data/reports: add 15 first-party reports

Fixes golang/vulndb#6599
Fixes golang/vulndb#6600
Fixes golang/vulndb#6601
Fixes golang/vulndb#6602
Fixes golang/vulndb#6603
Fixes golang/vulndb#6604
Fixes golang/vulndb#6605
Fixes golang/vulndb#6607
Fixes golang/vulndb#6608
Fixes golang/vulndb#6609
Fixes golang/vulndb#6610
Fixes golang/vulndb#6611
Fixes golang/vulndb#6612
Fixes golang/vulndb#6613
Fixes golang/vulndb#6617

Change-Id: Ia6a9c0b6e39e7c63ceaa89ae98d1d13183a198e0
Reviewed-on: https://go-review.googlesource.com/c/vulndb/+/847585
Reviewed-by: Nicholas Husin <nsh@golang.org>
Reviewed-by: Nicholas Husin <husin@google.com>
LUCI-TryBot-Result: golang-scoped@luci-project-accounts.iam.gserviceaccount.com <golang-scoped@luci-project-accounts.iam.gserviceaccount.com>
Reviewed-by: Neal Patel <nealpatel@google.com>
diff --git a/data/cve/v5/GO-2026-6599.json b/data/cve/v5/GO-2026-6599.json
new file mode 100644
index 0000000..8c61f6d
--- /dev/null
+++ b/data/cve/v5/GO-2026-6599.json
@@ -0,0 +1,79 @@
+{
+  "dataType": "CVE_RECORD",
+  "dataVersion": "5.0",
+  "cveMetadata": {
+    "cveId": "CVE-2026-94448"
+  },
+  "containers": {
+    "cna": {
+      "providerMetadata": {
+        "orgId": "1bb62c36-49e3-4200-9d77-64a1400537cc"
+      },
+      "title": "Reset context tracking on consecutive template expressions in html/template",
+      "descriptions": [
+        {
+          "lang": "en",
+          "value": "When a JavaScript template literal contains consecutive expressions, the context tracking state was not properly reset upon entering a new expression. We now ensure that template-literal expression entries correctly reset context variables so all subsequent regular expression literals are accurately recognized and escaped."
+        }
+      ],
+      "affected": [
+        {
+          "vendor": "Go standard library",
+          "product": "html/template",
+          "collectionURL": "https://pkg.go.dev",
+          "packageName": "html/template",
+          "versions": [
+            {
+              "version": "0",
+              "lessThan": "1.26.9",
+              "status": "affected",
+              "versionType": "semver"
+            },
+            {
+              "version": "1.27.0-0",
+              "lessThan": "1.27.2",
+              "status": "affected",
+              "versionType": "semver"
+            }
+          ],
+          "programRoutines": [
+            {
+              "name": "tJSTmpl"
+            },
+            {
+              "name": "Template.Execute"
+            },
+            {
+              "name": "Template.ExecuteTemplate"
+            }
+          ],
+          "defaultStatus": "unaffected"
+        }
+      ],
+      "problemTypes": [
+        {
+          "descriptions": [
+            {
+              "lang": "en",
+              "description": "CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')"
+            }
+          ]
+        }
+      ],
+      "references": [
+        {
+          "url": "https://go.dev/cl/839866"
+        },
+        {
+          "url": "https://go.dev/issue/81821"
+        },
+        {
+          "url": "https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"
+        },
+        {
+          "url": "https://pkg.go.dev/vuln/GO-2026-6599"
+        }
+      ]
+    }
+  }
+}
\ No newline at end of file
diff --git a/data/cve/v5/GO-2026-6600.json b/data/cve/v5/GO-2026-6600.json
new file mode 100644
index 0000000..2fb34f3
--- /dev/null
+++ b/data/cve/v5/GO-2026-6600.json
@@ -0,0 +1,82 @@
+{
+  "dataType": "CVE_RECORD",
+  "dataVersion": "5.0",
+  "cveMetadata": {
+    "cveId": "CVE-2026-97030"
+  },
+  "containers": {
+    "cna": {
+      "providerMetadata": {
+        "orgId": "1bb62c36-49e3-4200-9d77-64a1400537cc"
+      },
+      "title": "Recognize yield as regexp preceder keyword in html/template",
+      "descriptions": [
+        {
+          "lang": "en",
+          "value": "A trusted template author may have previously written a valid template wherein the use of the 'yield' keyword would not be correctly escaped. We now ensure that valid keyword uses are escaped and non-keyword uses are not escaped."
+        }
+      ],
+      "affected": [
+        {
+          "vendor": "Go standard library",
+          "product": "html/template",
+          "collectionURL": "https://pkg.go.dev",
+          "packageName": "html/template",
+          "versions": [
+            {
+              "version": "0",
+              "lessThan": "1.26.9",
+              "status": "affected",
+              "versionType": "semver"
+            },
+            {
+              "version": "1.27.0-0",
+              "lessThan": "1.27.2",
+              "status": "affected",
+              "versionType": "semver"
+            }
+          ],
+          "programRoutines": [
+            {
+              "name": "nextJSCtx"
+            },
+            {
+              "name": "tJS"
+            },
+            {
+              "name": "Template.Execute"
+            },
+            {
+              "name": "Template.ExecuteTemplate"
+            }
+          ],
+          "defaultStatus": "unaffected"
+        }
+      ],
+      "problemTypes": [
+        {
+          "descriptions": [
+            {
+              "lang": "en",
+              "description": "CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')"
+            }
+          ]
+        }
+      ],
+      "references": [
+        {
+          "url": "https://go.dev/cl/840925"
+        },
+        {
+          "url": "https://go.dev/issue/81823"
+        },
+        {
+          "url": "https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"
+        },
+        {
+          "url": "https://pkg.go.dev/vuln/GO-2026-6600"
+        }
+      ]
+    }
+  }
+}
\ No newline at end of file
diff --git a/data/cve/v5/GO-2026-6601.json b/data/cve/v5/GO-2026-6601.json
new file mode 100644
index 0000000..2364c30
--- /dev/null
+++ b/data/cve/v5/GO-2026-6601.json
@@ -0,0 +1,68 @@
+{
+  "dataType": "CVE_RECORD",
+  "dataVersion": "5.0",
+  "cveMetadata": {
+    "cveId": "CVE-2026-94444"
+  },
+  "containers": {
+    "cna": {
+      "providerMetadata": {
+        "orgId": "1bb62c36-49e3-4200-9d77-64a1400537cc"
+      },
+      "title": "Checksum bypass for golang.org/fips140 in cmd/go",
+      "descriptions": [
+        {
+          "lang": "en",
+          "value": "Previously, a user operating inside of a malicious Go project that defines a bogus golang.org/fips140 and operates a malicious GOMODPROXY the user chooses to connect to can serve an arbitrary module in its place. We now unpack the trusted ziphash for the bundled golang.org/fips140 module and construct its entry in the GOMODCACHE such that it can be verified by the toolchain."
+        }
+      ],
+      "affected": [
+        {
+          "vendor": "Go toolchain",
+          "product": "cmd/go",
+          "collectionURL": "https://pkg.go.dev",
+          "packageName": "cmd/go",
+          "versions": [
+            {
+              "version": "0",
+              "lessThan": "1.26.9",
+              "status": "affected",
+              "versionType": "semver"
+            },
+            {
+              "version": "1.27.0-0",
+              "lessThan": "1.27.2",
+              "status": "affected",
+              "versionType": "semver"
+            }
+          ],
+          "defaultStatus": "unaffected"
+        }
+      ],
+      "problemTypes": [
+        {
+          "descriptions": [
+            {
+              "lang": "en",
+              "description": "CWE-354: Improper Validation of Integrity Check Value"
+            }
+          ]
+        }
+      ],
+      "references": [
+        {
+          "url": "https://go.dev/cl/840685"
+        },
+        {
+          "url": "https://go.dev/issue/81833"
+        },
+        {
+          "url": "https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"
+        },
+        {
+          "url": "https://pkg.go.dev/vuln/GO-2026-6601"
+        }
+      ]
+    }
+  }
+}
\ No newline at end of file
diff --git a/data/cve/v5/GO-2026-6602.json b/data/cve/v5/GO-2026-6602.json
new file mode 100644
index 0000000..000ad67
--- /dev/null
+++ b/data/cve/v5/GO-2026-6602.json
@@ -0,0 +1,68 @@
+{
+  "dataType": "CVE_RECORD",
+  "dataVersion": "5.0",
+  "cveMetadata": {
+    "cveId": "CVE-2026-94447"
+  },
+  "containers": {
+    "cna": {
+      "providerMetadata": {
+        "orgId": "1bb62c36-49e3-4200-9d77-64a1400537cc"
+      },
+      "title": "Checksum database bypass for golang.org/toolchain in cmd/go",
+      "descriptions": [
+        {
+          "lang": "en",
+          "value": "Previously, a user operating inside of a malicious Go project that defines a bogus golang.org/toolchain go.sum entry and operates a malicious GOMODPROXY the user chooses to use can bypass the intended checksum. We now ensure that golang.org/toolchain always goes to the network for the canonical checksum."
+        }
+      ],
+      "affected": [
+        {
+          "vendor": "Go toolchain",
+          "product": "cmd/go",
+          "collectionURL": "https://pkg.go.dev",
+          "packageName": "cmd/go",
+          "versions": [
+            {
+              "version": "0",
+              "lessThan": "1.26.9",
+              "status": "affected",
+              "versionType": "semver"
+            },
+            {
+              "version": "1.27.0-0",
+              "lessThan": "1.27.2",
+              "status": "affected",
+              "versionType": "semver"
+            }
+          ],
+          "defaultStatus": "unaffected"
+        }
+      ],
+      "problemTypes": [
+        {
+          "descriptions": [
+            {
+              "lang": "en",
+              "description": "CWE-354: Improper Validation of Integrity Check Value"
+            }
+          ]
+        }
+      ],
+      "references": [
+        {
+          "url": "https://go.dev/cl/840785"
+        },
+        {
+          "url": "https://go.dev/issue/81834"
+        },
+        {
+          "url": "https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"
+        },
+        {
+          "url": "https://pkg.go.dev/vuln/GO-2026-6602"
+        }
+      ]
+    }
+  }
+}
\ No newline at end of file
diff --git a/data/cve/v5/GO-2026-6603.json b/data/cve/v5/GO-2026-6603.json
new file mode 100644
index 0000000..5515290
--- /dev/null
+++ b/data/cve/v5/GO-2026-6603.json
@@ -0,0 +1,1169 @@
+{
+  "dataType": "CVE_RECORD",
+  "dataVersion": "5.0",
+  "cveMetadata": {
+    "cveId": "CVE-2026-78659"
+  },
+  "containers": {
+    "cna": {
+      "providerMetadata": {
+        "orgId": "1bb62c36-49e3-4200-9d77-64a1400537cc"
+      },
+      "title": "HTTP/2 server memory exhaustion due to Trailer headers in net/http",
+      "descriptions": [
+        {
+          "lang": "en",
+          "value": "When \"Trailer\" headers are sent by a client, the HTTP server internally uses the header values to populate the Request.Trailer map passed to the server handler. Because Request.Trailer is a map, each entry incurs memory overhead. For HTTP/2 servers, a malicious client can exploit this by sending a \"Trailer\" header that declares a large number of fields, causing the server to allocate a disproportionate amount of memory while bypassing Server.MaxHeaderValueCount and Server.MaxHeaderBytes limits. This exploit is not applicable for HTTP/1 servers, which do not support multiplexing a large number of requests over one TCP connection, and whose Server.MaxHeaderBytes are calculated differently."
+        }
+      ],
+      "affected": [
+        {
+          "vendor": "Go standard library",
+          "product": "net/http",
+          "collectionURL": "https://pkg.go.dev",
+          "packageName": "net/http",
+          "versions": [
+            {
+              "version": "0",
+              "lessThan": "1.26.9",
+              "status": "affected",
+              "versionType": "semver"
+            }
+          ],
+          "programRoutines": [
+            {
+              "name": "http2Framer.readMetaFrame"
+            },
+            {
+              "name": "CanonicalHeaderKey"
+            },
+            {
+              "name": "Client.CloseIdleConnections"
+            },
+            {
+              "name": "Client.Do"
+            },
+            {
+              "name": "Client.Get"
+            },
+            {
+              "name": "Client.Head"
+            },
+            {
+              "name": "Client.Post"
+            },
+            {
+              "name": "Client.PostForm"
+            },
+            {
+              "name": "ClientConn.Close"
+            },
+            {
+              "name": "ClientConn.RoundTrip"
+            },
+            {
+              "name": "Cookie.String"
+            },
+            {
+              "name": "Cookie.Valid"
+            },
+            {
+              "name": "CrossOriginProtection.AddInsecureBypassPattern"
+            },
+            {
+              "name": "CrossOriginProtection.AddTrustedOrigin"
+            },
+            {
+              "name": "CrossOriginProtection.Check"
+            },
+            {
+              "name": "Dir.Open"
+            },
+            {
+              "name": "Error"
+            },
+            {
+              "name": "Get"
+            },
+            {
+              "name": "Handle"
+            },
+            {
+              "name": "HandleFunc"
+            },
+            {
+              "name": "HandlerFunc.ServeHTTP"
+            },
+            {
+              "name": "Head"
+            },
+            {
+              "name": "Header.Add"
+            },
+            {
+              "name": "Header.Del"
+            },
+            {
+              "name": "Header.Get"
+            },
+            {
+              "name": "Header.Set"
+            },
+            {
+              "name": "Header.Values"
+            },
+            {
+              "name": "Header.Write"
+            },
+            {
+              "name": "Header.WriteSubset"
+            },
+            {
+              "name": "ListenAndServe"
+            },
+            {
+              "name": "ListenAndServeTLS"
+            },
+            {
+              "name": "NewRequest"
+            },
+            {
+              "name": "NewRequestWithContext"
+            },
+            {
+              "name": "NotFound"
+            },
+            {
+              "name": "ParseCookie"
+            },
+            {
+              "name": "ParseSetCookie"
+            },
+            {
+              "name": "ParseTime"
+            },
+            {
+              "name": "Post"
+            },
+            {
+              "name": "PostForm"
+            },
+            {
+              "name": "ProxyFromEnvironment"
+            },
+            {
+              "name": "ReadRequest"
+            },
+            {
+              "name": "ReadResponse"
+            },
+            {
+              "name": "Redirect"
+            },
+            {
+              "name": "Request.AddCookie"
+            },
+            {
+              "name": "Request.BasicAuth"
+            },
+            {
+              "name": "Request.Cookie"
+            },
+            {
+              "name": "Request.Cookies"
+            },
+            {
+              "name": "Request.CookiesNamed"
+            },
+            {
+              "name": "Request.FormFile"
+            },
+            {
+              "name": "Request.FormValue"
+            },
+            {
+              "name": "Request.MultipartReader"
+            },
+            {
+              "name": "Request.ParseForm"
+            },
+            {
+              "name": "Request.ParseMultipartForm"
+            },
+            {
+              "name": "Request.PostFormValue"
+            },
+            {
+              "name": "Request.Referer"
+            },
+            {
+              "name": "Request.SetBasicAuth"
+            },
+            {
+              "name": "Request.UserAgent"
+            },
+            {
+              "name": "Request.Write"
+            },
+            {
+              "name": "Request.WriteProxy"
+            },
+            {
+              "name": "Response.Cookies"
+            },
+            {
+              "name": "Response.Location"
+            },
+            {
+              "name": "Response.Write"
+            },
+            {
+              "name": "ResponseController.EnableFullDuplex"
+            },
+            {
+              "name": "ResponseController.Flush"
+            },
+            {
+              "name": "ResponseController.Hijack"
+            },
+            {
+              "name": "ResponseController.SetReadDeadline"
+            },
+            {
+              "name": "ResponseController.SetWriteDeadline"
+            },
+            {
+              "name": "Serve"
+            },
+            {
+              "name": "ServeContent"
+            },
+            {
+              "name": "ServeFile"
+            },
+            {
+              "name": "ServeFileFS"
+            },
+            {
+              "name": "ServeMux.Handle"
+            },
+            {
+              "name": "ServeMux.HandleFunc"
+            },
+            {
+              "name": "ServeMux.ServeHTTP"
+            },
+            {
+              "name": "ServeTLS"
+            },
+            {
+              "name": "Server.Close"
+            },
+            {
+              "name": "Server.ListenAndServe"
+            },
+            {
+              "name": "Server.ListenAndServeTLS"
+            },
+            {
+              "name": "Server.Serve"
+            },
+            {
+              "name": "Server.ServeTLS"
+            },
+            {
+              "name": "Server.SetKeepAlivesEnabled"
+            },
+            {
+              "name": "Server.Shutdown"
+            },
+            {
+              "name": "SetCookie"
+            },
+            {
+              "name": "Transport.CancelRequest"
+            },
+            {
+              "name": "Transport.Clone"
+            },
+            {
+              "name": "Transport.CloseIdleConnections"
+            },
+            {
+              "name": "Transport.NewClientConn"
+            },
+            {
+              "name": "Transport.RoundTrip"
+            },
+            {
+              "name": "body.Close"
+            },
+            {
+              "name": "body.Read"
+            },
+            {
+              "name": "bodyEOFSignal.Close"
+            },
+            {
+              "name": "bodyEOFSignal.Read"
+            },
+            {
+              "name": "bodyLocked.Read"
+            },
+            {
+              "name": "bufioFlushWriter.Write"
+            },
+            {
+              "name": "cancelTimerBody.Close"
+            },
+            {
+              "name": "cancelTimerBody.Read"
+            },
+            {
+              "name": "checkConnErrorWriter.Write"
+            },
+            {
+              "name": "chunkWriter.Write"
+            },
+            {
+              "name": "connReader.Read"
+            },
+            {
+              "name": "connectMethodKey.String"
+            },
+            {
+              "name": "expectContinueReader.Close"
+            },
+            {
+              "name": "expectContinueReader.Read"
+            },
+            {
+              "name": "extraHeader.Write"
+            },
+            {
+              "name": "fileHandler.ServeHTTP"
+            },
+            {
+              "name": "fileTransport.RoundTrip"
+            },
+            {
+              "name": "globalOptionsHandler.ServeHTTP"
+            },
+            {
+              "name": "gzipReader.Close"
+            },
+            {
+              "name": "gzipReader.Read"
+            },
+            {
+              "name": "http1ClientConn.Close"
+            },
+            {
+              "name": "http1ClientConn.RoundTrip"
+            },
+            {
+              "name": "http2ClientConn.Close"
+            },
+            {
+              "name": "http2ClientConn.Ping"
+            },
+            {
+              "name": "http2ClientConn.RoundTrip"
+            },
+            {
+              "name": "http2ClientConn.Shutdown"
+            },
+            {
+              "name": "http2ConnectionError.Error"
+            },
+            {
+              "name": "http2ErrCode.String"
+            },
+            {
+              "name": "http2FrameHeader.String"
+            },
+            {
+              "name": "http2FrameType.String"
+            },
+            {
+              "name": "http2FrameWriteRequest.String"
+            },
+            {
+              "name": "http2Framer.ReadFrame"
+            },
+            {
+              "name": "http2Framer.ReadFrameForHeader"
+            },
+            {
+              "name": "http2Framer.ReadFrameHeader"
+            },
+            {
+              "name": "http2Framer.WriteContinuation"
+            },
+            {
+              "name": "http2Framer.WriteData"
+            },
+            {
+              "name": "http2Framer.WriteDataPadded"
+            },
+            {
+              "name": "http2Framer.WriteGoAway"
+            },
+            {
+              "name": "http2Framer.WriteHeaders"
+            },
+            {
+              "name": "http2Framer.WritePing"
+            },
+            {
+              "name": "http2Framer.WritePriority"
+            },
+            {
+              "name": "http2Framer.WritePushPromise"
+            },
+            {
+              "name": "http2Framer.WriteRSTStream"
+            },
+            {
+              "name": "http2Framer.WriteRawFrame"
+            },
+            {
+              "name": "http2Framer.WriteSettings"
+            },
+            {
+              "name": "http2Framer.WriteSettingsAck"
+            },
+            {
+              "name": "http2Framer.WriteWindowUpdate"
+            },
+            {
+              "name": "http2GoAwayError.Error"
+            },
+            {
+              "name": "http2Server.ServeConn"
+            },
+            {
+              "name": "http2Setting.String"
+            },
+            {
+              "name": "http2SettingID.String"
+            },
+            {
+              "name": "http2SettingsFrame.ForeachSetting"
+            },
+            {
+              "name": "http2StreamError.Error"
+            },
+            {
+              "name": "http2Transport.CloseIdleConnections"
+            },
+            {
+              "name": "http2Transport.NewClientConn"
+            },
+            {
+              "name": "http2Transport.RoundTrip"
+            },
+            {
+              "name": "http2Transport.RoundTripOpt"
+            },
+            {
+              "name": "http2bufferedWriter.Flush"
+            },
+            {
+              "name": "http2bufferedWriter.Write"
+            },
+            {
+              "name": "http2bufferedWriterTimeoutWriter.Write"
+            },
+            {
+              "name": "http2chunkWriter.Write"
+            },
+            {
+              "name": "http2clientConnPool.GetClientConn"
+            },
+            {
+              "name": "http2connError.Error"
+            },
+            {
+              "name": "http2dataBuffer.Read"
+            },
+            {
+              "name": "http2duplicatePseudoHeaderError.Error"
+            },
+            {
+              "name": "http2gzipReader.Close"
+            },
+            {
+              "name": "http2gzipReader.Read"
+            },
+            {
+              "name": "http2headerFieldNameError.Error"
+            },
+            {
+              "name": "http2headerFieldValueError.Error"
+            },
+            {
+              "name": "http2netHTTPClientConn.Close"
+            },
+            {
+              "name": "http2netHTTPClientConn.RoundTrip"
+            },
+            {
+              "name": "http2noDialClientConnPool.GetClientConn"
+            },
+            {
+              "name": "http2noDialH2RoundTripper.NewClientConn"
+            },
+            {
+              "name": "http2noDialH2RoundTripper.RoundTrip"
+            },
+            {
+              "name": "http2pipe.Read"
+            },
+            {
+              "name": "http2priorityWriteSchedulerRFC7540.CloseStream"
+            },
+            {
+              "name": "http2priorityWriteSchedulerRFC7540.OpenStream"
+            },
+            {
+              "name": "http2priorityWriteSchedulerRFC9218.OpenStream"
+            },
+            {
+              "name": "http2pseudoHeaderError.Error"
+            },
+            {
+              "name": "http2requestBody.Close"
+            },
+            {
+              "name": "http2requestBody.Read"
+            },
+            {
+              "name": "http2responseWriter.Flush"
+            },
+            {
+              "name": "http2responseWriter.FlushError"
+            },
+            {
+              "name": "http2responseWriter.Push"
+            },
+            {
+              "name": "http2responseWriter.SetReadDeadline"
+            },
+            {
+              "name": "http2responseWriter.SetWriteDeadline"
+            },
+            {
+              "name": "http2responseWriter.Write"
+            },
+            {
+              "name": "http2responseWriter.WriteHeader"
+            },
+            {
+              "name": "http2responseWriter.WriteString"
+            },
+            {
+              "name": "http2roundRobinWriteScheduler.OpenStream"
+            },
+            {
+              "name": "http2serverConn.CloseConn"
+            },
+            {
+              "name": "http2serverConn.Flush"
+            },
+            {
+              "name": "http2stickyErrWriter.Write"
+            },
+            {
+              "name": "http2transportResponseBody.Close"
+            },
+            {
+              "name": "http2transportResponseBody.Read"
+            },
+            {
+              "name": "http2unencryptedTransport.RoundTrip"
+            },
+            {
+              "name": "http2writeData.String"
+            },
+            {
+              "name": "initALPNRequest.ServeHTTP"
+            },
+            {
+              "name": "loggingConn.Close"
+            },
+            {
+              "name": "loggingConn.Read"
+            },
+            {
+              "name": "loggingConn.Write"
+            },
+            {
+              "name": "maxBytesReader.Close"
+            },
+            {
+              "name": "maxBytesReader.Read"
+            },
+            {
+              "name": "onceCloseListener.Close"
+            },
+            {
+              "name": "persistConn.Read"
+            },
+            {
+              "name": "persistConnWriter.ReadFrom"
+            },
+            {
+              "name": "persistConnWriter.Write"
+            },
+            {
+              "name": "populateResponse.Write"
+            },
+            {
+              "name": "populateResponse.WriteHeader"
+            },
+            {
+              "name": "readTrackingBody.Close"
+            },
+            {
+              "name": "readTrackingBody.Read"
+            },
+            {
+              "name": "readWriteCloserBody.CloseWrite"
+            },
+            {
+              "name": "readWriteCloserBody.Read"
+            },
+            {
+              "name": "redirectHandler.ServeHTTP"
+            },
+            {
+              "name": "response.Flush"
+            },
+            {
+              "name": "response.FlushError"
+            },
+            {
+              "name": "response.Hijack"
+            },
+            {
+              "name": "response.ReadFrom"
+            },
+            {
+              "name": "response.Write"
+            },
+            {
+              "name": "response.WriteHeader"
+            },
+            {
+              "name": "response.WriteString"
+            },
+            {
+              "name": "serverHandler.ServeHTTP"
+            },
+            {
+              "name": "socksDialer.DialWithConn"
+            },
+            {
+              "name": "socksUsernamePassword.Authenticate"
+            },
+            {
+              "name": "stringWriter.WriteString"
+            },
+            {
+              "name": "timeoutHandler.ServeHTTP"
+            },
+            {
+              "name": "timeoutWriter.Write"
+            },
+            {
+              "name": "timeoutWriter.WriteHeader"
+            },
+            {
+              "name": "transportReadFromServerError.Error"
+            },
+            {
+              "name": "unencryptedHTTP2Request.ServeHTTP"
+            }
+          ],
+          "defaultStatus": "unaffected"
+        },
+        {
+          "vendor": "Go standard library",
+          "product": "net/http/internal/http2",
+          "collectionURL": "https://pkg.go.dev",
+          "packageName": "net/http/internal/http2",
+          "versions": [
+            {
+              "version": "1.27.0-0",
+              "lessThan": "1.27.2",
+              "status": "affected",
+              "versionType": "semver"
+            }
+          ],
+          "programRoutines": [
+            {
+              "name": "Framer.readMetaFrame"
+            },
+            {
+              "name": "ClientConn.Close"
+            },
+            {
+              "name": "ClientConn.Ping"
+            },
+            {
+              "name": "ClientConn.RoundTrip"
+            },
+            {
+              "name": "ClientConn.Shutdown"
+            },
+            {
+              "name": "Framer.ReadFrame"
+            },
+            {
+              "name": "Framer.ReadFrameForHeader"
+            },
+            {
+              "name": "Framer.ReadFrameHeader"
+            },
+            {
+              "name": "Framer.WriteContinuation"
+            },
+            {
+              "name": "Framer.WriteData"
+            },
+            {
+              "name": "Framer.WriteDataPadded"
+            },
+            {
+              "name": "Framer.WriteGoAway"
+            },
+            {
+              "name": "Framer.WriteHeaders"
+            },
+            {
+              "name": "Framer.WritePing"
+            },
+            {
+              "name": "Framer.WritePriority"
+            },
+            {
+              "name": "Framer.WritePriorityUpdate"
+            },
+            {
+              "name": "Framer.WritePushPromise"
+            },
+            {
+              "name": "Framer.WriteRSTStream"
+            },
+            {
+              "name": "Framer.WriteRawFrame"
+            },
+            {
+              "name": "Framer.WriteSettings"
+            },
+            {
+              "name": "Framer.WriteSettingsAck"
+            },
+            {
+              "name": "Framer.WriteWindowUpdate"
+            },
+            {
+              "name": "NetHTTPClientConn.Close"
+            },
+            {
+              "name": "NetHTTPClientConn.Ping"
+            },
+            {
+              "name": "NetHTTPClientConn.RoundTrip"
+            },
+            {
+              "name": "ReadFrameHeader"
+            },
+            {
+              "name": "Server.GracefulShutdown"
+            },
+            {
+              "name": "Server.ServeConn"
+            },
+            {
+              "name": "SettingsFrame.ForeachSetting"
+            },
+            {
+              "name": "Transport.AddConn"
+            },
+            {
+              "name": "Transport.CloseIdleConnections"
+            },
+            {
+              "name": "Transport.NewClientConn"
+            },
+            {
+              "name": "Transport.RoundTrip"
+            },
+            {
+              "name": "Transport.RoundTripOpt"
+            },
+            {
+              "name": "bufferedWriter.Flush"
+            },
+            {
+              "name": "bufferedWriter.Write"
+            },
+            {
+              "name": "bufferedWriterTimeoutWriter.Write"
+            },
+            {
+              "name": "chunkWriter.Write"
+            },
+            {
+              "name": "clientConnPool.GetClientConn"
+            },
+            {
+              "name": "gzipReader.Close"
+            },
+            {
+              "name": "gzipReader.Read"
+            },
+            {
+              "name": "noDialClientConnPool.GetClientConn"
+            },
+            {
+              "name": "requestBody.Close"
+            },
+            {
+              "name": "responseWriter.Flush"
+            },
+            {
+              "name": "responseWriter.FlushError"
+            },
+            {
+              "name": "responseWriter.Push"
+            },
+            {
+              "name": "responseWriter.Write"
+            },
+            {
+              "name": "responseWriter.WriteHeader"
+            },
+            {
+              "name": "responseWriter.WriteString"
+            },
+            {
+              "name": "serve400Handler.ServeHTTP"
+            },
+            {
+              "name": "serverConn.Flush"
+            },
+            {
+              "name": "stickyErrWriter.Write"
+            },
+            {
+              "name": "transportResponseBody.Close"
+            },
+            {
+              "name": "transportResponseBody.Read"
+            }
+          ],
+          "defaultStatus": "unaffected"
+        },
+        {
+          "vendor": "golang.org/x/net",
+          "product": "golang.org/x/net/http2",
+          "collectionURL": "https://pkg.go.dev",
+          "packageName": "golang.org/x/net/http2",
+          "versions": [
+            {
+              "version": "0",
+              "lessThan": "0.60.0",
+              "status": "affected",
+              "versionType": "semver"
+            }
+          ],
+          "programRoutines": [
+            {
+              "name": "Framer.readMetaFrame"
+            },
+            {
+              "name": "ClientConn.Close"
+            },
+            {
+              "name": "ClientConn.Ping"
+            },
+            {
+              "name": "ClientConn.RoundTrip"
+            },
+            {
+              "name": "ClientConn.Shutdown"
+            },
+            {
+              "name": "ConfigureServer"
+            },
+            {
+              "name": "ConfigureTransport"
+            },
+            {
+              "name": "ConfigureTransports"
+            },
+            {
+              "name": "ConnectionError.Error"
+            },
+            {
+              "name": "ErrCode.String"
+            },
+            {
+              "name": "FrameHeader.String"
+            },
+            {
+              "name": "FrameType.String"
+            },
+            {
+              "name": "FrameWriteRequest.String"
+            },
+            {
+              "name": "Framer.ReadFrame"
+            },
+            {
+              "name": "Framer.ReadFrameForHeader"
+            },
+            {
+              "name": "Framer.ReadFrameHeader"
+            },
+            {
+              "name": "Framer.WriteContinuation"
+            },
+            {
+              "name": "Framer.WriteData"
+            },
+            {
+              "name": "Framer.WriteDataPadded"
+            },
+            {
+              "name": "Framer.WriteGoAway"
+            },
+            {
+              "name": "Framer.WriteHeaders"
+            },
+            {
+              "name": "Framer.WritePing"
+            },
+            {
+              "name": "Framer.WritePriority"
+            },
+            {
+              "name": "Framer.WritePriorityUpdate"
+            },
+            {
+              "name": "Framer.WritePushPromise"
+            },
+            {
+              "name": "Framer.WriteRSTStream"
+            },
+            {
+              "name": "Framer.WriteRawFrame"
+            },
+            {
+              "name": "Framer.WriteSettings"
+            },
+            {
+              "name": "Framer.WriteSettingsAck"
+            },
+            {
+              "name": "Framer.WriteWindowUpdate"
+            },
+            {
+              "name": "GoAwayError.Error"
+            },
+            {
+              "name": "ReadFrameHeader"
+            },
+            {
+              "name": "Server.ServeConn"
+            },
+            {
+              "name": "Setting.String"
+            },
+            {
+              "name": "SettingID.String"
+            },
+            {
+              "name": "SettingsFrame.ForeachSetting"
+            },
+            {
+              "name": "StreamError.Error"
+            },
+            {
+              "name": "Transport.CloseIdleConnections"
+            },
+            {
+              "name": "Transport.NewClientConn"
+            },
+            {
+              "name": "Transport.RoundTrip"
+            },
+            {
+              "name": "Transport.RoundTripOpt"
+            },
+            {
+              "name": "bufferedWriter.Flush"
+            },
+            {
+              "name": "bufferedWriter.Write"
+            },
+            {
+              "name": "bufferedWriterTimeoutWriter.Write"
+            },
+            {
+              "name": "chunkWriter.Write"
+            },
+            {
+              "name": "clientConnPool.GetClientConn"
+            },
+            {
+              "name": "connError.Error"
+            },
+            {
+              "name": "dataBuffer.Read"
+            },
+            {
+              "name": "duplicatePseudoHeaderError.Error"
+            },
+            {
+              "name": "gzipReader.Close"
+            },
+            {
+              "name": "gzipReader.Read"
+            },
+            {
+              "name": "headerFieldNameError.Error"
+            },
+            {
+              "name": "headerFieldValueError.Error"
+            },
+            {
+              "name": "netHTTPClientConn.Close"
+            },
+            {
+              "name": "netHTTPClientConn.RoundTrip"
+            },
+            {
+              "name": "noDialClientConnPool.GetClientConn"
+            },
+            {
+              "name": "noDialH2RoundTripper.NewClientConn"
+            },
+            {
+              "name": "noDialH2RoundTripper.RoundTrip"
+            },
+            {
+              "name": "pipe.Read"
+            },
+            {
+              "name": "priorityWriteSchedulerRFC7540.CloseStream"
+            },
+            {
+              "name": "priorityWriteSchedulerRFC7540.OpenStream"
+            },
+            {
+              "name": "priorityWriteSchedulerRFC9218.OpenStream"
+            },
+            {
+              "name": "pseudoHeaderError.Error"
+            },
+            {
+              "name": "requestBody.Close"
+            },
+            {
+              "name": "requestBody.Read"
+            },
+            {
+              "name": "responseWriter.Flush"
+            },
+            {
+              "name": "responseWriter.FlushError"
+            },
+            {
+              "name": "responseWriter.Push"
+            },
+            {
+              "name": "responseWriter.SetReadDeadline"
+            },
+            {
+              "name": "responseWriter.SetWriteDeadline"
+            },
+            {
+              "name": "responseWriter.Write"
+            },
+            {
+              "name": "responseWriter.WriteHeader"
+            },
+            {
+              "name": "responseWriter.WriteString"
+            },
+            {
+              "name": "roundRobinWriteScheduler.OpenStream"
+            },
+            {
+              "name": "serverConn.CloseConn"
+            },
+            {
+              "name": "serverConn.Flush"
+            },
+            {
+              "name": "stickyErrWriter.Write"
+            },
+            {
+              "name": "transportResponseBody.Close"
+            },
+            {
+              "name": "transportResponseBody.Read"
+            },
+            {
+              "name": "unencryptedTransport.RoundTrip"
+            },
+            {
+              "name": "writeData.String"
+            }
+          ],
+          "defaultStatus": "unaffected"
+        }
+      ],
+      "problemTypes": [
+        {
+          "descriptions": [
+            {
+              "lang": "en",
+              "description": "CWE-405: Asymmetric Resource Consumption (Amplification)"
+            }
+          ]
+        }
+      ],
+      "references": [
+        {
+          "url": "https://go.dev/cl/847185"
+        },
+        {
+          "url": "https://go.dev/cl/847314"
+        },
+        {
+          "url": "https://go.dev/issue/81857"
+        },
+        {
+          "url": "https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"
+        },
+        {
+          "url": "https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs"
+        },
+        {
+          "url": "https://pkg.go.dev/vuln/GO-2026-6603"
+        }
+      ],
+      "credits": [
+        {
+          "lang": "en",
+          "value": "RyotaK (https://ryotak.net) of GMO Flatt Security Inc."
+        }
+      ]
+    }
+  }
+}
\ No newline at end of file
diff --git a/data/cve/v5/GO-2026-6604.json b/data/cve/v5/GO-2026-6604.json
new file mode 100644
index 0000000..a0cadc3
--- /dev/null
+++ b/data/cve/v5/GO-2026-6604.json
@@ -0,0 +1,147 @@
+{
+  "dataType": "CVE_RECORD",
+  "dataVersion": "5.0",
+  "cveMetadata": {
+    "cveId": "CVE-2026-56857"
+  },
+  "containers": {
+    "cna": {
+      "providerMetadata": {
+        "orgId": "1bb62c36-49e3-4200-9d77-64a1400537cc"
+      },
+      "title": "Root.Mkdir(All) can follow junctions out of the root on Windows in os",
+      "descriptions": [
+        {
+          "lang": "en",
+          "value": "On Windows, when the target of Root.Mkdir or Root.MkdirAll is a junction pointing to an empty location, the operation can create a directory at the junction target even when that target is located outside the root. This only applies to operations where the last path component is a junction (path/to/junction, but not path/junction/target)."
