mode 100644 index 0000000..3cebd10 --- /dev/null +++ b/data/osv/GO-2026-6271.json
@@ -0,0 +1,52 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6271", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-67448", + "GHSA-8r62-w5wh-fc5m" + ], + "summary": "Mailpit: WebSocket origin check bypass via percent-encoded path (regression of CVE-2026-22689) in github.com/axllent/mailpit", + "details": "Mailpit: WebSocket origin check bypass via percent-encoded path (regression of CVE-2026-22689) in github.com/axllent/mailpit", + "affected": [ + { + "package": { + "name": "github.com/axllent/mailpit", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "1.29.0" + }, + { + "fixed": "1.30.6" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/axllent/mailpit/security/advisories/GHSA-8r62-w5wh-fc5m" + }, + { + "type": "FIX", + "url": "https://github.com/axllent/mailpit/commit/fbe5e006c3f1682b819df58b4a932d7a84920be9" + }, + { + "type": "WEB", + "url": "https://github.com/axllent/mailpit/releases/tag/v1.30.6" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6271", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6272.json b/data/osv/GO-2026-6272.json new file mode 100644 index 0000000..c23168a --- /dev/null +++ b/data/osv/GO-2026-6272.json
@@ -0,0 +1,52 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6272", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-67447", + "GHSA-r553-m4fv-5v97" + ], + "summary": "Mailpit: SMTP DATA line reader buffers over-limit input before size enforcement in github.com/axllent/mailpit", + "details": "Mailpit: SMTP DATA line reader buffers over-limit input before size enforcement in github.com/axllent/mailpit", + "affected": [ + { + "package": { + "name": "github.com/axllent/mailpit", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "1.30.0" + }, + { + "fixed": "1.30.5" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/axllent/mailpit/security/advisories/GHSA-r553-m4fv-5v97" + }, + { + "type": "FIX", + "url": "https://github.com/axllent/mailpit/commit/8720c6bd8281fc00d458081908f1dbef8e59a98c" + }, + { + "type": "WEB", + "url": "https://github.com/axllent/mailpit/releases/tag/v1.30.5" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6272", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6277.json b/data/osv/GO-2026-6277.json new file mode 100644 index 0000000..397bc0b --- /dev/null +++ b/data/osv/GO-2026-6277.json
@@ -0,0 +1,55 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6277", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "GHSA-4ph6-mjv7-3fq6" + ], + "summary": "netfoil vulnerable to improper handling of untrusted DoH response data in github.com/tinfoil-factory/netfoil", + "details": "netfoil vulnerable to improper handling of untrusted DoH response data in github.com/tinfoil-factory/netfoil", + "affected": [ + { + "package": { + "name": "github.com/tinfoil-factory/netfoil", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.5.0" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/tinfoil-factory/netfoil/security/advisories/GHSA-4ph6-mjv7-3fq6" + }, + { + "type": "FIX", + "url": "https://github.com/tinfoil-factory/netfoil/commit/58cfb0cb16b824e02bf53c2d67707e5e4bd9f59b" + }, + { + "type": "FIX", + "url": "https://github.com/tinfoil-factory/netfoil/commit/817f664c61aa64cbe0dbfcdfc05c16602b422e5b" + }, + { + "type": "WEB", + "url": "https://github.com/tinfoil-factory/netfoil/releases/tag/v0.5.0" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6277", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6279.json b/data/osv/GO-2026-6279.json new file mode 100644 index 0000000..e4bc1a8 --- /dev/null +++ b/data/osv/GO-2026-6279.json
@@ -0,0 +1,174 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6279", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-6046", + "GHSA-3vmp-whvv-5v9v" + ], + "summary": "Mattermost doesn't validate that a username returned during bot registration belongs to a bot account in github.com/mattermost/mattermost-server", + "details": "Mattermost doesn't validate that a username returned during bot registration belongs to a bot account in github.com/mattermost/mattermost-server", + "affected": [ + { + "package": { + "name": "github.com/mattermost/mattermost-server", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "10.11.0+incompatible" + }, + { + "fixed": "10.11.17+incompatible" + }, + { + "introduced": "11.5.0+incompatible" + }, + { + "fixed": "11.5.5+incompatible" + }, + { + "introduced": "11.6.0+incompatible" + }, + { + "fixed": "11.6.1+incompatible" + } + ] + } + ], + "ecosystem_specific": {} + }, + { + "package": { + "name": "github.com/mattermost/mattermost-server/v5", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": {} + }, + { + "package": { + "name": "github.com/mattermost/mattermost-server/v6", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": {} + }, + { + "package": { + "name": "github.com/mattermost/mattermost/server/v8", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "8.0.0-20250731163400-5b955468ea1e" + }, + { + "fixed": "8.0.0-20260428151657-c79c3831061a" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-3vmp-whvv-5v9v" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6046" + }, + { + "type": "WEB", + "url": "https://github.com/mattermost/mattermost/commit/3be10297c14d272f273d747af70728f9d03c60ec" + }, + { + "type": "WEB", + "url": "https://github.com/mattermost/mattermost/commit/98f9778cec1e7f3d97b3d4692fb91f8e7b659972" + }, + { + "type": "WEB", + "url": "https://github.com/mattermost/mattermost/commit/aba9339a24d4b287edd77377c19901d6e341bb96" + }, + { + "type": "WEB", + "url": "https://github.com/mattermost/mattermost/commit/c79c3831061a0880c0962c7d567c9e24dd35f44c" + }, + { + "type": "WEB", + "url": "https://github.com/mattermost/mattermost/commit/f706d1f01e6dfe62cab86c1d257f237daa78106a" + }, + { + "type": "WEB", + "url": "https://github.com/mattermost/mattermost/pull/36064" + }, + { + "type": "WEB", + "url": "https://github.com/mattermost/mattermost/pull/36305" + }, + { + "type": "WEB", + "url": "https://github.com/mattermost/mattermost/pull/36317" + }, + { + "type": "WEB", + "url": "https://github.com/mattermost/mattermost/pull/36318" + }, + { + "type": "WEB", + "url": "https://github.com/mattermost/mattermost/pull/36320" + }, + { + "type": "WEB", + "url": "https://github.com/mattermost/mattermost/releases/tag/v10.11.16" + }, + { + "type": "WEB", + "url": "https://github.com/mattermost/mattermost/releases/tag/v11.5.5" + }, + { + "type": "WEB", + "url": "https://github.com/mattermost/mattermost/releases/tag/v11.6.2" + }, + { + "type": "WEB", + "url": "https://github.com/mattermost/mattermost/releases/tag/v11.7.0" + }, + { + "type": "WEB", + "url": "https://mattermost.com/security-updates" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6279", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6280.json b/data/osv/GO-2026-6280.json new file mode 100644 index 0000000..cc0536e --- /dev/null +++ b/data/osv/GO-2026-6280.json
@@ -0,0 +1,174 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6280", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-7387", + "GHSA-6hxm-w4hv-vgvw" + ], + "summary": "Mattermost doesn't require role-management authorization when setting the scheme_admin flag on group syncable link and patch endpoints in github.com/mattermost/mattermost-server", + "details": "Mattermost doesn't require role-management authorization when setting the scheme_admin flag on group syncable link and patch endpoints in github.com/mattermost/mattermost-server", + "affected": [ + { + "package": { + "name": "github.com/mattermost/mattermost-server", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "10.11.0+incompatible" + }, + { + "fixed": "10.11.17+incompatible" + }, + { + "introduced": "11.5.0+incompatible" + }, + { + "fixed": "11.5.5+incompatible" + }, + { + "introduced": "11.6.0+incompatible" + }, + { + "fixed": "11.6.1+incompatible" + } + ] + } + ], + "ecosystem_specific": {} + }, + { + "package": { + "name": "github.com/mattermost/mattermost-server/v5", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": {} + }, + { + "package": { + "name": "github.com/mattermost/mattermost-server/v6", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": {} + }, + { + "package": { + "name": "github.com/mattermost/mattermost/server/v8", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "8.0.0-20250731163400-5b955468ea1e" + }, + { + "fixed": "8.0.0-20260506065351-202d125afa87" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-6hxm-w4hv-vgvw" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-7387" + }, + { + "type": "WEB", + "url": "https://github.com/mattermost/mattermost/commit/1ce2484a00c9821ee19708d2c46720e4855033a9" + }, + { + "type": "WEB", + "url": "https://github.com/mattermost/mattermost/commit/202d125afa87fe39611686850fd82590c99ca344" + }, + { + "type": "WEB", + "url": "https://github.com/mattermost/mattermost/commit/8c72083414e675c97987374395e36d1f36b4bd8a" + }, + { + "type": "WEB", + "url": "https://github.com/mattermost/mattermost/commit/a9e574a82633915f22071f0d7ca2b006f249ec2a" + }, + { + "type": "WEB", + "url": "https://github.com/mattermost/mattermost/commit/d5f29c8ebbeb04460d16d9e2635ce50deeb78428" + }, + { + "type": "WEB", + "url": "https://github.com/mattermost/mattermost/pull/36316" + }, + { + "type": "WEB", + "url": "https://github.com/mattermost/mattermost/pull/36423" + }, + { + "type": "WEB", + "url": "https://github.com/mattermost/mattermost/pull/36431" + }, + { + "type": "WEB", + "url": "https://github.com/mattermost/mattermost/pull/36432" + }, + { + "type": "WEB", + "url": "https://github.com/mattermost/mattermost/pull/36434" + }, + { + "type": "WEB", + "url": "https://github.com/mattermost/mattermost/releases/tag/v10.11.16" + }, + { + "type": "WEB", + "url": "https://github.com/mattermost/mattermost/releases/tag/v11.5.5" + }, + { + "type": "WEB", + "url": "https://github.com/mattermost/mattermost/releases/tag/v11.6.2" + }, + { + "type": "WEB", + "url": "https://github.com/mattermost/mattermost/releases/tag/v11.7.0" + }, + { + "type": "WEB", + "url": "https://mattermost.com/security-updates" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6280", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6281.json b/data/osv/GO-2026-6281.json new file mode 100644 index 0000000..1ec031d --- /dev/null +++ b/data/osv/GO-2026-6281.json
@@ -0,0 +1,174 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6281", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-6961", + "GHSA-8qq9-cqj8-82w4" + ], + "summary": "Mattermost doesn't sanitize FileInfo.Name received from federated peers during shared channel file sync in github.com/mattermost/mattermost-server", + "details": "Mattermost doesn't sanitize FileInfo.Name received from federated peers during shared channel file sync in github.com/mattermost/mattermost-server", + "affected": [ + { + "package": { + "name": "github.com/mattermost/mattermost-server", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "10.11.0+incompatible" + }, + { + "fixed": "10.11.17+incompatible" + }, + { + "introduced": "11.5.0+incompatible" + }, + { + "fixed": "11.5.5+incompatible" + }, + { + "introduced": "11.6.0+incompatible" + }, + { + "fixed": "11.6.1+incompatible" + } + ] + } + ], + "ecosystem_specific": {} + }, + { + "package": { + "name": "github.com/mattermost/mattermost-server/v5", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": {} + }, + { + "package": { + "name": "github.com/mattermost/mattermost-server/v6", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": {} + }, + { + "package": { + "name": "github.com/mattermost/mattermost/server/v8", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "8.0.0-20250731163400-5b955468ea1e" + }, + { + "fixed": "8.0.0-20260423180926-c021eeaff8f0" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-8qq9-cqj8-82w4" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6961" + }, + { + "type": "WEB", + "url": "https://github.com/mattermost/mattermost/commit/61d68d2d6ee81a5919597d91c736c502d7156859" + }, + { + "type": "WEB", + "url": "https://github.com/mattermost/mattermost/commit/a0056ed68d95f64d7c4586985e7b7f16b96b3bec" + }, + { + "type": "WEB", + "url": "https://github.com/mattermost/mattermost/commit/a9f3868e1eee9ec61855cd7277f39937385efffd" + }, + { + "type": "WEB", + "url": "https://github.com/mattermost/mattermost/commit/c021eeaff8f003034ab40f82c552cc26a710a8fd" + }, + { + "type": "WEB", + "url": "https://github.com/mattermost/mattermost/commit/c896a63dc44c2f9c081a0a15bfddc4e6eb50e753" + }, + { + "type": "WEB", + "url": "https://github.com/mattermost/mattermost/pull/36223" + }, + { + "type": "WEB", + "url": "https://github.com/mattermost/mattermost/pull/36251" + }, + { + "type": "WEB", + "url": "https://github.com/mattermost/mattermost/pull/36252" + }, + { + "type": "WEB", + "url": "https://github.com/mattermost/mattermost/pull/36253" + }, + { + "type": "WEB", + "url": "https://github.com/mattermost/mattermost/pull/36255" + }, + { + "type": "WEB", + "url": "https://github.com/mattermost/mattermost/releases/tag/v10.11.16" + }, + { + "type": "WEB", + "url": "https://github.com/mattermost/mattermost/releases/tag/v11.5.5" + }, + { + "type": "WEB", + "url": "https://github.com/mattermost/mattermost/releases/tag/v11.6.2" + }, + { + "type": "WEB", + "url": "https://github.com/mattermost/mattermost/releases/tag/v11.7.0" + }, + { + "type": "WEB", + "url": "https://mattermost.com/security-updates" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6281", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6282.json b/data/osv/GO-2026-6282.json new file mode 100644 index 0000000..3417b38 --- /dev/null +++ b/data/osv/GO-2026-6282.json
@@ -0,0 +1,174 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6282", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-7184", + "GHSA-9p44-r552-4wp9" + ], + "summary": "Mattermost doesn't sanitize the Remote Cluster API response on PATCH operations in github.com/mattermost/mattermost-server", + "details": "Mattermost doesn't sanitize the Remote Cluster API response on PATCH operations in github.com/mattermost/mattermost-server", + "affected": [ + { + "package": { + "name": "github.com/mattermost/mattermost-server", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "10.11.0+incompatible" + }, + { + "fixed": "10.11.16+incompatible" + }, + { + "introduced": "11.5.0+incompatible" + }, + { + "fixed": "11.5.5+incompatible" + }, + { + "introduced": "11.6.0+incompatible" + }, + { + "fixed": "11.6.1+incompatible" + } + ] + } + ], + "ecosystem_specific": {} + }, + { + "package": { + "name": "github.com/mattermost/mattermost-server/v5", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": {} + }, + { + "package": { + "name": "github.com/mattermost/mattermost-server/v6", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": {} + }, + { + "package": { + "name": "github.com/mattermost/mattermost/server/v8", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "8.0.0-20250731163400-5b955468ea1e" + }, + { + "fixed": "8.0.0-20260428142921-bd8fc9222672" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-9p44-r552-4wp9" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-7184" + }, + { + "type": "WEB", + "url": "https://github.com/mattermost/mattermost/commit/1a0643df00c1f51a3b7e919eec034eaf955f612f" + }, + { + "type": "WEB", + "url": "https://github.com/mattermost/mattermost/commit/6fd49f56b5920569218fd2fc76d8ae802942f274" + }, + { + "type": "WEB", + "url": "https://github.com/mattermost/mattermost/commit/bd8fc92226726da06c8fabaef568cc9ebaee1cb8" + }, + { + "type": "WEB", + "url": "https://github.com/mattermost/mattermost/commit/c5e67e28271c23cb585fe1a30ae81defcde848d6" + }, + { + "type": "WEB", + "url": "https://github.com/mattermost/mattermost/commit/cad3e8e51a4d8627af6442f9df8ae3667fac7fc1" + }, + { + "type": "WEB", + "url": "https://github.com/mattermost/mattermost/pull/36288" + }, + { + "type": "WEB", + "url": "https://github.com/mattermost/mattermost/pull/36306" + }, + { + "type": "WEB", + "url": "https://github.com/mattermost/mattermost/pull/36310" + }, + { + "type": "WEB", + "url": "https://github.com/mattermost/mattermost/pull/36311" + }, + { + "type": "WEB", + "url": "https://github.com/mattermost/mattermost/pull/36313" + }, + { + "type": "WEB", + "url": "https://github.com/mattermost/mattermost/releases/tag/v10.11.16" + }, + { + "type": "WEB", + "url": "https://github.com/mattermost/mattermost/releases/tag/v11.5.5" + }, + { + "type": "WEB", + "url": "https://github.com/mattermost/mattermost/releases/tag/v11.6.2" + }, + { + "type": "WEB", + "url": "https://github.com/mattermost/mattermost/releases/tag/v11.7.0" + }, + { + "type": "WEB", + "url": "https://mattermost.com/security-updates" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6282", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6283.json b/data/osv/GO-2026-6283.json new file mode 100644 index 0000000..0e1b095 --- /dev/null +++ b/data/osv/GO-2026-6283.json
