data/reports: add 5 reports

  - data/reports/GO-2026-5116.yaml
  - data/reports/GO-2026-5748.yaml
  - data/reports/GO-2026-5960.yaml
  - data/reports/GO-2026-5983.yaml
  - data/reports/GO-2026-6061.yaml

Fixes golang/vulndb#5116
Fixes golang/vulndb#5748
Fixes golang/vulndb#5960
Fixes golang/vulndb#5983
Fixes golang/vulndb#6061

Change-Id: Id6c327a28d440aac6929a8a68847995f39421020
Reviewed-on: https://go-review.googlesource.com/c/vulndb/+/805140
Reviewed-by: Nicholas Husin <husin@google.com>
Reviewed-by: Nicholas Husin <nsh@golang.org>
LUCI-TryBot-Result: golang-scoped@luci-project-accounts.iam.gserviceaccount.com <golang-scoped@luci-project-accounts.iam.gserviceaccount.com>
diff --git a/data/osv/GO-2026-5116.json b/data/osv/GO-2026-5116.json
new file mode 100644
index 0000000..215cfbe
--- /dev/null
+++ b/data/osv/GO-2026-5116.json
@@ -0,0 +1,41 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-5116",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-44517",
+    "GHSA-49p4-px3h-rq49"
+  ],
+  "summary": "Build breakout using malicious Containerfile or Git HTTP server in github.com/containers/buildah",
+  "details": "Buildah allows a build-time breakout when using a malicious Containerfile or a malicious Git HTTP server. A crafted Git URL or Containerfile can cause Buildah to access files outside of the build context during an ADD or COPY operation.",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/containers/buildah",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "1.38.1"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {}
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/containers/buildah/security/advisories/GHSA-49p4-px3h-rq49"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-5116",
+    "review_status": "REVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-5748.json b/data/osv/GO-2026-5748.json
new file mode 100644
index 0000000..dc54497
--- /dev/null
+++ b/data/osv/GO-2026-5748.json
@@ -0,0 +1,73 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-5748",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-7482",
+    "GHSA-x8qc-fggm-mpqg"
+  ],
+  "summary": "Ollama contains a heap out-of-bounds read vulnerability in the GGUF model loader in github.com/ollama/ollama",
+  "details": "Ollama is vulnerable to a heap out-of-bounds read in its GGUF model loader. A specially crafted GGUF file can cause the loader to read beyond the allocated heap buffer, potentially leading to a denial of service (crash).",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/ollama/ollama",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "0.17.1"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {
+        "imports": [
+          {
+            "path": "github.com/ollama/ollama/server",
+            "symbols": [
+              "WriteTo",
+              "quantizer.WriteTo"
+            ]
+          },
+          {
+            "path": "github.com/ollama/ollama/fs/ggml",
+            "symbols": [
+              "Decode",
+              "gguf.Decode"
+            ]
+          }
+        ]
+      }
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/advisories/GHSA-x8qc-fggm-mpqg"
+    },
+    {
+      "type": "FIX",
+      "url": "https://github.com/ollama/ollama/commit/88d57d0483cca907e0b23a968c83627a20b21047"
+    },
+    {
+      "type": "FIX",
+      "url": "https://github.com/ollama/ollama/pull/14406"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/ollama/ollama/releases/tag/v0.17.1"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-5748",
+    "review_status": "REVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-5960.json b/data/osv/GO-2026-5960.json
new file mode 100644
index 0000000..cd0918e
--- /dev/null
+++ b/data/osv/GO-2026-5960.json
@@ -0,0 +1,175 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-5960",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-54063",
+    "GHSA-h69g-9hx6-f3v4"
+  ],
+  "summary": "Excelize: Unbounded Row Index Allocation in Worksheet Parser (checkSheet OOM/Panic DoS) in github.com/xuri/excelize",
+  "details": "Excelize: Unbounded Row Index Allocation in Worksheet Parser (checkSheet OOM/Panic DoS) in github.com/xuri/excelize",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/xuri/excelize/v2",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "2.11.0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {
+        "imports": [
+          {
+            "path": "github.com/xuri/excelize/v2",
+            "symbols": [
+              "File.AddChart",
+              "File.AddComment",
+              "File.AddDataValidation",
+              "File.AddFormControl",
+              "File.AddHeaderFooterImage",
+              "File.AddIgnoredErrors",
+              "File.AddPicture",
+              "File.AddPictureFromBytes",
+              "File.AddPivotTable",
+              "File.AddShape",