+        }
+      ],
+      "affected": [
+        {
+          "vendor": "Go standard library",
+          "product": "os",
+          "collectionURL": "https://pkg.go.dev",
+          "packageName": "os",
+          "versions": [
+            {
+              "version": "0",
+              "lessThan": "1.26.9",
+              "status": "affected",
+              "versionType": "semver"
+            },
+            {
+              "version": "1.27.0-0",
+              "lessThan": "1.27.2",
+              "status": "affected",
+              "versionType": "semver"
+            }
+          ],
+          "platforms": [
+            "windows"
+          ],
+          "programRoutines": [
+            {
+              "name": "Root.Mkdir"
+            },
+            {
+              "name": "doInRoot"
+            },
+            {
+              "name": "rootMkdirAll"
+            },
+            {
+              "name": "Root.Chmod"
+            },
+            {
+              "name": "Root.Chown"
+            },
+            {
+              "name": "Root.Chtimes"
+            },
+            {
+              "name": "Root.Lchown"
+            },
+            {
+              "name": "Root.Link"
+            },
+            {
+              "name": "Root.MkdirAll"
+            },
+            {
+              "name": "Root.Remove"
+            },
+            {
+              "name": "Root.RemoveAll"
+            },
+            {
+              "name": "Root.Rename"
+            },
+            {
+              "name": "Root.Symlink"
+            }
+          ],
+          "defaultStatus": "unaffected"
+        },
+        {
+          "vendor": "Go standard library",
+          "product": "internal/syscall/windows",
+          "collectionURL": "https://pkg.go.dev",
+          "packageName": "internal/syscall/windows",
+          "versions": [
+            {
+              "version": "0",
+              "lessThan": "1.26.9",
+              "status": "affected",
+              "versionType": "semver"
+            },
+            {
+              "version": "1.27.0-0",
+              "lessThan": "1.27.2",
+              "status": "affected",
+              "versionType": "semver"
+            }
+          ],
+          "platforms": [
+            "windows"
+          ],
+          "programRoutines": [
+            {
+              "name": "Mkdirat"
+            }
+          ],
+          "defaultStatus": "unaffected"
+        }
+      ],
+      "problemTypes": [
+        {
+          "descriptions": [
+            {
+              "lang": "en",
+              "description": "CWE-1386: Insecure Operation on Windows Junction / Mount Point"
+            }
+          ]
+        }
+      ],
+      "references": [
+        {
+          "url": "https://go.dev/cl/847305"
+        },
+        {
+          "url": "https://go.dev/issue/81739"
+        },
+        {
+          "url": "https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"
+        },
+        {
+          "url": "https://pkg.go.dev/vuln/GO-2026-6604"
+        }
+      ],
+      "credits": [
+        {
+          "lang": "en",
+          "value": "Daniele Ballarini"
+        }
+      ]
+    }
+  }
+}
\ No newline at end of file
diff --git a/data/cve/v5/GO-2026-6605.json b/data/cve/v5/GO-2026-6605.json
new file mode 100644
index 0000000..9daa8d5
--- /dev/null
+++ b/data/cve/v5/GO-2026-6605.json
@@ -0,0 +1,159 @@
+{
+  "dataType": "CVE_RECORD",
+  "dataVersion": "5.0",
+  "cveMetadata": {
+    "cveId": "CVE-2026-56866"
+  },
+  "containers": {
+    "cna": {
+      "providerMetadata": {
+        "orgId": "1bb62c36-49e3-4200-9d77-64a1400537cc"
+      },
+      "title": "HTTP/1 client connection desynchronization after CONNECT rejection in net/http",
+      "descriptions": [
+        {
+          "lang": "en",
+          "value": "When http.Transport sends an HTTP/1 CONNECT request with a non-empty Request.Body, it writes the body directly to the connection without framing after the request headers. If the server rejects the CONNECT request with a non-2xx keep-alive response, Transport returns the connection to the idle pool. Because CONNECT requests do not have a request body, the server may interpret the trailing body bytes as a subsequent pipelined HTTP/1.1 request on the connection, leaving the pooled connection desynchronized and causing the next caller that reuses it to read the response to the injected request. In reverse proxies (including httputil.ReverseProxy) that forward CONNECT requests through a shared Transport, this can lead to cross-user response poisoning."
+        }
+      ],
+      "affected": [
+        {
+          "vendor": "Go standard library",
+          "product": "net/http",
+          "collectionURL": "https://pkg.go.dev",
+          "packageName": "net/http",
+          "versions": [
+            {
+              "version": "0",
+              "lessThan": "1.26.9",
+              "status": "affected",
+              "versionType": "semver"
+            },
+            {
+              "version": "1.27.0-0",
+              "lessThan": "1.27.2",
+              "status": "affected",
+              "versionType": "semver"
+            }
+          ],
+          "programRoutines": [
+            {
+              "name": "persistConn.readLoop"
+            },
+            {
+              "name": "Client.CloseIdleConnections"
+            },
+            {
+              "name": "Client.Do"
+            },
+            {
+              "name": "Client.Get"
+            },
+            {
+              "name": "Client.Head"
+            },
+            {
+              "name": "Client.Post"
+            },
+            {
+              "name": "Client.PostForm"
+            },
+            {
+              "name": "ClientConn.Close"
+            },
+            {
+              "name": "ClientConn.RoundTrip"
+            },
+            {
+              "name": "Get"
+            },
+            {
+              "name": "Head"
+            },
+            {
+              "name": "Post"
+            },
+            {
+              "name": "PostForm"
+            },
+            {
+              "name": "Transport.CloseIdleConnections"
+            },
+            {
+              "name": "Transport.NewClientConn"
+            },
+            {
+              "name": "Transport.RoundTrip"
+            },
+            {
+              "name": "http1ClientConn.Close"
+            },
+            {
+              "name": "http1ClientConn.RoundTrip"
+            }
+          ],
+          "defaultStatus": "unaffected"
+        },
+        {
+          "vendor": "Go standard library",
+          "product": "net/http/httputil",
+          "collectionURL": "https://pkg.go.dev",
+          "packageName": "net/http/httputil",
+          "versions": [
+            {
+              "version": "0",
+              "lessThan": "1.26.9",
+              "status": "affected",
+              "versionType": "semver"
+            },
+            {
+              "version": "1.27.0-0",
+              "lessThan": "1.27.2",
+              "status": "affected",
+              "versionType": "semver"
+            }
+          ],
+          "programRoutines": [
+            {
+              "name": "ReverseProxy.ServeHTTP"
+            },
+            {
+              "name": "DumpRequestOut"
+            }
+          ],
+          "defaultStatus": "unaffected"
+        }
+      ],
+      "problemTypes": [
+        {
+          "descriptions": [
+            {
+              "lang": "en",
+              "description": "CWE-444: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')"
+            }
+          ]
+        }
+      ],
+      "references": [
+        {
+          "url": "https://go.dev/cl/847306"
+        },
+        {
+          "url": "https://go.dev/issue/81740"
+        },
+        {
+          "url": "https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"
+        },
+        {
+          "url": "https://pkg.go.dev/vuln/GO-2026-6605"
+        }
+      ],
+      "credits": [
+        {
+          "lang": "en",
+          "value": "Xclow3n (Rajat Raghav)"
+        }
+      ]
+    }
+  }
+}
\ No newline at end of file
diff --git a/data/cve/v5/GO-2026-6607.json b/data/cve/v5/GO-2026-6607.json
new file mode 100644
index 0000000..efb01da
--- /dev/null
+++ b/data/cve/v5/GO-2026-6607.json
@@ -0,0 +1,100 @@
+{
+  "dataType": "CVE_RECORD",
+  "dataVersion": "5.0",
+  "cveMetadata": {
+    "cveId": "CVE-2026-97031"
+  },
+  "containers": {
+    "cna": {
+      "providerMetadata": {
+        "orgId": "1bb62c36-49e3-4200-9d77-64a1400537cc"
+      },
+      "title": "Reject malformed ECH outer extension references in crypto/tls",
+      "descriptions": [
+        {
+          "lang": "en",
+          "value": "Multiple ECH outer extension references are not permitted under RFC 9849; previously, a client could send a well-crafted packet that could trigger memory exhaustion in the server process by specifying multiple references. We now reject these as malformed and curb the memory amplification vector as a result."
+        }
+      ],
+      "affected": [
+        {
+          "vendor": "Go standard library",
+          "product": "crypto/tls",
+          "collectionURL": "https://pkg.go.dev",
+          "packageName": "crypto/tls",
+          "versions": [
+            {
+              "version": "0",
+              "lessThan": "1.26.9",
+              "status": "affected",
+              "versionType": "semver"
+            },
+            {
+              "version": "1.27.0-0",
+              "lessThan": "1.27.2",
+              "status": "affected",
+              "versionType": "semver"
+            }
+          ],
+          "programRoutines": [
+            {
+              "name": "decodeInnerClientHello"
+            },
+            {
+              "name": "Conn.Handshake"
+            },
+            {
+              "name": "Conn.HandshakeContext"
+            },
+            {
+              "name": "Conn.Read"
+            },
+            {
+              "name": "Conn.Write"
+            },
+            {
+              "name": "Dial"
+            },
+            {
+              "name": "DialWithDialer"
+            },
+            {
+              "name": "Dialer.Dial"
+            },
+            {
+              "name": "Dialer.DialContext"
+            },
+            {
+              "name": "QUICConn.Start"
+            }
+          ],
+          "defaultStatus": "unaffected"
+        }
+      ],
+      "problemTypes": [
+        {
+          "descriptions": [
+            {
+              "lang": "en",
+              "description": "CWE-405: Asymmetric Resource Consumption"
+            }
+          ]
+        }
+      ],
+      "references": [
+        {
+          "url": "https://go.dev/cl/847312"
+        },
+        {
+          "url": "https://go.dev/issue/81855"
+        },
+        {
+          "url": "https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"
+        },
+        {
+          "url": "https://pkg.go.dev/vuln/GO-2026-6607"
+        }
+      ]
+    }
+  }
+}
\ No newline at end of file
diff --git a/data/cve/v5/GO-2026-6608.json b/data/cve/v5/GO-2026-6608.json
new file mode 100644
index 0000000..d959f88
--- /dev/null
+++ b/data/cve/v5/GO-2026-6608.json
@@ -0,0 +1,129 @@
+{
+  "dataType": "CVE_RECORD",
+  "dataVersion": "5.0",
+  "cveMetadata": {
+    "cveId": "CVE-2026-94440"
+  },
+  "containers": {
+    "cna": {
+      "providerMetadata": {
+        "orgId": "1bb62c36-49e3-4200-9d77-64a1400537cc"
+      },
+      "title": "Memory limit bypass when parsing MIME headers in net/textproto, mime/multipart",
+      "descriptions": [
+        {
+          "lang": "en",
+          "value": "Parsing a multipart form can bypass memory limits and read an arbitrarily long line into memory when the remaining limit at the start of a part is less than 400 bytes."
+        }
+      ],
+      "affected": [
+        {
+          "vendor": "Go standard library",
+          "product": "net/textproto",
+          "collectionURL": "https://pkg.go.dev",
+          "packageName": "net/textproto",
+          "versions": [
+            {
+              "version": "0",
+              "lessThan": "1.26.9",
+              "status": "affected",
+              "versionType": "semver"
+            },
+            {
+              "version": "1.27.0-0",
+              "lessThan": "1.27.2",
+              "status": "affected",
+              "versionType": "semver"
+            }
+          ],
+          "programRoutines": [
+            {
+              "name": "readMIMEHeader"
+            },
+            {
+              "name": "Reader.readContinuedLineSlice"
+            },
+            {
+              "name": "Reader.ReadContinuedLine"
+            },
+            {
+              "name": "Reader.ReadContinuedLineBytes"
+            },
+            {
+              "name": "Reader.ReadMIMEHeader"
+            }
+          ],
+          "defaultStatus": "unaffected"
+        },
+        {
+          "vendor": "Go standard library",
+          "product": "mime/multipart",
+          "collectionURL": "https://pkg.go.dev",
+          "packageName": "mime/multipart",
+          "versions": [
+            {
+              "version": "0",
+              "lessThan": "1.26.9",
+              "status": "affected",
+              "versionType": "semver"
+            },
+            {
+              "version": "1.27.0-0",
+              "lessThan": "1.27.2",
+              "status": "affected",
+              "versionType": "semver"
+            }
+          ],
+          "programRoutines": [
+            {
+              "name": "Part.populateHeaders"
+            },
+            {
+              "name": "Reader.readForm"
+            },
+            {
+              "name": "Reader.NextPart"
+            },
+            {
+              "name": "Reader.NextRawPart"
+            },
+            {
+              "name": "Reader.ReadForm"
+            }
+          ],
+          "defaultStatus": "unaffected"
+        }
+      ],
+      "problemTypes": [
+        {
+          "descriptions": [
+            {
+              "lang": "en",
+              "description": "CWE-770: Allocation of Resources Without Limits or Throttling"
+            }
+          ]
+        }
+      ],
+      "references": [
+        {
+          "url": "https://go.dev/cl/847307"
+        },
+        {
+          "url": "https://go.dev/issue/81741"
+        },
+        {
+          "url": "https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"
+        },
+        {
+          "url": "https://pkg.go.dev/vuln/GO-2026-6608"
+        }
+      ],
+      "credits": [
+        {
+          "lang": "en",
+          "value": "Jakub Ciolek (https://ciolek.dev)"
+        }
+      ]
+    }
+  }
+}
\ No newline at end of file
diff --git a/data/cve/v5/GO-2026-6609.json b/data/cve/v5/GO-2026-6609.json
new file mode 100644
index 0000000..0d495cf
--- /dev/null
+++ b/data/cve/v5/GO-2026-6609.json
@@ -0,0 +1,94 @@
+{
+  "dataType": "CVE_RECORD",
+  "dataVersion": "5.0",
+  "cveMetadata": {
+    "cveId": "CVE-2026-78667"
+  },
+  "containers": {
+    "cna": {
+      "providerMetadata": {
+        "orgId": "1bb62c36-49e3-4200-9d77-64a1400537cc"
+      },
+      "title": "Lack of limit on size of parsed Range headers in net/http",
+      "descriptions": [
+        {
+          "lang": "en",
+          "value": "When parsing a Range header containing a large number of small ranges, FileServer(FS), ServeContent, and ServeFile(FS) can consume an excessive amount of CPU."
+        }
+      ],
+      "affected": [
+        {
+          "vendor": "Go standard library",
+          "product": "net/http",
+          "collectionURL": "https://pkg.go.dev",
+          "packageName": "net/http",
+          "versions": [
+            {
+              "version": "0",
+              "lessThan": "1.26.9",
+              "status": "affected",
+              "versionType": "semver"
+            },
+            {
+              "version": "1.27.0-0",
+              "lessThan": "1.27.2",
+              "status": "affected",
+              "versionType": "semver"
+            }
+          ],
+          "programRoutines": [
+            {
+              "name": "parseRange"
+            },
+            {
+              "name": "ServeContent"
+            },
+            {
+              "name": "ServeFile"
+            },
+            {
+              "name": "ServeFileFS"
+            },
+            {
+              "name": "fileHandler.ServeHTTP"
+            },
+            {
+              "name": "fileTransport.RoundTrip"
+            }
+          ],
+          "defaultStatus": "unaffected"
+        }
+      ],
+      "problemTypes": [
+        {
+          "descriptions": [
+            {
+              "lang": "en",
+              "description": "CWE-770: Allocation of Resources Without Limits or Throttling"
+            }
+          ]
+        }
+      ],
+      "references": [
+        {
+          "url": "https://go.dev/cl/847309"
+        },
+        {
+          "url": "https://go.dev/issue/81858"
+        },
+        {
+          "url": "https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"
+        },
+        {
+          "url": "https://pkg.go.dev/vuln/GO-2026-6609"
+        }
+      ],
+      "credits": [
+        {
+          "lang": "en",
+          "value": "Jakub Ciolek (https://ciolek.dev)"
+        }
+      ]
+    }
+  }
+}
\ No newline at end of file
diff --git a/data/cve/v5/GO-2026-6610.json b/data/cve/v5/GO-2026-6610.json
new file mode 100644
index 0000000..b3cc837
--- /dev/null
+++ b/data/cve/v5/GO-2026-6610.json
@@ -0,0 +1,233 @@
+{
+  "dataType": "CVE_RECORD",
+  "dataVersion": "5.0",
+  "cveMetadata": {
+    "cveId": "CVE-2026-78660"
+  },
+  "containers": {
+    "cna": {
+      "providerMetadata": {
+        "orgId": "1bb62c36-49e3-4200-9d77-64a1400537cc"
+      },
+      "title": "HTTP/2 transport accepts malformed framing-related headers in net/http",
+      "descriptions": [
+        {
+          "lang": "en",
+          "value": "Historically, we have been rather lax about malformed framing-related headers in our HTTP/2 implementation, as they cannot interfere with HTTP/2 framing. However, this makes it possible for our HTTP/2 implementation to forward responses containing such headers to an HTTP/1 client when acting as a reverse proxy. If the HTTP/1 client also does not behave strictly enough, this can result in response smuggling."
+        }
+      ],
+      "affected": [
+        {
+          "vendor": "Go standard library",
+          "product": "net/http",
+          "collectionURL": "https://pkg.go.dev",
+          "packageName": "net/http",
+          "versions": [
+            {
+              "version": "0",
+              "lessThan": "1.26.9",
+              "status": "affected",
+              "versionType": "semver"
+            }
+          ],
+          "programRoutines": [
+            {
+              "name": "http2clientConnReadLoop.handleResponse"
+            },
+            {
+              "name": "Client.CloseIdleConnections"
+            },
+            {
+              "name": "Client.Do"
+            },
+            {
+              "name": "Client.Get"
+            },
+            {
+              "name": "Client.Head"
+            },
+            {
+              "name": "Client.Post"
+            },
+            {
+              "name": "Client.PostForm"
+            },
+            {
+              "name": "ClientConn.Close"
+            },
+            {
+              "name": "ClientConn.RoundTrip"
+            },
+            {
+              "name": "Get"
+            },
+            {
+              "name": "Head"
+            },
+            {
+              "name": "Post"
+            },
+            {
+              "name": "PostForm"
+            },
+            {
+              "name": "Transport.CloseIdleConnections"
+            },
+            {
+              "name": "Transport.NewClientConn"
+            },
+            {
+              "name": "Transport.RoundTrip"
+            },
+            {
+              "name": "http1ClientConn.Close"
+            },
+            {
+              "name": "http1ClientConn.RoundTrip"
+            },
+            {
+              "name": "http2Transport.NewClientConn"
+            },
+            {
+              "name": "http2Transport.RoundTrip"
+            },
+            {
+              "name": "http2Transport.RoundTripOpt"
+            },
+            {
+              "name": "http2clientConnPool.GetClientConn"
+            },
+            {
+              "name": "http2noDialClientConnPool.GetClientConn"
+            },
+            {
+              "name": "http2noDialH2RoundTripper.NewClientConn"
+            },
+            {
+              "name": "http2noDialH2RoundTripper.RoundTrip"
+            },
+            {
+              "name": "http2unencryptedTransport.RoundTrip"
+            }
+          ],
+          "defaultStatus": "unaffected"
+        },
+        {
+          "vendor": "Go standard library",
+          "product": "net/http/internal/http2",
+          "collectionURL": "https://pkg.go.dev",
+          "packageName": "net/http/internal/http2",
+          "versions": [
+            {
+              "version": "1.27.0-0",
+              "lessThan": "1.27.2",
+              "status": "affected",
+              "versionType": "semver"
+            }
+          ],
+          "programRoutines": [
+            {
+              "name": "clientConnReadLoop.handleResponse"
+            },
+            {
+              "name": "Transport.AddConn"
+            },
+            {
+              "name": "Transport.NewClientConn"
+            },
+            {
+              "name": "Transport.RoundTrip"
+            },
+            {
+              "name": "Transport.RoundTripOpt"
+            },
+            {
+              "name": "clientConnPool.GetClientConn"
+            },
+            {
+              "name": "noDialClientConnPool.GetClientConn"
+            }
+          ],
+          "defaultStatus": "unaffected"
+        },
+        {
+          "vendor": "golang.org/x/net",
+          "product": "golang.org/x/net/http2",
+          "collectionURL": "https://pkg.go.dev",
+          "packageName": "golang.org/x/net/http2",
+          "versions": [
+            {
+              "version": "0",
+              "lessThan": "0.60.0",
+              "status": "affected",
+              "versionType": "semver"
+            }
+          ],
+          "programRoutines": [
+            {
+              "name": "clientConnReadLoop.handleResponse"
+            },
+            {
+              "name": "Transport.NewClientConn"
+            },
+            {
+              "name": "Transport.RoundTrip"
+            },
+            {
+              "name": "Transport.RoundTripOpt"
+            },
+            {
+              "name": "clientConnPool.GetClientConn"
+            },
+            {
+              "name": "noDialClientConnPool.GetClientConn"
+            },
+            {
+              "name": "noDialH2RoundTripper.NewClientConn"
+            },
+            {
+              "name": "noDialH2RoundTripper.RoundTrip"
+            },
+            {
+              "name": "unencryptedTransport.RoundTrip"
+            }
+          ],
+          "defaultStatus": "unaffected"
+        }
+      ],
+      "problemTypes": [
+        {
+          "descriptions": [
+            {
+              "lang": "en",
+              "description": "CWE-444: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')"
+            }
+          ]
+        }
+      ],
+      "references": [
+        {
+          "url": "https://go.dev/cl/835145"
+        },
+        {
+          "url": "https://go.dev/cl/836385"
+        },
+        {
+          "url": "https://go.dev/issue/81115"
+        },
+        {
+          "url": "https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"
+        },
+        {
+          "url": "https://pkg.go.dev/vuln/GO-2026-6610"
+        }
+      ],
+      "credits": [
+        {
+          "lang": "en",
+          "value": "TJ Barton"
+        }
+      ]
+    }
+  }
+}
\ No newline at end of file
diff --git a/data/cve/v5/GO-2026-6611.json b/data/cve/v5/GO-2026-6611.json
new file mode 100644
index 0000000..f4232ab
--- /dev/null
+++ b/data/cve/v5/GO-2026-6611.json
@@ -0,0 +1,1343 @@
+{
+  "dataType": "CVE_RECORD",
+  "dataVersion": "5.0",
+  "cveMetadata": {
+    "cveId": "CVE-2026-78669"
+  },
+  "containers": {
+    "cna": {
+      "providerMetadata": {
+        "orgId": "1bb62c36-49e3-4200-9d77-64a1400537cc"
+      },
+      "title": "Excessive CPU consumption from repeated initial window changes in net/http",
+      "descriptions": [
+        {
+          "lang": "en",
+          "value": "A malicious HTTP/2 peer can cause excessive CPU consumption in the client or server by opening a large number of streams and then sending many small SETTINGS frames containing SETTINGS_INITIAL_WINDOW_SIZE values."
+        }
+      ],
+      "affected": [
+        {
+          "vendor": "Go standard library",
+          "product": "net/http",
+          "collectionURL": "https://pkg.go.dev",
+          "packageName": "net/http",
+          "versions": [
+            {
+              "version": "0",
+              "lessThan": "1.26.9",
+              "status": "affected",
+              "versionType": "semver"
+            }
+          ],
+          "programRoutines": [
+            {
+              "name": "http2outflow.add"
+            },
+            {
+              "name": "http2outflow.available"
+            },
+            {
+              "name": "http2outflow.setConnFlow"
+            },
+            {
+              "name": "http2outflow.take"
+            },
+            {
+              "name": "http2Server.serveConn"
+            },
+            {
+              "name": "http2serverConn.newStream"
+            },
+            {
+              "name": "http2serverConn.processSettingInitialWindowSize"
+            },
+            {
+              "name": "http2serverConn.processWindowUpdate"
+            },
+            {
+              "name": "http2serverConn.scheduleFrameWrite"
+            },
+            {
+              "name": "http2ClientConn.addStreamLocked"
+            },
+            {
+              "name": "http2Transport.newClientConn"
+            },
+            {
+              "name": "http2clientConnReadLoop.processSettingsNoWrite"
+            },
+            {
+              "name": "http2clientConnReadLoop.processWindowUpdate"
+            },
+            {
+              "name": "http2clientConnReadLoop.streamByID"
+            },
+            {
+              "name": "http2clientStream.awaitFlowControl"
+            },
+            {
+              "name": "http2clientStream.cleanupWriteRequest"
+            },
+            {
+              "name": "http2FrameWriteRequest.Consume"
+            },
+            {
+              "name": "CanonicalHeaderKey"
+            },
+            {
+              "name": "Client.CloseIdleConnections"
+            },
+            {
+              "name": "Client.Do"
+            },
+            {
+              "name": "Client.Get"
+            },
+            {
+              "name": "Client.Head"
+            },
+            {
+              "name": "Client.Post"
+            },
+            {
+              "name": "Client.PostForm"
+            },
+            {
+              "name": "ClientConn.Close"
+            },
+            {
+              "name": "ClientConn.RoundTrip"
+            },
+            {
+              "name": "Cookie.String"
+            },
+            {
+              "name": "Cookie.Valid"
+            },
+            {
+              "name": "CrossOriginProtection.AddInsecureBypassPattern"
+            },
+            {
+              "name": "CrossOriginProtection.AddTrustedOrigin"
+            },
+            {
+              "name": "CrossOriginProtection.Check"
+            },
+            {
+              "name": "Dir.Open"
+            },
+            {
+              "name": "Error"
+            },
+            {
+              "name": "Get"
+            },
+            {
+              "name": "Handle"
+            },
+            {
+              "name": "HandleFunc"
+            },
+            {
+              "name": "HandlerFunc.ServeHTTP"
+            },
+            {
+              "name": "Head"
+            },
+            {
+              "name": "Header.Add"
+            },
+            {
+              "name": "Header.Del"
+            },
+            {
+              "name": "Header.Get"
+            },
+            {
+              "name": "Header.Set"
+            },
+            {
+              "name": "Header.Values"
+            },
+            {
+              "name": "Header.Write"
+            },
+            {
+              "name": "Header.WriteSubset"
+            },
+            {
+              "name": "ListenAndServe"
+            },
+            {
+              "name": "ListenAndServeTLS"
+            },
+            {
+              "name": "NewRequest"
+            },
+            {
+              "name": "NewRequestWithContext"
+            },
+            {
+              "name": "NotFound"
+            },
+            {
+              "name": "ParseCookie"
+            },
+            {
+              "name": "ParseSetCookie"
+            },
+            {
+              "name": "ParseTime"
+            },
+            {
+              "name": "Post"
+            },
+            {
+              "name": "PostForm"
+            },
+            {
+              "name": "ProxyFromEnvironment"
+            },
+            {
+              "name": "ReadRequest"
+            },
+            {
+              "name": "ReadResponse"
+            },
+            {
+              "name": "Redirect"
+            },
+            {
+              "name": "Request.AddCookie"
+            },
+            {
+              "name": "Request.BasicAuth"
+            },
+            {
+              "name": "Request.Cookie"
+            },
+            {
+              "name": "Request.Cookies"
+            },
+            {
+              "name": "Request.CookiesNamed"
+            },
+            {
+              "name": "Request.FormFile"
+            },
+            {
+              "name": "Request.FormValue"
+            },
+            {
+              "name": "Request.MultipartReader"
+            },
+            {
+              "name": "Request.ParseForm"
+            },
+            {
+              "name": "Request.ParseMultipartForm"
+            },
+            {
+              "name": "Request.PostFormValue"
+            },
+            {
+              "name": "Request.Referer"
+            },
+            {
+              "name": "Request.SetBasicAuth"
+            },
+            {
+              "name": "Request.UserAgent"
+            },
+            {
+              "name": "Request.Write"
+            },
+            {
+              "name": "Request.WriteProxy"
+            },
+            {
+              "name": "Response.Cookies"
+            },
+            {
+              "name": "Response.Location"
+            },
+            {
+              "name": "Response.Write"
+            },
+            {
+              "name": "ResponseController.EnableFullDuplex"
+            },
+            {
+              "name": "ResponseController.Flush"
+            },
+            {
+              "name": "ResponseController.Hijack"
+            },
+            {
+              "name": "ResponseController.SetReadDeadline"
+            },
+            {
+              "name": "ResponseController.SetWriteDeadline"
+            },
+            {
+              "name": "Serve"
+            },
+            {
+              "name": "ServeContent"
+            },
+            {
+              "name": "ServeFile"
+            },
+            {
+              "name": "ServeFileFS"
+            },
+            {
+              "name": "ServeMux.Handle"
+            },
+            {
+              "name": "ServeMux.HandleFunc"
+            },
+            {
+              "name": "ServeMux.ServeHTTP"
+            },
+            {
+              "name": "ServeTLS"
+            },
+            {
+              "name": "Server.Close"
+            },
+            {
+              "name": "Server.ListenAndServe"
+            },
+            {
+              "name": "Server.ListenAndServeTLS"
+            },
+            {
+              "name": "Server.Serve"
+            },
+            {
+              "name": "Server.ServeTLS"
+            },
+            {
+              "name": "Server.SetKeepAlivesEnabled"
+            },
+            {
+              "name": "Server.Shutdown"
+            },
+            {
+              "name": "SetCookie"
+            },
+            {
+              "name": "Transport.CancelRequest"
+            },
+            {
+              "name": "Transport.Clone"
+            },
+            {
+              "name": "Transport.CloseIdleConnections"
+            },
+            {
+              "name": "Transport.NewClientConn"
+            },
+            {
+              "name": "Transport.RoundTrip"
+            },
+            {
+              "name": "body.Close"
+            },
+            {
+              "name": "body.Read"
+            },
+            {
+              "name": "bodyEOFSignal.Close"
+            },
+            {
+              "name": "bodyEOFSignal.Read"
+            },
+            {
+              "name": "bodyLocked.Read"
+            },
+            {
+              "name": "bufioFlushWriter.Write"
+            },
+            {
+              "name": "cancelTimerBody.Close"
+            },
+            {
+              "name": "cancelTimerBody.Read"
+            },
+            {
+              "name": "checkConnErrorWriter.Write"
+            },
+            {
+              "name": "chunkWriter.Write"
+            },
+            {
+              "name": "connReader.Read"
+            },
+            {
+              "name": "connectMethodKey.String"
+            },
+            {
+              "name": "expectContinueReader.Close"
+            },
+            {
+              "name": "expectContinueReader.Read"
+            },
+            {
+              "name": "extraHeader.Write"
+            },
+            {
+              "name": "fileHandler.ServeHTTP"
+            },
+            {
+              "name": "fileTransport.RoundTrip"
+            },
+            {
+              "name": "globalOptionsHandler.ServeHTTP"
+            },
+            {
+              "name": "gzipReader.Close"
+            },
+            {
+              "name": "gzipReader.Read"
+            },
+            {
+              "name": "http1ClientConn.Close"
+            },
+            {
+              "name": "http1ClientConn.RoundTrip"
+            },
+            {
+              "name": "http2ClientConn.Close"
+            },
+            {
+              "name": "http2ClientConn.Ping"
+            },
+            {
+              "name": "http2ClientConn.RoundTrip"
+            },
+            {
+              "name": "http2ClientConn.Shutdown"
+            },
+            {
+              "name": "http2ConnectionError.Error"
+            },
+            {
+              "name": "http2ErrCode.String"
+            },
+            {
+              "name": "http2FrameHeader.String"
+            },
+            {
+              "name": "http2FrameType.String"
+            },
+            {
+              "name": "http2FrameWriteRequest.String"
+            },
+            {
+              "name": "http2Framer.ReadFrame"
+            },
+            {
+              "name": "http2Framer.ReadFrameForHeader"
+            },
+            {
+              "name": "http2Framer.ReadFrameHeader"
+            },
+            {
+              "name": "http2Framer.WriteContinuation"
+            },
+            {
+              "name": "http2Framer.WriteData"
+            },
+            {
+              "name": "http2Framer.WriteDataPadded"
+            },
+            {
+              "name": "http2Framer.WriteGoAway"
+            },
+            {
+              "name": "http2Framer.WriteHeaders"
+            },
+            {
+              "name": "http2Framer.WritePing"
+            },
+            {
+              "name": "http2Framer.WritePriority"
+            },
+            {
+              "name": "http2Framer.WritePushPromise"
+            },
+            {
+              "name": "http2Framer.WriteRSTStream"
+            },
+            {
+              "name": "http2Framer.WriteRawFrame"
+            },
+            {
+              "name": "http2Framer.WriteSettings"
+            },
+            {
+              "name": "http2Framer.WriteSettingsAck"
+            },
+            {
+              "name": "http2Framer.WriteWindowUpdate"
+            },
+            {
+              "name": "http2GoAwayError.Error"
+            },
+            {
+              "name": "http2Server.ServeConn"
+            },
+            {
+              "name": "http2Setting.String"
+            },
+            {
+              "name": "http2SettingID.String"
+            },
+            {
+              "name": "http2SettingsFrame.ForeachSetting"
+            },
+            {
+              "name": "http2StreamError.Error"
+            },
+            {
+              "name": "http2Transport.CloseIdleConnections"
+            },
+            {
+              "name": "http2Transport.NewClientConn"
+            },
+            {
+              "name": "http2Transport.RoundTrip"
+            },
+            {
+              "name": "http2Transport.RoundTripOpt"
+            },
+            {
+              "name": "http2bufferedWriter.Flush"
+            },
+            {
+              "name": "http2bufferedWriter.Write"
+            },
+            {
+              "name": "http2bufferedWriterTimeoutWriter.Write"
+            },
+            {
+              "name": "http2chunkWriter.Write"
+            },
+            {
+              "name": "http2clientConnPool.GetClientConn"
+            },
+            {
+              "name": "http2connError.Error"
+            },
+            {
+              "name": "http2dataBuffer.Read"
+            },
+            {
+              "name": "http2duplicatePseudoHeaderError.Error"
+            },
+            {
+              "name": "http2gzipReader.Close"
+            },
+            {
+              "name": "http2gzipReader.Read"
+            },
+            {
+              "name": "http2headerFieldNameError.Error"
+            },
+            {
+              "name": "http2headerFieldValueError.Error"
+            },
+            {
+              "name": "http2netHTTPClientConn.Close"
+            },
+            {
+              "name": "http2netHTTPClientConn.RoundTrip"
+            },
+            {
+              "name": "http2noDialClientConnPool.GetClientConn"
+            },
+            {
+              "name": "http2noDialH2RoundTripper.NewClientConn"
+            },
+            {
+              "name": "http2noDialH2RoundTripper.RoundTrip"
+            },
+            {
+              "name": "http2pipe.Read"
+            },
+            {
+              "name": "http2priorityWriteSchedulerRFC7540.CloseStream"
+            },
+            {
+              "name": "http2priorityWriteSchedulerRFC7540.OpenStream"
+            },
+            {
+              "name": "http2priorityWriteSchedulerRFC7540.Pop"
+            },
+            {
+              "name": "http2priorityWriteSchedulerRFC9218.OpenStream"
+            },
+            {
+              "name": "http2priorityWriteSchedulerRFC9218.Pop"
+            },
+            {
+              "name": "http2pseudoHeaderError.Error"
+            },
+            {
+              "name": "http2randomWriteScheduler.Pop"
+            },
+            {
+              "name": "http2requestBody.Close"
+            },
+            {
+              "name": "http2requestBody.Read"
+            },
+            {
+              "name": "http2responseWriter.Flush"
+            },
+            {
+              "name": "http2responseWriter.FlushError"
+            },
+            {
+              "name": "http2responseWriter.Push"
+            },
+            {
+              "name": "http2responseWriter.SetReadDeadline"
+            },
+            {
+              "name": "http2responseWriter.SetWriteDeadline"
+            },
+            {
+              "name": "http2responseWriter.Write"
+            },
+            {
+              "name": "http2responseWriter.WriteHeader"
+            },
+            {
+              "name": "http2responseWriter.WriteString"
+            },
+            {
+              "name": "http2roundRobinWriteScheduler.OpenStream"
+            },
+            {
+              "name": "http2roundRobinWriteScheduler.Pop"
+            },
+            {
+              "name": "http2serverConn.CloseConn"
+            },
+            {
+              "name": "http2serverConn.Flush"
+            },
+            {
+              "name": "http2stickyErrWriter.Write"
+            },
+            {
+              "name": "http2transportResponseBody.Close"
+            },
+            {
+              "name": "http2transportResponseBody.Read"
+            },
+            {
+              "name": "http2unencryptedTransport.RoundTrip"
+            },
+            {
+              "name": "http2writeData.String"
+            },
+            {
+              "name": "initALPNRequest.ServeHTTP"
+            },
+            {
+              "name": "loggingConn.Close"
+            },
+            {
+              "name": "loggingConn.Read"
+            },
+            {
+              "name": "loggingConn.Write"
+            },
+            {
+              "name": "maxBytesReader.Close"
+            },
+            {
+              "name": "maxBytesReader.Read"
+            },
+            {
+              "name": "onceCloseListener.Close"
+            },
+            {
+              "name": "persistConn.Read"
+            },
+            {
+              "name": "persistConnWriter.ReadFrom"
+            },
+            {
+              "name": "persistConnWriter.Write"
+            },
+            {
+              "name": "populateResponse.Write"
+            },
+            {
+              "name": "populateResponse.WriteHeader"
+            },
+            {
+              "name": "readTrackingBody.Close"
+            },
+            {
+              "name": "readTrackingBody.Read"
+            },
+            {
+              "name": "readWriteCloserBody.CloseWrite"
+            },
+            {
+              "name": "readWriteCloserBody.Read"
+            },
+            {
+              "name": "redirectHandler.ServeHTTP"
+            },
+            {
+              "name": "response.Flush"
+            },
+            {
+              "name": "response.FlushError"
+            },
+            {
+              "name": "response.Hijack"
+            },
+            {
+              "name": "response.ReadFrom"
+            },
+            {
+              "name": "response.Write"
+            },
+            {
+              "name": "response.WriteHeader"
+            },
+            {
+              "name": "response.WriteString"
+            },
+            {
+              "name": "serverHandler.ServeHTTP"
+            },
+            {
+              "name": "socksDialer.DialWithConn"
+            },
+            {
+              "name": "socksUsernamePassword.Authenticate"
+            },
+            {
+              "name": "stringWriter.WriteString"
+            },
+            {
+              "name": "timeoutHandler.ServeHTTP"
+            },
+            {
+              "name": "timeoutWriter.Write"
+            },
+            {
+              "name": "timeoutWriter.WriteHeader"
+            },
+            {
+              "name": "transportReadFromServerError.Error"
+            },
+            {
+              "name": "unencryptedHTTP2Request.ServeHTTP"
+            }
+          ],
+          "defaultStatus": "unaffected"
+        },
+        {
+          "vendor": "Go standard library",
+          "product": "net/http/internal/http2",
+          "collectionURL": "https://pkg.go.dev",
+          "packageName": "net/http/internal/http2",
+          "versions": [
+            {
+              "version": "1.27.0-0",
+              "lessThan": "1.27.2",
+              "status": "affected",
+              "versionType": "semver"
+            }
+          ],
+          "programRoutines": [
+            {
+              "name": "outflow.add"
+            },
+            {
+              "name": "outflow.available"
+            },
+            {
+              "name": "outflow.setConnFlow"
+            },
+            {
+              "name": "outflow.take"
+            },
+            {
+              "name": "Server.serveConn"
