data/reports: add 15 first-party reports Fixes golang/vulndb#6599 Fixes golang/vulndb#6600 Fixes golang/vulndb#6601 Fixes golang/vulndb#6602 Fixes golang/vulndb#6603 Fixes golang/vulndb#6604 Fixes golang/vulndb#6605 Fixes golang/vulndb#6607 Fixes golang/vulndb#6608 Fixes golang/vulndb#6609 Fixes golang/vulndb#6610 Fixes golang/vulndb#6611 Fixes golang/vulndb#6612 Fixes golang/vulndb#6613 Fixes golang/vulndb#6617 Change-Id: Ia6a9c0b6e39e7c63ceaa89ae98d1d13183a198e0 Reviewed-on: https://go-review.googlesource.com/c/vulndb/+/847585 Reviewed-by: Nicholas Husin <nsh@golang.org> Reviewed-by: Nicholas Husin <husin@google.com> LUCI-TryBot-Result: golang-scoped@luci-project-accounts.iam.gserviceaccount.com <golang-scoped@luci-project-accounts.iam.gserviceaccount.com> Reviewed-by: Neal Patel <nealpatel@google.com>
diff --git a/data/cve/v5/GO-2026-6599.json b/data/cve/v5/GO-2026-6599.json new file mode 100644 index 0000000..8c61f6d --- /dev/null +++ b/data/cve/v5/GO-2026-6599.json
@@ -0,0 +1,79 @@ +{ + "dataType": "CVE_RECORD", + "dataVersion": "5.0", + "cveMetadata": { + "cveId": "CVE-2026-94448" + }, + "containers": { + "cna": { + "providerMetadata": { + "orgId": "1bb62c36-49e3-4200-9d77-64a1400537cc" + }, + "title": "Reset context tracking on consecutive template expressions in html/template", + "descriptions": [ + { + "lang": "en", + "value": "When a JavaScript template literal contains consecutive expressions, the context tracking state was not properly reset upon entering a new expression. We now ensure that template-literal expression entries correctly reset context variables so all subsequent regular expression literals are accurately recognized and escaped." + } + ], + "affected": [ + { + "vendor": "Go standard library", + "product": "html/template", + "collectionURL": "https://pkg.go.dev", + "packageName": "html/template", + "versions": [ + { + "version": "0", + "lessThan": "1.26.9", + "status": "affected", + "versionType": "semver" + }, + { + "version": "1.27.0-0", + "lessThan": "1.27.2", + "status": "affected", + "versionType": "semver" + } + ], + "programRoutines": [ + { + "name": "tJSTmpl" + }, + { + "name": "Template.Execute" + }, + { + "name": "Template.ExecuteTemplate" + } + ], + "defaultStatus": "unaffected" + } + ], + "problemTypes": [ + { + "descriptions": [ + { + "lang": "en", + "description": "CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')" + } + ] + } + ], + "references": [ + { + "url": "https://go.dev/cl/839866" + }, + { + "url": "https://go.dev/issue/81821" + }, + { + "url": "https://groups.google.com/g/golang-announce/c/U2fTuyDJznI" + }, + { + "url": "https://pkg.go.dev/vuln/GO-2026-6599" + } + ] + } + } +} \ No newline at end of file
diff --git a/data/cve/v5/GO-2026-6600.json b/data/cve/v5/GO-2026-6600.json new file mode 100644 index 0000000..2fb34f3 --- /dev/null +++ b/data/cve/v5/GO-2026-6600.json
@@ -0,0 +1,82 @@ +{ + "dataType": "CVE_RECORD", + "dataVersion": "5.0", + "cveMetadata": { + "cveId": "CVE-2026-97030" + }, + "containers": { + "cna": { + "providerMetadata": { + "orgId": "1bb62c36-49e3-4200-9d77-64a1400537cc" + }, + "title": "Recognize yield as regexp preceder keyword in html/template", + "descriptions": [ + { + "lang": "en", + "value": "A trusted template author may have previously written a valid template wherein the use of the 'yield' keyword would not be correctly escaped. We now ensure that valid keyword uses are escaped and non-keyword uses are not escaped." + } + ], + "affected": [ + { + "vendor": "Go standard library", + "product": "html/template", + "collectionURL": "https://pkg.go.dev", + "packageName": "html/template", + "versions": [ + { + "version": "0", + "lessThan": "1.26.9", + "status": "affected", + "versionType": "semver" + }, + { + "version": "1.27.0-0", + "lessThan": "1.27.2", + "status": "affected", + "versionType": "semver" + } + ], + "programRoutines": [ + { + "name": "nextJSCtx" + }, + { + "name": "tJS" + }, + { + "name": "Template.Execute" + }, + { + "name": "Template.ExecuteTemplate" + } + ], + "defaultStatus": "unaffected" + } + ], + "problemTypes": [ + { + "descriptions": [ + { + "lang": "en", + "description": "CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')" + } + ] + } + ], + "references": [ + { + "url": "https://go.dev/cl/840925" + }, + { + "url": "https://go.dev/issue/81823" + }, + { + "url": "https://groups.google.com/g/golang-announce/c/U2fTuyDJznI" + }, + { + "url": "https://pkg.go.dev/vuln/GO-2026-6600" + } + ] + } + } +} \ No newline at end of file
diff --git a/data/cve/v5/GO-2026-6601.json b/data/cve/v5/GO-2026-6601.json new file mode 100644 index 0000000..2364c30 --- /dev/null +++ b/data/cve/v5/GO-2026-6601.json
@@ -0,0 +1,68 @@ +{ + "dataType": "CVE_RECORD", + "dataVersion": "5.0", + "cveMetadata": { + "cveId": "CVE-2026-94444" + }, + "containers": { + "cna": { + "providerMetadata": { + "orgId": "1bb62c36-49e3-4200-9d77-64a1400537cc" + }, + "title": "Checksum bypass for golang.org/fips140 in cmd/go", + "descriptions": [ + { + "lang": "en", + "value": "Previously, a user operating inside of a malicious Go project that defines a bogus golang.org/fips140 and operates a malicious GOMODPROXY the user chooses to connect to can serve an arbitrary module in its place. We now unpack the trusted ziphash for the bundled golang.org/fips140 module and construct its entry in the GOMODCACHE such that it can be verified by the toolchain." + } + ], + "affected": [ + { + "vendor": "Go toolchain", + "product": "cmd/go", + "collectionURL": "https://pkg.go.dev", + "packageName": "cmd/go", + "versions": [ + { + "version": "0", + "lessThan": "1.26.9", + "status": "affected", + "versionType": "semver" + }, + { + "version": "1.27.0-0", + "lessThan": "1.27.2", + "status": "affected", + "versionType": "semver" + } + ], + "defaultStatus": "unaffected" + } + ], + "problemTypes": [ + { + "descriptions": [ + { + "lang": "en", + "description": "CWE-354: Improper Validation of Integrity Check Value" + } + ] + } + ], + "references": [ + { + "url": "https://go.dev/cl/840685" + }, + { + "url": "https://go.dev/issue/81833" + }, + { + "url": "https://groups.google.com/g/golang-announce/c/U2fTuyDJznI" + }, + { + "url": "https://pkg.go.dev/vuln/GO-2026-6601" + } + ] + } + } +} \ No newline at end of file
diff --git a/data/cve/v5/GO-2026-6602.json b/data/cve/v5/GO-2026-6602.json new file mode 100644 index 0000000..000ad67 --- /dev/null +++ b/data/cve/v5/GO-2026-6602.json
@@ -0,0 +1,68 @@ +{ + "dataType": "CVE_RECORD", + "dataVersion": "5.0", + "cveMetadata": { + "cveId": "CVE-2026-94447" + }, + "containers": { + "cna": { + "providerMetadata": { + "orgId": "1bb62c36-49e3-4200-9d77-64a1400537cc" + }, + "title": "Checksum database bypass for golang.org/toolchain in cmd/go", + "descriptions": [ + { + "lang": "en", + "value": "Previously, a user operating inside of a malicious Go project that defines a bogus golang.org/toolchain go.sum entry and operates a malicious GOMODPROXY the user chooses to use can bypass the intended checksum. We now ensure that golang.org/toolchain always goes to the network for the canonical checksum." + } + ], + "affected": [ + { + "vendor": "Go toolchain", + "product": "cmd/go", + "collectionURL": "https://pkg.go.dev", + "packageName": "cmd/go", + "versions": [ + { + "version": "0", + "lessThan": "1.26.9", + "status": "affected", + "versionType": "semver" + }, + { + "version": "1.27.0-0", + "lessThan": "1.27.2", + "status": "affected", + "versionType": "semver" + } + ], + "defaultStatus": "unaffected" + } + ], + "problemTypes": [ + { + "descriptions": [ + { + "lang": "en", + "description": "CWE-354: Improper Validation of Integrity Check Value" + } + ] + } + ], + "references": [ + { + "url": "https://go.dev/cl/840785" + }, + { + "url": "https://go.dev/issue/81834" + }, + { + "url": "https://groups.google.com/g/golang-announce/c/U2fTuyDJznI" + }, + { + "url": "https://pkg.go.dev/vuln/GO-2026-6602" + } + ] + } + } +} \ No newline at end of file
diff --git a/data/cve/v5/GO-2026-6603.json b/data/cve/v5/GO-2026-6603.json new file mode 100644 index 0000000..5515290 --- /dev/null +++ b/data/cve/v5/GO-2026-6603.json
@@ -0,0 +1,1169 @@ +{ + "dataType": "CVE_RECORD", + "dataVersion": "5.0", + "cveMetadata": { + "cveId": "CVE-2026-78659" + }, + "containers": { + "cna": { + "providerMetadata": { + "orgId": "1bb62c36-49e3-4200-9d77-64a1400537cc" + }, + "title": "HTTP/2 server memory exhaustion due to Trailer headers in net/http", + "descriptions": [ + { + "lang": "en", + "value": "When \"Trailer\" headers are sent by a client, the HTTP server internally uses the header values to populate the Request.Trailer map passed to the server handler. Because Request.Trailer is a map, each entry incurs memory overhead. For HTTP/2 servers, a malicious client can exploit this by sending a \"Trailer\" header that declares a large number of fields, causing the server to allocate a disproportionate amount of memory while bypassing Server.MaxHeaderValueCount and Server.MaxHeaderBytes limits. This exploit is not applicable for HTTP/1 servers, which do not support multiplexing a large number of requests over one TCP connection, and whose Server.MaxHeaderBytes are calculated differently." + } + ], + "affected": [ + { + "vendor": "Go standard library", + "product": "net/http", + "collectionURL": "https://pkg.go.dev", + "packageName": "net/http", + "versions": [ + { + "version": "0", + "lessThan": "1.26.9", + "status": "affected", + "versionType": "semver" + } + ], + "programRoutines": [ + { + "name": "http2Framer.readMetaFrame" + }, + { + "name": "CanonicalHeaderKey" + }, + { + "name": "Client.CloseIdleConnections" + }, + { + "name": "Client.Do" + }, + { + "name": "Client.Get" + }, + { + "name": "Client.Head" + }, + { + "name": "Client.Post" + }, + { + "name": "Client.PostForm" + }, + { + "name": "ClientConn.Close" + }, + { + "name": "ClientConn.RoundTrip" + }, + { + "name": "Cookie.String" + }, + { + "name": "Cookie.Valid" + }, + { + "name": "CrossOriginProtection.AddInsecureBypassPattern" + }, + { + "name": "CrossOriginProtection.AddTrustedOrigin" + }, + { + "name": "CrossOriginProtection.Check" + }, + { + "name": "Dir.Open" + }, + { + "name": "Error" + }, + { + "name": "Get" + }, + { + "name": "Handle" + }, + { + "name": "HandleFunc" + }, + { + "name": "HandlerFunc.ServeHTTP" + }, + { + "name": "Head" + }, + { + "name": "Header.Add" + }, + { + "name": "Header.Del" + }, + { + "name": "Header.Get" + }, + { + "name": "Header.Set" + }, + { + "name": "Header.Values" + }, + { + "name": "Header.Write" + }, + { + "name": "Header.WriteSubset" + }, + { + "name": "ListenAndServe" + }, + { + "name": "ListenAndServeTLS" + }, + { + "name": "NewRequest" + }, + { + "name": "NewRequestWithContext" + }, + { + "name": "NotFound" + }, + { + "name": "ParseCookie" + }, + { + "name": "ParseSetCookie" + }, + { + "name": "ParseTime" + }, + { + "name": "Post" + }, + { + "name": "PostForm" + }, + { + "name": "ProxyFromEnvironment" + }, + { + "name": "ReadRequest" + }, + { + "name": "ReadResponse" + }, + { + "name": "Redirect" + }, + { + "name": "Request.AddCookie" + }, + { + "name": "Request.BasicAuth" + }, + { + "name": "Request.Cookie" + }, + { + "name": "Request.Cookies" + }, + { + "name": "Request.CookiesNamed" + }, + { + "name": "Request.FormFile" + }, + { + "name": "Request.FormValue" + }, + { + "name": "Request.MultipartReader" + }, + { + "name": "Request.ParseForm" + }, + { + "name": "Request.ParseMultipartForm" + }, + { + "name": "Request.PostFormValue" + }, + { + "name": "Request.Referer" + }, + { + "name": "Request.SetBasicAuth" + }, + { + "name": "Request.UserAgent" + }, + { + "name": "Request.Write" + }, + { + "name": "Request.WriteProxy" + }, + { + "name": "Response.Cookies" + }, + { + "name": "Response.Location" + }, + { + "name": "Response.Write" + }, + { + "name": "ResponseController.EnableFullDuplex" + }, + { + "name": "ResponseController.Flush" + }, + { + "name": "ResponseController.Hijack" + }, + { + "name": "ResponseController.SetReadDeadline" + }, + { + "name": "ResponseController.SetWriteDeadline" + }, + { + "name": "Serve" + }, + { + "name": "ServeContent" + }, + { + "name": "ServeFile" + }, + { + "name": "ServeFileFS" + }, + { + "name": "ServeMux.Handle" + }, + { + "name": "ServeMux.HandleFunc" + }, + { + "name": "ServeMux.ServeHTTP" + }, + { + "name": "ServeTLS" + }, + { + "name": "Server.Close" + }, + { + "name": "Server.ListenAndServe" + }, + { + "name": "Server.ListenAndServeTLS" + }, + { + "name": "Server.Serve" + }, + { + "name": "Server.ServeTLS" + }, + { + "name": "Server.SetKeepAlivesEnabled" + }, + { + "name": "Server.Shutdown" + }, + { + "name": "SetCookie" + }, + { + "name": "Transport.CancelRequest" + }, + { + "name": "Transport.Clone" + }, + { + "name": "Transport.CloseIdleConnections" + }, + { + "name": "Transport.NewClientConn" + }, + { + "name": "Transport.RoundTrip" + }, + { + "name": "body.Close" + }, + { + "name": "body.Read" + }, + { + "name": "bodyEOFSignal.Close" + }, + { + "name": "bodyEOFSignal.Read" + }, + { + "name": "bodyLocked.Read" + }, + { + "name": "bufioFlushWriter.Write" + }, + { + "name": "cancelTimerBody.Close" + }, + { + "name": "cancelTimerBody.Read" + }, + { + "name": "checkConnErrorWriter.Write" + }, + { + "name": "chunkWriter.Write" + }, + { + "name": "connReader.Read" + }, + { + "name": "connectMethodKey.String" + }, + { + "name": "expectContinueReader.Close" + }, + { + "name": "expectContinueReader.Read" + }, + { + "name": "extraHeader.Write" + }, + { + "name": "fileHandler.ServeHTTP" + }, + { + "name": "fileTransport.RoundTrip" + }, + { + "name": "globalOptionsHandler.ServeHTTP" + }, + { + "name": "gzipReader.Close" + }, + { + "name": "gzipReader.Read" + }, + { + "name": "http1ClientConn.Close" + }, + { + "name": "http1ClientConn.RoundTrip" + }, + { + "name": "http2ClientConn.Close" + }, + { + "name": "http2ClientConn.Ping" + }, + { + "name": "http2ClientConn.RoundTrip" + }, + { + "name": "http2ClientConn.Shutdown" + }, + { + "name": "http2ConnectionError.Error" + }, + { + "name": "http2ErrCode.String" + }, + { + "name": "http2FrameHeader.String" + }, + { + "name": "http2FrameType.String" + }, + { + "name": "http2FrameWriteRequest.String" + }, + { + "name": "http2Framer.ReadFrame" + }, + { + "name": "http2Framer.ReadFrameForHeader" + }, + { + "name": "http2Framer.ReadFrameHeader" + }, + { + "name": "http2Framer.WriteContinuation" + }, + { + "name": "http2Framer.WriteData" + }, + { + "name": "http2Framer.WriteDataPadded" + }, + { + "name": "http2Framer.WriteGoAway" + }, + { + "name": "http2Framer.WriteHeaders" + }, + { + "name": "http2Framer.WritePing" + }, + { + "name": "http2Framer.WritePriority" + }, + { + "name": "http2Framer.WritePushPromise" + }, + { + "name": "http2Framer.WriteRSTStream" + }, + { + "name": "http2Framer.WriteRawFrame" + }, + { + "name": "http2Framer.WriteSettings" + }, + { + "name": "http2Framer.WriteSettingsAck" + }, + { + "name": "http2Framer.WriteWindowUpdate" + }, + { + "name": "http2GoAwayError.Error" + }, + { + "name": "http2Server.ServeConn" + }, + { + "name": "http2Setting.String" + }, + { + "name": "http2SettingID.String" + }, + { + "name": "http2SettingsFrame.ForeachSetting" + }, + { + "name": "http2StreamError.Error" + }, + { + "name": "http2Transport.CloseIdleConnections" + }, + { + "name": "http2Transport.NewClientConn" + }, + { + "name": "http2Transport.RoundTrip" + }, + { + "name": "http2Transport.RoundTripOpt" + }, + { + "name": "http2bufferedWriter.Flush" + }, + { + "name": "http2bufferedWriter.Write" + }, + { + "name": "http2bufferedWriterTimeoutWriter.Write" + }, + { + "name": "http2chunkWriter.Write" + }, + { + "name": "http2clientConnPool.GetClientConn" + }, + { + "name": "http2connError.Error" + }, + { + "name": "http2dataBuffer.Read" + }, + { + "name": "http2duplicatePseudoHeaderError.Error" + }, + { + "name": "http2gzipReader.Close" + }, + { + "name": "http2gzipReader.Read" + }, + { + "name": "http2headerFieldNameError.Error" + }, + { + "name": "http2headerFieldValueError.Error" + }, + { + "name": "http2netHTTPClientConn.Close" + }, + { + "name": "http2netHTTPClientConn.RoundTrip" + }, + { + "name": "http2noDialClientConnPool.GetClientConn" + }, + { + "name": "http2noDialH2RoundTripper.NewClientConn" + }, + { + "name": "http2noDialH2RoundTripper.RoundTrip" + }, + { + "name": "http2pipe.Read" + }, + { + "name": "http2priorityWriteSchedulerRFC7540.CloseStream" + }, + { + "name": "http2priorityWriteSchedulerRFC7540.OpenStream" + }, + { + "name": "http2priorityWriteSchedulerRFC9218.OpenStream" + }, + { + "name": "http2pseudoHeaderError.Error" + }, + { + "name": "http2requestBody.Close" + }, + { + "name": "http2requestBody.Read" + }, + { + "name": "http2responseWriter.Flush" + }, + { + "name": "http2responseWriter.FlushError" + }, + { + "name": "http2responseWriter.Push" + }, + { + "name": "http2responseWriter.SetReadDeadline" + }, + { + "name": "http2responseWriter.SetWriteDeadline" + }, + { + "name": "http2responseWriter.Write" + }, + { + "name": "http2responseWriter.WriteHeader" + }, + { + "name": "http2responseWriter.WriteString" + }, + { + "name": "http2roundRobinWriteScheduler.OpenStream" + }, + { + "name": "http2serverConn.CloseConn" + }, + { + "name": "http2serverConn.Flush" + }, + { + "name": "http2stickyErrWriter.Write" + }, + { + "name": "http2transportResponseBody.Close" + }, + { + "name": "http2transportResponseBody.Read" + }, + { + "name": "http2unencryptedTransport.RoundTrip" + }, + { + "name": "http2writeData.String" + }, + { + "name": "initALPNRequest.ServeHTTP" + }, + { + "name": "loggingConn.Close" + }, + { + "name": "loggingConn.Read" + }, + { + "name": "loggingConn.Write" + }, + { + "name": "maxBytesReader.Close" + }, + { + "name": "maxBytesReader.Read" + }, + { + "name": "onceCloseListener.Close" + }, + { + "name": "persistConn.Read" + }, + { + "name": "persistConnWriter.ReadFrom" + }, + { + "name": "persistConnWriter.Write" + }, + { + "name": "populateResponse.Write" + }, + { + "name": "populateResponse.WriteHeader" + }, + { + "name": "readTrackingBody.Close" + }, + { + "name": "readTrackingBody.Read" + }, + { + "name": "readWriteCloserBody.CloseWrite" + }, + { + "name": "readWriteCloserBody.Read" + }, + { + "name": "redirectHandler.ServeHTTP" + }, + { + "name": "response.Flush" + }, + { + "name": "response.FlushError" + }, + { + "name": "response.Hijack" + }, + { + "name": "response.ReadFrom" + }, + { + "name": "response.Write" + }, + { + "name": "response.WriteHeader" + }, + { + "name": "response.WriteString" + }, + { + "name": "serverHandler.ServeHTTP" + }, + { + "name": "socksDialer.DialWithConn" + }, + { + "name": "socksUsernamePassword.Authenticate" + }, + { + "name": "stringWriter.WriteString" + }, + { + "name": "timeoutHandler.ServeHTTP" + }, + { + "name": "timeoutWriter.Write" + }, + { + "name": "timeoutWriter.WriteHeader" + }, + { + "name": "transportReadFromServerError.Error" + }, + { + "name": "unencryptedHTTP2Request.ServeHTTP" + } + ], + "defaultStatus": "unaffected" + }, + { + "vendor": "Go standard library", + "product": "net/http/internal/http2", + "collectionURL": "https://pkg.go.dev", + "packageName": "net/http/internal/http2", + "versions": [ + { + "version": "1.27.0-0", + "lessThan": "1.27.2", + "status": "affected", + "versionType": "semver" + } + ], + "programRoutines": [ + { + "name": "Framer.readMetaFrame" + }, + { + "name": "ClientConn.Close" + }, + { + "name": "ClientConn.Ping" + }, + { + "name": "ClientConn.RoundTrip" + }, + { + "name": "ClientConn.Shutdown" + }, + { + "name": "Framer.ReadFrame" + }, + { + "name": "Framer.ReadFrameForHeader" + }, + { + "name": "Framer.ReadFrameHeader" + }, + { + "name": "Framer.WriteContinuation" + }, + { + "name": "Framer.WriteData" + }, + { + "name": "Framer.WriteDataPadded" + }, + { + "name": "Framer.WriteGoAway" + }, + { + "name": "Framer.WriteHeaders" + }, + { + "name": "Framer.WritePing" + }, + { + "name": "Framer.WritePriority" + }, + { + "name": "Framer.WritePriorityUpdate" + }, + { + "name": "Framer.WritePushPromise" + }, + { + "name": "Framer.WriteRSTStream" + }, + { + "name": "Framer.WriteRawFrame" + }, + { + "name": "Framer.WriteSettings" + }, + { + "name": "Framer.WriteSettingsAck" + }, + { + "name": "Framer.WriteWindowUpdate" + }, + { + "name": "NetHTTPClientConn.Close" + }, + { + "name": "NetHTTPClientConn.Ping" + }, + { + "name": "NetHTTPClientConn.RoundTrip" + }, + { + "name": "ReadFrameHeader" + }, + { + "name": "Server.GracefulShutdown" + }, + { + "name": "Server.ServeConn" + }, + { + "name": "SettingsFrame.ForeachSetting" + }, + { + "name": "Transport.AddConn" + }, + { + "name": "Transport.CloseIdleConnections" + }, + { + "name": "Transport.NewClientConn" + }, + { + "name": "Transport.RoundTrip" + }, + { + "name": "Transport.RoundTripOpt" + }, + { + "name": "bufferedWriter.Flush" + }, + { + "name": "bufferedWriter.Write" + }, + { + "name": "bufferedWriterTimeoutWriter.Write" + }, + { + "name": "chunkWriter.Write" + }, + { + "name": "clientConnPool.GetClientConn" + }, + { + "name": "gzipReader.Close" + }, + { + "name": "gzipReader.Read" + }, + { + "name": "noDialClientConnPool.GetClientConn" + }, + { + "name": "requestBody.Close" + }, + { + "name": "responseWriter.Flush" + }, + { + "name": "responseWriter.FlushError" + }, + { + "name": "responseWriter.Push" + }, + { + "name": "responseWriter.Write" + }, + { + "name": "responseWriter.WriteHeader" + }, + { + "name": "responseWriter.WriteString" + }, + { + "name": "serve400Handler.ServeHTTP" + }, + { + "name": "serverConn.Flush" + }, + { + "name": "stickyErrWriter.Write" + }, + { + "name": "transportResponseBody.Close" + }, + { + "name": "transportResponseBody.Read" + } + ], + "defaultStatus": "unaffected" + }, + { + "vendor": "golang.org/x/net", + "product": "golang.org/x/net/http2", + "collectionURL": "https://pkg.go.dev", + "packageName": "golang.org/x/net/http2", + "versions": [ + { + "version": "0", + "lessThan": "0.60.0", + "status": "affected", + "versionType": "semver" + } + ], + "programRoutines": [ + { + "name": "Framer.readMetaFrame" + }, + { + "name": "ClientConn.Close" + }, + { + "name": "ClientConn.Ping" + }, + { + "name": "ClientConn.RoundTrip" + }, + { + "name": "ClientConn.Shutdown" + }, + { + "name": "ConfigureServer" + }, + { + "name": "ConfigureTransport" + }, + { + "name": "ConfigureTransports" + }, + { + "name": "ConnectionError.Error" + }, + { + "name": "ErrCode.String" + }, + { + "name": "FrameHeader.String" + }, + { + "name": "FrameType.String" + }, + { + "name": "FrameWriteRequest.String" + }, + { + "name": "Framer.ReadFrame" + }, + { + "name": "Framer.ReadFrameForHeader" + }, + { + "name": "Framer.ReadFrameHeader" + }, + { + "name": "Framer.WriteContinuation" + }, + { + "name": "Framer.WriteData" + }, + { + "name": "Framer.WriteDataPadded" + }, + { + "name": "Framer.WriteGoAway" + }, + { + "name": "Framer.WriteHeaders" + }, + { + "name": "Framer.WritePing" + }, + { + "name": "Framer.WritePriority" + }, + { + "name": "Framer.WritePriorityUpdate" + }, + { + "name": "Framer.WritePushPromise" + }, + { + "name": "Framer.WriteRSTStream" + }, + { + "name": "Framer.WriteRawFrame" + }, + { + "name": "Framer.WriteSettings" + }, + { + "name": "Framer.WriteSettingsAck" + }, + { + "name": "Framer.WriteWindowUpdate" + }, + { + "name": "GoAwayError.Error" + }, + { + "name": "ReadFrameHeader" + }, + { + "name": "Server.ServeConn" + }, + { + "name": "Setting.String" + }, + { + "name": "SettingID.String" + }, + { + "name": "SettingsFrame.ForeachSetting" + }, + { + "name": "StreamError.Error" + }, + { + "name": "Transport.CloseIdleConnections" + }, + { + "name": "Transport.NewClientConn" + }, + { + "name": "Transport.RoundTrip" + }, + { + "name": "Transport.RoundTripOpt" + }, + { + "name": "bufferedWriter.Flush" + }, + { + "name": "bufferedWriter.Write" + }, + { + "name": "bufferedWriterTimeoutWriter.Write" + }, + { + "name": "chunkWriter.Write" + }, + { + "name": "clientConnPool.GetClientConn" + }, + { + "name": "connError.Error" + }, + { + "name": "dataBuffer.Read" + }, + { + "name": "duplicatePseudoHeaderError.Error" + }, + { + "name": "gzipReader.Close" + }, + { + "name": "gzipReader.Read" + }, + { + "name": "headerFieldNameError.Error" + }, + { + "name": "headerFieldValueError.Error" + }, + { + "name": "netHTTPClientConn.Close" + }, + { + "name": "netHTTPClientConn.RoundTrip" + }, + { + "name": "noDialClientConnPool.GetClientConn" + }, + { + "name": "noDialH2RoundTripper.NewClientConn" + }, + { + "name": "noDialH2RoundTripper.RoundTrip" + }, + { + "name": "pipe.Read" + }, + { + "name": "priorityWriteSchedulerRFC7540.CloseStream" + }, + { + "name": "priorityWriteSchedulerRFC7540.OpenStream" + }, + { + "name": "priorityWriteSchedulerRFC9218.OpenStream" + }, + { + "name": "pseudoHeaderError.Error" + }, + { + "name": "requestBody.Close" + }, + { + "name": "requestBody.Read" + }, + { + "name": "responseWriter.Flush" + }, + { + "name": "responseWriter.FlushError" + }, + { + "name": "responseWriter.Push" + }, + { + "name": "responseWriter.SetReadDeadline" + }, + { + "name": "responseWriter.SetWriteDeadline" + }, + { + "name": "responseWriter.Write" + }, + { + "name": "responseWriter.WriteHeader" + }, + { + "name": "responseWriter.WriteString" + }, + { + "name": "roundRobinWriteScheduler.OpenStream" + }, + { + "name": "serverConn.CloseConn" + }, + { + "name": "serverConn.Flush" + }, + { + "name": "stickyErrWriter.Write" + }, + { + "name": "transportResponseBody.Close" + }, + { + "name": "transportResponseBody.Read" + }, + { + "name": "unencryptedTransport.RoundTrip" + }, + { + "name": "writeData.String" + } + ], + "defaultStatus": "unaffected" + } + ], + "problemTypes": [ + { + "descriptions": [ + { + "lang": "en", + "description": "CWE-405: Asymmetric Resource Consumption (Amplification)" + } + ] + } + ], + "references": [ + { + "url": "https://go.dev/cl/847185" + }, + { + "url": "https://go.dev/cl/847314" + }, + { + "url": "https://go.dev/issue/81857" + }, + { + "url": "https://groups.google.com/g/golang-announce/c/U2fTuyDJznI" + }, + { + "url": "https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs" + }, + { + "url": "https://pkg.go.dev/vuln/GO-2026-6603" + } + ], + "credits": [ + { + "lang": "en", + "value": "RyotaK (https://ryotak.net) of GMO Flatt Security Inc." + } + ] + } + } +} \ No newline at end of file
diff --git a/data/cve/v5/GO-2026-6604.json b/data/cve/v5/GO-2026-6604.json new file mode 100644 index 0000000..a0cadc3 --- /dev/null +++ b/data/cve/v5/GO-2026-6604.json
@@ -0,0 +1,147 @@ +{ + "dataType": "CVE_RECORD", + "dataVersion": "5.0", + "cveMetadata": { + "cveId": "CVE-2026-56857" + }, + "containers": { + "cna": { + "providerMetadata": { + "orgId": "1bb62c36-49e3-4200-9d77-64a1400537cc" + }, + "title": "Root.Mkdir(All) can follow junctions out of the root on Windows in os", + "descriptions": [ + { + "lang": "en", + "value": "On Windows, when the target of Root.Mkdir or Root.MkdirAll is a junction pointing to an empty location, the operation can create a directory at the junction target even when that target is located outside the root. This only applies to operations where the last path component is a junction (path/to/junction, but not path/junction/target)." + } + ], + "affected": [ + { + "vendor": "Go standard library", + "product": "os", + "collectionURL": "https://pkg.go.dev", + "packageName": "os", + "versions": [ + { + "version": "0", + "lessThan": "1.26.9", + "status": "affected", + "versionType": "semver" + }, + { + "version": "1.27.0-0", + "lessThan": "1.27.2", + "status": "affected", + "versionType": "semver" + } + ], + "platforms": [ + "windows" + ], + "programRoutines": [ + { + "name": "Root.Mkdir" + }, + { + "name": "doInRoot" + }, + { + "name": "rootMkdirAll" + }, + { + "name": "Root.Chmod" + }, + { + "name": "Root.Chown" + }, + { + "name": "Root.Chtimes" + }, + { + "name": "Root.Lchown" + }, + { + "name": "Root.Link" + }, + { + "name": "Root.MkdirAll" + }, + { + "name": "Root.Remove" + }, + { + "name": "Root.RemoveAll" + }, + { + "name": "Root.Rename" + }, + { + "name": "Root.Symlink" + } + ], + "defaultStatus": "unaffected" + }, + { + "vendor": "Go standard library", + "product": "internal/syscall/windows", + "collectionURL": "https://pkg.go.dev", + "packageName": "internal/syscall/windows", + "versions": [ + { + "version": "0", + "lessThan": "1.26.9", + "status": "affected", + "versionType": "semver" + }, + { + "version": "1.27.0-0", + "lessThan": "1.27.2", + "status": "affected", + "versionType": "semver" + } + ], + "platforms": [ + "windows" + ], + "programRoutines": [ + { + "name": "Mkdirat" + } + ], + "defaultStatus": "unaffected" + } + ], + "problemTypes": [ + { + "descriptions": [ + { + "lang": "en", + "description": "CWE-1386: Insecure Operation on Windows Junction / Mount Point" + } + ] + } + ], + "references": [ + { + "url": "https://go.dev/cl/847305" + }, + { + "url": "https://go.dev/issue/81739" + }, + { + "url": "https://groups.google.com/g/golang-announce/c/U2fTuyDJznI" + }, + { + "url": "https://pkg.go.dev/vuln/GO-2026-6604" + } + ], + "credits": [ + { + "lang": "en", + "value": "Daniele Ballarini" + } + ] + } + } +} \ No newline at end of file
diff --git a/data/cve/v5/GO-2026-6605.json b/data/cve/v5/GO-2026-6605.json new file mode 100644 index 0000000..9daa8d5 --- /dev/null +++ b/data/cve/v5/GO-2026-6605.json
