data/reports: add 5 reports - data/reports/GO-2026-5116.yaml - data/reports/GO-2026-5748.yaml - data/reports/GO-2026-5960.yaml - data/reports/GO-2026-5983.yaml - data/reports/GO-2026-6061.yaml Fixes golang/vulndb#5116 Fixes golang/vulndb#5748 Fixes golang/vulndb#5960 Fixes golang/vulndb#5983 Fixes golang/vulndb#6061 Change-Id: Id6c327a28d440aac6929a8a68847995f39421020 Reviewed-on: https://go-review.googlesource.com/c/vulndb/+/805140 Reviewed-by: Nicholas Husin <husin@google.com> Reviewed-by: Nicholas Husin <nsh@golang.org> LUCI-TryBot-Result: golang-scoped@luci-project-accounts.iam.gserviceaccount.com <golang-scoped@luci-project-accounts.iam.gserviceaccount.com>
diff --git a/data/osv/GO-2026-5116.json b/data/osv/GO-2026-5116.json new file mode 100644 index 0000000..215cfbe --- /dev/null +++ b/data/osv/GO-2026-5116.json
@@ -0,0 +1,41 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-5116", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-44517", + "GHSA-49p4-px3h-rq49" + ], + "summary": "Build breakout using malicious Containerfile or Git HTTP server in github.com/containers/buildah", + "details": "Buildah allows a build-time breakout when using a malicious Containerfile or a malicious Git HTTP server. A crafted Git URL or Containerfile can cause Buildah to access files outside of the build context during an ADD or COPY operation.", + "affected": [ + { + "package": { + "name": "github.com/containers/buildah", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "1.38.1" + } + ] + } + ], + "ecosystem_specific": {} + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/containers/buildah/security/advisories/GHSA-49p4-px3h-rq49" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-5116", + "review_status": "REVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-5748.json b/data/osv/GO-2026-5748.json new file mode 100644 index 0000000..dc54497 --- /dev/null +++ b/data/osv/GO-2026-5748.json
@@ -0,0 +1,73 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-5748", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-7482", + "GHSA-x8qc-fggm-mpqg" + ], + "summary": "Ollama contains a heap out-of-bounds read vulnerability in the GGUF model loader in github.com/ollama/ollama", + "details": "Ollama is vulnerable to a heap out-of-bounds read in its GGUF model loader. A specially crafted GGUF file can cause the loader to read beyond the allocated heap buffer, potentially leading to a denial of service (crash).", + "affected": [ + { + "package": { + "name": "github.com/ollama/ollama", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.17.1" + } + ] + } + ], + "ecosystem_specific": { + "imports": [ + { + "path": "github.com/ollama/ollama/server", + "symbols": [ + "WriteTo", + "quantizer.WriteTo" + ] + }, + { + "path": "github.com/ollama/ollama/fs/ggml", + "symbols": [ + "Decode", + "gguf.Decode" + ] + } + ] + } + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-x8qc-fggm-mpqg" + }, + { + "type": "FIX", + "url": "https://github.com/ollama/ollama/commit/88d57d0483cca907e0b23a968c83627a20b21047" + }, + { + "type": "FIX", + "url": "https://github.com/ollama/ollama/pull/14406" + }, + { + "type": "WEB", + "url": "https://github.com/ollama/ollama/releases/tag/v0.17.1" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-5748", + "review_status": "REVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-5960.json b/data/osv/GO-2026-5960.json new file mode 100644 index 0000000..cd0918e --- /dev/null +++ b/data/osv/GO-2026-5960.json