+            },
+            {
+              "name": "serverConn.newStream"
+            },
+            {
+              "name": "serverConn.processSettingInitialWindowSize"
+            },
+            {
+              "name": "serverConn.processWindowUpdate"
+            },
+            {
+              "name": "serverConn.scheduleFrameWrite"
+            },
+            {
+              "name": "ClientConn.addStreamLocked"
+            },
+            {
+              "name": "Transport.newClientConn"
+            },
+            {
+              "name": "clientConnReadLoop.processSettingsNoWrite"
+            },
+            {
+              "name": "clientConnReadLoop.processWindowUpdate"
+            },
+            {
+              "name": "clientConnReadLoop.streamByID"
+            },
+            {
+              "name": "clientStream.awaitFlowControl"
+            },
+            {
+              "name": "clientStream.cleanupWriteRequest"
+            },
+            {
+              "name": "FrameWriteRequest.Consume"
+            },
+            {
+              "name": "ClientConn.Close"
+            },
+            {
+              "name": "ClientConn.Ping"
+            },
+            {
+              "name": "ClientConn.RoundTrip"
+            },
+            {
+              "name": "ClientConn.Shutdown"
+            },
+            {
+              "name": "Framer.ReadFrame"
+            },
+            {
+              "name": "Framer.ReadFrameForHeader"
+            },
+            {
+              "name": "Framer.ReadFrameHeader"
+            },
+            {
+              "name": "Framer.WriteContinuation"
+            },
+            {
+              "name": "Framer.WriteData"
+            },
+            {
+              "name": "Framer.WriteDataPadded"
+            },
+            {
+              "name": "Framer.WriteGoAway"
+            },
+            {
+              "name": "Framer.WriteHeaders"
+            },
+            {
+              "name": "Framer.WritePing"
+            },
+            {
+              "name": "Framer.WritePriority"
+            },
+            {
+              "name": "Framer.WritePriorityUpdate"
+            },
+            {
+              "name": "Framer.WritePushPromise"
+            },
+            {
+              "name": "Framer.WriteRSTStream"
+            },
+            {
+              "name": "Framer.WriteRawFrame"
+            },
+            {
+              "name": "Framer.WriteSettings"
+            },
+            {
+              "name": "Framer.WriteSettingsAck"
+            },
+            {
+              "name": "Framer.WriteWindowUpdate"
+            },
+            {
+              "name": "NetHTTPClientConn.Close"
+            },
+            {
+              "name": "NetHTTPClientConn.Ping"
+            },
+            {
+              "name": "NetHTTPClientConn.RoundTrip"
+            },
+            {
+              "name": "ReadFrameHeader"
+            },
+            {
+              "name": "Server.GracefulShutdown"
+            },
+            {
+              "name": "Server.ServeConn"
+            },
+            {
+              "name": "SettingsFrame.ForeachSetting"
+            },
+            {
+              "name": "Transport.AddConn"
+            },
+            {
+              "name": "Transport.CloseIdleConnections"
+            },
+            {
+              "name": "Transport.NewClientConn"
+            },
+            {
+              "name": "Transport.RoundTrip"
+            },
+            {
+              "name": "Transport.RoundTripOpt"
+            },
+            {
+              "name": "bufferedWriter.Flush"
+            },
+            {
+              "name": "bufferedWriter.Write"
+            },
+            {
+              "name": "bufferedWriterTimeoutWriter.Write"
+            },
+            {
+              "name": "chunkWriter.Write"
+            },
+            {
+              "name": "clientConnPool.GetClientConn"
+            },
+            {
+              "name": "gzipReader.Close"
+            },
+            {
+              "name": "gzipReader.Read"
+            },
+            {
+              "name": "noDialClientConnPool.GetClientConn"
+            },
+            {
+              "name": "priorityWriteSchedulerRFC9218.Pop"
+            },
+            {
+              "name": "requestBody.Close"
+            },
+            {
+              "name": "responseWriter.Flush"
+            },
+            {
+              "name": "responseWriter.FlushError"
+            },
+            {
+              "name": "responseWriter.Push"
+            },
+            {
+              "name": "responseWriter.Write"
+            },
+            {
+              "name": "responseWriter.WriteHeader"
+            },
+            {
+              "name": "responseWriter.WriteString"
+            },
+            {
+              "name": "roundRobinWriteScheduler.Pop"
+            },
+            {
+              "name": "serve400Handler.ServeHTTP"
+            },
+            {
+              "name": "serverConn.Flush"
+            },
+            {
+              "name": "stickyErrWriter.Write"
+            },
+            {
+              "name": "transportResponseBody.Close"
+            },
+            {
+              "name": "transportResponseBody.Read"
+            }
+          ],
+          "defaultStatus": "unaffected"
+        },
+        {
+          "vendor": "golang.org/x/net",
+          "product": "golang.org/x/net/http2",
+          "collectionURL": "https://pkg.go.dev",
+          "packageName": "golang.org/x/net/http2",
+          "versions": [
+            {
+              "version": "0",
+              "lessThan": "0.60.0",
+              "status": "affected",
+              "versionType": "semver"
+            }
+          ],
+          "programRoutines": [
+            {
+              "name": "outflow.add"
+            },
+            {
+              "name": "outflow.available"
+            },
+            {
+              "name": "outflow.setConnFlow"
+            },
+            {
+              "name": "outflow.take"
+            },
+            {
+              "name": "Server.serveConn"
+            },
+            {
+              "name": "serverConn.newStream"
+            },
+            {
+              "name": "serverConn.processSettingInitialWindowSize"
+            },
+            {
+              "name": "serverConn.processWindowUpdate"
+            },
+            {
+              "name": "serverConn.scheduleFrameWrite"
+            },
+            {
+              "name": "ClientConn.addStreamLocked"
+            },
+            {
+              "name": "Transport.newClientConn"
+            },
+            {
+              "name": "clientConnReadLoop.processSettingsNoWrite"
+            },
+            {
+              "name": "clientConnReadLoop.processWindowUpdate"
+            },
+            {
+              "name": "clientConnReadLoop.streamByID"
+            },
+            {
+              "name": "clientStream.awaitFlowControl"
+            },
+            {
+              "name": "clientStream.cleanupWriteRequest"
+            },
+            {
+              "name": "FrameWriteRequest.Consume"
+            },
+            {
+              "name": "ClientConn.Close"
+            },
+            {
+              "name": "ClientConn.Ping"
+            },
+            {
+              "name": "ClientConn.RoundTrip"
+            },
+            {
+              "name": "ClientConn.Shutdown"
+            },
+            {
+              "name": "ConfigureServer"
+            },
+            {
+              "name": "ConfigureTransport"
+            },
+            {
+              "name": "ConfigureTransports"
+            },
+            {
+              "name": "ConnectionError.Error"
+            },
+            {
+              "name": "ErrCode.String"
+            },
+            {
+              "name": "FrameHeader.String"
+            },
+            {
+              "name": "FrameType.String"
+            },
+            {
+              "name": "FrameWriteRequest.String"
+            },
+            {
+              "name": "Framer.ReadFrame"
+            },
+            {
+              "name": "Framer.ReadFrameForHeader"
+            },
+            {
+              "name": "Framer.ReadFrameHeader"
+            },
+            {
+              "name": "Framer.WriteContinuation"
+            },
+            {
+              "name": "Framer.WriteData"
+            },
+            {
+              "name": "Framer.WriteDataPadded"
+            },
+            {
+              "name": "Framer.WriteGoAway"
+            },
+            {
+              "name": "Framer.WriteHeaders"
+            },
+            {
+              "name": "Framer.WritePing"
+            },
+            {
+              "name": "Framer.WritePriority"
+            },
+            {
+              "name": "Framer.WritePriorityUpdate"
+            },
+            {
+              "name": "Framer.WritePushPromise"
+            },
+            {
+              "name": "Framer.WriteRSTStream"
+            },
+            {
+              "name": "Framer.WriteRawFrame"
+            },
+            {
+              "name": "Framer.WriteSettings"
+            },
+            {
+              "name": "Framer.WriteSettingsAck"
+            },
+            {
+              "name": "Framer.WriteWindowUpdate"
+            },
+            {
+              "name": "GoAwayError.Error"
+            },
+            {
+              "name": "ReadFrameHeader"
+            },
+            {
+              "name": "Server.ServeConn"
+            },
+            {
+              "name": "Setting.String"
+            },
+            {
+              "name": "SettingID.String"
+            },
+            {
+              "name": "SettingsFrame.ForeachSetting"
+            },
+            {
+              "name": "StreamError.Error"
+            },
+            {
+              "name": "Transport.CloseIdleConnections"
+            },
+            {
+              "name": "Transport.NewClientConn"
+            },
+            {
+              "name": "Transport.RoundTrip"
+            },
+            {
+              "name": "Transport.RoundTripOpt"
+            },
+            {
+              "name": "bufferedWriter.Flush"
+            },
+            {
+              "name": "bufferedWriter.Write"
+            },
+            {
+              "name": "bufferedWriterTimeoutWriter.Write"
+            },
+            {
+              "name": "chunkWriter.Write"
+            },
+            {
+              "name": "clientConnPool.GetClientConn"
+            },
+            {
+              "name": "connError.Error"
+            },
+            {
+              "name": "dataBuffer.Read"
+            },
+            {
+              "name": "duplicatePseudoHeaderError.Error"
+            },
+            {
+              "name": "gzipReader.Close"
+            },
+            {
+              "name": "gzipReader.Read"
+            },
+            {
+              "name": "headerFieldNameError.Error"
+            },
+            {
+              "name": "headerFieldValueError.Error"
+            },
+            {
+              "name": "netHTTPClientConn.Close"
+            },
+            {
+              "name": "netHTTPClientConn.RoundTrip"
+            },
+            {
+              "name": "noDialClientConnPool.GetClientConn"
+            },
+            {
+              "name": "noDialH2RoundTripper.NewClientConn"
+            },
+            {
+              "name": "noDialH2RoundTripper.RoundTrip"
+            },
+            {
+              "name": "pipe.Read"
+            },
+            {
+              "name": "priorityWriteSchedulerRFC7540.CloseStream"
+            },
+            {
+              "name": "priorityWriteSchedulerRFC7540.OpenStream"
+            },
+            {
+              "name": "priorityWriteSchedulerRFC7540.Pop"
+            },
+            {
+              "name": "priorityWriteSchedulerRFC9218.OpenStream"
+            },
+            {
+              "name": "priorityWriteSchedulerRFC9218.Pop"
+            },
+            {
+              "name": "pseudoHeaderError.Error"
+            },
+            {
+              "name": "randomWriteScheduler.Pop"
+            },
+            {
+              "name": "requestBody.Close"
+            },
+            {
+              "name": "requestBody.Read"
+            },
+            {
+              "name": "responseWriter.Flush"
+            },
+            {
+              "name": "responseWriter.FlushError"
+            },
+            {
+              "name": "responseWriter.Push"
+            },
+            {
+              "name": "responseWriter.SetReadDeadline"
+            },
+            {
+              "name": "responseWriter.SetWriteDeadline"
+            },
+            {
+              "name": "responseWriter.Write"
+            },
+            {
+              "name": "responseWriter.WriteHeader"
+            },
+            {
+              "name": "responseWriter.WriteString"
+            },
+            {
+              "name": "roundRobinWriteScheduler.OpenStream"
+            },
+            {
+              "name": "roundRobinWriteScheduler.Pop"
+            },
+            {
+              "name": "serverConn.CloseConn"
+            },
+            {
+              "name": "serverConn.Flush"
+            },
+            {
+              "name": "stickyErrWriter.Write"
+            },
+            {
+              "name": "transportResponseBody.Close"
+            },
+            {
+              "name": "transportResponseBody.Read"
+            },
+            {
+              "name": "unencryptedTransport.RoundTrip"
+            },
+            {
+              "name": "writeData.String"
+            }
+          ],
+          "defaultStatus": "unaffected"
+        }
+      ],
+      "problemTypes": [
+        {
+          "descriptions": [
+            {
+              "lang": "en",
+              "description": "CWE-405: Asymmetric Resource Consumption (Amplification)"
+            }
+          ]
+        }
+      ],
+      "references": [
+        {
+          "url": "https://go.dev/cl/847186"
+        },
+        {
+          "url": "https://go.dev/cl/847308"
+        },
+        {
+          "url": "https://go.dev/issue/81742"
+        },
+        {
+          "url": "https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"
+        },
+        {
+          "url": "https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs"
+        },
+        {
+          "url": "https://pkg.go.dev/vuln/GO-2026-6611"
+        }
+      ],
+      "credits": [
+        {
+          "lang": "en",
+          "value": "Jakub Ciolek (https://ciolek.dev)"
+        }
+      ]
+    }
+  }
+}
\ No newline at end of file
diff --git a/data/cve/v5/GO-2026-6612.json b/data/cve/v5/GO-2026-6612.json
new file mode 100644
index 0000000..deea3b4
--- /dev/null
+++ b/data/cve/v5/GO-2026-6612.json
@@ -0,0 +1,1082 @@
+{
+  "dataType": "CVE_RECORD",
+  "dataVersion": "5.0",
+  "cveMetadata": {
+    "cveId": "CVE-2026-78663"
+  },
+  "containers": {
+    "cna": {
+      "providerMetadata": {
+        "orgId": "1bb62c36-49e3-4200-9d77-64a1400537cc"
+      },
+      "title": "Double flow control refund on HTTP/2 server streams in net/http",
+      "descriptions": [
+        {
+          "lang": "en",
+          "value": "The HTTP/2 server can refund connection-level flow control twice for the same data: Once when a client resets a stream (refunding data for any sent-but-unread portion of the stream), and again when a request handler reads the buffered data. A malicious client can exploit this to bypass the configured connection-level flow control limit (MaxReceiveBufferPerConnection). Total buffered data is still limited by the concurrent stream limit and stream-level flow control."
+        }
+      ],
+      "affected": [
+        {
+          "vendor": "Go standard library",
+          "product": "net/http",
+          "collectionURL": "https://pkg.go.dev",
+          "packageName": "net/http",
+          "versions": [
+            {
+              "version": "0",
+              "lessThan": "1.26.9",
+              "status": "affected",
+              "versionType": "semver"
+            }
+          ],
+          "programRoutines": [
+            {
+              "name": "http2requestBody.Close"
+            },
+            {
+              "name": "http2requestBody.Read"
+            },
+            {
+              "name": "http2serverConn.closeStream"
+            },
+            {
+              "name": "http2serverConn.handlerDone"
+            },
+            {
+              "name": "http2serverConn.newWriterAndRequest"
+            },
+            {
+              "name": "http2serverConn.newWriterAndRequestNoBody"
+            },
+            {
+              "name": "http2serverConn.noteBodyRead"
+            },
+            {
+              "name": "http2serverConn.processHeaders"
+            },
+            {
+              "name": "http2serverConn.runHandler"
+            },
+            {
+              "name": "http2serverConn.scheduleHandler"
+            },
+            {
+              "name": "CanonicalHeaderKey"
+            },
+            {
+              "name": "Client.CloseIdleConnections"
+            },
+            {
+              "name": "Client.Do"
+            },
+            {
+              "name": "Client.Get"
+            },
+            {
+              "name": "Client.Head"
+            },
+            {
+              "name": "Client.Post"
+            },
+            {
+              "name": "Client.PostForm"
+            },
+            {
+              "name": "ClientConn.Close"
+            },
+            {
+              "name": "ClientConn.RoundTrip"
+            },
+            {
+              "name": "Cookie.String"
+            },
+            {
+              "name": "Cookie.Valid"
+            },
+            {
+              "name": "CrossOriginProtection.AddInsecureBypassPattern"
+            },
+            {
+              "name": "CrossOriginProtection.AddTrustedOrigin"
+            },
+            {
+              "name": "CrossOriginProtection.Check"
+            },
+            {
+              "name": "Dir.Open"
+            },
+            {
+              "name": "Error"
+            },
+            {
+              "name": "Get"
+            },
+            {
+              "name": "Handle"
+            },
+            {
+              "name": "HandleFunc"
+            },
+            {
+              "name": "HandlerFunc.ServeHTTP"
+            },
+            {
+              "name": "Head"
+            },
+            {
+              "name": "Header.Add"
+            },
+            {
+              "name": "Header.Del"
+            },
+            {
+              "name": "Header.Get"
+            },
+            {
+              "name": "Header.Set"
+            },
+            {
+              "name": "Header.Values"
+            },
+            {
+              "name": "Header.Write"
+            },
+            {
+              "name": "Header.WriteSubset"
+            },
+            {
+              "name": "ListenAndServe"
+            },
+            {
+              "name": "ListenAndServeTLS"
+            },
+            {
+              "name": "NewRequest"
+            },
+            {
+              "name": "NewRequestWithContext"
+            },
+            {
+              "name": "NotFound"
+            },
+            {
+              "name": "ParseCookie"
+            },
+            {
+              "name": "ParseSetCookie"
+            },
+            {
+              "name": "ParseTime"
+            },
+            {
+              "name": "Post"
+            },
+            {
+              "name": "PostForm"
+            },
+            {
+              "name": "ProxyFromEnvironment"
+            },
+            {
+              "name": "ReadRequest"
+            },
+            {
+              "name": "ReadResponse"
+            },
+            {
+              "name": "Redirect"
+            },
+            {
+              "name": "Request.AddCookie"
+            },
+            {
+              "name": "Request.BasicAuth"
+            },
+            {
+              "name": "Request.Cookie"
+            },
+            {
+              "name": "Request.Cookies"
+            },
+            {
+              "name": "Request.CookiesNamed"
+            },
+            {
+              "name": "Request.FormFile"
+            },
+            {
+              "name": "Request.FormValue"
+            },
+            {
+              "name": "Request.MultipartReader"
+            },
+            {
+              "name": "Request.ParseForm"
+            },
+            {
+              "name": "Request.ParseMultipartForm"
+            },
+            {
+              "name": "Request.PostFormValue"
+            },
+            {
+              "name": "Request.Referer"
+            },
+            {
+              "name": "Request.SetBasicAuth"
+            },
+            {
+              "name": "Request.UserAgent"
+            },
+            {
+              "name": "Request.Write"
+            },
+            {
+              "name": "Request.WriteProxy"
+            },
+            {
+              "name": "Response.Cookies"
+            },
+            {
+              "name": "Response.Location"
+            },
+            {
+              "name": "Response.Write"
+            },
+            {
+              "name": "ResponseController.EnableFullDuplex"
+            },
+            {
+              "name": "ResponseController.Flush"
+            },
+            {
+              "name": "ResponseController.Hijack"
+            },
+            {
+              "name": "ResponseController.SetReadDeadline"
+            },
+            {
+              "name": "ResponseController.SetWriteDeadline"
+            },
+            {
+              "name": "Serve"
+            },
+            {
+              "name": "ServeContent"
+            },
+            {
+              "name": "ServeFile"
+            },
+            {
+              "name": "ServeFileFS"
+            },
+            {
+              "name": "ServeMux.Handle"
+            },
+            {
+              "name": "ServeMux.HandleFunc"
+            },
+            {
+              "name": "ServeMux.ServeHTTP"
+            },
+            {
+              "name": "ServeTLS"
+            },
+            {
+              "name": "Server.Close"
+            },
+            {
+              "name": "Server.ListenAndServe"
+            },
+            {
+              "name": "Server.ListenAndServeTLS"
+            },
+            {
+              "name": "Server.Serve"
+            },
+            {
+              "name": "Server.ServeTLS"
+            },
+            {
+              "name": "Server.SetKeepAlivesEnabled"
+            },
+            {
+              "name": "Server.Shutdown"
+            },
+            {
+              "name": "SetCookie"
+            },
+            {
+              "name": "Transport.CancelRequest"
+            },
+            {
+              "name": "Transport.Clone"
+            },
+            {
+              "name": "Transport.CloseIdleConnections"
+            },
+            {
+              "name": "Transport.NewClientConn"
+            },
+            {
+              "name": "Transport.RoundTrip"
+            },
+            {
+              "name": "body.Close"
+            },
+            {
+              "name": "body.Read"
+            },
+            {
+              "name": "bodyEOFSignal.Close"
+            },
+            {
+              "name": "bodyEOFSignal.Read"
+            },
+            {
+              "name": "bodyLocked.Read"
+            },
+            {
+              "name": "bufioFlushWriter.Write"
+            },
+            {
+              "name": "cancelTimerBody.Close"
+            },
+            {
+              "name": "cancelTimerBody.Read"
+            },
+            {
+              "name": "checkConnErrorWriter.Write"
+            },
+            {
+              "name": "chunkWriter.Write"
+            },
+            {
+              "name": "connReader.Read"
+            },
+            {
+              "name": "connectMethodKey.String"
+            },
+            {
+              "name": "expectContinueReader.Close"
+            },
+            {
+              "name": "expectContinueReader.Read"
+            },
+            {
+              "name": "extraHeader.Write"
+            },
+            {
+              "name": "fileHandler.ServeHTTP"
+            },
+            {
+              "name": "fileTransport.RoundTrip"
+            },
+            {
+              "name": "globalOptionsHandler.ServeHTTP"
+            },
+            {
+              "name": "gzipReader.Close"
+            },
+            {
+              "name": "gzipReader.Read"
+            },
+            {
+              "name": "http1ClientConn.Close"
+            },
+            {
+              "name": "http1ClientConn.RoundTrip"
+            },
+            {
+              "name": "http2ClientConn.Close"
+            },
+            {
+              "name": "http2ClientConn.Ping"
+            },
+            {
+              "name": "http2ClientConn.RoundTrip"
+            },
+            {
+              "name": "http2ClientConn.Shutdown"
+            },
+            {
+              "name": "http2ConnectionError.Error"
+            },
+            {
+              "name": "http2ErrCode.String"
+            },
+            {
+              "name": "http2FrameHeader.String"
+            },
+            {
+              "name": "http2FrameType.String"
+            },
+            {
+              "name": "http2FrameWriteRequest.String"
+            },
+            {
+              "name": "http2Framer.ReadFrame"
+            },
+            {
+              "name": "http2Framer.ReadFrameForHeader"
+            },
+            {
+              "name": "http2Framer.ReadFrameHeader"
+            },
+            {
+              "name": "http2Framer.WriteContinuation"
+            },
+            {
+              "name": "http2Framer.WriteData"
+            },
+            {
+              "name": "http2Framer.WriteDataPadded"
+            },
+            {
+              "name": "http2Framer.WriteGoAway"
+            },
+            {
+              "name": "http2Framer.WriteHeaders"
+            },
+            {
+              "name": "http2Framer.WritePing"
+            },
+            {
+              "name": "http2Framer.WritePriority"
+            },
+            {
+              "name": "http2Framer.WritePushPromise"
+            },
+            {
+              "name": "http2Framer.WriteRSTStream"
+            },
+            {
+              "name": "http2Framer.WriteRawFrame"
+            },
+            {
+              "name": "http2Framer.WriteSettings"
+            },
+            {
+              "name": "http2Framer.WriteSettingsAck"
+            },
+            {
+              "name": "http2Framer.WriteWindowUpdate"
+            },
+            {
+              "name": "http2GoAwayError.Error"
+            },
+            {
+              "name": "http2Server.ServeConn"
+            },
+            {
+              "name": "http2Setting.String"
+            },
+            {
+              "name": "http2SettingID.String"
+            },
+            {
+              "name": "http2SettingsFrame.ForeachSetting"
+            },
+            {
+              "name": "http2StreamError.Error"
+            },
+            {
+              "name": "http2Transport.CloseIdleConnections"
+            },
+            {
+              "name": "http2Transport.NewClientConn"
+            },
+            {
+              "name": "http2Transport.RoundTrip"
+            },
+            {
+              "name": "http2Transport.RoundTripOpt"
+            },
+            {
+              "name": "http2bufferedWriter.Flush"
+            },
+            {
+              "name": "http2bufferedWriter.Write"
+            },
+            {
+              "name": "http2bufferedWriterTimeoutWriter.Write"
+            },
+            {
+              "name": "http2chunkWriter.Write"
+            },
+            {
+              "name": "http2clientConnPool.GetClientConn"
+            },
+            {
+              "name": "http2connError.Error"
+            },
+            {
+              "name": "http2dataBuffer.Read"
+            },
+            {
+              "name": "http2duplicatePseudoHeaderError.Error"
+            },
+            {
+              "name": "http2gzipReader.Close"
+            },
+            {
+              "name": "http2gzipReader.Read"
+            },
+            {
+              "name": "http2headerFieldNameError.Error"
+            },
+            {
+              "name": "http2headerFieldValueError.Error"
+            },
+            {
+              "name": "http2netHTTPClientConn.Close"
+            },
+            {
+              "name": "http2netHTTPClientConn.RoundTrip"
+            },
+            {
+              "name": "http2noDialClientConnPool.GetClientConn"
+            },
+            {
+              "name": "http2noDialH2RoundTripper.NewClientConn"
+            },
+            {
+              "name": "http2noDialH2RoundTripper.RoundTrip"
+            },
+            {
+              "name": "http2pipe.Read"
+            },
+            {
+              "name": "http2priorityWriteSchedulerRFC7540.CloseStream"
+            },
+            {
+              "name": "http2priorityWriteSchedulerRFC7540.OpenStream"
+            },
+            {
+              "name": "http2priorityWriteSchedulerRFC9218.OpenStream"
+            },
+            {
+              "name": "http2pseudoHeaderError.Error"
+            },
+            {
+              "name": "http2responseWriter.Flush"
+            },
+            {
+              "name": "http2responseWriter.FlushError"
+            },
+            {
+              "name": "http2responseWriter.Push"
+            },
+            {
+              "name": "http2responseWriter.SetReadDeadline"
+            },
+            {
+              "name": "http2responseWriter.SetWriteDeadline"
+            },
+            {
+              "name": "http2responseWriter.Write"
+            },
+            {
+              "name": "http2responseWriter.WriteHeader"
+            },
+            {
+              "name": "http2responseWriter.WriteString"
+            },
+            {
+              "name": "http2roundRobinWriteScheduler.OpenStream"
+            },
+            {
+              "name": "http2serverConn.CloseConn"
+            },
+            {
+              "name": "http2serverConn.Flush"
+            },
+            {
+              "name": "http2stickyErrWriter.Write"
+            },
+            {
+              "name": "http2transportResponseBody.Close"
+            },
+            {
+              "name": "http2transportResponseBody.Read"
+            },
+            {
+              "name": "http2unencryptedTransport.RoundTrip"
+            },
+            {
+              "name": "http2writeData.String"
+            },
+            {
+              "name": "initALPNRequest.ServeHTTP"
+            },
+            {
+              "name": "loggingConn.Close"
+            },
+            {
+              "name": "loggingConn.Read"
+            },
+            {
+              "name": "loggingConn.Write"
+            },
+            {
+              "name": "maxBytesReader.Close"
+            },
+            {
+              "name": "maxBytesReader.Read"
+            },
+            {
+              "name": "onceCloseListener.Close"
+            },
+            {
+              "name": "persistConn.Read"
+            },
+            {
+              "name": "persistConnWriter.ReadFrom"
+            },
+            {
+              "name": "persistConnWriter.Write"
+            },
+            {
+              "name": "populateResponse.Write"
+            },
+            {
+              "name": "populateResponse.WriteHeader"
+            },
+            {
+              "name": "readTrackingBody.Close"
+            },
+            {
+              "name": "readTrackingBody.Read"
+            },
+            {
+              "name": "readWriteCloserBody.CloseWrite"
+            },
+            {
+              "name": "readWriteCloserBody.Read"
+            },
+            {
+              "name": "redirectHandler.ServeHTTP"
+            },
+            {
+              "name": "response.Flush"
+            },
+            {
+              "name": "response.FlushError"
+            },
+            {
+              "name": "response.Hijack"
+            },
+            {
+              "name": "response.ReadFrom"
+            },
+            {
+              "name": "response.Write"
+            },
+            {
+              "name": "response.WriteHeader"
+            },
+            {
+              "name": "response.WriteString"
+            },
+            {
+              "name": "serverHandler.ServeHTTP"
+            },
+            {
+              "name": "socksDialer.DialWithConn"
+            },
+            {
+              "name": "socksUsernamePassword.Authenticate"
+            },
+            {
+              "name": "stringWriter.WriteString"
+            },
+            {
+              "name": "timeoutHandler.ServeHTTP"
+            },
+            {
+              "name": "timeoutWriter.Write"
+            },
+            {
+              "name": "timeoutWriter.WriteHeader"
+            },
+            {
+              "name": "transportReadFromServerError.Error"
+            },
+            {
+              "name": "unencryptedHTTP2Request.ServeHTTP"
+            }
+          ],
+          "defaultStatus": "unaffected"
+        },
+        {
+          "vendor": "Go standard library",
+          "product": "net/http/internal/http2",
+          "collectionURL": "https://pkg.go.dev",
+          "packageName": "net/http/internal/http2",
+          "versions": [
+            {
+              "version": "1.27.0-0",
+              "lessThan": "1.27.2",
+              "status": "affected",
+              "versionType": "semver"
+            }
+          ],
+          "programRoutines": [
+            {
+              "name": "requestBody.Close"
+            },
+            {
+              "name": "requestBody.Read"
+            },
+            {
+              "name": "serverConn.closeStream"
+            },
+            {
+              "name": "serverConn.handlerDone"
+            },
+            {
+              "name": "serverConn.newWriterAndRequest"
+            },
+            {
+              "name": "serverConn.newWriterAndRequestNoBody"
+            },
+            {
+              "name": "serverConn.noteBodyRead"
+            },
+            {
+              "name": "serverConn.processHeaders"
+            },
+            {
+              "name": "serverConn.runHandler"
+            },
+            {
+              "name": "serverConn.scheduleHandler"
+            },
+            {
+              "name": "Server.ServeConn"
+            }
+          ],
+          "defaultStatus": "unaffected"
+        },
+        {
+          "vendor": "golang.org/x/net",
+          "product": "golang.org/x/net/http2",
+          "collectionURL": "https://pkg.go.dev",
+          "packageName": "golang.org/x/net/http2",
+          "versions": [
+            {
+              "version": "0",
+              "lessThan": "0.60.0",
+              "status": "affected",
+              "versionType": "semver"
+            }
+          ],
+          "programRoutines": [
+            {
+              "name": "requestBody.Close"
+            },
+            {
+              "name": "requestBody.Read"
+            },
+            {
+              "name": "serverConn.closeStream"
+            },
+            {
+              "name": "serverConn.handlerDone"
+            },
+            {
+              "name": "serverConn.newWriterAndRequest"
+            },
+            {
+              "name": "serverConn.newWriterAndRequestNoBody"
+            },
+            {
+              "name": "serverConn.noteBodyRead"
+            },
+            {
+              "name": "serverConn.processHeaders"
+            },
+            {
+              "name": "serverConn.runHandler"
+            },
+            {
+              "name": "serverConn.scheduleHandler"
+            },
+            {
+              "name": "ClientConn.Close"
+            },
+            {
+              "name": "ClientConn.Ping"
+            },
+            {
+              "name": "ClientConn.RoundTrip"
+            },
+            {
+              "name": "ClientConn.Shutdown"
+            },
+            {
+              "name": "ConfigureServer"
+            },
+            {
+              "name": "ConfigureTransport"
+            },
+            {
+              "name": "ConfigureTransports"
+            },
+            {
+              "name": "ConnectionError.Error"
+            },
+            {
+              "name": "ErrCode.String"
+            },
+            {
+              "name": "FrameHeader.String"
+            },
+            {
+              "name": "FrameType.String"
+            },
+            {
+              "name": "FrameWriteRequest.String"
+            },
+            {
+              "name": "Framer.ReadFrame"
+            },
+            {
+              "name": "Framer.ReadFrameForHeader"
+            },
+            {
+              "name": "Framer.ReadFrameHeader"
+            },
+            {
+              "name": "Framer.WriteContinuation"
+            },
+            {
+              "name": "Framer.WriteData"
+            },
+            {
+              "name": "Framer.WriteDataPadded"
+            },
+            {
+              "name": "Framer.WriteGoAway"
+            },
+            {
+              "name": "Framer.WriteHeaders"
+            },
+            {
+              "name": "Framer.WritePing"
+            },
+            {
+              "name": "Framer.WritePriority"
+            },
+            {
+              "name": "Framer.WritePriorityUpdate"
+            },
+            {
+              "name": "Framer.WritePushPromise"
+            },
+            {
+              "name": "Framer.WriteRSTStream"
+            },
+            {
+              "name": "Framer.WriteRawFrame"
+            },
+            {
+              "name": "Framer.WriteSettings"
+            },
+            {
+              "name": "Framer.WriteSettingsAck"
+            },
+            {
+              "name": "Framer.WriteWindowUpdate"
+            },
+            {
+              "name": "GoAwayError.Error"
+            },
+            {
+              "name": "ReadFrameHeader"
+            },
+            {
+              "name": "Server.ServeConn"
+            },
+            {
+              "name": "Setting.String"
+            },
+            {
+              "name": "SettingID.String"
+            },
+            {
+              "name": "SettingsFrame.ForeachSetting"
+            },
+            {
+              "name": "StreamError.Error"
+            },
+            {
+              "name": "Transport.CloseIdleConnections"
+            },
+            {
+              "name": "Transport.NewClientConn"
+            },
+            {
+              "name": "Transport.RoundTrip"
+            },
+            {
+              "name": "Transport.RoundTripOpt"
+            },
+            {
+              "name": "bufferedWriter.Flush"
+            },
+            {
+              "name": "bufferedWriter.Write"
+            },
+            {
+              "name": "bufferedWriterTimeoutWriter.Write"
+            },
+            {
+              "name": "chunkWriter.Write"
+            },
+            {
+              "name": "clientConnPool.GetClientConn"
+            },
+            {
+              "name": "connError.Error"
+            },
+            {
+              "name": "dataBuffer.Read"
+            },
+            {
+              "name": "duplicatePseudoHeaderError.Error"
+            },
+            {
+              "name": "gzipReader.Close"
+            },
+            {
+              "name": "gzipReader.Read"
+            },
+            {
+              "name": "headerFieldNameError.Error"
+            },
+            {
+              "name": "headerFieldValueError.Error"
+            },
+            {
+              "name": "netHTTPClientConn.Close"
+            },
+            {
+              "name": "netHTTPClientConn.RoundTrip"
+            },
+            {
+              "name": "noDialClientConnPool.GetClientConn"
+            },
+            {
+              "name": "noDialH2RoundTripper.NewClientConn"
+            },
+            {
+              "name": "noDialH2RoundTripper.RoundTrip"
+            },
+            {
+              "name": "pipe.Read"
+            },
+            {
+              "name": "priorityWriteSchedulerRFC7540.CloseStream"
+            },
+            {
+              "name": "priorityWriteSchedulerRFC7540.OpenStream"
+            },
+            {
+              "name": "priorityWriteSchedulerRFC9218.OpenStream"
+            },
+            {
+              "name": "pseudoHeaderError.Error"
+            },
+            {
+              "name": "responseWriter.Flush"
+            },
+            {
+              "name": "responseWriter.FlushError"
+            },
+            {
+              "name": "responseWriter.Push"
+            },
+            {
+              "name": "responseWriter.SetReadDeadline"
+            },
+            {
+              "name": "responseWriter.SetWriteDeadline"
+            },
+            {
+              "name": "responseWriter.Write"
+            },
+            {
+              "name": "responseWriter.WriteHeader"
+            },
+            {
+              "name": "responseWriter.WriteString"
+            },
+            {
+              "name": "roundRobinWriteScheduler.OpenStream"
+            },
+            {
+              "name": "serverConn.CloseConn"
+            },
+            {
+              "name": "serverConn.Flush"
+            },
+            {
+              "name": "stickyErrWriter.Write"
+            },
+            {
+              "name": "transportResponseBody.Close"
+            },
+            {
+              "name": "transportResponseBody.Read"
+            },
+            {
+              "name": "unencryptedTransport.RoundTrip"
+            },
+            {
+              "name": "writeData.String"
+            }
+          ],
+          "defaultStatus": "unaffected"
+        }
+      ],
+      "problemTypes": [
+        {
+          "descriptions": [
+            {
+              "lang": "en",
+              "description": "CWE-675: Multiple Operations on Resource in Single-Operation Context"
+            }
+          ]
+        }
+      ],
+      "references": [
+        {
+          "url": "https://go.dev/cl/847187"
+        },
+        {
+          "url": "https://go.dev/cl/847310"
+        },
+        {
+          "url": "https://go.dev/issue/81743"
+        },
+        {
+          "url": "https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"
+        },
+        {
+          "url": "https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs"
+        },
+        {
+          "url": "https://pkg.go.dev/vuln/GO-2026-6612"
+        }
+      ],
+      "credits": [
+        {
+          "lang": "en",
+          "value": "Ali Sherif (https://www.linkedin.com/in/ali-sherif-13812b276/)"
+        }
+      ]
+    }
+  }
+}
\ No newline at end of file
diff --git a/data/cve/v5/GO-2026-6613.json b/data/cve/v5/GO-2026-6613.json
new file mode 100644
index 0000000..c2d0757
--- /dev/null
+++ b/data/cve/v5/GO-2026-6613.json
@@ -0,0 +1,526 @@
+{
+  "dataType": "CVE_RECORD",
+  "dataVersion": "5.0",
+  "cveMetadata": {
+    "cveId": "CVE-2026-94439"
+  },
+  "containers": {
+    "cna": {
+      "providerMetadata": {
+        "orgId": "1bb62c36-49e3-4200-9d77-64a1400537cc"
+      },
+      "title": "HTTP/1 server connection desynchronization after 2xx CONNECT response in net/http",
+      "descriptions": [
+        {
+          "lang": "en",
+          "value": "When an HTTP server handler sends a 2xx response to an HTTP/1 CONNECT request and returns without hijacking the connection, the server improperly continues to read and serve requests from the connection. Since a 2xx response to an HTTP/1 CONNECT converts the connection into a tunnel, the server should not treat the connection as continuing to contain HTTP. The impact of this misbehavior is mostly limited to potential request smuggling, where an intermediate proxy considers the data on the connection to be tunneled and the server considers it to be HTTP."