@@ -0,0 +1,159 @@ +{ + "dataType": "CVE_RECORD", + "dataVersion": "5.0", + "cveMetadata": { + "cveId": "CVE-2026-56866" + }, + "containers": { + "cna": { + "providerMetadata": { + "orgId": "1bb62c36-49e3-4200-9d77-64a1400537cc" + }, + "title": "HTTP/1 client connection desynchronization after CONNECT rejection in net/http", + "descriptions": [ + { + "lang": "en", + "value": "When http.Transport sends an HTTP/1 CONNECT request with a non-empty Request.Body, it writes the body directly to the connection without framing after the request headers. If the server rejects the CONNECT request with a non-2xx keep-alive response, Transport returns the connection to the idle pool. Because CONNECT requests do not have a request body, the server may interpret the trailing body bytes as a subsequent pipelined HTTP/1.1 request on the connection, leaving the pooled connection desynchronized and causing the next caller that reuses it to read the response to the injected request. In reverse proxies (including httputil.ReverseProxy) that forward CONNECT requests through a shared Transport, this can lead to cross-user response poisoning." + } + ], + "affected": [ + { + "vendor": "Go standard library", + "product": "net/http", + "collectionURL": "https://pkg.go.dev", + "packageName": "net/http", + "versions": [ + { + "version": "0", + "lessThan": "1.26.9", + "status": "affected", + "versionType": "semver" + }, + { + "version": "1.27.0-0", + "lessThan": "1.27.2", + "status": "affected", + "versionType": "semver" + } + ], + "programRoutines": [ + { + "name": "persistConn.readLoop" + }, + { + "name": "Client.CloseIdleConnections" + }, + { + "name": "Client.Do" + }, + { + "name": "Client.Get" + }, + { + "name": "Client.Head" + }, + { + "name": "Client.Post" + }, + { + "name": "Client.PostForm" + }, + { + "name": "ClientConn.Close" + }, + { + "name": "ClientConn.RoundTrip" + }, + { + "name": "Get" + }, + { + "name": "Head" + }, + { + "name": "Post" + }, + { + "name": "PostForm" + }, + { + "name": "Transport.CloseIdleConnections" + }, + { + "name": "Transport.NewClientConn" + }, + { + "name": "Transport.RoundTrip" + }, + { + "name": "http1ClientConn.Close" + }, + { + "name": "http1ClientConn.RoundTrip" + } + ], + "defaultStatus": "unaffected" + }, + { + "vendor": "Go standard library", + "product": "net/http/httputil", + "collectionURL": "https://pkg.go.dev", + "packageName": "net/http/httputil", + "versions": [ + { + "version": "0", + "lessThan": "1.26.9", + "status": "affected", + "versionType": "semver" + }, + { + "version": "1.27.0-0", + "lessThan": "1.27.2", + "status": "affected", + "versionType": "semver" + } + ], + "programRoutines": [ + { + "name": "ReverseProxy.ServeHTTP" + }, + { + "name": "DumpRequestOut" + } + ], + "defaultStatus": "unaffected" + } + ], + "problemTypes": [ + { + "descriptions": [ + { + "lang": "en", + "description": "CWE-444: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')" + } + ] + } + ], + "references": [ + { + "url": "https://go.dev/cl/847306" + }, + { + "url": "https://go.dev/issue/81740" + }, + { + "url": "https://groups.google.com/g/golang-announce/c/U2fTuyDJznI" + }, + { + "url": "https://pkg.go.dev/vuln/GO-2026-6605" + } + ], + "credits": [ + { + "lang": "en", + "value": "Xclow3n (Rajat Raghav)" + } + ] + } + } +} \ No newline at end of file
diff --git a/data/cve/v5/GO-2026-6607.json b/data/cve/v5/GO-2026-6607.json new file mode 100644 index 0000000..efb01da --- /dev/null +++ b/data/cve/v5/GO-2026-6607.json
@@ -0,0 +1,100 @@ +{ + "dataType": "CVE_RECORD", + "dataVersion": "5.0", + "cveMetadata": { + "cveId": "CVE-2026-97031" + }, + "containers": { + "cna": { + "providerMetadata": { + "orgId": "1bb62c36-49e3-4200-9d77-64a1400537cc" + }, + "title": "Reject malformed ECH outer extension references in crypto/tls", + "descriptions": [ + { + "lang": "en", + "value": "Multiple ECH outer extension references are not permitted under RFC 9849; previously, a client could send a well-crafted packet that could trigger memory exhaustion in the server process by specifying multiple references. We now reject these as malformed and curb the memory amplification vector as a result." + } + ], + "affected": [ + { + "vendor": "Go standard library", + "product": "crypto/tls", + "collectionURL": "https://pkg.go.dev", + "packageName": "crypto/tls", + "versions": [ + { + "version": "0", + "lessThan": "1.26.9", + "status": "affected", + "versionType": "semver" + }, + { + "version": "1.27.0-0", + "lessThan": "1.27.2", + "status": "affected", + "versionType": "semver" + } + ], + "programRoutines": [ + { + "name": "decodeInnerClientHello" + }, + { + "name": "Conn.Handshake" + }, + { + "name": "Conn.HandshakeContext" + }, + { + "name": "Conn.Read" + }, + { + "name": "Conn.Write" + }, + { + "name": "Dial" + }, + { + "name": "DialWithDialer" + }, + { + "name": "Dialer.Dial" + }, + { + "name": "Dialer.DialContext" + }, + { + "name": "QUICConn.Start" + } + ], + "defaultStatus": "unaffected" + } + ], + "problemTypes": [ + { + "descriptions": [ + { + "lang": "en", + "description": "CWE-405: Asymmetric Resource Consumption" + } + ] + } + ], + "references": [ + { + "url": "https://go.dev/cl/847312" + }, + { + "url": "https://go.dev/issue/81855" + }, + { + "url": "https://groups.google.com/g/golang-announce/c/U2fTuyDJznI" + }, + { + "url": "https://pkg.go.dev/vuln/GO-2026-6607" + } + ] + } + } +} \ No newline at end of file
diff --git a/data/cve/v5/GO-2026-6608.json b/data/cve/v5/GO-2026-6608.json new file mode 100644 index 0000000..d959f88 --- /dev/null +++ b/data/cve/v5/GO-2026-6608.json
@@ -0,0 +1,129 @@ +{ + "dataType": "CVE_RECORD", + "dataVersion": "5.0", + "cveMetadata": { + "cveId": "CVE-2026-94440" + }, + "containers": { + "cna": { + "providerMetadata": { + "orgId": "1bb62c36-49e3-4200-9d77-64a1400537cc" + }, + "title": "Memory limit bypass when parsing MIME headers in net/textproto, mime/multipart", + "descriptions": [ + { + "lang": "en", + "value": "Parsing a multipart form can bypass memory limits and read an arbitrarily long line into memory when the remaining limit at the start of a part is less than 400 bytes." + } + ], + "affected": [ + { + "vendor": "Go standard library", + "product": "net/textproto", + "collectionURL": "https://pkg.go.dev", + "packageName": "net/textproto", + "versions": [ + { + "version": "0", + "lessThan": "1.26.9", + "status": "affected", + "versionType": "semver" + }, + { + "version": "1.27.0-0", + "lessThan": "1.27.2", + "status": "affected", + "versionType": "semver" + } + ], + "programRoutines": [ + { + "name": "readMIMEHeader" + }, + { + "name": "Reader.readContinuedLineSlice" + }, + { + "name": "Reader.ReadContinuedLine" + }, + { + "name": "Reader.ReadContinuedLineBytes" + }, + { + "name": "Reader.ReadMIMEHeader" + } + ], + "defaultStatus": "unaffected" + }, + { + "vendor": "Go standard library", + "product": "mime/multipart", + "collectionURL": "https://pkg.go.dev", + "packageName": "mime/multipart", + "versions": [ + { + "version": "0", + "lessThan": "1.26.9", + "status": "affected", + "versionType": "semver" + }, + { + "version": "1.27.0-0", + "lessThan": "1.27.2", + "status": "affected", + "versionType": "semver" + } + ], + "programRoutines": [ + { + "name": "Part.populateHeaders" + }, + { + "name": "Reader.readForm" + }, + { + "name": "Reader.NextPart" + }, + { + "name": "Reader.NextRawPart" + }, + { + "name": "Reader.ReadForm" + } + ], + "defaultStatus": "unaffected" + } + ], + "problemTypes": [ + { + "descriptions": [ + { + "lang": "en", + "description": "CWE-770: Allocation of Resources Without Limits or Throttling" + } + ] + } + ], + "references": [ + { + "url": "https://go.dev/cl/847307" + }, + { + "url": "https://go.dev/issue/81741" + }, + { + "url": "https://groups.google.com/g/golang-announce/c/U2fTuyDJznI" + }, + { + "url": "https://pkg.go.dev/vuln/GO-2026-6608" + } + ], + "credits": [ + { + "lang": "en", + "value": "Jakub Ciolek (https://ciolek.dev)" + } + ] + } + } +} \ No newline at end of file
diff --git a/data/cve/v5/GO-2026-6609.json b/data/cve/v5/GO-2026-6609.json new file mode 100644 index 0000000..0d495cf --- /dev/null +++ b/data/cve/v5/GO-2026-6609.json
@@ -0,0 +1,94 @@ +{ + "dataType": "CVE_RECORD", + "dataVersion": "5.0", + "cveMetadata": { + "cveId": "CVE-2026-78667" + }, + "containers": { + "cna": { + "providerMetadata": { + "orgId": "1bb62c36-49e3-4200-9d77-64a1400537cc" + }, + "title": "Lack of limit on size of parsed Range headers in net/http", + "descriptions": [ + { + "lang": "en", + "value": "When parsing a Range header containing a large number of small ranges, FileServer(FS), ServeContent, and ServeFile(FS) can consume an excessive amount of CPU." + } + ], + "affected": [ + { + "vendor": "Go standard library", + "product": "net/http", + "collectionURL": "https://pkg.go.dev", + "packageName": "net/http", + "versions": [ + { + "version": "0", + "lessThan": "1.26.9", + "status": "affected", + "versionType": "semver" + }, + { + "version": "1.27.0-0", + "lessThan": "1.27.2", + "status": "affected", + "versionType": "semver" + } + ], + "programRoutines": [ + { + "name": "parseRange" + }, + { + "name": "ServeContent" + }, + { + "name": "ServeFile" + }, + { + "name": "ServeFileFS" + }, + { + "name": "fileHandler.ServeHTTP" + }, + { + "name": "fileTransport.RoundTrip" + } + ], + "defaultStatus": "unaffected" + } + ], + "problemTypes": [ + { + "descriptions": [ + { + "lang": "en", + "description": "CWE-770: Allocation of Resources Without Limits or Throttling" + } + ] + } + ], + "references": [ + { + "url": "https://go.dev/cl/847309" + }, + { + "url": "https://go.dev/issue/81858" + }, + { + "url": "https://groups.google.com/g/golang-announce/c/U2fTuyDJznI" + }, + { + "url": "https://pkg.go.dev/vuln/GO-2026-6609" + } + ], + "credits": [ + { + "lang": "en", + "value": "Jakub Ciolek (https://ciolek.dev)" + } + ] + } + } +} \ No newline at end of file
diff --git a/data/cve/v5/GO-2026-6610.json b/data/cve/v5/GO-2026-6610.json new file mode 100644 index 0000000..b3cc837 --- /dev/null +++ b/data/cve/v5/GO-2026-6610.json
@@ -0,0 +1,233 @@ +{ + "dataType": "CVE_RECORD", + "dataVersion": "5.0", + "cveMetadata": { + "cveId": "CVE-2026-78660" + }, + "containers": { + "cna": { + "providerMetadata": { + "orgId": "1bb62c36-49e3-4200-9d77-64a1400537cc" + }, + "title": "HTTP/2 transport accepts malformed framing-related headers in net/http", + "descriptions": [ + { + "lang": "en", + "value": "Historically, we have been rather lax about malformed framing-related headers in our HTTP/2 implementation, as they cannot interfere with HTTP/2 framing. However, this makes it possible for our HTTP/2 implementation to forward responses containing such headers to an HTTP/1 client when acting as a reverse proxy. If the HTTP/1 client also does not behave strictly enough, this can result in response smuggling." + } + ], + "affected": [ + { + "vendor": "Go standard library", + "product": "net/http", + "collectionURL": "https://pkg.go.dev", + "packageName": "net/http", + "versions": [ + { + "version": "0", + "lessThan": "1.26.9", + "status": "affected", + "versionType": "semver" + } + ], + "programRoutines": [ + { + "name": "http2clientConnReadLoop.handleResponse" + }, + { + "name": "Client.CloseIdleConnections" + }, + { + "name": "Client.Do" + }, + { + "name": "Client.Get" + }, + { + "name": "Client.Head" + }, + { + "name": "Client.Post" + }, + { + "name": "Client.PostForm" + }, + { + "name": "ClientConn.Close" + }, + { + "name": "ClientConn.RoundTrip" + }, + { + "name": "Get" + }, + { + "name": "Head" + }, + { + "name": "Post" + }, + { + "name": "PostForm" + }, + { + "name": "Transport.CloseIdleConnections" + }, + { + "name": "Transport.NewClientConn" + }, + { + "name": "Transport.RoundTrip" + }, + { + "name": "http1ClientConn.Close" + }, + { + "name": "http1ClientConn.RoundTrip" + }, + { + "name": "http2Transport.NewClientConn" + }, + { + "name": "http2Transport.RoundTrip" + }, + { + "name": "http2Transport.RoundTripOpt" + }, + { + "name": "http2clientConnPool.GetClientConn" + }, + { + "name": "http2noDialClientConnPool.GetClientConn" + }, + { + "name": "http2noDialH2RoundTripper.NewClientConn" + }, + { + "name": "http2noDialH2RoundTripper.RoundTrip" + }, + { + "name": "http2unencryptedTransport.RoundTrip" + } + ], + "defaultStatus": "unaffected" + }, + { + "vendor": "Go standard library", + "product": "net/http/internal/http2", + "collectionURL": "https://pkg.go.dev", + "packageName": "net/http/internal/http2", + "versions": [ + { + "version": "1.27.0-0", + "lessThan": "1.27.2", + "status": "affected", + "versionType": "semver" + } + ], + "programRoutines": [ + { + "name": "clientConnReadLoop.handleResponse" + }, + { + "name": "Transport.AddConn" + }, + { + "name": "Transport.NewClientConn" + }, + { + "name": "Transport.RoundTrip" + }, + { + "name": "Transport.RoundTripOpt" + }, + { + "name": "clientConnPool.GetClientConn" + }, + { + "name": "noDialClientConnPool.GetClientConn" + } + ], + "defaultStatus": "unaffected" + }, + { + "vendor": "golang.org/x/net", + "product": "golang.org/x/net/http2", + "collectionURL": "https://pkg.go.dev", + "packageName": "golang.org/x/net/http2", + "versions": [ + { + "version": "0", + "lessThan": "0.60.0", + "status": "affected", + "versionType": "semver" + } + ], + "programRoutines": [ + { + "name": "clientConnReadLoop.handleResponse" + }, + { + "name": "Transport.NewClientConn" + }, + { + "name": "Transport.RoundTrip" + }, + { + "name": "Transport.RoundTripOpt" + }, + { + "name": "clientConnPool.GetClientConn" + }, + { + "name": "noDialClientConnPool.GetClientConn" + }, + { + "name": "noDialH2RoundTripper.NewClientConn" + }, + { + "name": "noDialH2RoundTripper.RoundTrip" + }, + { + "name": "unencryptedTransport.RoundTrip" + } + ], + "defaultStatus": "unaffected" + } + ], + "problemTypes": [ + { + "descriptions": [ + { + "lang": "en", + "description": "CWE-444: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')" + } + ] + } + ], + "references": [ + { + "url": "https://go.dev/cl/835145" + }, + { + "url": "https://go.dev/cl/836385" + }, + { + "url": "https://go.dev/issue/81115" + }, + { + "url": "https://groups.google.com/g/golang-announce/c/U2fTuyDJznI" + }, + { + "url": "https://pkg.go.dev/vuln/GO-2026-6610" + } + ], + "credits": [ + { + "lang": "en", + "value": "TJ Barton" + } + ] + } + } +} \ No newline at end of file
diff --git a/data/cve/v5/GO-2026-6611.json b/data/cve/v5/GO-2026-6611.json new file mode 100644 index 0000000..f4232ab --- /dev/null +++ b/data/cve/v5/GO-2026-6611.json
@@ -0,0 +1,1343 @@ +{ + "dataType": "CVE_RECORD", + "dataVersion": "5.0", + "cveMetadata": { + "cveId": "CVE-2026-78669" + }, + "containers": { + "cna": { + "providerMetadata": { + "orgId": "1bb62c36-49e3-4200-9d77-64a1400537cc" + }, + "title": "Excessive CPU consumption from repeated initial window changes in net/http", + "descriptions": [ + { + "lang": "en", + "value": "A malicious HTTP/2 peer can cause excessive CPU consumption in the client or server by opening a large number of streams and then sending many small SETTINGS frames containing SETTINGS_INITIAL_WINDOW_SIZE values." + } + ], + "affected": [ + { + "vendor": "Go standard library", + "product": "net/http", + "collectionURL": "https://pkg.go.dev", + "packageName": "net/http", + "versions": [ + { + "version": "0", + "lessThan": "1.26.9", + "status": "affected", + "versionType": "semver" + } + ], + "programRoutines": [ + { + "name": "http2outflow.add" + }, + { + "name": "http2outflow.available" + }, + { + "name": "http2outflow.setConnFlow" + }, + { + "name": "http2outflow.take" + }, + { + "name": "http2Server.serveConn" + }, + { + "name": "http2serverConn.newStream" + }, + { + "name": "http2serverConn.processSettingInitialWindowSize" + }, + { + "name": "http2serverConn.processWindowUpdate" + }, + { + "name": "http2serverConn.scheduleFrameWrite" + }, + { + "name": "http2ClientConn.addStreamLocked" + }, + { + "name": "http2Transport.newClientConn" + }, + { + "name": "http2clientConnReadLoop.processSettingsNoWrite" + }, + { + "name": "http2clientConnReadLoop.processWindowUpdate" + }, + { + "name": "http2clientConnReadLoop.streamByID" + }, + { + "name": "http2clientStream.awaitFlowControl" + }, + { + "name": "http2clientStream.cleanupWriteRequest" + }, + { + "name": "http2FrameWriteRequest.Consume" + }, + { + "name": "CanonicalHeaderKey" + }, + { + "name": "Client.CloseIdleConnections" + }, + { + "name": "Client.Do" + }, + { + "name": "Client.Get" + }, + { + "name": "Client.Head" + }, + { + "name": "Client.Post" + }, + { + "name": "Client.PostForm" + }, + { + "name": "ClientConn.Close" + }, + { + "name": "ClientConn.RoundTrip" + }, + { + "name": "Cookie.String" + }, + { + "name": "Cookie.Valid" + }, + { + "name": "CrossOriginProtection.AddInsecureBypassPattern" + }, + { + "name": "CrossOriginProtection.AddTrustedOrigin" + }, + { + "name": "CrossOriginProtection.Check" + }, + { + "name": "Dir.Open" + }, + { + "name": "Error" + }, + { + "name": "Get" + }, + { + "name": "Handle" + }, + { + "name": "HandleFunc" + }, + { + "name": "HandlerFunc.ServeHTTP" + }, + { + "name": "Head" + }, + { + "name": "Header.Add" + }, + { + "name": "Header.Del" + }, + { + "name": "Header.Get" + }, + { + "name": "Header.Set" + }, + { + "name": "Header.Values" + }, + { + "name": "Header.Write" + }, + { + "name": "Header.WriteSubset" + }, + { + "name": "ListenAndServe" + }, + { + "name": "ListenAndServeTLS" + }, + { + "name": "NewRequest" + }, + { + "name": "NewRequestWithContext" + }, + { + "name": "NotFound" + }, + { + "name": "ParseCookie" + }, + { + "name": "ParseSetCookie" + }, + { + "name": "ParseTime" + }, + { + "name": "Post" + }, + { + "name": "PostForm" + }, + { + "name": "ProxyFromEnvironment" + }, + { + "name": "ReadRequest" + }, + { + "name": "ReadResponse" + }, + { + "name": "Redirect" + }, + { + "name": "Request.AddCookie" + }, + { + "name": "Request.BasicAuth" + }, + { + "name": "Request.Cookie" + }, + { + "name": "Request.Cookies" + }, + { + "name": "Request.CookiesNamed" + }, + { + "name": "Request.FormFile" + }, + { + "name": "Request.FormValue" + }, + { + "name": "Request.MultipartReader" + }, + { + "name": "Request.ParseForm" + }, + { + "name": "Request.ParseMultipartForm" + }, + { + "name": "Request.PostFormValue" + }, + { + "name": "Request.Referer" + }, + { + "name": "Request.SetBasicAuth" + }, + { + "name": "Request.UserAgent" + }, + { + "name": "Request.Write" + }, + { + "name": "Request.WriteProxy" + }, + { + "name": "Response.Cookies" + }, + { + "name": "Response.Location" + }, + { + "name": "Response.Write" + }, + { + "name": "ResponseController.EnableFullDuplex" + }, + { + "name": "ResponseController.Flush" + }, + { + "name": "ResponseController.Hijack" + }, + { + "name": "ResponseController.SetReadDeadline" + }, + { + "name": "ResponseController.SetWriteDeadline" + }, + { + "name": "Serve" + }, + { + "name": "ServeContent" + }, + { + "name": "ServeFile" + }, + { + "name": "ServeFileFS" + }, + { + "name": "ServeMux.Handle" + }, + { + "name": "ServeMux.HandleFunc" + }, + { + "name": "ServeMux.ServeHTTP" + }, + { + "name": "ServeTLS" + }, + { + "name": "Server.Close" + }, + { + "name": "Server.ListenAndServe" + }, + { + "name": "Server.ListenAndServeTLS" + }, + { + "name": "Server.Serve" + }, + { + "name": "Server.ServeTLS" + }, + { + "name": "Server.SetKeepAlivesEnabled" + }, + { + "name": "Server.Shutdown" + }, + { + "name": "SetCookie" + }, + { + "name": "Transport.CancelRequest" + }, + { + "name": "Transport.Clone" + }, + { + "name": "Transport.CloseIdleConnections" + }, + { + "name": "Transport.NewClientConn" + }, + { + "name": "Transport.RoundTrip" + }, + { + "name": "body.Close" + }, + { + "name": "body.Read" + }, + { + "name": "bodyEOFSignal.Close" + }, + { + "name": "bodyEOFSignal.Read" + }, + { + "name": "bodyLocked.Read" + }, + { + "name": "bufioFlushWriter.Write" + }, + { + "name": "cancelTimerBody.Close" + }, + { + "name": "cancelTimerBody.Read" + }, + { + "name": "checkConnErrorWriter.Write" + }, + { + "name": "chunkWriter.Write" + }, + { + "name": "connReader.Read" + }, + { + "name": "connectMethodKey.String" + }, + { + "name": "expectContinueReader.Close" + }, + { + "name": "expectContinueReader.Read" + }, + { + "name": "extraHeader.Write" + }, + { + "name": "fileHandler.ServeHTTP" + }, + { + "name": "fileTransport.RoundTrip" + }, + { + "name": "globalOptionsHandler.ServeHTTP" + }, + { + "name": "gzipReader.Close" + }, + { + "name": "gzipReader.Read" + }, + { + "name": "http1ClientConn.Close" + }, + { + "name": "http1ClientConn.RoundTrip" + }, + { + "name": "http2ClientConn.Close" + }, + { + "name": "http2ClientConn.Ping" + }, + { + "name": "http2ClientConn.RoundTrip" + }, + { + "name": "http2ClientConn.Shutdown" + }, + { + "name": "http2ConnectionError.Error" + }, + { + "name": "http2ErrCode.String" + }, + { + "name": "http2FrameHeader.String" + }, + { + "name": "http2FrameType.String" + }, + { + "name": "http2FrameWriteRequest.String" + }, + { + "name": "http2Framer.ReadFrame" + }, + { + "name": "http2Framer.ReadFrameForHeader" + }, + { + "name": "http2Framer.ReadFrameHeader" + }, + { + "name": "http2Framer.WriteContinuation" + }, + { + "name": "http2Framer.WriteData" + }, + { + "name": "http2Framer.WriteDataPadded" + }, + { + "name": "http2Framer.WriteGoAway" + }, + { + "name": "http2Framer.WriteHeaders" + }, + { + "name": "http2Framer.WritePing" + }, + { + "name": "http2Framer.WritePriority" + }, + { + "name": "http2Framer.WritePushPromise" + }, + { + "name": "http2Framer.WriteRSTStream" + }, + { + "name": "http2Framer.WriteRawFrame" + }, + { + "name": "http2Framer.WriteSettings" + }, + { + "name": "http2Framer.WriteSettingsAck" + }, + { + "name": "http2Framer.WriteWindowUpdate" + }, + { + "name": "http2GoAwayError.Error" + }, + { + "name": "http2Server.ServeConn" + }, + { + "name": "http2Setting.String" + }, + { + "name": "http2SettingID.String" + }, + { + "name": "http2SettingsFrame.ForeachSetting" + }, + { + "name": "http2StreamError.Error" + }, + { + "name": "http2Transport.CloseIdleConnections" + }, + { + "name": "http2Transport.NewClientConn" + }, + { + "name": "http2Transport.RoundTrip" + }, + { + "name": "http2Transport.RoundTripOpt" + }, + { + "name": "http2bufferedWriter.Flush" + }, + { + "name": "http2bufferedWriter.Write" + }, + { + "name": "http2bufferedWriterTimeoutWriter.Write" + }, + { + "name": "http2chunkWriter.Write" + }, + { + "name": "http2clientConnPool.GetClientConn" + }, + { + "name": "http2connError.Error" + }, + { + "name": "http2dataBuffer.Read" + }, + { + "name": "http2duplicatePseudoHeaderError.Error" + }, + { + "name": "http2gzipReader.Close" + }, + { + "name": "http2gzipReader.Read" + }, + { + "name": "http2headerFieldNameError.Error" + }, + { + "name": "http2headerFieldValueError.Error" + }, + { + "name": "http2netHTTPClientConn.Close" + }, + { + "name": "http2netHTTPClientConn.RoundTrip" + }, + { + "name": "http2noDialClientConnPool.GetClientConn" + }, + { + "name": "http2noDialH2RoundTripper.NewClientConn" + }, + { + "name": "http2noDialH2RoundTripper.RoundTrip" + }, + { + "name": "http2pipe.Read" + }, + { + "name": "http2priorityWriteSchedulerRFC7540.CloseStream" + }, + { + "name": "http2priorityWriteSchedulerRFC7540.OpenStream" + }, + { + "name": "http2priorityWriteSchedulerRFC7540.Pop" + }, + { + "name": "http2priorityWriteSchedulerRFC9218.OpenStream" + }, + { + "name": "http2priorityWriteSchedulerRFC9218.Pop" + }, + { + "name": "http2pseudoHeaderError.Error" + }, + { + "name": "http2randomWriteScheduler.Pop" + }, + { + "name": "http2requestBody.Close" + }, + { + "name": "http2requestBody.Read" + }, + { + "name": "http2responseWriter.Flush" + }, + { + "name": "http2responseWriter.FlushError" + }, + { + "name": "http2responseWriter.Push" + }, + { + "name": "http2responseWriter.SetReadDeadline" + }, + { + "name": "http2responseWriter.SetWriteDeadline" + }, + { + "name": "http2responseWriter.Write" + }, + { + "name": "http2responseWriter.WriteHeader" + }, + { + "name": "http2responseWriter.WriteString" + }, + { + "name": "http2roundRobinWriteScheduler.OpenStream" + }, + { + "name": "http2roundRobinWriteScheduler.Pop" + }, + { + "name": "http2serverConn.CloseConn" + }, + { + "name": "http2serverConn.Flush" + }, + { + "name": "http2stickyErrWriter.Write" + }, + { + "name": "http2transportResponseBody.Close" + }, + { + "name": "http2transportResponseBody.Read" + }, + { + "name": "http2unencryptedTransport.RoundTrip" + }, + { + "name": "http2writeData.String" + }, + { + "name": "initALPNRequest.ServeHTTP" + }, + { + "name": "loggingConn.Close" + }, + { + "name": "loggingConn.Read" + }, + { + "name": "loggingConn.Write" + }, + { + "name": "maxBytesReader.Close" + }, + { + "name": "maxBytesReader.Read" + }, + { + "name": "onceCloseListener.Close" + }, + { + "name": "persistConn.Read" + }, + { + "name": "persistConnWriter.ReadFrom" + }, + { + "name": "persistConnWriter.Write" + }, + { + "name": "populateResponse.Write" + }, + { + "name": "populateResponse.WriteHeader" + }, + { + "name": "readTrackingBody.Close" + }, + { + "name": "readTrackingBody.Read" + }, + { + "name": "readWriteCloserBody.CloseWrite" + }, + { + "name": "readWriteCloserBody.Read" + }, + { + "name": "redirectHandler.ServeHTTP" + }, + { + "name": "response.Flush" + }, + { + "name": "response.FlushError" + }, + { + "name": "response.Hijack" + }, + { + "name": "response.ReadFrom" + }, + { + "name": "response.Write" + }, + { + "name": "response.WriteHeader" + }, + { + "name": "response.WriteString" + }, + { + "name": "serverHandler.ServeHTTP" + }, + { + "name": "socksDialer.DialWithConn" + }, + { + "name": "socksUsernamePassword.Authenticate" + }, + { + "name": "stringWriter.WriteString" + }, + { + "name": "timeoutHandler.ServeHTTP" + }, + { + "name": "timeoutWriter.Write" + }, + { + "name": "timeoutWriter.WriteHeader" + }, + { + "name": "transportReadFromServerError.Error" + }, + { + "name": "unencryptedHTTP2Request.ServeHTTP" + } + ], + "defaultStatus": "unaffected" + }, + { + "vendor": "Go standard library", + "product": "net/http/internal/http2", + "collectionURL": "https://pkg.go.dev", + "packageName": "net/http/internal/http2", + "versions": [ + { + "version": "1.27.0-0", + "lessThan": "1.27.2", + "status": "affected", + "versionType": "semver" + } + ], + "programRoutines": [ + { + "name": "outflow.add" + }, + { + "name": "outflow.available" + }, + { + "name": "outflow.setConnFlow" + }, + { + "name": "outflow.take" + }, + { + "name": "Server.serveConn" + }, + { + "name": "serverConn.newStream" + }, + { + "name": "serverConn.processSettingInitialWindowSize" + }, + { + "name": "serverConn.processWindowUpdate" + }, + { + "name": "serverConn.scheduleFrameWrite" + }, + { + "name": "ClientConn.addStreamLocked" + }, + { + "name": "Transport.newClientConn" + }, + { + "name": "clientConnReadLoop.processSettingsNoWrite" + }, + { + "name": "clientConnReadLoop.processWindowUpdate" + }, + { + "name": "clientConnReadLoop.streamByID" + }, + { + "name": "clientStream.awaitFlowControl" + }, + { + "name": "clientStream.cleanupWriteRequest" + }, + { + "name": "FrameWriteRequest.Consume" + }, + { + "name": "ClientConn.Close" + }, + { + "name": "ClientConn.Ping" + }, + { + "name": "ClientConn.RoundTrip" + }, + { + "name": "ClientConn.Shutdown" + }, + { + "name": "Framer.ReadFrame" + }, + { + "name": "Framer.ReadFrameForHeader" + }, + { + "name": "Framer.ReadFrameHeader" + }, + { + "name": "Framer.WriteContinuation" + }, + { + "name": "Framer.WriteData" + }, + { + "name": "Framer.WriteDataPadded" + }, + { + "name": "Framer.WriteGoAway" + }, + { + "name": "Framer.WriteHeaders" + }, + { + "name": "Framer.WritePing" + }, + { + "name": "Framer.WritePriority" + }, + { + "name": "Framer.WritePriorityUpdate" + }, + { + "name": "Framer.WritePushPromise" + }, + { + "name": "Framer.WriteRSTStream" + }, + { + "name": "Framer.WriteRawFrame" + }, + { + "name": "Framer.WriteSettings" + }, + { + "name": "Framer.WriteSettingsAck" + }, + { + "name": "Framer.WriteWindowUpdate" + }, + { + "name": "NetHTTPClientConn.Close" + }, + { + "name": "NetHTTPClientConn.Ping" + }, + { + "name": "NetHTTPClientConn.RoundTrip" + }, + { + "name": "ReadFrameHeader" + }, + { + "name": "Server.GracefulShutdown" + }, + { + "name": "Server.ServeConn" + }, + { + "name": "SettingsFrame.ForeachSetting" + }, + { + "name": "Transport.AddConn" + }, + { + "name": "Transport.CloseIdleConnections" + }, + { + "name": "Transport.NewClientConn" + }, + { + "name": "Transport.RoundTrip" + }, + { + "name": "Transport.RoundTripOpt" + }, + { + "name": "bufferedWriter.Flush" + }, + { + "name": "bufferedWriter.Write" + }, + { + "name": "bufferedWriterTimeoutWriter.Write" + }, + { + "name": "chunkWriter.Write" + }, + { + "name": "clientConnPool.GetClientConn" + }, + { + "name": "gzipReader.Close" + }, + { + "name": "gzipReader.Read" + }, + { + "name": "noDialClientConnPool.GetClientConn" + }, + { + "name": "priorityWriteSchedulerRFC9218.Pop" + }, + { + "name": "requestBody.Close" + }, + { + "name": "responseWriter.Flush" + }, + { + "name": "responseWriter.FlushError" + }, + { + "name": "responseWriter.Push" + }, + { + "name": "responseWriter.Write" + }, + { + "name": "responseWriter.WriteHeader" + }, + { + "name": "responseWriter.WriteString" + }, + { + "name": "roundRobinWriteScheduler.Pop" + }, + { + "name": "serve400Handler.ServeHTTP" + }, + { + "name": "serverConn.Flush" + }, + { + "name": "stickyErrWriter.Write" + }, + { + "name": "transportResponseBody.Close" + }, + { + "name": "transportResponseBody.Read" + } + ], + "defaultStatus": "unaffected" + }, + { + "vendor": "golang.org/x/net", + "product": "golang.org/x/net/http2", + "collectionURL": "https://pkg.go.dev", + "packageName": "golang.org/x/net/http2", + "versions": [ + { + "version": "0", + "lessThan": "0.60.0", + "status": "affected", + "versionType": "semver" + } + ], + "programRoutines": [ + { + "name": "outflow.add" + }, + { + "name": "outflow.available" + }, + { + "name": "outflow.setConnFlow" + }, + { + "name": "outflow.take" + }, + { + "name": "Server.serveConn" + }, + { + "name": "serverConn.newStream" + }, + { + "name": "serverConn.processSettingInitialWindowSize" + }, + { + "name": "serverConn.processWindowUpdate" + }, + { + "name": "serverConn.scheduleFrameWrite" + }, + { + "name": "ClientConn.addStreamLocked" + }, + { + "name": "Transport.newClientConn" + }, + { + "name": "clientConnReadLoop.processSettingsNoWrite" + }, + { + "name": "clientConnReadLoop.processWindowUpdate" + }, + { + "name": "clientConnReadLoop.streamByID" + }, + { + "name": "clientStream.awaitFlowControl" + }, + { + "name": "clientStream.cleanupWriteRequest" + }, + { + "name": "FrameWriteRequest.Consume" + }, + { + "name": "ClientConn.Close" + }, + { + "name": "ClientConn.Ping" + }, + { + "name": "ClientConn.RoundTrip" + }, + { + "name": "ClientConn.Shutdown" + }, + { + "name": "ConfigureServer" + }, + { + "name": "ConfigureTransport" + }, + { + "name": "ConfigureTransports" + }, + { + "name": "ConnectionError.Error" + }, + { + "name": "ErrCode.String" + }, + { + "name": "FrameHeader.String" + }, + { + "name": "FrameType.String" + }, + { + "name": "FrameWriteRequest.String" + }, + { + "name": "Framer.ReadFrame" + }, + { + "name": "Framer.ReadFrameForHeader" + }, + { + "name": "Framer.ReadFrameHeader" + }, + { + "name": "Framer.WriteContinuation" + }, + { + "name": "Framer.WriteData" + }, + { + "name": "Framer.WriteDataPadded" + }, + { + "name": "Framer.WriteGoAway" + }, + { + "name": "Framer.WriteHeaders" + }, + { + "name": "Framer.WritePing" + }, + { + "name": "Framer.WritePriority" + }, + { + "name": "Framer.WritePriorityUpdate" + }, + { + "name": "Framer.WritePushPromise" + }, + { + "name": "Framer.WriteRSTStream" + }, + { + "name": "Framer.WriteRawFrame" + }, + { + "name": "Framer.WriteSettings" + }, + { + "name": "Framer.WriteSettingsAck" + }, + { + "name": "Framer.WriteWindowUpdate" + }, + { + "name": "GoAwayError.Error" + }, + { + "name": "ReadFrameHeader" + }, + { + "name": "Server.ServeConn" + }, + { + "name": "Setting.String" + }, + { + "name": "SettingID.String" + }, + { + "name": "SettingsFrame.ForeachSetting" + }, + { + "name": "StreamError.Error" + }, + { + "name": "Transport.CloseIdleConnections" + }, + { + "name": "Transport.NewClientConn" + }, + { + "name": "Transport.RoundTrip" + }, + { + "name": "Transport.RoundTripOpt" + }, + { + "name": "bufferedWriter.Flush" + }, + { + "name": "bufferedWriter.Write" + }, + { + "name": "bufferedWriterTimeoutWriter.Write" + }, + { + "name": "chunkWriter.Write" + }, + { + "name": "clientConnPool.GetClientConn" + }, + { + "name": "connError.Error" + }, + { + "name": "dataBuffer.Read" + }, + { + "name": "duplicatePseudoHeaderError.Error" + }, + { + "name": "gzipReader.Close" + }, + { + "name": "gzipReader.Read" + }, + { + "name": "headerFieldNameError.Error" + }, + { + "name": "headerFieldValueError.Error" + }, + { + "name": "netHTTPClientConn.Close" + }, + { + "name": "netHTTPClientConn.RoundTrip" + }, + { + "name": "noDialClientConnPool.GetClientConn" + }, + { + "name": "noDialH2RoundTripper.NewClientConn" + }, + { + "name": "noDialH2RoundTripper.RoundTrip" + }, + { + "name": "pipe.Read" + }, + { + "name": "priorityWriteSchedulerRFC7540.CloseStream" + }, + { + "name": "priorityWriteSchedulerRFC7540.OpenStream" + }, + { + "name": "priorityWriteSchedulerRFC7540.Pop" + }, + { + "name": "priorityWriteSchedulerRFC9218.OpenStream" + }, + { + "name": "priorityWriteSchedulerRFC9218.Pop" + }, + { + "name": "pseudoHeaderError.Error" + }, + { + "name": "randomWriteScheduler.Pop" + }, + { + "name": "requestBody.Close" + }, + { + "name": "requestBody.Read" + }, + { + "name": "responseWriter.Flush" + }, + { + "name": "responseWriter.FlushError" + }, + { + "name": "responseWriter.Push" + }, + { + "name": "responseWriter.SetReadDeadline" + }, + { + "name": "responseWriter.SetWriteDeadline" + }, + { + "name": "responseWriter.Write" + }, + { + "name": "responseWriter.WriteHeader" + }, + { + "name": "responseWriter.WriteString" + }, + { + "name": "roundRobinWriteScheduler.OpenStream" + }, + { + "name": "roundRobinWriteScheduler.Pop" + }, + { + "name": "serverConn.CloseConn" + }, + { + "name": "serverConn.Flush" + }, + { + "name": "stickyErrWriter.Write" + }, + { + "name": "transportResponseBody.Close" + }, + { + "name": "transportResponseBody.Read" + }, + { + "name": "unencryptedTransport.RoundTrip" + }, + { + "name": "writeData.String" + } + ], + "defaultStatus": "unaffected" + } + ], + "problemTypes": [ + { + "descriptions": [ + { + "lang": "en", + "description": "CWE-405: Asymmetric Resource Consumption (Amplification)" + } + ] + } + ], + "references": [ + { + "url": "https://go.dev/cl/847186" + }, + { + "url": "https://go.dev/cl/847308" + }, + { + "url": "https://go.dev/issue/81742" + }, + { + "url": "https://groups.google.com/g/golang-announce/c/U2fTuyDJznI" + }, + { + "url": "https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs" + }, + { + "url": "https://pkg.go.dev/vuln/GO-2026-6611" + } + ], + "credits": [ + { + "lang": "en", + "value": "Jakub Ciolek (https://ciolek.dev)" + } + ] + } + } +} \ No newline at end of file