@@ -0,0 +1,174 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6283", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-6689", + "GHSA-c28q-m4gf-vg4q" + ], + "summary": "Mattermost doesn't enforce PermissionInviteUser when setting AllowOpenInvite or AllowedDomains during team creation in github.com/mattermost/mattermost-server", + "details": "Mattermost doesn't enforce PermissionInviteUser when setting AllowOpenInvite or AllowedDomains during team creation in github.com/mattermost/mattermost-server", + "affected": [ + { + "package": { + "name": "github.com/mattermost/mattermost-server", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "10.11.0+incompatible" + }, + { + "fixed": "10.11.17+incompatible" + }, + { + "introduced": "11.5.0+incompatible" + }, + { + "fixed": "11.5.5+incompatible" + }, + { + "introduced": "11.6.0+incompatible" + }, + { + "fixed": "11.6.1+incompatible" + } + ] + } + ], + "ecosystem_specific": {} + }, + { + "package": { + "name": "github.com/mattermost/mattermost-server/v5", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": {} + }, + { + "package": { + "name": "github.com/mattermost/mattermost-server/v6", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": {} + }, + { + "package": { + "name": "github.com/mattermost/mattermost/server/v8", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "8.0.0-20250731163400-5b955468ea1e" + }, + { + "fixed": "8.0.0-20260501144115-7d6816abdfd1" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-c28q-m4gf-vg4q" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6689" + }, + { + "type": "WEB", + "url": "https://github.com/mattermost/mattermost/commit/2dea05864024b3254fb28c5ed679592e2b7cd672" + }, + { + "type": "WEB", + "url": "https://github.com/mattermost/mattermost/commit/3a96344214b1a84df70d97052d46b6f2b40b0caa" + }, + { + "type": "WEB", + "url": "https://github.com/mattermost/mattermost/commit/479fc42d0ec6da48e76b59608233d90bfc69769d" + }, + { + "type": "WEB", + "url": "https://github.com/mattermost/mattermost/commit/7d6816abdfd170169f717aea43c5716a1f9ef6b0" + }, + { + "type": "WEB", + "url": "https://github.com/mattermost/mattermost/commit/977c791e5b54bc14fdb96a2b3dacc85da5d8c623" + }, + { + "type": "WEB", + "url": "https://github.com/mattermost/mattermost/pull/36188" + }, + { + "type": "WEB", + "url": "https://github.com/mattermost/mattermost/pull/36375" + }, + { + "type": "WEB", + "url": "https://github.com/mattermost/mattermost/pull/36383" + }, + { + "type": "WEB", + "url": "https://github.com/mattermost/mattermost/pull/36384" + }, + { + "type": "WEB", + "url": "https://github.com/mattermost/mattermost/pull/36402" + }, + { + "type": "WEB", + "url": "https://github.com/mattermost/mattermost/releases/tag/v10.11.16" + }, + { + "type": "WEB", + "url": "https://github.com/mattermost/mattermost/releases/tag/v11.5.5" + }, + { + "type": "WEB", + "url": "https://github.com/mattermost/mattermost/releases/tag/v11.6.2" + }, + { + "type": "WEB", + "url": "https://github.com/mattermost/mattermost/releases/tag/v11.7.0" + }, + { + "type": "WEB", + "url": "https://mattermost.com/security-updates" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6283", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6284.json b/data/osv/GO-2026-6284.json new file mode 100644 index 0000000..fbf22e2 --- /dev/null +++ b/data/osv/GO-2026-6284.json
@@ -0,0 +1,90 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6284", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-55477", + "GHSA-jm48-m3rr-9hgg" + ], + "summary": "3X-UI Vulnerable to Authenticated Arbitrary File Write via Database Import and Xray Log Path Manipulation in github.com/mhsanaei/3x-ui", + "details": "3X-UI Vulnerable to Authenticated Arbitrary File Write via Database Import and Xray Log Path Manipulation in github.com/mhsanaei/3x-ui", + "affected": [ + { + "package": { + "name": "github.com/mhsanaei/3x-ui", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": {} + }, + { + "package": { + "name": "github.com/mhsanaei/3x-ui/v2", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": {} + }, + { + "package": { + "name": "github.com/mhsanaei/3x-ui/v3", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "3.3.1" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/MHSanaei/3x-ui/security/advisories/GHSA-jm48-m3rr-9hgg" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-55477" + }, + { + "type": "WEB", + "url": "https://github.com/MHSanaei/3x-ui/commit/80e168787ed608e83a065033ee94c8bfc3025ce7" + }, + { + "type": "WEB", + "url": "https://github.com/MHSanaei/3x-ui/releases/tag/v3.3.1" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6284", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6285.json b/data/osv/GO-2026-6285.json new file mode 100644 index 0000000..624792d --- /dev/null +++ b/data/osv/GO-2026-6285.json
@@ -0,0 +1,170 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6285", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-6739", + "GHSA-m2w9-h2mm-79qr" + ], + "summary": "Mattermost doesn't require system-level permission when patching protected default system roles in github.com/mattermost/mattermost-server", + "details": "Mattermost doesn't require system-level permission when patching protected default system roles in github.com/mattermost/mattermost-server", + "affected": [ + { + "package": { + "name": "github.com/mattermost/mattermost-server", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "10.11.0+incompatible" + }, + { + "fixed": "10.11.17+incompatible" + }, + { + "introduced": "11.5.0+incompatible" + }, + { + "fixed": "11.5.5+incompatible" + }, + { + "introduced": "11.6.0+incompatible" + }, + { + "fixed": "11.6.1+incompatible" + } + ] + } + ], + "ecosystem_specific": {} + }, + { + "package": { + "name": "github.com/mattermost/mattermost-server/v5", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": {} + }, + { + "package": { + "name": "github.com/mattermost/mattermost-server/v6", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": {} + }, + { + "package": { + "name": "github.com/mattermost/mattermost/server/v8", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "8.0.0-20250731163400-5b955468ea1e" + }, + { + "fixed": "8.0.0-20260501142004-99b73d4c4acf" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-m2w9-h2mm-79qr" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6739" + }, + { + "type": "WEB", + "url": "https://github.com/mattermost/mattermost/commit/2c89c2f6768fbe4dfd57a21ca38c0aecead8d4a8" + }, + { + "type": "WEB", + "url": "https://github.com/mattermost/mattermost/commit/5e159647b16e571b327ac6882f32eae42971f540" + }, + { + "type": "WEB", + "url": "https://github.com/mattermost/mattermost/commit/8000e5933526f4fd66b92131db3a1b1f4520dbae" + }, + { + "type": "WEB", + "url": "https://github.com/mattermost/mattermost/commit/f0a390b96e4c730daedbaf5190684776730218c7" + }, + { + "type": "WEB", + "url": "https://github.com/mattermost/mattermost/pull/36197" + }, + { + "type": "WEB", + "url": "https://github.com/mattermost/mattermost/pull/36377" + }, + { + "type": "WEB", + "url": "https://github.com/mattermost/mattermost/pull/36379" + }, + { + "type": "WEB", + "url": "https://github.com/mattermost/mattermost/pull/36380" + }, + { + "type": "WEB", + "url": "https://github.com/mattermost/mattermost/pull/36382" + }, + { + "type": "WEB", + "url": "https://github.com/mattermost/mattermost/releases/tag/v10.11.16" + }, + { + "type": "WEB", + "url": "https://github.com/mattermost/mattermost/releases/tag/v11.5.5" + }, + { + "type": "WEB", + "url": "https://github.com/mattermost/mattermost/releases/tag/v11.6.2" + }, + { + "type": "WEB", + "url": "https://github.com/mattermost/mattermost/releases/tag/v11.7.0" + }, + { + "type": "WEB", + "url": "https://mattermost.com/security-updates" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6285", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6286.json b/data/osv/GO-2026-6286.json new file mode 100644 index 0000000..e14b844 --- /dev/null +++ b/data/osv/GO-2026-6286.json
@@ -0,0 +1,166 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6286", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-3433", + "GHSA-rp4v-qc77-phm4" + ], + "summary": "Mattermost doesn't restrict role_updated websocket event broadcasts to members of the affected team or channel in github.com/mattermost/mattermost-server", + "details": "Mattermost doesn't restrict role_updated websocket event broadcasts to members of the affected team or channel in github.com/mattermost/mattermost-server", + "affected": [ + { + "package": { + "name": "github.com/mattermost/mattermost-server", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "10.11.0+incompatible" + }, + { + "fixed": "10.11.17+incompatible" + }, + { + "introduced": "11.5.0+incompatible" + }, + { + "fixed": "11.5.5+incompatible" + }, + { + "introduced": "11.6.0+incompatible" + }, + { + "fixed": "11.6.1+incompatible" + } + ] + } + ], + "ecosystem_specific": {} + }, + { + "package": { + "name": "github.com/mattermost/mattermost-server/v5", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": {} + }, + { + "package": { + "name": "github.com/mattermost/mattermost-server/v6", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": {} + }, + { + "package": { + "name": "github.com/mattermost/mattermost/server/v8", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "8.0.0-20250731163400-5b955468ea1e" + }, + { + "fixed": "8.0.0-20260504071740-9408b98025d7" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-rp4v-qc77-phm4" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-3433" + }, + { + "type": "WEB", + "url": "https://github.com/mattermost/mattermost/commit/0a0ab0d54d899d308bd1352cc577036917500318" + }, + { + "type": "WEB", + "url": "https://github.com/mattermost/mattermost/commit/7425c6817bf244f976c729f8a73cecac8039a1e1" + }, + { + "type": "WEB", + "url": "https://github.com/mattermost/mattermost/commit/9408b98025d7364d7dfe7cdb28fcd109b1b595a6" + }, + { + "type": "WEB", + "url": "https://github.com/mattermost/mattermost/commit/a30a331a29b9766d46716d4252056d7b74e66da0" + }, + { + "type": "WEB", + "url": "https://github.com/mattermost/mattermost/pull/35497" + }, + { + "type": "WEB", + "url": "https://github.com/mattermost/mattermost/pull/36256" + }, + { + "type": "WEB", + "url": "https://github.com/mattermost/mattermost/pull/36257" + }, + { + "type": "WEB", + "url": "https://github.com/mattermost/mattermost/pull/36341" + }, + { + "type": "WEB", + "url": "https://github.com/mattermost/mattermost/releases/tag/v10.11.16" + }, + { + "type": "WEB", + "url": "https://github.com/mattermost/mattermost/releases/tag/v11.5.5" + }, + { + "type": "WEB", + "url": "https://github.com/mattermost/mattermost/releases/tag/v11.6.2" + }, + { + "type": "WEB", + "url": "https://github.com/mattermost/mattermost/releases/tag/v11.7.0" + }, + { + "type": "WEB", + "url": "https://mattermost.com/security-updates" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6286", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6287.json b/data/osv/GO-2026-6287.json new file mode 100644 index 0000000..bfe0d06 --- /dev/null +++ b/data/osv/GO-2026-6287.json
@@ -0,0 +1,74 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6287", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "GHSA-vx2m-jpxr-xv7w" + ], + "summary": "Cloudreve has Broken Access Control - Revoked Share Access Still Allows Signed File URL Generation via Cached context_hint in github.com/cloudreve/Cloudreve", + "details": "Cloudreve has Broken Access Control - Revoked Share Access Still Allows Signed File URL Generation via Cached context_hint in github.com/cloudreve/Cloudreve", + "affected": [ + { + "package": { + "name": "github.com/cloudreve/Cloudreve", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": {} + }, + { + "package": { + "name": "github.com/cloudreve/Cloudreve/v3", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": {} + }, + { + "package": { + "name": "github.com/cloudreve/Cloudreve/v4", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/cloudreve/cloudreve/security/advisories/GHSA-vx2m-jpxr-xv7w" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6287", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6288.json b/data/osv/GO-2026-6288.json new file mode 100644 index 0000000..a0ef11f --- /dev/null +++ b/data/osv/GO-2026-6288.json
@@ -0,0 +1,60 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6288", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-11624", + "GHSA-76g7-m3xw-x9gr" + ], + "summary": "MCP Toolbox for Databases has an Origin Validation Error in github.com/googleapis/genai-toolbox", + "details": "MCP Toolbox for Databases has an Origin Validation Error in github.com/googleapis/genai-toolbox", + "affected": [ + { + "package": { + "name": "github.com/googleapis/genai-toolbox", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.25.0" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-76g7-m3xw-x9gr" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-11624" + }, + { + "type": "WEB", + "url": "https://github.com/googleapis/mcp-toolbox/commit/17b41f64531b8fe417c28ada45d1992ba430dc1b" + }, + { + "type": "WEB", + "url": "https://github.com/googleapis/mcp-toolbox/issues/3113" + }, + { + "type": "WEB", + "url": "https://github.com/googleapis/mcp-toolbox/pull/2254" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6288", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6289.json b/data/osv/GO-2026-6289.json new file mode 100644 index 0000000..c2e8ce6 --- /dev/null +++ b/data/osv/GO-2026-6289.json
@@ -0,0 +1,74 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6289", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "GHSA-w8j7-39hp-8x59" + ], + "summary": "Cloudreve's remote download file paths can escape the selected destination directory in github.com/cloudreve/Cloudreve", + "details": "Cloudreve's remote download file paths can escape the selected destination directory in github.com/cloudreve/Cloudreve", + "affected": [ + { + "package": { + "name": "github.com/cloudreve/Cloudreve", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": {} + }, + { + "package": { + "name": "github.com/cloudreve/Cloudreve/v3", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": {} + }, + { + "package": { + "name": "github.com/cloudreve/Cloudreve/v4", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/cloudreve/cloudreve/security/advisories/GHSA-w8j7-39hp-8x59" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6289", + "review_status": "UNREVIEWED" + } +} \ No newline at end of file
diff --git a/data/reports/GO-2026-6253.yaml b/data/reports/GO-2026-6253.yaml new file mode 100644 index 0000000..e380b07 --- /dev/null +++ b/data/reports/GO-2026-6253.yaml
@@ -0,0 +1,23 @@ +id: GO-2026-6253 +modules: + - module: github.com/moby/go-archive + versions: + - fixed: 0.3.0 + vulnerable_at: 0.2.1 +summary: 'moby/go-archive: Crafted tar archive can write outside the extraction directory in github.com/moby/go-archive' +cves: + - CVE-2026-17106 +ghsas: + - GHSA-hfg8-hc9c-6c3h +references: + - advisory: https://github.com/moby/go-archive/security/advisories/GHSA-hfg8-hc9c-6c3h + - web: https://docs.docker.com/desktop/release-notes/#4860 + - web: https://github.com/bikini/exploitarium/tree/main/docker-cp-copyout-destination-escape + - web: https://github.com/docker/cli/releases/tag/v29.7.0 + - web: https://github.com/moby/moby/issues/52948 + - web: https://github.com/moby/moby/releases/tag/docker-v29.7.0 + - web: https://www.imperva.com/blog/copyescape-taking-over-docker-hosts-with-docker-cp +source: + id: GHSA-hfg8-hc9c-6c3h + created: 2026-08-24T21:38:53.334308-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6254.yaml b/data/reports/GO-2026-6254.yaml new file mode 100644 index 0000000..cd1efb8 --- /dev/null +++ b/data/reports/GO-2026-6254.yaml
@@ -0,0 +1,21 @@ +id: GO-2026-6254 +modules: + - module: github.com/inspektor-gadget/inspektor-gadget + versions: + - introduced: 0.27.0 + - fixed: 0.53.1 + vulnerable_at: 0.53.0 +summary: |- + Uprobe gadgets: unprivileged container's ld.so.cache causes high CPU utilization + and container startup DoS in github.com/inspektor-gadget/inspektor-gadget +cves: + - CVE-2026-53941 +ghsas: + - GHSA-vjhx-2cqw-3q6q +references: + - advisory: https://github.com/inspektor-gadget/inspektor-gadget/security/advisories/GHSA-vjhx-2cqw-3q6q + - web: https://github.com/inspektor-gadget/inspektor-gadget/releases/tag/v0.53.1 +source: + id: GHSA-vjhx-2cqw-3q6q + created: 2026-08-24T21:38:47.793237-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6258.yaml b/data/reports/GO-2026-6258.yaml new file mode 100644 index 0000000..008c9f2 --- /dev/null +++ b/data/reports/GO-2026-6258.yaml