+        }
+      ],
+      "affected": [
+        {
+          "vendor": "Go standard library",
+          "product": "net/http",
+          "collectionURL": "https://pkg.go.dev",
+          "packageName": "net/http",
+          "versions": [
+            {
+              "version": "0",
+              "lessThan": "1.26.9",
+              "status": "affected",
+              "versionType": "semver"
+            },
+            {
+              "version": "1.27.0-0",
+              "lessThan": "1.27.2",
+              "status": "affected",
+              "versionType": "semver"
+            }
+          ],
+          "programRoutines": [
+            {
+              "name": "chunkWriter.writeHeader"
+            },
+            {
+              "name": "CanonicalHeaderKey"
+            },
+            {
+              "name": "Client.CloseIdleConnections"
+            },
+            {
+              "name": "Client.Do"
+            },
+            {
+              "name": "Client.Get"
+            },
+            {
+              "name": "Client.Head"
+            },
+            {
+              "name": "Client.Post"
+            },
+            {
+              "name": "Client.PostForm"
+            },
+            {
+              "name": "ClientConn.Close"
+            },
+            {
+              "name": "ClientConn.RoundTrip"
+            },
+            {
+              "name": "Cookie.String"
+            },
+            {
+              "name": "Cookie.Valid"
+            },
+            {
+              "name": "CrossOriginProtection.AddInsecureBypassPattern"
+            },
+            {
+              "name": "CrossOriginProtection.AddTrustedOrigin"
+            },
+            {
+              "name": "CrossOriginProtection.Check"
+            },
+            {
+              "name": "Dir.Open"
+            },
+            {
+              "name": "Error"
+            },
+            {
+              "name": "Get"
+            },
+            {
+              "name": "Handle"
+            },
+            {
+              "name": "HandleFunc"
+            },
+            {
+              "name": "HandlerFunc.ServeHTTP"
+            },
+            {
+              "name": "Head"
+            },
+            {
+              "name": "Header.Add"
+            },
+            {
+              "name": "Header.Del"
+            },
+            {
+              "name": "Header.Get"
+            },
+            {
+              "name": "Header.Set"
+            },
+            {
+              "name": "Header.Values"
+            },
+            {
+              "name": "Header.Write"
+            },
+            {
+              "name": "Header.WriteSubset"
+            },
+            {
+              "name": "ListenAndServe"
+            },
+            {
+              "name": "ListenAndServeTLS"
+            },
+            {
+              "name": "NewRequest"
+            },
+            {
+              "name": "NewRequestWithContext"
+            },
+            {
+              "name": "NotFound"
+            },
+            {
+              "name": "ParseCookie"
+            },
+            {
+              "name": "ParseSetCookie"
+            },
+            {
+              "name": "ParseTime"
+            },
+            {
+              "name": "Post"
+            },
+            {
+              "name": "PostForm"
+            },
+            {
+              "name": "ProxyFromEnvironment"
+            },
+            {
+              "name": "ReadRequest"
+            },
+            {
+              "name": "ReadResponse"
+            },
+            {
+              "name": "Redirect"
+            },
+            {
+              "name": "Request.AddCookie"
+            },
+            {
+              "name": "Request.BasicAuth"
+            },
+            {
+              "name": "Request.Cookie"
+            },
+            {
+              "name": "Request.Cookies"
+            },
+            {
+              "name": "Request.CookiesNamed"
+            },
+            {
+              "name": "Request.FormFile"
+            },
+            {
+              "name": "Request.FormValue"
+            },
+            {
+              "name": "Request.MultipartReader"
+            },
+            {
+              "name": "Request.ParseForm"
+            },
+            {
+              "name": "Request.ParseMultipartForm"
+            },
+            {
+              "name": "Request.PostFormValue"
+            },
+            {
+              "name": "Request.Referer"
+            },
+            {
+              "name": "Request.SetBasicAuth"
+            },
+            {
+              "name": "Request.UserAgent"
+            },
+            {
+              "name": "Request.Write"
+            },
+            {
+              "name": "Request.WriteProxy"
+            },
+            {
+              "name": "Response.Cookies"
+            },
+            {
+              "name": "Response.Location"
+            },
+            {
+              "name": "Response.Write"
+            },
+            {
+              "name": "ResponseController.EnableFullDuplex"
+            },
+            {
+              "name": "ResponseController.Flush"
+            },
+            {
+              "name": "ResponseController.Hijack"
+            },
+            {
+              "name": "ResponseController.SetReadDeadline"
+            },
+            {
+              "name": "ResponseController.SetWriteDeadline"
+            },
+            {
+              "name": "Serve"
+            },
+            {
+              "name": "ServeContent"
+            },
+            {
+              "name": "ServeFile"
+            },
+            {
+              "name": "ServeFileFS"
+            },
+            {
+              "name": "ServeMux.Handle"
+            },
+            {
+              "name": "ServeMux.HandleFunc"
+            },
+            {
+              "name": "ServeMux.ServeHTTP"
+            },
+            {
+              "name": "ServeTLS"
+            },
+            {
+              "name": "Server.Close"
+            },
+            {
+              "name": "Server.ListenAndServe"
+            },
+            {
+              "name": "Server.ListenAndServeTLS"
+            },
+            {
+              "name": "Server.Serve"
+            },
+            {
+              "name": "Server.ServeTLS"
+            },
+            {
+              "name": "Server.SetKeepAlivesEnabled"
+            },
+            {
+              "name": "Server.Shutdown"
+            },
+            {
+              "name": "SetCookie"
+            },
+            {
+              "name": "Transport.CancelRequest"
+            },
+            {
+              "name": "Transport.Clone"
+            },
+            {
+              "name": "Transport.CloseIdleConnections"
+            },
+            {
+              "name": "Transport.NewClientConn"
+            },
+            {
+              "name": "Transport.RoundTrip"
+            },
+            {
+              "name": "body.Close"
+            },
+            {
+              "name": "body.Read"
+            },
+            {
+              "name": "bodyEOFSignal.Close"
+            },
+            {
+              "name": "bodyEOFSignal.Read"
+            },
+            {
+              "name": "bodyLocked.Read"
+            },
+            {
+              "name": "bufioFlushWriter.Write"
+            },
+            {
+              "name": "cancelTimerBody.Close"
+            },
+            {
+              "name": "cancelTimerBody.Read"
+            },
+            {
+              "name": "checkConnErrorWriter.Write"
+            },
+            {
+              "name": "chunkWriter.Write"
+            },
+            {
+              "name": "connReader.Read"
+            },
+            {
+              "name": "connectMethodKey.String"
+            },
+            {
+              "name": "expectContinueReader.Close"
+            },
+            {
+              "name": "expectContinueReader.Read"
+            },
+            {
+              "name": "extraHeader.Write"
+            },
+            {
+              "name": "fileHandler.ServeHTTP"
+            },
+            {
+              "name": "fileTransport.RoundTrip"
+            },
+            {
+              "name": "globalOptionsHandler.ServeHTTP"
+            },
+            {
+              "name": "gzipReader.Close"
+            },
+            {
+              "name": "gzipReader.Read"
+            },
+            {
+              "name": "http1ClientConn.Close"
+            },
+            {
+              "name": "http1ClientConn.RoundTrip"
+            },
+            {
+              "name": "http2ClientConn.RoundTrip"
+            },
+            {
+              "name": "http2Handler.ServeHTTP"
+            },
+            {
+              "name": "http2ResponseWriter.Flush"
+            },
+            {
+              "name": "http2ResponseWriter.FlushError"
+            },
+            {
+              "name": "http2ResponseWriter.Push"
+            },
+            {
+              "name": "http2RoundTripper.RoundTrip"
+            },
+            {
+              "name": "http3ServerHandler.ServeHTTP"
+            },
+            {
+              "name": "initALPNRequest.ServeHTTP"
+            },
+            {
+              "name": "loggingConn.Close"
+            },
+            {
+              "name": "loggingConn.Read"
+            },
+            {
+              "name": "loggingConn.Write"
+            },
+            {
+              "name": "maxBytesReader.Close"
+            },
+            {
+              "name": "maxBytesReader.Read"
+            },
+            {
+              "name": "onceCloseListener.Close"
+            },
+            {
+              "name": "persistConn.Read"
+            },
+            {
+              "name": "persistConnWriter.ReadFrom"
+            },
+            {
+              "name": "persistConnWriter.Write"
+            },
+            {
+              "name": "populateResponse.Write"
+            },
+            {
+              "name": "populateResponse.WriteHeader"
+            },
+            {
+              "name": "readTrackingBody.Close"
+            },
+            {
+              "name": "readTrackingBody.Read"
+            },
+            {
+              "name": "readWriteCloserBody.CloseWrite"
+            },
+            {
+              "name": "readWriteCloserBody.Read"
+            },
+            {
+              "name": "redirectHandler.ServeHTTP"
+            },
+            {
+              "name": "response.Flush"
+            },
+            {
+              "name": "response.FlushError"
+            },
+            {
+              "name": "response.Hijack"
+            },
+            {
+              "name": "response.ReadFrom"
+            },
+            {
+              "name": "response.Write"
+            },
+            {
+              "name": "response.WriteHeader"
+            },
+            {
+              "name": "response.WriteString"
+            },
+            {
+              "name": "serverHandler.ServeHTTP"
+            },
+            {
+              "name": "socksDialer.DialWithConn"
+            },
+            {
+              "name": "socksUsernamePassword.Authenticate"
+            },
+            {
+              "name": "stringWriter.WriteString"
+            },
+            {
+              "name": "timeoutHandler.ServeHTTP"
+            },
+            {
+              "name": "timeoutWriter.Write"
+            },
+            {
+              "name": "timeoutWriter.WriteHeader"
+            },
+            {
+              "name": "transportReadFromServerError.Error"
+            },
+            {
+              "name": "unencryptedHTTP2Request.ServeHTTP"
+            }
+          ],
+          "defaultStatus": "unaffected"
+        }
+      ],
+      "problemTypes": [
+        {
+          "descriptions": [
+            {
+              "lang": "en",
+              "description": "CWE-444: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')"
+            }
+          ]
+        }
+      ],
+      "references": [
+        {
+          "url": "https://go.dev/cl/847311"
+        },
+        {
+          "url": "https://go.dev/issue/81744"
+        },
+        {
+          "url": "https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"
+        },
+        {
+          "url": "https://pkg.go.dev/vuln/GO-2026-6613"
+        }
+      ],
+      "credits": [
+        {
+          "lang": "en",
+          "value": "Jakub Ciolek (https://ciolek.dev)"
+        }
+      ]
+    }
+  }
+}
\ No newline at end of file
diff --git a/data/cve/v5/GO-2026-6617.json b/data/cve/v5/GO-2026-6617.json
new file mode 100644
index 0000000..8de5c4b
--- /dev/null
+++ b/data/cve/v5/GO-2026-6617.json
@@ -0,0 +1,1178 @@
+{
+  "dataType": "CVE_RECORD",
+  "dataVersion": "5.0",
+  "cveMetadata": {
+    "cveId": "CVE-2026-97032"
+  },
+  "containers": {
+    "cna": {
+      "providerMetadata": {
+        "orgId": "1bb62c36-49e3-4200-9d77-64a1400537cc"
+      },
+      "title": "HTTP/2 server crash due to HPACK encoder race in net/http",
+      "descriptions": [
+        {
+          "lang": "en",
+          "value": "HTTP/2 servers could end up crashing due to inadvertently modifying its HPACK encoder concurrently. This happens because the server modifies the HPACK encoder from two goroutines without synchronization: one uses the encoder to encode a HEADERS frame as part of a response sent to a client and the other modifies the encoder's table size when handling a SETTINGS frame containing SETTINGS_HEADER_TABLE_SIZE that a client sends. A malicious client can repeatedly send a request while changing the header table size to crash the server."
+        }
+      ],
+      "affected": [
+        {
+          "vendor": "Go standard library",
+          "product": "net/http",
+          "collectionURL": "https://pkg.go.dev",
+          "packageName": "net/http",
+          "versions": [
+            {
+              "version": "0",
+              "lessThan": "1.26.9",
+              "status": "affected",
+              "versionType": "semver"
+            }
+          ],
+          "programRoutines": [
+            {
+              "name": "http2serverConn.processSetting"
+            },
+            {
+              "name": "http2serverConn.startFrameWrite"
+            },
+            {
+              "name": "CanonicalHeaderKey"
+            },
+            {
+              "name": "Client.CloseIdleConnections"
+            },
+            {
+              "name": "Client.Do"
+            },
+            {
+              "name": "Client.Get"
+            },
+            {
+              "name": "Client.Head"
+            },
+            {
+              "name": "Client.Post"
+            },
+            {
+              "name": "Client.PostForm"
+            },
+            {
+              "name": "ClientConn.Close"
+            },
+            {
+              "name": "ClientConn.RoundTrip"
+            },
+            {
+              "name": "Cookie.String"
+            },
+            {
+              "name": "Cookie.Valid"
+            },
+            {
+              "name": "CrossOriginProtection.AddInsecureBypassPattern"
+            },
+            {
+              "name": "CrossOriginProtection.AddTrustedOrigin"
+            },
+            {
+              "name": "CrossOriginProtection.Check"
+            },
+            {
+              "name": "Dir.Open"
+            },
+            {
+              "name": "Error"
+            },
+            {
+              "name": "Get"
+            },
+            {
+              "name": "Handle"
+            },
+            {
+              "name": "HandleFunc"
+            },
+            {
+              "name": "HandlerFunc.ServeHTTP"
+            },
+            {
+              "name": "Head"
+            },
+            {
+              "name": "Header.Add"
+            },
+            {
+              "name": "Header.Del"
+            },
+            {
+              "name": "Header.Get"
+            },
+            {
+              "name": "Header.Set"
+            },
+            {
+              "name": "Header.Values"
+            },
+            {
+              "name": "Header.Write"
+            },
+            {
+              "name": "Header.WriteSubset"
+            },
+            {
+              "name": "ListenAndServe"
+            },
+            {
+              "name": "ListenAndServeTLS"
+            },
+            {
+              "name": "NewRequest"
+            },
+            {
+              "name": "NewRequestWithContext"
+            },
+            {
+              "name": "NotFound"
+            },
+            {
+              "name": "ParseCookie"
+            },
+            {
+              "name": "ParseSetCookie"
+            },
+            {
+              "name": "ParseTime"
+            },
+            {
+              "name": "Post"
+            },
+            {
+              "name": "PostForm"
+            },
+            {
+              "name": "ProxyFromEnvironment"
+            },
+            {
+              "name": "ReadRequest"
+            },
+            {
+              "name": "ReadResponse"
+            },
+            {
+              "name": "Redirect"
+            },
+            {
+              "name": "Request.AddCookie"
+            },
+            {
+              "name": "Request.BasicAuth"
+            },
+            {
+              "name": "Request.Cookie"
+            },
+            {
+              "name": "Request.Cookies"
+            },
+            {
+              "name": "Request.CookiesNamed"
+            },
+            {
+              "name": "Request.FormFile"
+            },
+            {
+              "name": "Request.FormValue"
+            },
+            {
+              "name": "Request.MultipartReader"
+            },
+            {
+              "name": "Request.ParseForm"
+            },
+            {
+              "name": "Request.ParseMultipartForm"
+            },
+            {
+              "name": "Request.PostFormValue"
+            },
+            {
+              "name": "Request.Referer"
+            },
+            {
+              "name": "Request.SetBasicAuth"
+            },
+            {
+              "name": "Request.UserAgent"
+            },
+            {
+              "name": "Request.Write"
+            },
+            {
+              "name": "Request.WriteProxy"
+            },
+            {
+              "name": "Response.Cookies"
+            },
+            {
+              "name": "Response.Location"
+            },
+            {
+              "name": "Response.Write"
+            },
+            {
+              "name": "ResponseController.EnableFullDuplex"
+            },
+            {
+              "name": "ResponseController.Flush"
+            },
+            {
+              "name": "ResponseController.Hijack"
+            },
+            {
+              "name": "ResponseController.SetReadDeadline"
+            },
+            {
+              "name": "ResponseController.SetWriteDeadline"
+            },
+            {
+              "name": "Serve"
+            },
+            {
+              "name": "ServeContent"
+            },
+            {
+              "name": "ServeFile"
+            },
+            {
+              "name": "ServeFileFS"
+            },
+            {
+              "name": "ServeMux.Handle"
+            },
+            {
+              "name": "ServeMux.HandleFunc"
+            },
+            {
+              "name": "ServeMux.ServeHTTP"
+            },
+            {
+              "name": "ServeTLS"
+            },
+            {
+              "name": "Server.Close"
+            },
+            {
+              "name": "Server.ListenAndServe"
+            },
+            {
+              "name": "Server.ListenAndServeTLS"
+            },
+            {
+              "name": "Server.Serve"
+            },
+            {
+              "name": "Server.ServeTLS"
+            },
+            {
+              "name": "Server.SetKeepAlivesEnabled"
+            },
+            {
+              "name": "Server.Shutdown"
+            },
+            {
+              "name": "SetCookie"
+            },
+            {
+              "name": "Transport.CancelRequest"
+            },
+            {
+              "name": "Transport.Clone"
+            },
+            {
+              "name": "Transport.CloseIdleConnections"
+            },
+            {
+              "name": "Transport.NewClientConn"
+            },
+            {
+              "name": "Transport.RoundTrip"
+            },
+            {
+              "name": "body.Close"
+            },
+            {
+              "name": "body.Read"
+            },
+            {
+              "name": "bodyEOFSignal.Close"
+            },
+            {
+              "name": "bodyEOFSignal.Read"
+            },
+            {
+              "name": "bodyLocked.Read"
+            },
+            {
+              "name": "bufioFlushWriter.Write"
+            },
+            {
+              "name": "cancelTimerBody.Close"
+            },
+            {
+              "name": "cancelTimerBody.Read"
+            },
+            {
+              "name": "checkConnErrorWriter.Write"
+            },
+            {
+              "name": "chunkWriter.Write"
+            },
+            {
+              "name": "connReader.Read"
+            },
+            {
+              "name": "connectMethodKey.String"
+            },
+            {
+              "name": "expectContinueReader.Close"
+            },
+            {
+              "name": "expectContinueReader.Read"
+            },
+            {
+              "name": "extraHeader.Write"
+            },
+            {
+              "name": "fileHandler.ServeHTTP"
+            },
+            {
+              "name": "fileTransport.RoundTrip"
+            },
+            {
+              "name": "globalOptionsHandler.ServeHTTP"
+            },
+            {
+              "name": "gzipReader.Close"
+            },
+            {
+              "name": "gzipReader.Read"
+            },
+            {
+              "name": "http1ClientConn.Close"
+            },
+            {
+              "name": "http1ClientConn.RoundTrip"
+            },
+            {
+              "name": "http2ClientConn.Close"
+            },
+            {
+              "name": "http2ClientConn.Ping"
+            },
+            {
+              "name": "http2ClientConn.RoundTrip"
+            },
+            {
+              "name": "http2ClientConn.Shutdown"
+            },
+            {
+              "name": "http2ConnectionError.Error"
+            },
+            {
+              "name": "http2ErrCode.String"
+            },
+            {
+              "name": "http2FrameHeader.String"
+            },
+            {
+              "name": "http2FrameType.String"
+            },
+            {
+              "name": "http2FrameWriteRequest.String"
+            },
+            {
+              "name": "http2Framer.ReadFrame"
+            },
+            {
+              "name": "http2Framer.ReadFrameForHeader"
+            },
+            {
+              "name": "http2Framer.ReadFrameHeader"
+            },
+            {
+              "name": "http2Framer.WriteContinuation"
+            },
+            {
+              "name": "http2Framer.WriteData"
+            },
+            {
+              "name": "http2Framer.WriteDataPadded"
+            },
+            {
+              "name": "http2Framer.WriteGoAway"
+            },
+            {
+              "name": "http2Framer.WriteHeaders"
+            },
+            {
+              "name": "http2Framer.WritePing"
+            },
+            {
+              "name": "http2Framer.WritePriority"
+            },
+            {
+              "name": "http2Framer.WritePushPromise"
+            },
+            {
+              "name": "http2Framer.WriteRSTStream"
+            },
+            {
+              "name": "http2Framer.WriteRawFrame"
+            },
+            {
+              "name": "http2Framer.WriteSettings"
+            },
+            {
+              "name": "http2Framer.WriteSettingsAck"
+            },
+            {
+              "name": "http2Framer.WriteWindowUpdate"
+            },
+            {
+              "name": "http2GoAwayError.Error"
+            },
+            {
+              "name": "http2Server.ServeConn"
+            },
+            {
+              "name": "http2Setting.String"
+            },
+            {
+              "name": "http2SettingID.String"
+            },
+            {
+              "name": "http2SettingsFrame.ForeachSetting"
+            },
+            {
+              "name": "http2StreamError.Error"
+            },
+            {
+              "name": "http2Transport.CloseIdleConnections"
+            },
+            {
+              "name": "http2Transport.NewClientConn"
+            },
+            {
+              "name": "http2Transport.RoundTrip"
+            },
+            {
+              "name": "http2Transport.RoundTripOpt"
+            },
+            {
+              "name": "http2bufferedWriter.Flush"
+            },
+            {
+              "name": "http2bufferedWriter.Write"
+            },
+            {
+              "name": "http2bufferedWriterTimeoutWriter.Write"
+            },
+            {
+              "name": "http2chunkWriter.Write"
+            },
+            {
+              "name": "http2clientConnPool.GetClientConn"
+            },
+            {
+              "name": "http2connError.Error"
+            },
+            {
+              "name": "http2dataBuffer.Read"
+            },
+            {
+              "name": "http2duplicatePseudoHeaderError.Error"
+            },
+            {
+              "name": "http2gzipReader.Close"
+            },
+            {
+              "name": "http2gzipReader.Read"
+            },
+            {
+              "name": "http2headerFieldNameError.Error"
+            },
+            {
+              "name": "http2headerFieldValueError.Error"
+            },
+            {
+              "name": "http2netHTTPClientConn.Close"
+            },
+            {
+              "name": "http2netHTTPClientConn.RoundTrip"
+            },
+            {
+              "name": "http2noDialClientConnPool.GetClientConn"
+            },
+            {
+              "name": "http2noDialH2RoundTripper.NewClientConn"
+            },
+            {
+              "name": "http2noDialH2RoundTripper.RoundTrip"
+            },
+            {
+              "name": "http2pipe.Read"
+            },
+            {
+              "name": "http2priorityWriteSchedulerRFC7540.CloseStream"
+            },
+            {
+              "name": "http2priorityWriteSchedulerRFC7540.OpenStream"
+            },
+            {
+              "name": "http2priorityWriteSchedulerRFC9218.OpenStream"
+            },
+            {
+              "name": "http2pseudoHeaderError.Error"
+            },
+            {
+              "name": "http2requestBody.Close"
+            },
+            {
+              "name": "http2requestBody.Read"
+            },
+            {
+              "name": "http2responseWriter.Flush"
+            },
+            {
+              "name": "http2responseWriter.FlushError"
+            },
+            {
+              "name": "http2responseWriter.Push"
+            },
+            {
+              "name": "http2responseWriter.SetReadDeadline"
+            },
+            {
+              "name": "http2responseWriter.SetWriteDeadline"
+            },
+            {
+              "name": "http2responseWriter.Write"
+            },
+            {
+              "name": "http2responseWriter.WriteHeader"
+            },
+            {
+              "name": "http2responseWriter.WriteString"
+            },
+            {
+              "name": "http2roundRobinWriteScheduler.OpenStream"
+            },
+            {
+              "name": "http2serverConn.CloseConn"
+            },
+            {
+              "name": "http2serverConn.Flush"
+            },
+            {
+              "name": "http2stickyErrWriter.Write"
+            },
+            {
+              "name": "http2transportResponseBody.Close"
+            },
+            {
+              "name": "http2transportResponseBody.Read"
+            },
+            {
+              "name": "http2unencryptedTransport.RoundTrip"
+            },
+            {
+              "name": "http2writeData.String"
+            },
+            {
+              "name": "initALPNRequest.ServeHTTP"
+            },
+            {
+              "name": "loggingConn.Close"
+            },
+            {
+              "name": "loggingConn.Read"
+            },
+            {
+              "name": "loggingConn.Write"
+            },
+            {
+              "name": "maxBytesReader.Close"
+            },
+            {
+              "name": "maxBytesReader.Read"
+            },
+            {
+              "name": "onceCloseListener.Close"
+            },
+            {
+              "name": "persistConn.Read"
+            },
+            {
+              "name": "persistConnWriter.ReadFrom"
+            },
+            {
+              "name": "persistConnWriter.Write"
+            },
+            {
+              "name": "populateResponse.Write"
+            },
+            {
+              "name": "populateResponse.WriteHeader"
+            },
+            {
+              "name": "readTrackingBody.Close"
+            },
+            {
+              "name": "readTrackingBody.Read"
+            },
+            {
+              "name": "readWriteCloserBody.CloseWrite"
+            },
+            {
+              "name": "readWriteCloserBody.Read"
+            },
+            {
+              "name": "redirectHandler.ServeHTTP"
+            },
+            {
+              "name": "response.Flush"
+            },
+            {
+              "name": "response.FlushError"
+            },
+            {
+              "name": "response.Hijack"
+            },
+            {
+              "name": "response.ReadFrom"
+            },
+            {
+              "name": "response.Write"
+            },
+            {
+              "name": "response.WriteHeader"
+            },
+            {
+              "name": "response.WriteString"
+            },
+            {
+              "name": "serverHandler.ServeHTTP"
+            },
+            {
+              "name": "socksDialer.DialWithConn"
+            },
+            {
+              "name": "socksUsernamePassword.Authenticate"
+            },
+            {
+              "name": "stringWriter.WriteString"
+            },
+            {
+              "name": "timeoutHandler.ServeHTTP"
+            },
+            {
+              "name": "timeoutWriter.Write"
+            },
+            {
+              "name": "timeoutWriter.WriteHeader"
+            },
+            {
+              "name": "transportReadFromServerError.Error"
+            },
+            {
+              "name": "unencryptedHTTP2Request.ServeHTTP"
+            }
+          ],
+          "defaultStatus": "unaffected"
+        },
+        {
+          "vendor": "Go standard library",
+          "product": "net/http/internal/http2",
+          "collectionURL": "https://pkg.go.dev",
+          "packageName": "net/http/internal/http2",
+          "versions": [
+            {
+              "version": "1.27.0-0",
+              "lessThan": "1.27.2",
+              "status": "affected",
+              "versionType": "semver"
+            }
+          ],
+          "programRoutines": [
+            {
+              "name": "serverConn.processSetting"
+            },
+            {
+              "name": "serverConn.startFrameWrite"
+            },
+            {
+              "name": "ClientConn.Close"
+            },
+            {
+              "name": "ClientConn.Ping"
+            },
+            {
+              "name": "ClientConn.RoundTrip"
+            },
+            {
+              "name": "ClientConn.Shutdown"
+            },
+            {
+              "name": "Framer.ReadFrame"
+            },
+            {
+              "name": "Framer.ReadFrameForHeader"
+            },
+            {
+              "name": "Framer.ReadFrameHeader"
+            },
+            {
+              "name": "Framer.WriteContinuation"
+            },
+            {
+              "name": "Framer.WriteData"
+            },
+            {
+              "name": "Framer.WriteDataPadded"
+            },
+            {
+              "name": "Framer.WriteGoAway"
+            },
+            {
+              "name": "Framer.WriteHeaders"
+            },
+            {
+              "name": "Framer.WritePing"
+            },
+            {
+              "name": "Framer.WritePriority"
+            },
+            {
+              "name": "Framer.WritePriorityUpdate"
+            },
+            {
+              "name": "Framer.WritePushPromise"
+            },
+            {
+              "name": "Framer.WriteRSTStream"
+            },
+            {
+              "name": "Framer.WriteRawFrame"
+            },
+            {
+              "name": "Framer.WriteSettings"
+            },
+            {
+              "name": "Framer.WriteSettingsAck"
+            },
+            {
+              "name": "Framer.WriteWindowUpdate"
+            },
+            {
+              "name": "NetHTTPClientConn.Close"
+            },
+            {
+              "name": "NetHTTPClientConn.Ping"
+            },
+            {
+              "name": "NetHTTPClientConn.RoundTrip"
+            },
+            {
+              "name": "ReadFrameHeader"
+            },
+            {
+              "name": "Server.GracefulShutdown"
+            },
+            {
+              "name": "Server.ServeConn"
+            },
+            {
+              "name": "SettingsFrame.ForeachSetting"
+            },
+            {
+              "name": "Transport.AddConn"
+            },
+            {
+              "name": "Transport.CloseIdleConnections"
+            },
+            {
+              "name": "Transport.NewClientConn"
+            },
+            {
+              "name": "Transport.RoundTrip"
+            },
+            {
+              "name": "Transport.RoundTripOpt"
+            },
+            {
+              "name": "bufferedWriter.Flush"
+            },
+            {
+              "name": "bufferedWriter.Write"
+            },
+            {
+              "name": "bufferedWriterTimeoutWriter.Write"
+            },
+            {
+              "name": "chunkWriter.Write"
+            },
+            {
+              "name": "clientConnPool.GetClientConn"
+            },
+            {
+              "name": "gzipReader.Close"
+            },
+            {
+              "name": "gzipReader.Read"
+            },
+            {
+              "name": "noDialClientConnPool.GetClientConn"
+            },
+            {
+              "name": "requestBody.Close"
+            },
+            {
+              "name": "responseWriter.Flush"
+            },
+            {
+              "name": "responseWriter.FlushError"
+            },
+            {
+              "name": "responseWriter.Push"
+            },
+            {
+              "name": "responseWriter.Write"
+            },
+            {
+              "name": "responseWriter.WriteHeader"
+            },
+            {
+              "name": "responseWriter.WriteString"
+            },
+            {
+              "name": "serve400Handler.ServeHTTP"
+            },
+            {
+              "name": "serverConn.Flush"
+            },
+            {
+              "name": "stickyErrWriter.Write"
+            },
+            {
+              "name": "transportResponseBody.Close"
+            },
+            {
+              "name": "transportResponseBody.Read"
+            }
+          ],
+          "defaultStatus": "unaffected"
+        },
+        {
+          "vendor": "golang.org/x/net",
+          "product": "golang.org/x/net/http2",
+          "collectionURL": "https://pkg.go.dev",
+          "packageName": "golang.org/x/net/http2",
+          "versions": [
+            {
+              "version": "0",
+              "lessThan": "0.60.0",
+              "status": "affected",
+              "versionType": "semver"
+            }
+          ],
+          "programRoutines": [
+            {
+              "name": "serverConn.processSetting"
+            },
+            {
+              "name": "serverConn.startFrameWrite"
+            },
+            {
+              "name": "ClientConn.Close"
+            },
+            {
+              "name": "ClientConn.Ping"
+            },
+            {
+              "name": "ClientConn.RoundTrip"
+            },
+            {
+              "name": "ClientConn.Shutdown"
+            },
+            {
+              "name": "ConfigureServer"
+            },
+            {
+              "name": "ConfigureTransport"
+            },
+            {
+              "name": "ConfigureTransports"
+            },
+            {
+              "name": "ConnectionError.Error"
+            },
+            {
+              "name": "ErrCode.String"
+            },
+            {
+              "name": "FrameHeader.String"
+            },
+            {
+              "name": "FrameType.String"
+            },
+            {
+              "name": "FrameWriteRequest.String"
+            },
+            {
+              "name": "Framer.ReadFrame"
+            },
+            {
+              "name": "Framer.ReadFrameForHeader"
+            },
+            {
+              "name": "Framer.ReadFrameHeader"
+            },
+            {
+              "name": "Framer.WriteContinuation"
+            },
+            {
+              "name": "Framer.WriteData"
+            },
+            {
+              "name": "Framer.WriteDataPadded"
+            },
+            {
+              "name": "Framer.WriteGoAway"
+            },
+            {
+              "name": "Framer.WriteHeaders"
+            },
+            {
+              "name": "Framer.WritePing"
+            },
+            {
+              "name": "Framer.WritePriority"
+            },
+            {
+              "name": "Framer.WritePriorityUpdate"
+            },
+            {
+              "name": "Framer.WritePushPromise"
+            },
+            {
+              "name": "Framer.WriteRSTStream"
+            },
+            {
+              "name": "Framer.WriteRawFrame"
+            },
+            {
+              "name": "Framer.WriteSettings"
+            },
+            {
+              "name": "Framer.WriteSettingsAck"
+            },
+            {
+              "name": "Framer.WriteWindowUpdate"
+            },
+            {
+              "name": "GoAwayError.Error"
+            },
+            {
+              "name": "ReadFrameHeader"
+            },
+            {
+              "name": "Server.ServeConn"
+            },
+            {
+              "name": "Setting.String"
+            },
+            {
+              "name": "SettingID.String"
+            },
+            {
+              "name": "SettingsFrame.ForeachSetting"
+            },
+            {
+              "name": "StreamError.Error"
+            },
+            {
+              "name": "Transport.CloseIdleConnections"
+            },
+            {
+              "name": "Transport.NewClientConn"
+            },
+            {
+              "name": "Transport.RoundTrip"
+            },
+            {
+              "name": "Transport.RoundTripOpt"
+            },
+            {
+              "name": "bufferedWriter.Flush"
+            },
+            {
+              "name": "bufferedWriter.Write"
+            },
+            {
+              "name": "bufferedWriterTimeoutWriter.Write"
+            },
+            {
+              "name": "chunkWriter.Write"
+            },
+            {
+              "name": "clientConnPool.GetClientConn"
+            },
+            {
+              "name": "connError.Error"
+            },
+            {
+              "name": "dataBuffer.Read"
+            },
+            {
+              "name": "duplicatePseudoHeaderError.Error"
+            },
+            {
+              "name": "gzipReader.Close"
+            },
+            {
+              "name": "gzipReader.Read"
+            },
+            {
+              "name": "headerFieldNameError.Error"
+            },
+            {
+              "name": "headerFieldValueError.Error"
+            },
+            {
+              "name": "netHTTPClientConn.Close"
+            },
+            {
+              "name": "netHTTPClientConn.RoundTrip"
+            },
+            {
+              "name": "noDialClientConnPool.GetClientConn"
+            },
+            {
+              "name": "noDialH2RoundTripper.NewClientConn"
+            },
+            {
+              "name": "noDialH2RoundTripper.RoundTrip"
+            },
+            {
+              "name": "pipe.Read"
+            },
+            {
+              "name": "priorityWriteSchedulerRFC7540.CloseStream"
+            },
+            {
+              "name": "priorityWriteSchedulerRFC7540.OpenStream"
+            },
+            {
+              "name": "priorityWriteSchedulerRFC9218.OpenStream"
+            },
+            {
+              "name": "pseudoHeaderError.Error"
+            },
+            {
+              "name": "requestBody.Close"
+            },
+            {
+              "name": "requestBody.Read"
+            },
+            {
+              "name": "responseWriter.Flush"
+            },
+            {
+              "name": "responseWriter.FlushError"
+            },
+            {
+              "name": "responseWriter.Push"
+            },
+            {
+              "name": "responseWriter.SetReadDeadline"
+            },
+            {
+              "name": "responseWriter.SetWriteDeadline"
+            },
+            {
+              "name": "responseWriter.Write"
+            },
+            {
+              "name": "responseWriter.WriteHeader"
+            },
+            {
+              "name": "responseWriter.WriteString"
+            },
+            {
+              "name": "roundRobinWriteScheduler.OpenStream"
+            },
+            {
+              "name": "serverConn.CloseConn"
+            },
+            {
+              "name": "serverConn.Flush"
+            },
+            {
+              "name": "stickyErrWriter.Write"
+            },
+            {
+              "name": "transportResponseBody.Close"
+            },
+            {
+              "name": "transportResponseBody.Read"
+            },
+            {
+              "name": "unencryptedTransport.RoundTrip"
+            },
+            {
+              "name": "writeData.String"
+            }
+          ],
+          "defaultStatus": "unaffected"
+        }
+      ],
+      "problemTypes": [
+        {
+          "descriptions": [
+            {
+              "lang": "en",
+              "description": "CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')"
+            }
+          ]
+        }
+      ],
+      "references": [
+        {
+          "url": "https://go.dev/cl/847188"
+        },
+        {
+          "url": "https://go.dev/cl/847313"
+        },
+        {
+          "url": "https://go.dev/issue/81867"
+        },
+        {
+          "url": "https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"
+        },
+        {
+          "url": "https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs"
+        },
+        {
+          "url": "https://pkg.go.dev/vuln/GO-2026-6617"
+        }
+      ],
+      "credits": [
+        {
+          "lang": "en",
+          "value": "RyotaK (https://ryotak.net) of GMO Flatt Security Inc."