+              "File.AddSlicer",
+              "File.AddSparkline",
+              "File.AddTable",
+              "File.AutoFilter",
+              "File.CalcCellValue",
+              "File.CopySheet",
+              "File.DeleteChart",
+              "File.DeleteComment",
+              "File.DeleteDataValidation",
+              "File.DeleteFormControl",
+              "File.DeletePicture",
+              "File.DeletePivotTable",
+              "File.DeleteSheet",
+              "File.DeleteSlicer",
+              "File.DeleteTable",
+              "File.DuplicateRow",
+              "File.DuplicateRowTo",
+              "File.GetCellFormula",
+              "File.GetCellHyperLink",
+              "File.GetCellRichText",
+              "File.GetCellStyle",
+              "File.GetCellType",
+              "File.GetCellValue",
+              "File.GetColOutlineLevel",
+              "File.GetColStyle",
+              "File.GetColVisible",
+              "File.GetColWidth",
+              "File.GetConditionalFormats",
+              "File.GetDataValidations",
+              "File.GetFormControls",
+              "File.GetHeaderFooter",
+              "File.GetHyperLinkCells",
+              "File.GetMergeCells",
+              "File.GetPageLayout",
+              "File.GetPageMargins",
+              "File.GetPanes",
+              "File.GetPictureCells",
+              "File.GetPictures",
+              "File.GetPivotTables",
+              "File.GetRowHeight",
+              "File.GetRowOutlineLevel",
+              "File.GetRowVisible",
+              "File.GetSheetProps",
+              "File.GetSheetProtection",
+              "File.GetSheetView",
+              "File.GetSlicers",
+              "File.GetTables",
+              "File.GroupSheets",
+              "File.InsertCols",
+              "File.InsertPageBreak",
+              "File.InsertRows",
+              "File.MergeCell",
+              "File.MoveSheet",
+              "File.NewSheet",
+              "File.NewStreamWriter",
+              "File.ProtectSheet",
+              "File.RemoveCol",
+              "File.RemovePageBreak",
+              "File.RemoveRow",
+              "File.SetActiveSheet",
+              "File.SetCellBool",
+              "File.SetCellDefault",
+              "File.SetCellFloat",
+              "File.SetCellFormula",
+              "File.SetCellHyperLink",
+              "File.SetCellInt",
+              "File.SetCellRichText",
+              "File.SetCellStr",
+              "File.SetCellStyle",
+              "File.SetCellUint",
+              "File.SetCellValue",
+              "File.SetColOutlineLevel",
+              "File.SetColStyle",
+              "File.SetColVisible",
+              "File.SetColWidth",
+              "File.SetConditionalFormat",
+              "File.SetHeaderFooter",
+              "File.SetPageLayout",
+              "File.SetPageMargins",
+              "File.SetPanes",
+              "File.SetRowHeight",
+              "File.SetRowOutlineLevel",
+              "File.SetRowStyle",
+              "File.SetRowVisible",
+              "File.SetSheetBackground",
+              "File.SetSheetBackgroundFromBytes",
+              "File.SetSheetCol",
+              "File.SetSheetDimension",
+              "File.SetSheetProps",
+              "File.SetSheetRow",
+              "File.SetSheetView",
+              "File.SetSheetVisible",
+              "File.UngroupSheets",
+              "File.UnmergeCell",
+              "File.UnprotectSheet",
+              "File.UnsetConditionalFormat",
+              "File.UpdateLinkedValue",
+              "File.adjustHelper",
+              "File.workSheetReader",
+              "NewFile",
+              "formulaFuncs.ANCHORARRAY",
+              "formulaFuncs.FORMULATEXT",
+              "formulaFuncs.INDIRECT",
+              "formulaFuncs.ISFORMULA",
+              "xlsxWorksheet.checkSheet"
+            ]
+          }
+        ]
+      }
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/qax-os/excelize/security/advisories/GHSA-h69g-9hx6-f3v4"
+    },
+    {
+      "type": "FIX",
+      "url": "https://github.com/qax-os/excelize/commit/875b959ba62fc9bf45bb0de547ae7c7f7549835c"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/qax-os/excelize/releases/tag/v2.11.0"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-5960",
+    "review_status": "REVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-5983.json b/data/osv/GO-2026-5983.json
new file mode 100644
index 0000000..7167e1d
--- /dev/null
+++ b/data/osv/GO-2026-5983.json
@@ -0,0 +1,80 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-5983",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-54448",
+    "GHSA-q3fv-x8vg-qqm4"
+  ],
+  "summary": "Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser in github.com/aquasecurity/trivy",