diff --git a/data/cve/v5/GO-2026-6612.json b/data/cve/v5/GO-2026-6612.json new file mode 100644 index 0000000..deea3b4 --- /dev/null +++ b/data/cve/v5/GO-2026-6612.json
@@ -0,0 +1,1082 @@ +{ + "dataType": "CVE_RECORD", + "dataVersion": "5.0", + "cveMetadata": { + "cveId": "CVE-2026-78663" + }, + "containers": { + "cna": { + "providerMetadata": { + "orgId": "1bb62c36-49e3-4200-9d77-64a1400537cc" + }, + "title": "Double flow control refund on HTTP/2 server streams in net/http", + "descriptions": [ + { + "lang": "en", + "value": "The HTTP/2 server can refund connection-level flow control twice for the same data: Once when a client resets a stream (refunding data for any sent-but-unread portion of the stream), and again when a request handler reads the buffered data. A malicious client can exploit this to bypass the configured connection-level flow control limit (MaxReceiveBufferPerConnection). Total buffered data is still limited by the concurrent stream limit and stream-level flow control." + } + ], + "affected": [ + { + "vendor": "Go standard library", + "product": "net/http", + "collectionURL": "https://pkg.go.dev", + "packageName": "net/http", + "versions": [ + { + "version": "0", + "lessThan": "1.26.9", + "status": "affected", + "versionType": "semver" + } + ], + "programRoutines": [ + { + "name": "http2requestBody.Close" + }, + { + "name": "http2requestBody.Read" + }, + { + "name": "http2serverConn.closeStream" + }, + { + "name": "http2serverConn.handlerDone" + }, + { + "name": "http2serverConn.newWriterAndRequest" + }, + { + "name": "http2serverConn.newWriterAndRequestNoBody" + }, + { + "name": "http2serverConn.noteBodyRead" + }, + { + "name": "http2serverConn.processHeaders" + }, + { + "name": "http2serverConn.runHandler" + }, + { + "name": "http2serverConn.scheduleHandler" + }, + { + "name": "CanonicalHeaderKey" + }, + { + "name": "Client.CloseIdleConnections" + }, + { + "name": "Client.Do" + }, + { + "name": "Client.Get" + }, + { + "name": "Client.Head" + }, + { + "name": "Client.Post" + }, + { + "name": "Client.PostForm" + }, + { + "name": "ClientConn.Close" + }, + { + "name": "ClientConn.RoundTrip" + }, + { + "name": "Cookie.String" + }, + { + "name": "Cookie.Valid" + }, + { + "name": "CrossOriginProtection.AddInsecureBypassPattern" + }, + { + "name": "CrossOriginProtection.AddTrustedOrigin" + }, + { + "name": "CrossOriginProtection.Check" + }, + { + "name": "Dir.Open" + }, + { + "name": "Error" + }, + { + "name": "Get" + }, + { + "name": "Handle" + }, + { + "name": "HandleFunc" + }, + { + "name": "HandlerFunc.ServeHTTP" + }, + { + "name": "Head" + }, + { + "name": "Header.Add" + }, + { + "name": "Header.Del" + }, + { + "name": "Header.Get" + }, + { + "name": "Header.Set" + }, + { + "name": "Header.Values" + }, + { + "name": "Header.Write" + }, + { + "name": "Header.WriteSubset" + }, + { + "name": "ListenAndServe" + }, + { + "name": "ListenAndServeTLS" + }, + { + "name": "NewRequest" + }, + { + "name": "NewRequestWithContext" + }, + { + "name": "NotFound" + }, + { + "name": "ParseCookie" + }, + { + "name": "ParseSetCookie" + }, + { + "name": "ParseTime" + }, + { + "name": "Post" + }, + { + "name": "PostForm" + }, + { + "name": "ProxyFromEnvironment" + }, + { + "name": "ReadRequest" + }, + { + "name": "ReadResponse" + }, + { + "name": "Redirect" + }, + { + "name": "Request.AddCookie" + }, + { + "name": "Request.BasicAuth" + }, + { + "name": "Request.Cookie" + }, + { + "name": "Request.Cookies" + }, + { + "name": "Request.CookiesNamed" + }, + { + "name": "Request.FormFile" + }, + { + "name": "Request.FormValue" + }, + { + "name": "Request.MultipartReader" + }, + { + "name": "Request.ParseForm" + }, + { + "name": "Request.ParseMultipartForm" + }, + { + "name": "Request.PostFormValue" + }, + { + "name": "Request.Referer" + }, + { + "name": "Request.SetBasicAuth" + }, + { + "name": "Request.UserAgent" + }, + { + "name": "Request.Write" + }, + { + "name": "Request.WriteProxy" + }, + { + "name": "Response.Cookies" + }, + { + "name": "Response.Location" + }, + { + "name": "Response.Write" + }, + { + "name": "ResponseController.EnableFullDuplex" + }, + { + "name": "ResponseController.Flush" + }, + { + "name": "ResponseController.Hijack" + }, + { + "name": "ResponseController.SetReadDeadline" + }, + { + "name": "ResponseController.SetWriteDeadline" + }, + { + "name": "Serve" + }, + { + "name": "ServeContent" + }, + { + "name": "ServeFile" + }, + { + "name": "ServeFileFS" + }, + { + "name": "ServeMux.Handle" + }, + { + "name": "ServeMux.HandleFunc" + }, + { + "name": "ServeMux.ServeHTTP" + }, + { + "name": "ServeTLS" + }, + { + "name": "Server.Close" + }, + { + "name": "Server.ListenAndServe" + }, + { + "name": "Server.ListenAndServeTLS" + }, + { + "name": "Server.Serve" + }, + { + "name": "Server.ServeTLS" + }, + { + "name": "Server.SetKeepAlivesEnabled" + }, + { + "name": "Server.Shutdown" + }, + { + "name": "SetCookie" + }, + { + "name": "Transport.CancelRequest" + }, + { + "name": "Transport.Clone" + }, + { + "name": "Transport.CloseIdleConnections" + }, + { + "name": "Transport.NewClientConn" + }, + { + "name": "Transport.RoundTrip" + }, + { + "name": "body.Close" + }, + { + "name": "body.Read" + }, + { + "name": "bodyEOFSignal.Close" + }, + { + "name": "bodyEOFSignal.Read" + }, + { + "name": "bodyLocked.Read" + }, + { + "name": "bufioFlushWriter.Write" + }, + { + "name": "cancelTimerBody.Close" + }, + { + "name": "cancelTimerBody.Read" + }, + { + "name": "checkConnErrorWriter.Write" + }, + { + "name": "chunkWriter.Write" + }, + { + "name": "connReader.Read" + }, + { + "name": "connectMethodKey.String" + }, + { + "name": "expectContinueReader.Close" + }, + { + "name": "expectContinueReader.Read" + }, + { + "name": "extraHeader.Write" + }, + { + "name": "fileHandler.ServeHTTP" + }, + { + "name": "fileTransport.RoundTrip" + }, + { + "name": "globalOptionsHandler.ServeHTTP" + }, + { + "name": "gzipReader.Close" + }, + { + "name": "gzipReader.Read" + }, + { + "name": "http1ClientConn.Close" + }, + { + "name": "http1ClientConn.RoundTrip" + }, + { + "name": "http2ClientConn.Close" + }, + { + "name": "http2ClientConn.Ping" + }, + { + "name": "http2ClientConn.RoundTrip" + }, + { + "name": "http2ClientConn.Shutdown" + }, + { + "name": "http2ConnectionError.Error" + }, + { + "name": "http2ErrCode.String" + }, + { + "name": "http2FrameHeader.String" + }, + { + "name": "http2FrameType.String" + }, + { + "name": "http2FrameWriteRequest.String" + }, + { + "name": "http2Framer.ReadFrame" + }, + { + "name": "http2Framer.ReadFrameForHeader" + }, + { + "name": "http2Framer.ReadFrameHeader" + }, + { + "name": "http2Framer.WriteContinuation" + }, + { + "name": "http2Framer.WriteData" + }, + { + "name": "http2Framer.WriteDataPadded" + }, + { + "name": "http2Framer.WriteGoAway" + }, + { + "name": "http2Framer.WriteHeaders" + }, + { + "name": "http2Framer.WritePing" + }, + { + "name": "http2Framer.WritePriority" + }, + { + "name": "http2Framer.WritePushPromise" + }, + { + "name": "http2Framer.WriteRSTStream" + }, + { + "name": "http2Framer.WriteRawFrame" + }, + { + "name": "http2Framer.WriteSettings" + }, + { + "name": "http2Framer.WriteSettingsAck" + }, + { + "name": "http2Framer.WriteWindowUpdate" + }, + { + "name": "http2GoAwayError.Error" + }, + { + "name": "http2Server.ServeConn" + }, + { + "name": "http2Setting.String" + }, + { + "name": "http2SettingID.String" + }, + { + "name": "http2SettingsFrame.ForeachSetting" + }, + { + "name": "http2StreamError.Error" + }, + { + "name": "http2Transport.CloseIdleConnections" + }, + { + "name": "http2Transport.NewClientConn" + }, + { + "name": "http2Transport.RoundTrip" + }, + { + "name": "http2Transport.RoundTripOpt" + }, + { + "name": "http2bufferedWriter.Flush" + }, + { + "name": "http2bufferedWriter.Write" + }, + { + "name": "http2bufferedWriterTimeoutWriter.Write" + }, + { + "name": "http2chunkWriter.Write" + }, + { + "name": "http2clientConnPool.GetClientConn" + }, + { + "name": "http2connError.Error" + }, + { + "name": "http2dataBuffer.Read" + }, + { + "name": "http2duplicatePseudoHeaderError.Error" + }, + { + "name": "http2gzipReader.Close" + }, + { + "name": "http2gzipReader.Read" + }, + { + "name": "http2headerFieldNameError.Error" + }, + { + "name": "http2headerFieldValueError.Error" + }, + { + "name": "http2netHTTPClientConn.Close" + }, + { + "name": "http2netHTTPClientConn.RoundTrip" + }, + { + "name": "http2noDialClientConnPool.GetClientConn" + }, + { + "name": "http2noDialH2RoundTripper.NewClientConn" + }, + { + "name": "http2noDialH2RoundTripper.RoundTrip" + }, + { + "name": "http2pipe.Read" + }, + { + "name": "http2priorityWriteSchedulerRFC7540.CloseStream" + }, + { + "name": "http2priorityWriteSchedulerRFC7540.OpenStream" + }, + { + "name": "http2priorityWriteSchedulerRFC9218.OpenStream" + }, + { + "name": "http2pseudoHeaderError.Error" + }, + { + "name": "http2responseWriter.Flush" + }, + { + "name": "http2responseWriter.FlushError" + }, + { + "name": "http2responseWriter.Push" + }, + { + "name": "http2responseWriter.SetReadDeadline" + }, + { + "name": "http2responseWriter.SetWriteDeadline" + }, + { + "name": "http2responseWriter.Write" + }, + { + "name": "http2responseWriter.WriteHeader" + }, + { + "name": "http2responseWriter.WriteString" + }, + { + "name": "http2roundRobinWriteScheduler.OpenStream" + }, + { + "name": "http2serverConn.CloseConn" + }, + { + "name": "http2serverConn.Flush" + }, + { + "name": "http2stickyErrWriter.Write" + }, + { + "name": "http2transportResponseBody.Close" + }, + { + "name": "http2transportResponseBody.Read" + }, + { + "name": "http2unencryptedTransport.RoundTrip" + }, + { + "name": "http2writeData.String" + }, + { + "name": "initALPNRequest.ServeHTTP" + }, + { + "name": "loggingConn.Close" + }, + { + "name": "loggingConn.Read" + }, + { + "name": "loggingConn.Write" + }, + { + "name": "maxBytesReader.Close" + }, + { + "name": "maxBytesReader.Read" + }, + { + "name": "onceCloseListener.Close" + }, + { + "name": "persistConn.Read" + }, + { + "name": "persistConnWriter.ReadFrom" + }, + { + "name": "persistConnWriter.Write" + }, + { + "name": "populateResponse.Write" + }, + { + "name": "populateResponse.WriteHeader" + }, + { + "name": "readTrackingBody.Close" + }, + { + "name": "readTrackingBody.Read" + }, + { + "name": "readWriteCloserBody.CloseWrite" + }, + { + "name": "readWriteCloserBody.Read" + }, + { + "name": "redirectHandler.ServeHTTP" + }, + { + "name": "response.Flush" + }, + { + "name": "response.FlushError" + }, + { + "name": "response.Hijack" + }, + { + "name": "response.ReadFrom" + }, + { + "name": "response.Write" + }, + { + "name": "response.WriteHeader" + }, + { + "name": "response.WriteString" + }, + { + "name": "serverHandler.ServeHTTP" + }, + { + "name": "socksDialer.DialWithConn" + }, + { + "name": "socksUsernamePassword.Authenticate" + }, + { + "name": "stringWriter.WriteString" + }, + { + "name": "timeoutHandler.ServeHTTP" + }, + { + "name": "timeoutWriter.Write" + }, + { + "name": "timeoutWriter.WriteHeader" + }, + { + "name": "transportReadFromServerError.Error" + }, + { + "name": "unencryptedHTTP2Request.ServeHTTP" + } + ], + "defaultStatus": "unaffected" + }, + { + "vendor": "Go standard library", + "product": "net/http/internal/http2", + "collectionURL": "https://pkg.go.dev", + "packageName": "net/http/internal/http2", + "versions": [ + { + "version": "1.27.0-0", + "lessThan": "1.27.2", + "status": "affected", + "versionType": "semver" + } + ], + "programRoutines": [ + { + "name": "requestBody.Close" + }, + { + "name": "requestBody.Read" + }, + { + "name": "serverConn.closeStream" + }, + { + "name": "serverConn.handlerDone" + }, + { + "name": "serverConn.newWriterAndRequest" + }, + { + "name": "serverConn.newWriterAndRequestNoBody" + }, + { + "name": "serverConn.noteBodyRead" + }, + { + "name": "serverConn.processHeaders" + }, + { + "name": "serverConn.runHandler" + }, + { + "name": "serverConn.scheduleHandler" + }, + { + "name": "Server.ServeConn" + } + ], + "defaultStatus": "unaffected" + }, + { + "vendor": "golang.org/x/net", + "product": "golang.org/x/net/http2", + "collectionURL": "https://pkg.go.dev", + "packageName": "golang.org/x/net/http2", + "versions": [ + { + "version": "0", + "lessThan": "0.60.0", + "status": "affected", + "versionType": "semver" + } + ], + "programRoutines": [ + { + "name": "requestBody.Close" + }, + { + "name": "requestBody.Read" + }, + { + "name": "serverConn.closeStream" + }, + { + "name": "serverConn.handlerDone" + }, + { + "name": "serverConn.newWriterAndRequest" + }, + { + "name": "serverConn.newWriterAndRequestNoBody" + }, + { + "name": "serverConn.noteBodyRead" + }, + { + "name": "serverConn.processHeaders" + }, + { + "name": "serverConn.runHandler" + }, + { + "name": "serverConn.scheduleHandler" + }, + { + "name": "ClientConn.Close" + }, + { + "name": "ClientConn.Ping" + }, + { + "name": "ClientConn.RoundTrip" + }, + { + "name": "ClientConn.Shutdown" + }, + { + "name": "ConfigureServer" + }, + { + "name": "ConfigureTransport" + }, + { + "name": "ConfigureTransports" + }, + { + "name": "ConnectionError.Error" + }, + { + "name": "ErrCode.String" + }, + { + "name": "FrameHeader.String" + }, + { + "name": "FrameType.String" + }, + { + "name": "FrameWriteRequest.String" + }, + { + "name": "Framer.ReadFrame" + }, + { + "name": "Framer.ReadFrameForHeader" + }, + { + "name": "Framer.ReadFrameHeader" + }, + { + "name": "Framer.WriteContinuation" + }, + { + "name": "Framer.WriteData" + }, + { + "name": "Framer.WriteDataPadded" + }, + { + "name": "Framer.WriteGoAway" + }, + { + "name": "Framer.WriteHeaders" + }, + { + "name": "Framer.WritePing" + }, + { + "name": "Framer.WritePriority" + }, + { + "name": "Framer.WritePriorityUpdate" + }, + { + "name": "Framer.WritePushPromise" + }, + { + "name": "Framer.WriteRSTStream" + }, + { + "name": "Framer.WriteRawFrame" + }, + { + "name": "Framer.WriteSettings" + }, + { + "name": "Framer.WriteSettingsAck" + }, + { + "name": "Framer.WriteWindowUpdate" + }, + { + "name": "GoAwayError.Error" + }, + { + "name": "ReadFrameHeader" + }, + { + "name": "Server.ServeConn" + }, + { + "name": "Setting.String" + }, + { + "name": "SettingID.String" + }, + { + "name": "SettingsFrame.ForeachSetting" + }, + { + "name": "StreamError.Error" + }, + { + "name": "Transport.CloseIdleConnections" + }, + { + "name": "Transport.NewClientConn" + }, + { + "name": "Transport.RoundTrip" + }, + { + "name": "Transport.RoundTripOpt" + }, + { + "name": "bufferedWriter.Flush" + }, + { + "name": "bufferedWriter.Write" + }, + { + "name": "bufferedWriterTimeoutWriter.Write" + }, + { + "name": "chunkWriter.Write" + }, + { + "name": "clientConnPool.GetClientConn" + }, + { + "name": "connError.Error" + }, + { + "name": "dataBuffer.Read" + }, + { + "name": "duplicatePseudoHeaderError.Error" + }, + { + "name": "gzipReader.Close" + }, + { + "name": "gzipReader.Read" + }, + { + "name": "headerFieldNameError.Error" + }, + { + "name": "headerFieldValueError.Error" + }, + { + "name": "netHTTPClientConn.Close" + }, + { + "name": "netHTTPClientConn.RoundTrip" + }, + { + "name": "noDialClientConnPool.GetClientConn" + }, + { + "name": "noDialH2RoundTripper.NewClientConn" + }, + { + "name": "noDialH2RoundTripper.RoundTrip" + }, + { + "name": "pipe.Read" + }, + { + "name": "priorityWriteSchedulerRFC7540.CloseStream" + }, + { + "name": "priorityWriteSchedulerRFC7540.OpenStream" + }, + { + "name": "priorityWriteSchedulerRFC9218.OpenStream" + }, + { + "name": "pseudoHeaderError.Error" + }, + { + "name": "responseWriter.Flush" + }, + { + "name": "responseWriter.FlushError" + }, + { + "name": "responseWriter.Push" + }, + { + "name": "responseWriter.SetReadDeadline" + }, + { + "name": "responseWriter.SetWriteDeadline" + }, + { + "name": "responseWriter.Write" + }, + { + "name": "responseWriter.WriteHeader" + }, + { + "name": "responseWriter.WriteString" + }, + { + "name": "roundRobinWriteScheduler.OpenStream" + }, + { + "name": "serverConn.CloseConn" + }, + { + "name": "serverConn.Flush" + }, + { + "name": "stickyErrWriter.Write" + }, + { + "name": "transportResponseBody.Close" + }, + { + "name": "transportResponseBody.Read" + }, + { + "name": "unencryptedTransport.RoundTrip" + }, + { + "name": "writeData.String" + } + ], + "defaultStatus": "unaffected" + } + ], + "problemTypes": [ + { + "descriptions": [ + { + "lang": "en", + "description": "CWE-675: Multiple Operations on Resource in Single-Operation Context" + } + ] + } + ], + "references": [ + { + "url": "https://go.dev/cl/847187" + }, + { + "url": "https://go.dev/cl/847310" + }, + { + "url": "https://go.dev/issue/81743" + }, + { + "url": "https://groups.google.com/g/golang-announce/c/U2fTuyDJznI" + }, + { + "url": "https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs" + }, + { + "url": "https://pkg.go.dev/vuln/GO-2026-6612" + } + ], + "credits": [ + { + "lang": "en", + "value": "Ali Sherif (https://www.linkedin.com/in/ali-sherif-13812b276/)" + } + ] + } + } +} \ No newline at end of file
diff --git a/data/cve/v5/GO-2026-6613.json b/data/cve/v5/GO-2026-6613.json new file mode 100644 index 0000000..c2d0757 --- /dev/null +++ b/data/cve/v5/GO-2026-6613.json
@@ -0,0 +1,526 @@ +{ + "dataType": "CVE_RECORD", + "dataVersion": "5.0", + "cveMetadata": { + "cveId": "CVE-2026-94439" + }, + "containers": { + "cna": { + "providerMetadata": { + "orgId": "1bb62c36-49e3-4200-9d77-64a1400537cc" + }, + "title": "HTTP/1 server connection desynchronization after 2xx CONNECT response in net/http", + "descriptions": [ + { + "lang": "en", + "value": "When an HTTP server handler sends a 2xx response to an HTTP/1 CONNECT request and returns without hijacking the connection, the server improperly continues to read and serve requests from the connection. Since a 2xx response to an HTTP/1 CONNECT converts the connection into a tunnel, the server should not treat the connection as continuing to contain HTTP. The impact of this misbehavior is mostly limited to potential request smuggling, where an intermediate proxy considers the data on the connection to be tunneled and the server considers it to be HTTP." + } + ], + "affected": [ + { + "vendor": "Go standard library", + "product": "net/http", + "collectionURL": "https://pkg.go.dev", + "packageName": "net/http", + "versions": [ + { + "version": "0", + "lessThan": "1.26.9", + "status": "affected", + "versionType": "semver" + }, + { + "version": "1.27.0-0", + "lessThan": "1.27.2", + "status": "affected", + "versionType": "semver" + } + ], + "programRoutines": [ + { + "name": "chunkWriter.writeHeader" + }, + { + "name": "CanonicalHeaderKey" + }, + { + "name": "Client.CloseIdleConnections" + }, + { + "name": "Client.Do" + }, + { + "name": "Client.Get" + }, + { + "name": "Client.Head" + }, + { + "name": "Client.Post" + }, + { + "name": "Client.PostForm" + }, + { + "name": "ClientConn.Close" + }, + { + "name": "ClientConn.RoundTrip" + }, + { + "name": "Cookie.String" + }, + { + "name": "Cookie.Valid" + }, + { + "name": "CrossOriginProtection.AddInsecureBypassPattern" + }, + { + "name": "CrossOriginProtection.AddTrustedOrigin" + }, + { + "name": "CrossOriginProtection.Check" + }, + { + "name": "Dir.Open" + }, + { + "name": "Error" + }, + { + "name": "Get" + }, + { + "name": "Handle" + }, + { + "name": "HandleFunc" + }, + { + "name": "HandlerFunc.ServeHTTP" + }, + { + "name": "Head" + }, + { + "name": "Header.Add" + }, + { + "name": "Header.Del" + }, + { + "name": "Header.Get" + }, + { + "name": "Header.Set" + }, + { + "name": "Header.Values" + }, + { + "name": "Header.Write" + }, + { + "name": "Header.WriteSubset" + }, + { + "name": "ListenAndServe" + }, + { + "name": "ListenAndServeTLS" + }, + { + "name": "NewRequest" + }, + { + "name": "NewRequestWithContext" + }, + { + "name": "NotFound" + }, + { + "name": "ParseCookie" + }, + { + "name": "ParseSetCookie" + }, + { + "name": "ParseTime" + }, + { + "name": "Post" + }, + { + "name": "PostForm" + }, + { + "name": "ProxyFromEnvironment" + }, + { + "name": "ReadRequest" + }, + { + "name": "ReadResponse" + }, + { + "name": "Redirect" + }, + { + "name": "Request.AddCookie" + }, + { + "name": "Request.BasicAuth" + }, + { + "name": "Request.Cookie" + }, + { + "name": "Request.Cookies" + }, + { + "name": "Request.CookiesNamed" + }, + { + "name": "Request.FormFile" + }, + { + "name": "Request.FormValue" + }, + { + "name": "Request.MultipartReader" + }, + { + "name": "Request.ParseForm" + }, + { + "name": "Request.ParseMultipartForm" + }, + { + "name": "Request.PostFormValue" + }, + { + "name": "Request.Referer" + }, + { + "name": "Request.SetBasicAuth" + }, + { + "name": "Request.UserAgent" + }, + { + "name": "Request.Write" + }, + { + "name": "Request.WriteProxy" + }, + { + "name": "Response.Cookies" + }, + { + "name": "Response.Location" + }, + { + "name": "Response.Write" + }, + { + "name": "ResponseController.EnableFullDuplex" + }, + { + "name": "ResponseController.Flush" + }, + { + "name": "ResponseController.Hijack" + }, + { + "name": "ResponseController.SetReadDeadline" + }, + { + "name": "ResponseController.SetWriteDeadline" + }, + { + "name": "Serve" + }, + { + "name": "ServeContent" + }, + { + "name": "ServeFile" + }, + { + "name": "ServeFileFS" + }, + { + "name": "ServeMux.Handle" + }, + { + "name": "ServeMux.HandleFunc" + }, + { + "name": "ServeMux.ServeHTTP" + }, + { + "name": "ServeTLS" + }, + { + "name": "Server.Close" + }, + { + "name": "Server.ListenAndServe" + }, + { + "name": "Server.ListenAndServeTLS" + }, + { + "name": "Server.Serve" + }, + { + "name": "Server.ServeTLS" + }, + { + "name": "Server.SetKeepAlivesEnabled" + }, + { + "name": "Server.Shutdown" + }, + { + "name": "SetCookie" + }, + { + "name": "Transport.CancelRequest" + }, + { + "name": "Transport.Clone" + }, + { + "name": "Transport.CloseIdleConnections" + }, + { + "name": "Transport.NewClientConn" + }, + { + "name": "Transport.RoundTrip" + }, + { + "name": "body.Close" + }, + { + "name": "body.Read" + }, + { + "name": "bodyEOFSignal.Close" + }, + { + "name": "bodyEOFSignal.Read" + }, + { + "name": "bodyLocked.Read" + }, + { + "name": "bufioFlushWriter.Write" + }, + { + "name": "cancelTimerBody.Close" + }, + { + "name": "cancelTimerBody.Read" + }, + { + "name": "checkConnErrorWriter.Write" + }, + { + "name": "chunkWriter.Write" + }, + { + "name": "connReader.Read" + }, + { + "name": "connectMethodKey.String" + }, + { + "name": "expectContinueReader.Close" + }, + { + "name": "expectContinueReader.Read" + }, + { + "name": "extraHeader.Write" + }, + { + "name": "fileHandler.ServeHTTP" + }, + { + "name": "fileTransport.RoundTrip" + }, + { + "name": "globalOptionsHandler.ServeHTTP" + }, + { + "name": "gzipReader.Close" + }, + { + "name": "gzipReader.Read" + }, + { + "name": "http1ClientConn.Close" + }, + { + "name": "http1ClientConn.RoundTrip" + }, + { + "name": "http2ClientConn.RoundTrip" + }, + { + "name": "http2Handler.ServeHTTP" + }, + { + "name": "http2ResponseWriter.Flush" + }, + { + "name": "http2ResponseWriter.FlushError" + }, + { + "name": "http2ResponseWriter.Push" + }, + { + "name": "http2RoundTripper.RoundTrip" + }, + { + "name": "http3ServerHandler.ServeHTTP" + }, + { + "name": "initALPNRequest.ServeHTTP" + }, + { + "name": "loggingConn.Close" + }, + { + "name": "loggingConn.Read" + }, + { + "name": "loggingConn.Write" + }, + { + "name": "maxBytesReader.Close" + }, + { + "name": "maxBytesReader.Read" + }, + { + "name": "onceCloseListener.Close" + }, + { + "name": "persistConn.Read" + }, + { + "name": "persistConnWriter.ReadFrom" + }, + { + "name": "persistConnWriter.Write" + }, + { + "name": "populateResponse.Write" + }, + { + "name": "populateResponse.WriteHeader" + }, + { + "name": "readTrackingBody.Close" + }, + { + "name": "readTrackingBody.Read" + }, + { + "name": "readWriteCloserBody.CloseWrite" + }, + { + "name": "readWriteCloserBody.Read" + }, + { + "name": "redirectHandler.ServeHTTP" + }, + { + "name": "response.Flush" + }, + { + "name": "response.FlushError" + }, + { + "name": "response.Hijack" + }, + { + "name": "response.ReadFrom" + }, + { + "name": "response.Write" + }, + { + "name": "response.WriteHeader" + }, + { + "name": "response.WriteString" + }, + { + "name": "serverHandler.ServeHTTP" + }, + { + "name": "socksDialer.DialWithConn" + }, + { + "name": "socksUsernamePassword.Authenticate" + }, + { + "name": "stringWriter.WriteString" + }, + { + "name": "timeoutHandler.ServeHTTP" + }, + { + "name": "timeoutWriter.Write" + }, + { + "name": "timeoutWriter.WriteHeader" + }, + { + "name": "transportReadFromServerError.Error" + }, + { + "name": "unencryptedHTTP2Request.ServeHTTP" + } + ], + "defaultStatus": "unaffected" + } + ], + "problemTypes": [ + { + "descriptions": [ + { + "lang": "en", + "description": "CWE-444: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')" + } + ] + } + ], + "references": [ + { + "url": "https://go.dev/cl/847311" + }, + { + "url": "https://go.dev/issue/81744" + }, + { + "url": "https://groups.google.com/g/golang-announce/c/U2fTuyDJznI" + }, + { + "url": "https://pkg.go.dev/vuln/GO-2026-6613" + } + ], + "credits": [ + { + "lang": "en", + "value": "Jakub Ciolek (https://ciolek.dev)" + } + ] + } + } +} \ No newline at end of file
diff --git a/data/cve/v5/GO-2026-6617.json b/data/cve/v5/GO-2026-6617.json new file mode 100644 index 0000000..8de5c4b --- /dev/null +++ b/data/cve/v5/GO-2026-6617.json