+        }
+      ]
+    }
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6599.json b/data/osv/GO-2026-6599.json
new file mode 100644
index 0000000..53c60b4
--- /dev/null
+++ b/data/osv/GO-2026-6599.json
@@ -0,0 +1,68 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6599",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-94448"
+  ],
+  "summary": "Reset context tracking on consecutive template expressions in html/template",
+  "details": "When a JavaScript template literal contains consecutive expressions, the context tracking state was not properly reset upon entering a new expression.\n\nWe now ensure that template-literal expression entries correctly reset context variables so all subsequent regular expression literals are accurately recognized and escaped.",
+  "affected": [
+    {
+      "package": {
+        "name": "stdlib",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "1.26.9"
+            },
+            {
+              "introduced": "1.27.0-0"
+            },
+            {
+              "fixed": "1.27.2"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {
+        "imports": [
+          {
+            "path": "html/template",
+            "symbols": [
+              "Template.Execute",
+              "Template.ExecuteTemplate",
+              "tJSTmpl"
+            ]
+          }
+        ]
+      }
+    }
+  ],
+  "references": [
+    {
+      "type": "FIX",
+      "url": "https://go.dev/cl/839866"
+    },
+    {
+      "type": "REPORT",
+      "url": "https://go.dev/issue/81821"
+    },
+    {
+      "type": "WEB",
+      "url": "https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6599",
+    "review_status": "REVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6600.json b/data/osv/GO-2026-6600.json
new file mode 100644
index 0000000..d8a15a0
--- /dev/null
+++ b/data/osv/GO-2026-6600.json
@@ -0,0 +1,69 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6600",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-97030"
+  ],
+  "summary": "Recognize yield as regexp preceder keyword in html/template",
+  "details": "A trusted template author may have previously written a valid template wherein the use of the 'yield' keyword would not be correctly escaped.\n\nWe now ensure that valid keyword uses are escaped and non-keyword uses are not escaped.",
+  "affected": [
+    {
+      "package": {
+        "name": "stdlib",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "1.26.9"
+            },
+            {
+              "introduced": "1.27.0-0"
+            },
+            {
+              "fixed": "1.27.2"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {
+        "imports": [
+          {
+            "path": "html/template",
+            "symbols": [
+              "Template.Execute",
+              "Template.ExecuteTemplate",
+              "nextJSCtx",
+              "tJS"
+            ]
+          }
+        ]
+      }
+    }
+  ],
+  "references": [
+    {
+      "type": "FIX",
+      "url": "https://go.dev/cl/840925"
+    },
+    {
+      "type": "REPORT",
+      "url": "https://go.dev/issue/81823"
+    },
+    {
+      "type": "WEB",
+      "url": "https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6600",
+    "review_status": "REVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6601.json b/data/osv/GO-2026-6601.json
new file mode 100644
index 0000000..a78465a
--- /dev/null
+++ b/data/osv/GO-2026-6601.json
@@ -0,0 +1,63 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6601",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-94444"
+  ],
+  "summary": "Checksum bypass for golang.org/fips140 in cmd/go",
+  "details": "Previously, a user operating inside of a malicious Go project that defines a bogus golang.org/fips140 and operates a malicious GOMODPROXY the user chooses to connect to can serve an arbitrary module in its place.\n\nWe now unpack the trusted ziphash for the bundled golang.org/fips140 module and construct its entry in the GOMODCACHE such that it can be verified by the toolchain.",
+  "affected": [
+    {
+      "package": {
+        "name": "toolchain",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "1.26.9"
+            },
+            {
+              "introduced": "1.27.0-0"
+            },
+            {
+              "fixed": "1.27.2"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {
+        "imports": [
+          {
+            "path": "cmd/go"
+          }
+        ]
+      }
+    }
+  ],
+  "references": [
+    {
+      "type": "FIX",
+      "url": "https://go.dev/cl/840685"
+    },
+    {
+      "type": "REPORT",
+      "url": "https://go.dev/issue/81833"
+    },
+    {
+      "type": "WEB",
+      "url": "https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6601",
+    "review_status": "REVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6602.json b/data/osv/GO-2026-6602.json
new file mode 100644
index 0000000..ffd6930
--- /dev/null
+++ b/data/osv/GO-2026-6602.json
@@ -0,0 +1,63 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6602",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-94447"
+  ],
+  "summary": "Checksum database bypass for golang.org/toolchain in cmd/go",
+  "details": "Previously, a user operating inside of a malicious Go project that defines a bogus golang.org/toolchain go.sum entry and operates a malicious GOMODPROXY the user chooses to use can bypass the intended checksum.\n\nWe now ensure that golang.org/toolchain always goes to the network for the canonical checksum.",
+  "affected": [
+    {
+      "package": {
+        "name": "toolchain",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "1.26.9"
+            },
+            {
+              "introduced": "1.27.0-0"
+            },
+            {
+              "fixed": "1.27.2"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {
+        "imports": [
+          {
+            "path": "cmd/go"
+          }
+        ]
+      }
+    }
+  ],
+  "references": [
+    {
+      "type": "FIX",
+      "url": "https://go.dev/cl/840785"
+    },
+    {
+      "type": "REPORT",
+      "url": "https://go.dev/issue/81834"
+    },
+    {
+      "type": "WEB",
+      "url": "https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6602",
+    "review_status": "REVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6603.json b/data/osv/GO-2026-6603.json
new file mode 100644
index 0000000..e6f4161
--- /dev/null
+++ b/data/osv/GO-2026-6603.json
@@ -0,0 +1,481 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6603",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-78659"
+  ],
+  "summary": "HTTP/2 server memory exhaustion due to Trailer headers in net/http",
+  "details": "When \"Trailer\" headers are sent by a client, the HTTP server internally uses the header values to populate the Request.Trailer map passed to the server handler. Because Request.Trailer is a map, each entry incurs memory overhead. For HTTP/2 servers, a malicious client can exploit this by sending a \"Trailer\" header that declares a large number of fields, causing the server to allocate a disproportionate amount of memory while bypassing Server.MaxHeaderValueCount and Server.MaxHeaderBytes limits. This exploit is not applicable for HTTP/1 servers, which do not support multiplexing a large number of requests over one TCP connection, and whose Server.MaxHeaderBytes are calculated differently.",
+  "affected": [
+    {
+      "package": {
+        "name": "stdlib",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "1.26.9"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {
+        "imports": [
+          {
+            "path": "net/http",
+            "symbols": [
+              "CanonicalHeaderKey",
+              "Client.CloseIdleConnections",
+              "Client.Do",
+              "Client.Get",
+              "Client.Head",
+              "Client.Post",
+              "Client.PostForm",
+              "ClientConn.Close",
+              "ClientConn.RoundTrip",
+              "Cookie.String",
+              "Cookie.Valid",
+              "CrossOriginProtection.AddInsecureBypassPattern",
+              "CrossOriginProtection.AddTrustedOrigin",
+              "CrossOriginProtection.Check",
+              "Dir.Open",
+              "Error",
+              "Get",
+              "Handle",
+              "HandleFunc",
+              "HandlerFunc.ServeHTTP",
+              "Head",
+              "Header.Add",
+              "Header.Del",
+              "Header.Get",
+              "Header.Set",
+              "Header.Values",
+              "Header.Write",
+              "Header.WriteSubset",
+              "ListenAndServe",
+              "ListenAndServeTLS",
+              "NewRequest",
+              "NewRequestWithContext",
+              "NotFound",
+              "ParseCookie",
+              "ParseSetCookie",
+              "ParseTime",
+              "Post",
+              "PostForm",
+              "ProxyFromEnvironment",
+              "ReadRequest",
+              "ReadResponse",
+              "Redirect",
+              "Request.AddCookie",
+              "Request.BasicAuth",
+              "Request.Cookie",
+              "Request.Cookies",
+              "Request.CookiesNamed",
+              "Request.FormFile",
+              "Request.FormValue",
+              "Request.MultipartReader",
+              "Request.ParseForm",
+              "Request.ParseMultipartForm",
+              "Request.PostFormValue",
+              "Request.Referer",
+              "Request.SetBasicAuth",
+              "Request.UserAgent",
+              "Request.Write",
+              "Request.WriteProxy",
+              "Response.Cookies",
+              "Response.Location",
+              "Response.Write",
+              "ResponseController.EnableFullDuplex",
+              "ResponseController.Flush",
+              "ResponseController.Hijack",
+              "ResponseController.SetReadDeadline",
+              "ResponseController.SetWriteDeadline",
+              "Serve",
+              "ServeContent",
+              "ServeFile",
+              "ServeFileFS",
+              "ServeMux.Handle",
+              "ServeMux.HandleFunc",
+              "ServeMux.ServeHTTP",
+              "ServeTLS",
+              "Server.Close",
+              "Server.ListenAndServe",
+              "Server.ListenAndServeTLS",
+              "Server.Serve",
+              "Server.ServeTLS",
+              "Server.SetKeepAlivesEnabled",
+              "Server.Shutdown",
+              "SetCookie",
+              "Transport.CancelRequest",
+              "Transport.Clone",
+              "Transport.CloseIdleConnections",
+              "Transport.NewClientConn",
+              "Transport.RoundTrip",
+              "body.Close",
+              "body.Read",
+              "bodyEOFSignal.Close",
+              "bodyEOFSignal.Read",
+              "bodyLocked.Read",
+              "bufioFlushWriter.Write",
+              "cancelTimerBody.Close",
+              "cancelTimerBody.Read",
+              "checkConnErrorWriter.Write",
+              "chunkWriter.Write",
+              "connReader.Read",
+              "connectMethodKey.String",
+              "expectContinueReader.Close",
+              "expectContinueReader.Read",
+              "extraHeader.Write",
+              "fileHandler.ServeHTTP",
+              "fileTransport.RoundTrip",
+              "globalOptionsHandler.ServeHTTP",
+              "gzipReader.Close",
+              "gzipReader.Read",
+              "http1ClientConn.Close",
+              "http1ClientConn.RoundTrip",
+              "http2ClientConn.Close",
+              "http2ClientConn.Ping",
+              "http2ClientConn.RoundTrip",
+              "http2ClientConn.Shutdown",
+              "http2ConnectionError.Error",
+              "http2ErrCode.String",
+              "http2FrameHeader.String",
+              "http2FrameType.String",
+              "http2FrameWriteRequest.String",
+              "http2Framer.ReadFrame",
+              "http2Framer.ReadFrameForHeader",
+              "http2Framer.ReadFrameHeader",
+              "http2Framer.WriteContinuation",
+              "http2Framer.WriteData",
+              "http2Framer.WriteDataPadded",
+              "http2Framer.WriteGoAway",
+              "http2Framer.WriteHeaders",
+              "http2Framer.WritePing",
+              "http2Framer.WritePriority",
+              "http2Framer.WritePushPromise",
+              "http2Framer.WriteRSTStream",
+              "http2Framer.WriteRawFrame",
+              "http2Framer.WriteSettings",
+              "http2Framer.WriteSettingsAck",
+              "http2Framer.WriteWindowUpdate",
+              "http2Framer.readMetaFrame",
+              "http2GoAwayError.Error",
+              "http2Server.ServeConn",
+              "http2Setting.String",
+              "http2SettingID.String",
+              "http2SettingsFrame.ForeachSetting",
+              "http2StreamError.Error",
+              "http2Transport.CloseIdleConnections",
+              "http2Transport.NewClientConn",
+              "http2Transport.RoundTrip",
+              "http2Transport.RoundTripOpt",
+              "http2bufferedWriter.Flush",
+              "http2bufferedWriter.Write",
+              "http2bufferedWriterTimeoutWriter.Write",
+              "http2chunkWriter.Write",
+              "http2clientConnPool.GetClientConn",
+              "http2connError.Error",
+              "http2dataBuffer.Read",
+              "http2duplicatePseudoHeaderError.Error",
+              "http2gzipReader.Close",
+              "http2gzipReader.Read",
+              "http2headerFieldNameError.Error",
+              "http2headerFieldValueError.Error",
+              "http2netHTTPClientConn.Close",
+              "http2netHTTPClientConn.RoundTrip",
+              "http2noDialClientConnPool.GetClientConn",
+              "http2noDialH2RoundTripper.NewClientConn",
+              "http2noDialH2RoundTripper.RoundTrip",
+              "http2pipe.Read",
+              "http2priorityWriteSchedulerRFC7540.CloseStream",
+              "http2priorityWriteSchedulerRFC7540.OpenStream",
+              "http2priorityWriteSchedulerRFC9218.OpenStream",
+              "http2pseudoHeaderError.Error",
+              "http2requestBody.Close",
+              "http2requestBody.Read",
+              "http2responseWriter.Flush",
+              "http2responseWriter.FlushError",
+              "http2responseWriter.Push",
+              "http2responseWriter.SetReadDeadline",
+              "http2responseWriter.SetWriteDeadline",
+              "http2responseWriter.Write",
+              "http2responseWriter.WriteHeader",
+              "http2responseWriter.WriteString",
+              "http2roundRobinWriteScheduler.OpenStream",
+              "http2serverConn.CloseConn",
+              "http2serverConn.Flush",
+              "http2stickyErrWriter.Write",
+              "http2transportResponseBody.Close",
+              "http2transportResponseBody.Read",
+              "http2unencryptedTransport.RoundTrip",
+              "http2writeData.String",
+              "initALPNRequest.ServeHTTP",
+              "loggingConn.Close",
+              "loggingConn.Read",
+              "loggingConn.Write",
+              "maxBytesReader.Close",
+              "maxBytesReader.Read",
+              "onceCloseListener.Close",
+              "persistConn.Read",
+              "persistConnWriter.ReadFrom",
+              "persistConnWriter.Write",
+              "populateResponse.Write",
+              "populateResponse.WriteHeader",
+              "readTrackingBody.Close",
+              "readTrackingBody.Read",
+              "readWriteCloserBody.CloseWrite",
+              "readWriteCloserBody.Read",
+              "redirectHandler.ServeHTTP",
+              "response.Flush",
+              "response.FlushError",
+              "response.Hijack",
+              "response.ReadFrom",
+              "response.Write",
+              "response.WriteHeader",
+              "response.WriteString",
+              "serverHandler.ServeHTTP",
+              "socksDialer.DialWithConn",
+              "socksUsernamePassword.Authenticate",
+              "stringWriter.WriteString",
+              "timeoutHandler.ServeHTTP",
+              "timeoutWriter.Write",
+              "timeoutWriter.WriteHeader",
+              "transportReadFromServerError.Error",
+              "unencryptedHTTP2Request.ServeHTTP"
+            ]
+          }
+        ]
+      }
+    },
+    {
+      "package": {
+        "name": "stdlib",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "1.27.0-0"
+            },
+            {
+              "fixed": "1.27.2"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {
+        "imports": [
+          {
+            "path": "net/http/internal/http2",
+            "symbols": [
+              "ClientConn.Close",
+              "ClientConn.Ping",
+              "ClientConn.RoundTrip",
+              "ClientConn.Shutdown",
+              "Framer.ReadFrame",
+              "Framer.ReadFrameForHeader",
+              "Framer.ReadFrameHeader",
+              "Framer.WriteContinuation",
+              "Framer.WriteData",
+              "Framer.WriteDataPadded",
+              "Framer.WriteGoAway",
+              "Framer.WriteHeaders",
+              "Framer.WritePing",
+              "Framer.WritePriority",
+              "Framer.WritePriorityUpdate",
+              "Framer.WritePushPromise",
+              "Framer.WriteRSTStream",
+              "Framer.WriteRawFrame",
+              "Framer.WriteSettings",
+              "Framer.WriteSettingsAck",
+              "Framer.WriteWindowUpdate",
+              "Framer.readMetaFrame",
+              "NetHTTPClientConn.Close",
+              "NetHTTPClientConn.Ping",
+              "NetHTTPClientConn.RoundTrip",
+              "ReadFrameHeader",
+              "Server.GracefulShutdown",
+              "Server.ServeConn",
+              "SettingsFrame.ForeachSetting",
+              "Transport.AddConn",
+              "Transport.CloseIdleConnections",
+              "Transport.NewClientConn",
+              "Transport.RoundTrip",
+              "Transport.RoundTripOpt",
+              "bufferedWriter.Flush",
+              "bufferedWriter.Write",
+              "bufferedWriterTimeoutWriter.Write",
+              "chunkWriter.Write",
+              "clientConnPool.GetClientConn",
+              "gzipReader.Close",
+              "gzipReader.Read",
+              "noDialClientConnPool.GetClientConn",
+              "requestBody.Close",
+              "responseWriter.Flush",
+              "responseWriter.FlushError",
+              "responseWriter.Push",
+              "responseWriter.Write",
+              "responseWriter.WriteHeader",
+              "responseWriter.WriteString",
+              "serve400Handler.ServeHTTP",
+              "serverConn.Flush",
+              "stickyErrWriter.Write",
+              "transportResponseBody.Close",
+              "transportResponseBody.Read"
+            ]
+          }
+        ]
+      }
+    },
+    {
+      "package": {
+        "name": "golang.org/x/net",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "0.60.0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {
+        "imports": [
+          {
+            "path": "golang.org/x/net/http2",
+            "symbols": [
+              "ClientConn.Close",
+              "ClientConn.Ping",
+              "ClientConn.RoundTrip",
+              "ClientConn.Shutdown",
+              "ConfigureServer",
+              "ConfigureTransport",
+              "ConfigureTransports",
+              "ConnectionError.Error",
+              "ErrCode.String",
+              "FrameHeader.String",
+              "FrameType.String",
+              "FrameWriteRequest.String",
+              "Framer.ReadFrame",
+              "Framer.ReadFrameForHeader",
+              "Framer.ReadFrameHeader",
+              "Framer.WriteContinuation",
+              "Framer.WriteData",
+              "Framer.WriteDataPadded",
+              "Framer.WriteGoAway",
+              "Framer.WriteHeaders",
+              "Framer.WritePing",
+              "Framer.WritePriority",
+              "Framer.WritePriorityUpdate",
+              "Framer.WritePushPromise",
+              "Framer.WriteRSTStream",
+              "Framer.WriteRawFrame",
+              "Framer.WriteSettings",
+              "Framer.WriteSettingsAck",
+              "Framer.WriteWindowUpdate",
+              "Framer.readMetaFrame",
+              "GoAwayError.Error",
+              "ReadFrameHeader",
+              "Server.ServeConn",
+              "Setting.String",
+              "SettingID.String",
+              "SettingsFrame.ForeachSetting",
+              "StreamError.Error",
+              "Transport.CloseIdleConnections",
+              "Transport.NewClientConn",
+              "Transport.RoundTrip",
+              "Transport.RoundTripOpt",
+              "bufferedWriter.Flush",
+              "bufferedWriter.Write",
+              "bufferedWriterTimeoutWriter.Write",
+              "chunkWriter.Write",
+              "clientConnPool.GetClientConn",
+              "connError.Error",
+              "dataBuffer.Read",
+              "duplicatePseudoHeaderError.Error",
+              "gzipReader.Close",
+              "gzipReader.Read",
+              "headerFieldNameError.Error",
+              "headerFieldValueError.Error",
+              "netHTTPClientConn.Close",
+              "netHTTPClientConn.RoundTrip",
+              "noDialClientConnPool.GetClientConn",
+              "noDialH2RoundTripper.NewClientConn",
+              "noDialH2RoundTripper.RoundTrip",
+              "pipe.Read",
+              "priorityWriteSchedulerRFC7540.CloseStream",
+              "priorityWriteSchedulerRFC7540.OpenStream",
+              "priorityWriteSchedulerRFC9218.OpenStream",
+              "pseudoHeaderError.Error",
+              "requestBody.Close",
+              "requestBody.Read",
+              "responseWriter.Flush",
+              "responseWriter.FlushError",
+              "responseWriter.Push",
+              "responseWriter.SetReadDeadline",
+              "responseWriter.SetWriteDeadline",
+              "responseWriter.Write",
+              "responseWriter.WriteHeader",
+              "responseWriter.WriteString",
+              "roundRobinWriteScheduler.OpenStream",
+              "serverConn.CloseConn",
+              "serverConn.Flush",
+              "stickyErrWriter.Write",
+              "transportResponseBody.Close",
+              "transportResponseBody.Read",
+              "unencryptedTransport.RoundTrip",
+              "writeData.String"
+            ]
+          }
+        ]
+      }
+    }
+  ],
+  "references": [
+    {
+      "type": "FIX",
+      "url": "https://go.dev/cl/847185"
+    },
+    {
+      "type": "FIX",
+      "url": "https://go.dev/cl/847314"
+    },
+    {
+      "type": "REPORT",
+      "url": "https://go.dev/issue/81857"
+    },
+    {
+      "type": "WEB",
+      "url": "https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"
+    },
+    {
+      "type": "WEB",
+      "url": "https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs"
+    }
+  ],
+  "credits": [
+    {
+      "name": "RyotaK (https://ryotak.net) of GMO Flatt Security Inc."
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6603",
+    "review_status": "REVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6604.json b/data/osv/GO-2026-6604.json
new file mode 100644
index 0000000..f71c308
--- /dev/null
+++ b/data/osv/GO-2026-6604.json
@@ -0,0 +1,95 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6604",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-56857"
+  ],
+  "summary": "Root.Mkdir(All) can follow junctions out of the root on Windows in os",
+  "details": "On Windows, when the target of Root.Mkdir or Root.MkdirAll is a junction pointing to an empty location, the operation can create a directory at the junction target even when that target is located outside the root. This only applies to operations where the last path component is a junction (path/to/junction, but not path/junction/target).",
+  "affected": [
+    {
+      "package": {
+        "name": "stdlib",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "1.26.9"
+            },
+            {
+              "introduced": "1.27.0-0"
+            },
+            {
+              "fixed": "1.27.2"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {
+        "imports": [
+          {
+            "path": "os",
+            "goos": [
+              "windows"
+            ],
+            "symbols": [
+              "Root.Chmod",
+              "Root.Chown",
+              "Root.Chtimes",
+              "Root.Lchown",
+              "Root.Link",
+              "Root.Mkdir",
+              "Root.MkdirAll",
+              "Root.Remove",
+              "Root.RemoveAll",
+              "Root.Rename",
+              "Root.Symlink",
+              "doInRoot",
+              "rootMkdirAll"
+            ]
+          },
+          {
+            "path": "internal/syscall/windows",
+            "goos": [
+              "windows"
+            ],
+            "symbols": [
+              "Mkdirat"
+            ]
+          }
+        ]
+      }
+    }
+  ],
+  "references": [
+    {
+      "type": "FIX",
+      "url": "https://go.dev/cl/847305"
+    },
+    {
+      "type": "REPORT",
+      "url": "https://go.dev/issue/81739"
+    },
+    {
+      "type": "WEB",
+      "url": "https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"
+    }
+  ],
+  "credits": [
+    {
+      "name": "Daniele Ballarini"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6604",
+    "review_status": "REVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6605.json b/data/osv/GO-2026-6605.json
new file mode 100644
index 0000000..e2fff39
--- /dev/null
+++ b/data/osv/GO-2026-6605.json
@@ -0,0 +1,95 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6605",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-56866"
+  ],
+  "summary": "HTTP/1 client connection desynchronization after CONNECT rejection in net/http",
+  "details": "When http.Transport sends an HTTP/1 CONNECT request with a non-empty Request.Body, it writes the body directly to the connection without framing after the request headers. If the server rejects the CONNECT request with a non-2xx keep-alive response, Transport returns the connection to the idle pool. Because CONNECT requests do not have a request body, the server may interpret the trailing body bytes as a subsequent pipelined HTTP/1.1 request on the connection, leaving the pooled connection desynchronized and causing the next caller that reuses it to read the response to the injected request. In reverse proxies (including httputil.ReverseProxy) that forward CONNECT requests through a shared Transport, this can lead to cross-user response poisoning.",
+  "affected": [
+    {
+      "package": {
+        "name": "stdlib",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "1.26.9"
+            },
+            {
+              "introduced": "1.27.0-0"
+            },
+            {
+              "fixed": "1.27.2"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {
+        "imports": [
+          {
+            "path": "net/http",
+            "symbols": [
+              "Client.CloseIdleConnections",
+              "Client.Do",
+              "Client.Get",
+              "Client.Head",
+              "Client.Post",
+              "Client.PostForm",
+              "ClientConn.Close",
+              "ClientConn.RoundTrip",
+              "Get",
+              "Head",
+              "Post",
+              "PostForm",
+              "Transport.CloseIdleConnections",
+              "Transport.NewClientConn",
+              "Transport.RoundTrip",
+              "http1ClientConn.Close",
+              "http1ClientConn.RoundTrip",
+              "persistConn.readLoop"
+            ]
+          },
+          {
+            "path": "net/http/httputil",
+            "symbols": [
+              "DumpRequestOut",
+              "ReverseProxy.ServeHTTP"
+            ]
+          }
+        ]
+      }
+    }
+  ],
+  "references": [
+    {
+      "type": "FIX",
+      "url": "https://go.dev/cl/847306"
+    },
+    {
+      "type": "REPORT",
+      "url": "https://go.dev/issue/81740"
+    },
+    {
+      "type": "WEB",
+      "url": "https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"
+    }
+  ],
+  "credits": [
+    {
+      "name": "Xclow3n (Rajat Raghav)"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6605",
+    "review_status": "REVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6607.json b/data/osv/GO-2026-6607.json
new file mode 100644
index 0000000..501396b
--- /dev/null
+++ b/data/osv/GO-2026-6607.json
@@ -0,0 +1,75 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6607",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-97031"
+  ],
+  "summary": "Reject malformed ECH outer extension references in crypto/tls",
+  "details": "Multiple ECH outer extension references are not permitted under RFC 9849; previously, a client could send a well-crafted packet that could trigger memory exhaustion in the server process by specifying multiple references.\n\nWe now reject these as malformed and curb the memory amplification vector as a result.",
+  "affected": [
+    {
+      "package": {
+        "name": "stdlib",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "1.26.9"
+            },
+            {
+              "introduced": "1.27.0-0"
+            },
+            {
+              "fixed": "1.27.2"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {
+        "imports": [
+          {
+            "path": "crypto/tls",
+            "symbols": [
+              "Conn.Handshake",
+              "Conn.HandshakeContext",
+              "Conn.Read",
+              "Conn.Write",
+              "Dial",
+              "DialWithDialer",
+              "Dialer.Dial",
+              "Dialer.DialContext",
+              "QUICConn.Start",
+              "decodeInnerClientHello"
+            ]
+          }
+        ]
+      }
+    }
+  ],
+  "references": [
+    {
+      "type": "FIX",
+      "url": "https://go.dev/cl/847312"
+    },
+    {
+      "type": "REPORT",
+      "url": "https://go.dev/issue/81855"
+    },
+    {
+      "type": "WEB",
+      "url": "https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6607",
+    "review_status": "REVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6608.json b/data/osv/GO-2026-6608.json
new file mode 100644
index 0000000..da61056
--- /dev/null
+++ b/data/osv/GO-2026-6608.json
@@ -0,0 +1,85 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6608",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-94440"
+  ],
+  "summary": "Memory limit bypass when parsing MIME headers in net/textproto, mime/multipart",
+  "details": "Parsing a multipart form can bypass memory limits and read an arbitrarily long line into memory when the remaining limit at the start of a part is less than 400 bytes.",
+  "affected": [
+    {
+      "package": {
+        "name": "stdlib",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "1.26.9"
+            },
+            {
+              "introduced": "1.27.0-0"
+            },
+            {
+              "fixed": "1.27.2"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {
+        "imports": [
+          {
+            "path": "net/textproto",
+            "symbols": [
+              "Reader.ReadContinuedLine",
+              "Reader.ReadContinuedLineBytes",
+              "Reader.ReadMIMEHeader",
+              "Reader.readContinuedLineSlice",
+              "readMIMEHeader"
+            ]
+          },
+          {
+            "path": "mime/multipart",
+            "symbols": [
+              "Part.populateHeaders",
+              "Reader.NextPart",
+              "Reader.NextRawPart",
+              "Reader.ReadForm",
+              "Reader.readForm"
+            ]
+          }
+        ]
+      }
+    }
+  ],
+  "references": [
+    {
+      "type": "FIX",
+      "url": "https://go.dev/cl/847307"
+    },
+    {
+      "type": "REPORT",
+      "url": "https://go.dev/issue/81741"
+    },
+    {
+      "type": "WEB",
+      "url": "https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"
+    }
+  ],
+  "credits": [
+    {
+      "name": "Jakub Ciolek (https://ciolek.dev)"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6608",
+    "review_status": "REVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6609.json b/data/osv/GO-2026-6609.json
new file mode 100644
index 0000000..9539cfc
--- /dev/null
+++ b/data/osv/GO-2026-6609.json
@@ -0,0 +1,76 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6609",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-78667"
+  ],
+  "summary": "Lack of limit on size of parsed Range headers in net/http",
+  "details": "When parsing a Range header containing a large number of small ranges, FileServer(FS), ServeContent, and ServeFile(FS) can consume an excessive amount of CPU.",
+  "affected": [
+    {
+      "package": {
+        "name": "stdlib",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "1.26.9"
+            },
+            {
+              "introduced": "1.27.0-0"
+            },
+            {
+              "fixed": "1.27.2"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {
+        "imports": [
+          {
+            "path": "net/http",
+            "symbols": [
+              "ServeContent",
+              "ServeFile",
+              "ServeFileFS",
+              "fileHandler.ServeHTTP",
+              "fileTransport.RoundTrip",
+              "parseRange"
+            ]
+          }
+        ]
+      }
+    }
+  ],
+  "references": [
+    {
+      "type": "FIX",
+      "url": "https://go.dev/cl/847309"
+    },
+    {
+      "type": "REPORT",
+      "url": "https://go.dev/issue/81858"
+    },
+    {
+      "type": "WEB",
+      "url": "https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"
+    }
+  ],
+  "credits": [
+    {
+      "name": "Jakub Ciolek (https://ciolek.dev)"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6609",
+    "review_status": "REVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6610.json b/data/osv/GO-2026-6610.json
new file mode 100644
index 0000000..75803fc
--- /dev/null
+++ b/data/osv/GO-2026-6610.json
@@ -0,0 +1,166 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6610",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-78660"
+  ],
+  "summary": "HTTP/2 transport accepts malformed framing-related headers in net/http",
+  "details": "Historically, we have been rather lax about malformed framing-related headers in our HTTP/2 implementation, as they cannot interfere with HTTP/2 framing. However, this makes it possible for our HTTP/2 implementation to forward responses containing such headers to an HTTP/1 client when acting as a reverse proxy. If the HTTP/1 client also does not behave strictly enough, this can result in response smuggling.",
+  "affected": [
+    {
+      "package": {
+        "name": "stdlib",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "1.26.9"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {
+        "imports": [
+          {
+            "path": "net/http",
+            "symbols": [
+              "Client.CloseIdleConnections",
+              "Client.Do",
+              "Client.Get",
+              "Client.Head",
+              "Client.Post",
+              "Client.PostForm",
+              "ClientConn.Close",
+              "ClientConn.RoundTrip",
+              "Get",
+              "Head",
+              "Post",
+              "PostForm",
+              "Transport.CloseIdleConnections",
+              "Transport.NewClientConn",
+              "Transport.RoundTrip",
+              "http1ClientConn.Close",
+              "http1ClientConn.RoundTrip",
+              "http2Transport.NewClientConn",
+              "http2Transport.RoundTrip",
+              "http2Transport.RoundTripOpt",
+              "http2clientConnPool.GetClientConn",
+              "http2clientConnReadLoop.handleResponse",
+              "http2noDialClientConnPool.GetClientConn",
+              "http2noDialH2RoundTripper.NewClientConn",
+              "http2noDialH2RoundTripper.RoundTrip",
+              "http2unencryptedTransport.RoundTrip"
+            ]
+          }
+        ]
+      }
+    },
+    {
+      "package": {
+        "name": "stdlib",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "1.27.0-0"
+            },
+            {
+              "fixed": "1.27.2"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {
+        "imports": [
+          {
+            "path": "net/http/internal/http2",
+            "symbols": [
+              "Transport.AddConn",
+              "Transport.NewClientConn",
+              "Transport.RoundTrip",
+              "Transport.RoundTripOpt",
+              "clientConnPool.GetClientConn",
+              "clientConnReadLoop.handleResponse",
+              "noDialClientConnPool.GetClientConn"
+            ]
+          }
+        ]
+      }
+    },
+    {
+      "package": {
+        "name": "golang.org/x/net",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "0.60.0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {
+        "imports": [
+          {
+            "path": "golang.org/x/net/http2",
+            "symbols": [
+              "Transport.NewClientConn",
+              "Transport.RoundTrip",
+              "Transport.RoundTripOpt",
+              "clientConnPool.GetClientConn",
+              "clientConnReadLoop.handleResponse",
+              "noDialClientConnPool.GetClientConn",
+              "noDialH2RoundTripper.NewClientConn",
+              "noDialH2RoundTripper.RoundTrip",
+              "unencryptedTransport.RoundTrip"
+            ]
+          }
+        ]
+      }
+    }
+  ],
+  "references": [
+    {
+      "type": "FIX",
+      "url": "https://go.dev/cl/835145"
+    },
+    {
+      "type": "FIX",
+      "url": "https://go.dev/cl/836385"
+    },
+    {
+      "type": "REPORT",
+      "url": "https://go.dev/issue/81115"
+    },
+    {
+      "type": "WEB",
+      "url": "https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"
+    }
+  ],
+  "credits": [
+    {
+      "name": "TJ Barton"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6610",
+    "review_status": "REVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6611.json b/data/osv/GO-2026-6611.json
new file mode 100644
index 0000000..b253d5b
--- /dev/null
+++ b/data/osv/GO-2026-6611.json
@@ -0,0 +1,539 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6611",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-78669"
+  ],
+  "summary": "Excessive CPU consumption from repeated initial window changes in net/http",
+  "details": "A malicious HTTP/2 peer can cause excessive CPU consumption in the client or server by opening a large number of streams and then sending many small SETTINGS frames containing SETTINGS_INITIAL_WINDOW_SIZE values.",
+  "affected": [
+    {
+      "package": {
+        "name": "stdlib",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "1.26.9"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {
+        "imports": [
+          {
+            "path": "net/http",
+            "symbols": [
+              "CanonicalHeaderKey",
+              "Client.CloseIdleConnections",
+              "Client.Do",
+              "Client.Get",
+              "Client.Head",
+              "Client.Post",
+              "Client.PostForm",
+              "ClientConn.Close",
+              "ClientConn.RoundTrip",
+              "Cookie.String",
+              "Cookie.Valid",
+              "CrossOriginProtection.AddInsecureBypassPattern",
+              "CrossOriginProtection.AddTrustedOrigin",
+              "CrossOriginProtection.Check",
+              "Dir.Open",
+              "Error",
+              "Get",
+              "Handle",
+              "HandleFunc",
+              "HandlerFunc.ServeHTTP",
+              "Head",
+              "Header.Add",
+              "Header.Del",
+              "Header.Get",
+              "Header.Set",
+              "Header.Values",
+              "Header.Write",
+              "Header.WriteSubset",
+              "ListenAndServe",
+              "ListenAndServeTLS",
+              "NewRequest",
+              "NewRequestWithContext",
+              "NotFound",
+              "ParseCookie",
+              "ParseSetCookie",
+              "ParseTime",
+              "Post",
+              "PostForm",
+              "ProxyFromEnvironment",
+              "ReadRequest",
+              "ReadResponse",
+              "Redirect",
+              "Request.AddCookie",
+              "Request.BasicAuth",
+              "Request.Cookie",
+              "Request.Cookies",
+              "Request.CookiesNamed",
+              "Request.FormFile",
+              "Request.FormValue",
+              "Request.MultipartReader",
+              "Request.ParseForm",
+              "Request.ParseMultipartForm",
+              "Request.PostFormValue",
+              "Request.Referer",
+              "Request.SetBasicAuth",
+              "Request.UserAgent",
+              "Request.Write",
+              "Request.WriteProxy",
+              "Response.Cookies",
+              "Response.Location",
+              "Response.Write",
+              "ResponseController.EnableFullDuplex",
+              "ResponseController.Flush",
+              "ResponseController.Hijack",
+              "ResponseController.SetReadDeadline",
+              "ResponseController.SetWriteDeadline",
+              "Serve",
+              "ServeContent",
+              "ServeFile",
+              "ServeFileFS",
+              "ServeMux.Handle",
+              "ServeMux.HandleFunc",
+              "ServeMux.ServeHTTP",
+              "ServeTLS",
+              "Server.Close",
+              "Server.ListenAndServe",
+              "Server.ListenAndServeTLS",
+              "Server.Serve",
+              "Server.ServeTLS",
+              "Server.SetKeepAlivesEnabled",
+              "Server.Shutdown",
+              "SetCookie",
+              "Transport.CancelRequest",
+              "Transport.Clone",
+              "Transport.CloseIdleConnections",
+              "Transport.NewClientConn",
+              "Transport.RoundTrip",
+              "body.Close",
+              "body.Read",
+              "bodyEOFSignal.Close",
+              "bodyEOFSignal.Read",
+              "bodyLocked.Read",
+              "bufioFlushWriter.Write",
+              "cancelTimerBody.Close",
+              "cancelTimerBody.Read",
+              "checkConnErrorWriter.Write",
+              "chunkWriter.Write",
+              "connReader.Read",
+              "connectMethodKey.String",
+              "expectContinueReader.Close",
+              "expectContinueReader.Read",
+              "extraHeader.Write",
+              "fileHandler.ServeHTTP",
+              "fileTransport.RoundTrip",
+              "globalOptionsHandler.ServeHTTP",
+              "gzipReader.Close",
+              "gzipReader.Read",
+              "http1ClientConn.Close",
+              "http1ClientConn.RoundTrip",
+              "http2ClientConn.Close",
+              "http2ClientConn.Ping",
+              "http2ClientConn.RoundTrip",
+              "http2ClientConn.Shutdown",
+              "http2ClientConn.addStreamLocked",
+              "http2ConnectionError.Error",
+              "http2ErrCode.String",
+              "http2FrameHeader.String",
+              "http2FrameType.String",
+              "http2FrameWriteRequest.Consume",
+              "http2FrameWriteRequest.String",
+              "http2Framer.ReadFrame",
+              "http2Framer.ReadFrameForHeader",
+              "http2Framer.ReadFrameHeader",
+              "http2Framer.WriteContinuation",
+              "http2Framer.WriteData",
+              "http2Framer.WriteDataPadded",
+              "http2Framer.WriteGoAway",
+              "http2Framer.WriteHeaders",
+              "http2Framer.WritePing",
+              "http2Framer.WritePriority",
+              "http2Framer.WritePushPromise",
+              "http2Framer.WriteRSTStream",
+              "http2Framer.WriteRawFrame",
+              "http2Framer.WriteSettings",
+              "http2Framer.WriteSettingsAck",
+              "http2Framer.WriteWindowUpdate",
+              "http2GoAwayError.Error",
+              "http2Server.ServeConn",
+              "http2Server.serveConn",
+              "http2Setting.String",
+              "http2SettingID.String",
+              "http2SettingsFrame.ForeachSetting",
+              "http2StreamError.Error",
+              "http2Transport.CloseIdleConnections",
+              "http2Transport.NewClientConn",
+              "http2Transport.RoundTrip",
+              "http2Transport.RoundTripOpt",
+              "http2Transport.newClientConn",
+              "http2bufferedWriter.Flush",
+              "http2bufferedWriter.Write",
+              "http2bufferedWriterTimeoutWriter.Write",
+              "http2chunkWriter.Write",
+              "http2clientConnPool.GetClientConn",
+              "http2clientConnReadLoop.processSettingsNoWrite",
+              "http2clientConnReadLoop.processWindowUpdate",
+              "http2clientConnReadLoop.streamByID",
+              "http2clientStream.awaitFlowControl",
+              "http2clientStream.cleanupWriteRequest",
+              "http2connError.Error",
+              "http2dataBuffer.Read",
+              "http2duplicatePseudoHeaderError.Error",
+              "http2gzipReader.Close",
+              "http2gzipReader.Read",
+              "http2headerFieldNameError.Error",
+              "http2headerFieldValueError.Error",
+              "http2netHTTPClientConn.Close",
+              "http2netHTTPClientConn.RoundTrip",
+              "http2noDialClientConnPool.GetClientConn",
+              "http2noDialH2RoundTripper.NewClientConn",
+              "http2noDialH2RoundTripper.RoundTrip",
+              "http2outflow.add",
+              "http2outflow.available",
+              "http2outflow.setConnFlow",
+              "http2outflow.take",
+              "http2pipe.Read",
+              "http2priorityWriteSchedulerRFC7540.CloseStream",
+              "http2priorityWriteSchedulerRFC7540.OpenStream",
+              "http2priorityWriteSchedulerRFC7540.Pop",
+              "http2priorityWriteSchedulerRFC9218.OpenStream",
+              "http2priorityWriteSchedulerRFC9218.Pop",
+              "http2pseudoHeaderError.Error",
+              "http2randomWriteScheduler.Pop",
+              "http2requestBody.Close",
+              "http2requestBody.Read",
+              "http2responseWriter.Flush",
+              "http2responseWriter.FlushError",
+              "http2responseWriter.Push",
+              "http2responseWriter.SetReadDeadline",
+              "http2responseWriter.SetWriteDeadline",
+              "http2responseWriter.Write",
+              "http2responseWriter.WriteHeader",
+              "http2responseWriter.WriteString",
+              "http2roundRobinWriteScheduler.OpenStream",
+              "http2roundRobinWriteScheduler.Pop",
+              "http2serverConn.CloseConn",
+              "http2serverConn.Flush",
+              "http2serverConn.newStream",
+              "http2serverConn.processSettingInitialWindowSize",
+              "http2serverConn.processWindowUpdate",
+              "http2serverConn.scheduleFrameWrite",
+              "http2stickyErrWriter.Write",
+              "http2transportResponseBody.Close",
+              "http2transportResponseBody.Read",
+              "http2unencryptedTransport.RoundTrip",
+              "http2writeData.String",
+              "initALPNRequest.ServeHTTP",
+              "loggingConn.Close",
+              "loggingConn.Read",
+              "loggingConn.Write",
+              "maxBytesReader.Close",
+              "maxBytesReader.Read",
+              "onceCloseListener.Close",
+              "persistConn.Read",
+              "persistConnWriter.ReadFrom",
+              "persistConnWriter.Write",
+              "populateResponse.Write",
+              "populateResponse.WriteHeader",
+              "readTrackingBody.Close",
+              "readTrackingBody.Read",
+              "readWriteCloserBody.CloseWrite",
+              "readWriteCloserBody.Read",
+              "redirectHandler.ServeHTTP",
+              "response.Flush",
+              "response.FlushError",
+              "response.Hijack",
+              "response.ReadFrom",
+              "response.Write",
+              "response.WriteHeader",
+              "response.WriteString",
+              "serverHandler.ServeHTTP",
+              "socksDialer.DialWithConn",
+              "socksUsernamePassword.Authenticate",
+              "stringWriter.WriteString",
+              "timeoutHandler.ServeHTTP",
+              "timeoutWriter.Write",
+              "timeoutWriter.WriteHeader",
+              "transportReadFromServerError.Error",
+              "unencryptedHTTP2Request.ServeHTTP"
+            ]