+  "details": "Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser in github.com/aquasecurity/trivy",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/aquasecurity/trivy",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "0.71.0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {
+        "imports": [
+          {
+            "path": "github.com/aquasecurity/trivy/pkg/iac/detection",
+            "symbols": [
+              "IsArchive"
+            ]
+          },
+          {
+            "path": "github.com/aquasecurity/trivy/pkg/iac/scanners/helm",
+            "symbols": [
+              "Scanner.ScanFS"
+            ]
+          },
+          {
+            "path": "github.com/aquasecurity/trivy/pkg/iac/scanners/helm/parser",
+            "symbols": [
+              "New",
+              "Parser.ParseFS",
+              "Parser.RenderedChartFiles",
+              "Parser.unpackArchive"
+            ]
+          }
+        ]
+      }
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/aquasecurity/trivy/security/advisories/GHSA-q3fv-x8vg-qqm4"
+    },
+    {
+      "type": "FIX",
+      "url": "https://github.com/aquasecurity/trivy/commit/441251e51ae46cbcf7f436547e0a5766b25328b4"
+    },
+    {
+      "type": "FIX",
+      "url": "https://github.com/aquasecurity/trivy/pull/10718"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/aquasecurity/trivy/releases/tag/v0.71.0"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-5983",
+    "review_status": "REVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6061.json b/data/osv/GO-2026-6061.json
new file mode 100644
index 0000000..335200f
--- /dev/null
+++ b/data/osv/GO-2026-6061.json
@@ -0,0 +1,96 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6061",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "GHSA-hrxh-6v49-42gf"
+  ],
+  "summary": "Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc",
+  "details": "Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc",
+  "affected": [
+    {
+      "package": {
+        "name": "google.golang.org/grpc",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "1.82.1"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {
+        "imports": [
+          {
+            "path": "google.golang.org/grpc/internal/transport",
+            "symbols": [
+              "ClientStream.Close",
+              "ClientStream.Header",
+              "ClientStream.Read",
+              "ClientStream.RecvCompress",
+              "ClientStream.TrailersOnly",
+              "ClientStream.Write",
+              "NewHTTP2Client",
+              "NewServerTransport",
+              "ServerStream.Read",
+              "ServerStream.SendHeader",
+              "ServerStream.Write",
+              "ServerStream.WriteStatus",
+              "Stream.ReadMessageHeader",
+              "controlBuffer.executeAndPut",
+              "controlBuffer.getOnceLocked",
+              "http2Client.Close",
+              "http2Client.GracefulClose",
+              "http2Client.NewStream",
+              "http2Server.Drain",
+              "http2Server.HandleStreams",
+              "recvBufferReader.Read",
+              "recvBufferReader.ReadMessageHeader",
+              "transportReader.Read",
+              "transportReader.ReadMessageHeader"
+            ]
+          },
+          {
+            "path": "google.golang.org/grpc/internal/xds/rbac",
+            "symbols": [
+              "ChainEngine.IsAuthorized",
+              "NewChainEngine",
+              "matchersFromPermissions",
+              "matchersFromPrincipals"
+            ]
+          }
+        ]
+      }
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/grpc/grpc-go/security/advisories/GHSA-hrxh-6v49-42gf"
+    },
+    {
+      "type": "FIX",
+      "url": "https://github.com/grpc/grpc-go/commit/4ea465d4ab98013f72a142fe0fc89c19770b2935"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/grpc/grpc-go/pull/9236"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/grpc/grpc-go/releases/tag/v1.82.1"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6061",
+    "review_status": "REVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/reports/GO-2026-5116.yaml b/data/reports/GO-2026-5116.yaml
new file mode 100644
index 0000000..6937782
--- /dev/null
+++ b/data/reports/GO-2026-5116.yaml
@@ -0,0 +1,24 @@
+id: GO-2026-5116
+modules:
+    - module: github.com/containers/buildah
+      versions:
+        - introduced: 1.38.1
+      vulnerable_at: 1.43.1
+summary: |-
+    Build breakout using malicious Containerfile or Git HTTP server in
+    github.com/containers/buildah
+description: |-
+    Buildah allows a build-time breakout when using a malicious Containerfile
+    or a malicious Git HTTP server. A crafted Git URL or Containerfile can
+    cause Buildah to access files outside of the build context during an
+    ADD or COPY operation.