@@ -0,0 +1,21 @@ +id: GO-2026-6258 +modules: + - module: go.opentelemetry.io/otel/bridge/opentracing + versions: + - introduced: 0.11.0 + - fixed: 1.45.0 + vulnerable_at: 1.44.0 +summary: 'OpenTelemetry-Go: Unsynchronized baggage map can panic under concurrent access in go.opentelemetry.io/otel/bridge/opentracing' +cves: + - CVE-2026-45404 +ghsas: + - GHSA-42cj-99w8-cp2p +references: + - advisory: https://github.com/open-telemetry/opentelemetry-go/security/advisories/GHSA-42cj-99w8-cp2p + - web: https://github.com/open-telemetry/opentelemetry-go/commit/93a693edeed0e07ce5ebd1dfe67af42d1e2055d8 + - web: https://github.com/open-telemetry/opentelemetry-go/pull/8693 + - web: https://github.com/open-telemetry/opentelemetry-go/releases/tag/v1.45.0 +source: + id: GHSA-42cj-99w8-cp2p + created: 2026-08-24T21:37:03.480167-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6259.yaml b/data/reports/GO-2026-6259.yaml new file mode 100644 index 0000000..b58025a --- /dev/null +++ b/data/reports/GO-2026-6259.yaml
@@ -0,0 +1,18 @@ +id: GO-2026-6259 +modules: + - module: github.com/vmware-tanzu/velero + versions: + - fixed: 1.18.1 + vulnerable_at: 1.18.1-rc.2 +summary: Velero vulnerable to file path traversal when extracting from backup's tarball in github.com/vmware-tanzu/velero +cves: + - CVE-2026-32637 +ghsas: + - GHSA-j2g6-362q-6qc6 +references: + - advisory: https://github.com/velero-io/velero/security/advisories/GHSA-j2g6-362q-6qc6 + - web: https://github.com/securego/gosec/issues/324 +source: + id: GHSA-j2g6-362q-6qc6 + created: 2026-08-24T21:36:57.513666-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6260.yaml b/data/reports/GO-2026-6260.yaml new file mode 100644 index 0000000..3cc1930 --- /dev/null +++ b/data/reports/GO-2026-6260.yaml
@@ -0,0 +1,19 @@ +id: GO-2026-6260 +modules: + - module: github.com/vouch/vouch-proxy + versions: + - fixed: 0.48.0 + vulnerable_at: 0.47.2 +summary: vouch-proxy has an Unbounded Multipart Cookie Allocation DoS in github.com/vouch/vouch-proxy +cves: + - CVE-2026-55149 +ghsas: + - GHSA-qqff-5854-px68 +references: + - advisory: https://github.com/vouch/vouch-proxy/security/advisories/GHSA-qqff-5854-px68 + - fix: https://github.com/vouch/vouch-proxy/commit/fa18ce30ba50a4863a436acad044c22965329c4f + - web: https://github.com/vouch/vouch-proxy/releases/tag/v0.48.0 +source: + id: GHSA-qqff-5854-px68 + created: 2026-08-24T21:36:51.179521-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6262.yaml b/data/reports/GO-2026-6262.yaml new file mode 100644 index 0000000..df2b3da --- /dev/null +++ b/data/reports/GO-2026-6262.yaml
@@ -0,0 +1,24 @@ +id: GO-2026-6262 +modules: + - module: github.com/opentofu/opentofu + versions: + - fixed: 1.11.9 + - introduced: 1.12.0-beta1 + - fixed: 1.12.2 + vulnerable_at: 1.12.1 +summary: |- + OpenTofu has high CPU usage when using K8S remote state backend or when parsing + specifically crafted TLS certificates from untrusted or compromised servers in github.com/opentofu/opentofu +ghsas: + - GHSA-22w5-2fxg-vrwx +references: + - advisory: https://github.com/opentofu/opentofu/security/advisories/GHSA-22w5-2fxg-vrwx + - report: https://github.com/opentofu/opentofu/issues/4242 + - report: https://github.com/opentofu/opentofu/issues/4243 + - report: https://github.com/opentofu/opentofu/issues/4244 + - web: https://github.com/opentofu/opentofu/releases/tag/v1.11.9 + - web: https://github.com/opentofu/opentofu/releases/tag/v1.12.2 +source: + id: GHSA-22w5-2fxg-vrwx + created: 2026-08-24T21:22:17.062569-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6263.yaml b/data/reports/GO-2026-6263.yaml new file mode 100644 index 0000000..c797e37 --- /dev/null +++ b/data/reports/GO-2026-6263.yaml
@@ -0,0 +1,25 @@ +id: GO-2026-6263 +modules: + - module: github.com/openshift-pipelines/pipelines-as-code + versions: + - fixed: 0.37.8 + - introduced: 0.38.0 + - fixed: 0.39.6 + - introduced: 0.40.0 + - fixed: 0.42.1 + - introduced: 0.43.0 + - fixed: 0.48.0 + vulnerable_at: 0.47.0 +summary: |- + Tekton Pipelines-as-Code: Unscoped GitHub App installation token allows + unauthorized access to private repositories via remote task resolution in github.com/openshift-pipelines/pipelines-as-code +cves: + - CVE-2026-54168 +ghsas: + - GHSA-6f2p-296r-cc28 +references: + - advisory: https://github.com/tektoncd/pipelines-as-code/security/advisories/GHSA-6f2p-296r-cc28 +source: + id: GHSA-6f2p-296r-cc28 + created: 2026-08-24T21:22:13.304323-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6265.yaml b/data/reports/GO-2026-6265.yaml new file mode 100644 index 0000000..2226da9 --- /dev/null +++ b/data/reports/GO-2026-6265.yaml
@@ -0,0 +1,31 @@ +id: GO-2026-6265 +modules: + - module: github.com/coder/coder + vulnerable_at: 0.27.3 + - module: github.com/coder/coder/v2 + versions: + - fixed: 2.29.17 + - introduced: 2.30.0 + - fixed: 2.32.7 + - introduced: 2.33.0 + - fixed: 2.33.8 + - introduced: 2.34.0 + - fixed: 2.34.2 + vulnerable_at: 2.34.1 +summary: |- + Coder: Login endpoint user enumeration via timing-defense placeholder in + password comparison in github.com/coder/coder +ghsas: + - GHSA-8fxq-53rx-ph5f +references: + - advisory: https://github.com/coder/coder/security/advisories/GHSA-8fxq-53rx-ph5f + - fix: https://github.com/coder/coder/commit/35a7dc8ab9c7f15ce05d963947823ee31224512f + - fix: https://github.com/coder/coder/pull/26205 + - web: https://github.com/coder/coder/releases/tag/v2.29.17 + - web: https://github.com/coder/coder/releases/tag/v2.32.7 + - web: https://github.com/coder/coder/releases/tag/v2.33.8 + - web: https://github.com/coder/coder/releases/tag/v2.34.2 +source: + id: GHSA-8fxq-53rx-ph5f + created: 2026-08-24T21:21:06.952342-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6266.yaml b/data/reports/GO-2026-6266.yaml new file mode 100644 index 0000000..a54f654 --- /dev/null +++ b/data/reports/GO-2026-6266.yaml
@@ -0,0 +1,25 @@ +id: GO-2026-6266 +modules: + - module: github.com/openshift-pipelines/pipelines-as-code + versions: + - fixed: 0.37.8 + - introduced: 0.38.0 + - fixed: 0.39.6 + - introduced: 0.40.0 + - fixed: 0.42.1 + - introduced: 0.43.0 + - fixed: 0.48.0 + vulnerable_at: 0.47.0 +summary: |- + Pipelines-as-Code GitHub App token request can be redirected via untrusted + Enterprise Host header in github.com/openshift-pipelines/pipelines-as-code +cves: + - CVE-2026-54167 +ghsas: + - GHSA-f5f4-3hh4-f54m +references: + - advisory: https://github.com/tektoncd/pipelines-as-code/security/advisories/GHSA-f5f4-3hh4-f54m +source: + id: GHSA-f5f4-3hh4-f54m + created: 2026-08-24T21:21:02.953327-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6267.yaml b/data/reports/GO-2026-6267.yaml new file mode 100644 index 0000000..47b9954 --- /dev/null +++ b/data/reports/GO-2026-6267.yaml
@@ -0,0 +1,31 @@ +id: GO-2026-6267 +modules: + - module: github.com/coder/coder + vulnerable_at: 0.27.3 + - module: github.com/coder/coder/v2 + versions: + - fixed: 2.29.17 + - introduced: 2.30.0 + - fixed: 2.32.7 + - introduced: 2.33.0 + - fixed: 2.33.8 + - introduced: 2.34.0 + - fixed: 2.34.2 + vulnerable_at: 2.34.1 +summary: |- + Coder: Stored HTML injection via unescaped ApplicationName and LogoURL + appearance settings in github.com/coder/coder +ghsas: + - GHSA-h58c-xccx-75m3 +references: + - advisory: https://github.com/coder/coder/security/advisories/GHSA-h58c-xccx-75m3 + - fix: https://github.com/coder/coder/commit/ec19bc41d80568c0eb9f74b526e8cc8ffbe3be9a + - fix: https://github.com/coder/coder/pull/25804 + - web: https://github.com/coder/coder/releases/tag/v2.29.17 + - web: https://github.com/coder/coder/releases/tag/v2.32.7 + - web: https://github.com/coder/coder/releases/tag/v2.33.8 + - web: https://github.com/coder/coder/releases/tag/v2.34.2 +source: + id: GHSA-h58c-xccx-75m3 + created: 2026-08-24T21:20:57.250057-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6270.yaml b/data/reports/GO-2026-6270.yaml new file mode 100644 index 0000000..8d6f52a --- /dev/null +++ b/data/reports/GO-2026-6270.yaml