@@ -0,0 +1,1178 @@ +{ + "dataType": "CVE_RECORD", + "dataVersion": "5.0", + "cveMetadata": { + "cveId": "CVE-2026-97032" + }, + "containers": { + "cna": { + "providerMetadata": { + "orgId": "1bb62c36-49e3-4200-9d77-64a1400537cc" + }, + "title": "HTTP/2 server crash due to HPACK encoder race in net/http", + "descriptions": [ + { + "lang": "en", + "value": "HTTP/2 servers could end up crashing due to inadvertently modifying its HPACK encoder concurrently. This happens because the server modifies the HPACK encoder from two goroutines without synchronization: one uses the encoder to encode a HEADERS frame as part of a response sent to a client and the other modifies the encoder's table size when handling a SETTINGS frame containing SETTINGS_HEADER_TABLE_SIZE that a client sends. A malicious client can repeatedly send a request while changing the header table size to crash the server." + } + ], + "affected": [ + { + "vendor": "Go standard library", + "product": "net/http", + "collectionURL": "https://pkg.go.dev", + "packageName": "net/http", + "versions": [ + { + "version": "0", + "lessThan": "1.26.9", + "status": "affected", + "versionType": "semver" + } + ], + "programRoutines": [ + { + "name": "http2serverConn.processSetting" + }, + { + "name": "http2serverConn.startFrameWrite" + }, + { + "name": "CanonicalHeaderKey" + }, + { + "name": "Client.CloseIdleConnections" + }, + { + "name": "Client.Do" + }, + { + "name": "Client.Get" + }, + { + "name": "Client.Head" + }, + { + "name": "Client.Post" + }, + { + "name": "Client.PostForm" + }, + { + "name": "ClientConn.Close" + }, + { + "name": "ClientConn.RoundTrip" + }, + { + "name": "Cookie.String" + }, + { + "name": "Cookie.Valid" + }, + { + "name": "CrossOriginProtection.AddInsecureBypassPattern" + }, + { + "name": "CrossOriginProtection.AddTrustedOrigin" + }, + { + "name": "CrossOriginProtection.Check" + }, + { + "name": "Dir.Open" + }, + { + "name": "Error" + }, + { + "name": "Get" + }, + { + "name": "Handle" + }, + { + "name": "HandleFunc" + }, + { + "name": "HandlerFunc.ServeHTTP" + }, + { + "name": "Head" + }, + { + "name": "Header.Add" + }, + { + "name": "Header.Del" + }, + { + "name": "Header.Get" + }, + { + "name": "Header.Set" + }, + { + "name": "Header.Values" + }, + { + "name": "Header.Write" + }, + { + "name": "Header.WriteSubset" + }, + { + "name": "ListenAndServe" + }, + { + "name": "ListenAndServeTLS" + }, + { + "name": "NewRequest" + }, + { + "name": "NewRequestWithContext" + }, + { + "name": "NotFound" + }, + { + "name": "ParseCookie" + }, + { + "name": "ParseSetCookie" + }, + { + "name": "ParseTime" + }, + { + "name": "Post" + }, + { + "name": "PostForm" + }, + { + "name": "ProxyFromEnvironment" + }, + { + "name": "ReadRequest" + }, + { + "name": "ReadResponse" + }, + { + "name": "Redirect" + }, + { + "name": "Request.AddCookie" + }, + { + "name": "Request.BasicAuth" + }, + { + "name": "Request.Cookie" + }, + { + "name": "Request.Cookies" + }, + { + "name": "Request.CookiesNamed" + }, + { + "name": "Request.FormFile" + }, + { + "name": "Request.FormValue" + }, + { + "name": "Request.MultipartReader" + }, + { + "name": "Request.ParseForm" + }, + { + "name": "Request.ParseMultipartForm" + }, + { + "name": "Request.PostFormValue" + }, + { + "name": "Request.Referer" + }, + { + "name": "Request.SetBasicAuth" + }, + { + "name": "Request.UserAgent" + }, + { + "name": "Request.Write" + }, + { + "name": "Request.WriteProxy" + }, + { + "name": "Response.Cookies" + }, + { + "name": "Response.Location" + }, + { + "name": "Response.Write" + }, + { + "name": "ResponseController.EnableFullDuplex" + }, + { + "name": "ResponseController.Flush" + }, + { + "name": "ResponseController.Hijack" + }, + { + "name": "ResponseController.SetReadDeadline" + }, + { + "name": "ResponseController.SetWriteDeadline" + }, + { + "name": "Serve" + }, + { + "name": "ServeContent" + }, + { + "name": "ServeFile" + }, + { + "name": "ServeFileFS" + }, + { + "name": "ServeMux.Handle" + }, + { + "name": "ServeMux.HandleFunc" + }, + { + "name": "ServeMux.ServeHTTP" + }, + { + "name": "ServeTLS" + }, + { + "name": "Server.Close" + }, + { + "name": "Server.ListenAndServe" + }, + { + "name": "Server.ListenAndServeTLS" + }, + { + "name": "Server.Serve" + }, + { + "name": "Server.ServeTLS" + }, + { + "name": "Server.SetKeepAlivesEnabled" + }, + { + "name": "Server.Shutdown" + }, + { + "name": "SetCookie" + }, + { + "name": "Transport.CancelRequest" + }, + { + "name": "Transport.Clone" + }, + { + "name": "Transport.CloseIdleConnections" + }, + { + "name": "Transport.NewClientConn" + }, + { + "name": "Transport.RoundTrip" + }, + { + "name": "body.Close" + }, + { + "name": "body.Read" + }, + { + "name": "bodyEOFSignal.Close" + }, + { + "name": "bodyEOFSignal.Read" + }, + { + "name": "bodyLocked.Read" + }, + { + "name": "bufioFlushWriter.Write" + }, + { + "name": "cancelTimerBody.Close" + }, + { + "name": "cancelTimerBody.Read" + }, + { + "name": "checkConnErrorWriter.Write" + }, + { + "name": "chunkWriter.Write" + }, + { + "name": "connReader.Read" + }, + { + "name": "connectMethodKey.String" + }, + { + "name": "expectContinueReader.Close" + }, + { + "name": "expectContinueReader.Read" + }, + { + "name": "extraHeader.Write" + }, + { + "name": "fileHandler.ServeHTTP" + }, + { + "name": "fileTransport.RoundTrip" + }, + { + "name": "globalOptionsHandler.ServeHTTP" + }, + { + "name": "gzipReader.Close" + }, + { + "name": "gzipReader.Read" + }, + { + "name": "http1ClientConn.Close" + }, + { + "name": "http1ClientConn.RoundTrip" + }, + { + "name": "http2ClientConn.Close" + }, + { + "name": "http2ClientConn.Ping" + }, + { + "name": "http2ClientConn.RoundTrip" + }, + { + "name": "http2ClientConn.Shutdown" + }, + { + "name": "http2ConnectionError.Error" + }, + { + "name": "http2ErrCode.String" + }, + { + "name": "http2FrameHeader.String" + }, + { + "name": "http2FrameType.String" + }, + { + "name": "http2FrameWriteRequest.String" + }, + { + "name": "http2Framer.ReadFrame" + }, + { + "name": "http2Framer.ReadFrameForHeader" + }, + { + "name": "http2Framer.ReadFrameHeader" + }, + { + "name": "http2Framer.WriteContinuation" + }, + { + "name": "http2Framer.WriteData" + }, + { + "name": "http2Framer.WriteDataPadded" + }, + { + "name": "http2Framer.WriteGoAway" + }, + { + "name": "http2Framer.WriteHeaders" + }, + { + "name": "http2Framer.WritePing" + }, + { + "name": "http2Framer.WritePriority" + }, + { + "name": "http2Framer.WritePushPromise" + }, + { + "name": "http2Framer.WriteRSTStream" + }, + { + "name": "http2Framer.WriteRawFrame" + }, + { + "name": "http2Framer.WriteSettings" + }, + { + "name": "http2Framer.WriteSettingsAck" + }, + { + "name": "http2Framer.WriteWindowUpdate" + }, + { + "name": "http2GoAwayError.Error" + }, + { + "name": "http2Server.ServeConn" + }, + { + "name": "http2Setting.String" + }, + { + "name": "http2SettingID.String" + }, + { + "name": "http2SettingsFrame.ForeachSetting" + }, + { + "name": "http2StreamError.Error" + }, + { + "name": "http2Transport.CloseIdleConnections" + }, + { + "name": "http2Transport.NewClientConn" + }, + { + "name": "http2Transport.RoundTrip" + }, + { + "name": "http2Transport.RoundTripOpt" + }, + { + "name": "http2bufferedWriter.Flush" + }, + { + "name": "http2bufferedWriter.Write" + }, + { + "name": "http2bufferedWriterTimeoutWriter.Write" + }, + { + "name": "http2chunkWriter.Write" + }, + { + "name": "http2clientConnPool.GetClientConn" + }, + { + "name": "http2connError.Error" + }, + { + "name": "http2dataBuffer.Read" + }, + { + "name": "http2duplicatePseudoHeaderError.Error" + }, + { + "name": "http2gzipReader.Close" + }, + { + "name": "http2gzipReader.Read" + }, + { + "name": "http2headerFieldNameError.Error" + }, + { + "name": "http2headerFieldValueError.Error" + }, + { + "name": "http2netHTTPClientConn.Close" + }, + { + "name": "http2netHTTPClientConn.RoundTrip" + }, + { + "name": "http2noDialClientConnPool.GetClientConn" + }, + { + "name": "http2noDialH2RoundTripper.NewClientConn" + }, + { + "name": "http2noDialH2RoundTripper.RoundTrip" + }, + { + "name": "http2pipe.Read" + }, + { + "name": "http2priorityWriteSchedulerRFC7540.CloseStream" + }, + { + "name": "http2priorityWriteSchedulerRFC7540.OpenStream" + }, + { + "name": "http2priorityWriteSchedulerRFC9218.OpenStream" + }, + { + "name": "http2pseudoHeaderError.Error" + }, + { + "name": "http2requestBody.Close" + }, + { + "name": "http2requestBody.Read" + }, + { + "name": "http2responseWriter.Flush" + }, + { + "name": "http2responseWriter.FlushError" + }, + { + "name": "http2responseWriter.Push" + }, + { + "name": "http2responseWriter.SetReadDeadline" + }, + { + "name": "http2responseWriter.SetWriteDeadline" + }, + { + "name": "http2responseWriter.Write" + }, + { + "name": "http2responseWriter.WriteHeader" + }, + { + "name": "http2responseWriter.WriteString" + }, + { + "name": "http2roundRobinWriteScheduler.OpenStream" + }, + { + "name": "http2serverConn.CloseConn" + }, + { + "name": "http2serverConn.Flush" + }, + { + "name": "http2stickyErrWriter.Write" + }, + { + "name": "http2transportResponseBody.Close" + }, + { + "name": "http2transportResponseBody.Read" + }, + { + "name": "http2unencryptedTransport.RoundTrip" + }, + { + "name": "http2writeData.String" + }, + { + "name": "initALPNRequest.ServeHTTP" + }, + { + "name": "loggingConn.Close" + }, + { + "name": "loggingConn.Read" + }, + { + "name": "loggingConn.Write" + }, + { + "name": "maxBytesReader.Close" + }, + { + "name": "maxBytesReader.Read" + }, + { + "name": "onceCloseListener.Close" + }, + { + "name": "persistConn.Read" + }, + { + "name": "persistConnWriter.ReadFrom" + }, + { + "name": "persistConnWriter.Write" + }, + { + "name": "populateResponse.Write" + }, + { + "name": "populateResponse.WriteHeader" + }, + { + "name": "readTrackingBody.Close" + }, + { + "name": "readTrackingBody.Read" + }, + { + "name": "readWriteCloserBody.CloseWrite" + }, + { + "name": "readWriteCloserBody.Read" + }, + { + "name": "redirectHandler.ServeHTTP" + }, + { + "name": "response.Flush" + }, + { + "name": "response.FlushError" + }, + { + "name": "response.Hijack" + }, + { + "name": "response.ReadFrom" + }, + { + "name": "response.Write" + }, + { + "name": "response.WriteHeader" + }, + { + "name": "response.WriteString" + }, + { + "name": "serverHandler.ServeHTTP" + }, + { + "name": "socksDialer.DialWithConn" + }, + { + "name": "socksUsernamePassword.Authenticate" + }, + { + "name": "stringWriter.WriteString" + }, + { + "name": "timeoutHandler.ServeHTTP" + }, + { + "name": "timeoutWriter.Write" + }, + { + "name": "timeoutWriter.WriteHeader" + }, + { + "name": "transportReadFromServerError.Error" + }, + { + "name": "unencryptedHTTP2Request.ServeHTTP" + } + ], + "defaultStatus": "unaffected" + }, + { + "vendor": "Go standard library", + "product": "net/http/internal/http2", + "collectionURL": "https://pkg.go.dev", + "packageName": "net/http/internal/http2", + "versions": [ + { + "version": "1.27.0-0", + "lessThan": "1.27.2", + "status": "affected", + "versionType": "semver" + } + ], + "programRoutines": [ + { + "name": "serverConn.processSetting" + }, + { + "name": "serverConn.startFrameWrite" + }, + { + "name": "ClientConn.Close" + }, + { + "name": "ClientConn.Ping" + }, + { + "name": "ClientConn.RoundTrip" + }, + { + "name": "ClientConn.Shutdown" + }, + { + "name": "Framer.ReadFrame" + }, + { + "name": "Framer.ReadFrameForHeader" + }, + { + "name": "Framer.ReadFrameHeader" + }, + { + "name": "Framer.WriteContinuation" + }, + { + "name": "Framer.WriteData" + }, + { + "name": "Framer.WriteDataPadded" + }, + { + "name": "Framer.WriteGoAway" + }, + { + "name": "Framer.WriteHeaders" + }, + { + "name": "Framer.WritePing" + }, + { + "name": "Framer.WritePriority" + }, + { + "name": "Framer.WritePriorityUpdate" + }, + { + "name": "Framer.WritePushPromise" + }, + { + "name": "Framer.WriteRSTStream" + }, + { + "name": "Framer.WriteRawFrame" + }, + { + "name": "Framer.WriteSettings" + }, + { + "name": "Framer.WriteSettingsAck" + }, + { + "name": "Framer.WriteWindowUpdate" + }, + { + "name": "NetHTTPClientConn.Close" + }, + { + "name": "NetHTTPClientConn.Ping" + }, + { + "name": "NetHTTPClientConn.RoundTrip" + }, + { + "name": "ReadFrameHeader" + }, + { + "name": "Server.GracefulShutdown" + }, + { + "name": "Server.ServeConn" + }, + { + "name": "SettingsFrame.ForeachSetting" + }, + { + "name": "Transport.AddConn" + }, + { + "name": "Transport.CloseIdleConnections" + }, + { + "name": "Transport.NewClientConn" + }, + { + "name": "Transport.RoundTrip" + }, + { + "name": "Transport.RoundTripOpt" + }, + { + "name": "bufferedWriter.Flush" + }, + { + "name": "bufferedWriter.Write" + }, + { + "name": "bufferedWriterTimeoutWriter.Write" + }, + { + "name": "chunkWriter.Write" + }, + { + "name": "clientConnPool.GetClientConn" + }, + { + "name": "gzipReader.Close" + }, + { + "name": "gzipReader.Read" + }, + { + "name": "noDialClientConnPool.GetClientConn" + }, + { + "name": "requestBody.Close" + }, + { + "name": "responseWriter.Flush" + }, + { + "name": "responseWriter.FlushError" + }, + { + "name": "responseWriter.Push" + }, + { + "name": "responseWriter.Write" + }, + { + "name": "responseWriter.WriteHeader" + }, + { + "name": "responseWriter.WriteString" + }, + { + "name": "serve400Handler.ServeHTTP" + }, + { + "name": "serverConn.Flush" + }, + { + "name": "stickyErrWriter.Write" + }, + { + "name": "transportResponseBody.Close" + }, + { + "name": "transportResponseBody.Read" + } + ], + "defaultStatus": "unaffected" + }, + { + "vendor": "golang.org/x/net", + "product": "golang.org/x/net/http2", + "collectionURL": "https://pkg.go.dev", + "packageName": "golang.org/x/net/http2", + "versions": [ + { + "version": "0", + "lessThan": "0.60.0", + "status": "affected", + "versionType": "semver" + } + ], + "programRoutines": [ + { + "name": "serverConn.processSetting" + }, + { + "name": "serverConn.startFrameWrite" + }, + { + "name": "ClientConn.Close" + }, + { + "name": "ClientConn.Ping" + }, + { + "name": "ClientConn.RoundTrip" + }, + { + "name": "ClientConn.Shutdown" + }, + { + "name": "ConfigureServer" + }, + { + "name": "ConfigureTransport" + }, + { + "name": "ConfigureTransports" + }, + { + "name": "ConnectionError.Error" + }, + { + "name": "ErrCode.String" + }, + { + "name": "FrameHeader.String" + }, + { + "name": "FrameType.String" + }, + { + "name": "FrameWriteRequest.String" + }, + { + "name": "Framer.ReadFrame" + }, + { + "name": "Framer.ReadFrameForHeader" + }, + { + "name": "Framer.ReadFrameHeader" + }, + { + "name": "Framer.WriteContinuation" + }, + { + "name": "Framer.WriteData" + }, + { + "name": "Framer.WriteDataPadded" + }, + { + "name": "Framer.WriteGoAway" + }, + { + "name": "Framer.WriteHeaders" + }, + { + "name": "Framer.WritePing" + }, + { + "name": "Framer.WritePriority" + }, + { + "name": "Framer.WritePriorityUpdate" + }, + { + "name": "Framer.WritePushPromise" + }, + { + "name": "Framer.WriteRSTStream" + }, + { + "name": "Framer.WriteRawFrame" + }, + { + "name": "Framer.WriteSettings" + }, + { + "name": "Framer.WriteSettingsAck" + }, + { + "name": "Framer.WriteWindowUpdate" + }, + { + "name": "GoAwayError.Error" + }, + { + "name": "ReadFrameHeader" + }, + { + "name": "Server.ServeConn" + }, + { + "name": "Setting.String" + }, + { + "name": "SettingID.String" + }, + { + "name": "SettingsFrame.ForeachSetting" + }, + { + "name": "StreamError.Error" + }, + { + "name": "Transport.CloseIdleConnections" + }, + { + "name": "Transport.NewClientConn" + }, + { + "name": "Transport.RoundTrip" + }, + { + "name": "Transport.RoundTripOpt" + }, + { + "name": "bufferedWriter.Flush" + }, + { + "name": "bufferedWriter.Write" + }, + { + "name": "bufferedWriterTimeoutWriter.Write" + }, + { + "name": "chunkWriter.Write" + }, + { + "name": "clientConnPool.GetClientConn" + }, + { + "name": "connError.Error" + }, + { + "name": "dataBuffer.Read" + }, + { + "name": "duplicatePseudoHeaderError.Error" + }, + { + "name": "gzipReader.Close" + }, + { + "name": "gzipReader.Read" + }, + { + "name": "headerFieldNameError.Error" + }, + { + "name": "headerFieldValueError.Error" + }, + { + "name": "netHTTPClientConn.Close" + }, + { + "name": "netHTTPClientConn.RoundTrip" + }, + { + "name": "noDialClientConnPool.GetClientConn" + }, + { + "name": "noDialH2RoundTripper.NewClientConn" + }, + { + "name": "noDialH2RoundTripper.RoundTrip" + }, + { + "name": "pipe.Read" + }, + { + "name": "priorityWriteSchedulerRFC7540.CloseStream" + }, + { + "name": "priorityWriteSchedulerRFC7540.OpenStream" + }, + { + "name": "priorityWriteSchedulerRFC9218.OpenStream" + }, + { + "name": "pseudoHeaderError.Error" + }, + { + "name": "requestBody.Close" + }, + { + "name": "requestBody.Read" + }, + { + "name": "responseWriter.Flush" + }, + { + "name": "responseWriter.FlushError" + }, + { + "name": "responseWriter.Push" + }, + { + "name": "responseWriter.SetReadDeadline" + }, + { + "name": "responseWriter.SetWriteDeadline" + }, + { + "name": "responseWriter.Write" + }, + { + "name": "responseWriter.WriteHeader" + }, + { + "name": "responseWriter.WriteString" + }, + { + "name": "roundRobinWriteScheduler.OpenStream" + }, + { + "name": "serverConn.CloseConn" + }, + { + "name": "serverConn.Flush" + }, + { + "name": "stickyErrWriter.Write" + }, + { + "name": "transportResponseBody.Close" + }, + { + "name": "transportResponseBody.Read" + }, + { + "name": "unencryptedTransport.RoundTrip" + }, + { + "name": "writeData.String" + } + ], + "defaultStatus": "unaffected" + } + ], + "problemTypes": [ + { + "descriptions": [ + { + "lang": "en", + "description": "CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')" + } + ] + } + ], + "references": [ + { + "url": "https://go.dev/cl/847188" + }, + { + "url": "https://go.dev/cl/847313" + }, + { + "url": "https://go.dev/issue/81867" + }, + { + "url": "https://groups.google.com/g/golang-announce/c/U2fTuyDJznI" + }, + { + "url": "https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs" + }, + { + "url": "https://pkg.go.dev/vuln/GO-2026-6617" + } + ], + "credits": [ + { + "lang": "en", + "value": "RyotaK (https://ryotak.net) of GMO Flatt Security Inc." + } + ] + } + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6599.json b/data/osv/GO-2026-6599.json new file mode 100644 index 0000000..53c60b4 --- /dev/null +++ b/data/osv/GO-2026-6599.json
@@ -0,0 +1,68 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6599", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-94448" + ], + "summary": "Reset context tracking on consecutive template expressions in html/template", + "details": "When a JavaScript template literal contains consecutive expressions, the context tracking state was not properly reset upon entering a new expression.\n\nWe now ensure that template-literal expression entries correctly reset context variables so all subsequent regular expression literals are accurately recognized and escaped.", + "affected": [ + { + "package": { + "name": "stdlib", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.26.9" + }, + { + "introduced": "1.27.0-0" + }, + { + "fixed": "1.27.2" + } + ] + } + ], + "ecosystem_specific": { + "imports": [ + { + "path": "html/template", + "symbols": [ + "Template.Execute", + "Template.ExecuteTemplate", + "tJSTmpl" + ] + } + ] + } + } + ], + "references": [ + { + "type": "FIX", + "url": "https://go.dev/cl/839866" + }, + { + "type": "REPORT", + "url": "https://go.dev/issue/81821" + }, + { + "type": "WEB", + "url": "https://groups.google.com/g/golang-announce/c/U2fTuyDJznI" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6599", + "review_status": "REVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6600.json b/data/osv/GO-2026-6600.json new file mode 100644 index 0000000..d8a15a0 --- /dev/null +++ b/data/osv/GO-2026-6600.json
@@ -0,0 +1,69 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6600", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-97030" + ], + "summary": "Recognize yield as regexp preceder keyword in html/template", + "details": "A trusted template author may have previously written a valid template wherein the use of the 'yield' keyword would not be correctly escaped.\n\nWe now ensure that valid keyword uses are escaped and non-keyword uses are not escaped.", + "affected": [ + { + "package": { + "name": "stdlib", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.26.9" + }, + { + "introduced": "1.27.0-0" + }, + { + "fixed": "1.27.2" + } + ] + } + ], + "ecosystem_specific": { + "imports": [ + { + "path": "html/template", + "symbols": [ + "Template.Execute", + "Template.ExecuteTemplate", + "nextJSCtx", + "tJS" + ] + } + ] + } + } + ], + "references": [ + { + "type": "FIX", + "url": "https://go.dev/cl/840925" + }, + { + "type": "REPORT", + "url": "https://go.dev/issue/81823" + }, + { + "type": "WEB", + "url": "https://groups.google.com/g/golang-announce/c/U2fTuyDJznI" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6600", + "review_status": "REVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6601.json b/data/osv/GO-2026-6601.json new file mode 100644 index 0000000..a78465a --- /dev/null +++ b/data/osv/GO-2026-6601.json
@@ -0,0 +1,63 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6601", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-94444" + ], + "summary": "Checksum bypass for golang.org/fips140 in cmd/go", + "details": "Previously, a user operating inside of a malicious Go project that defines a bogus golang.org/fips140 and operates a malicious GOMODPROXY the user chooses to connect to can serve an arbitrary module in its place.\n\nWe now unpack the trusted ziphash for the bundled golang.org/fips140 module and construct its entry in the GOMODCACHE such that it can be verified by the toolchain.", + "affected": [ + { + "package": { + "name": "toolchain", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.26.9" + }, + { + "introduced": "1.27.0-0" + }, + { + "fixed": "1.27.2" + } + ] + } + ], + "ecosystem_specific": { + "imports": [ + { + "path": "cmd/go" + } + ] + } + } + ], + "references": [ + { + "type": "FIX", + "url": "https://go.dev/cl/840685" + }, + { + "type": "REPORT", + "url": "https://go.dev/issue/81833" + }, + { + "type": "WEB", + "url": "https://groups.google.com/g/golang-announce/c/U2fTuyDJznI" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6601", + "review_status": "REVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6602.json b/data/osv/GO-2026-6602.json new file mode 100644 index 0000000..ffd6930 --- /dev/null +++ b/data/osv/GO-2026-6602.json
@@ -0,0 +1,63 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6602", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-94447" + ], + "summary": "Checksum database bypass for golang.org/toolchain in cmd/go", + "details": "Previously, a user operating inside of a malicious Go project that defines a bogus golang.org/toolchain go.sum entry and operates a malicious GOMODPROXY the user chooses to use can bypass the intended checksum.\n\nWe now ensure that golang.org/toolchain always goes to the network for the canonical checksum.", + "affected": [ + { + "package": { + "name": "toolchain", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.26.9" + }, + { + "introduced": "1.27.0-0" + }, + { + "fixed": "1.27.2" + } + ] + } + ], + "ecosystem_specific": { + "imports": [ + { + "path": "cmd/go" + } + ] + } + } + ], + "references": [ + { + "type": "FIX", + "url": "https://go.dev/cl/840785" + }, + { + "type": "REPORT", + "url": "https://go.dev/issue/81834" + }, + { + "type": "WEB", + "url": "https://groups.google.com/g/golang-announce/c/U2fTuyDJznI" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6602", + "review_status": "REVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6603.json b/data/osv/GO-2026-6603.json new file mode 100644 index 0000000..e6f4161 --- /dev/null +++ b/data/osv/GO-2026-6603.json
@@ -0,0 +1,481 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6603", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-78659" + ], + "summary": "HTTP/2 server memory exhaustion due to Trailer headers in net/http", + "details": "When \"Trailer\" headers are sent by a client, the HTTP server internally uses the header values to populate the Request.Trailer map passed to the server handler. Because Request.Trailer is a map, each entry incurs memory overhead. For HTTP/2 servers, a malicious client can exploit this by sending a \"Trailer\" header that declares a large number of fields, causing the server to allocate a disproportionate amount of memory while bypassing Server.MaxHeaderValueCount and Server.MaxHeaderBytes limits. This exploit is not applicable for HTTP/1 servers, which do not support multiplexing a large number of requests over one TCP connection, and whose Server.MaxHeaderBytes are calculated differently.", + "affected": [ + { + "package": { + "name": "stdlib", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.26.9" + } + ] + } + ], + "ecosystem_specific": { + "imports": [ + { + "path": "net/http", + "symbols": [ + "CanonicalHeaderKey", + "Client.CloseIdleConnections", + "Client.Do", + "Client.Get", + "Client.Head", + "Client.Post", + "Client.PostForm", + "ClientConn.Close", + "ClientConn.RoundTrip", + "Cookie.String", + "Cookie.Valid", + "CrossOriginProtection.AddInsecureBypassPattern", + "CrossOriginProtection.AddTrustedOrigin", + "CrossOriginProtection.Check", + "Dir.Open", + "Error", + "Get", + "Handle", + "HandleFunc", + "HandlerFunc.ServeHTTP", + "Head", + "Header.Add", + "Header.Del", + "Header.Get", + "Header.Set", + "Header.Values", + "Header.Write", + "Header.WriteSubset", + "ListenAndServe", + "ListenAndServeTLS", + "NewRequest", + "NewRequestWithContext", + "NotFound", + "ParseCookie", + "ParseSetCookie", + "ParseTime", + "Post", + "PostForm", + "ProxyFromEnvironment", + "ReadRequest", + "ReadResponse", + "Redirect", + "Request.AddCookie", + "Request.BasicAuth", + "Request.Cookie", + "Request.Cookies", + "Request.CookiesNamed", + "Request.FormFile", + "Request.FormValue", + "Request.MultipartReader", + "Request.ParseForm", + "Request.ParseMultipartForm", + "Request.PostFormValue", + "Request.Referer", + "Request.SetBasicAuth", + "Request.UserAgent", + "Request.Write", + "Request.WriteProxy", + "Response.Cookies", + "Response.Location", + "Response.Write", + "ResponseController.EnableFullDuplex", + "ResponseController.Flush", + "ResponseController.Hijack", + "ResponseController.SetReadDeadline", + "ResponseController.SetWriteDeadline", + "Serve", + "ServeContent", + "ServeFile", + "ServeFileFS", + "ServeMux.Handle", + "ServeMux.HandleFunc", + "ServeMux.ServeHTTP", + "ServeTLS", + "Server.Close", + "Server.ListenAndServe", + "Server.ListenAndServeTLS", + "Server.Serve", + "Server.ServeTLS", + "Server.SetKeepAlivesEnabled", + "Server.Shutdown", + "SetCookie", + "Transport.CancelRequest", + "Transport.Clone", + "Transport.CloseIdleConnections", + "Transport.NewClientConn", + "Transport.RoundTrip", + "body.Close", + "body.Read", + "bodyEOFSignal.Close", + "bodyEOFSignal.Read", + "bodyLocked.Read", + "bufioFlushWriter.Write", + "cancelTimerBody.Close", + "cancelTimerBody.Read", + "checkConnErrorWriter.Write", + "chunkWriter.Write", + "connReader.Read", + "connectMethodKey.String", + "expectContinueReader.Close", + "expectContinueReader.Read", + "extraHeader.Write", + "fileHandler.ServeHTTP", + "fileTransport.RoundTrip", + "globalOptionsHandler.ServeHTTP", + "gzipReader.Close", + "gzipReader.Read", + "http1ClientConn.Close", + "http1ClientConn.RoundTrip", + "http2ClientConn.Close", + "http2ClientConn.Ping", + "http2ClientConn.RoundTrip", + "http2ClientConn.Shutdown", + "http2ConnectionError.Error", + "http2ErrCode.String", + "http2FrameHeader.String", + "http2FrameType.String", + "http2FrameWriteRequest.String", + "http2Framer.ReadFrame", + "http2Framer.ReadFrameForHeader", + "http2Framer.ReadFrameHeader", + "http2Framer.WriteContinuation", + "http2Framer.WriteData", + "http2Framer.WriteDataPadded", + "http2Framer.WriteGoAway", + "http2Framer.WriteHeaders", + "http2Framer.WritePing", + "http2Framer.WritePriority", + "http2Framer.WritePushPromise", + "http2Framer.WriteRSTStream", + "http2Framer.WriteRawFrame", + "http2Framer.WriteSettings", + "http2Framer.WriteSettingsAck", + "http2Framer.WriteWindowUpdate", + "http2Framer.readMetaFrame", + "http2GoAwayError.Error", + "http2Server.ServeConn", + "http2Setting.String", + "http2SettingID.String", + "http2SettingsFrame.ForeachSetting", + "http2StreamError.Error", + "http2Transport.CloseIdleConnections", + "http2Transport.NewClientConn", + "http2Transport.RoundTrip", + "http2Transport.RoundTripOpt", + "http2bufferedWriter.Flush", + "http2bufferedWriter.Write", + "http2bufferedWriterTimeoutWriter.Write", + "http2chunkWriter.Write", + "http2clientConnPool.GetClientConn", + "http2connError.Error", + "http2dataBuffer.Read", + "http2duplicatePseudoHeaderError.Error", + "http2gzipReader.Close", + "http2gzipReader.Read", + "http2headerFieldNameError.Error", + "http2headerFieldValueError.Error", + "http2netHTTPClientConn.Close", + "http2netHTTPClientConn.RoundTrip", + "http2noDialClientConnPool.GetClientConn", + "http2noDialH2RoundTripper.NewClientConn", + "http2noDialH2RoundTripper.RoundTrip", + "http2pipe.Read", + "http2priorityWriteSchedulerRFC7540.CloseStream", + "http2priorityWriteSchedulerRFC7540.OpenStream", + "http2priorityWriteSchedulerRFC9218.OpenStream", + "http2pseudoHeaderError.Error", + "http2requestBody.Close", + "http2requestBody.Read", + "http2responseWriter.Flush", + "http2responseWriter.FlushError", + "http2responseWriter.Push", + "http2responseWriter.SetReadDeadline", + "http2responseWriter.SetWriteDeadline", + "http2responseWriter.Write", + "http2responseWriter.WriteHeader", + "http2responseWriter.WriteString", + "http2roundRobinWriteScheduler.OpenStream", + "http2serverConn.CloseConn", + "http2serverConn.Flush", + "http2stickyErrWriter.Write", + "http2transportResponseBody.Close", + "http2transportResponseBody.Read", + "http2unencryptedTransport.RoundTrip", + "http2writeData.String", + "initALPNRequest.ServeHTTP", + "loggingConn.Close", + "loggingConn.Read", + "loggingConn.Write", + "maxBytesReader.Close", + "maxBytesReader.Read", + "onceCloseListener.Close", + "persistConn.Read", + "persistConnWriter.ReadFrom", + "persistConnWriter.Write", + "populateResponse.Write", + "populateResponse.WriteHeader", + "readTrackingBody.Close", + "readTrackingBody.Read", + "readWriteCloserBody.CloseWrite", + "readWriteCloserBody.Read", + "redirectHandler.ServeHTTP", + "response.Flush", + "response.FlushError", + "response.Hijack", + "response.ReadFrom", + "response.Write", + "response.WriteHeader", + "response.WriteString", + "serverHandler.ServeHTTP", + "socksDialer.DialWithConn", + "socksUsernamePassword.Authenticate", + "stringWriter.WriteString", + "timeoutHandler.ServeHTTP", + "timeoutWriter.Write", + "timeoutWriter.WriteHeader", + "transportReadFromServerError.Error", + "unencryptedHTTP2Request.ServeHTTP" + ] + } + ] + } + }, + { + "package": { + "name": "stdlib", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "1.27.0-0" + }, + { + "fixed": "1.27.2" + } + ] + } + ], + "ecosystem_specific": { + "imports": [ + { + "path": "net/http/internal/http2", + "symbols": [ + "ClientConn.Close", + "ClientConn.Ping", + "ClientConn.RoundTrip", + "ClientConn.Shutdown", + "Framer.ReadFrame", + "Framer.ReadFrameForHeader", + "Framer.ReadFrameHeader", + "Framer.WriteContinuation", + "Framer.WriteData", + "Framer.WriteDataPadded", + "Framer.WriteGoAway", + "Framer.WriteHeaders", + "Framer.WritePing", + "Framer.WritePriority", + "Framer.WritePriorityUpdate", + "Framer.WritePushPromise", + "Framer.WriteRSTStream", + "Framer.WriteRawFrame", + "Framer.WriteSettings", + "Framer.WriteSettingsAck", + "Framer.WriteWindowUpdate", + "Framer.readMetaFrame", + "NetHTTPClientConn.Close", + "NetHTTPClientConn.Ping", + "NetHTTPClientConn.RoundTrip", + "ReadFrameHeader", + "Server.GracefulShutdown", + "Server.ServeConn", + "SettingsFrame.ForeachSetting", + "Transport.AddConn", + "Transport.CloseIdleConnections", + "Transport.NewClientConn", + "Transport.RoundTrip", + "Transport.RoundTripOpt", + "bufferedWriter.Flush", + "bufferedWriter.Write", + "bufferedWriterTimeoutWriter.Write", + "chunkWriter.Write", + "clientConnPool.GetClientConn", + "gzipReader.Close", + "gzipReader.Read", + "noDialClientConnPool.GetClientConn", + "requestBody.Close", + "responseWriter.Flush", + "responseWriter.FlushError", + "responseWriter.Push", + "responseWriter.Write", + "responseWriter.WriteHeader", + "responseWriter.WriteString", + "serve400Handler.ServeHTTP", + "serverConn.Flush", + "stickyErrWriter.Write", + "transportResponseBody.Close", + "transportResponseBody.Read" + ] + } + ] + } + }, + { + "package": { + "name": "golang.org/x/net", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.60.0" + } + ] + } + ], + "ecosystem_specific": { + "imports": [ + { + "path": "golang.org/x/net/http2", + "symbols": [ + "ClientConn.Close", + "ClientConn.Ping", + "ClientConn.RoundTrip", + "ClientConn.Shutdown", + "ConfigureServer", + "ConfigureTransport", + "ConfigureTransports", + "ConnectionError.Error", + "ErrCode.String", + "FrameHeader.String", + "FrameType.String", + "FrameWriteRequest.String", + "Framer.ReadFrame", + "Framer.ReadFrameForHeader", + "Framer.ReadFrameHeader", + "Framer.WriteContinuation", + "Framer.WriteData", + "Framer.WriteDataPadded", + "Framer.WriteGoAway", + "Framer.WriteHeaders", + "Framer.WritePing", + "Framer.WritePriority", + "Framer.WritePriorityUpdate", + "Framer.WritePushPromise", + "Framer.WriteRSTStream", + "Framer.WriteRawFrame", + "Framer.WriteSettings", + "Framer.WriteSettingsAck", + "Framer.WriteWindowUpdate", + "Framer.readMetaFrame", + "GoAwayError.Error", + "ReadFrameHeader", + "Server.ServeConn", + "Setting.String", + "SettingID.String", + "SettingsFrame.ForeachSetting", + "StreamError.Error", + "Transport.CloseIdleConnections", + "Transport.NewClientConn", + "Transport.RoundTrip", + "Transport.RoundTripOpt", + "bufferedWriter.Flush", + "bufferedWriter.Write", + "bufferedWriterTimeoutWriter.Write", + "chunkWriter.Write", + "clientConnPool.GetClientConn", + "connError.Error", + "dataBuffer.Read", + "duplicatePseudoHeaderError.Error", + "gzipReader.Close", + "gzipReader.Read", + "headerFieldNameError.Error", + "headerFieldValueError.Error", + "netHTTPClientConn.Close", + "netHTTPClientConn.RoundTrip", + "noDialClientConnPool.GetClientConn", + "noDialH2RoundTripper.NewClientConn", + "noDialH2RoundTripper.RoundTrip", + "pipe.Read", + "priorityWriteSchedulerRFC7540.CloseStream", + "priorityWriteSchedulerRFC7540.OpenStream", + "priorityWriteSchedulerRFC9218.OpenStream", + "pseudoHeaderError.Error", + "requestBody.Close", + "requestBody.Read", + "responseWriter.Flush", + "responseWriter.FlushError", + "responseWriter.Push", + "responseWriter.SetReadDeadline", + "responseWriter.SetWriteDeadline", + "responseWriter.Write", + "responseWriter.WriteHeader", + "responseWriter.WriteString", + "roundRobinWriteScheduler.OpenStream", + "serverConn.CloseConn", + "serverConn.Flush", + "stickyErrWriter.Write", + "transportResponseBody.Close", + "transportResponseBody.Read", + "unencryptedTransport.RoundTrip", + "writeData.String" + ] + } + ] + } + } + ], + "references": [ + { + "type": "FIX", + "url": "https://go.dev/cl/847185" + }, + { + "type": "FIX", + "url": "https://go.dev/cl/847314" + }, + { + "type": "REPORT", + "url": "https://go.dev/issue/81857" + }, + { + "type": "WEB", + "url": "https://groups.google.com/g/golang-announce/c/U2fTuyDJznI" + }, + { + "type": "WEB", + "url": "https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs" + } + ], + "credits": [ + { + "name": "RyotaK (https://ryotak.net) of GMO Flatt Security Inc." + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6603", + "review_status": "REVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6604.json b/data/osv/GO-2026-6604.json new file mode 100644 index 0000000..f71c308 --- /dev/null +++ b/data/osv/GO-2026-6604.json