+          }
+        ]
+      }
+    },
+    {
+      "package": {
+        "name": "stdlib",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "1.27.0-0"
+            },
+            {
+              "fixed": "1.27.2"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {
+        "imports": [
+          {
+            "path": "net/http/internal/http2",
+            "symbols": [
+              "ClientConn.Close",
+              "ClientConn.Ping",
+              "ClientConn.RoundTrip",
+              "ClientConn.Shutdown",
+              "ClientConn.addStreamLocked",
+              "FrameWriteRequest.Consume",
+              "Framer.ReadFrame",
+              "Framer.ReadFrameForHeader",
+              "Framer.ReadFrameHeader",
+              "Framer.WriteContinuation",
+              "Framer.WriteData",
+              "Framer.WriteDataPadded",
+              "Framer.WriteGoAway",
+              "Framer.WriteHeaders",
+              "Framer.WritePing",
+              "Framer.WritePriority",
+              "Framer.WritePriorityUpdate",
+              "Framer.WritePushPromise",
+              "Framer.WriteRSTStream",
+              "Framer.WriteRawFrame",
+              "Framer.WriteSettings",
+              "Framer.WriteSettingsAck",
+              "Framer.WriteWindowUpdate",
+              "NetHTTPClientConn.Close",
+              "NetHTTPClientConn.Ping",
+              "NetHTTPClientConn.RoundTrip",
+              "ReadFrameHeader",
+              "Server.GracefulShutdown",
+              "Server.ServeConn",
+              "Server.serveConn",
+              "SettingsFrame.ForeachSetting",
+              "Transport.AddConn",
+              "Transport.CloseIdleConnections",
+              "Transport.NewClientConn",
+              "Transport.RoundTrip",
+              "Transport.RoundTripOpt",
+              "Transport.newClientConn",
+              "bufferedWriter.Flush",
+              "bufferedWriter.Write",
+              "bufferedWriterTimeoutWriter.Write",
+              "chunkWriter.Write",
+              "clientConnPool.GetClientConn",
+              "clientConnReadLoop.processSettingsNoWrite",
+              "clientConnReadLoop.processWindowUpdate",
+              "clientConnReadLoop.streamByID",
+              "clientStream.awaitFlowControl",
+              "clientStream.cleanupWriteRequest",
+              "gzipReader.Close",
+              "gzipReader.Read",
+              "noDialClientConnPool.GetClientConn",
+              "outflow.add",
+              "outflow.available",
+              "outflow.setConnFlow",
+              "outflow.take",
+              "priorityWriteSchedulerRFC9218.Pop",
+              "requestBody.Close",
+              "responseWriter.Flush",
+              "responseWriter.FlushError",
+              "responseWriter.Push",
+              "responseWriter.Write",
+              "responseWriter.WriteHeader",
+              "responseWriter.WriteString",
+              "roundRobinWriteScheduler.Pop",
+              "serve400Handler.ServeHTTP",
+              "serverConn.Flush",
+              "serverConn.newStream",
+              "serverConn.processSettingInitialWindowSize",
+              "serverConn.processWindowUpdate",
+              "serverConn.scheduleFrameWrite",
+              "stickyErrWriter.Write",
+              "transportResponseBody.Close",
+              "transportResponseBody.Read"
+            ]
+          }
+        ]
+      }
+    },
+    {
+      "package": {
+        "name": "golang.org/x/net",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "0.60.0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {
+        "imports": [
+          {
+            "path": "golang.org/x/net/http2",
+            "symbols": [
+              "ClientConn.Close",
+              "ClientConn.Ping",
+              "ClientConn.RoundTrip",
+              "ClientConn.Shutdown",
+              "ClientConn.addStreamLocked",
+              "ConfigureServer",
+              "ConfigureTransport",
+              "ConfigureTransports",
+              "ConnectionError.Error",
+              "ErrCode.String",
+              "FrameHeader.String",
+              "FrameType.String",
+              "FrameWriteRequest.Consume",
+              "FrameWriteRequest.String",
+              "Framer.ReadFrame",
+              "Framer.ReadFrameForHeader",
+              "Framer.ReadFrameHeader",
+              "Framer.WriteContinuation",
+              "Framer.WriteData",
+              "Framer.WriteDataPadded",
+              "Framer.WriteGoAway",
+              "Framer.WriteHeaders",
+              "Framer.WritePing",
+              "Framer.WritePriority",
+              "Framer.WritePriorityUpdate",
+              "Framer.WritePushPromise",
+              "Framer.WriteRSTStream",
+              "Framer.WriteRawFrame",
+              "Framer.WriteSettings",
+              "Framer.WriteSettingsAck",
+              "Framer.WriteWindowUpdate",
+              "GoAwayError.Error",
+              "ReadFrameHeader",
+              "Server.ServeConn",
+              "Server.serveConn",
+              "Setting.String",
+              "SettingID.String",
+              "SettingsFrame.ForeachSetting",
+              "StreamError.Error",
+              "Transport.CloseIdleConnections",
+              "Transport.NewClientConn",
+              "Transport.RoundTrip",
+              "Transport.RoundTripOpt",
+              "Transport.newClientConn",
+              "bufferedWriter.Flush",
+              "bufferedWriter.Write",
+              "bufferedWriterTimeoutWriter.Write",
+              "chunkWriter.Write",
+              "clientConnPool.GetClientConn",
+              "clientConnReadLoop.processSettingsNoWrite",
+              "clientConnReadLoop.processWindowUpdate",
+              "clientConnReadLoop.streamByID",
+              "clientStream.awaitFlowControl",
+              "clientStream.cleanupWriteRequest",
+              "connError.Error",
+              "dataBuffer.Read",
+              "duplicatePseudoHeaderError.Error",
+              "gzipReader.Close",
+              "gzipReader.Read",
+              "headerFieldNameError.Error",
+              "headerFieldValueError.Error",
+              "netHTTPClientConn.Close",
+              "netHTTPClientConn.RoundTrip",
+              "noDialClientConnPool.GetClientConn",
+              "noDialH2RoundTripper.NewClientConn",
+              "noDialH2RoundTripper.RoundTrip",
+              "outflow.add",
+              "outflow.available",
+              "outflow.setConnFlow",
+              "outflow.take",
+              "pipe.Read",
+              "priorityWriteSchedulerRFC7540.CloseStream",
+              "priorityWriteSchedulerRFC7540.OpenStream",
+              "priorityWriteSchedulerRFC7540.Pop",
+              "priorityWriteSchedulerRFC9218.OpenStream",
+              "priorityWriteSchedulerRFC9218.Pop",
+              "pseudoHeaderError.Error",
+              "randomWriteScheduler.Pop",
+              "requestBody.Close",
+              "requestBody.Read",
+              "responseWriter.Flush",
+              "responseWriter.FlushError",
+              "responseWriter.Push",
+              "responseWriter.SetReadDeadline",
+              "responseWriter.SetWriteDeadline",
+              "responseWriter.Write",
+              "responseWriter.WriteHeader",
+              "responseWriter.WriteString",
+              "roundRobinWriteScheduler.OpenStream",
+              "roundRobinWriteScheduler.Pop",
+              "serverConn.CloseConn",
+              "serverConn.Flush",
+              "serverConn.newStream",
+              "serverConn.processSettingInitialWindowSize",
+              "serverConn.processWindowUpdate",
+              "serverConn.scheduleFrameWrite",
+              "stickyErrWriter.Write",
+              "transportResponseBody.Close",
+              "transportResponseBody.Read",
+              "unencryptedTransport.RoundTrip",
+              "writeData.String"
+            ]
+          }
+        ]
+      }
+    }
+  ],
+  "references": [
+    {
+      "type": "FIX",
+      "url": "https://go.dev/cl/847186"
+    },
+    {
+      "type": "FIX",
+      "url": "https://go.dev/cl/847308"
+    },
+    {
+      "type": "REPORT",
+      "url": "https://go.dev/issue/81742"
+    },
+    {
+      "type": "WEB",
+      "url": "https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"
+    },
+    {
+      "type": "WEB",
+      "url": "https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs"
+    }
+  ],
+  "credits": [
+    {
+      "name": "Jakub Ciolek (https://ciolek.dev)"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6611",
+    "review_status": "REVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6612.json b/data/osv/GO-2026-6612.json
new file mode 100644
index 0000000..8b1472d
--- /dev/null
+++ b/data/osv/GO-2026-6612.json
@@ -0,0 +1,452 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6612",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-78663"
+  ],
+  "summary": "Double flow control refund on HTTP/2 server streams in net/http",
+  "details": "The HTTP/2 server can refund connection-level flow control twice for the same data: Once when a client resets a stream (refunding data for any sent-but-unread portion of the stream), and again when a request handler reads the buffered data. A malicious client can exploit this to bypass the configured connection-level flow control limit (MaxReceiveBufferPerConnection). Total buffered data is still limited by the concurrent stream limit and stream-level flow control.",
+  "affected": [
+    {
+      "package": {
+        "name": "stdlib",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "1.26.9"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {
+        "imports": [
+          {
+            "path": "net/http",
+            "symbols": [
+              "CanonicalHeaderKey",
+              "Client.CloseIdleConnections",
+              "Client.Do",
+              "Client.Get",
+              "Client.Head",
+              "Client.Post",
+              "Client.PostForm",
+              "ClientConn.Close",
+              "ClientConn.RoundTrip",
+              "Cookie.String",
+              "Cookie.Valid",
+              "CrossOriginProtection.AddInsecureBypassPattern",
+              "CrossOriginProtection.AddTrustedOrigin",
+              "CrossOriginProtection.Check",
+              "Dir.Open",
+              "Error",
+              "Get",
+              "Handle",
+              "HandleFunc",
+              "HandlerFunc.ServeHTTP",
+              "Head",
+              "Header.Add",
+              "Header.Del",
+              "Header.Get",
+              "Header.Set",
+              "Header.Values",
+              "Header.Write",
+              "Header.WriteSubset",
+              "ListenAndServe",
+              "ListenAndServeTLS",
+              "NewRequest",
+              "NewRequestWithContext",
+              "NotFound",
+              "ParseCookie",
+              "ParseSetCookie",
+              "ParseTime",
+              "Post",
+              "PostForm",
+              "ProxyFromEnvironment",
+              "ReadRequest",
+              "ReadResponse",
+              "Redirect",
+              "Request.AddCookie",
+              "Request.BasicAuth",
+              "Request.Cookie",
+              "Request.Cookies",
+              "Request.CookiesNamed",
+              "Request.FormFile",
+              "Request.FormValue",
+              "Request.MultipartReader",
+              "Request.ParseForm",
+              "Request.ParseMultipartForm",
+              "Request.PostFormValue",
+              "Request.Referer",
+              "Request.SetBasicAuth",
+              "Request.UserAgent",
+              "Request.Write",
+              "Request.WriteProxy",
+              "Response.Cookies",
+              "Response.Location",
+              "Response.Write",
+              "ResponseController.EnableFullDuplex",
+              "ResponseController.Flush",
+              "ResponseController.Hijack",
+              "ResponseController.SetReadDeadline",
+              "ResponseController.SetWriteDeadline",
+              "Serve",
+              "ServeContent",
+              "ServeFile",
+              "ServeFileFS",
+              "ServeMux.Handle",
+              "ServeMux.HandleFunc",
+              "ServeMux.ServeHTTP",
+              "ServeTLS",
+              "Server.Close",
+              "Server.ListenAndServe",
+              "Server.ListenAndServeTLS",
+              "Server.Serve",
+              "Server.ServeTLS",
+              "Server.SetKeepAlivesEnabled",
+              "Server.Shutdown",
+              "SetCookie",
+              "Transport.CancelRequest",
+              "Transport.Clone",
+              "Transport.CloseIdleConnections",
+              "Transport.NewClientConn",
+              "Transport.RoundTrip",
+              "body.Close",
+              "body.Read",
+              "bodyEOFSignal.Close",
+              "bodyEOFSignal.Read",
+              "bodyLocked.Read",
+              "bufioFlushWriter.Write",
+              "cancelTimerBody.Close",
+              "cancelTimerBody.Read",
+              "checkConnErrorWriter.Write",
+              "chunkWriter.Write",
+              "connReader.Read",
+              "connectMethodKey.String",
+              "expectContinueReader.Close",
+              "expectContinueReader.Read",
+              "extraHeader.Write",
+              "fileHandler.ServeHTTP",
+              "fileTransport.RoundTrip",
+              "globalOptionsHandler.ServeHTTP",
+              "gzipReader.Close",
+              "gzipReader.Read",
+              "http1ClientConn.Close",
+              "http1ClientConn.RoundTrip",
+              "http2ClientConn.Close",
+              "http2ClientConn.Ping",
+              "http2ClientConn.RoundTrip",
+              "http2ClientConn.Shutdown",
+              "http2ConnectionError.Error",
+              "http2ErrCode.String",
+              "http2FrameHeader.String",
+              "http2FrameType.String",
+              "http2FrameWriteRequest.String",
+              "http2Framer.ReadFrame",
+              "http2Framer.ReadFrameForHeader",
+              "http2Framer.ReadFrameHeader",
+              "http2Framer.WriteContinuation",
+              "http2Framer.WriteData",
+              "http2Framer.WriteDataPadded",
+              "http2Framer.WriteGoAway",
+              "http2Framer.WriteHeaders",
+              "http2Framer.WritePing",
+              "http2Framer.WritePriority",
+              "http2Framer.WritePushPromise",
+              "http2Framer.WriteRSTStream",
+              "http2Framer.WriteRawFrame",
+              "http2Framer.WriteSettings",
+              "http2Framer.WriteSettingsAck",
+              "http2Framer.WriteWindowUpdate",
+              "http2GoAwayError.Error",
+              "http2Server.ServeConn",
+              "http2Setting.String",
+              "http2SettingID.String",
+              "http2SettingsFrame.ForeachSetting",
+              "http2StreamError.Error",
+              "http2Transport.CloseIdleConnections",
+              "http2Transport.NewClientConn",
+              "http2Transport.RoundTrip",
+              "http2Transport.RoundTripOpt",
+              "http2bufferedWriter.Flush",
+              "http2bufferedWriter.Write",
+              "http2bufferedWriterTimeoutWriter.Write",
+              "http2chunkWriter.Write",
+              "http2clientConnPool.GetClientConn",
+              "http2connError.Error",
+              "http2dataBuffer.Read",
+              "http2duplicatePseudoHeaderError.Error",
+              "http2gzipReader.Close",
+              "http2gzipReader.Read",
+              "http2headerFieldNameError.Error",
+              "http2headerFieldValueError.Error",
+              "http2netHTTPClientConn.Close",
+              "http2netHTTPClientConn.RoundTrip",
+              "http2noDialClientConnPool.GetClientConn",
+              "http2noDialH2RoundTripper.NewClientConn",
+              "http2noDialH2RoundTripper.RoundTrip",
+              "http2pipe.Read",
+              "http2priorityWriteSchedulerRFC7540.CloseStream",
+              "http2priorityWriteSchedulerRFC7540.OpenStream",
+              "http2priorityWriteSchedulerRFC9218.OpenStream",
+              "http2pseudoHeaderError.Error",
+              "http2requestBody.Close",
+              "http2requestBody.Read",
+              "http2responseWriter.Flush",
+              "http2responseWriter.FlushError",
+              "http2responseWriter.Push",
+              "http2responseWriter.SetReadDeadline",
+              "http2responseWriter.SetWriteDeadline",
+              "http2responseWriter.Write",
+              "http2responseWriter.WriteHeader",
+              "http2responseWriter.WriteString",
+              "http2roundRobinWriteScheduler.OpenStream",
+              "http2serverConn.CloseConn",
+              "http2serverConn.Flush",
+              "http2serverConn.closeStream",
+              "http2serverConn.handlerDone",
+              "http2serverConn.newWriterAndRequest",
+              "http2serverConn.newWriterAndRequestNoBody",
+              "http2serverConn.noteBodyRead",
+              "http2serverConn.processHeaders",
+              "http2serverConn.runHandler",
+              "http2serverConn.scheduleHandler",
+              "http2stickyErrWriter.Write",
+              "http2transportResponseBody.Close",
+              "http2transportResponseBody.Read",
+              "http2unencryptedTransport.RoundTrip",
+              "http2writeData.String",
+              "initALPNRequest.ServeHTTP",
+              "loggingConn.Close",
+              "loggingConn.Read",
+              "loggingConn.Write",
+              "maxBytesReader.Close",
+              "maxBytesReader.Read",
+              "onceCloseListener.Close",
+              "persistConn.Read",
+              "persistConnWriter.ReadFrom",
+              "persistConnWriter.Write",
+              "populateResponse.Write",
+              "populateResponse.WriteHeader",
+              "readTrackingBody.Close",
+              "readTrackingBody.Read",
+              "readWriteCloserBody.CloseWrite",
+              "readWriteCloserBody.Read",
+              "redirectHandler.ServeHTTP",
+              "response.Flush",
+              "response.FlushError",
+              "response.Hijack",
+              "response.ReadFrom",
+              "response.Write",
+              "response.WriteHeader",
+              "response.WriteString",
+              "serverHandler.ServeHTTP",
+              "socksDialer.DialWithConn",
+              "socksUsernamePassword.Authenticate",
+              "stringWriter.WriteString",
+              "timeoutHandler.ServeHTTP",
+              "timeoutWriter.Write",
+              "timeoutWriter.WriteHeader",
+              "transportReadFromServerError.Error",
+              "unencryptedHTTP2Request.ServeHTTP"
+            ]
+          }
+        ]
+      }
+    },
+    {
+      "package": {
+        "name": "stdlib",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "1.27.0-0"
+            },
+            {
+              "fixed": "1.27.2"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {
+        "imports": [
+          {
+            "path": "net/http/internal/http2",
+            "symbols": [
+              "Server.ServeConn",
+              "requestBody.Close",
+              "requestBody.Read",
+              "serverConn.closeStream",
+              "serverConn.handlerDone",
+              "serverConn.newWriterAndRequest",
+              "serverConn.newWriterAndRequestNoBody",
+              "serverConn.noteBodyRead",
+              "serverConn.processHeaders",
+              "serverConn.runHandler",
+              "serverConn.scheduleHandler"
+            ]
+          }
+        ]
+      }
+    },
+    {
+      "package": {
+        "name": "golang.org/x/net",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "0.60.0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {
+        "imports": [
+          {
+            "path": "golang.org/x/net/http2",
+            "symbols": [
+              "ClientConn.Close",
+              "ClientConn.Ping",
+              "ClientConn.RoundTrip",
+              "ClientConn.Shutdown",
+              "ConfigureServer",
+              "ConfigureTransport",
+              "ConfigureTransports",
+              "ConnectionError.Error",
+              "ErrCode.String",
+              "FrameHeader.String",
+              "FrameType.String",
+              "FrameWriteRequest.String",
+              "Framer.ReadFrame",
+              "Framer.ReadFrameForHeader",
+              "Framer.ReadFrameHeader",
+              "Framer.WriteContinuation",
+              "Framer.WriteData",
+              "Framer.WriteDataPadded",
+              "Framer.WriteGoAway",
+              "Framer.WriteHeaders",
+              "Framer.WritePing",
+              "Framer.WritePriority",
+              "Framer.WritePriorityUpdate",
+              "Framer.WritePushPromise",
+              "Framer.WriteRSTStream",
+              "Framer.WriteRawFrame",
+              "Framer.WriteSettings",
+              "Framer.WriteSettingsAck",
+              "Framer.WriteWindowUpdate",
+              "GoAwayError.Error",
+              "ReadFrameHeader",
+              "Server.ServeConn",
+              "Setting.String",
+              "SettingID.String",
+              "SettingsFrame.ForeachSetting",
+              "StreamError.Error",
+              "Transport.CloseIdleConnections",
+              "Transport.NewClientConn",
+              "Transport.RoundTrip",
+              "Transport.RoundTripOpt",
+              "bufferedWriter.Flush",
+              "bufferedWriter.Write",
+              "bufferedWriterTimeoutWriter.Write",
+              "chunkWriter.Write",
+              "clientConnPool.GetClientConn",
+              "connError.Error",
+              "dataBuffer.Read",
+              "duplicatePseudoHeaderError.Error",
+              "gzipReader.Close",
+              "gzipReader.Read",
+              "headerFieldNameError.Error",
+              "headerFieldValueError.Error",
+              "netHTTPClientConn.Close",
+              "netHTTPClientConn.RoundTrip",
+              "noDialClientConnPool.GetClientConn",
+              "noDialH2RoundTripper.NewClientConn",
+              "noDialH2RoundTripper.RoundTrip",
+              "pipe.Read",
+              "priorityWriteSchedulerRFC7540.CloseStream",
+              "priorityWriteSchedulerRFC7540.OpenStream",
+              "priorityWriteSchedulerRFC9218.OpenStream",
+              "pseudoHeaderError.Error",
+              "requestBody.Close",
+              "requestBody.Read",
+              "responseWriter.Flush",
+              "responseWriter.FlushError",
+              "responseWriter.Push",
+              "responseWriter.SetReadDeadline",
+              "responseWriter.SetWriteDeadline",
+              "responseWriter.Write",
+              "responseWriter.WriteHeader",
+              "responseWriter.WriteString",
+              "roundRobinWriteScheduler.OpenStream",
+              "serverConn.CloseConn",
+              "serverConn.Flush",
+              "serverConn.closeStream",
+              "serverConn.handlerDone",
+              "serverConn.newWriterAndRequest",
+              "serverConn.newWriterAndRequestNoBody",
+              "serverConn.noteBodyRead",
+              "serverConn.processHeaders",
+              "serverConn.runHandler",
+              "serverConn.scheduleHandler",
+              "stickyErrWriter.Write",
+              "transportResponseBody.Close",
+              "transportResponseBody.Read",
+              "unencryptedTransport.RoundTrip",
+              "writeData.String"
+            ]
+          }
+        ]
+      }
+    }
+  ],
+  "references": [
+    {
+      "type": "FIX",
+      "url": "https://go.dev/cl/847187"
+    },
+    {
+      "type": "FIX",
+      "url": "https://go.dev/cl/847310"
+    },
+    {
+      "type": "REPORT",
+      "url": "https://go.dev/issue/81743"
+    },
+    {
+      "type": "WEB",
+      "url": "https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"
+    },
+    {
+      "type": "WEB",
+      "url": "https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs"
+    }
+  ],
+  "credits": [
+    {
+      "name": "Ali Sherif (https://www.linkedin.com/in/ali-sherif-13812b276/)"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6612",
+    "review_status": "REVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6613.json b/data/osv/GO-2026-6613.json
new file mode 100644
index 0000000..c780f41
--- /dev/null
+++ b/data/osv/GO-2026-6613.json
@@ -0,0 +1,220 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6613",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-94439"
+  ],
+  "summary": "HTTP/1 server connection desynchronization after 2xx CONNECT response in net/http",
+  "details": "When an HTTP server handler sends a 2xx response to an HTTP/1 CONNECT request and returns without hijacking the connection, the server improperly continues to read and serve requests from the connection. Since a 2xx response to an HTTP/1 CONNECT converts the connection into a tunnel, the server should not treat the connection as continuing to contain HTTP.\n\nThe impact of this misbehavior is mostly limited to potential request smuggling, where an intermediate proxy considers the data on the connection to be tunneled and the server considers it to be HTTP.",
+  "affected": [
+    {
+      "package": {
+        "name": "stdlib",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "1.26.9"
+            },
+            {
+              "introduced": "1.27.0-0"
+            },
+            {
+              "fixed": "1.27.2"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {
+        "imports": [
+          {
+            "path": "net/http",
+            "symbols": [
+              "CanonicalHeaderKey",
+              "Client.CloseIdleConnections",
+              "Client.Do",
+              "Client.Get",
+              "Client.Head",
+              "Client.Post",
+              "Client.PostForm",
+              "ClientConn.Close",
+              "ClientConn.RoundTrip",
+              "Cookie.String",
+              "Cookie.Valid",
+              "CrossOriginProtection.AddInsecureBypassPattern",
+              "CrossOriginProtection.AddTrustedOrigin",
+              "CrossOriginProtection.Check",
+              "Dir.Open",
+              "Error",
+              "Get",
+              "Handle",
+              "HandleFunc",
+              "HandlerFunc.ServeHTTP",
+              "Head",
+              "Header.Add",
+              "Header.Del",
+              "Header.Get",
+              "Header.Set",
+              "Header.Values",
+              "Header.Write",
+              "Header.WriteSubset",
+              "ListenAndServe",
+              "ListenAndServeTLS",
+              "NewRequest",
+              "NewRequestWithContext",
+              "NotFound",
+              "ParseCookie",
+              "ParseSetCookie",
+              "ParseTime",
+              "Post",
+              "PostForm",
+              "ProxyFromEnvironment",
+              "ReadRequest",
+              "ReadResponse",
+              "Redirect",
+              "Request.AddCookie",
+              "Request.BasicAuth",
+              "Request.Cookie",
+              "Request.Cookies",
+              "Request.CookiesNamed",
+              "Request.FormFile",
+              "Request.FormValue",
+              "Request.MultipartReader",
+              "Request.ParseForm",
+              "Request.ParseMultipartForm",
+              "Request.PostFormValue",
+              "Request.Referer",
+              "Request.SetBasicAuth",
+              "Request.UserAgent",
+              "Request.Write",
+              "Request.WriteProxy",
+              "Response.Cookies",
+              "Response.Location",
+              "Response.Write",
+              "ResponseController.EnableFullDuplex",
+              "ResponseController.Flush",
+              "ResponseController.Hijack",
+              "ResponseController.SetReadDeadline",
+              "ResponseController.SetWriteDeadline",
+              "Serve",
+              "ServeContent",
+              "ServeFile",
+              "ServeFileFS",
+              "ServeMux.Handle",
+              "ServeMux.HandleFunc",
+              "ServeMux.ServeHTTP",
+              "ServeTLS",
+              "Server.Close",
+              "Server.ListenAndServe",
+              "Server.ListenAndServeTLS",
+              "Server.Serve",
+              "Server.ServeTLS",
+              "Server.SetKeepAlivesEnabled",
+              "Server.Shutdown",
+              "SetCookie",
+              "Transport.CancelRequest",
+              "Transport.Clone",
+              "Transport.CloseIdleConnections",
+              "Transport.NewClientConn",
+              "Transport.RoundTrip",
+              "body.Close",
+              "body.Read",
+              "bodyEOFSignal.Close",
+              "bodyEOFSignal.Read",
+              "bodyLocked.Read",
+              "bufioFlushWriter.Write",
+              "cancelTimerBody.Close",
+              "cancelTimerBody.Read",
+              "checkConnErrorWriter.Write",
+              "chunkWriter.Write",
+              "chunkWriter.writeHeader",
+              "connReader.Read",
+              "connectMethodKey.String",
+              "expectContinueReader.Close",
+              "expectContinueReader.Read",
+              "extraHeader.Write",
+              "fileHandler.ServeHTTP",
+              "fileTransport.RoundTrip",
+              "globalOptionsHandler.ServeHTTP",
+              "gzipReader.Close",
+              "gzipReader.Read",
+              "http1ClientConn.Close",
+              "http1ClientConn.RoundTrip",
+              "http2ClientConn.RoundTrip",
+              "http2Handler.ServeHTTP",
+              "http2ResponseWriter.Flush",
+              "http2ResponseWriter.FlushError",
+              "http2ResponseWriter.Push",
+              "http2RoundTripper.RoundTrip",
+              "http3ServerHandler.ServeHTTP",
+              "initALPNRequest.ServeHTTP",
+              "loggingConn.Close",
+              "loggingConn.Read",
+              "loggingConn.Write",
+              "maxBytesReader.Close",
+              "maxBytesReader.Read",
+              "onceCloseListener.Close",
+              "persistConn.Read",
+              "persistConnWriter.ReadFrom",
+              "persistConnWriter.Write",
+              "populateResponse.Write",
+              "populateResponse.WriteHeader",
+              "readTrackingBody.Close",
+              "readTrackingBody.Read",
+              "readWriteCloserBody.CloseWrite",
+              "readWriteCloserBody.Read",
+              "redirectHandler.ServeHTTP",
+              "response.Flush",
+              "response.FlushError",
+              "response.Hijack",
+              "response.ReadFrom",
+              "response.Write",
+              "response.WriteHeader",
+              "response.WriteString",
+              "serverHandler.ServeHTTP",
+              "socksDialer.DialWithConn",
+              "socksUsernamePassword.Authenticate",
+              "stringWriter.WriteString",
+              "timeoutHandler.ServeHTTP",
+              "timeoutWriter.Write",
+              "timeoutWriter.WriteHeader",
+              "transportReadFromServerError.Error",
+              "unencryptedHTTP2Request.ServeHTTP"
+            ]
+          }
+        ]
+      }
+    }
+  ],
+  "references": [
+    {
+      "type": "FIX",
+      "url": "https://go.dev/cl/847311"
+    },
+    {
+      "type": "REPORT",
+      "url": "https://go.dev/issue/81744"
+    },
+    {
+      "type": "WEB",
+      "url": "https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"
+    }
+  ],
+  "credits": [
+    {
+      "name": "Jakub Ciolek (https://ciolek.dev)"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6613",
+    "review_status": "REVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/osv/GO-2026-6617.json b/data/osv/GO-2026-6617.json
new file mode 100644
index 0000000..9ca2ee6
--- /dev/null
+++ b/data/osv/GO-2026-6617.json
@@ -0,0 +1,484 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6617",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-97032"
+  ],
+  "summary": "HTTP/2 server crash due to HPACK encoder race in net/http",
+  "details": "HTTP/2 servers could end up crashing due to inadvertently modifying its HPACK encoder concurrently. This happens because the server modifies the HPACK encoder from two goroutines without synchronization: one uses the encoder to encode a HEADERS frame as part of a response sent to a client and the other modifies the encoder's table size when handling a SETTINGS frame containing SETTINGS_HEADER_TABLE_SIZE that a client sends. A malicious client can repeatedly send a request while changing the header table size to crash the server.",
+  "affected": [
+    {
+      "package": {
+        "name": "stdlib",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "1.26.9"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {
+        "imports": [
+          {
+            "path": "net/http",
+            "symbols": [
+              "CanonicalHeaderKey",
+              "Client.CloseIdleConnections",
+              "Client.Do",
+              "Client.Get",
+              "Client.Head",
+              "Client.Post",
+              "Client.PostForm",
+              "ClientConn.Close",
+              "ClientConn.RoundTrip",
+              "Cookie.String",
+              "Cookie.Valid",
+              "CrossOriginProtection.AddInsecureBypassPattern",
+              "CrossOriginProtection.AddTrustedOrigin",
+              "CrossOriginProtection.Check",
+              "Dir.Open",
+              "Error",
+              "Get",
+              "Handle",
+              "HandleFunc",
+              "HandlerFunc.ServeHTTP",
+              "Head",
+              "Header.Add",
+              "Header.Del",
+              "Header.Get",
+              "Header.Set",
+              "Header.Values",
+              "Header.Write",
+              "Header.WriteSubset",
+              "ListenAndServe",
+              "ListenAndServeTLS",
+              "NewRequest",
+              "NewRequestWithContext",
+              "NotFound",
+              "ParseCookie",
+              "ParseSetCookie",
+              "ParseTime",
+              "Post",
+              "PostForm",
+              "ProxyFromEnvironment",
+              "ReadRequest",
+              "ReadResponse",
+              "Redirect",
+              "Request.AddCookie",
+              "Request.BasicAuth",
+              "Request.Cookie",
+              "Request.Cookies",
+              "Request.CookiesNamed",
+              "Request.FormFile",
+              "Request.FormValue",
+              "Request.MultipartReader",
+              "Request.ParseForm",
+              "Request.ParseMultipartForm",
+              "Request.PostFormValue",
+              "Request.Referer",
+              "Request.SetBasicAuth",
+              "Request.UserAgent",
+              "Request.Write",
+              "Request.WriteProxy",
+              "Response.Cookies",
+              "Response.Location",
+              "Response.Write",
+              "ResponseController.EnableFullDuplex",
+              "ResponseController.Flush",
+              "ResponseController.Hijack",
+              "ResponseController.SetReadDeadline",
+              "ResponseController.SetWriteDeadline",
+              "Serve",
+              "ServeContent",
+              "ServeFile",
+              "ServeFileFS",
+              "ServeMux.Handle",
+              "ServeMux.HandleFunc",
+              "ServeMux.ServeHTTP",
+              "ServeTLS",
+              "Server.Close",
+              "Server.ListenAndServe",
+              "Server.ListenAndServeTLS",
+              "Server.Serve",
+              "Server.ServeTLS",
+              "Server.SetKeepAlivesEnabled",
+              "Server.Shutdown",
+              "SetCookie",
+              "Transport.CancelRequest",
+              "Transport.Clone",
+              "Transport.CloseIdleConnections",
+              "Transport.NewClientConn",
+              "Transport.RoundTrip",
+              "body.Close",
+              "body.Read",
+              "bodyEOFSignal.Close",
+              "bodyEOFSignal.Read",
+              "bodyLocked.Read",
+              "bufioFlushWriter.Write",
+              "cancelTimerBody.Close",
+              "cancelTimerBody.Read",
+              "checkConnErrorWriter.Write",
+              "chunkWriter.Write",
+              "connReader.Read",
+              "connectMethodKey.String",
+              "expectContinueReader.Close",
+              "expectContinueReader.Read",
+              "extraHeader.Write",
+              "fileHandler.ServeHTTP",
+              "fileTransport.RoundTrip",
+              "globalOptionsHandler.ServeHTTP",
+              "gzipReader.Close",
+              "gzipReader.Read",
+              "http1ClientConn.Close",
+              "http1ClientConn.RoundTrip",
+              "http2ClientConn.Close",
+              "http2ClientConn.Ping",
+              "http2ClientConn.RoundTrip",
+              "http2ClientConn.Shutdown",
+              "http2ConnectionError.Error",
+              "http2ErrCode.String",
+              "http2FrameHeader.String",
+              "http2FrameType.String",
+              "http2FrameWriteRequest.String",
+              "http2Framer.ReadFrame",
+              "http2Framer.ReadFrameForHeader",
+              "http2Framer.ReadFrameHeader",
+              "http2Framer.WriteContinuation",
+              "http2Framer.WriteData",
+              "http2Framer.WriteDataPadded",
+              "http2Framer.WriteGoAway",
+              "http2Framer.WriteHeaders",
+              "http2Framer.WritePing",
+              "http2Framer.WritePriority",
+              "http2Framer.WritePushPromise",
+              "http2Framer.WriteRSTStream",
+              "http2Framer.WriteRawFrame",
+              "http2Framer.WriteSettings",
+              "http2Framer.WriteSettingsAck",
+              "http2Framer.WriteWindowUpdate",
+              "http2GoAwayError.Error",
+              "http2Server.ServeConn",
+              "http2Setting.String",
+              "http2SettingID.String",
+              "http2SettingsFrame.ForeachSetting",
+              "http2StreamError.Error",
+              "http2Transport.CloseIdleConnections",
+              "http2Transport.NewClientConn",
+              "http2Transport.RoundTrip",
+              "http2Transport.RoundTripOpt",
+              "http2bufferedWriter.Flush",
+              "http2bufferedWriter.Write",
+              "http2bufferedWriterTimeoutWriter.Write",
+              "http2chunkWriter.Write",
+              "http2clientConnPool.GetClientConn",
+              "http2connError.Error",
+              "http2dataBuffer.Read",
+              "http2duplicatePseudoHeaderError.Error",
+              "http2gzipReader.Close",
+              "http2gzipReader.Read",
+              "http2headerFieldNameError.Error",
+              "http2headerFieldValueError.Error",
+              "http2netHTTPClientConn.Close",
+              "http2netHTTPClientConn.RoundTrip",
+              "http2noDialClientConnPool.GetClientConn",
+              "http2noDialH2RoundTripper.NewClientConn",
+              "http2noDialH2RoundTripper.RoundTrip",
+              "http2pipe.Read",
+              "http2priorityWriteSchedulerRFC7540.CloseStream",
+              "http2priorityWriteSchedulerRFC7540.OpenStream",
+              "http2priorityWriteSchedulerRFC9218.OpenStream",
+              "http2pseudoHeaderError.Error",
+              "http2requestBody.Close",
+              "http2requestBody.Read",
+              "http2responseWriter.Flush",
+              "http2responseWriter.FlushError",
+              "http2responseWriter.Push",
+              "http2responseWriter.SetReadDeadline",
+              "http2responseWriter.SetWriteDeadline",
+              "http2responseWriter.Write",
+              "http2responseWriter.WriteHeader",
+              "http2responseWriter.WriteString",
+              "http2roundRobinWriteScheduler.OpenStream",
+              "http2serverConn.CloseConn",
+              "http2serverConn.Flush",
+              "http2serverConn.processSetting",
+              "http2serverConn.startFrameWrite",
+              "http2stickyErrWriter.Write",
+              "http2transportResponseBody.Close",
+              "http2transportResponseBody.Read",
+              "http2unencryptedTransport.RoundTrip",
+              "http2writeData.String",
+              "initALPNRequest.ServeHTTP",
+              "loggingConn.Close",
+              "loggingConn.Read",
+              "loggingConn.Write",
+              "maxBytesReader.Close",
+              "maxBytesReader.Read",
+              "onceCloseListener.Close",
+              "persistConn.Read",
+              "persistConnWriter.ReadFrom",
+              "persistConnWriter.Write",
+              "populateResponse.Write",
+              "populateResponse.WriteHeader",
+              "readTrackingBody.Close",
+              "readTrackingBody.Read",
+              "readWriteCloserBody.CloseWrite",
+              "readWriteCloserBody.Read",
+              "redirectHandler.ServeHTTP",
+              "response.Flush",
+              "response.FlushError",
+              "response.Hijack",
+              "response.ReadFrom",
+              "response.Write",
+              "response.WriteHeader",
+              "response.WriteString",
+              "serverHandler.ServeHTTP",
+              "socksDialer.DialWithConn",
+              "socksUsernamePassword.Authenticate",
+              "stringWriter.WriteString",
+              "timeoutHandler.ServeHTTP",
+              "timeoutWriter.Write",
+              "timeoutWriter.WriteHeader",
+              "transportReadFromServerError.Error",
+              "unencryptedHTTP2Request.ServeHTTP"
+            ]
+          }
+        ]
+      }
+    },
+    {
+      "package": {
+        "name": "stdlib",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "1.27.0-0"
+            },
+            {
+              "fixed": "1.27.2"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {
+        "imports": [
+          {
+            "path": "net/http/internal/http2",
+            "symbols": [
+              "ClientConn.Close",
+              "ClientConn.Ping",
+              "ClientConn.RoundTrip",
+              "ClientConn.Shutdown",
+              "Framer.ReadFrame",
+              "Framer.ReadFrameForHeader",
+              "Framer.ReadFrameHeader",
+              "Framer.WriteContinuation",
+              "Framer.WriteData",
+              "Framer.WriteDataPadded",
+              "Framer.WriteGoAway",
+              "Framer.WriteHeaders",
+              "Framer.WritePing",
+              "Framer.WritePriority",
+              "Framer.WritePriorityUpdate",
+              "Framer.WritePushPromise",
+              "Framer.WriteRSTStream",
+              "Framer.WriteRawFrame",
+              "Framer.WriteSettings",
+              "Framer.WriteSettingsAck",
+              "Framer.WriteWindowUpdate",
+              "NetHTTPClientConn.Close",
+              "NetHTTPClientConn.Ping",
+              "NetHTTPClientConn.RoundTrip",
+              "ReadFrameHeader",
+              "Server.GracefulShutdown",
+              "Server.ServeConn",
+              "SettingsFrame.ForeachSetting",
+              "Transport.AddConn",
+              "Transport.CloseIdleConnections",
+              "Transport.NewClientConn",
+              "Transport.RoundTrip",
+              "Transport.RoundTripOpt",
+              "bufferedWriter.Flush",
+              "bufferedWriter.Write",
+              "bufferedWriterTimeoutWriter.Write",
+              "chunkWriter.Write",
+              "clientConnPool.GetClientConn",
+              "gzipReader.Close",
+              "gzipReader.Read",
+              "noDialClientConnPool.GetClientConn",
+              "requestBody.Close",
+              "responseWriter.Flush",
+              "responseWriter.FlushError",
+              "responseWriter.Push",
+              "responseWriter.Write",
+              "responseWriter.WriteHeader",
+              "responseWriter.WriteString",
+              "serve400Handler.ServeHTTP",
+              "serverConn.Flush",
+              "serverConn.processSetting",
+              "serverConn.startFrameWrite",
+              "stickyErrWriter.Write",
+              "transportResponseBody.Close",
+              "transportResponseBody.Read"
+            ]
+          }
+        ]
+      }
+    },
+    {
+      "package": {
+        "name": "golang.org/x/net",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "0.60.0"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {
+        "imports": [
+          {
+            "path": "golang.org/x/net/http2",
+            "symbols": [
+              "ClientConn.Close",
+              "ClientConn.Ping",
+              "ClientConn.RoundTrip",
+              "ClientConn.Shutdown",
+              "ConfigureServer",
+              "ConfigureTransport",
+              "ConfigureTransports",
+              "ConnectionError.Error",
+              "ErrCode.String",
+              "FrameHeader.String",
+              "FrameType.String",
+              "FrameWriteRequest.String",
+              "Framer.ReadFrame",
+              "Framer.ReadFrameForHeader",
+              "Framer.ReadFrameHeader",
+              "Framer.WriteContinuation",
+              "Framer.WriteData",
+              "Framer.WriteDataPadded",
+              "Framer.WriteGoAway",
+              "Framer.WriteHeaders",
+              "Framer.WritePing",
+              "Framer.WritePriority",
+              "Framer.WritePriorityUpdate",
+              "Framer.WritePushPromise",
+              "Framer.WriteRSTStream",
+              "Framer.WriteRawFrame",
+              "Framer.WriteSettings",
+              "Framer.WriteSettingsAck",
+              "Framer.WriteWindowUpdate",
+              "GoAwayError.Error",
+              "ReadFrameHeader",
+              "Server.ServeConn",
+              "Setting.String",
+              "SettingID.String",
+              "SettingsFrame.ForeachSetting",
+              "StreamError.Error",
+              "Transport.CloseIdleConnections",
+              "Transport.NewClientConn",
+              "Transport.RoundTrip",
+              "Transport.RoundTripOpt",
+              "bufferedWriter.Flush",
+              "bufferedWriter.Write",
+              "bufferedWriterTimeoutWriter.Write",
+              "chunkWriter.Write",
+              "clientConnPool.GetClientConn",
+              "connError.Error",
+              "dataBuffer.Read",
+              "duplicatePseudoHeaderError.Error",
+              "gzipReader.Close",
+              "gzipReader.Read",
+              "headerFieldNameError.Error",
+              "headerFieldValueError.Error",
+              "netHTTPClientConn.Close",
+              "netHTTPClientConn.RoundTrip",
+              "noDialClientConnPool.GetClientConn",
+              "noDialH2RoundTripper.NewClientConn",
+              "noDialH2RoundTripper.RoundTrip",
+              "pipe.Read",
+              "priorityWriteSchedulerRFC7540.CloseStream",
+              "priorityWriteSchedulerRFC7540.OpenStream",
+              "priorityWriteSchedulerRFC9218.OpenStream",
+              "pseudoHeaderError.Error",
+              "requestBody.Close",
+              "requestBody.Read",
+              "responseWriter.Flush",
+              "responseWriter.FlushError",
+              "responseWriter.Push",
+              "responseWriter.SetReadDeadline",
+              "responseWriter.SetWriteDeadline",
+              "responseWriter.Write",
+              "responseWriter.WriteHeader",
+              "responseWriter.WriteString",
+              "roundRobinWriteScheduler.OpenStream",
+              "serverConn.CloseConn",
+              "serverConn.Flush",
+              "serverConn.processSetting",
+              "serverConn.startFrameWrite",
+              "stickyErrWriter.Write",
+              "transportResponseBody.Close",
+              "transportResponseBody.Read",
+              "unencryptedTransport.RoundTrip",
+              "writeData.String"
+            ]
+          }
+        ]
+      }
+    }
+  ],
+  "references": [
+    {
+      "type": "FIX",
+      "url": "https://go.dev/cl/847188"
+    },
+    {
+      "type": "FIX",
+      "url": "https://go.dev/cl/847313"
+    },
+    {
+      "type": "REPORT",
+      "url": "https://go.dev/issue/81867"
+    },
+    {
+      "type": "WEB",
+      "url": "https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"
+    },
+    {
+      "type": "WEB",
+      "url": "https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs"
+    }
+  ],
+  "credits": [
+    {
+      "name": "RyotaK (https://ryotak.net) of GMO Flatt Security Inc."