@@ -0,0 +1,175 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-5960", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-54063", + "GHSA-h69g-9hx6-f3v4" + ], + "summary": "Excelize: Unbounded Row Index Allocation in Worksheet Parser (checkSheet OOM/Panic DoS) in github.com/xuri/excelize", + "details": "Excelize: Unbounded Row Index Allocation in Worksheet Parser (checkSheet OOM/Panic DoS) in github.com/xuri/excelize", + "affected": [ + { + "package": { + "name": "github.com/xuri/excelize/v2", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "2.11.0" + } + ] + } + ], + "ecosystem_specific": { + "imports": [ + { + "path": "github.com/xuri/excelize/v2", + "symbols": [ + "File.AddChart", + "File.AddComment", + "File.AddDataValidation", + "File.AddFormControl", + "File.AddHeaderFooterImage", + "File.AddIgnoredErrors", + "File.AddPicture", + "File.AddPictureFromBytes", + "File.AddPivotTable", + "File.AddShape", + "File.AddSlicer", + "File.AddSparkline", + "File.AddTable", + "File.AutoFilter", + "File.CalcCellValue", + "File.CopySheet", + "File.DeleteChart", + "File.DeleteComment", + "File.DeleteDataValidation", + "File.DeleteFormControl", + "File.DeletePicture", + "File.DeletePivotTable", + "File.DeleteSheet", + "File.DeleteSlicer", + "File.DeleteTable", + "File.DuplicateRow", + "File.DuplicateRowTo", + "File.GetCellFormula", + "File.GetCellHyperLink", + "File.GetCellRichText", + "File.GetCellStyle", + "File.GetCellType", + "File.GetCellValue", + "File.GetColOutlineLevel", + "File.GetColStyle", + "File.GetColVisible", + "File.GetColWidth", + "File.GetConditionalFormats", + "File.GetDataValidations", + "File.GetFormControls", + "File.GetHeaderFooter", + "File.GetHyperLinkCells", + "File.GetMergeCells", + "File.GetPageLayout", + "File.GetPageMargins", + "File.GetPanes", + "File.GetPictureCells", + "File.GetPictures", + "File.GetPivotTables", + "File.GetRowHeight", + "File.GetRowOutlineLevel", + "File.GetRowVisible", + "File.GetSheetProps", + "File.GetSheetProtection", + "File.GetSheetView", + "File.GetSlicers", + "File.GetTables", + "File.GroupSheets", + "File.InsertCols", + "File.InsertPageBreak", + "File.InsertRows", + "File.MergeCell", + "File.MoveSheet", + "File.NewSheet", + "File.NewStreamWriter", + "File.ProtectSheet", + "File.RemoveCol", + "File.RemovePageBreak", + "File.RemoveRow", + "File.SetActiveSheet", + "File.SetCellBool", + "File.SetCellDefault", + "File.SetCellFloat", + "File.SetCellFormula", + "File.SetCellHyperLink", + "File.SetCellInt", + "File.SetCellRichText", + "File.SetCellStr", + "File.SetCellStyle", + "File.SetCellUint", + "File.SetCellValue", + "File.SetColOutlineLevel", + "File.SetColStyle", + "File.SetColVisible", + "File.SetColWidth", + "File.SetConditionalFormat", + "File.SetHeaderFooter", + "File.SetPageLayout", + "File.SetPageMargins", + "File.SetPanes", + "File.SetRowHeight", + "File.SetRowOutlineLevel", + "File.SetRowStyle", + "File.SetRowVisible", + "File.SetSheetBackground", + "File.SetSheetBackgroundFromBytes", + "File.SetSheetCol", + "File.SetSheetDimension", + "File.SetSheetProps", + "File.SetSheetRow", + "File.SetSheetView", + "File.SetSheetVisible", + "File.UngroupSheets", + "File.UnmergeCell", + "File.UnprotectSheet", + "File.UnsetConditionalFormat", + "File.UpdateLinkedValue", + "File.adjustHelper", + "File.workSheetReader", + "NewFile", + "formulaFuncs.ANCHORARRAY", + "formulaFuncs.FORMULATEXT", + "formulaFuncs.INDIRECT", + "formulaFuncs.ISFORMULA", + "xlsxWorksheet.checkSheet" + ] + } + ] + } + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/qax-os/excelize/security/advisories/GHSA-h69g-9hx6-f3v4" + }, + { + "type": "FIX", + "url": "https://github.com/qax-os/excelize/commit/875b959ba62fc9bf45bb0de547ae7c7f7549835c" + }, + { + "type": "WEB", + "url": "https://github.com/qax-os/excelize/releases/tag/v2.11.0" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-5960", + "review_status": "REVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-5983.json b/data/osv/GO-2026-5983.json new file mode 100644 index 0000000..7167e1d --- /dev/null +++ b/data/osv/GO-2026-5983.json
@@ -0,0 +1,80 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-5983", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-54448", + "GHSA-q3fv-x8vg-qqm4" + ], + "summary": "Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser in github.com/aquasecurity/trivy", + "details": "Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser in github.com/aquasecurity/trivy", + "affected": [ + { + "package": { + "name": "github.com/aquasecurity/trivy", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.71.0" + } + ] + } + ], + "ecosystem_specific": { + "imports": [ + { + "path": "github.com/aquasecurity/trivy/pkg/iac/detection", + "symbols": [ + "IsArchive" + ] + }, + { + "path": "github.com/aquasecurity/trivy/pkg/iac/scanners/helm", + "symbols": [ + "Scanner.ScanFS" + ] + }, + { + "path": "github.com/aquasecurity/trivy/pkg/iac/scanners/helm/parser", + "symbols": [ + "New", + "Parser.ParseFS", + "Parser.RenderedChartFiles", + "Parser.unpackArchive" + ] + } + ] + } + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/aquasecurity/trivy/security/advisories/GHSA-q3fv-x8vg-qqm4" + }, + { + "type": "FIX", + "url": "https://github.com/aquasecurity/trivy/commit/441251e51ae46cbcf7f436547e0a5766b25328b4" + }, + { + "type": "FIX", + "url": "https://github.com/aquasecurity/trivy/pull/10718" + }, + { + "type": "WEB", + "url": "https://github.com/aquasecurity/trivy/releases/tag/v0.71.0" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-5983", + "review_status": "REVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6061.json b/data/osv/GO-2026-6061.json new file mode 100644 index 0000000..335200f --- /dev/null +++ b/data/osv/GO-2026-6061.json
@@ -0,0 +1,96 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6061", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "GHSA-hrxh-6v49-42gf" + ], + "summary": "Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc", + "details": "Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc", + "affected": [ + { + "package": { + "name": "google.golang.org/grpc", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.82.1" + } + ] + } + ], + "ecosystem_specific": { + "imports": [ + { + "path": "google.golang.org/grpc/internal/transport", + "symbols": [ + "ClientStream.Close", + "ClientStream.Header", + "ClientStream.Read", + "ClientStream.RecvCompress", + "ClientStream.TrailersOnly", + "ClientStream.Write", + "NewHTTP2Client", + "NewServerTransport", + "ServerStream.Read", + "ServerStream.SendHeader", + "ServerStream.Write", + "ServerStream.WriteStatus", + "Stream.ReadMessageHeader", + "controlBuffer.executeAndPut", + "controlBuffer.getOnceLocked", + "http2Client.Close", + "http2Client.GracefulClose", + "http2Client.NewStream", + "http2Server.Drain", + "http2Server.HandleStreams", + "recvBufferReader.Read", + "recvBufferReader.ReadMessageHeader", + "transportReader.Read", + "transportReader.ReadMessageHeader" + ] + }, + { + "path": "google.golang.org/grpc/internal/xds/rbac", + "symbols": [ + "ChainEngine.IsAuthorized", + "NewChainEngine", + "matchersFromPermissions", + "matchersFromPrincipals" + ] + } + ] + } + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/grpc/grpc-go/security/advisories/GHSA-hrxh-6v49-42gf" + }, + { + "type": "FIX", + "url": "https://github.com/grpc/grpc-go/commit/4ea465d4ab98013f72a142fe0fc89c19770b2935" + }, + { + "type": "WEB", + "url": "https://github.com/grpc/grpc-go/pull/9236" + }, + { + "type": "WEB", + "url": "https://github.com/grpc/grpc-go/releases/tag/v1.82.1" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6061", + "review_status": "REVIEWED" + } +} \ No newline at end of file
diff --git a/data/reports/GO-2026-5116.yaml b/data/reports/GO-2026-5116.yaml new file mode 100644 index 0000000..6937782 --- /dev/null +++ b/data/reports/GO-2026-5116.yaml
@@ -0,0 +1,24 @@ +id: GO-2026-5116 +modules: + - module: github.com/containers/buildah + versions: + - introduced: 1.38.1 + vulnerable_at: 1.43.1 +summary: |- + Build breakout using malicious Containerfile or Git HTTP server in + github.com/containers/buildah +description: |- + Buildah allows a build-time breakout when using a malicious Containerfile + or a malicious Git HTTP server. A crafted Git URL or Containerfile can + cause Buildah to access files outside of the build context during an + ADD or COPY operation. +cves: + - CVE-2026-44517 +ghsas: + - GHSA-49p4-px3h-rq49 +references: + - advisory: https://github.com/containers/buildah/security/advisories/GHSA-49p4-px3h-rq49 +source: + id: GHSA-49p4-px3h-rq49 + created: 2026-07-23T19:30:52.165275-04:00 +review_status: REVIEWED
diff --git a/data/reports/GO-2026-5748.yaml b/data/reports/GO-2026-5748.yaml new file mode 100644 index 0000000..a621279 --- /dev/null +++ b/data/reports/GO-2026-5748.yaml
@@ -0,0 +1,37 @@ +id: GO-2026-5748 +modules: + - module: github.com/ollama/ollama + versions: + - fixed: 0.17.1 + vulnerable_at: 0.17.1-rc2 + packages: + - package: github.com/ollama/ollama/server + symbols: + - WriteTo + - quantizer.WriteTo + skip_fix: build errors during static analysis + - package: github.com/ollama/ollama/fs/ggml + symbols: + - Decode + - gguf.Decode + skip_fix: build errors during static analysis +summary: |- + Ollama contains a heap out-of-bounds read vulnerability in the GGUF model loader + in github.com/ollama/ollama +description: |- + Ollama is vulnerable to a heap out-of-bounds read in its GGUF model loader. + A specially crafted GGUF file can cause the loader to read beyond the + allocated heap buffer, potentially leading to a denial of service (crash). +cves: + - CVE-2026-7482 +ghsas: + - GHSA-x8qc-fggm-mpqg +references: + - advisory: https://github.com/advisories/GHSA-x8qc-fggm-mpqg + - fix: https://github.com/ollama/ollama/commit/88d57d0483cca907e0b23a968c83627a20b21047 + - fix: https://github.com/ollama/ollama/pull/14406 + - web: https://github.com/ollama/ollama/releases/tag/v0.17.1 +source: + id: GHSA-x8qc-fggm-mpqg + created: 2026-07-23T19:00:31.725511-04:00 +review_status: REVIEWED
diff --git a/data/reports/GO-2026-5960.yaml b/data/reports/GO-2026-5960.yaml new file mode 100644 index 0000000..6087903 --- /dev/null +++ b/data/reports/GO-2026-5960.yaml