+cves:
+    - CVE-2026-44517
+ghsas:
+    - GHSA-49p4-px3h-rq49
+references:
+    - advisory: https://github.com/containers/buildah/security/advisories/GHSA-49p4-px3h-rq49
+source:
+    id: GHSA-49p4-px3h-rq49
+    created: 2026-07-23T19:30:52.165275-04:00
+review_status: REVIEWED
diff --git a/data/reports/GO-2026-5748.yaml b/data/reports/GO-2026-5748.yaml
new file mode 100644
index 0000000..a621279
--- /dev/null
+++ b/data/reports/GO-2026-5748.yaml
@@ -0,0 +1,37 @@
+id: GO-2026-5748
+modules:
+    - module: github.com/ollama/ollama
+      versions:
+        - fixed: 0.17.1
+      vulnerable_at: 0.17.1-rc2
+      packages:
+        - package: github.com/ollama/ollama/server
+          symbols:
+            - WriteTo
+            - quantizer.WriteTo
+          skip_fix: build errors during static analysis
+        - package: github.com/ollama/ollama/fs/ggml
+          symbols:
+            - Decode
+            - gguf.Decode
+          skip_fix: build errors during static analysis
+summary: |-
+    Ollama contains a heap out-of-bounds read vulnerability in the GGUF model loader
+    in github.com/ollama/ollama
+description: |-
+    Ollama is vulnerable to a heap out-of-bounds read in its GGUF model loader.
+    A specially crafted GGUF file can cause the loader to read beyond the
+    allocated heap buffer, potentially leading to a denial of service (crash).
+cves:
+    - CVE-2026-7482
+ghsas:
+    - GHSA-x8qc-fggm-mpqg
+references:
+    - advisory: https://github.com/advisories/GHSA-x8qc-fggm-mpqg
+    - fix: https://github.com/ollama/ollama/commit/88d57d0483cca907e0b23a968c83627a20b21047
+    - fix: https://github.com/ollama/ollama/pull/14406
+    - web: https://github.com/ollama/ollama/releases/tag/v0.17.1
+source:
+    id: GHSA-x8qc-fggm-mpqg
+    created: 2026-07-23T19:00:31.725511-04:00
+review_status: REVIEWED
diff --git a/data/reports/GO-2026-5960.yaml b/data/reports/GO-2026-5960.yaml
new file mode 100644
index 0000000..6087903
--- /dev/null
+++ b/data/reports/GO-2026-5960.yaml
@@ -0,0 +1,140 @@
+id: GO-2026-5960
+modules:
+    - module: github.com/xuri/excelize/v2
+      versions:
+        - fixed: 2.11.0
+      vulnerable_at: 2.10.1
+      packages:
+        - package: github.com/xuri/excelize/v2
+          symbols:
+            - File.adjustHelper
+            - File.workSheetReader
+            - xlsxWorksheet.checkSheet
+          derived_symbols:
+            - File.AddChart
+            - File.AddComment
+            - File.AddDataValidation
+            - File.AddFormControl
+            - File.AddHeaderFooterImage
+            - File.AddIgnoredErrors
+            - File.AddPicture
+            - File.AddPictureFromBytes
+            - File.AddPivotTable
+            - File.AddShape
+            - File.AddSlicer
+            - File.AddSparkline
+            - File.AddTable
+            - File.AutoFilter
+            - File.CalcCellValue
+            - File.CopySheet
+            - File.DeleteChart
+            - File.DeleteComment
+            - File.DeleteDataValidation
+            - File.DeleteFormControl
+            - File.DeletePicture
+            - File.DeletePivotTable
+            - File.DeleteSheet
+            - File.DeleteSlicer
+            - File.DeleteTable
+            - File.DuplicateRow
+            - File.DuplicateRowTo
+            - File.GetCellFormula
+            - File.GetCellHyperLink
+            - File.GetCellRichText
+            - File.GetCellStyle
+            - File.GetCellType
+            - File.GetCellValue
+            - File.GetColOutlineLevel
+            - File.GetColStyle