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6617",
+    "review_status": "REVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/reports/GO-2026-6599.yaml b/data/reports/GO-2026-6599.yaml
new file mode 100644
index 0000000..3b3d3cb
--- /dev/null
+++ b/data/reports/GO-2026-6599.yaml
@@ -0,0 +1,37 @@
+id: GO-2026-6599
+modules:
+    - module: std
+      versions:
+        - fixed: 1.26.9
+        - introduced: 1.27.0-0
+        - fixed: 1.27.2
+      vulnerable_at: 1.27.1
+      packages:
+        - package: html/template
+          symbols:
+            - tJSTmpl
+          derived_symbols:
+            - Template.Execute
+            - Template.ExecuteTemplate
+summary: Reset context tracking on consecutive template expressions in html/template
+description: |-
+    When a JavaScript template literal contains
+    consecutive expressions, the context tracking
+    state was not properly reset upon entering a
+    new expression.
+
+    We now ensure that template-literal expression
+    entries correctly reset context variables so all
+    subsequent regular expression literals are
+    accurately recognized and escaped.
+references:
+    - fix: https://go.dev/cl/839866
+    - report: https://go.dev/issue/81821
+    - web: https://groups.google.com/g/golang-announce/c/U2fTuyDJznI
+cve_metadata:
+    id: CVE-2026-94448
+    cwe: 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site Scripting'')'
+source:
+    id: go-security-team
+    created: 2026-10-08T00:00:00Z
+review_status: REVIEWED
diff --git a/data/reports/GO-2026-6600.yaml b/data/reports/GO-2026-6600.yaml
new file mode 100644
index 0000000..973d450
--- /dev/null
+++ b/data/reports/GO-2026-6600.yaml
@@ -0,0 +1,34 @@
+id: GO-2026-6600
+modules:
+    - module: std
+      versions:
+        - fixed: 1.26.9
+        - introduced: 1.27.0-0
+        - fixed: 1.27.2
+      vulnerable_at: 1.27.1
+      packages:
+        - package: html/template
+          symbols:
+            - nextJSCtx
+            - tJS
+          derived_symbols:
+            - Template.Execute
+            - Template.ExecuteTemplate
+summary: Recognize yield as regexp preceder keyword in html/template
+description: |-
+    A trusted template author may have previously written a valid template wherein
+    the use of the 'yield' keyword would not be correctly escaped.
+
+    We now ensure that valid keyword uses are escaped and non-keyword uses are not
+    escaped.
+references:
+    - fix: https://go.dev/cl/840925
+    - report: https://go.dev/issue/81823
+    - web: https://groups.google.com/g/golang-announce/c/U2fTuyDJznI
+cve_metadata:
+    id: CVE-2026-97030
+    cwe: 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site Scripting'')'
+source:
+    id: go-security-team
+    created: 2026-10-08T00:00:00Z
+review_status: REVIEWED
diff --git a/data/reports/GO-2026-6601.yaml b/data/reports/GO-2026-6601.yaml
new file mode 100644
index 0000000..6a19312
--- /dev/null
+++ b/data/reports/GO-2026-6601.yaml
@@ -0,0 +1,33 @@
+id: GO-2026-6601
+modules:
+    - module: cmd
+      versions:
+        - fixed: 1.26.9
+        - introduced: 1.27.0-0
+        - fixed: 1.27.2
+      vulnerable_at: 1.27.1
+      packages:
+        - package: cmd/go
+summary: Checksum bypass for golang.org/fips140 in cmd/go
+description: |-
+    Previously, a user operating inside of a malicious
+    Go project that defines a bogus golang.org/fips140
+    and operates a malicious GOMODPROXY the user chooses
+    to connect to can serve an arbitrary module in its
+    place.
+
+    We now unpack the trusted ziphash for the bundled
+    golang.org/fips140 module and construct its entry
+    in the GOMODCACHE such that it can be verified by
+    the toolchain.
+references:
+    - fix: https://go.dev/cl/840685
+    - report: https://go.dev/issue/81833
+    - web: https://groups.google.com/g/golang-announce/c/U2fTuyDJznI
+cve_metadata:
+    id: CVE-2026-94444
+    cwe: 'CWE-354: Improper Validation of Integrity Check Value'
+source:
+    id: go-security-team
+    created: 2026-10-08T00:00:00Z
+review_status: REVIEWED
diff --git a/data/reports/GO-2026-6602.yaml b/data/reports/GO-2026-6602.yaml
new file mode 100644
index 0000000..37dc327
--- /dev/null
+++ b/data/reports/GO-2026-6602.yaml
@@ -0,0 +1,30 @@
+id: GO-2026-6602
+modules:
+    - module: cmd
+      versions:
+        - fixed: 1.26.9
+        - introduced: 1.27.0-0
+        - fixed: 1.27.2
+      vulnerable_at: 1.27.1
+      packages:
+        - package: cmd/go
+summary: Checksum database bypass for golang.org/toolchain in cmd/go
+description: |-
+    Previously, a user operating inside of a malicious
+    Go project that defines a bogus golang.org/toolchain
+    go.sum entry and operates a malicious GOMODPROXY the
+    user chooses to use can bypass the intended checksum.
+
+    We now ensure that golang.org/toolchain always goes
+    to the network for the canonical checksum.
+references:
+    - fix: https://go.dev/cl/840785
+    - report: https://go.dev/issue/81834
+    - web: https://groups.google.com/g/golang-announce/c/U2fTuyDJznI
+cve_metadata:
+    id: CVE-2026-94447
+    cwe: 'CWE-354: Improper Validation of Integrity Check Value'
+source:
+    id: go-security-team
+    created: 2026-10-08T00:00:00Z
+review_status: REVIEWED
diff --git a/data/reports/GO-2026-6603.yaml b/data/reports/GO-2026-6603.yaml
new file mode 100644
index 0000000..18d6bf2
--- /dev/null
+++ b/data/reports/GO-2026-6603.yaml
@@ -0,0 +1,407 @@
+id: GO-2026-6603
+modules:
+    - module: std
+      versions:
+        - fixed: 1.26.9
+      vulnerable_at: 1.26.8
+      packages:
+        - package: net/http
+          symbols:
+            - http2Framer.readMetaFrame
+          derived_symbols:
+            - CanonicalHeaderKey
+            - Client.CloseIdleConnections
+            - Client.Do
+            - Client.Get
+            - Client.Head
+            - Client.Post
+            - Client.PostForm
+            - ClientConn.Close
+            - ClientConn.RoundTrip
+            - Cookie.String
+            - Cookie.Valid
+            - CrossOriginProtection.AddInsecureBypassPattern
+            - CrossOriginProtection.AddTrustedOrigin
+            - CrossOriginProtection.Check
+            - Dir.Open
+            - Error
+            - Get
+            - Handle
+            - HandleFunc
+            - HandlerFunc.ServeHTTP
+            - Head
+            - Header.Add
+            - Header.Del
+            - Header.Get
+            - Header.Set
+            - Header.Values
+            - Header.Write
+            - Header.WriteSubset
+            - ListenAndServe
+            - ListenAndServeTLS
+            - NewRequest
+            - NewRequestWithContext
+            - NotFound
+            - ParseCookie
+            - ParseSetCookie
+            - ParseTime
+            - Post
+            - PostForm
+            - ProxyFromEnvironment
+            - ReadRequest
+            - ReadResponse
+            - Redirect
+            - Request.AddCookie
+            - Request.BasicAuth
+            - Request.Cookie
+            - Request.Cookies
+            - Request.CookiesNamed
+            - Request.FormFile
+            - Request.FormValue
+            - Request.MultipartReader
+            - Request.ParseForm
+            - Request.ParseMultipartForm
+            - Request.PostFormValue
+            - Request.Referer
+            - Request.SetBasicAuth
+            - Request.UserAgent
+            - Request.Write
+            - Request.WriteProxy
+            - Response.Cookies
+            - Response.Location
+            - Response.Write
+            - ResponseController.EnableFullDuplex
+            - ResponseController.Flush
+            - ResponseController.Hijack
+            - ResponseController.SetReadDeadline
+            - ResponseController.SetWriteDeadline
+            - Serve
+            - ServeContent
+            - ServeFile
+            - ServeFileFS
+            - ServeMux.Handle
+            - ServeMux.HandleFunc
+            - ServeMux.ServeHTTP
+            - ServeTLS
+            - Server.Close
+            - Server.ListenAndServe
+            - Server.ListenAndServeTLS
+            - Server.Serve
+            - Server.ServeTLS
+            - Server.SetKeepAlivesEnabled
+            - Server.Shutdown
+            - SetCookie
+            - Transport.CancelRequest
+            - Transport.Clone
+            - Transport.CloseIdleConnections
+            - Transport.NewClientConn
+            - Transport.RoundTrip
+            - body.Close
+            - body.Read
+            - bodyEOFSignal.Close
+            - bodyEOFSignal.Read
+            - bodyLocked.Read
+            - bufioFlushWriter.Write
+            - cancelTimerBody.Close
+            - cancelTimerBody.Read
+            - checkConnErrorWriter.Write
+            - chunkWriter.Write
+            - connReader.Read
+            - connectMethodKey.String
+            - expectContinueReader.Close
+            - expectContinueReader.Read
+            - extraHeader.Write
+            - fileHandler.ServeHTTP
+            - fileTransport.RoundTrip
+            - globalOptionsHandler.ServeHTTP
+            - gzipReader.Close
+            - gzipReader.Read
+            - http1ClientConn.Close
+            - http1ClientConn.RoundTrip
+            - http2ClientConn.Close
+            - http2ClientConn.Ping
+            - http2ClientConn.RoundTrip
+            - http2ClientConn.Shutdown
+            - http2ConnectionError.Error
+            - http2ErrCode.String
+            - http2FrameHeader.String
+            - http2FrameType.String
+            - http2FrameWriteRequest.String
+            - http2Framer.ReadFrame
+            - http2Framer.ReadFrameForHeader
+            - http2Framer.ReadFrameHeader
+            - http2Framer.WriteContinuation
+            - http2Framer.WriteData
+            - http2Framer.WriteDataPadded
+            - http2Framer.WriteGoAway
+            - http2Framer.WriteHeaders
+            - http2Framer.WritePing
+            - http2Framer.WritePriority
+            - http2Framer.WritePushPromise
+            - http2Framer.WriteRSTStream
+            - http2Framer.WriteRawFrame
+            - http2Framer.WriteSettings
+            - http2Framer.WriteSettingsAck
+            - http2Framer.WriteWindowUpdate
+            - http2GoAwayError.Error
+            - http2Server.ServeConn
+            - http2Setting.String
+            - http2SettingID.String
+            - http2SettingsFrame.ForeachSetting
+            - http2StreamError.Error
+            - http2Transport.CloseIdleConnections
+            - http2Transport.NewClientConn
+            - http2Transport.RoundTrip
+            - http2Transport.RoundTripOpt
+            - http2bufferedWriter.Flush
+            - http2bufferedWriter.Write
+            - http2bufferedWriterTimeoutWriter.Write
+            - http2chunkWriter.Write
+            - http2clientConnPool.GetClientConn
+            - http2connError.Error
+            - http2dataBuffer.Read
+            - http2duplicatePseudoHeaderError.Error
+            - http2gzipReader.Close
+            - http2gzipReader.Read
+            - http2headerFieldNameError.Error
+            - http2headerFieldValueError.Error
+            - http2netHTTPClientConn.Close
+            - http2netHTTPClientConn.RoundTrip
+            - http2noDialClientConnPool.GetClientConn
+            - http2noDialH2RoundTripper.NewClientConn
+            - http2noDialH2RoundTripper.RoundTrip
+            - http2pipe.Read
+            - http2priorityWriteSchedulerRFC7540.CloseStream
+            - http2priorityWriteSchedulerRFC7540.OpenStream
+            - http2priorityWriteSchedulerRFC9218.OpenStream
+            - http2pseudoHeaderError.Error
+            - http2requestBody.Close
+            - http2requestBody.Read
+            - http2responseWriter.Flush
+            - http2responseWriter.FlushError
+            - http2responseWriter.Push
+            - http2responseWriter.SetReadDeadline
+            - http2responseWriter.SetWriteDeadline
+            - http2responseWriter.Write
+            - http2responseWriter.WriteHeader
+            - http2responseWriter.WriteString
+            - http2roundRobinWriteScheduler.OpenStream
+            - http2serverConn.CloseConn
+            - http2serverConn.Flush
+            - http2stickyErrWriter.Write
+            - http2transportResponseBody.Close
+            - http2transportResponseBody.Read
+            - http2unencryptedTransport.RoundTrip
+            - http2writeData.String
+            - initALPNRequest.ServeHTTP
+            - loggingConn.Close
+            - loggingConn.Read
+            - loggingConn.Write
+            - maxBytesReader.Close
+            - maxBytesReader.Read
+            - onceCloseListener.Close
+            - persistConn.Read
+            - persistConnWriter.ReadFrom
+            - persistConnWriter.Write
+            - populateResponse.Write
+            - populateResponse.WriteHeader
+            - readTrackingBody.Close
+            - readTrackingBody.Read
+            - readWriteCloserBody.CloseWrite
+            - readWriteCloserBody.Read
+            - redirectHandler.ServeHTTP
+            - response.Flush
+            - response.FlushError
+            - response.Hijack
+            - response.ReadFrom
+            - response.Write
+            - response.WriteHeader
+            - response.WriteString
+            - serverHandler.ServeHTTP
+            - socksDialer.DialWithConn
+            - socksUsernamePassword.Authenticate
+            - stringWriter.WriteString
+            - timeoutHandler.ServeHTTP
+            - timeoutWriter.Write
+            - timeoutWriter.WriteHeader
+            - transportReadFromServerError.Error
+            - unencryptedHTTP2Request.ServeHTTP
+    - module: std
+      versions:
+        - introduced: 1.27.0-0
+        - fixed: 1.27.2
+      vulnerable_at: 1.27.1
+      packages:
+        - package: net/http/internal/http2
+          symbols:
+            - Framer.readMetaFrame
+          derived_symbols:
+            - ClientConn.Close
+            - ClientConn.Ping
+            - ClientConn.RoundTrip
+            - ClientConn.Shutdown
+            - Framer.ReadFrame
+            - Framer.ReadFrameForHeader
+            - Framer.ReadFrameHeader
+            - Framer.WriteContinuation
+            - Framer.WriteData
+            - Framer.WriteDataPadded
+            - Framer.WriteGoAway
+            - Framer.WriteHeaders
+            - Framer.WritePing
+            - Framer.WritePriority
+            - Framer.WritePriorityUpdate
+            - Framer.WritePushPromise
+            - Framer.WriteRSTStream
+            - Framer.WriteRawFrame
+            - Framer.WriteSettings
+            - Framer.WriteSettingsAck
+            - Framer.WriteWindowUpdate
+            - NetHTTPClientConn.Close
+            - NetHTTPClientConn.Ping
+            - NetHTTPClientConn.RoundTrip
+            - ReadFrameHeader
+            - Server.GracefulShutdown
+            - Server.ServeConn
+            - SettingsFrame.ForeachSetting
+            - Transport.AddConn
+            - Transport.CloseIdleConnections
+            - Transport.NewClientConn
+            - Transport.RoundTrip
+            - Transport.RoundTripOpt
+            - bufferedWriter.Flush
+            - bufferedWriter.Write
+            - bufferedWriterTimeoutWriter.Write
+            - chunkWriter.Write
+            - clientConnPool.GetClientConn
+            - gzipReader.Close
+            - gzipReader.Read
+            - noDialClientConnPool.GetClientConn
+            - requestBody.Close
+            - responseWriter.Flush
+            - responseWriter.FlushError
+            - responseWriter.Push
+            - responseWriter.Write
+            - responseWriter.WriteHeader
+            - responseWriter.WriteString
+            - serve400Handler.ServeHTTP
+            - serverConn.Flush
+            - stickyErrWriter.Write
+            - transportResponseBody.Close
+            - transportResponseBody.Read
+    - module: golang.org/x/net
+      versions:
+        - fixed: 0.60.0
+      vulnerable_at: 0.59.0
+      packages:
+        - package: golang.org/x/net/http2
+          symbols:
+            - Framer.readMetaFrame
+          derived_symbols:
+            - ClientConn.Close
+            - ClientConn.Ping
+            - ClientConn.RoundTrip
+            - ClientConn.Shutdown
+            - ConfigureServer
+            - ConfigureTransport
+            - ConfigureTransports
+            - ConnectionError.Error
+            - ErrCode.String
+            - FrameHeader.String
+            - FrameType.String
+            - FrameWriteRequest.String
+            - Framer.ReadFrame
+            - Framer.ReadFrameForHeader
+            - Framer.ReadFrameHeader
+            - Framer.WriteContinuation
+            - Framer.WriteData
+            - Framer.WriteDataPadded
+            - Framer.WriteGoAway
+            - Framer.WriteHeaders
+            - Framer.WritePing
+            - Framer.WritePriority
+            - Framer.WritePriorityUpdate
+            - Framer.WritePushPromise
+            - Framer.WriteRSTStream
+            - Framer.WriteRawFrame
+            - Framer.WriteSettings
+            - Framer.WriteSettingsAck
+            - Framer.WriteWindowUpdate
+            - GoAwayError.Error
+            - ReadFrameHeader
+            - Server.ServeConn
+            - Setting.String
+            - SettingID.String
+            - SettingsFrame.ForeachSetting
+            - StreamError.Error
+            - Transport.CloseIdleConnections
+            - Transport.NewClientConn
+            - Transport.RoundTrip
+            - Transport.RoundTripOpt
+            - bufferedWriter.Flush
+            - bufferedWriter.Write
+            - bufferedWriterTimeoutWriter.Write
+            - chunkWriter.Write
+            - clientConnPool.GetClientConn
+            - connError.Error
+            - dataBuffer.Read
+            - duplicatePseudoHeaderError.Error
+            - gzipReader.Close
+            - gzipReader.Read
+            - headerFieldNameError.Error
+            - headerFieldValueError.Error
+            - netHTTPClientConn.Close
+            - netHTTPClientConn.RoundTrip
+            - noDialClientConnPool.GetClientConn
+            - noDialH2RoundTripper.NewClientConn
+            - noDialH2RoundTripper.RoundTrip
+            - pipe.Read
+            - priorityWriteSchedulerRFC7540.CloseStream
+            - priorityWriteSchedulerRFC7540.OpenStream
+            - priorityWriteSchedulerRFC9218.OpenStream
+            - pseudoHeaderError.Error
+            - requestBody.Close
+            - requestBody.Read
+            - responseWriter.Flush
+            - responseWriter.FlushError
+            - responseWriter.Push
+            - responseWriter.SetReadDeadline
+            - responseWriter.SetWriteDeadline
+            - responseWriter.Write
+            - responseWriter.WriteHeader
+            - responseWriter.WriteString
+            - roundRobinWriteScheduler.OpenStream
+            - serverConn.CloseConn
+            - serverConn.Flush
+            - stickyErrWriter.Write
+            - transportResponseBody.Close
+            - transportResponseBody.Read
+            - unencryptedTransport.RoundTrip
+            - writeData.String
+summary: HTTP/2 server memory exhaustion due to Trailer headers in net/http
+description: |-
+    When "Trailer" headers are sent by a client, the HTTP server internally
+    uses the header values to populate the Request.Trailer map passed to the
+    server handler. Because Request.Trailer is a map, each entry incurs
+    memory overhead. For HTTP/2 servers, a malicious client can exploit this
+    by sending a "Trailer" header that declares a large number of fields,
+    causing the server to allocate a disproportionate amount of memory while
+    bypassing Server.MaxHeaderValueCount and Server.MaxHeaderBytes limits.
+    This exploit is not applicable for HTTP/1 servers, which do not support
+    multiplexing a large number of requests over one TCP connection, and
+    whose Server.MaxHeaderBytes are calculated differently.
+credits:
+    - RyotaK (https://ryotak.net) of GMO Flatt Security Inc.
+references:
+    - fix: https://go.dev/cl/847185
+    - fix: https://go.dev/cl/847314
+    - report: https://go.dev/issue/81857
+    - web: https://groups.google.com/g/golang-announce/c/U2fTuyDJznI
+    - web: https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs
+cve_metadata:
+    id: CVE-2026-78659
+    cwe: 'CWE-405: Asymmetric Resource Consumption (Amplification)'
+source:
+    id: go-security-team
+    created: 2026-10-08T00:00:00Z
+review_status: REVIEWED
diff --git a/data/reports/GO-2026-6604.yaml b/data/reports/GO-2026-6604.yaml
new file mode 100644
index 0000000..509a69a
--- /dev/null
+++ b/data/reports/GO-2026-6604.yaml
@@ -0,0 +1,52 @@
+id: GO-2026-6604
+modules:
+    - module: std
+      versions:
+        - fixed: 1.26.9
+        - introduced: 1.27.0-0
+        - fixed: 1.27.2
+      vulnerable_at: 1.27.1
+      packages:
+        - package: os
+          goos:
+            - windows
+          symbols:
+            - Root.Mkdir
+            - doInRoot
+            - rootMkdirAll
+          derived_symbols:
+            - Root.Chmod
+            - Root.Chown
+            - Root.Chtimes
+            - Root.Lchown
+            - Root.Link
+            - Root.MkdirAll
+            - Root.Remove
+            - Root.RemoveAll
+            - Root.Rename
+            - Root.Symlink
+        - package: internal/syscall/windows
+          goos:
+            - windows
+          symbols:
+            - Mkdirat
+summary: Root.Mkdir(All) can follow junctions out of the root on Windows in os
+description: |-
+    On Windows, when the target of Root.Mkdir or Root.MkdirAll is a junction
+    pointing to an empty location, the operation can create a directory at
+    the junction target even when that target is located outside the root.
+    This only applies to operations where the last path component is a
+    junction (path/to/junction, but not path/junction/target).
+credits:
+    - Daniele Ballarini
+references:
+    - fix: https://go.dev/cl/847305
+    - report: https://go.dev/issue/81739
+    - web: https://groups.google.com/g/golang-announce/c/U2fTuyDJznI
+cve_metadata:
+    id: CVE-2026-56857
+    cwe: 'CWE-1386: Insecure Operation on Windows Junction / Mount Point'
+source:
+    id: go-security-team
+    created: 2026-10-08T00:00:00Z
+review_status: REVIEWED
diff --git a/data/reports/GO-2026-6605.yaml b/data/reports/GO-2026-6605.yaml
new file mode 100644
index 0000000..94038ce
--- /dev/null
+++ b/data/reports/GO-2026-6605.yaml
@@ -0,0 +1,61 @@
+id: GO-2026-6605
+modules:
+    - module: std
+      versions:
+        - fixed: 1.26.9
+        - introduced: 1.27.0-0
+        - fixed: 1.27.2
+      vulnerable_at: 1.27.1
+      packages:
+        - package: net/http
+          symbols:
+            - persistConn.readLoop
+          derived_symbols:
+            - Client.CloseIdleConnections
+            - Client.Do
+            - Client.Get
+            - Client.Head
+            - Client.Post
+            - Client.PostForm
+            - ClientConn.Close
+            - ClientConn.RoundTrip
+            - Get
+            - Head
+            - Post
+            - PostForm
+            - Transport.CloseIdleConnections
+            - Transport.NewClientConn
+            - Transport.RoundTrip
+            - http1ClientConn.Close
+            - http1ClientConn.RoundTrip
+        - package: net/http/httputil
+          symbols:
+            - ReverseProxy.ServeHTTP
+          derived_symbols:
+            - DumpRequestOut
+summary: HTTP/1 client connection desynchronization after CONNECT rejection in net/http
+description: |-
+    When http.Transport sends an HTTP/1 CONNECT request with a non-empty
+    Request.Body, it writes the body directly to the connection without
+    framing after the request headers. If the server rejects the CONNECT
+    request with a non-2xx keep-alive response, Transport returns the
+    connection to the idle pool. Because CONNECT requests do not have a
+    request body, the server may interpret the trailing body bytes as a
+    subsequent pipelined HTTP/1.1 request on the connection, leaving the
+    pooled connection desynchronized and causing the next caller that reuses
+    it to read the response to the injected request. In reverse proxies
+    (including httputil.ReverseProxy) that forward CONNECT requests through
+    a shared Transport, this can lead to cross-user response poisoning.
+credits:
+    - Xclow3n (Rajat Raghav)
+references:
+    - fix: https://go.dev/cl/847306
+    - report: https://go.dev/issue/81740
+    - web: https://groups.google.com/g/golang-announce/c/U2fTuyDJznI
+cve_metadata:
+    id: CVE-2026-56866
+    cwe: 'CWE-444: Inconsistent Interpretation of HTTP Requests (''HTTP Request/Response Smuggling'')'
+source:
+    id: go-security-team
+    created: 2026-10-08T00:00:00Z
+review_status: REVIEWED
diff --git a/data/reports/GO-2026-6607.yaml b/data/reports/GO-2026-6607.yaml
new file mode 100644
index 0000000..42f2e59
--- /dev/null
+++ b/data/reports/GO-2026-6607.yaml
@@ -0,0 +1,43 @@
+id: GO-2026-6607
+modules:
+    - module: std
+      versions:
+        - fixed: 1.26.9
+        - introduced: 1.27.0-0
+        - fixed: 1.27.2
+      vulnerable_at: 1.27.1
+      packages:
+        - package: crypto/tls
+          symbols:
+            - decodeInnerClientHello
+          derived_symbols:
+            - Conn.Handshake
+            - Conn.HandshakeContext
+            - Conn.Read
+            - Conn.Write
+            - Dial
+            - DialWithDialer
+            - Dialer.Dial
+            - Dialer.DialContext
+            - QUICConn.Start
+summary: Reject malformed ECH outer extension references in crypto/tls
+description: |-
+    Multiple ECH outer extension references are not
+    permitted under RFC 9849; previously, a client
+    could send a well-crafted packet that could
+    trigger memory exhaustion in the server process
+    by specifying multiple references.
+
+    We now reject these as malformed and curb the
+    memory amplification vector as a result.
+references:
+    - fix: https://go.dev/cl/847312
+    - report: https://go.dev/issue/81855
+    - web: https://groups.google.com/g/golang-announce/c/U2fTuyDJznI
+cve_metadata:
+    id: CVE-2026-97031
+    cwe: 'CWE-405: Asymmetric Resource Consumption'
+source:
+    id: go-security-team
+    created: 2026-10-08T00:00:00Z
+review_status: REVIEWED
diff --git a/data/reports/GO-2026-6608.yaml b/data/reports/GO-2026-6608.yaml
new file mode 100644
index 0000000..01758e7
--- /dev/null
+++ b/data/reports/GO-2026-6608.yaml
@@ -0,0 +1,43 @@
+id: GO-2026-6608
+modules:
+    - module: std
+      versions:
+        - fixed: 1.26.9
+        - introduced: 1.27.0-0
+        - fixed: 1.27.2
+      vulnerable_at: 1.27.1
+      packages:
+        - package: net/textproto
+          symbols:
+            - readMIMEHeader
+            - Reader.readContinuedLineSlice
+          derived_symbols:
+            - Reader.ReadContinuedLine
+            - Reader.ReadContinuedLineBytes
+            - Reader.ReadMIMEHeader
+        - package: mime/multipart
+          symbols:
+            - Part.populateHeaders
+            - Reader.readForm
+          derived_symbols:
+            - Reader.NextPart
+            - Reader.NextRawPart
+            - Reader.ReadForm
+summary: Memory limit bypass when parsing MIME headers in net/textproto, mime/multipart
+description: |-
+    Parsing a multipart form can bypass memory limits and read an
+    arbitrarily long line into memory when the remaining limit at the
+    start of a part is less than 400 bytes.
+credits:
+    - Jakub Ciolek (https://ciolek.dev)
+references:
+    - fix: https://go.dev/cl/847307
+    - report: https://go.dev/issue/81741
+    - web: https://groups.google.com/g/golang-announce/c/U2fTuyDJznI
+cve_metadata:
+    id: CVE-2026-94440
+    cwe: 'CWE-770: Allocation of Resources Without Limits or Throttling'
+source:
+    id: go-security-team
+    created: 2026-10-08T00:00:00Z
+review_status: REVIEWED
diff --git a/data/reports/GO-2026-6609.yaml b/data/reports/GO-2026-6609.yaml
new file mode 100644
index 0000000..a82558b
--- /dev/null
+++ b/data/reports/GO-2026-6609.yaml
@@ -0,0 +1,36 @@
+id: GO-2026-6609
+modules:
+    - module: std
+      versions:
+        - fixed: 1.26.9
+        - introduced: 1.27.0-0
+        - fixed: 1.27.2
+      vulnerable_at: 1.27.1
+      packages:
+        - package: net/http
+          symbols:
+            - parseRange
+          derived_symbols:
+            - ServeContent
+            - ServeFile
+            - ServeFileFS
+            - fileHandler.ServeHTTP
+            - fileTransport.RoundTrip
+summary: Lack of limit on size of parsed Range headers in net/http
+description: |-
+    When parsing a Range header containing a large number of small ranges,
+    FileServer(FS), ServeContent, and ServeFile(FS) can consume an excessive
+    amount of CPU.