@@ -0,0 +1,95 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6604", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-56857" + ], + "summary": "Root.Mkdir(All) can follow junctions out of the root on Windows in os", + "details": "On Windows, when the target of Root.Mkdir or Root.MkdirAll is a junction pointing to an empty location, the operation can create a directory at the junction target even when that target is located outside the root. This only applies to operations where the last path component is a junction (path/to/junction, but not path/junction/target).", + "affected": [ + { + "package": { + "name": "stdlib", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.26.9" + }, + { + "introduced": "1.27.0-0" + }, + { + "fixed": "1.27.2" + } + ] + } + ], + "ecosystem_specific": { + "imports": [ + { + "path": "os", + "goos": [ + "windows" + ], + "symbols": [ + "Root.Chmod", + "Root.Chown", + "Root.Chtimes", + "Root.Lchown", + "Root.Link", + "Root.Mkdir", + "Root.MkdirAll", + "Root.Remove", + "Root.RemoveAll", + "Root.Rename", + "Root.Symlink", + "doInRoot", + "rootMkdirAll" + ] + }, + { + "path": "internal/syscall/windows", + "goos": [ + "windows" + ], + "symbols": [ + "Mkdirat" + ] + } + ] + } + } + ], + "references": [ + { + "type": "FIX", + "url": "https://go.dev/cl/847305" + }, + { + "type": "REPORT", + "url": "https://go.dev/issue/81739" + }, + { + "type": "WEB", + "url": "https://groups.google.com/g/golang-announce/c/U2fTuyDJznI" + } + ], + "credits": [ + { + "name": "Daniele Ballarini" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6604", + "review_status": "REVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6605.json b/data/osv/GO-2026-6605.json new file mode 100644 index 0000000..e2fff39 --- /dev/null +++ b/data/osv/GO-2026-6605.json
@@ -0,0 +1,95 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6605", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-56866" + ], + "summary": "HTTP/1 client connection desynchronization after CONNECT rejection in net/http", + "details": "When http.Transport sends an HTTP/1 CONNECT request with a non-empty Request.Body, it writes the body directly to the connection without framing after the request headers. If the server rejects the CONNECT request with a non-2xx keep-alive response, Transport returns the connection to the idle pool. Because CONNECT requests do not have a request body, the server may interpret the trailing body bytes as a subsequent pipelined HTTP/1.1 request on the connection, leaving the pooled connection desynchronized and causing the next caller that reuses it to read the response to the injected request. In reverse proxies (including httputil.ReverseProxy) that forward CONNECT requests through a shared Transport, this can lead to cross-user response poisoning.", + "affected": [ + { + "package": { + "name": "stdlib", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.26.9" + }, + { + "introduced": "1.27.0-0" + }, + { + "fixed": "1.27.2" + } + ] + } + ], + "ecosystem_specific": { + "imports": [ + { + "path": "net/http", + "symbols": [ + "Client.CloseIdleConnections", + "Client.Do", + "Client.Get", + "Client.Head", + "Client.Post", + "Client.PostForm", + "ClientConn.Close", + "ClientConn.RoundTrip", + "Get", + "Head", + "Post", + "PostForm", + "Transport.CloseIdleConnections", + "Transport.NewClientConn", + "Transport.RoundTrip", + "http1ClientConn.Close", + "http1ClientConn.RoundTrip", + "persistConn.readLoop" + ] + }, + { + "path": "net/http/httputil", + "symbols": [ + "DumpRequestOut", + "ReverseProxy.ServeHTTP" + ] + } + ] + } + } + ], + "references": [ + { + "type": "FIX", + "url": "https://go.dev/cl/847306" + }, + { + "type": "REPORT", + "url": "https://go.dev/issue/81740" + }, + { + "type": "WEB", + "url": "https://groups.google.com/g/golang-announce/c/U2fTuyDJznI" + } + ], + "credits": [ + { + "name": "Xclow3n (Rajat Raghav)" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6605", + "review_status": "REVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6607.json b/data/osv/GO-2026-6607.json new file mode 100644 index 0000000..501396b --- /dev/null +++ b/data/osv/GO-2026-6607.json
@@ -0,0 +1,75 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6607", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-97031" + ], + "summary": "Reject malformed ECH outer extension references in crypto/tls", + "details": "Multiple ECH outer extension references are not permitted under RFC 9849; previously, a client could send a well-crafted packet that could trigger memory exhaustion in the server process by specifying multiple references.\n\nWe now reject these as malformed and curb the memory amplification vector as a result.", + "affected": [ + { + "package": { + "name": "stdlib", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.26.9" + }, + { + "introduced": "1.27.0-0" + }, + { + "fixed": "1.27.2" + } + ] + } + ], + "ecosystem_specific": { + "imports": [ + { + "path": "crypto/tls", + "symbols": [ + "Conn.Handshake", + "Conn.HandshakeContext", + "Conn.Read", + "Conn.Write", + "Dial", + "DialWithDialer", + "Dialer.Dial", + "Dialer.DialContext", + "QUICConn.Start", + "decodeInnerClientHello" + ] + } + ] + } + } + ], + "references": [ + { + "type": "FIX", + "url": "https://go.dev/cl/847312" + }, + { + "type": "REPORT", + "url": "https://go.dev/issue/81855" + }, + { + "type": "WEB", + "url": "https://groups.google.com/g/golang-announce/c/U2fTuyDJznI" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6607", + "review_status": "REVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6608.json b/data/osv/GO-2026-6608.json new file mode 100644 index 0000000..da61056 --- /dev/null +++ b/data/osv/GO-2026-6608.json
@@ -0,0 +1,85 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6608", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-94440" + ], + "summary": "Memory limit bypass when parsing MIME headers in net/textproto, mime/multipart", + "details": "Parsing a multipart form can bypass memory limits and read an arbitrarily long line into memory when the remaining limit at the start of a part is less than 400 bytes.", + "affected": [ + { + "package": { + "name": "stdlib", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.26.9" + }, + { + "introduced": "1.27.0-0" + }, + { + "fixed": "1.27.2" + } + ] + } + ], + "ecosystem_specific": { + "imports": [ + { + "path": "net/textproto", + "symbols": [ + "Reader.ReadContinuedLine", + "Reader.ReadContinuedLineBytes", + "Reader.ReadMIMEHeader", + "Reader.readContinuedLineSlice", + "readMIMEHeader" + ] + }, + { + "path": "mime/multipart", + "symbols": [ + "Part.populateHeaders", + "Reader.NextPart", + "Reader.NextRawPart", + "Reader.ReadForm", + "Reader.readForm" + ] + } + ] + } + } + ], + "references": [ + { + "type": "FIX", + "url": "https://go.dev/cl/847307" + }, + { + "type": "REPORT", + "url": "https://go.dev/issue/81741" + }, + { + "type": "WEB", + "url": "https://groups.google.com/g/golang-announce/c/U2fTuyDJznI" + } + ], + "credits": [ + { + "name": "Jakub Ciolek (https://ciolek.dev)" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6608", + "review_status": "REVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6609.json b/data/osv/GO-2026-6609.json new file mode 100644 index 0000000..9539cfc --- /dev/null +++ b/data/osv/GO-2026-6609.json
@@ -0,0 +1,76 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6609", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-78667" + ], + "summary": "Lack of limit on size of parsed Range headers in net/http", + "details": "When parsing a Range header containing a large number of small ranges, FileServer(FS), ServeContent, and ServeFile(FS) can consume an excessive amount of CPU.", + "affected": [ + { + "package": { + "name": "stdlib", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.26.9" + }, + { + "introduced": "1.27.0-0" + }, + { + "fixed": "1.27.2" + } + ] + } + ], + "ecosystem_specific": { + "imports": [ + { + "path": "net/http", + "symbols": [ + "ServeContent", + "ServeFile", + "ServeFileFS", + "fileHandler.ServeHTTP", + "fileTransport.RoundTrip", + "parseRange" + ] + } + ] + } + } + ], + "references": [ + { + "type": "FIX", + "url": "https://go.dev/cl/847309" + }, + { + "type": "REPORT", + "url": "https://go.dev/issue/81858" + }, + { + "type": "WEB", + "url": "https://groups.google.com/g/golang-announce/c/U2fTuyDJznI" + } + ], + "credits": [ + { + "name": "Jakub Ciolek (https://ciolek.dev)" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6609", + "review_status": "REVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6610.json b/data/osv/GO-2026-6610.json new file mode 100644 index 0000000..75803fc --- /dev/null +++ b/data/osv/GO-2026-6610.json
@@ -0,0 +1,166 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6610", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-78660" + ], + "summary": "HTTP/2 transport accepts malformed framing-related headers in net/http", + "details": "Historically, we have been rather lax about malformed framing-related headers in our HTTP/2 implementation, as they cannot interfere with HTTP/2 framing. However, this makes it possible for our HTTP/2 implementation to forward responses containing such headers to an HTTP/1 client when acting as a reverse proxy. If the HTTP/1 client also does not behave strictly enough, this can result in response smuggling.", + "affected": [ + { + "package": { + "name": "stdlib", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.26.9" + } + ] + } + ], + "ecosystem_specific": { + "imports": [ + { + "path": "net/http", + "symbols": [ + "Client.CloseIdleConnections", + "Client.Do", + "Client.Get", + "Client.Head", + "Client.Post", + "Client.PostForm", + "ClientConn.Close", + "ClientConn.RoundTrip", + "Get", + "Head", + "Post", + "PostForm", + "Transport.CloseIdleConnections", + "Transport.NewClientConn", + "Transport.RoundTrip", + "http1ClientConn.Close", + "http1ClientConn.RoundTrip", + "http2Transport.NewClientConn", + "http2Transport.RoundTrip", + "http2Transport.RoundTripOpt", + "http2clientConnPool.GetClientConn", + "http2clientConnReadLoop.handleResponse", + "http2noDialClientConnPool.GetClientConn", + "http2noDialH2RoundTripper.NewClientConn", + "http2noDialH2RoundTripper.RoundTrip", + "http2unencryptedTransport.RoundTrip" + ] + } + ] + } + }, + { + "package": { + "name": "stdlib", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "1.27.0-0" + }, + { + "fixed": "1.27.2" + } + ] + } + ], + "ecosystem_specific": { + "imports": [ + { + "path": "net/http/internal/http2", + "symbols": [ + "Transport.AddConn", + "Transport.NewClientConn", + "Transport.RoundTrip", + "Transport.RoundTripOpt", + "clientConnPool.GetClientConn", + "clientConnReadLoop.handleResponse", + "noDialClientConnPool.GetClientConn" + ] + } + ] + } + }, + { + "package": { + "name": "golang.org/x/net", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.60.0" + } + ] + } + ], + "ecosystem_specific": { + "imports": [ + { + "path": "golang.org/x/net/http2", + "symbols": [ + "Transport.NewClientConn", + "Transport.RoundTrip", + "Transport.RoundTripOpt", + "clientConnPool.GetClientConn", + "clientConnReadLoop.handleResponse", + "noDialClientConnPool.GetClientConn", + "noDialH2RoundTripper.NewClientConn", + "noDialH2RoundTripper.RoundTrip", + "unencryptedTransport.RoundTrip" + ] + } + ] + } + } + ], + "references": [ + { + "type": "FIX", + "url": "https://go.dev/cl/835145" + }, + { + "type": "FIX", + "url": "https://go.dev/cl/836385" + }, + { + "type": "REPORT", + "url": "https://go.dev/issue/81115" + }, + { + "type": "WEB", + "url": "https://groups.google.com/g/golang-announce/c/U2fTuyDJznI" + } + ], + "credits": [ + { + "name": "TJ Barton" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6610", + "review_status": "REVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6611.json b/data/osv/GO-2026-6611.json new file mode 100644 index 0000000..b253d5b --- /dev/null +++ b/data/osv/GO-2026-6611.json
@@ -0,0 +1,539 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6611", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-78669" + ], + "summary": "Excessive CPU consumption from repeated initial window changes in net/http", + "details": "A malicious HTTP/2 peer can cause excessive CPU consumption in the client or server by opening a large number of streams and then sending many small SETTINGS frames containing SETTINGS_INITIAL_WINDOW_SIZE values.", + "affected": [ + { + "package": { + "name": "stdlib", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.26.9" + } + ] + } + ], + "ecosystem_specific": { + "imports": [ + { + "path": "net/http", + "symbols": [ + "CanonicalHeaderKey", + "Client.CloseIdleConnections", + "Client.Do", + "Client.Get", + "Client.Head", + "Client.Post", + "Client.PostForm", + "ClientConn.Close", + "ClientConn.RoundTrip", + "Cookie.String", + "Cookie.Valid", + "CrossOriginProtection.AddInsecureBypassPattern", + "CrossOriginProtection.AddTrustedOrigin", + "CrossOriginProtection.Check", + "Dir.Open", + "Error", + "Get", + "Handle", + "HandleFunc", + "HandlerFunc.ServeHTTP", + "Head", + "Header.Add", + "Header.Del", + "Header.Get", + "Header.Set", + "Header.Values", + "Header.Write", + "Header.WriteSubset", + "ListenAndServe", + "ListenAndServeTLS", + "NewRequest", + "NewRequestWithContext", + "NotFound", + "ParseCookie", + "ParseSetCookie", + "ParseTime", + "Post", + "PostForm", + "ProxyFromEnvironment", + "ReadRequest", + "ReadResponse", + "Redirect", + "Request.AddCookie", + "Request.BasicAuth", + "Request.Cookie", + "Request.Cookies", + "Request.CookiesNamed", + "Request.FormFile", + "Request.FormValue", + "Request.MultipartReader", + "Request.ParseForm", + "Request.ParseMultipartForm", + "Request.PostFormValue", + "Request.Referer", + "Request.SetBasicAuth", + "Request.UserAgent", + "Request.Write", + "Request.WriteProxy", + "Response.Cookies", + "Response.Location", + "Response.Write", + "ResponseController.EnableFullDuplex", + "ResponseController.Flush", + "ResponseController.Hijack", + "ResponseController.SetReadDeadline", + "ResponseController.SetWriteDeadline", + "Serve", + "ServeContent", + "ServeFile", + "ServeFileFS", + "ServeMux.Handle", + "ServeMux.HandleFunc", + "ServeMux.ServeHTTP", + "ServeTLS", + "Server.Close", + "Server.ListenAndServe", + "Server.ListenAndServeTLS", + "Server.Serve", + "Server.ServeTLS", + "Server.SetKeepAlivesEnabled", + "Server.Shutdown", + "SetCookie", + "Transport.CancelRequest", + "Transport.Clone", + "Transport.CloseIdleConnections", + "Transport.NewClientConn", + "Transport.RoundTrip", + "body.Close", + "body.Read", + "bodyEOFSignal.Close", + "bodyEOFSignal.Read", + "bodyLocked.Read", + "bufioFlushWriter.Write", + "cancelTimerBody.Close", + "cancelTimerBody.Read", + "checkConnErrorWriter.Write", + "chunkWriter.Write", + "connReader.Read", + "connectMethodKey.String", + "expectContinueReader.Close", + "expectContinueReader.Read", + "extraHeader.Write", + "fileHandler.ServeHTTP", + "fileTransport.RoundTrip", + "globalOptionsHandler.ServeHTTP", + "gzipReader.Close", + "gzipReader.Read", + "http1ClientConn.Close", + "http1ClientConn.RoundTrip", + "http2ClientConn.Close", + "http2ClientConn.Ping", + "http2ClientConn.RoundTrip", + "http2ClientConn.Shutdown", + "http2ClientConn.addStreamLocked", + "http2ConnectionError.Error", + "http2ErrCode.String", + "http2FrameHeader.String", + "http2FrameType.String", + "http2FrameWriteRequest.Consume", + "http2FrameWriteRequest.String", + "http2Framer.ReadFrame", + "http2Framer.ReadFrameForHeader", + "http2Framer.ReadFrameHeader", + "http2Framer.WriteContinuation", + "http2Framer.WriteData", + "http2Framer.WriteDataPadded", + "http2Framer.WriteGoAway", + "http2Framer.WriteHeaders", + "http2Framer.WritePing", + "http2Framer.WritePriority", + "http2Framer.WritePushPromise", + "http2Framer.WriteRSTStream", + "http2Framer.WriteRawFrame", + "http2Framer.WriteSettings", + "http2Framer.WriteSettingsAck", + "http2Framer.WriteWindowUpdate", + "http2GoAwayError.Error", + "http2Server.ServeConn", + "http2Server.serveConn", + "http2Setting.String", + "http2SettingID.String", + "http2SettingsFrame.ForeachSetting", + "http2StreamError.Error", + "http2Transport.CloseIdleConnections", + "http2Transport.NewClientConn", + "http2Transport.RoundTrip", + "http2Transport.RoundTripOpt", + "http2Transport.newClientConn", + "http2bufferedWriter.Flush", + "http2bufferedWriter.Write", + "http2bufferedWriterTimeoutWriter.Write", + "http2chunkWriter.Write", + "http2clientConnPool.GetClientConn", + "http2clientConnReadLoop.processSettingsNoWrite", + "http2clientConnReadLoop.processWindowUpdate", + "http2clientConnReadLoop.streamByID", + "http2clientStream.awaitFlowControl", + "http2clientStream.cleanupWriteRequest", + "http2connError.Error", + "http2dataBuffer.Read", + "http2duplicatePseudoHeaderError.Error", + "http2gzipReader.Close", + "http2gzipReader.Read", + "http2headerFieldNameError.Error", + "http2headerFieldValueError.Error", + "http2netHTTPClientConn.Close", + "http2netHTTPClientConn.RoundTrip", + "http2noDialClientConnPool.GetClientConn", + "http2noDialH2RoundTripper.NewClientConn", + "http2noDialH2RoundTripper.RoundTrip", + "http2outflow.add", + "http2outflow.available", + "http2outflow.setConnFlow", + "http2outflow.take", + "http2pipe.Read", + "http2priorityWriteSchedulerRFC7540.CloseStream", + "http2priorityWriteSchedulerRFC7540.OpenStream", + "http2priorityWriteSchedulerRFC7540.Pop", + "http2priorityWriteSchedulerRFC9218.OpenStream", + "http2priorityWriteSchedulerRFC9218.Pop", + "http2pseudoHeaderError.Error", + "http2randomWriteScheduler.Pop", + "http2requestBody.Close", + "http2requestBody.Read", + "http2responseWriter.Flush", + "http2responseWriter.FlushError", + "http2responseWriter.Push", + "http2responseWriter.SetReadDeadline", + "http2responseWriter.SetWriteDeadline", + "http2responseWriter.Write", + "http2responseWriter.WriteHeader", + "http2responseWriter.WriteString", + "http2roundRobinWriteScheduler.OpenStream", + "http2roundRobinWriteScheduler.Pop", + "http2serverConn.CloseConn", + "http2serverConn.Flush", + "http2serverConn.newStream", + "http2serverConn.processSettingInitialWindowSize", + "http2serverConn.processWindowUpdate", + "http2serverConn.scheduleFrameWrite", + "http2stickyErrWriter.Write", + "http2transportResponseBody.Close", + "http2transportResponseBody.Read", + "http2unencryptedTransport.RoundTrip", + "http2writeData.String", + "initALPNRequest.ServeHTTP", + "loggingConn.Close", + "loggingConn.Read", + "loggingConn.Write", + "maxBytesReader.Close", + "maxBytesReader.Read", + "onceCloseListener.Close", + "persistConn.Read", + "persistConnWriter.ReadFrom", + "persistConnWriter.Write", + "populateResponse.Write", + "populateResponse.WriteHeader", + "readTrackingBody.Close", + "readTrackingBody.Read", + "readWriteCloserBody.CloseWrite", + "readWriteCloserBody.Read", + "redirectHandler.ServeHTTP", + "response.Flush", + "response.FlushError", + "response.Hijack", + "response.ReadFrom", + "response.Write", + "response.WriteHeader", + "response.WriteString", + "serverHandler.ServeHTTP", + "socksDialer.DialWithConn", + "socksUsernamePassword.Authenticate", + "stringWriter.WriteString", + "timeoutHandler.ServeHTTP", + "timeoutWriter.Write", + "timeoutWriter.WriteHeader", + "transportReadFromServerError.Error", + "unencryptedHTTP2Request.ServeHTTP" + ] + } + ] + } + }, + { + "package": { + "name": "stdlib", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "1.27.0-0" + }, + { + "fixed": "1.27.2" + } + ] + } + ], + "ecosystem_specific": { + "imports": [ + { + "path": "net/http/internal/http2", + "symbols": [ + "ClientConn.Close", + "ClientConn.Ping", + "ClientConn.RoundTrip", + "ClientConn.Shutdown", + "ClientConn.addStreamLocked", + "FrameWriteRequest.Consume", + "Framer.ReadFrame", + "Framer.ReadFrameForHeader", + "Framer.ReadFrameHeader", + "Framer.WriteContinuation", + "Framer.WriteData", + "Framer.WriteDataPadded", + "Framer.WriteGoAway", + "Framer.WriteHeaders", + "Framer.WritePing", + "Framer.WritePriority", + "Framer.WritePriorityUpdate", + "Framer.WritePushPromise", + "Framer.WriteRSTStream", + "Framer.WriteRawFrame", + "Framer.WriteSettings", + "Framer.WriteSettingsAck", + "Framer.WriteWindowUpdate", + "NetHTTPClientConn.Close", + "NetHTTPClientConn.Ping", + "NetHTTPClientConn.RoundTrip", + "ReadFrameHeader", + "Server.GracefulShutdown", + "Server.ServeConn", + "Server.serveConn", + "SettingsFrame.ForeachSetting", + "Transport.AddConn", + "Transport.CloseIdleConnections", + "Transport.NewClientConn", + "Transport.RoundTrip", + "Transport.RoundTripOpt", + "Transport.newClientConn", + "bufferedWriter.Flush", + "bufferedWriter.Write", + "bufferedWriterTimeoutWriter.Write", + "chunkWriter.Write", + "clientConnPool.GetClientConn", + "clientConnReadLoop.processSettingsNoWrite", + "clientConnReadLoop.processWindowUpdate", + "clientConnReadLoop.streamByID", + "clientStream.awaitFlowControl", + "clientStream.cleanupWriteRequest", + "gzipReader.Close", + "gzipReader.Read", + "noDialClientConnPool.GetClientConn", + "outflow.add", + "outflow.available", + "outflow.setConnFlow", + "outflow.take", + "priorityWriteSchedulerRFC9218.Pop", + "requestBody.Close", + "responseWriter.Flush", + "responseWriter.FlushError", + "responseWriter.Push", + "responseWriter.Write", + "responseWriter.WriteHeader", + "responseWriter.WriteString", + "roundRobinWriteScheduler.Pop", + "serve400Handler.ServeHTTP", + "serverConn.Flush", + "serverConn.newStream", + "serverConn.processSettingInitialWindowSize", + "serverConn.processWindowUpdate", + "serverConn.scheduleFrameWrite", + "stickyErrWriter.Write", + "transportResponseBody.Close", + "transportResponseBody.Read" + ] + } + ] + } + }, + { + "package": { + "name": "golang.org/x/net", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.60.0" + } + ] + } + ], + "ecosystem_specific": { + "imports": [ + { + "path": "golang.org/x/net/http2", + "symbols": [ + "ClientConn.Close", + "ClientConn.Ping", + "ClientConn.RoundTrip", + "ClientConn.Shutdown", + "ClientConn.addStreamLocked", + "ConfigureServer", + "ConfigureTransport", + "ConfigureTransports", + "ConnectionError.Error", + "ErrCode.String", + "FrameHeader.String", + "FrameType.String", + "FrameWriteRequest.Consume", + "FrameWriteRequest.String", + "Framer.ReadFrame", + "Framer.ReadFrameForHeader", + "Framer.ReadFrameHeader", + "Framer.WriteContinuation", + "Framer.WriteData", + "Framer.WriteDataPadded", + "Framer.WriteGoAway", + "Framer.WriteHeaders", + "Framer.WritePing", + "Framer.WritePriority", + "Framer.WritePriorityUpdate", + "Framer.WritePushPromise", + "Framer.WriteRSTStream", + "Framer.WriteRawFrame", + "Framer.WriteSettings", + "Framer.WriteSettingsAck", + "Framer.WriteWindowUpdate", + "GoAwayError.Error", + "ReadFrameHeader", + "Server.ServeConn", + "Server.serveConn", + "Setting.String", + "SettingID.String", + "SettingsFrame.ForeachSetting", + "StreamError.Error", + "Transport.CloseIdleConnections", + "Transport.NewClientConn", + "Transport.RoundTrip", + "Transport.RoundTripOpt", + "Transport.newClientConn", + "bufferedWriter.Flush", + "bufferedWriter.Write", + "bufferedWriterTimeoutWriter.Write", + "chunkWriter.Write", + "clientConnPool.GetClientConn", + "clientConnReadLoop.processSettingsNoWrite", + "clientConnReadLoop.processWindowUpdate", + "clientConnReadLoop.streamByID", + "clientStream.awaitFlowControl", + "clientStream.cleanupWriteRequest", + "connError.Error", + "dataBuffer.Read", + "duplicatePseudoHeaderError.Error", + "gzipReader.Close", + "gzipReader.Read", + "headerFieldNameError.Error", + "headerFieldValueError.Error", + "netHTTPClientConn.Close", + "netHTTPClientConn.RoundTrip", + "noDialClientConnPool.GetClientConn", + "noDialH2RoundTripper.NewClientConn", + "noDialH2RoundTripper.RoundTrip", + "outflow.add", + "outflow.available", + "outflow.setConnFlow", + "outflow.take", + "pipe.Read", + "priorityWriteSchedulerRFC7540.CloseStream", + "priorityWriteSchedulerRFC7540.OpenStream", + "priorityWriteSchedulerRFC7540.Pop", + "priorityWriteSchedulerRFC9218.OpenStream", + "priorityWriteSchedulerRFC9218.Pop", + "pseudoHeaderError.Error", + "randomWriteScheduler.Pop", + "requestBody.Close", + "requestBody.Read", + "responseWriter.Flush", + "responseWriter.FlushError", + "responseWriter.Push", + "responseWriter.SetReadDeadline", + "responseWriter.SetWriteDeadline", + "responseWriter.Write", + "responseWriter.WriteHeader", + "responseWriter.WriteString", + "roundRobinWriteScheduler.OpenStream", + "roundRobinWriteScheduler.Pop", + "serverConn.CloseConn", + "serverConn.Flush", + "serverConn.newStream", + "serverConn.processSettingInitialWindowSize", + "serverConn.processWindowUpdate", + "serverConn.scheduleFrameWrite", + "stickyErrWriter.Write", + "transportResponseBody.Close", + "transportResponseBody.Read", + "unencryptedTransport.RoundTrip", + "writeData.String" + ] + } + ] + } + } + ], + "references": [ + { + "type": "FIX", + "url": "https://go.dev/cl/847186" + }, + { + "type": "FIX", + "url": "https://go.dev/cl/847308" + }, + { + "type": "REPORT", + "url": "https://go.dev/issue/81742" + }, + { + "type": "WEB", + "url": "https://groups.google.com/g/golang-announce/c/U2fTuyDJznI" + }, + { + "type": "WEB", + "url": "https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs" + } + ], + "credits": [ + { + "name": "Jakub Ciolek (https://ciolek.dev)" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6611", + "review_status": "REVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6612.json b/data/osv/GO-2026-6612.json new file mode 100644 index 0000000..8b1472d --- /dev/null +++ b/data/osv/GO-2026-6612.json