@@ -0,0 +1,140 @@ +id: GO-2026-5960 +modules: + - module: github.com/xuri/excelize/v2 + versions: + - fixed: 2.11.0 + vulnerable_at: 2.10.1 + packages: + - package: github.com/xuri/excelize/v2 + symbols: + - File.adjustHelper + - File.workSheetReader + - xlsxWorksheet.checkSheet + derived_symbols: + - File.AddChart + - File.AddComment + - File.AddDataValidation + - File.AddFormControl + - File.AddHeaderFooterImage + - File.AddIgnoredErrors + - File.AddPicture + - File.AddPictureFromBytes + - File.AddPivotTable + - File.AddShape + - File.AddSlicer + - File.AddSparkline + - File.AddTable + - File.AutoFilter + - File.CalcCellValue + - File.CopySheet + - File.DeleteChart + - File.DeleteComment + - File.DeleteDataValidation + - File.DeleteFormControl + - File.DeletePicture + - File.DeletePivotTable + - File.DeleteSheet + - File.DeleteSlicer + - File.DeleteTable + - File.DuplicateRow + - File.DuplicateRowTo + - File.GetCellFormula + - File.GetCellHyperLink + - File.GetCellRichText + - File.GetCellStyle + - File.GetCellType + - File.GetCellValue + - File.GetColOutlineLevel + - File.GetColStyle + - File.GetColVisible + - File.GetColWidth + - File.GetConditionalFormats + - File.GetDataValidations + - File.GetFormControls + - File.GetHeaderFooter + - File.GetHyperLinkCells + - File.GetMergeCells + - File.GetPageLayout + - File.GetPageMargins + - File.GetPanes + - File.GetPictureCells + - File.GetPictures + - File.GetPivotTables + - File.GetRowHeight + - File.GetRowOutlineLevel + - File.GetRowVisible + - File.GetSheetProps + - File.GetSheetProtection + - File.GetSheetView + - File.GetSlicers + - File.GetTables + - File.GroupSheets + - File.InsertCols + - File.InsertPageBreak + - File.InsertRows + - File.MergeCell + - File.MoveSheet + - File.NewSheet + - File.NewStreamWriter + - File.ProtectSheet + - File.RemoveCol + - File.RemovePageBreak + - File.RemoveRow + - File.SetActiveSheet + - File.SetCellBool + - File.SetCellDefault + - File.SetCellFloat + - File.SetCellFormula + - File.SetCellHyperLink + - File.SetCellInt + - File.SetCellRichText + - File.SetCellStr + - File.SetCellStyle + - File.SetCellUint + - File.SetCellValue + - File.SetColOutlineLevel + - File.SetColStyle + - File.SetColVisible + - File.SetColWidth + - File.SetConditionalFormat + - File.SetHeaderFooter + - File.SetPageLayout + - File.SetPageMargins + - File.SetPanes + - File.SetRowHeight + - File.SetRowOutlineLevel + - File.SetRowStyle + - File.SetRowVisible + - File.SetSheetBackground + - File.SetSheetBackgroundFromBytes + - File.SetSheetCol + - File.SetSheetDimension + - File.SetSheetProps + - File.SetSheetRow + - File.SetSheetView + - File.SetSheetVisible + - File.UngroupSheets + - File.UnmergeCell + - File.UnprotectSheet + - File.UnsetConditionalFormat + - File.UpdateLinkedValue + - NewFile + - formulaFuncs.ANCHORARRAY + - formulaFuncs.FORMULATEXT + - formulaFuncs.INDIRECT + - formulaFuncs.ISFORMULA +summary: |- + Excelize: Unbounded Row Index Allocation in Worksheet Parser (checkSheet + OOM/Panic DoS) in github.com/xuri/excelize +cves: + - CVE-2026-54063 +ghsas: + - GHSA-h69g-9hx6-f3v4 +references: + - advisory: https://github.com/qax-os/excelize/security/advisories/GHSA-h69g-9hx6-f3v4 + - fix: https://github.com/qax-os/excelize/commit/875b959ba62fc9bf45bb0de547ae7c7f7549835c + - web: https://github.com/qax-os/excelize/releases/tag/v2.11.0 +source: + id: GHSA-h69g-9hx6-f3v4 + created: 2026-07-23T18:59:10.303167-04:00 +review_status: REVIEWED