@@ -0,0 +1,21 @@ +id: GO-2026-6270 +modules: + - module: github.com/alexandre-daubois/ember + versions: + - fixed: 1.4.2 + vulnerable_at: 1.4.1 +summary: |- + Ember has unneutralized terminal escape/control sequences from Caddy logs + injected into the operator's TUI in github.com/alexandre-daubois/ember +cves: + - CVE-2026-54162 +ghsas: + - GHSA-x3g7-qrwc-f6c5 +references: + - advisory: https://github.com/alexandre-daubois/ember/security/advisories/GHSA-x3g7-qrwc-f6c5 + - fix: https://github.com/alexandre-daubois/ember/commit/fcb7160e58dba58d6f9b5033cc312fdedc8c9f6b + - web: https://github.com/alexandre-daubois/ember/releases/tag/v1.4.2 +source: + id: GHSA-x3g7-qrwc-f6c5 + created: 2026-08-24T21:16:04.593049-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6271.yaml b/data/reports/GO-2026-6271.yaml new file mode 100644 index 0000000..17c71ce --- /dev/null +++ b/data/reports/GO-2026-6271.yaml
@@ -0,0 +1,22 @@ +id: GO-2026-6271 +modules: + - module: github.com/axllent/mailpit + versions: + - introduced: 1.29.0 + - fixed: 1.30.6 + vulnerable_at: 1.30.5 +summary: |- + Mailpit: WebSocket origin check bypass via percent-encoded path (regression of + CVE-2026-22689) in github.com/axllent/mailpit +cves: + - CVE-2026-67448 +ghsas: + - GHSA-8r62-w5wh-fc5m +references: + - advisory: https://github.com/axllent/mailpit/security/advisories/GHSA-8r62-w5wh-fc5m + - fix: https://github.com/axllent/mailpit/commit/fbe5e006c3f1682b819df58b4a932d7a84920be9 + - web: https://github.com/axllent/mailpit/releases/tag/v1.30.6 +source: + id: GHSA-8r62-w5wh-fc5m + created: 2026-08-24T21:15:57.916821-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6272.yaml b/data/reports/GO-2026-6272.yaml new file mode 100644 index 0000000..99b629b --- /dev/null +++ b/data/reports/GO-2026-6272.yaml
@@ -0,0 +1,20 @@ +id: GO-2026-6272 +modules: + - module: github.com/axllent/mailpit + versions: + - introduced: 1.30.0 + - fixed: 1.30.5 + vulnerable_at: 1.30.4 +summary: 'Mailpit: SMTP DATA line reader buffers over-limit input before size enforcement in github.com/axllent/mailpit' +cves: + - CVE-2026-67447 +ghsas: + - GHSA-r553-m4fv-5v97 +references: + - advisory: https://github.com/axllent/mailpit/security/advisories/GHSA-r553-m4fv-5v97 + - fix: https://github.com/axllent/mailpit/commit/8720c6bd8281fc00d458081908f1dbef8e59a98c + - web: https://github.com/axllent/mailpit/releases/tag/v1.30.5 +source: + id: GHSA-r553-m4fv-5v97 + created: 2026-08-24T21:15:51.523482-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6277.yaml b/data/reports/GO-2026-6277.yaml new file mode 100644 index 0000000..0c68c5e --- /dev/null +++ b/data/reports/GO-2026-6277.yaml
@@ -0,0 +1,18 @@ +id: GO-2026-6277 +modules: + - module: github.com/tinfoil-factory/netfoil + versions: + - fixed: 0.5.0 + vulnerable_at: 0.4.0 +summary: netfoil vulnerable to improper handling of untrusted DoH response data in github.com/tinfoil-factory/netfoil +ghsas: + - GHSA-4ph6-mjv7-3fq6 +references: + - advisory: https://github.com/tinfoil-factory/netfoil/security/advisories/GHSA-4ph6-mjv7-3fq6 + - fix: https://github.com/tinfoil-factory/netfoil/commit/58cfb0cb16b824e02bf53c2d67707e5e4bd9f59b + - fix: https://github.com/tinfoil-factory/netfoil/commit/817f664c61aa64cbe0dbfcdfc05c16602b422e5b + - web: https://github.com/tinfoil-factory/netfoil/releases/tag/v0.5.0 +source: + id: GHSA-4ph6-mjv7-3fq6 + created: 2026-08-24T21:14:22.613785-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6279.yaml b/data/reports/GO-2026-6279.yaml new file mode 100644 index 0000000..7a1c6f4 --- /dev/null +++ b/data/reports/GO-2026-6279.yaml
@@ -0,0 +1,50 @@ +id: GO-2026-6279 +modules: + - module: github.com/mattermost/mattermost-server + versions: + - introduced: 10.11.0+incompatible + - fixed: 10.11.17+incompatible + - introduced: 11.5.0+incompatible + - fixed: 11.5.5+incompatible + - introduced: 11.6.0+incompatible + - fixed: 11.6.1+incompatible + vulnerable_at: 11.6.1-rc1+incompatible + - module: github.com/mattermost/mattermost-server/v5 + vulnerable_at: 5.39.3 + - module: github.com/mattermost/mattermost-server/v6 + vulnerable_at: 6.7.2 + - module: github.com/mattermost/mattermost/server/v8 + versions: + - introduced: 8.0.0-20250731163400-5b955468ea1e + - fixed: 8.0.0-20260428151657-c79c3831061a +summary: |- + Mattermost doesn't validate that a username returned during bot registration + belongs to a bot account in github.com/mattermost/mattermost-server +cves: + - CVE-2026-6046 +ghsas: + - GHSA-3vmp-whvv-5v9v +references: + - advisory: https://github.com/advisories/GHSA-3vmp-whvv-5v9v + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-6046 + - web: https://github.com/mattermost/mattermost/commit/3be10297c14d272f273d747af70728f9d03c60ec + - web: https://github.com/mattermost/mattermost/commit/98f9778cec1e7f3d97b3d4692fb91f8e7b659972 + - web: https://github.com/mattermost/mattermost/commit/aba9339a24d4b287edd77377c19901d6e341bb96 + - web: https://github.com/mattermost/mattermost/commit/c79c3831061a0880c0962c7d567c9e24dd35f44c + - web: https://github.com/mattermost/mattermost/commit/f706d1f01e6dfe62cab86c1d257f237daa78106a + - web: https://github.com/mattermost/mattermost/pull/36064 + - web: https://github.com/mattermost/mattermost/pull/36305 + - web: https://github.com/mattermost/mattermost/pull/36317 + - web: https://github.com/mattermost/mattermost/pull/36318 + - web: https://github.com/mattermost/mattermost/pull/36320 + - web: https://github.com/mattermost/mattermost/releases/tag/v10.11.16 + - web: https://github.com/mattermost/mattermost/releases/tag/v11.5.5 + - web: https://github.com/mattermost/mattermost/releases/tag/v11.6.2 + - web: https://github.com/mattermost/mattermost/releases/tag/v11.7.0 + - web: https://mattermost.com/security-updates +notes: + - fix: 'github.com/mattermost/mattermost/server/v8: could not add vulnerable_at: could not find tagged version between introduced and fixed' +source: + id: GHSA-3vmp-whvv-5v9v + created: 2026-08-24T21:14:05.042562-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6280.yaml b/data/reports/GO-2026-6280.yaml new file mode 100644 index 0000000..cb291c0 --- /dev/null +++ b/data/reports/GO-2026-6280.yaml
@@ -0,0 +1,50 @@ +id: GO-2026-6280 +modules: + - module: github.com/mattermost/mattermost-server + versions: + - introduced: 10.11.0+incompatible + - fixed: 10.11.17+incompatible + - introduced: 11.5.0+incompatible + - fixed: 11.5.5+incompatible + - introduced: 11.6.0+incompatible + - fixed: 11.6.1+incompatible + vulnerable_at: 11.6.1-rc1+incompatible + - module: github.com/mattermost/mattermost-server/v5 + vulnerable_at: 5.39.3 + - module: github.com/mattermost/mattermost-server/v6 + vulnerable_at: 6.7.2 + - module: github.com/mattermost/mattermost/server/v8 + versions: + - introduced: 8.0.0-20250731163400-5b955468ea1e + - fixed: 8.0.0-20260506065351-202d125afa87 +summary: |- + Mattermost doesn't require role-management authorization when setting the + scheme_admin flag on group syncable link and patch endpoints in github.com/mattermost/mattermost-server +cves: + - CVE-2026-7387 +ghsas: + - GHSA-6hxm-w4hv-vgvw +references: + - advisory: https://github.com/advisories/GHSA-6hxm-w4hv-vgvw + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-7387 + - web: https://github.com/mattermost/mattermost/commit/1ce2484a00c9821ee19708d2c46720e4855033a9 + - web: https://github.com/mattermost/mattermost/commit/202d125afa87fe39611686850fd82590c99ca344 + - web: https://github.com/mattermost/mattermost/commit/8c72083414e675c97987374395e36d1f36b4bd8a + - web: https://github.com/mattermost/mattermost/commit/a9e574a82633915f22071f0d7ca2b006f249ec2a + - web: https://github.com/mattermost/mattermost/commit/d5f29c8ebbeb04460d16d9e2635ce50deeb78428 + - web: https://github.com/mattermost/mattermost/pull/36316 + - web: https://github.com/mattermost/mattermost/pull/36423 + - web: https://github.com/mattermost/mattermost/pull/36431 + - web: https://github.com/mattermost/mattermost/pull/36432 + - web: https://github.com/mattermost/mattermost/pull/36434 + - web: https://github.com/mattermost/mattermost/releases/tag/v10.11.16 + - web: https://github.com/mattermost/mattermost/releases/tag/v11.5.5 + - web: https://github.com/mattermost/mattermost/releases/tag/v11.6.2 + - web: https://github.com/mattermost/mattermost/releases/tag/v11.7.0 + - web: https://mattermost.com/security-updates +notes: + - fix: 'github.com/mattermost/mattermost/server/v8: could not add vulnerable_at: could not find tagged version between introduced and fixed' +source: + id: GHSA-6hxm-w4hv-vgvw + created: 2026-08-24T21:13:52.372095-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6281.yaml b/data/reports/GO-2026-6281.yaml new file mode 100644 index 0000000..479d632 --- /dev/null +++ b/data/reports/GO-2026-6281.yaml