@@ -0,0 +1,452 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6612", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-78663" + ], + "summary": "Double flow control refund on HTTP/2 server streams in net/http", + "details": "The HTTP/2 server can refund connection-level flow control twice for the same data: Once when a client resets a stream (refunding data for any sent-but-unread portion of the stream), and again when a request handler reads the buffered data. A malicious client can exploit this to bypass the configured connection-level flow control limit (MaxReceiveBufferPerConnection). Total buffered data is still limited by the concurrent stream limit and stream-level flow control.", + "affected": [ + { + "package": { + "name": "stdlib", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.26.9" + } + ] + } + ], + "ecosystem_specific": { + "imports": [ + { + "path": "net/http", + "symbols": [ + "CanonicalHeaderKey", + "Client.CloseIdleConnections", + "Client.Do", + "Client.Get", + "Client.Head", + "Client.Post", + "Client.PostForm", + "ClientConn.Close", + "ClientConn.RoundTrip", + "Cookie.String", + "Cookie.Valid", + "CrossOriginProtection.AddInsecureBypassPattern", + "CrossOriginProtection.AddTrustedOrigin", + "CrossOriginProtection.Check", + "Dir.Open", + "Error", + "Get", + "Handle", + "HandleFunc", + "HandlerFunc.ServeHTTP", + "Head", + "Header.Add", + "Header.Del", + "Header.Get", + "Header.Set", + "Header.Values", + "Header.Write", + "Header.WriteSubset", + "ListenAndServe", + "ListenAndServeTLS", + "NewRequest", + "NewRequestWithContext", + "NotFound", + "ParseCookie", + "ParseSetCookie", + "ParseTime", + "Post", + "PostForm", + "ProxyFromEnvironment", + "ReadRequest", + "ReadResponse", + "Redirect", + "Request.AddCookie", + "Request.BasicAuth", + "Request.Cookie", + "Request.Cookies", + "Request.CookiesNamed", + "Request.FormFile", + "Request.FormValue", + "Request.MultipartReader", + "Request.ParseForm", + "Request.ParseMultipartForm", + "Request.PostFormValue", + "Request.Referer", + "Request.SetBasicAuth", + "Request.UserAgent", + "Request.Write", + "Request.WriteProxy", + "Response.Cookies", + "Response.Location", + "Response.Write", + "ResponseController.EnableFullDuplex", + "ResponseController.Flush", + "ResponseController.Hijack", + "ResponseController.SetReadDeadline", + "ResponseController.SetWriteDeadline", + "Serve", + "ServeContent", + "ServeFile", + "ServeFileFS", + "ServeMux.Handle", + "ServeMux.HandleFunc", + "ServeMux.ServeHTTP", + "ServeTLS", + "Server.Close", + "Server.ListenAndServe", + "Server.ListenAndServeTLS", + "Server.Serve", + "Server.ServeTLS", + "Server.SetKeepAlivesEnabled", + "Server.Shutdown", + "SetCookie", + "Transport.CancelRequest", + "Transport.Clone", + "Transport.CloseIdleConnections", + "Transport.NewClientConn", + "Transport.RoundTrip", + "body.Close", + "body.Read", + "bodyEOFSignal.Close", + "bodyEOFSignal.Read", + "bodyLocked.Read", + "bufioFlushWriter.Write", + "cancelTimerBody.Close", + "cancelTimerBody.Read", + "checkConnErrorWriter.Write", + "chunkWriter.Write", + "connReader.Read", + "connectMethodKey.String", + "expectContinueReader.Close", + "expectContinueReader.Read", + "extraHeader.Write", + "fileHandler.ServeHTTP", + "fileTransport.RoundTrip", + "globalOptionsHandler.ServeHTTP", + "gzipReader.Close", + "gzipReader.Read", + "http1ClientConn.Close", + "http1ClientConn.RoundTrip", + "http2ClientConn.Close", + "http2ClientConn.Ping", + "http2ClientConn.RoundTrip", + "http2ClientConn.Shutdown", + "http2ConnectionError.Error", + "http2ErrCode.String", + "http2FrameHeader.String", + "http2FrameType.String", + "http2FrameWriteRequest.String", + "http2Framer.ReadFrame", + "http2Framer.ReadFrameForHeader", + "http2Framer.ReadFrameHeader", + "http2Framer.WriteContinuation", + "http2Framer.WriteData", + "http2Framer.WriteDataPadded", + "http2Framer.WriteGoAway", + "http2Framer.WriteHeaders", + "http2Framer.WritePing", + "http2Framer.WritePriority", + "http2Framer.WritePushPromise", + "http2Framer.WriteRSTStream", + "http2Framer.WriteRawFrame", + "http2Framer.WriteSettings", + "http2Framer.WriteSettingsAck", + "http2Framer.WriteWindowUpdate", + "http2GoAwayError.Error", + "http2Server.ServeConn", + "http2Setting.String", + "http2SettingID.String", + "http2SettingsFrame.ForeachSetting", + "http2StreamError.Error", + "http2Transport.CloseIdleConnections", + "http2Transport.NewClientConn", + "http2Transport.RoundTrip", + "http2Transport.RoundTripOpt", + "http2bufferedWriter.Flush", + "http2bufferedWriter.Write", + "http2bufferedWriterTimeoutWriter.Write", + "http2chunkWriter.Write", + "http2clientConnPool.GetClientConn", + "http2connError.Error", + "http2dataBuffer.Read", + "http2duplicatePseudoHeaderError.Error", + "http2gzipReader.Close", + "http2gzipReader.Read", + "http2headerFieldNameError.Error", + "http2headerFieldValueError.Error", + "http2netHTTPClientConn.Close", + "http2netHTTPClientConn.RoundTrip", + "http2noDialClientConnPool.GetClientConn", + "http2noDialH2RoundTripper.NewClientConn", + "http2noDialH2RoundTripper.RoundTrip", + "http2pipe.Read", + "http2priorityWriteSchedulerRFC7540.CloseStream", + "http2priorityWriteSchedulerRFC7540.OpenStream", + "http2priorityWriteSchedulerRFC9218.OpenStream", + "http2pseudoHeaderError.Error", + "http2requestBody.Close", + "http2requestBody.Read", + "http2responseWriter.Flush", + "http2responseWriter.FlushError", + "http2responseWriter.Push", + "http2responseWriter.SetReadDeadline", + "http2responseWriter.SetWriteDeadline", + "http2responseWriter.Write", + "http2responseWriter.WriteHeader", + "http2responseWriter.WriteString", + "http2roundRobinWriteScheduler.OpenStream", + "http2serverConn.CloseConn", + "http2serverConn.Flush", + "http2serverConn.closeStream", + "http2serverConn.handlerDone", + "http2serverConn.newWriterAndRequest", + "http2serverConn.newWriterAndRequestNoBody", + "http2serverConn.noteBodyRead", + "http2serverConn.processHeaders", + "http2serverConn.runHandler", + "http2serverConn.scheduleHandler", + "http2stickyErrWriter.Write", + "http2transportResponseBody.Close", + "http2transportResponseBody.Read", + "http2unencryptedTransport.RoundTrip", + "http2writeData.String", + "initALPNRequest.ServeHTTP", + "loggingConn.Close", + "loggingConn.Read", + "loggingConn.Write", + "maxBytesReader.Close", + "maxBytesReader.Read", + "onceCloseListener.Close", + "persistConn.Read", + "persistConnWriter.ReadFrom", + "persistConnWriter.Write", + "populateResponse.Write", + "populateResponse.WriteHeader", + "readTrackingBody.Close", + "readTrackingBody.Read", + "readWriteCloserBody.CloseWrite", + "readWriteCloserBody.Read", + "redirectHandler.ServeHTTP", + "response.Flush", + "response.FlushError", + "response.Hijack", + "response.ReadFrom", + "response.Write", + "response.WriteHeader", + "response.WriteString", + "serverHandler.ServeHTTP", + "socksDialer.DialWithConn", + "socksUsernamePassword.Authenticate", + "stringWriter.WriteString", + "timeoutHandler.ServeHTTP", + "timeoutWriter.Write", + "timeoutWriter.WriteHeader", + "transportReadFromServerError.Error", + "unencryptedHTTP2Request.ServeHTTP" + ] + } + ] + } + }, + { + "package": { + "name": "stdlib", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "1.27.0-0" + }, + { + "fixed": "1.27.2" + } + ] + } + ], + "ecosystem_specific": { + "imports": [ + { + "path": "net/http/internal/http2", + "symbols": [ + "Server.ServeConn", + "requestBody.Close", + "requestBody.Read", + "serverConn.closeStream", + "serverConn.handlerDone", + "serverConn.newWriterAndRequest", + "serverConn.newWriterAndRequestNoBody", + "serverConn.noteBodyRead", + "serverConn.processHeaders", + "serverConn.runHandler", + "serverConn.scheduleHandler" + ] + } + ] + } + }, + { + "package": { + "name": "golang.org/x/net", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.60.0" + } + ] + } + ], + "ecosystem_specific": { + "imports": [ + { + "path": "golang.org/x/net/http2", + "symbols": [ + "ClientConn.Close", + "ClientConn.Ping", + "ClientConn.RoundTrip", + "ClientConn.Shutdown", + "ConfigureServer", + "ConfigureTransport", + "ConfigureTransports", + "ConnectionError.Error", + "ErrCode.String", + "FrameHeader.String", + "FrameType.String", + "FrameWriteRequest.String", + "Framer.ReadFrame", + "Framer.ReadFrameForHeader", + "Framer.ReadFrameHeader", + "Framer.WriteContinuation", + "Framer.WriteData", + "Framer.WriteDataPadded", + "Framer.WriteGoAway", + "Framer.WriteHeaders", + "Framer.WritePing", + "Framer.WritePriority", + "Framer.WritePriorityUpdate", + "Framer.WritePushPromise", + "Framer.WriteRSTStream", + "Framer.WriteRawFrame", + "Framer.WriteSettings", + "Framer.WriteSettingsAck", + "Framer.WriteWindowUpdate", + "GoAwayError.Error", + "ReadFrameHeader", + "Server.ServeConn", + "Setting.String", + "SettingID.String", + "SettingsFrame.ForeachSetting", + "StreamError.Error", + "Transport.CloseIdleConnections", + "Transport.NewClientConn", + "Transport.RoundTrip", + "Transport.RoundTripOpt", + "bufferedWriter.Flush", + "bufferedWriter.Write", + "bufferedWriterTimeoutWriter.Write", + "chunkWriter.Write", + "clientConnPool.GetClientConn", + "connError.Error", + "dataBuffer.Read", + "duplicatePseudoHeaderError.Error", + "gzipReader.Close", + "gzipReader.Read", + "headerFieldNameError.Error", + "headerFieldValueError.Error", + "netHTTPClientConn.Close", + "netHTTPClientConn.RoundTrip", + "noDialClientConnPool.GetClientConn", + "noDialH2RoundTripper.NewClientConn", + "noDialH2RoundTripper.RoundTrip", + "pipe.Read", + "priorityWriteSchedulerRFC7540.CloseStream", + "priorityWriteSchedulerRFC7540.OpenStream", + "priorityWriteSchedulerRFC9218.OpenStream", + "pseudoHeaderError.Error", + "requestBody.Close", + "requestBody.Read", + "responseWriter.Flush", + "responseWriter.FlushError", + "responseWriter.Push", + "responseWriter.SetReadDeadline", + "responseWriter.SetWriteDeadline", + "responseWriter.Write", + "responseWriter.WriteHeader", + "responseWriter.WriteString", + "roundRobinWriteScheduler.OpenStream", + "serverConn.CloseConn", + "serverConn.Flush", + "serverConn.closeStream", + "serverConn.handlerDone", + "serverConn.newWriterAndRequest", + "serverConn.newWriterAndRequestNoBody", + "serverConn.noteBodyRead", + "serverConn.processHeaders", + "serverConn.runHandler", + "serverConn.scheduleHandler", + "stickyErrWriter.Write", + "transportResponseBody.Close", + "transportResponseBody.Read", + "unencryptedTransport.RoundTrip", + "writeData.String" + ] + } + ] + } + } + ], + "references": [ + { + "type": "FIX", + "url": "https://go.dev/cl/847187" + }, + { + "type": "FIX", + "url": "https://go.dev/cl/847310" + }, + { + "type": "REPORT", + "url": "https://go.dev/issue/81743" + }, + { + "type": "WEB", + "url": "https://groups.google.com/g/golang-announce/c/U2fTuyDJznI" + }, + { + "type": "WEB", + "url": "https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs" + } + ], + "credits": [ + { + "name": "Ali Sherif (https://www.linkedin.com/in/ali-sherif-13812b276/)" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6612", + "review_status": "REVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6613.json b/data/osv/GO-2026-6613.json new file mode 100644 index 0000000..c780f41 --- /dev/null +++ b/data/osv/GO-2026-6613.json
@@ -0,0 +1,220 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6613", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-94439" + ], + "summary": "HTTP/1 server connection desynchronization after 2xx CONNECT response in net/http", + "details": "When an HTTP server handler sends a 2xx response to an HTTP/1 CONNECT request and returns without hijacking the connection, the server improperly continues to read and serve requests from the connection. Since a 2xx response to an HTTP/1 CONNECT converts the connection into a tunnel, the server should not treat the connection as continuing to contain HTTP.\n\nThe impact of this misbehavior is mostly limited to potential request smuggling, where an intermediate proxy considers the data on the connection to be tunneled and the server considers it to be HTTP.", + "affected": [ + { + "package": { + "name": "stdlib", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.26.9" + }, + { + "introduced": "1.27.0-0" + }, + { + "fixed": "1.27.2" + } + ] + } + ], + "ecosystem_specific": { + "imports": [ + { + "path": "net/http", + "symbols": [ + "CanonicalHeaderKey", + "Client.CloseIdleConnections", + "Client.Do", + "Client.Get", + "Client.Head", + "Client.Post", + "Client.PostForm", + "ClientConn.Close", + "ClientConn.RoundTrip", + "Cookie.String", + "Cookie.Valid", + "CrossOriginProtection.AddInsecureBypassPattern", + "CrossOriginProtection.AddTrustedOrigin", + "CrossOriginProtection.Check", + "Dir.Open", + "Error", + "Get", + "Handle", + "HandleFunc", + "HandlerFunc.ServeHTTP", + "Head", + "Header.Add", + "Header.Del", + "Header.Get", + "Header.Set", + "Header.Values", + "Header.Write", + "Header.WriteSubset", + "ListenAndServe", + "ListenAndServeTLS", + "NewRequest", + "NewRequestWithContext", + "NotFound", + "ParseCookie", + "ParseSetCookie", + "ParseTime", + "Post", + "PostForm", + "ProxyFromEnvironment", + "ReadRequest", + "ReadResponse", + "Redirect", + "Request.AddCookie", + "Request.BasicAuth", + "Request.Cookie", + "Request.Cookies", + "Request.CookiesNamed", + "Request.FormFile", + "Request.FormValue", + "Request.MultipartReader", + "Request.ParseForm", + "Request.ParseMultipartForm", + "Request.PostFormValue", + "Request.Referer", + "Request.SetBasicAuth", + "Request.UserAgent", + "Request.Write", + "Request.WriteProxy", + "Response.Cookies", + "Response.Location", + "Response.Write", + "ResponseController.EnableFullDuplex", + "ResponseController.Flush", + "ResponseController.Hijack", + "ResponseController.SetReadDeadline", + "ResponseController.SetWriteDeadline", + "Serve", + "ServeContent", + "ServeFile", + "ServeFileFS", + "ServeMux.Handle", + "ServeMux.HandleFunc", + "ServeMux.ServeHTTP", + "ServeTLS", + "Server.Close", + "Server.ListenAndServe", + "Server.ListenAndServeTLS", + "Server.Serve", + "Server.ServeTLS", + "Server.SetKeepAlivesEnabled", + "Server.Shutdown", + "SetCookie", + "Transport.CancelRequest", + "Transport.Clone", + "Transport.CloseIdleConnections", + "Transport.NewClientConn", + "Transport.RoundTrip", + "body.Close", + "body.Read", + "bodyEOFSignal.Close", + "bodyEOFSignal.Read", + "bodyLocked.Read", + "bufioFlushWriter.Write", + "cancelTimerBody.Close", + "cancelTimerBody.Read", + "checkConnErrorWriter.Write", + "chunkWriter.Write", + "chunkWriter.writeHeader", + "connReader.Read", + "connectMethodKey.String", + "expectContinueReader.Close", + "expectContinueReader.Read", + "extraHeader.Write", + "fileHandler.ServeHTTP", + "fileTransport.RoundTrip", + "globalOptionsHandler.ServeHTTP", + "gzipReader.Close", + "gzipReader.Read", + "http1ClientConn.Close", + "http1ClientConn.RoundTrip", + "http2ClientConn.RoundTrip", + "http2Handler.ServeHTTP", + "http2ResponseWriter.Flush", + "http2ResponseWriter.FlushError", + "http2ResponseWriter.Push", + "http2RoundTripper.RoundTrip", + "http3ServerHandler.ServeHTTP", + "initALPNRequest.ServeHTTP", + "loggingConn.Close", + "loggingConn.Read", + "loggingConn.Write", + "maxBytesReader.Close", + "maxBytesReader.Read", + "onceCloseListener.Close", + "persistConn.Read", + "persistConnWriter.ReadFrom", + "persistConnWriter.Write", + "populateResponse.Write", + "populateResponse.WriteHeader", + "readTrackingBody.Close", + "readTrackingBody.Read", + "readWriteCloserBody.CloseWrite", + "readWriteCloserBody.Read", + "redirectHandler.ServeHTTP", + "response.Flush", + "response.FlushError", + "response.Hijack", + "response.ReadFrom", + "response.Write", + "response.WriteHeader", + "response.WriteString", + "serverHandler.ServeHTTP", + "socksDialer.DialWithConn", + "socksUsernamePassword.Authenticate", + "stringWriter.WriteString", + "timeoutHandler.ServeHTTP", + "timeoutWriter.Write", + "timeoutWriter.WriteHeader", + "transportReadFromServerError.Error", + "unencryptedHTTP2Request.ServeHTTP" + ] + } + ] + } + } + ], + "references": [ + { + "type": "FIX", + "url": "https://go.dev/cl/847311" + }, + { + "type": "REPORT", + "url": "https://go.dev/issue/81744" + }, + { + "type": "WEB", + "url": "https://groups.google.com/g/golang-announce/c/U2fTuyDJznI" + } + ], + "credits": [ + { + "name": "Jakub Ciolek (https://ciolek.dev)" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6613", + "review_status": "REVIEWED" + } +} \ No newline at end of file
diff --git a/data/osv/GO-2026-6617.json b/data/osv/GO-2026-6617.json new file mode 100644 index 0000000..9ca2ee6 --- /dev/null +++ b/data/osv/GO-2026-6617.json
@@ -0,0 +1,484 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6617", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-97032" + ], + "summary": "HTTP/2 server crash due to HPACK encoder race in net/http", + "details": "HTTP/2 servers could end up crashing due to inadvertently modifying its HPACK encoder concurrently. This happens because the server modifies the HPACK encoder from two goroutines without synchronization: one uses the encoder to encode a HEADERS frame as part of a response sent to a client and the other modifies the encoder's table size when handling a SETTINGS frame containing SETTINGS_HEADER_TABLE_SIZE that a client sends. A malicious client can repeatedly send a request while changing the header table size to crash the server.", + "affected": [ + { + "package": { + "name": "stdlib", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.26.9" + } + ] + } + ], + "ecosystem_specific": { + "imports": [ + { + "path": "net/http", + "symbols": [ + "CanonicalHeaderKey", + "Client.CloseIdleConnections", + "Client.Do", + "Client.Get", + "Client.Head", + "Client.Post", + "Client.PostForm", + "ClientConn.Close", + "ClientConn.RoundTrip", + "Cookie.String", + "Cookie.Valid", + "CrossOriginProtection.AddInsecureBypassPattern", + "CrossOriginProtection.AddTrustedOrigin", + "CrossOriginProtection.Check", + "Dir.Open", + "Error", + "Get", + "Handle", + "HandleFunc", + "HandlerFunc.ServeHTTP", + "Head", + "Header.Add", + "Header.Del", + "Header.Get", + "Header.Set", + "Header.Values", + "Header.Write", + "Header.WriteSubset", + "ListenAndServe", + "ListenAndServeTLS", + "NewRequest", + "NewRequestWithContext", + "NotFound", + "ParseCookie", + "ParseSetCookie", + "ParseTime", + "Post", + "PostForm", + "ProxyFromEnvironment", + "ReadRequest", + "ReadResponse", + "Redirect", + "Request.AddCookie", + "Request.BasicAuth", + "Request.Cookie", + "Request.Cookies", + "Request.CookiesNamed", + "Request.FormFile", + "Request.FormValue", + "Request.MultipartReader", + "Request.ParseForm", + "Request.ParseMultipartForm", + "Request.PostFormValue", + "Request.Referer", + "Request.SetBasicAuth", + "Request.UserAgent", + "Request.Write", + "Request.WriteProxy", + "Response.Cookies", + "Response.Location", + "Response.Write", + "ResponseController.EnableFullDuplex", + "ResponseController.Flush", + "ResponseController.Hijack", + "ResponseController.SetReadDeadline", + "ResponseController.SetWriteDeadline", + "Serve", + "ServeContent", + "ServeFile", + "ServeFileFS", + "ServeMux.Handle", + "ServeMux.HandleFunc", + "ServeMux.ServeHTTP", + "ServeTLS", + "Server.Close", + "Server.ListenAndServe", + "Server.ListenAndServeTLS", + "Server.Serve", + "Server.ServeTLS", + "Server.SetKeepAlivesEnabled", + "Server.Shutdown", + "SetCookie", + "Transport.CancelRequest", + "Transport.Clone", + "Transport.CloseIdleConnections", + "Transport.NewClientConn", + "Transport.RoundTrip", + "body.Close", + "body.Read", + "bodyEOFSignal.Close", + "bodyEOFSignal.Read", + "bodyLocked.Read", + "bufioFlushWriter.Write", + "cancelTimerBody.Close", + "cancelTimerBody.Read", + "checkConnErrorWriter.Write", + "chunkWriter.Write", + "connReader.Read", + "connectMethodKey.String", + "expectContinueReader.Close", + "expectContinueReader.Read", + "extraHeader.Write", + "fileHandler.ServeHTTP", + "fileTransport.RoundTrip", + "globalOptionsHandler.ServeHTTP", + "gzipReader.Close", + "gzipReader.Read", + "http1ClientConn.Close", + "http1ClientConn.RoundTrip", + "http2ClientConn.Close", + "http2ClientConn.Ping", + "http2ClientConn.RoundTrip", + "http2ClientConn.Shutdown", + "http2ConnectionError.Error", + "http2ErrCode.String", + "http2FrameHeader.String", + "http2FrameType.String", + "http2FrameWriteRequest.String", + "http2Framer.ReadFrame", + "http2Framer.ReadFrameForHeader", + "http2Framer.ReadFrameHeader", + "http2Framer.WriteContinuation", + "http2Framer.WriteData", + "http2Framer.WriteDataPadded", + "http2Framer.WriteGoAway", + "http2Framer.WriteHeaders", + "http2Framer.WritePing", + "http2Framer.WritePriority", + "http2Framer.WritePushPromise", + "http2Framer.WriteRSTStream", + "http2Framer.WriteRawFrame", + "http2Framer.WriteSettings", + "http2Framer.WriteSettingsAck", + "http2Framer.WriteWindowUpdate", + "http2GoAwayError.Error", + "http2Server.ServeConn", + "http2Setting.String", + "http2SettingID.String", + "http2SettingsFrame.ForeachSetting", + "http2StreamError.Error", + "http2Transport.CloseIdleConnections", + "http2Transport.NewClientConn", + "http2Transport.RoundTrip", + "http2Transport.RoundTripOpt", + "http2bufferedWriter.Flush", + "http2bufferedWriter.Write", + "http2bufferedWriterTimeoutWriter.Write", + "http2chunkWriter.Write", + "http2clientConnPool.GetClientConn", + "http2connError.Error", + "http2dataBuffer.Read", + "http2duplicatePseudoHeaderError.Error", + "http2gzipReader.Close", + "http2gzipReader.Read", + "http2headerFieldNameError.Error", + "http2headerFieldValueError.Error", + "http2netHTTPClientConn.Close", + "http2netHTTPClientConn.RoundTrip", + "http2noDialClientConnPool.GetClientConn", + "http2noDialH2RoundTripper.NewClientConn", + "http2noDialH2RoundTripper.RoundTrip", + "http2pipe.Read", + "http2priorityWriteSchedulerRFC7540.CloseStream", + "http2priorityWriteSchedulerRFC7540.OpenStream", + "http2priorityWriteSchedulerRFC9218.OpenStream", + "http2pseudoHeaderError.Error", + "http2requestBody.Close", + "http2requestBody.Read", + "http2responseWriter.Flush", + "http2responseWriter.FlushError", + "http2responseWriter.Push", + "http2responseWriter.SetReadDeadline", + "http2responseWriter.SetWriteDeadline", + "http2responseWriter.Write", + "http2responseWriter.WriteHeader", + "http2responseWriter.WriteString", + "http2roundRobinWriteScheduler.OpenStream", + "http2serverConn.CloseConn", + "http2serverConn.Flush", + "http2serverConn.processSetting", + "http2serverConn.startFrameWrite", + "http2stickyErrWriter.Write", + "http2transportResponseBody.Close", + "http2transportResponseBody.Read", + "http2unencryptedTransport.RoundTrip", + "http2writeData.String", + "initALPNRequest.ServeHTTP", + "loggingConn.Close", + "loggingConn.Read", + "loggingConn.Write", + "maxBytesReader.Close", + "maxBytesReader.Read", + "onceCloseListener.Close", + "persistConn.Read", + "persistConnWriter.ReadFrom", + "persistConnWriter.Write", + "populateResponse.Write", + "populateResponse.WriteHeader", + "readTrackingBody.Close", + "readTrackingBody.Read", + "readWriteCloserBody.CloseWrite", + "readWriteCloserBody.Read", + "redirectHandler.ServeHTTP", + "response.Flush", + "response.FlushError", + "response.Hijack", + "response.ReadFrom", + "response.Write", + "response.WriteHeader", + "response.WriteString", + "serverHandler.ServeHTTP", + "socksDialer.DialWithConn", + "socksUsernamePassword.Authenticate", + "stringWriter.WriteString", + "timeoutHandler.ServeHTTP", + "timeoutWriter.Write", + "timeoutWriter.WriteHeader", + "transportReadFromServerError.Error", + "unencryptedHTTP2Request.ServeHTTP" + ] + } + ] + } + }, + { + "package": { + "name": "stdlib", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "1.27.0-0" + }, + { + "fixed": "1.27.2" + } + ] + } + ], + "ecosystem_specific": { + "imports": [ + { + "path": "net/http/internal/http2", + "symbols": [ + "ClientConn.Close", + "ClientConn.Ping", + "ClientConn.RoundTrip", + "ClientConn.Shutdown", + "Framer.ReadFrame", + "Framer.ReadFrameForHeader", + "Framer.ReadFrameHeader", + "Framer.WriteContinuation", + "Framer.WriteData", + "Framer.WriteDataPadded", + "Framer.WriteGoAway", + "Framer.WriteHeaders", + "Framer.WritePing", + "Framer.WritePriority", + "Framer.WritePriorityUpdate", + "Framer.WritePushPromise", + "Framer.WriteRSTStream", + "Framer.WriteRawFrame", + "Framer.WriteSettings", + "Framer.WriteSettingsAck", + "Framer.WriteWindowUpdate", + "NetHTTPClientConn.Close", + "NetHTTPClientConn.Ping", + "NetHTTPClientConn.RoundTrip", + "ReadFrameHeader", + "Server.GracefulShutdown", + "Server.ServeConn", + "SettingsFrame.ForeachSetting", + "Transport.AddConn", + "Transport.CloseIdleConnections", + "Transport.NewClientConn", + "Transport.RoundTrip", + "Transport.RoundTripOpt", + "bufferedWriter.Flush", + "bufferedWriter.Write", + "bufferedWriterTimeoutWriter.Write", + "chunkWriter.Write", + "clientConnPool.GetClientConn", + "gzipReader.Close", + "gzipReader.Read", + "noDialClientConnPool.GetClientConn", + "requestBody.Close", + "responseWriter.Flush", + "responseWriter.FlushError", + "responseWriter.Push", + "responseWriter.Write", + "responseWriter.WriteHeader", + "responseWriter.WriteString", + "serve400Handler.ServeHTTP", + "serverConn.Flush", + "serverConn.processSetting", + "serverConn.startFrameWrite", + "stickyErrWriter.Write", + "transportResponseBody.Close", + "transportResponseBody.Read" + ] + } + ] + } + }, + { + "package": { + "name": "golang.org/x/net", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.60.0" + } + ] + } + ], + "ecosystem_specific": { + "imports": [ + { + "path": "golang.org/x/net/http2", + "symbols": [ + "ClientConn.Close", + "ClientConn.Ping", + "ClientConn.RoundTrip", + "ClientConn.Shutdown", + "ConfigureServer", + "ConfigureTransport", + "ConfigureTransports", + "ConnectionError.Error", + "ErrCode.String", + "FrameHeader.String", + "FrameType.String", + "FrameWriteRequest.String", + "Framer.ReadFrame", + "Framer.ReadFrameForHeader", + "Framer.ReadFrameHeader", + "Framer.WriteContinuation", + "Framer.WriteData", + "Framer.WriteDataPadded", + "Framer.WriteGoAway", + "Framer.WriteHeaders", + "Framer.WritePing", + "Framer.WritePriority", + "Framer.WritePriorityUpdate", + "Framer.WritePushPromise", + "Framer.WriteRSTStream", + "Framer.WriteRawFrame", + "Framer.WriteSettings", + "Framer.WriteSettingsAck", + "Framer.WriteWindowUpdate", + "GoAwayError.Error", + "ReadFrameHeader", + "Server.ServeConn", + "Setting.String", + "SettingID.String", + "SettingsFrame.ForeachSetting", + "StreamError.Error", + "Transport.CloseIdleConnections", + "Transport.NewClientConn", + "Transport.RoundTrip", + "Transport.RoundTripOpt", + "bufferedWriter.Flush", + "bufferedWriter.Write", + "bufferedWriterTimeoutWriter.Write", + "chunkWriter.Write", + "clientConnPool.GetClientConn", + "connError.Error", + "dataBuffer.Read", + "duplicatePseudoHeaderError.Error", + "gzipReader.Close", + "gzipReader.Read", + "headerFieldNameError.Error", + "headerFieldValueError.Error", + "netHTTPClientConn.Close", + "netHTTPClientConn.RoundTrip", + "noDialClientConnPool.GetClientConn", + "noDialH2RoundTripper.NewClientConn", + "noDialH2RoundTripper.RoundTrip", + "pipe.Read", + "priorityWriteSchedulerRFC7540.CloseStream", + "priorityWriteSchedulerRFC7540.OpenStream", + "priorityWriteSchedulerRFC9218.OpenStream", + "pseudoHeaderError.Error", + "requestBody.Close", + "requestBody.Read", + "responseWriter.Flush", + "responseWriter.FlushError", + "responseWriter.Push", + "responseWriter.SetReadDeadline", + "responseWriter.SetWriteDeadline", + "responseWriter.Write", + "responseWriter.WriteHeader", + "responseWriter.WriteString", + "roundRobinWriteScheduler.OpenStream", + "serverConn.CloseConn", + "serverConn.Flush", + "serverConn.processSetting", + "serverConn.startFrameWrite", + "stickyErrWriter.Write", + "transportResponseBody.Close", + "transportResponseBody.Read", + "unencryptedTransport.RoundTrip", + "writeData.String" + ] + } + ] + } + } + ], + "references": [ + { + "type": "FIX", + "url": "https://go.dev/cl/847188" + }, + { + "type": "FIX", + "url": "https://go.dev/cl/847313" + }, + { + "type": "REPORT", + "url": "https://go.dev/issue/81867" + }, + { + "type": "WEB", + "url": "https://groups.google.com/g/golang-announce/c/U2fTuyDJznI" + }, + { + "type": "WEB", + "url": "https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs" + } + ], + "credits": [ + { + "name": "RyotaK (https://ryotak.net) of GMO Flatt Security Inc." + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6617", + "review_status": "REVIEWED" + } +} \ No newline at end of file
diff --git a/data/reports/GO-2026-6599.yaml b/data/reports/GO-2026-6599.yaml new file mode 100644 index 0000000..3b3d3cb --- /dev/null +++ b/data/reports/GO-2026-6599.yaml
@@ -0,0 +1,37 @@ +id: GO-2026-6599 +modules: + - module: std + versions: + - fixed: 1.26.9 + - introduced: 1.27.0-0 + - fixed: 1.27.2 + vulnerable_at: 1.27.1 + packages: + - package: html/template + symbols: + - tJSTmpl + derived_symbols: + - Template.Execute + - Template.ExecuteTemplate +summary: Reset context tracking on consecutive template expressions in html/template +description: |- + When a JavaScript template literal contains + consecutive expressions, the context tracking + state was not properly reset upon entering a + new expression. + + We now ensure that template-literal expression + entries correctly reset context variables so all + subsequent regular expression literals are + accurately recognized and escaped. +references: + - fix: https://go.dev/cl/839866 + - report: https://go.dev/issue/81821 + - web: https://groups.google.com/g/golang-announce/c/U2fTuyDJznI +cve_metadata: + id: CVE-2026-94448 + cwe: 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site Scripting'')' +source: + id: go-security-team + created: 2026-10-08T00:00:00Z +review_status: REVIEWED
diff --git a/data/reports/GO-2026-6600.yaml b/data/reports/GO-2026-6600.yaml new file mode 100644 index 0000000..973d450 --- /dev/null +++ b/data/reports/GO-2026-6600.yaml
@@ -0,0 +1,34 @@ +id: GO-2026-6600 +modules: + - module: std + versions: + - fixed: 1.26.9 + - introduced: 1.27.0-0 + - fixed: 1.27.2 + vulnerable_at: 1.27.1 + packages: + - package: html/template + symbols: + - nextJSCtx + - tJS + derived_symbols: + - Template.Execute + - Template.ExecuteTemplate +summary: Recognize yield as regexp preceder keyword in html/template +description: |- + A trusted template author may have previously written a valid template wherein + the use of the 'yield' keyword would not be correctly escaped. + + We now ensure that valid keyword uses are escaped and non-keyword uses are not + escaped. +references: + - fix: https://go.dev/cl/840925 + - report: https://go.dev/issue/81823 + - web: https://groups.google.com/g/golang-announce/c/U2fTuyDJznI +cve_metadata: + id: CVE-2026-97030 + cwe: 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site Scripting'')' +source: + id: go-security-team + created: 2026-10-08T00:00:00Z +review_status: REVIEWED
diff --git a/data/reports/GO-2026-6601.yaml b/data/reports/GO-2026-6601.yaml new file mode 100644 index 0000000..6a19312 --- /dev/null +++ b/data/reports/GO-2026-6601.yaml
@@ -0,0 +1,33 @@ +id: GO-2026-6601 +modules: + - module: cmd + versions: + - fixed: 1.26.9 + - introduced: 1.27.0-0 + - fixed: 1.27.2 + vulnerable_at: 1.27.1 + packages: + - package: cmd/go +summary: Checksum bypass for golang.org/fips140 in cmd/go +description: |- + Previously, a user operating inside of a malicious + Go project that defines a bogus golang.org/fips140 + and operates a malicious GOMODPROXY the user chooses + to connect to can serve an arbitrary module in its + place. + + We now unpack the trusted ziphash for the bundled + golang.org/fips140 module and construct its entry + in the GOMODCACHE such that it can be verified by + the toolchain. +references: + - fix: https://go.dev/cl/840685 + - report: https://go.dev/issue/81833 + - web: https://groups.google.com/g/golang-announce/c/U2fTuyDJznI +cve_metadata: + id: CVE-2026-94444 + cwe: 'CWE-354: Improper Validation of Integrity Check Value' +source: + id: go-security-team + created: 2026-10-08T00:00:00Z +review_status: REVIEWED
diff --git a/data/reports/GO-2026-6602.yaml b/data/reports/GO-2026-6602.yaml new file mode 100644 index 0000000..37dc327 --- /dev/null +++ b/data/reports/GO-2026-6602.yaml
@@ -0,0 +1,30 @@ +id: GO-2026-6602 +modules: + - module: cmd + versions: + - fixed: 1.26.9 + - introduced: 1.27.0-0 + - fixed: 1.27.2 + vulnerable_at: 1.27.1 + packages: + - package: cmd/go +summary: Checksum database bypass for golang.org/toolchain in cmd/go +description: |- + Previously, a user operating inside of a malicious + Go project that defines a bogus golang.org/toolchain + go.sum entry and operates a malicious GOMODPROXY the + user chooses to use can bypass the intended checksum. + + We now ensure that golang.org/toolchain always goes + to the network for the canonical checksum. +references: + - fix: https://go.dev/cl/840785 + - report: https://go.dev/issue/81834 + - web: https://groups.google.com/g/golang-announce/c/U2fTuyDJznI +cve_metadata: + id: CVE-2026-94447 + cwe: 'CWE-354: Improper Validation of Integrity Check Value' +source: + id: go-security-team + created: 2026-10-08T00:00:00Z +review_status: REVIEWED