+            - File.GetColVisible
+            - File.GetColWidth
+            - File.GetConditionalFormats
+            - File.GetDataValidations
+            - File.GetFormControls
+            - File.GetHeaderFooter
+            - File.GetHyperLinkCells
+            - File.GetMergeCells
+            - File.GetPageLayout
+            - File.GetPageMargins
+            - File.GetPanes
+            - File.GetPictureCells
+            - File.GetPictures
+            - File.GetPivotTables
+            - File.GetRowHeight
+            - File.GetRowOutlineLevel
+            - File.GetRowVisible
+            - File.GetSheetProps
+            - File.GetSheetProtection
+            - File.GetSheetView
+            - File.GetSlicers
+            - File.GetTables
+            - File.GroupSheets
+            - File.InsertCols
+            - File.InsertPageBreak
+            - File.InsertRows
+            - File.MergeCell
+            - File.MoveSheet
+            - File.NewSheet
+            - File.NewStreamWriter
+            - File.ProtectSheet
+            - File.RemoveCol
+            - File.RemovePageBreak
+            - File.RemoveRow
+            - File.SetActiveSheet
+            - File.SetCellBool
+            - File.SetCellDefault
+            - File.SetCellFloat
+            - File.SetCellFormula
+            - File.SetCellHyperLink
+            - File.SetCellInt
+            - File.SetCellRichText
+            - File.SetCellStr
+            - File.SetCellStyle
+            - File.SetCellUint
+            - File.SetCellValue
+            - File.SetColOutlineLevel
+            - File.SetColStyle
+            - File.SetColVisible
+            - File.SetColWidth
+            - File.SetConditionalFormat
+            - File.SetHeaderFooter
+            - File.SetPageLayout
+            - File.SetPageMargins
+            - File.SetPanes
+            - File.SetRowHeight
+            - File.SetRowOutlineLevel
+            - File.SetRowStyle
+            - File.SetRowVisible
+            - File.SetSheetBackground
+            - File.SetSheetBackgroundFromBytes
+            - File.SetSheetCol
+            - File.SetSheetDimension
+            - File.SetSheetProps
+            - File.SetSheetRow
+            - File.SetSheetView
+            - File.SetSheetVisible
+            - File.UngroupSheets
+            - File.UnmergeCell
+            - File.UnprotectSheet
+            - File.UnsetConditionalFormat
+            - File.UpdateLinkedValue
+            - NewFile
+            - formulaFuncs.ANCHORARRAY
+            - formulaFuncs.FORMULATEXT
+            - formulaFuncs.INDIRECT
+            - formulaFuncs.ISFORMULA
+summary: |-
+    Excelize: Unbounded Row Index Allocation in Worksheet Parser (checkSheet
+    OOM/Panic DoS) in github.com/xuri/excelize
+cves:
+    - CVE-2026-54063
+ghsas:
+    - GHSA-h69g-9hx6-f3v4
+references:
+    - advisory: https://github.com/qax-os/excelize/security/advisories/GHSA-h69g-9hx6-f3v4
+    - fix: https://github.com/qax-os/excelize/commit/875b959ba62fc9bf45bb0de547ae7c7f7549835c
+    - web: https://github.com/qax-os/excelize/releases/tag/v2.11.0
+source:
+    id: GHSA-h69g-9hx6-f3v4
+    created: 2026-07-23T18:59:10.303167-04:00
+review_status: REVIEWED
diff --git a/data/reports/GO-2026-5983.yaml b/data/reports/GO-2026-5983.yaml
new file mode 100644
index 0000000..3cc5b34
--- /dev/null
+++ b/data/reports/GO-2026-5983.yaml
@@ -0,0 +1,40 @@
+id: GO-2026-5983
+modules:
+    - module: github.com/aquasecurity/trivy
+      versions:
+        - fixed: 0.71.0
+      vulnerable_at: 0.70.0
+      packages:
+        - package: github.com/aquasecurity/trivy/pkg/iac/detection
+          symbols:
+            - IsArchive
+          skip_fix: build errors during static analysis
+        - package: github.com/aquasecurity/trivy/pkg/iac/scanners/helm
+          symbols:
+            - Scanner.ScanFS
+          skip_fix: build errors during static analysis
+        - package: github.com/aquasecurity/trivy/pkg/iac/scanners/helm/parser
+          symbols:
+            - Parser.RenderedChartFiles
+            - Parser.ParseFS
+            - New
+            - Parser.unpackArchive
+          skip_fix: build errors during static analysis
+summary: |-
+    Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser in
+    github.com/aquasecurity/trivy
+cves:
+    - CVE-2026-54448
+ghsas:
+    - GHSA-q3fv-x8vg-qqm4
+references:
+    - advisory: https://github.com/aquasecurity/trivy/security/advisories/GHSA-q3fv-x8vg-qqm4
+    - fix: https://github.com/aquasecurity/trivy/commit/441251e51ae46cbcf7f436547e0a5766b25328b4
+    - fix: https://github.com/aquasecurity/trivy/pull/10718
+    - web: https://github.com/aquasecurity/trivy/releases/tag/v0.71.0
+notes:
+    - failed to auto-populate derived symbols: build errors during static analysis
+source:
+    id: GHSA-q3fv-x8vg-qqm4
+    created: 2026-07-23T18:58:13.333642-04:00
+review_status: REVIEWED
diff --git a/data/reports/GO-2026-6061.yaml b/data/reports/GO-2026-6061.yaml
new file mode 100644
index 0000000..1841248
--- /dev/null
+++ b/data/reports/GO-2026-6061.yaml
@@ -0,0 +1,57 @@
+id: GO-2026-6061
+modules:
+    - module: google.golang.org/grpc
+      versions:
+        - fixed: 1.82.1
+      vulnerable_at: 1.82.0
+      packages:
+        - package: google.golang.org/grpc/internal/transport
+          symbols:
+            - controlBuffer.executeAndPut
+            - controlBuffer.getOnceLocked
+          derived_symbols:
+            - ClientStream.Close
+            - ClientStream.Header
+            - ClientStream.Read
+            - ClientStream.RecvCompress
+            - ClientStream.TrailersOnly
+            - ClientStream.Write
+            - NewHTTP2Client
+            - NewServerTransport
+            - ServerStream.Read
+            - ServerStream.SendHeader
+            - ServerStream.Write
+            - ServerStream.WriteStatus
+            - Stream.ReadMessageHeader
+            - http2Client.Close
+            - http2Client.GracefulClose
+            - http2Client.NewStream
+            - http2Server.Drain
+            - http2Server.HandleStreams
+            - recvBufferReader.Read
+            - recvBufferReader.ReadMessageHeader
+            - transportReader.Read
+            - transportReader.ReadMessageHeader
+        - package: google.golang.org/grpc/internal/xds/rbac
+          symbols:
+            - matchersFromPrincipals
+            - matchersFromPermissions
+          derived_symbols:
+            - ChainEngine.IsAuthorized
+            - NewChainEngine
+summary: |-
+    Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2
+    transport server implementation in google.golang.org/grpc
+ghsas:
+    - GHSA-hrxh-6v49-42gf
+references:
+    - advisory: https://github.com/grpc/grpc-go/security/advisories/GHSA-hrxh-6v49-42gf
+    - fix: https://github.com/grpc/grpc-go/commit/4ea465d4ab98013f72a142fe0fc89c19770b2935
+    - web: https://github.com/grpc/grpc-go/pull/9236
+    - web: https://github.com/grpc/grpc-go/releases/tag/v1.82.1
+notes:
+    - create: failed to auto-populate symbols
+source:
+    id: GHSA-hrxh-6v49-42gf
+    created: 2026-07-23T18:57:44.966005-04:00
+review_status: REVIEWED