@@ -0,0 +1,50 @@ +id: GO-2026-6281 +modules: + - module: github.com/mattermost/mattermost-server + versions: + - introduced: 10.11.0+incompatible + - fixed: 10.11.17+incompatible + - introduced: 11.5.0+incompatible + - fixed: 11.5.5+incompatible + - introduced: 11.6.0+incompatible + - fixed: 11.6.1+incompatible + vulnerable_at: 11.6.1-rc1+incompatible + - module: github.com/mattermost/mattermost-server/v5 + vulnerable_at: 5.39.3 + - module: github.com/mattermost/mattermost-server/v6 + vulnerable_at: 6.7.2 + - module: github.com/mattermost/mattermost/server/v8 + versions: + - introduced: 8.0.0-20250731163400-5b955468ea1e + - fixed: 8.0.0-20260423180926-c021eeaff8f0 +summary: |- + Mattermost doesn't sanitize FileInfo.Name received from federated peers during + shared channel file sync in github.com/mattermost/mattermost-server +cves: + - CVE-2026-6961 +ghsas: + - GHSA-8qq9-cqj8-82w4 +references: + - advisory: https://github.com/advisories/GHSA-8qq9-cqj8-82w4 + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-6961 + - web: https://github.com/mattermost/mattermost/commit/61d68d2d6ee81a5919597d91c736c502d7156859 + - web: https://github.com/mattermost/mattermost/commit/a0056ed68d95f64d7c4586985e7b7f16b96b3bec + - web: https://github.com/mattermost/mattermost/commit/a9f3868e1eee9ec61855cd7277f39937385efffd + - web: https://github.com/mattermost/mattermost/commit/c021eeaff8f003034ab40f82c552cc26a710a8fd + - web: https://github.com/mattermost/mattermost/commit/c896a63dc44c2f9c081a0a15bfddc4e6eb50e753 + - web: https://github.com/mattermost/mattermost/pull/36223 + - web: https://github.com/mattermost/mattermost/pull/36251 + - web: https://github.com/mattermost/mattermost/pull/36252 + - web: https://github.com/mattermost/mattermost/pull/36253 + - web: https://github.com/mattermost/mattermost/pull/36255 + - web: https://github.com/mattermost/mattermost/releases/tag/v10.11.16 + - web: https://github.com/mattermost/mattermost/releases/tag/v11.5.5 + - web: https://github.com/mattermost/mattermost/releases/tag/v11.6.2 + - web: https://github.com/mattermost/mattermost/releases/tag/v11.7.0 + - web: https://mattermost.com/security-updates +notes: + - fix: 'github.com/mattermost/mattermost/server/v8: could not add vulnerable_at: could not find tagged version between introduced and fixed' +source: + id: GHSA-8qq9-cqj8-82w4 + created: 2026-08-24T21:13:39.56039-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6282.yaml b/data/reports/GO-2026-6282.yaml new file mode 100644 index 0000000..cf8182e --- /dev/null +++ b/data/reports/GO-2026-6282.yaml
@@ -0,0 +1,48 @@ +id: GO-2026-6282 +modules: + - module: github.com/mattermost/mattermost-server + versions: + - introduced: 10.11.0+incompatible + - fixed: 10.11.16+incompatible + - introduced: 11.5.0+incompatible + - fixed: 11.5.5+incompatible + - introduced: 11.6.0+incompatible + - fixed: 11.6.1+incompatible + vulnerable_at: 11.6.1-rc1+incompatible + - module: github.com/mattermost/mattermost-server/v5 + vulnerable_at: 5.39.3 + - module: github.com/mattermost/mattermost-server/v6 + vulnerable_at: 6.7.2 + - module: github.com/mattermost/mattermost/server/v8 + versions: + - introduced: 8.0.0-20250731163400-5b955468ea1e + - fixed: 8.0.0-20260428142921-bd8fc9222672 +summary: Mattermost doesn't sanitize the Remote Cluster API response on PATCH operations in github.com/mattermost/mattermost-server +cves: + - CVE-2026-7184 +ghsas: + - GHSA-9p44-r552-4wp9 +references: + - advisory: https://github.com/advisories/GHSA-9p44-r552-4wp9 + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-7184 + - web: https://github.com/mattermost/mattermost/commit/1a0643df00c1f51a3b7e919eec034eaf955f612f + - web: https://github.com/mattermost/mattermost/commit/6fd49f56b5920569218fd2fc76d8ae802942f274 + - web: https://github.com/mattermost/mattermost/commit/bd8fc92226726da06c8fabaef568cc9ebaee1cb8 + - web: https://github.com/mattermost/mattermost/commit/c5e67e28271c23cb585fe1a30ae81defcde848d6 + - web: https://github.com/mattermost/mattermost/commit/cad3e8e51a4d8627af6442f9df8ae3667fac7fc1 + - web: https://github.com/mattermost/mattermost/pull/36288 + - web: https://github.com/mattermost/mattermost/pull/36306 + - web: https://github.com/mattermost/mattermost/pull/36310 + - web: https://github.com/mattermost/mattermost/pull/36311 + - web: https://github.com/mattermost/mattermost/pull/36313 + - web: https://github.com/mattermost/mattermost/releases/tag/v10.11.16 + - web: https://github.com/mattermost/mattermost/releases/tag/v11.5.5 + - web: https://github.com/mattermost/mattermost/releases/tag/v11.6.2 + - web: https://github.com/mattermost/mattermost/releases/tag/v11.7.0 + - web: https://mattermost.com/security-updates +notes: + - fix: 'github.com/mattermost/mattermost/server/v8: could not add vulnerable_at: could not find tagged version between introduced and fixed' +source: + id: GHSA-9p44-r552-4wp9 + created: 2026-08-24T21:13:27.738755-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6283.yaml b/data/reports/GO-2026-6283.yaml new file mode 100644 index 0000000..e858517 --- /dev/null +++ b/data/reports/GO-2026-6283.yaml
@@ -0,0 +1,50 @@ +id: GO-2026-6283 +modules: + - module: github.com/mattermost/mattermost-server + versions: + - introduced: 10.11.0+incompatible + - fixed: 10.11.17+incompatible + - introduced: 11.5.0+incompatible + - fixed: 11.5.5+incompatible + - introduced: 11.6.0+incompatible + - fixed: 11.6.1+incompatible + vulnerable_at: 11.6.1-rc1+incompatible + - module: github.com/mattermost/mattermost-server/v5 + vulnerable_at: 5.39.3 + - module: github.com/mattermost/mattermost-server/v6 + vulnerable_at: 6.7.2 + - module: github.com/mattermost/mattermost/server/v8 + versions: + - introduced: 8.0.0-20250731163400-5b955468ea1e + - fixed: 8.0.0-20260501144115-7d6816abdfd1 +summary: |- + Mattermost doesn't enforce PermissionInviteUser when setting AllowOpenInvite or + AllowedDomains during team creation in github.com/mattermost/mattermost-server +cves: + - CVE-2026-6689 +ghsas: + - GHSA-c28q-m4gf-vg4q +references: + - advisory: https://github.com/advisories/GHSA-c28q-m4gf-vg4q + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-6689 + - web: https://github.com/mattermost/mattermost/commit/2dea05864024b3254fb28c5ed679592e2b7cd672 + - web: https://github.com/mattermost/mattermost/commit/3a96344214b1a84df70d97052d46b6f2b40b0caa + - web: https://github.com/mattermost/mattermost/commit/479fc42d0ec6da48e76b59608233d90bfc69769d + - web: https://github.com/mattermost/mattermost/commit/7d6816abdfd170169f717aea43c5716a1f9ef6b0 + - web: https://github.com/mattermost/mattermost/commit/977c791e5b54bc14fdb96a2b3dacc85da5d8c623 + - web: https://github.com/mattermost/mattermost/pull/36188 + - web: https://github.com/mattermost/mattermost/pull/36375 + - web: https://github.com/mattermost/mattermost/pull/36383 + - web: https://github.com/mattermost/mattermost/pull/36384 + - web: https://github.com/mattermost/mattermost/pull/36402 + - web: https://github.com/mattermost/mattermost/releases/tag/v10.11.16 + - web: https://github.com/mattermost/mattermost/releases/tag/v11.5.5 + - web: https://github.com/mattermost/mattermost/releases/tag/v11.6.2 + - web: https://github.com/mattermost/mattermost/releases/tag/v11.7.0 + - web: https://mattermost.com/security-updates +notes: + - fix: 'github.com/mattermost/mattermost/server/v8: could not add vulnerable_at: could not find tagged version between introduced and fixed' +source: + id: GHSA-c28q-m4gf-vg4q + created: 2026-08-24T21:13:14.65208-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6284.yaml b/data/reports/GO-2026-6284.yaml new file mode 100644 index 0000000..c7fb4b6 --- /dev/null +++ b/data/reports/GO-2026-6284.yaml