diff --git a/data/reports/GO-2026-6603.yaml b/data/reports/GO-2026-6603.yaml new file mode 100644 index 0000000..18d6bf2 --- /dev/null +++ b/data/reports/GO-2026-6603.yaml
@@ -0,0 +1,407 @@ +id: GO-2026-6603 +modules: + - module: std + versions: + - fixed: 1.26.9 + vulnerable_at: 1.26.8 + packages: + - package: net/http + symbols: + - http2Framer.readMetaFrame + derived_symbols: + - CanonicalHeaderKey + - Client.CloseIdleConnections + - Client.Do + - Client.Get + - Client.Head + - Client.Post + - Client.PostForm + - ClientConn.Close + - ClientConn.RoundTrip + - Cookie.String + - Cookie.Valid + - CrossOriginProtection.AddInsecureBypassPattern + - CrossOriginProtection.AddTrustedOrigin + - CrossOriginProtection.Check + - Dir.Open + - Error + - Get + - Handle + - HandleFunc + - HandlerFunc.ServeHTTP + - Head + - Header.Add + - Header.Del + - Header.Get + - Header.Set + - Header.Values + - Header.Write + - Header.WriteSubset + - ListenAndServe + - ListenAndServeTLS + - NewRequest + - NewRequestWithContext + - NotFound + - ParseCookie + - ParseSetCookie + - ParseTime + - Post + - PostForm + - ProxyFromEnvironment + - ReadRequest + - ReadResponse + - Redirect + - Request.AddCookie + - Request.BasicAuth + - Request.Cookie + - Request.Cookies + - Request.CookiesNamed + - Request.FormFile + - Request.FormValue + - Request.MultipartReader + - Request.ParseForm + - Request.ParseMultipartForm + - Request.PostFormValue + - Request.Referer + - Request.SetBasicAuth + - Request.UserAgent + - Request.Write + - Request.WriteProxy + - Response.Cookies + - Response.Location + - Response.Write + - ResponseController.EnableFullDuplex + - ResponseController.Flush + - ResponseController.Hijack + - ResponseController.SetReadDeadline + - ResponseController.SetWriteDeadline + - Serve + - ServeContent + - ServeFile + - ServeFileFS + - ServeMux.Handle + - ServeMux.HandleFunc + - ServeMux.ServeHTTP + - ServeTLS + - Server.Close + - Server.ListenAndServe + - Server.ListenAndServeTLS + - Server.Serve + - Server.ServeTLS + - Server.SetKeepAlivesEnabled + - Server.Shutdown + - SetCookie + - Transport.CancelRequest + - Transport.Clone + - Transport.CloseIdleConnections + - Transport.NewClientConn + - Transport.RoundTrip + - body.Close + - body.Read + - bodyEOFSignal.Close + - bodyEOFSignal.Read + - bodyLocked.Read + - bufioFlushWriter.Write + - cancelTimerBody.Close + - cancelTimerBody.Read + - checkConnErrorWriter.Write + - chunkWriter.Write + - connReader.Read + - connectMethodKey.String + - expectContinueReader.Close + - expectContinueReader.Read + - extraHeader.Write + - fileHandler.ServeHTTP + - fileTransport.RoundTrip + - globalOptionsHandler.ServeHTTP + - gzipReader.Close + - gzipReader.Read + - http1ClientConn.Close + - http1ClientConn.RoundTrip + - http2ClientConn.Close + - http2ClientConn.Ping + - http2ClientConn.RoundTrip + - http2ClientConn.Shutdown + - http2ConnectionError.Error + - http2ErrCode.String + - http2FrameHeader.String + - http2FrameType.String + - http2FrameWriteRequest.String + - http2Framer.ReadFrame + - http2Framer.ReadFrameForHeader + - http2Framer.ReadFrameHeader + - http2Framer.WriteContinuation + - http2Framer.WriteData + - http2Framer.WriteDataPadded + - http2Framer.WriteGoAway + - http2Framer.WriteHeaders + - http2Framer.WritePing + - http2Framer.WritePriority + - http2Framer.WritePushPromise + - http2Framer.WriteRSTStream + - http2Framer.WriteRawFrame + - http2Framer.WriteSettings + - http2Framer.WriteSettingsAck + - http2Framer.WriteWindowUpdate + - http2GoAwayError.Error + - http2Server.ServeConn + - http2Setting.String + - http2SettingID.String + - http2SettingsFrame.ForeachSetting + - http2StreamError.Error + - http2Transport.CloseIdleConnections + - http2Transport.NewClientConn + - http2Transport.RoundTrip + - http2Transport.RoundTripOpt + - http2bufferedWriter.Flush + - http2bufferedWriter.Write + - http2bufferedWriterTimeoutWriter.Write + - http2chunkWriter.Write + - http2clientConnPool.GetClientConn + - http2connError.Error + - http2dataBuffer.Read + - http2duplicatePseudoHeaderError.Error + - http2gzipReader.Close + - http2gzipReader.Read + - http2headerFieldNameError.Error + - http2headerFieldValueError.Error + - http2netHTTPClientConn.Close + - http2netHTTPClientConn.RoundTrip + - http2noDialClientConnPool.GetClientConn + - http2noDialH2RoundTripper.NewClientConn + - http2noDialH2RoundTripper.RoundTrip + - http2pipe.Read + - http2priorityWriteSchedulerRFC7540.CloseStream + - http2priorityWriteSchedulerRFC7540.OpenStream + - http2priorityWriteSchedulerRFC9218.OpenStream + - http2pseudoHeaderError.Error + - http2requestBody.Close + - http2requestBody.Read + - http2responseWriter.Flush + - http2responseWriter.FlushError + - http2responseWriter.Push + - http2responseWriter.SetReadDeadline + - http2responseWriter.SetWriteDeadline + - http2responseWriter.Write + - http2responseWriter.WriteHeader + - http2responseWriter.WriteString + - http2roundRobinWriteScheduler.OpenStream + - http2serverConn.CloseConn + - http2serverConn.Flush + - http2stickyErrWriter.Write + - http2transportResponseBody.Close + - http2transportResponseBody.Read + - http2unencryptedTransport.RoundTrip + - http2writeData.String + - initALPNRequest.ServeHTTP + - loggingConn.Close + - loggingConn.Read + - loggingConn.Write + - maxBytesReader.Close + - maxBytesReader.Read + - onceCloseListener.Close + - persistConn.Read + - persistConnWriter.ReadFrom + - persistConnWriter.Write + - populateResponse.Write + - populateResponse.WriteHeader + - readTrackingBody.Close + - readTrackingBody.Read + - readWriteCloserBody.CloseWrite + - readWriteCloserBody.Read + - redirectHandler.ServeHTTP + - response.Flush + - response.FlushError + - response.Hijack + - response.ReadFrom + - response.Write + - response.WriteHeader + - response.WriteString + - serverHandler.ServeHTTP + - socksDialer.DialWithConn + - socksUsernamePassword.Authenticate + - stringWriter.WriteString + - timeoutHandler.ServeHTTP + - timeoutWriter.Write + - timeoutWriter.WriteHeader + - transportReadFromServerError.Error + - unencryptedHTTP2Request.ServeHTTP + - module: std + versions: + - introduced: 1.27.0-0 + - fixed: 1.27.2 + vulnerable_at: 1.27.1 + packages: + - package: net/http/internal/http2 + symbols: + - Framer.readMetaFrame + derived_symbols: + - ClientConn.Close + - ClientConn.Ping + - ClientConn.RoundTrip + - ClientConn.Shutdown + - Framer.ReadFrame + - Framer.ReadFrameForHeader + - Framer.ReadFrameHeader + - Framer.WriteContinuation + - Framer.WriteData + - Framer.WriteDataPadded + - Framer.WriteGoAway + - Framer.WriteHeaders + - Framer.WritePing + - Framer.WritePriority + - Framer.WritePriorityUpdate + - Framer.WritePushPromise + - Framer.WriteRSTStream + - Framer.WriteRawFrame + - Framer.WriteSettings + - Framer.WriteSettingsAck + - Framer.WriteWindowUpdate + - NetHTTPClientConn.Close + - NetHTTPClientConn.Ping + - NetHTTPClientConn.RoundTrip + - ReadFrameHeader + - Server.GracefulShutdown + - Server.ServeConn + - SettingsFrame.ForeachSetting + - Transport.AddConn + - Transport.CloseIdleConnections + - Transport.NewClientConn + - Transport.RoundTrip + - Transport.RoundTripOpt + - bufferedWriter.Flush + - bufferedWriter.Write + - bufferedWriterTimeoutWriter.Write + - chunkWriter.Write + - clientConnPool.GetClientConn + - gzipReader.Close + - gzipReader.Read + - noDialClientConnPool.GetClientConn + - requestBody.Close + - responseWriter.Flush + - responseWriter.FlushError + - responseWriter.Push + - responseWriter.Write + - responseWriter.WriteHeader + - responseWriter.WriteString + - serve400Handler.ServeHTTP + - serverConn.Flush + - stickyErrWriter.Write + - transportResponseBody.Close + - transportResponseBody.Read + - module: golang.org/x/net + versions: + - fixed: 0.60.0 + vulnerable_at: 0.59.0 + packages: + - package: golang.org/x/net/http2 + symbols: + - Framer.readMetaFrame + derived_symbols: + - ClientConn.Close + - ClientConn.Ping + - ClientConn.RoundTrip + - ClientConn.Shutdown + - ConfigureServer + - ConfigureTransport + - ConfigureTransports + - ConnectionError.Error + - ErrCode.String + - FrameHeader.String + - FrameType.String + - FrameWriteRequest.String + - Framer.ReadFrame + - Framer.ReadFrameForHeader + - Framer.ReadFrameHeader + - Framer.WriteContinuation + - Framer.WriteData + - Framer.WriteDataPadded + - Framer.WriteGoAway + - Framer.WriteHeaders + - Framer.WritePing + - Framer.WritePriority + - Framer.WritePriorityUpdate + - Framer.WritePushPromise + - Framer.WriteRSTStream + - Framer.WriteRawFrame + - Framer.WriteSettings + - Framer.WriteSettingsAck + - Framer.WriteWindowUpdate + - GoAwayError.Error + - ReadFrameHeader + - Server.ServeConn + - Setting.String + - SettingID.String + - SettingsFrame.ForeachSetting + - StreamError.Error + - Transport.CloseIdleConnections + - Transport.NewClientConn + - Transport.RoundTrip + - Transport.RoundTripOpt + - bufferedWriter.Flush + - bufferedWriter.Write + - bufferedWriterTimeoutWriter.Write + - chunkWriter.Write + - clientConnPool.GetClientConn + - connError.Error + - dataBuffer.Read + - duplicatePseudoHeaderError.Error + - gzipReader.Close + - gzipReader.Read + - headerFieldNameError.Error + - headerFieldValueError.Error + - netHTTPClientConn.Close + - netHTTPClientConn.RoundTrip + - noDialClientConnPool.GetClientConn + - noDialH2RoundTripper.NewClientConn + - noDialH2RoundTripper.RoundTrip + - pipe.Read + - priorityWriteSchedulerRFC7540.CloseStream + - priorityWriteSchedulerRFC7540.OpenStream + - priorityWriteSchedulerRFC9218.OpenStream + - pseudoHeaderError.Error + - requestBody.Close + - requestBody.Read + - responseWriter.Flush + - responseWriter.FlushError + - responseWriter.Push + - responseWriter.SetReadDeadline + - responseWriter.SetWriteDeadline + - responseWriter.Write + - responseWriter.WriteHeader + - responseWriter.WriteString + - roundRobinWriteScheduler.OpenStream + - serverConn.CloseConn + - serverConn.Flush + - stickyErrWriter.Write + - transportResponseBody.Close + - transportResponseBody.Read + - unencryptedTransport.RoundTrip + - writeData.String +summary: HTTP/2 server memory exhaustion due to Trailer headers in net/http +description: |- + When "Trailer" headers are sent by a client, the HTTP server internally + uses the header values to populate the Request.Trailer map passed to the + server handler. Because Request.Trailer is a map, each entry incurs + memory overhead. For HTTP/2 servers, a malicious client can exploit this + by sending a "Trailer" header that declares a large number of fields, + causing the server to allocate a disproportionate amount of memory while + bypassing Server.MaxHeaderValueCount and Server.MaxHeaderBytes limits. + This exploit is not applicable for HTTP/1 servers, which do not support + multiplexing a large number of requests over one TCP connection, and + whose Server.MaxHeaderBytes are calculated differently. +credits: + - RyotaK (https://ryotak.net) of GMO Flatt Security Inc. +references: + - fix: https://go.dev/cl/847185 + - fix: https://go.dev/cl/847314 + - report: https://go.dev/issue/81857 + - web: https://groups.google.com/g/golang-announce/c/U2fTuyDJznI + - web: https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs +cve_metadata: + id: CVE-2026-78659 + cwe: 'CWE-405: Asymmetric Resource Consumption (Amplification)' +source: + id: go-security-team + created: 2026-10-08T00:00:00Z +review_status: REVIEWED
diff --git a/data/reports/GO-2026-6604.yaml b/data/reports/GO-2026-6604.yaml new file mode 100644 index 0000000..509a69a --- /dev/null +++ b/data/reports/GO-2026-6604.yaml
@@ -0,0 +1,52 @@ +id: GO-2026-6604 +modules: + - module: std + versions: + - fixed: 1.26.9 + - introduced: 1.27.0-0 + - fixed: 1.27.2 + vulnerable_at: 1.27.1 + packages: + - package: os + goos: + - windows + symbols: + - Root.Mkdir + - doInRoot + - rootMkdirAll + derived_symbols: + - Root.Chmod + - Root.Chown + - Root.Chtimes + - Root.Lchown + - Root.Link + - Root.MkdirAll + - Root.Remove + - Root.RemoveAll + - Root.Rename + - Root.Symlink + - package: internal/syscall/windows + goos: + - windows + symbols: + - Mkdirat +summary: Root.Mkdir(All) can follow junctions out of the root on Windows in os +description: |- + On Windows, when the target of Root.Mkdir or Root.MkdirAll is a junction + pointing to an empty location, the operation can create a directory at + the junction target even when that target is located outside the root. + This only applies to operations where the last path component is a + junction (path/to/junction, but not path/junction/target). +credits: + - Daniele Ballarini +references: + - fix: https://go.dev/cl/847305 + - report: https://go.dev/issue/81739 + - web: https://groups.google.com/g/golang-announce/c/U2fTuyDJznI +cve_metadata: + id: CVE-2026-56857 + cwe: 'CWE-1386: Insecure Operation on Windows Junction / Mount Point' +source: + id: go-security-team + created: 2026-10-08T00:00:00Z +review_status: REVIEWED
diff --git a/data/reports/GO-2026-6605.yaml b/data/reports/GO-2026-6605.yaml new file mode 100644 index 0000000..94038ce --- /dev/null +++ b/data/reports/GO-2026-6605.yaml
@@ -0,0 +1,61 @@ +id: GO-2026-6605 +modules: + - module: std + versions: + - fixed: 1.26.9 + - introduced: 1.27.0-0 + - fixed: 1.27.2 + vulnerable_at: 1.27.1 + packages: + - package: net/http + symbols: + - persistConn.readLoop + derived_symbols: + - Client.CloseIdleConnections + - Client.Do + - Client.Get + - Client.Head + - Client.Post + - Client.PostForm + - ClientConn.Close + - ClientConn.RoundTrip + - Get + - Head + - Post + - PostForm + - Transport.CloseIdleConnections + - Transport.NewClientConn + - Transport.RoundTrip + - http1ClientConn.Close + - http1ClientConn.RoundTrip + - package: net/http/httputil + symbols: + - ReverseProxy.ServeHTTP + derived_symbols: + - DumpRequestOut +summary: HTTP/1 client connection desynchronization after CONNECT rejection in net/http +description: |- + When http.Transport sends an HTTP/1 CONNECT request with a non-empty + Request.Body, it writes the body directly to the connection without + framing after the request headers. If the server rejects the CONNECT + request with a non-2xx keep-alive response, Transport returns the + connection to the idle pool. Because CONNECT requests do not have a + request body, the server may interpret the trailing body bytes as a + subsequent pipelined HTTP/1.1 request on the connection, leaving the + pooled connection desynchronized and causing the next caller that reuses + it to read the response to the injected request. In reverse proxies + (including httputil.ReverseProxy) that forward CONNECT requests through + a shared Transport, this can lead to cross-user response poisoning. +credits: + - Xclow3n (Rajat Raghav) +references: + - fix: https://go.dev/cl/847306 + - report: https://go.dev/issue/81740 + - web: https://groups.google.com/g/golang-announce/c/U2fTuyDJznI +cve_metadata: + id: CVE-2026-56866 + cwe: 'CWE-444: Inconsistent Interpretation of HTTP Requests (''HTTP Request/Response Smuggling'')' +source: + id: go-security-team + created: 2026-10-08T00:00:00Z +review_status: REVIEWED
diff --git a/data/reports/GO-2026-6607.yaml b/data/reports/GO-2026-6607.yaml new file mode 100644 index 0000000..42f2e59 --- /dev/null +++ b/data/reports/GO-2026-6607.yaml
@@ -0,0 +1,43 @@ +id: GO-2026-6607 +modules: + - module: std + versions: + - fixed: 1.26.9 + - introduced: 1.27.0-0 + - fixed: 1.27.2 + vulnerable_at: 1.27.1 + packages: + - package: crypto/tls + symbols: + - decodeInnerClientHello + derived_symbols: + - Conn.Handshake + - Conn.HandshakeContext + - Conn.Read + - Conn.Write + - Dial + - DialWithDialer + - Dialer.Dial + - Dialer.DialContext + - QUICConn.Start +summary: Reject malformed ECH outer extension references in crypto/tls +description: |- + Multiple ECH outer extension references are not + permitted under RFC 9849; previously, a client + could send a well-crafted packet that could + trigger memory exhaustion in the server process + by specifying multiple references. + + We now reject these as malformed and curb the + memory amplification vector as a result. +references: + - fix: https://go.dev/cl/847312 + - report: https://go.dev/issue/81855 + - web: https://groups.google.com/g/golang-announce/c/U2fTuyDJznI +cve_metadata: + id: CVE-2026-97031 + cwe: 'CWE-405: Asymmetric Resource Consumption' +source: + id: go-security-team + created: 2026-10-08T00:00:00Z +review_status: REVIEWED
diff --git a/data/reports/GO-2026-6608.yaml b/data/reports/GO-2026-6608.yaml new file mode 100644 index 0000000..01758e7 --- /dev/null +++ b/data/reports/GO-2026-6608.yaml
@@ -0,0 +1,43 @@ +id: GO-2026-6608 +modules: + - module: std + versions: + - fixed: 1.26.9 + - introduced: 1.27.0-0 + - fixed: 1.27.2 + vulnerable_at: 1.27.1 + packages: + - package: net/textproto + symbols: + - readMIMEHeader + - Reader.readContinuedLineSlice + derived_symbols: + - Reader.ReadContinuedLine + - Reader.ReadContinuedLineBytes + - Reader.ReadMIMEHeader + - package: mime/multipart + symbols: + - Part.populateHeaders + - Reader.readForm + derived_symbols: + - Reader.NextPart + - Reader.NextRawPart + - Reader.ReadForm +summary: Memory limit bypass when parsing MIME headers in net/textproto, mime/multipart +description: |- + Parsing a multipart form can bypass memory limits and read an + arbitrarily long line into memory when the remaining limit at the + start of a part is less than 400 bytes. +credits: + - Jakub Ciolek (https://ciolek.dev) +references: + - fix: https://go.dev/cl/847307 + - report: https://go.dev/issue/81741 + - web: https://groups.google.com/g/golang-announce/c/U2fTuyDJznI +cve_metadata: + id: CVE-2026-94440 + cwe: 'CWE-770: Allocation of Resources Without Limits or Throttling' +source: + id: go-security-team + created: 2026-10-08T00:00:00Z +review_status: REVIEWED
diff --git a/data/reports/GO-2026-6609.yaml b/data/reports/GO-2026-6609.yaml new file mode 100644 index 0000000..a82558b --- /dev/null +++ b/data/reports/GO-2026-6609.yaml
@@ -0,0 +1,36 @@ +id: GO-2026-6609 +modules: + - module: std + versions: + - fixed: 1.26.9 + - introduced: 1.27.0-0 + - fixed: 1.27.2 + vulnerable_at: 1.27.1 + packages: + - package: net/http + symbols: + - parseRange + derived_symbols: + - ServeContent + - ServeFile + - ServeFileFS + - fileHandler.ServeHTTP + - fileTransport.RoundTrip +summary: Lack of limit on size of parsed Range headers in net/http +description: |- + When parsing a Range header containing a large number of small ranges, + FileServer(FS), ServeContent, and ServeFile(FS) can consume an excessive + amount of CPU. +credits: + - Jakub Ciolek (https://ciolek.dev) +references: + - fix: https://go.dev/cl/847309 + - report: https://go.dev/issue/81858 + - web: https://groups.google.com/g/golang-announce/c/U2fTuyDJznI +cve_metadata: + id: CVE-2026-78667 + cwe: 'CWE-770: Allocation of Resources Without Limits or Throttling' +source: + id: go-security-team + created: 2026-10-08T00:00:00Z +review_status: REVIEWED
diff --git a/data/reports/GO-2026-6610.yaml b/data/reports/GO-2026-6610.yaml new file mode 100644 index 0000000..7973693 --- /dev/null +++ b/data/reports/GO-2026-6610.yaml
@@ -0,0 +1,91 @@ +id: GO-2026-6610 +modules: + - module: std + versions: + - fixed: 1.26.9 + vulnerable_at: 1.26.8 + packages: + - package: net/http + symbols: + - http2clientConnReadLoop.handleResponse + derived_symbols: + - Client.CloseIdleConnections + - Client.Do + - Client.Get + - Client.Head + - Client.Post + - Client.PostForm + - ClientConn.Close + - ClientConn.RoundTrip + - Get + - Head + - Post + - PostForm + - Transport.CloseIdleConnections + - Transport.NewClientConn + - Transport.RoundTrip + - http1ClientConn.Close + - http1ClientConn.RoundTrip + - http2Transport.NewClientConn + - http2Transport.RoundTrip + - http2Transport.RoundTripOpt + - http2clientConnPool.GetClientConn + - http2noDialClientConnPool.GetClientConn + - http2noDialH2RoundTripper.NewClientConn + - http2noDialH2RoundTripper.RoundTrip + - http2unencryptedTransport.RoundTrip + - module: std + versions: + - introduced: 1.27.0-0 + - fixed: 1.27.2 + vulnerable_at: 1.27.1 + packages: + - package: net/http/internal/http2 + symbols: + - clientConnReadLoop.handleResponse + derived_symbols: + - Transport.AddConn + - Transport.NewClientConn + - Transport.RoundTrip + - Transport.RoundTripOpt + - clientConnPool.GetClientConn + - noDialClientConnPool.GetClientConn + - module: golang.org/x/net + versions: + - fixed: 0.60.0 + vulnerable_at: 0.59.0 + packages: + - package: golang.org/x/net/http2 + symbols: + - clientConnReadLoop.handleResponse + derived_symbols: + - Transport.NewClientConn + - Transport.RoundTrip + - Transport.RoundTripOpt + - clientConnPool.GetClientConn + - noDialClientConnPool.GetClientConn + - noDialH2RoundTripper.NewClientConn + - noDialH2RoundTripper.RoundTrip + - unencryptedTransport.RoundTrip +summary: HTTP/2 transport accepts malformed framing-related headers in net/http +description: |- + Historically, we have been rather lax about malformed framing-related + headers in our HTTP/2 implementation, as they cannot interfere with + HTTP/2 framing. However, this makes it possible for our HTTP/2 + implementation to forward responses containing such headers to an HTTP/1 + client when acting as a reverse proxy. If the HTTP/1 client also does + not behave strictly enough, this can result in response smuggling. +credits: + - TJ Barton +references: + - fix: https://go.dev/cl/835145 + - fix: https://go.dev/cl/836385 + - report: https://go.dev/issue/81115 + - web: https://groups.google.com/g/golang-announce/c/U2fTuyDJznI +cve_metadata: + id: CVE-2026-78660 + cwe: 'CWE-444: Inconsistent Interpretation of HTTP Requests (''HTTP Request/Response Smuggling'')' +source: + id: go-security-team + created: 2026-10-08T00:00:00Z +review_status: REVIEWED
diff --git a/data/reports/GO-2026-6611.yaml b/data/reports/GO-2026-6611.yaml new file mode 100644 index 0000000..ecbe358 --- /dev/null +++ b/data/reports/GO-2026-6611.yaml
@@ -0,0 +1,458 @@ +id: GO-2026-6611 +modules: + - module: std + versions: + - fixed: 1.26.9 + vulnerable_at: 1.26.8 + packages: + - package: net/http + symbols: + - http2outflow.add + - http2outflow.available + - http2outflow.setConnFlow + - http2outflow.take + - http2Server.serveConn + - http2serverConn.newStream + - http2serverConn.processSettingInitialWindowSize + - http2serverConn.processWindowUpdate + - http2serverConn.scheduleFrameWrite + - http2ClientConn.addStreamLocked + - http2Transport.newClientConn + - http2clientConnReadLoop.processSettingsNoWrite + - http2clientConnReadLoop.processWindowUpdate + - http2clientConnReadLoop.streamByID + - http2clientStream.awaitFlowControl + - http2clientStream.cleanupWriteRequest + - http2FrameWriteRequest.Consume + derived_symbols: + - CanonicalHeaderKey + - Client.CloseIdleConnections + - Client.Do + - Client.Get + - Client.Head + - Client.Post + - Client.PostForm + - ClientConn.Close + - ClientConn.RoundTrip + - Cookie.String + - Cookie.Valid + - CrossOriginProtection.AddInsecureBypassPattern + - CrossOriginProtection.AddTrustedOrigin + - CrossOriginProtection.Check + - Dir.Open + - Error + - Get + - Handle + - HandleFunc + - HandlerFunc.ServeHTTP + - Head + - Header.Add + - Header.Del + - Header.Get + - Header.Set + - Header.Values + - Header.Write + - Header.WriteSubset + - ListenAndServe + - ListenAndServeTLS + - NewRequest + - NewRequestWithContext + - NotFound + - ParseCookie + - ParseSetCookie + - ParseTime + - Post + - PostForm + - ProxyFromEnvironment + - ReadRequest + - ReadResponse + - Redirect + - Request.AddCookie + - Request.BasicAuth + - Request.Cookie + - Request.Cookies + - Request.CookiesNamed + - Request.FormFile + - Request.FormValue + - Request.MultipartReader + - Request.ParseForm + - Request.ParseMultipartForm + - Request.PostFormValue + - Request.Referer + - Request.SetBasicAuth + - Request.UserAgent + - Request.Write + - Request.WriteProxy + - Response.Cookies + - Response.Location + - Response.Write + - ResponseController.EnableFullDuplex + - ResponseController.Flush + - ResponseController.Hijack + - ResponseController.SetReadDeadline + - ResponseController.SetWriteDeadline + - Serve + - ServeContent + - ServeFile + - ServeFileFS + - ServeMux.Handle + - ServeMux.HandleFunc + - ServeMux.ServeHTTP + - ServeTLS + - Server.Close + - Server.ListenAndServe + - Server.ListenAndServeTLS + - Server.Serve + - Server.ServeTLS + - Server.SetKeepAlivesEnabled + - Server.Shutdown + - SetCookie + - Transport.CancelRequest + - Transport.Clone + - Transport.CloseIdleConnections + - Transport.NewClientConn + - Transport.RoundTrip + - body.Close + - body.Read + - bodyEOFSignal.Close + - bodyEOFSignal.Read + - bodyLocked.Read + - bufioFlushWriter.Write + - cancelTimerBody.Close + - cancelTimerBody.Read + - checkConnErrorWriter.Write + - chunkWriter.Write + - connReader.Read + - connectMethodKey.String + - expectContinueReader.Close + - expectContinueReader.Read + - extraHeader.Write + - fileHandler.ServeHTTP + - fileTransport.RoundTrip + - globalOptionsHandler.ServeHTTP + - gzipReader.Close + - gzipReader.Read + - http1ClientConn.Close + - http1ClientConn.RoundTrip + - http2ClientConn.Close + - http2ClientConn.Ping + - http2ClientConn.RoundTrip + - http2ClientConn.Shutdown + - http2ConnectionError.Error + - http2ErrCode.String + - http2FrameHeader.String + - http2FrameType.String + - http2FrameWriteRequest.String + - http2Framer.ReadFrame + - http2Framer.ReadFrameForHeader + - http2Framer.ReadFrameHeader + - http2Framer.WriteContinuation + - http2Framer.WriteData + - http2Framer.WriteDataPadded + - http2Framer.WriteGoAway + - http2Framer.WriteHeaders + - http2Framer.WritePing + - http2Framer.WritePriority + - http2Framer.WritePushPromise + - http2Framer.WriteRSTStream + - http2Framer.WriteRawFrame + - http2Framer.WriteSettings + - http2Framer.WriteSettingsAck + - http2Framer.WriteWindowUpdate + - http2GoAwayError.Error + - http2Server.ServeConn + - http2Setting.String + - http2SettingID.String + - http2SettingsFrame.ForeachSetting + - http2StreamError.Error + - http2Transport.CloseIdleConnections + - http2Transport.NewClientConn + - http2Transport.RoundTrip + - http2Transport.RoundTripOpt + - http2bufferedWriter.Flush + - http2bufferedWriter.Write + - http2bufferedWriterTimeoutWriter.Write + - http2chunkWriter.Write + - http2clientConnPool.GetClientConn + - http2connError.Error + - http2dataBuffer.Read + - http2duplicatePseudoHeaderError.Error + - http2gzipReader.Close + - http2gzipReader.Read + - http2headerFieldNameError.Error + - http2headerFieldValueError.Error + - http2netHTTPClientConn.Close + - http2netHTTPClientConn.RoundTrip + - http2noDialClientConnPool.GetClientConn + - http2noDialH2RoundTripper.NewClientConn + - http2noDialH2RoundTripper.RoundTrip + - http2pipe.Read + - http2priorityWriteSchedulerRFC7540.CloseStream + - http2priorityWriteSchedulerRFC7540.OpenStream + - http2priorityWriteSchedulerRFC7540.Pop + - http2priorityWriteSchedulerRFC9218.OpenStream + - http2priorityWriteSchedulerRFC9218.Pop + - http2pseudoHeaderError.Error + - http2randomWriteScheduler.Pop + - http2requestBody.Close + - http2requestBody.Read + - http2responseWriter.Flush + - http2responseWriter.FlushError + - http2responseWriter.Push + - http2responseWriter.SetReadDeadline + - http2responseWriter.SetWriteDeadline + - http2responseWriter.Write + - http2responseWriter.WriteHeader + - http2responseWriter.WriteString + - http2roundRobinWriteScheduler.OpenStream + - http2roundRobinWriteScheduler.Pop + - http2serverConn.CloseConn + - http2serverConn.Flush + - http2stickyErrWriter.Write + - http2transportResponseBody.Close + - http2transportResponseBody.Read + - http2unencryptedTransport.RoundTrip + - http2writeData.String + - initALPNRequest.ServeHTTP + - loggingConn.Close + - loggingConn.Read + - loggingConn.Write + - maxBytesReader.Close + - maxBytesReader.Read + - onceCloseListener.Close + - persistConn.Read + - persistConnWriter.ReadFrom + - persistConnWriter.Write + - populateResponse.Write + - populateResponse.WriteHeader + - readTrackingBody.Close + - readTrackingBody.Read + - readWriteCloserBody.CloseWrite + - readWriteCloserBody.Read + - redirectHandler.ServeHTTP + - response.Flush + - response.FlushError + - response.Hijack + - response.ReadFrom + - response.Write + - response.WriteHeader + - response.WriteString + - serverHandler.ServeHTTP + - socksDialer.DialWithConn + - socksUsernamePassword.Authenticate + - stringWriter.WriteString + - timeoutHandler.ServeHTTP + - timeoutWriter.Write + - timeoutWriter.WriteHeader + - transportReadFromServerError.Error + - unencryptedHTTP2Request.ServeHTTP + - module: std + versions: + - introduced: 1.27.0-0 + - fixed: 1.27.2 + vulnerable_at: 1.27.1 + packages: + - package: net/http/internal/http2 + symbols: + - outflow.add + - outflow.available + - outflow.setConnFlow + - outflow.take + - Server.serveConn + - serverConn.newStream + - serverConn.processSettingInitialWindowSize + - serverConn.processWindowUpdate + - serverConn.scheduleFrameWrite + - ClientConn.addStreamLocked + - Transport.newClientConn + - clientConnReadLoop.processSettingsNoWrite + - clientConnReadLoop.processWindowUpdate + - clientConnReadLoop.streamByID + - clientStream.awaitFlowControl + - clientStream.cleanupWriteRequest + - FrameWriteRequest.Consume + derived_symbols: + - ClientConn.Close + - ClientConn.Ping + - ClientConn.RoundTrip + - ClientConn.Shutdown + - Framer.ReadFrame + - Framer.ReadFrameForHeader + - Framer.ReadFrameHeader + - Framer.WriteContinuation + - Framer.WriteData + - Framer.WriteDataPadded + - Framer.WriteGoAway + - Framer.WriteHeaders + - Framer.WritePing + - Framer.WritePriority + - Framer.WritePriorityUpdate + - Framer.WritePushPromise + - Framer.WriteRSTStream + - Framer.WriteRawFrame + - Framer.WriteSettings + - Framer.WriteSettingsAck + - Framer.WriteWindowUpdate + - NetHTTPClientConn.Close + - NetHTTPClientConn.Ping + - NetHTTPClientConn.RoundTrip + - ReadFrameHeader + - Server.GracefulShutdown + - Server.ServeConn + - SettingsFrame.ForeachSetting + - Transport.AddConn + - Transport.CloseIdleConnections + - Transport.NewClientConn + - Transport.RoundTrip + - Transport.RoundTripOpt + - bufferedWriter.Flush + - bufferedWriter.Write + - bufferedWriterTimeoutWriter.Write + - chunkWriter.Write + - clientConnPool.GetClientConn + - gzipReader.Close + - gzipReader.Read + - noDialClientConnPool.GetClientConn + - priorityWriteSchedulerRFC9218.Pop + - requestBody.Close + - responseWriter.Flush + - responseWriter.FlushError + - responseWriter.Push + - responseWriter.Write + - responseWriter.WriteHeader + - responseWriter.WriteString + - roundRobinWriteScheduler.Pop + - serve400Handler.ServeHTTP + - serverConn.Flush + - stickyErrWriter.Write + - transportResponseBody.Close + - transportResponseBody.Read + - module: golang.org/x/net + versions: + - fixed: 0.60.0 + vulnerable_at: 0.59.0 + packages: + - package: golang.org/x/net/http2 + symbols: + - outflow.add + - outflow.available + - outflow.setConnFlow + - outflow.take + - Server.serveConn + - serverConn.newStream + - serverConn.processSettingInitialWindowSize + - serverConn.processWindowUpdate + - serverConn.scheduleFrameWrite + - ClientConn.addStreamLocked + - Transport.newClientConn + - clientConnReadLoop.processSettingsNoWrite + - clientConnReadLoop.processWindowUpdate + - clientConnReadLoop.streamByID + - clientStream.awaitFlowControl + - clientStream.cleanupWriteRequest + - FrameWriteRequest.Consume + derived_symbols: + - ClientConn.Close + - ClientConn.Ping + - ClientConn.RoundTrip + - ClientConn.Shutdown + - ConfigureServer + - ConfigureTransport + - ConfigureTransports + - ConnectionError.Error + - ErrCode.String + - FrameHeader.String + - FrameType.String + - FrameWriteRequest.String + - Framer.ReadFrame + - Framer.ReadFrameForHeader + - Framer.ReadFrameHeader + - Framer.WriteContinuation + - Framer.WriteData + - Framer.WriteDataPadded + - Framer.WriteGoAway + - Framer.WriteHeaders + - Framer.WritePing + - Framer.WritePriority + - Framer.WritePriorityUpdate + - Framer.WritePushPromise + - Framer.WriteRSTStream + - Framer.WriteRawFrame + - Framer.WriteSettings + - Framer.WriteSettingsAck + - Framer.WriteWindowUpdate + - GoAwayError.Error + - ReadFrameHeader + - Server.ServeConn + - Setting.String + - SettingID.String + - SettingsFrame.ForeachSetting + - StreamError.Error + - Transport.CloseIdleConnections + - Transport.NewClientConn + - Transport.RoundTrip + - Transport.RoundTripOpt + - bufferedWriter.Flush + - bufferedWriter.Write + - bufferedWriterTimeoutWriter.Write + - chunkWriter.Write + - clientConnPool.GetClientConn + - connError.Error + - dataBuffer.Read + - duplicatePseudoHeaderError.Error + - gzipReader.Close + - gzipReader.Read + - headerFieldNameError.Error + - headerFieldValueError.Error + - netHTTPClientConn.Close + - netHTTPClientConn.RoundTrip + - noDialClientConnPool.GetClientConn + - noDialH2RoundTripper.NewClientConn + - noDialH2RoundTripper.RoundTrip + - pipe.Read + - priorityWriteSchedulerRFC7540.CloseStream + - priorityWriteSchedulerRFC7540.OpenStream + - priorityWriteSchedulerRFC7540.Pop + - priorityWriteSchedulerRFC9218.OpenStream + - priorityWriteSchedulerRFC9218.Pop + - pseudoHeaderError.Error + - randomWriteScheduler.Pop + - requestBody.Close + - requestBody.Read + - responseWriter.Flush + - responseWriter.FlushError + - responseWriter.Push + - responseWriter.SetReadDeadline + - responseWriter.SetWriteDeadline + - responseWriter.Write + - responseWriter.WriteHeader + - responseWriter.WriteString + - roundRobinWriteScheduler.OpenStream + - roundRobinWriteScheduler.Pop + - serverConn.CloseConn + - serverConn.Flush + - stickyErrWriter.Write + - transportResponseBody.Close + - transportResponseBody.Read + - unencryptedTransport.RoundTrip + - writeData.String +summary: Excessive CPU consumption from repeated initial window changes in net/http +description: |- + A malicious HTTP/2 peer can cause excessive CPU consumption in the + client or server by opening a large number of streams and then sending + many small SETTINGS frames containing SETTINGS_INITIAL_WINDOW_SIZE values. +credits: + - Jakub Ciolek (https://ciolek.dev) +references: + - fix: https://go.dev/cl/847186 + - fix: https://go.dev/cl/847308 + - report: https://go.dev/issue/81742 + - web: https://groups.google.com/g/golang-announce/c/U2fTuyDJznI + - web: https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs +cve_metadata: + id: CVE-2026-78669 + cwe: 'CWE-405: Asymmetric Resource Consumption (Amplification)' +source: + id: go-security-team + created: 2026-10-08T00:00:00Z +review_status: REVIEWED