diff --git a/data/reports/GO-2026-5983.yaml b/data/reports/GO-2026-5983.yaml new file mode 100644 index 0000000..3cc5b34 --- /dev/null +++ b/data/reports/GO-2026-5983.yaml
@@ -0,0 +1,40 @@ +id: GO-2026-5983 +modules: + - module: github.com/aquasecurity/trivy + versions: + - fixed: 0.71.0 + vulnerable_at: 0.70.0 + packages: + - package: github.com/aquasecurity/trivy/pkg/iac/detection + symbols: + - IsArchive + skip_fix: build errors during static analysis + - package: github.com/aquasecurity/trivy/pkg/iac/scanners/helm + symbols: + - Scanner.ScanFS + skip_fix: build errors during static analysis + - package: github.com/aquasecurity/trivy/pkg/iac/scanners/helm/parser + symbols: + - Parser.RenderedChartFiles + - Parser.ParseFS + - New + - Parser.unpackArchive + skip_fix: build errors during static analysis +summary: |- + Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser in + github.com/aquasecurity/trivy +cves: + - CVE-2026-54448 +ghsas: + - GHSA-q3fv-x8vg-qqm4 +references: + - advisory: https://github.com/aquasecurity/trivy/security/advisories/GHSA-q3fv-x8vg-qqm4 + - fix: https://github.com/aquasecurity/trivy/commit/441251e51ae46cbcf7f436547e0a5766b25328b4 + - fix: https://github.com/aquasecurity/trivy/pull/10718 + - web: https://github.com/aquasecurity/trivy/releases/tag/v0.71.0 +notes: + - failed to auto-populate derived symbols: build errors during static analysis +source: + id: GHSA-q3fv-x8vg-qqm4 + created: 2026-07-23T18:58:13.333642-04:00 +review_status: REVIEWED
diff --git a/data/reports/GO-2026-6061.yaml b/data/reports/GO-2026-6061.yaml new file mode 100644 index 0000000..1841248 --- /dev/null +++ b/data/reports/GO-2026-6061.yaml
@@ -0,0 +1,57 @@ +id: GO-2026-6061 +modules: + - module: google.golang.org/grpc + versions: + - fixed: 1.82.1 + vulnerable_at: 1.82.0 + packages: + - package: google.golang.org/grpc/internal/transport + symbols: + - controlBuffer.executeAndPut + - controlBuffer.getOnceLocked + derived_symbols: + - ClientStream.Close + - ClientStream.Header + - ClientStream.Read + - ClientStream.RecvCompress + - ClientStream.TrailersOnly + - ClientStream.Write + - NewHTTP2Client + - NewServerTransport + - ServerStream.Read + - ServerStream.SendHeader + - ServerStream.Write + - ServerStream.WriteStatus + - Stream.ReadMessageHeader + - http2Client.Close + - http2Client.GracefulClose + - http2Client.NewStream + - http2Server.Drain + - http2Server.HandleStreams + - recvBufferReader.Read + - recvBufferReader.ReadMessageHeader + - transportReader.Read + - transportReader.ReadMessageHeader + - package: google.golang.org/grpc/internal/xds/rbac + symbols: + - matchersFromPrincipals + - matchersFromPermissions + derived_symbols: + - ChainEngine.IsAuthorized + - NewChainEngine +summary: |- + Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 + transport server implementation in google.golang.org/grpc +ghsas: + - GHSA-hrxh-6v49-42gf +references: + - advisory: https://github.com/grpc/grpc-go/security/advisories/GHSA-hrxh-6v49-42gf + - fix: https://github.com/grpc/grpc-go/commit/4ea465d4ab98013f72a142fe0fc89c19770b2935 + - web: https://github.com/grpc/grpc-go/pull/9236 + - web: https://github.com/grpc/grpc-go/releases/tag/v1.82.1 +notes: + - create: failed to auto-populate symbols +source: + id: GHSA-hrxh-6v49-42gf + created: 2026-07-23T18:57:44.966005-04:00 +review_status: REVIEWED