@@ -0,0 +1,28 @@ +id: GO-2026-6284 +modules: + - module: github.com/mhsanaei/3x-ui + vulnerable_at: 1.7.9 + - module: github.com/mhsanaei/3x-ui/v2 + unsupported_versions: + - last_affected: 2.9.4 + vulnerable_at: 2.9.4 + - module: github.com/mhsanaei/3x-ui/v3 + versions: + - fixed: 3.3.1 + vulnerable_at: 3.3.0 +summary: |- + 3X-UI Vulnerable to Authenticated Arbitrary File Write via Database Import and + Xray Log Path Manipulation in github.com/mhsanaei/3x-ui +cves: + - CVE-2026-55477 +ghsas: + - GHSA-jm48-m3rr-9hgg +references: + - advisory: https://github.com/MHSanaei/3x-ui/security/advisories/GHSA-jm48-m3rr-9hgg + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-55477 + - web: https://github.com/MHSanaei/3x-ui/commit/80e168787ed608e83a065033ee94c8bfc3025ce7 + - web: https://github.com/MHSanaei/3x-ui/releases/tag/v3.3.1 +source: + id: GHSA-jm48-m3rr-9hgg + created: 2026-08-24T21:13:06.930922-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6285.yaml b/data/reports/GO-2026-6285.yaml new file mode 100644 index 0000000..a204f29 --- /dev/null +++ b/data/reports/GO-2026-6285.yaml
@@ -0,0 +1,49 @@ +id: GO-2026-6285 +modules: + - module: github.com/mattermost/mattermost-server + versions: + - introduced: 10.11.0+incompatible + - fixed: 10.11.17+incompatible + - introduced: 11.5.0+incompatible + - fixed: 11.5.5+incompatible + - introduced: 11.6.0+incompatible + - fixed: 11.6.1+incompatible + vulnerable_at: 11.6.1-rc1+incompatible + - module: github.com/mattermost/mattermost-server/v5 + vulnerable_at: 5.39.3 + - module: github.com/mattermost/mattermost-server/v6 + vulnerable_at: 6.7.2 + - module: github.com/mattermost/mattermost/server/v8 + versions: + - introduced: 8.0.0-20250731163400-5b955468ea1e + - fixed: 8.0.0-20260501142004-99b73d4c4acf +summary: |- + Mattermost doesn't require system-level permission when patching protected + default system roles in github.com/mattermost/mattermost-server +cves: + - CVE-2026-6739 +ghsas: + - GHSA-m2w9-h2mm-79qr +references: + - advisory: https://github.com/advisories/GHSA-m2w9-h2mm-79qr + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-6739 + - web: https://github.com/mattermost/mattermost/commit/2c89c2f6768fbe4dfd57a21ca38c0aecead8d4a8 + - web: https://github.com/mattermost/mattermost/commit/5e159647b16e571b327ac6882f32eae42971f540 + - web: https://github.com/mattermost/mattermost/commit/8000e5933526f4fd66b92131db3a1b1f4520dbae + - web: https://github.com/mattermost/mattermost/commit/f0a390b96e4c730daedbaf5190684776730218c7 + - web: https://github.com/mattermost/mattermost/pull/36197 + - web: https://github.com/mattermost/mattermost/pull/36377 + - web: https://github.com/mattermost/mattermost/pull/36379 + - web: https://github.com/mattermost/mattermost/pull/36380 + - web: https://github.com/mattermost/mattermost/pull/36382 + - web: https://github.com/mattermost/mattermost/releases/tag/v10.11.16 + - web: https://github.com/mattermost/mattermost/releases/tag/v11.5.5 + - web: https://github.com/mattermost/mattermost/releases/tag/v11.6.2 + - web: https://github.com/mattermost/mattermost/releases/tag/v11.7.0 + - web: https://mattermost.com/security-updates +notes: + - fix: 'github.com/mattermost/mattermost/server/v8: could not add vulnerable_at: could not find tagged version between introduced and fixed' +source: + id: GHSA-m2w9-h2mm-79qr + created: 2026-08-24T21:12:54.88112-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6286.yaml b/data/reports/GO-2026-6286.yaml new file mode 100644 index 0000000..e1ab93f --- /dev/null +++ b/data/reports/GO-2026-6286.yaml
@@ -0,0 +1,48 @@ +id: GO-2026-6286 +modules: + - module: github.com/mattermost/mattermost-server + versions: + - introduced: 10.11.0+incompatible + - fixed: 10.11.17+incompatible + - introduced: 11.5.0+incompatible + - fixed: 11.5.5+incompatible + - introduced: 11.6.0+incompatible + - fixed: 11.6.1+incompatible + vulnerable_at: 11.6.1-rc1+incompatible + - module: github.com/mattermost/mattermost-server/v5 + vulnerable_at: 5.39.3 + - module: github.com/mattermost/mattermost-server/v6 + vulnerable_at: 6.7.2 + - module: github.com/mattermost/mattermost/server/v8 + versions: + - introduced: 8.0.0-20250731163400-5b955468ea1e + - fixed: 8.0.0-20260504071740-9408b98025d7 +summary: |- + Mattermost doesn't restrict role_updated websocket event broadcasts to members + of the affected team or channel in github.com/mattermost/mattermost-server +cves: + - CVE-2026-3433 +ghsas: + - GHSA-rp4v-qc77-phm4 +references: + - advisory: https://github.com/advisories/GHSA-rp4v-qc77-phm4 + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-3433 + - web: https://github.com/mattermost/mattermost/commit/0a0ab0d54d899d308bd1352cc577036917500318 + - web: https://github.com/mattermost/mattermost/commit/7425c6817bf244f976c729f8a73cecac8039a1e1 + - web: https://github.com/mattermost/mattermost/commit/9408b98025d7364d7dfe7cdb28fcd109b1b595a6 + - web: https://github.com/mattermost/mattermost/commit/a30a331a29b9766d46716d4252056d7b74e66da0 + - web: https://github.com/mattermost/mattermost/pull/35497 + - web: https://github.com/mattermost/mattermost/pull/36256 + - web: https://github.com/mattermost/mattermost/pull/36257 + - web: https://github.com/mattermost/mattermost/pull/36341 + - web: https://github.com/mattermost/mattermost/releases/tag/v10.11.16 + - web: https://github.com/mattermost/mattermost/releases/tag/v11.5.5 + - web: https://github.com/mattermost/mattermost/releases/tag/v11.6.2 + - web: https://github.com/mattermost/mattermost/releases/tag/v11.7.0 + - web: https://mattermost.com/security-updates +notes: + - fix: 'github.com/mattermost/mattermost/server/v8: could not add vulnerable_at: could not find tagged version between introduced and fixed' +source: + id: GHSA-rp4v-qc77-phm4 + created: 2026-08-24T21:11:39.367569-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6287.yaml b/data/reports/GO-2026-6287.yaml new file mode 100644 index 0000000..a5e5c43 --- /dev/null +++ b/data/reports/GO-2026-6287.yaml
@@ -0,0 +1,21 @@ +id: GO-2026-6287 +modules: + - module: github.com/cloudreve/Cloudreve + vulnerable_at: 0.0.0-20201026073328-746aa3e8ef26 + - module: github.com/cloudreve/Cloudreve/v3 + vulnerable_at: 3.0.0-20250225100611-da4e44b77af4 + - module: github.com/cloudreve/Cloudreve/v4 + unsupported_versions: + - last_affected: 4.0.0-20260606032813-26b6b1044b02 + vulnerable_at: 4.0.0-20260802015950-20c95ad73f3a +summary: |- + Cloudreve has Broken Access Control - Revoked Share Access Still Allows Signed + File URL Generation via Cached context_hint in github.com/cloudreve/Cloudreve +ghsas: + - GHSA-vx2m-jpxr-xv7w +references: + - advisory: https://github.com/cloudreve/cloudreve/security/advisories/GHSA-vx2m-jpxr-xv7w +source: + id: GHSA-vx2m-jpxr-xv7w + created: 2026-08-24T21:11:36.871164-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6288.yaml b/data/reports/GO-2026-6288.yaml new file mode 100644 index 0000000..ec49bd5 --- /dev/null +++ b/data/reports/GO-2026-6288.yaml
@@ -0,0 +1,21 @@ +id: GO-2026-6288 +modules: + - module: github.com/googleapis/genai-toolbox + versions: + - fixed: 0.25.0 + vulnerable_at: 0.24.0 +summary: MCP Toolbox for Databases has an Origin Validation Error in github.com/googleapis/genai-toolbox +cves: + - CVE-2026-11624 +ghsas: + - GHSA-76g7-m3xw-x9gr +references: + - advisory: https://github.com/advisories/GHSA-76g7-m3xw-x9gr + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-11624 + - web: https://github.com/googleapis/mcp-toolbox/commit/17b41f64531b8fe417c28ada45d1992ba430dc1b + - web: https://github.com/googleapis/mcp-toolbox/issues/3113 + - web: https://github.com/googleapis/mcp-toolbox/pull/2254 +source: + id: GHSA-76g7-m3xw-x9gr + created: 2026-08-24T21:11:27.656174-04:00 +review_status: UNREVIEWED
diff --git a/data/reports/GO-2026-6289.yaml b/data/reports/GO-2026-6289.yaml new file mode 100644 index 0000000..7ced993 --- /dev/null +++ b/data/reports/GO-2026-6289.yaml
@@ -0,0 +1,21 @@ +id: GO-2026-6289 +modules: + - module: github.com/cloudreve/Cloudreve + vulnerable_at: 0.0.0-20201026073328-746aa3e8ef26 + - module: github.com/cloudreve/Cloudreve/v3 + vulnerable_at: 3.0.0-20250225100611-da4e44b77af4 + - module: github.com/cloudreve/Cloudreve/v4 + unsupported_versions: + - last_affected: 4.0.0-20260606032813-26b6b1044b02 + vulnerable_at: 4.0.0-20260802015950-20c95ad73f3a +summary: |- + Cloudreve's remote download file paths can escape the selected destination + directory in github.com/cloudreve/Cloudreve +ghsas: + - GHSA-w8j7-39hp-8x59 +references: + - advisory: https://github.com/cloudreve/cloudreve/security/advisories/GHSA-w8j7-39hp-8x59 +source: + id: GHSA-w8j7-39hp-8x59 + created: 2026-08-24T21:11:22.388565-04:00 +review_status: UNREVIEWED