diff --git a/data/reports/GO-2026-6612.yaml b/data/reports/GO-2026-6612.yaml new file mode 100644 index 0000000..317b7b4 --- /dev/null +++ b/data/reports/GO-2026-6612.yaml
@@ -0,0 +1,375 @@ +id: GO-2026-6612 +modules: + - module: std + versions: + - fixed: 1.26.9 + vulnerable_at: 1.26.8 + packages: + - package: net/http + symbols: + - http2requestBody.Close + - http2requestBody.Read + - http2serverConn.closeStream + - http2serverConn.handlerDone + - http2serverConn.newWriterAndRequest + - http2serverConn.newWriterAndRequestNoBody + - http2serverConn.noteBodyRead + - http2serverConn.processHeaders + - http2serverConn.runHandler + - http2serverConn.scheduleHandler + derived_symbols: + - CanonicalHeaderKey + - Client.CloseIdleConnections + - Client.Do + - Client.Get + - Client.Head + - Client.Post + - Client.PostForm + - ClientConn.Close + - ClientConn.RoundTrip + - Cookie.String + - Cookie.Valid + - CrossOriginProtection.AddInsecureBypassPattern + - CrossOriginProtection.AddTrustedOrigin + - CrossOriginProtection.Check + - Dir.Open + - Error + - Get + - Handle + - HandleFunc + - HandlerFunc.ServeHTTP + - Head + - Header.Add + - Header.Del + - Header.Get + - Header.Set + - Header.Values + - Header.Write + - Header.WriteSubset + - ListenAndServe + - ListenAndServeTLS + - NewRequest + - NewRequestWithContext + - NotFound + - ParseCookie + - ParseSetCookie + - ParseTime + - Post + - PostForm + - ProxyFromEnvironment + - ReadRequest + - ReadResponse + - Redirect + - Request.AddCookie + - Request.BasicAuth + - Request.Cookie + - Request.Cookies + - Request.CookiesNamed + - Request.FormFile + - Request.FormValue + - Request.MultipartReader + - Request.ParseForm + - Request.ParseMultipartForm + - Request.PostFormValue + - Request.Referer + - Request.SetBasicAuth + - Request.UserAgent + - Request.Write + - Request.WriteProxy + - Response.Cookies + - Response.Location + - Response.Write + - ResponseController.EnableFullDuplex + - ResponseController.Flush + - ResponseController.Hijack + - ResponseController.SetReadDeadline + - ResponseController.SetWriteDeadline + - Serve + - ServeContent + - ServeFile + - ServeFileFS + - ServeMux.Handle + - ServeMux.HandleFunc + - ServeMux.ServeHTTP + - ServeTLS + - Server.Close + - Server.ListenAndServe + - Server.ListenAndServeTLS + - Server.Serve + - Server.ServeTLS + - Server.SetKeepAlivesEnabled + - Server.Shutdown + - SetCookie + - Transport.CancelRequest + - Transport.Clone + - Transport.CloseIdleConnections + - Transport.NewClientConn + - Transport.RoundTrip + - body.Close + - body.Read + - bodyEOFSignal.Close + - bodyEOFSignal.Read + - bodyLocked.Read + - bufioFlushWriter.Write + - cancelTimerBody.Close + - cancelTimerBody.Read + - checkConnErrorWriter.Write + - chunkWriter.Write + - connReader.Read + - connectMethodKey.String + - expectContinueReader.Close + - expectContinueReader.Read + - extraHeader.Write + - fileHandler.ServeHTTP + - fileTransport.RoundTrip + - globalOptionsHandler.ServeHTTP + - gzipReader.Close + - gzipReader.Read + - http1ClientConn.Close + - http1ClientConn.RoundTrip + - http2ClientConn.Close + - http2ClientConn.Ping + - http2ClientConn.RoundTrip + - http2ClientConn.Shutdown + - http2ConnectionError.Error + - http2ErrCode.String + - http2FrameHeader.String + - http2FrameType.String + - http2FrameWriteRequest.String + - http2Framer.ReadFrame + - http2Framer.ReadFrameForHeader + - http2Framer.ReadFrameHeader + - http2Framer.WriteContinuation + - http2Framer.WriteData + - http2Framer.WriteDataPadded + - http2Framer.WriteGoAway + - http2Framer.WriteHeaders + - http2Framer.WritePing + - http2Framer.WritePriority + - http2Framer.WritePushPromise + - http2Framer.WriteRSTStream + - http2Framer.WriteRawFrame + - http2Framer.WriteSettings + - http2Framer.WriteSettingsAck + - http2Framer.WriteWindowUpdate + - http2GoAwayError.Error + - http2Server.ServeConn + - http2Setting.String + - http2SettingID.String + - http2SettingsFrame.ForeachSetting + - http2StreamError.Error + - http2Transport.CloseIdleConnections + - http2Transport.NewClientConn + - http2Transport.RoundTrip + - http2Transport.RoundTripOpt + - http2bufferedWriter.Flush + - http2bufferedWriter.Write + - http2bufferedWriterTimeoutWriter.Write + - http2chunkWriter.Write + - http2clientConnPool.GetClientConn + - http2connError.Error + - http2dataBuffer.Read + - http2duplicatePseudoHeaderError.Error + - http2gzipReader.Close + - http2gzipReader.Read + - http2headerFieldNameError.Error + - http2headerFieldValueError.Error + - http2netHTTPClientConn.Close + - http2netHTTPClientConn.RoundTrip + - http2noDialClientConnPool.GetClientConn + - http2noDialH2RoundTripper.NewClientConn + - http2noDialH2RoundTripper.RoundTrip + - http2pipe.Read + - http2priorityWriteSchedulerRFC7540.CloseStream + - http2priorityWriteSchedulerRFC7540.OpenStream + - http2priorityWriteSchedulerRFC9218.OpenStream + - http2pseudoHeaderError.Error + - http2responseWriter.Flush + - http2responseWriter.FlushError + - http2responseWriter.Push + - http2responseWriter.SetReadDeadline + - http2responseWriter.SetWriteDeadline + - http2responseWriter.Write + - http2responseWriter.WriteHeader + - http2responseWriter.WriteString + - http2roundRobinWriteScheduler.OpenStream + - http2serverConn.CloseConn + - http2serverConn.Flush + - http2stickyErrWriter.Write + - http2transportResponseBody.Close + - http2transportResponseBody.Read + - http2unencryptedTransport.RoundTrip + - http2writeData.String + - initALPNRequest.ServeHTTP + - loggingConn.Close + - loggingConn.Read + - loggingConn.Write + - maxBytesReader.Close + - maxBytesReader.Read + - onceCloseListener.Close + - persistConn.Read + - persistConnWriter.ReadFrom + - persistConnWriter.Write + - populateResponse.Write + - populateResponse.WriteHeader + - readTrackingBody.Close + - readTrackingBody.Read + - readWriteCloserBody.CloseWrite + - readWriteCloserBody.Read + - redirectHandler.ServeHTTP + - response.Flush + - response.FlushError + - response.Hijack + - response.ReadFrom + - response.Write + - response.WriteHeader + - response.WriteString + - serverHandler.ServeHTTP + - socksDialer.DialWithConn + - socksUsernamePassword.Authenticate + - stringWriter.WriteString + - timeoutHandler.ServeHTTP + - timeoutWriter.Write + - timeoutWriter.WriteHeader + - transportReadFromServerError.Error + - unencryptedHTTP2Request.ServeHTTP + - module: std + versions: + - introduced: 1.27.0-0 + - fixed: 1.27.2 + vulnerable_at: 1.27.1 + packages: + - package: net/http/internal/http2 + symbols: + - requestBody.Close + - requestBody.Read + - serverConn.closeStream + - serverConn.handlerDone + - serverConn.newWriterAndRequest + - serverConn.newWriterAndRequestNoBody + - serverConn.noteBodyRead + - serverConn.processHeaders + - serverConn.runHandler + - serverConn.scheduleHandler + derived_symbols: + - Server.ServeConn + - module: golang.org/x/net + versions: + - fixed: 0.60.0 + vulnerable_at: 0.59.0 + packages: + - package: golang.org/x/net/http2 + symbols: + - requestBody.Close + - requestBody.Read + - serverConn.closeStream + - serverConn.handlerDone + - serverConn.newWriterAndRequest + - serverConn.newWriterAndRequestNoBody + - serverConn.noteBodyRead + - serverConn.processHeaders + - serverConn.runHandler + - serverConn.scheduleHandler + derived_symbols: + - ClientConn.Close + - ClientConn.Ping + - ClientConn.RoundTrip + - ClientConn.Shutdown + - ConfigureServer + - ConfigureTransport + - ConfigureTransports + - ConnectionError.Error + - ErrCode.String + - FrameHeader.String + - FrameType.String + - FrameWriteRequest.String + - Framer.ReadFrame + - Framer.ReadFrameForHeader + - Framer.ReadFrameHeader + - Framer.WriteContinuation + - Framer.WriteData + - Framer.WriteDataPadded + - Framer.WriteGoAway + - Framer.WriteHeaders + - Framer.WritePing + - Framer.WritePriority + - Framer.WritePriorityUpdate + - Framer.WritePushPromise + - Framer.WriteRSTStream + - Framer.WriteRawFrame + - Framer.WriteSettings + - Framer.WriteSettingsAck + - Framer.WriteWindowUpdate + - GoAwayError.Error + - ReadFrameHeader + - Server.ServeConn + - Setting.String + - SettingID.String + - SettingsFrame.ForeachSetting + - StreamError.Error + - Transport.CloseIdleConnections + - Transport.NewClientConn + - Transport.RoundTrip + - Transport.RoundTripOpt + - bufferedWriter.Flush + - bufferedWriter.Write + - bufferedWriterTimeoutWriter.Write + - chunkWriter.Write + - clientConnPool.GetClientConn + - connError.Error + - dataBuffer.Read + - duplicatePseudoHeaderError.Error + - gzipReader.Close + - gzipReader.Read + - headerFieldNameError.Error + - headerFieldValueError.Error + - netHTTPClientConn.Close + - netHTTPClientConn.RoundTrip + - noDialClientConnPool.GetClientConn + - noDialH2RoundTripper.NewClientConn + - noDialH2RoundTripper.RoundTrip + - pipe.Read + - priorityWriteSchedulerRFC7540.CloseStream + - priorityWriteSchedulerRFC7540.OpenStream + - priorityWriteSchedulerRFC9218.OpenStream + - pseudoHeaderError.Error + - responseWriter.Flush + - responseWriter.FlushError + - responseWriter.Push + - responseWriter.SetReadDeadline + - responseWriter.SetWriteDeadline + - responseWriter.Write + - responseWriter.WriteHeader + - responseWriter.WriteString + - roundRobinWriteScheduler.OpenStream + - serverConn.CloseConn + - serverConn.Flush + - stickyErrWriter.Write + - transportResponseBody.Close + - transportResponseBody.Read + - unencryptedTransport.RoundTrip + - writeData.String +summary: Double flow control refund on HTTP/2 server streams in net/http +description: |- + The HTTP/2 server can refund connection-level flow control twice for the same + data: Once when a client resets a stream (refunding data for any sent-but-unread + portion of the stream), and again when a request handler reads the buffered + data. A malicious client can exploit this to bypass the configured + connection-level flow control limit (MaxReceiveBufferPerConnection). Total + buffered data is still limited by the concurrent stream limit and stream-level + flow control. +credits: + - Ali Sherif (https://www.linkedin.com/in/ali-sherif-13812b276/) +references: + - fix: https://go.dev/cl/847187 + - fix: https://go.dev/cl/847310 + - report: https://go.dev/issue/81743 + - web: https://groups.google.com/g/golang-announce/c/U2fTuyDJznI + - web: https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs +cve_metadata: + id: CVE-2026-78663 + cwe: 'CWE-675: Multiple Operations on Resource in Single-Operation Context' +source: + id: go-security-team + created: 2026-10-08T00:00:00Z +review_status: REVIEWED
diff --git a/data/reports/GO-2026-6613.yaml b/data/reports/GO-2026-6613.yaml new file mode 100644 index 0000000..20bd0fa --- /dev/null +++ b/data/reports/GO-2026-6613.yaml
@@ -0,0 +1,186 @@ +id: GO-2026-6613 +modules: + - module: std + versions: + - fixed: 1.26.9 + - introduced: 1.27.0-0 + - fixed: 1.27.2 + vulnerable_at: 1.27.1 + packages: + - package: net/http + symbols: + - chunkWriter.writeHeader + derived_symbols: + - CanonicalHeaderKey + - Client.CloseIdleConnections + - Client.Do + - Client.Get + - Client.Head + - Client.Post + - Client.PostForm + - ClientConn.Close + - ClientConn.RoundTrip + - Cookie.String + - Cookie.Valid + - CrossOriginProtection.AddInsecureBypassPattern + - CrossOriginProtection.AddTrustedOrigin + - CrossOriginProtection.Check + - Dir.Open + - Error + - Get + - Handle + - HandleFunc + - HandlerFunc.ServeHTTP + - Head + - Header.Add + - Header.Del + - Header.Get + - Header.Set + - Header.Values + - Header.Write + - Header.WriteSubset + - ListenAndServe + - ListenAndServeTLS + - NewRequest + - NewRequestWithContext + - NotFound + - ParseCookie + - ParseSetCookie + - ParseTime + - Post + - PostForm + - ProxyFromEnvironment + - ReadRequest + - ReadResponse + - Redirect + - Request.AddCookie + - Request.BasicAuth + - Request.Cookie + - Request.Cookies + - Request.CookiesNamed + - Request.FormFile + - Request.FormValue + - Request.MultipartReader + - Request.ParseForm + - Request.ParseMultipartForm + - Request.PostFormValue + - Request.Referer + - Request.SetBasicAuth + - Request.UserAgent + - Request.Write + - Request.WriteProxy + - Response.Cookies + - Response.Location + - Response.Write + - ResponseController.EnableFullDuplex + - ResponseController.Flush + - ResponseController.Hijack + - ResponseController.SetReadDeadline + - ResponseController.SetWriteDeadline + - Serve + - ServeContent + - ServeFile + - ServeFileFS + - ServeMux.Handle + - ServeMux.HandleFunc + - ServeMux.ServeHTTP + - ServeTLS + - Server.Close + - Server.ListenAndServe + - Server.ListenAndServeTLS + - Server.Serve + - Server.ServeTLS + - Server.SetKeepAlivesEnabled + - Server.Shutdown + - SetCookie + - Transport.CancelRequest + - Transport.Clone + - Transport.CloseIdleConnections + - Transport.NewClientConn + - Transport.RoundTrip + - body.Close + - body.Read + - bodyEOFSignal.Close + - bodyEOFSignal.Read + - bodyLocked.Read + - bufioFlushWriter.Write + - cancelTimerBody.Close + - cancelTimerBody.Read + - checkConnErrorWriter.Write + - chunkWriter.Write + - connReader.Read + - connectMethodKey.String + - expectContinueReader.Close + - expectContinueReader.Read + - extraHeader.Write + - fileHandler.ServeHTTP + - fileTransport.RoundTrip + - globalOptionsHandler.ServeHTTP + - gzipReader.Close + - gzipReader.Read + - http1ClientConn.Close + - http1ClientConn.RoundTrip + - http2ClientConn.RoundTrip + - http2Handler.ServeHTTP + - http2ResponseWriter.Flush + - http2ResponseWriter.FlushError + - http2ResponseWriter.Push + - http2RoundTripper.RoundTrip + - http3ServerHandler.ServeHTTP + - initALPNRequest.ServeHTTP + - loggingConn.Close + - loggingConn.Read + - loggingConn.Write + - maxBytesReader.Close + - maxBytesReader.Read + - onceCloseListener.Close + - persistConn.Read + - persistConnWriter.ReadFrom + - persistConnWriter.Write + - populateResponse.Write + - populateResponse.WriteHeader + - readTrackingBody.Close + - readTrackingBody.Read + - readWriteCloserBody.CloseWrite + - readWriteCloserBody.Read + - redirectHandler.ServeHTTP + - response.Flush + - response.FlushError + - response.Hijack + - response.ReadFrom + - response.Write + - response.WriteHeader + - response.WriteString + - serverHandler.ServeHTTP + - socksDialer.DialWithConn + - socksUsernamePassword.Authenticate + - stringWriter.WriteString + - timeoutHandler.ServeHTTP + - timeoutWriter.Write + - timeoutWriter.WriteHeader + - transportReadFromServerError.Error + - unencryptedHTTP2Request.ServeHTTP +summary: HTTP/1 server connection desynchronization after 2xx CONNECT response in net/http +description: |- + When an HTTP server handler sends a 2xx response to an HTTP/1 CONNECT request + and returns without hijacking the connection, the server improperly continues + to read and serve requests from the connection. Since a 2xx response to an + HTTP/1 CONNECT converts the connection into a tunnel, the server should not + treat the connection as continuing to contain HTTP. + + The impact of this misbehavior is mostly limited to potential request smuggling, + where an intermediate proxy considers the data on the connection to be tunneled + and the server considers it to be HTTP. +credits: + - Jakub Ciolek (https://ciolek.dev) +references: + - fix: https://go.dev/cl/847311 + - report: https://go.dev/issue/81744 + - web: https://groups.google.com/g/golang-announce/c/U2fTuyDJznI +cve_metadata: + id: CVE-2026-94439 + cwe: 'CWE-444: Inconsistent Interpretation of HTTP Requests (''HTTP Request/Response Smuggling'')' +source: + id: go-security-team + created: 2026-10-08T00:00:00Z +review_status: REVIEWED
diff --git a/data/reports/GO-2026-6617.yaml b/data/reports/GO-2026-6617.yaml new file mode 100644 index 0000000..2df3088 --- /dev/null +++ b/data/reports/GO-2026-6617.yaml
@@ -0,0 +1,409 @@ +id: GO-2026-6617 +modules: + - module: std + versions: + - fixed: 1.26.9 + vulnerable_at: 1.26.8 + packages: + - package: net/http + symbols: + - http2serverConn.processSetting + - http2serverConn.startFrameWrite + derived_symbols: + - CanonicalHeaderKey + - Client.CloseIdleConnections + - Client.Do + - Client.Get + - Client.Head + - Client.Post + - Client.PostForm + - ClientConn.Close + - ClientConn.RoundTrip + - Cookie.String + - Cookie.Valid + - CrossOriginProtection.AddInsecureBypassPattern + - CrossOriginProtection.AddTrustedOrigin + - CrossOriginProtection.Check + - Dir.Open + - Error + - Get + - Handle + - HandleFunc + - HandlerFunc.ServeHTTP + - Head + - Header.Add + - Header.Del + - Header.Get + - Header.Set + - Header.Values + - Header.Write + - Header.WriteSubset + - ListenAndServe + - ListenAndServeTLS + - NewRequest + - NewRequestWithContext + - NotFound + - ParseCookie + - ParseSetCookie + - ParseTime + - Post + - PostForm + - ProxyFromEnvironment + - ReadRequest + - ReadResponse + - Redirect + - Request.AddCookie + - Request.BasicAuth + - Request.Cookie + - Request.Cookies + - Request.CookiesNamed + - Request.FormFile + - Request.FormValue + - Request.MultipartReader + - Request.ParseForm + - Request.ParseMultipartForm + - Request.PostFormValue + - Request.Referer + - Request.SetBasicAuth + - Request.UserAgent + - Request.Write + - Request.WriteProxy + - Response.Cookies + - Response.Location + - Response.Write + - ResponseController.EnableFullDuplex + - ResponseController.Flush + - ResponseController.Hijack + - ResponseController.SetReadDeadline + - ResponseController.SetWriteDeadline + - Serve + - ServeContent + - ServeFile + - ServeFileFS + - ServeMux.Handle + - ServeMux.HandleFunc + - ServeMux.ServeHTTP + - ServeTLS + - Server.Close + - Server.ListenAndServe + - Server.ListenAndServeTLS + - Server.Serve + - Server.ServeTLS + - Server.SetKeepAlivesEnabled + - Server.Shutdown + - SetCookie + - Transport.CancelRequest + - Transport.Clone + - Transport.CloseIdleConnections + - Transport.NewClientConn + - Transport.RoundTrip + - body.Close + - body.Read + - bodyEOFSignal.Close + - bodyEOFSignal.Read + - bodyLocked.Read + - bufioFlushWriter.Write + - cancelTimerBody.Close + - cancelTimerBody.Read + - checkConnErrorWriter.Write + - chunkWriter.Write + - connReader.Read + - connectMethodKey.String + - expectContinueReader.Close + - expectContinueReader.Read + - extraHeader.Write + - fileHandler.ServeHTTP + - fileTransport.RoundTrip + - globalOptionsHandler.ServeHTTP + - gzipReader.Close + - gzipReader.Read + - http1ClientConn.Close + - http1ClientConn.RoundTrip + - http2ClientConn.Close + - http2ClientConn.Ping + - http2ClientConn.RoundTrip + - http2ClientConn.Shutdown + - http2ConnectionError.Error + - http2ErrCode.String + - http2FrameHeader.String + - http2FrameType.String + - http2FrameWriteRequest.String + - http2Framer.ReadFrame + - http2Framer.ReadFrameForHeader + - http2Framer.ReadFrameHeader + - http2Framer.WriteContinuation + - http2Framer.WriteData + - http2Framer.WriteDataPadded + - http2Framer.WriteGoAway + - http2Framer.WriteHeaders + - http2Framer.WritePing + - http2Framer.WritePriority + - http2Framer.WritePushPromise + - http2Framer.WriteRSTStream + - http2Framer.WriteRawFrame + - http2Framer.WriteSettings + - http2Framer.WriteSettingsAck + - http2Framer.WriteWindowUpdate + - http2GoAwayError.Error + - http2Server.ServeConn + - http2Setting.String + - http2SettingID.String + - http2SettingsFrame.ForeachSetting + - http2StreamError.Error + - http2Transport.CloseIdleConnections + - http2Transport.NewClientConn + - http2Transport.RoundTrip + - http2Transport.RoundTripOpt + - http2bufferedWriter.Flush + - http2bufferedWriter.Write + - http2bufferedWriterTimeoutWriter.Write + - http2chunkWriter.Write + - http2clientConnPool.GetClientConn + - http2connError.Error + - http2dataBuffer.Read + - http2duplicatePseudoHeaderError.Error + - http2gzipReader.Close + - http2gzipReader.Read + - http2headerFieldNameError.Error + - http2headerFieldValueError.Error + - http2netHTTPClientConn.Close + - http2netHTTPClientConn.RoundTrip + - http2noDialClientConnPool.GetClientConn + - http2noDialH2RoundTripper.NewClientConn + - http2noDialH2RoundTripper.RoundTrip + - http2pipe.Read + - http2priorityWriteSchedulerRFC7540.CloseStream + - http2priorityWriteSchedulerRFC7540.OpenStream + - http2priorityWriteSchedulerRFC9218.OpenStream + - http2pseudoHeaderError.Error + - http2requestBody.Close + - http2requestBody.Read + - http2responseWriter.Flush + - http2responseWriter.FlushError + - http2responseWriter.Push + - http2responseWriter.SetReadDeadline + - http2responseWriter.SetWriteDeadline + - http2responseWriter.Write + - http2responseWriter.WriteHeader + - http2responseWriter.WriteString + - http2roundRobinWriteScheduler.OpenStream + - http2serverConn.CloseConn + - http2serverConn.Flush + - http2stickyErrWriter.Write + - http2transportResponseBody.Close + - http2transportResponseBody.Read + - http2unencryptedTransport.RoundTrip + - http2writeData.String + - initALPNRequest.ServeHTTP + - loggingConn.Close + - loggingConn.Read + - loggingConn.Write + - maxBytesReader.Close + - maxBytesReader.Read + - onceCloseListener.Close + - persistConn.Read + - persistConnWriter.ReadFrom + - persistConnWriter.Write + - populateResponse.Write + - populateResponse.WriteHeader + - readTrackingBody.Close + - readTrackingBody.Read + - readWriteCloserBody.CloseWrite + - readWriteCloserBody.Read + - redirectHandler.ServeHTTP + - response.Flush + - response.FlushError + - response.Hijack + - response.ReadFrom + - response.Write + - response.WriteHeader + - response.WriteString + - serverHandler.ServeHTTP + - socksDialer.DialWithConn + - socksUsernamePassword.Authenticate + - stringWriter.WriteString + - timeoutHandler.ServeHTTP + - timeoutWriter.Write + - timeoutWriter.WriteHeader + - transportReadFromServerError.Error + - unencryptedHTTP2Request.ServeHTTP + - module: std + versions: + - introduced: 1.27.0-0 + - fixed: 1.27.2 + vulnerable_at: 1.27.1 + packages: + - package: net/http/internal/http2 + symbols: + - serverConn.processSetting + - serverConn.startFrameWrite + derived_symbols: + - ClientConn.Close + - ClientConn.Ping + - ClientConn.RoundTrip + - ClientConn.Shutdown + - Framer.ReadFrame + - Framer.ReadFrameForHeader + - Framer.ReadFrameHeader + - Framer.WriteContinuation + - Framer.WriteData + - Framer.WriteDataPadded + - Framer.WriteGoAway + - Framer.WriteHeaders + - Framer.WritePing + - Framer.WritePriority + - Framer.WritePriorityUpdate + - Framer.WritePushPromise + - Framer.WriteRSTStream + - Framer.WriteRawFrame + - Framer.WriteSettings + - Framer.WriteSettingsAck + - Framer.WriteWindowUpdate + - NetHTTPClientConn.Close + - NetHTTPClientConn.Ping + - NetHTTPClientConn.RoundTrip + - ReadFrameHeader + - Server.GracefulShutdown + - Server.ServeConn + - SettingsFrame.ForeachSetting + - Transport.AddConn + - Transport.CloseIdleConnections + - Transport.NewClientConn + - Transport.RoundTrip + - Transport.RoundTripOpt + - bufferedWriter.Flush + - bufferedWriter.Write + - bufferedWriterTimeoutWriter.Write + - chunkWriter.Write + - clientConnPool.GetClientConn + - gzipReader.Close + - gzipReader.Read + - noDialClientConnPool.GetClientConn + - requestBody.Close + - responseWriter.Flush + - responseWriter.FlushError + - responseWriter.Push + - responseWriter.Write + - responseWriter.WriteHeader + - responseWriter.WriteString + - serve400Handler.ServeHTTP + - serverConn.Flush + - stickyErrWriter.Write + - transportResponseBody.Close + - transportResponseBody.Read + - module: golang.org/x/net + versions: + - fixed: 0.60.0 + vulnerable_at: 0.59.0 + packages: + - package: golang.org/x/net/http2 + symbols: + - serverConn.processSetting + - serverConn.startFrameWrite + derived_symbols: + - ClientConn.Close + - ClientConn.Ping + - ClientConn.RoundTrip + - ClientConn.Shutdown + - ConfigureServer + - ConfigureTransport + - ConfigureTransports + - ConnectionError.Error + - ErrCode.String + - FrameHeader.String + - FrameType.String + - FrameWriteRequest.String + - Framer.ReadFrame + - Framer.ReadFrameForHeader + - Framer.ReadFrameHeader + - Framer.WriteContinuation + - Framer.WriteData + - Framer.WriteDataPadded + - Framer.WriteGoAway + - Framer.WriteHeaders + - Framer.WritePing + - Framer.WritePriority + - Framer.WritePriorityUpdate + - Framer.WritePushPromise + - Framer.WriteRSTStream + - Framer.WriteRawFrame + - Framer.WriteSettings + - Framer.WriteSettingsAck + - Framer.WriteWindowUpdate + - GoAwayError.Error + - ReadFrameHeader + - Server.ServeConn + - Setting.String + - SettingID.String + - SettingsFrame.ForeachSetting + - StreamError.Error + - Transport.CloseIdleConnections + - Transport.NewClientConn + - Transport.RoundTrip + - Transport.RoundTripOpt + - bufferedWriter.Flush + - bufferedWriter.Write + - bufferedWriterTimeoutWriter.Write + - chunkWriter.Write + - clientConnPool.GetClientConn + - connError.Error + - dataBuffer.Read + - duplicatePseudoHeaderError.Error + - gzipReader.Close + - gzipReader.Read + - headerFieldNameError.Error + - headerFieldValueError.Error + - netHTTPClientConn.Close + - netHTTPClientConn.RoundTrip + - noDialClientConnPool.GetClientConn + - noDialH2RoundTripper.NewClientConn + - noDialH2RoundTripper.RoundTrip + - pipe.Read + - priorityWriteSchedulerRFC7540.CloseStream + - priorityWriteSchedulerRFC7540.OpenStream + - priorityWriteSchedulerRFC9218.OpenStream + - pseudoHeaderError.Error + - requestBody.Close + - requestBody.Read + - responseWriter.Flush + - responseWriter.FlushError + - responseWriter.Push + - responseWriter.SetReadDeadline + - responseWriter.SetWriteDeadline + - responseWriter.Write + - responseWriter.WriteHeader + - responseWriter.WriteString + - roundRobinWriteScheduler.OpenStream + - serverConn.CloseConn + - serverConn.Flush + - stickyErrWriter.Write + - transportResponseBody.Close + - transportResponseBody.Read + - unencryptedTransport.RoundTrip + - writeData.String +summary: HTTP/2 server crash due to HPACK encoder race in net/http +description: |- + HTTP/2 servers could end up crashing due to inadvertently + modifying its HPACK encoder concurrently. This happens because the + server modifies the HPACK encoder from two goroutines without + synchronization: one uses the encoder to encode a HEADERS frame as part + of a response sent to a client and the other modifies the encoder's + table size when handling a SETTINGS frame containing + SETTINGS_HEADER_TABLE_SIZE that a client sends. A malicious client can + repeatedly send a request while changing the header table size to crash + the server. +credits: + - RyotaK (https://ryotak.net) of GMO Flatt Security Inc. +references: + - fix: https://go.dev/cl/847188 + - fix: https://go.dev/cl/847313 + - report: https://go.dev/issue/81867 + - web: https://groups.google.com/g/golang-announce/c/U2fTuyDJznI + - web: https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs +cve_metadata: + id: CVE-2026-97032 + cwe: 'CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization (''Race Condition'')' +source: + id: go-security-team + created: 2026-10-08T00:00:00Z +review_status: REVIEWED