+credits:
+    - Jakub Ciolek (https://ciolek.dev)
+references:
+    - fix: https://go.dev/cl/847309
+    - report: https://go.dev/issue/81858
+    - web: https://groups.google.com/g/golang-announce/c/U2fTuyDJznI
+cve_metadata:
+    id: CVE-2026-78667
+    cwe: 'CWE-770: Allocation of Resources Without Limits or Throttling'
+source:
+    id: go-security-team
+    created: 2026-10-08T00:00:00Z
+review_status: REVIEWED
diff --git a/data/reports/GO-2026-6610.yaml b/data/reports/GO-2026-6610.yaml
new file mode 100644
index 0000000..7973693
--- /dev/null
+++ b/data/reports/GO-2026-6610.yaml
@@ -0,0 +1,91 @@
+id: GO-2026-6610
+modules:
+    - module: std
+      versions:
+        - fixed: 1.26.9
+      vulnerable_at: 1.26.8
+      packages:
+        - package: net/http
+          symbols:
+            - http2clientConnReadLoop.handleResponse
+          derived_symbols:
+            - Client.CloseIdleConnections
+            - Client.Do
+            - Client.Get
+            - Client.Head
+            - Client.Post
+            - Client.PostForm
+            - ClientConn.Close
+            - ClientConn.RoundTrip
+            - Get
+            - Head
+            - Post
+            - PostForm
+            - Transport.CloseIdleConnections
+            - Transport.NewClientConn
+            - Transport.RoundTrip
+            - http1ClientConn.Close
+            - http1ClientConn.RoundTrip
+            - http2Transport.NewClientConn
+            - http2Transport.RoundTrip
+            - http2Transport.RoundTripOpt
+            - http2clientConnPool.GetClientConn
+            - http2noDialClientConnPool.GetClientConn
+            - http2noDialH2RoundTripper.NewClientConn
+            - http2noDialH2RoundTripper.RoundTrip
+            - http2unencryptedTransport.RoundTrip
+    - module: std
+      versions:
+        - introduced: 1.27.0-0
+        - fixed: 1.27.2
+      vulnerable_at: 1.27.1
+      packages:
+        - package: net/http/internal/http2
+          symbols:
+            - clientConnReadLoop.handleResponse
+          derived_symbols:
+            - Transport.AddConn
+            - Transport.NewClientConn
+            - Transport.RoundTrip
+            - Transport.RoundTripOpt
+            - clientConnPool.GetClientConn
+            - noDialClientConnPool.GetClientConn
+    - module: golang.org/x/net
+      versions:
+        - fixed: 0.60.0
+      vulnerable_at: 0.59.0
+      packages:
+        - package: golang.org/x/net/http2
+          symbols:
+            - clientConnReadLoop.handleResponse
+          derived_symbols:
+            - Transport.NewClientConn
+            - Transport.RoundTrip
+            - Transport.RoundTripOpt
+            - clientConnPool.GetClientConn
+            - noDialClientConnPool.GetClientConn
+            - noDialH2RoundTripper.NewClientConn
+            - noDialH2RoundTripper.RoundTrip
+            - unencryptedTransport.RoundTrip
+summary: HTTP/2 transport accepts malformed framing-related headers in net/http
+description: |-
+    Historically, we have been rather lax about malformed framing-related
+    headers in our HTTP/2 implementation, as they cannot interfere with
+    HTTP/2 framing. However, this makes it possible for our HTTP/2
+    implementation to forward responses containing such headers to an HTTP/1
+    client when acting as a reverse proxy. If the HTTP/1 client also does
+    not behave strictly enough, this can result in response smuggling.
+credits:
+    - TJ Barton
+references:
+    - fix: https://go.dev/cl/835145
+    - fix: https://go.dev/cl/836385
+    - report: https://go.dev/issue/81115
+    - web: https://groups.google.com/g/golang-announce/c/U2fTuyDJznI
+cve_metadata:
+    id: CVE-2026-78660
+    cwe: 'CWE-444: Inconsistent Interpretation of HTTP Requests (''HTTP Request/Response Smuggling'')'
+source:
+    id: go-security-team
+    created: 2026-10-08T00:00:00Z
+review_status: REVIEWED
diff --git a/data/reports/GO-2026-6611.yaml b/data/reports/GO-2026-6611.yaml
new file mode 100644
index 0000000..ecbe358
--- /dev/null
+++ b/data/reports/GO-2026-6611.yaml
@@ -0,0 +1,458 @@
+id: GO-2026-6611
+modules:
+    - module: std
+      versions:
+        - fixed: 1.26.9
+      vulnerable_at: 1.26.8
+      packages:
+        - package: net/http
+          symbols:
+            - http2outflow.add
+            - http2outflow.available
+            - http2outflow.setConnFlow
+            - http2outflow.take
+            - http2Server.serveConn
+            - http2serverConn.newStream
+            - http2serverConn.processSettingInitialWindowSize
+            - http2serverConn.processWindowUpdate
+            - http2serverConn.scheduleFrameWrite
+            - http2ClientConn.addStreamLocked
+            - http2Transport.newClientConn
+            - http2clientConnReadLoop.processSettingsNoWrite
+            - http2clientConnReadLoop.processWindowUpdate
+            - http2clientConnReadLoop.streamByID
+            - http2clientStream.awaitFlowControl
+            - http2clientStream.cleanupWriteRequest
+            - http2FrameWriteRequest.Consume
+          derived_symbols:
+            - CanonicalHeaderKey
+            - Client.CloseIdleConnections
+            - Client.Do
+            - Client.Get
+            - Client.Head
+            - Client.Post
+            - Client.PostForm
+            - ClientConn.Close
+            - ClientConn.RoundTrip
+            - Cookie.String
+            - Cookie.Valid
+            - CrossOriginProtection.AddInsecureBypassPattern
+            - CrossOriginProtection.AddTrustedOrigin
+            - CrossOriginProtection.Check
+            - Dir.Open
+            - Error
+            - Get
+            - Handle
+            - HandleFunc
+            - HandlerFunc.ServeHTTP
+            - Head
+            - Header.Add
+            - Header.Del
+            - Header.Get
+            - Header.Set
+            - Header.Values
+            - Header.Write
+            - Header.WriteSubset
+            - ListenAndServe
+            - ListenAndServeTLS
+            - NewRequest
+            - NewRequestWithContext
+            - NotFound
+            - ParseCookie
+            - ParseSetCookie
+            - ParseTime
+            - Post
+            - PostForm
+            - ProxyFromEnvironment
+            - ReadRequest
+            - ReadResponse
+            - Redirect
+            - Request.AddCookie
+            - Request.BasicAuth
+            - Request.Cookie
+            - Request.Cookies
+            - Request.CookiesNamed
+            - Request.FormFile
+            - Request.FormValue
+            - Request.MultipartReader
+            - Request.ParseForm
+            - Request.ParseMultipartForm
+            - Request.PostFormValue
+            - Request.Referer
+            - Request.SetBasicAuth
+            - Request.UserAgent
+            - Request.Write
+            - Request.WriteProxy
+            - Response.Cookies
+            - Response.Location
+            - Response.Write
+            - ResponseController.EnableFullDuplex
+            - ResponseController.Flush
+            - ResponseController.Hijack
+            - ResponseController.SetReadDeadline
+            - ResponseController.SetWriteDeadline
+            - Serve
+            - ServeContent
+            - ServeFile
+            - ServeFileFS
+            - ServeMux.Handle
+            - ServeMux.HandleFunc
+            - ServeMux.ServeHTTP
+            - ServeTLS
+            - Server.Close
+            - Server.ListenAndServe
+            - Server.ListenAndServeTLS
+            - Server.Serve
+            - Server.ServeTLS
+            - Server.SetKeepAlivesEnabled
+            - Server.Shutdown
+            - SetCookie
+            - Transport.CancelRequest
+            - Transport.Clone
+            - Transport.CloseIdleConnections
+            - Transport.NewClientConn
+            - Transport.RoundTrip
+            - body.Close
+            - body.Read
+            - bodyEOFSignal.Close
+            - bodyEOFSignal.Read
+            - bodyLocked.Read
+            - bufioFlushWriter.Write
+            - cancelTimerBody.Close
+            - cancelTimerBody.Read
+            - checkConnErrorWriter.Write
+            - chunkWriter.Write
+            - connReader.Read
+            - connectMethodKey.String
+            - expectContinueReader.Close
+            - expectContinueReader.Read
+            - extraHeader.Write
+            - fileHandler.ServeHTTP
+            - fileTransport.RoundTrip
+            - globalOptionsHandler.ServeHTTP
+            - gzipReader.Close
+            - gzipReader.Read
+            - http1ClientConn.Close
+            - http1ClientConn.RoundTrip
+            - http2ClientConn.Close
+            - http2ClientConn.Ping
+            - http2ClientConn.RoundTrip
+            - http2ClientConn.Shutdown
+            - http2ConnectionError.Error
+            - http2ErrCode.String
+            - http2FrameHeader.String
+            - http2FrameType.String
+            - http2FrameWriteRequest.String
+            - http2Framer.ReadFrame
+            - http2Framer.ReadFrameForHeader
+            - http2Framer.ReadFrameHeader
+            - http2Framer.WriteContinuation
+            - http2Framer.WriteData
+            - http2Framer.WriteDataPadded
+            - http2Framer.WriteGoAway
+            - http2Framer.WriteHeaders
+            - http2Framer.WritePing
+            - http2Framer.WritePriority
+            - http2Framer.WritePushPromise
+            - http2Framer.WriteRSTStream
+            - http2Framer.WriteRawFrame
+            - http2Framer.WriteSettings
+            - http2Framer.WriteSettingsAck
+            - http2Framer.WriteWindowUpdate
+            - http2GoAwayError.Error
+            - http2Server.ServeConn
+            - http2Setting.String
+            - http2SettingID.String
+            - http2SettingsFrame.ForeachSetting
+            - http2StreamError.Error
+            - http2Transport.CloseIdleConnections
+            - http2Transport.NewClientConn
+            - http2Transport.RoundTrip
+            - http2Transport.RoundTripOpt
+            - http2bufferedWriter.Flush
+            - http2bufferedWriter.Write
+            - http2bufferedWriterTimeoutWriter.Write
+            - http2chunkWriter.Write
+            - http2clientConnPool.GetClientConn
+            - http2connError.Error
+            - http2dataBuffer.Read
+            - http2duplicatePseudoHeaderError.Error
+            - http2gzipReader.Close
+            - http2gzipReader.Read
+            - http2headerFieldNameError.Error
+            - http2headerFieldValueError.Error
+            - http2netHTTPClientConn.Close
+            - http2netHTTPClientConn.RoundTrip
+            - http2noDialClientConnPool.GetClientConn
+            - http2noDialH2RoundTripper.NewClientConn
+            - http2noDialH2RoundTripper.RoundTrip
+            - http2pipe.Read
+            - http2priorityWriteSchedulerRFC7540.CloseStream
+            - http2priorityWriteSchedulerRFC7540.OpenStream
+            - http2priorityWriteSchedulerRFC7540.Pop
+            - http2priorityWriteSchedulerRFC9218.OpenStream
+            - http2priorityWriteSchedulerRFC9218.Pop
+            - http2pseudoHeaderError.Error
+            - http2randomWriteScheduler.Pop
+            - http2requestBody.Close
+            - http2requestBody.Read
+            - http2responseWriter.Flush
+            - http2responseWriter.FlushError
+            - http2responseWriter.Push
+            - http2responseWriter.SetReadDeadline
+            - http2responseWriter.SetWriteDeadline
+            - http2responseWriter.Write
+            - http2responseWriter.WriteHeader
+            - http2responseWriter.WriteString
+            - http2roundRobinWriteScheduler.OpenStream
+            - http2roundRobinWriteScheduler.Pop
+            - http2serverConn.CloseConn
+            - http2serverConn.Flush
+            - http2stickyErrWriter.Write
+            - http2transportResponseBody.Close
+            - http2transportResponseBody.Read
+            - http2unencryptedTransport.RoundTrip
+            - http2writeData.String
+            - initALPNRequest.ServeHTTP
+            - loggingConn.Close
+            - loggingConn.Read
+            - loggingConn.Write
+            - maxBytesReader.Close
+            - maxBytesReader.Read
+            - onceCloseListener.Close
+            - persistConn.Read
+            - persistConnWriter.ReadFrom
+            - persistConnWriter.Write
+            - populateResponse.Write
+            - populateResponse.WriteHeader
+            - readTrackingBody.Close
+            - readTrackingBody.Read
+            - readWriteCloserBody.CloseWrite
+            - readWriteCloserBody.Read
+            - redirectHandler.ServeHTTP
+            - response.Flush
+            - response.FlushError
+            - response.Hijack
+            - response.ReadFrom
+            - response.Write
+            - response.WriteHeader
+            - response.WriteString
+            - serverHandler.ServeHTTP
+            - socksDialer.DialWithConn
+            - socksUsernamePassword.Authenticate
+            - stringWriter.WriteString
+            - timeoutHandler.ServeHTTP
+            - timeoutWriter.Write
+            - timeoutWriter.WriteHeader
+            - transportReadFromServerError.Error
+            - unencryptedHTTP2Request.ServeHTTP
+    - module: std
+      versions:
+        - introduced: 1.27.0-0
+        - fixed: 1.27.2
+      vulnerable_at: 1.27.1
+      packages:
+        - package: net/http/internal/http2
+          symbols:
+            - outflow.add
+            - outflow.available
+            - outflow.setConnFlow
+            - outflow.take
+            - Server.serveConn
+            - serverConn.newStream
+            - serverConn.processSettingInitialWindowSize
+            - serverConn.processWindowUpdate
+            - serverConn.scheduleFrameWrite
+            - ClientConn.addStreamLocked
+            - Transport.newClientConn
+            - clientConnReadLoop.processSettingsNoWrite
+            - clientConnReadLoop.processWindowUpdate
+            - clientConnReadLoop.streamByID
+            - clientStream.awaitFlowControl
+            - clientStream.cleanupWriteRequest
+            - FrameWriteRequest.Consume
+          derived_symbols:
+            - ClientConn.Close
+            - ClientConn.Ping
+            - ClientConn.RoundTrip
+            - ClientConn.Shutdown
+            - Framer.ReadFrame
+            - Framer.ReadFrameForHeader
+            - Framer.ReadFrameHeader
+            - Framer.WriteContinuation
+            - Framer.WriteData
+            - Framer.WriteDataPadded
+            - Framer.WriteGoAway
+            - Framer.WriteHeaders
+            - Framer.WritePing
+            - Framer.WritePriority
+            - Framer.WritePriorityUpdate
+            - Framer.WritePushPromise
+            - Framer.WriteRSTStream
+            - Framer.WriteRawFrame
+            - Framer.WriteSettings
+            - Framer.WriteSettingsAck
+            - Framer.WriteWindowUpdate
+            - NetHTTPClientConn.Close
+            - NetHTTPClientConn.Ping
+            - NetHTTPClientConn.RoundTrip
+            - ReadFrameHeader
+            - Server.GracefulShutdown
+            - Server.ServeConn
+            - SettingsFrame.ForeachSetting
+            - Transport.AddConn
+            - Transport.CloseIdleConnections
+            - Transport.NewClientConn
+            - Transport.RoundTrip
+            - Transport.RoundTripOpt
+            - bufferedWriter.Flush
+            - bufferedWriter.Write
+            - bufferedWriterTimeoutWriter.Write
+            - chunkWriter.Write
+            - clientConnPool.GetClientConn
+            - gzipReader.Close
+            - gzipReader.Read
+            - noDialClientConnPool.GetClientConn
+            - priorityWriteSchedulerRFC9218.Pop
+            - requestBody.Close
+            - responseWriter.Flush
+            - responseWriter.FlushError
+            - responseWriter.Push
+            - responseWriter.Write
+            - responseWriter.WriteHeader
+            - responseWriter.WriteString
+            - roundRobinWriteScheduler.Pop
+            - serve400Handler.ServeHTTP
+            - serverConn.Flush
+            - stickyErrWriter.Write
+            - transportResponseBody.Close
+            - transportResponseBody.Read
+    - module: golang.org/x/net
+      versions:
+        - fixed: 0.60.0
+      vulnerable_at: 0.59.0
+      packages:
+        - package: golang.org/x/net/http2
+          symbols:
+            - outflow.add
+            - outflow.available
+            - outflow.setConnFlow
+            - outflow.take
+            - Server.serveConn
+            - serverConn.newStream
+            - serverConn.processSettingInitialWindowSize
+            - serverConn.processWindowUpdate
+            - serverConn.scheduleFrameWrite
+            - ClientConn.addStreamLocked
+            - Transport.newClientConn
+            - clientConnReadLoop.processSettingsNoWrite
+            - clientConnReadLoop.processWindowUpdate
+            - clientConnReadLoop.streamByID
+            - clientStream.awaitFlowControl
+            - clientStream.cleanupWriteRequest
+            - FrameWriteRequest.Consume
+          derived_symbols:
+            - ClientConn.Close
+            - ClientConn.Ping
+            - ClientConn.RoundTrip
+            - ClientConn.Shutdown
+            - ConfigureServer
+            - ConfigureTransport
+            - ConfigureTransports
+            - ConnectionError.Error
+            - ErrCode.String
+            - FrameHeader.String
+            - FrameType.String
+            - FrameWriteRequest.String
+            - Framer.ReadFrame
+            - Framer.ReadFrameForHeader
+            - Framer.ReadFrameHeader
+            - Framer.WriteContinuation
+            - Framer.WriteData
+            - Framer.WriteDataPadded
+            - Framer.WriteGoAway
+            - Framer.WriteHeaders
+            - Framer.WritePing
+            - Framer.WritePriority
+            - Framer.WritePriorityUpdate
+            - Framer.WritePushPromise
+            - Framer.WriteRSTStream
+            - Framer.WriteRawFrame
+            - Framer.WriteSettings
+            - Framer.WriteSettingsAck
+            - Framer.WriteWindowUpdate
+            - GoAwayError.Error
+            - ReadFrameHeader
+            - Server.ServeConn
+            - Setting.String
+            - SettingID.String
+            - SettingsFrame.ForeachSetting
+            - StreamError.Error
+            - Transport.CloseIdleConnections
+            - Transport.NewClientConn
+            - Transport.RoundTrip
+            - Transport.RoundTripOpt
+            - bufferedWriter.Flush
+            - bufferedWriter.Write
+            - bufferedWriterTimeoutWriter.Write
+            - chunkWriter.Write
+            - clientConnPool.GetClientConn
+            - connError.Error
+            - dataBuffer.Read
+            - duplicatePseudoHeaderError.Error
+            - gzipReader.Close
+            - gzipReader.Read
+            - headerFieldNameError.Error
+            - headerFieldValueError.Error
+            - netHTTPClientConn.Close
+            - netHTTPClientConn.RoundTrip
+            - noDialClientConnPool.GetClientConn
+            - noDialH2RoundTripper.NewClientConn
+            - noDialH2RoundTripper.RoundTrip
+            - pipe.Read
+            - priorityWriteSchedulerRFC7540.CloseStream
+            - priorityWriteSchedulerRFC7540.OpenStream
+            - priorityWriteSchedulerRFC7540.Pop
+            - priorityWriteSchedulerRFC9218.OpenStream
+            - priorityWriteSchedulerRFC9218.Pop
+            - pseudoHeaderError.Error
+            - randomWriteScheduler.Pop
+            - requestBody.Close
+            - requestBody.Read
+            - responseWriter.Flush
+            - responseWriter.FlushError
+            - responseWriter.Push
+            - responseWriter.SetReadDeadline
+            - responseWriter.SetWriteDeadline
+            - responseWriter.Write
+            - responseWriter.WriteHeader
+            - responseWriter.WriteString
+            - roundRobinWriteScheduler.OpenStream
+            - roundRobinWriteScheduler.Pop
+            - serverConn.CloseConn
+            - serverConn.Flush
+            - stickyErrWriter.Write
+            - transportResponseBody.Close
+            - transportResponseBody.Read
+            - unencryptedTransport.RoundTrip
+            - writeData.String
+summary: Excessive CPU consumption from repeated initial window changes in net/http
+description: |-
+    A malicious HTTP/2 peer can cause excessive CPU consumption in the
+    client or server by opening a large number of streams and then sending
+    many small SETTINGS frames containing SETTINGS_INITIAL_WINDOW_SIZE values.
+credits:
+    - Jakub Ciolek (https://ciolek.dev)
+references:
+    - fix: https://go.dev/cl/847186
+    - fix: https://go.dev/cl/847308
+    - report: https://go.dev/issue/81742
+    - web: https://groups.google.com/g/golang-announce/c/U2fTuyDJznI
+    - web: https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs
+cve_metadata:
+    id: CVE-2026-78669
+    cwe: 'CWE-405: Asymmetric Resource Consumption (Amplification)'
+source:
+    id: go-security-team
+    created: 2026-10-08T00:00:00Z
+review_status: REVIEWED
diff --git a/data/reports/GO-2026-6612.yaml b/data/reports/GO-2026-6612.yaml
new file mode 100644
index 0000000..317b7b4
--- /dev/null
+++ b/data/reports/GO-2026-6612.yaml
@@ -0,0 +1,375 @@
+id: GO-2026-6612
+modules:
+    - module: std
+      versions:
+        - fixed: 1.26.9
+      vulnerable_at: 1.26.8
+      packages:
+        - package: net/http
+          symbols:
+            - http2requestBody.Close
+            - http2requestBody.Read
+            - http2serverConn.closeStream
+            - http2serverConn.handlerDone
+            - http2serverConn.newWriterAndRequest
+            - http2serverConn.newWriterAndRequestNoBody
+            - http2serverConn.noteBodyRead
+            - http2serverConn.processHeaders
+            - http2serverConn.runHandler
+            - http2serverConn.scheduleHandler
+          derived_symbols:
+            - CanonicalHeaderKey
+            - Client.CloseIdleConnections
+            - Client.Do
+            - Client.Get
+            - Client.Head
+            - Client.Post
+            - Client.PostForm
+            - ClientConn.Close
+            - ClientConn.RoundTrip
+            - Cookie.String
+            - Cookie.Valid
+            - CrossOriginProtection.AddInsecureBypassPattern
+            - CrossOriginProtection.AddTrustedOrigin
+            - CrossOriginProtection.Check
+            - Dir.Open
+            - Error
+            - Get
+            - Handle
+            - HandleFunc
+            - HandlerFunc.ServeHTTP
+            - Head
+            - Header.Add
+            - Header.Del
+            - Header.Get
+            - Header.Set
+            - Header.Values
+            - Header.Write
+            - Header.WriteSubset
+            - ListenAndServe
+            - ListenAndServeTLS
+            - NewRequest
+            - NewRequestWithContext
+            - NotFound
+            - ParseCookie
+            - ParseSetCookie
+            - ParseTime
+            - Post
+            - PostForm
+            - ProxyFromEnvironment
+            - ReadRequest
+            - ReadResponse
+            - Redirect
+            - Request.AddCookie
+            - Request.BasicAuth
+            - Request.Cookie
+            - Request.Cookies
+            - Request.CookiesNamed
+            - Request.FormFile
+            - Request.FormValue
+            - Request.MultipartReader
+            - Request.ParseForm
+            - Request.ParseMultipartForm
+            - Request.PostFormValue
+            - Request.Referer
+            - Request.SetBasicAuth
+            - Request.UserAgent
+            - Request.Write
+            - Request.WriteProxy
+            - Response.Cookies
+            - Response.Location
+            - Response.Write
+            - ResponseController.EnableFullDuplex
+            - ResponseController.Flush
+            - ResponseController.Hijack
+            - ResponseController.SetReadDeadline
+            - ResponseController.SetWriteDeadline
+            - Serve
+            - ServeContent
+            - ServeFile
+            - ServeFileFS
+            - ServeMux.Handle
+            - ServeMux.HandleFunc
+            - ServeMux.ServeHTTP
+            - ServeTLS
+            - Server.Close
+            - Server.ListenAndServe
+            - Server.ListenAndServeTLS
+            - Server.Serve
+            - Server.ServeTLS
+            - Server.SetKeepAlivesEnabled
+            - Server.Shutdown
+            - SetCookie
+            - Transport.CancelRequest
+            - Transport.Clone
+            - Transport.CloseIdleConnections
+            - Transport.NewClientConn
+            - Transport.RoundTrip
+            - body.Close
+            - body.Read
+            - bodyEOFSignal.Close
+            - bodyEOFSignal.Read
+            - bodyLocked.Read
+            - bufioFlushWriter.Write
+            - cancelTimerBody.Close
+            - cancelTimerBody.Read
+            - checkConnErrorWriter.Write
+            - chunkWriter.Write
+            - connReader.Read
+            - connectMethodKey.String
+            - expectContinueReader.Close
+            - expectContinueReader.Read
+            - extraHeader.Write
+            - fileHandler.ServeHTTP
+            - fileTransport.RoundTrip
+            - globalOptionsHandler.ServeHTTP
+            - gzipReader.Close
+            - gzipReader.Read
+            - http1ClientConn.Close
+            - http1ClientConn.RoundTrip
+            - http2ClientConn.Close
+            - http2ClientConn.Ping
+            - http2ClientConn.RoundTrip
+            - http2ClientConn.Shutdown
+            - http2ConnectionError.Error
+            - http2ErrCode.String
+            - http2FrameHeader.String
+            - http2FrameType.String
+            - http2FrameWriteRequest.String
+            - http2Framer.ReadFrame
+            - http2Framer.ReadFrameForHeader
+            - http2Framer.ReadFrameHeader
+            - http2Framer.WriteContinuation
+            - http2Framer.WriteData
+            - http2Framer.WriteDataPadded
+            - http2Framer.WriteGoAway
+            - http2Framer.WriteHeaders
+            - http2Framer.WritePing
+            - http2Framer.WritePriority
+            - http2Framer.WritePushPromise
+            - http2Framer.WriteRSTStream
+            - http2Framer.WriteRawFrame
+            - http2Framer.WriteSettings
+            - http2Framer.WriteSettingsAck
+            - http2Framer.WriteWindowUpdate
+            - http2GoAwayError.Error
+            - http2Server.ServeConn
+            - http2Setting.String
+            - http2SettingID.String
+            - http2SettingsFrame.ForeachSetting
+            - http2StreamError.Error
+            - http2Transport.CloseIdleConnections
+            - http2Transport.NewClientConn
+            - http2Transport.RoundTrip
+            - http2Transport.RoundTripOpt
+            - http2bufferedWriter.Flush
+            - http2bufferedWriter.Write
+            - http2bufferedWriterTimeoutWriter.Write
+            - http2chunkWriter.Write
+            - http2clientConnPool.GetClientConn
+            - http2connError.Error
+            - http2dataBuffer.Read
+            - http2duplicatePseudoHeaderError.Error
+            - http2gzipReader.Close
+            - http2gzipReader.Read
+            - http2headerFieldNameError.Error
+            - http2headerFieldValueError.Error
+            - http2netHTTPClientConn.Close
+            - http2netHTTPClientConn.RoundTrip
+            - http2noDialClientConnPool.GetClientConn
+            - http2noDialH2RoundTripper.NewClientConn
+            - http2noDialH2RoundTripper.RoundTrip
+            - http2pipe.Read
+            - http2priorityWriteSchedulerRFC7540.CloseStream
+            - http2priorityWriteSchedulerRFC7540.OpenStream
+            - http2priorityWriteSchedulerRFC9218.OpenStream
+            - http2pseudoHeaderError.Error
+            - http2responseWriter.Flush
+            - http2responseWriter.FlushError
+            - http2responseWriter.Push
+            - http2responseWriter.SetReadDeadline
+            - http2responseWriter.SetWriteDeadline
+            - http2responseWriter.Write
+            - http2responseWriter.WriteHeader
+            - http2responseWriter.WriteString
+            - http2roundRobinWriteScheduler.OpenStream
+            - http2serverConn.CloseConn
+            - http2serverConn.Flush
+            - http2stickyErrWriter.Write
+            - http2transportResponseBody.Close
+            - http2transportResponseBody.Read
+            - http2unencryptedTransport.RoundTrip
+            - http2writeData.String
+            - initALPNRequest.ServeHTTP
+            - loggingConn.Close
+            - loggingConn.Read
+            - loggingConn.Write
+            - maxBytesReader.Close
+            - maxBytesReader.Read
+            - onceCloseListener.Close
+            - persistConn.Read
+            - persistConnWriter.ReadFrom
+            - persistConnWriter.Write
+            - populateResponse.Write
+            - populateResponse.WriteHeader
+            - readTrackingBody.Close
+            - readTrackingBody.Read
+            - readWriteCloserBody.CloseWrite
+            - readWriteCloserBody.Read
+            - redirectHandler.ServeHTTP
+            - response.Flush
+            - response.FlushError
+            - response.Hijack
+            - response.ReadFrom
+            - response.Write
+            - response.WriteHeader
+            - response.WriteString
+            - serverHandler.ServeHTTP
+            - socksDialer.DialWithConn
+            - socksUsernamePassword.Authenticate
+            - stringWriter.WriteString
+            - timeoutHandler.ServeHTTP
+            - timeoutWriter.Write
+            - timeoutWriter.WriteHeader
+            - transportReadFromServerError.Error
+            - unencryptedHTTP2Request.ServeHTTP
+    - module: std
+      versions:
+        - introduced: 1.27.0-0
+        - fixed: 1.27.2
+      vulnerable_at: 1.27.1
+      packages:
+        - package: net/http/internal/http2
+          symbols:
+            - requestBody.Close
+            - requestBody.Read
+            - serverConn.closeStream
+            - serverConn.handlerDone
+            - serverConn.newWriterAndRequest
+            - serverConn.newWriterAndRequestNoBody
+            - serverConn.noteBodyRead
+            - serverConn.processHeaders
+            - serverConn.runHandler
+            - serverConn.scheduleHandler
+          derived_symbols:
+            - Server.ServeConn
+    - module: golang.org/x/net
+      versions:
+        - fixed: 0.60.0
+      vulnerable_at: 0.59.0
+      packages:
+        - package: golang.org/x/net/http2
+          symbols:
+            - requestBody.Close
+            - requestBody.Read
+            - serverConn.closeStream
+            - serverConn.handlerDone
+            - serverConn.newWriterAndRequest
+            - serverConn.newWriterAndRequestNoBody
+            - serverConn.noteBodyRead
+            - serverConn.processHeaders
+            - serverConn.runHandler
+            - serverConn.scheduleHandler
+          derived_symbols:
+            - ClientConn.Close
+            - ClientConn.Ping
+            - ClientConn.RoundTrip
+            - ClientConn.Shutdown
+            - ConfigureServer
+            - ConfigureTransport
+            - ConfigureTransports
+            - ConnectionError.Error
+            - ErrCode.String
+            - FrameHeader.String
+            - FrameType.String
+            - FrameWriteRequest.String
+            - Framer.ReadFrame
+            - Framer.ReadFrameForHeader
+            - Framer.ReadFrameHeader
+            - Framer.WriteContinuation
+            - Framer.WriteData
+            - Framer.WriteDataPadded
+            - Framer.WriteGoAway
+            - Framer.WriteHeaders
+            - Framer.WritePing
+            - Framer.WritePriority
+            - Framer.WritePriorityUpdate
+            - Framer.WritePushPromise
+            - Framer.WriteRSTStream
+            - Framer.WriteRawFrame
+            - Framer.WriteSettings
+            - Framer.WriteSettingsAck
+            - Framer.WriteWindowUpdate
+            - GoAwayError.Error
+            - ReadFrameHeader
+            - Server.ServeConn
+            - Setting.String
+            - SettingID.String
+            - SettingsFrame.ForeachSetting
+            - StreamError.Error
+            - Transport.CloseIdleConnections
+            - Transport.NewClientConn
+            - Transport.RoundTrip
+            - Transport.RoundTripOpt
+            - bufferedWriter.Flush
+            - bufferedWriter.Write
+            - bufferedWriterTimeoutWriter.Write
+            - chunkWriter.Write
+            - clientConnPool.GetClientConn
+            - connError.Error
+            - dataBuffer.Read
+            - duplicatePseudoHeaderError.Error
+            - gzipReader.Close
+            - gzipReader.Read
+            - headerFieldNameError.Error
+            - headerFieldValueError.Error
+            - netHTTPClientConn.Close
+            - netHTTPClientConn.RoundTrip
+            - noDialClientConnPool.GetClientConn
+            - noDialH2RoundTripper.NewClientConn
+            - noDialH2RoundTripper.RoundTrip
+            - pipe.Read
+            - priorityWriteSchedulerRFC7540.CloseStream
+            - priorityWriteSchedulerRFC7540.OpenStream
+            - priorityWriteSchedulerRFC9218.OpenStream
+            - pseudoHeaderError.Error
+            - responseWriter.Flush
+            - responseWriter.FlushError
+            - responseWriter.Push
+            - responseWriter.SetReadDeadline
+            - responseWriter.SetWriteDeadline
+            - responseWriter.Write
+            - responseWriter.WriteHeader
+            - responseWriter.WriteString
+            - roundRobinWriteScheduler.OpenStream
+            - serverConn.CloseConn
+            - serverConn.Flush
+            - stickyErrWriter.Write
+            - transportResponseBody.Close
+            - transportResponseBody.Read
+            - unencryptedTransport.RoundTrip
+            - writeData.String
+summary: Double flow control refund on HTTP/2 server streams in net/http
+description: |-
+    The HTTP/2 server can refund connection-level flow control twice for the same
+    data: Once when a client resets a stream (refunding data for any sent-but-unread
+    portion of the stream), and again when a request handler reads the buffered
+    data. A malicious client can exploit this to bypass the configured
+    connection-level flow control limit (MaxReceiveBufferPerConnection). Total
+    buffered data is still limited by the concurrent stream limit and stream-level
+    flow control.
+credits:
+    - Ali Sherif (https://www.linkedin.com/in/ali-sherif-13812b276/)
+references:
+    - fix: https://go.dev/cl/847187
+    - fix: https://go.dev/cl/847310
+    - report: https://go.dev/issue/81743
+    - web: https://groups.google.com/g/golang-announce/c/U2fTuyDJznI
+    - web: https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs
+cve_metadata:
+    id: CVE-2026-78663
+    cwe: 'CWE-675: Multiple Operations on Resource in Single-Operation Context'
+source:
+    id: go-security-team
+    created: 2026-10-08T00:00:00Z
+review_status: REVIEWED
diff --git a/data/reports/GO-2026-6613.yaml b/data/reports/GO-2026-6613.yaml
new file mode 100644
index 0000000..20bd0fa
--- /dev/null
+++ b/data/reports/GO-2026-6613.yaml
@@ -0,0 +1,186 @@
+id: GO-2026-6613
+modules:
+    - module: std
+      versions:
+        - fixed: 1.26.9
+        - introduced: 1.27.0-0
+        - fixed: 1.27.2
+      vulnerable_at: 1.27.1
+      packages:
+        - package: net/http
+          symbols:
+            - chunkWriter.writeHeader
+          derived_symbols:
+            - CanonicalHeaderKey
+            - Client.CloseIdleConnections
+            - Client.Do
+            - Client.Get
+            - Client.Head
+            - Client.Post
+            - Client.PostForm
+            - ClientConn.Close
+            - ClientConn.RoundTrip
+            - Cookie.String
+            - Cookie.Valid
+            - CrossOriginProtection.AddInsecureBypassPattern
+            - CrossOriginProtection.AddTrustedOrigin
+            - CrossOriginProtection.Check
+            - Dir.Open
+            - Error
+            - Get
+            - Handle
+            - HandleFunc
+            - HandlerFunc.ServeHTTP
+            - Head
+            - Header.Add
+            - Header.Del
+            - Header.Get
+            - Header.Set
+            - Header.Values
+            - Header.Write
+            - Header.WriteSubset
+            - ListenAndServe
+            - ListenAndServeTLS
+            - NewRequest
+            - NewRequestWithContext
+            - NotFound
+            - ParseCookie
+            - ParseSetCookie
+            - ParseTime
+            - Post
+            - PostForm
+            - ProxyFromEnvironment
+            - ReadRequest
+            - ReadResponse
+            - Redirect
+            - Request.AddCookie
+            - Request.BasicAuth
+            - Request.Cookie
+            - Request.Cookies
+            - Request.CookiesNamed
+            - Request.FormFile
+            - Request.FormValue
+            - Request.MultipartReader
+            - Request.ParseForm
+            - Request.ParseMultipartForm
+            - Request.PostFormValue
+            - Request.Referer
+            - Request.SetBasicAuth
+            - Request.UserAgent
+            - Request.Write
+            - Request.WriteProxy
+            - Response.Cookies
+            - Response.Location
+            - Response.Write
+            - ResponseController.EnableFullDuplex
+            - ResponseController.Flush
+            - ResponseController.Hijack
+            - ResponseController.SetReadDeadline
+            - ResponseController.SetWriteDeadline
+            - Serve
+            - ServeContent
+            - ServeFile
+            - ServeFileFS
+            - ServeMux.Handle
+            - ServeMux.HandleFunc
+            - ServeMux.ServeHTTP
+            - ServeTLS
+            - Server.Close
+            - Server.ListenAndServe
+            - Server.ListenAndServeTLS
+            - Server.Serve
+            - Server.ServeTLS
+            - Server.SetKeepAlivesEnabled
+            - Server.Shutdown
+            - SetCookie
+            - Transport.CancelRequest
+            - Transport.Clone
+            - Transport.CloseIdleConnections
+            - Transport.NewClientConn
+            - Transport.RoundTrip
+            - body.Close
+            - body.Read
+            - bodyEOFSignal.Close
+            - bodyEOFSignal.Read
+            - bodyLocked.Read
+            - bufioFlushWriter.Write
+            - cancelTimerBody.Close
+            - cancelTimerBody.Read
+            - checkConnErrorWriter.Write
+            - chunkWriter.Write
+            - connReader.Read
+            - connectMethodKey.String
+            - expectContinueReader.Close
+            - expectContinueReader.Read
+            - extraHeader.Write
+            - fileHandler.ServeHTTP
+            - fileTransport.RoundTrip
+            - globalOptionsHandler.ServeHTTP
+            - gzipReader.Close
+            - gzipReader.Read
+            - http1ClientConn.Close
+            - http1ClientConn.RoundTrip
+            - http2ClientConn.RoundTrip
+            - http2Handler.ServeHTTP
+            - http2ResponseWriter.Flush
+            - http2ResponseWriter.FlushError
+            - http2ResponseWriter.Push
+            - http2RoundTripper.RoundTrip
+            - http3ServerHandler.ServeHTTP
+            - initALPNRequest.ServeHTTP
+            - loggingConn.Close
+            - loggingConn.Read
+            - loggingConn.Write
+            - maxBytesReader.Close
+            - maxBytesReader.Read
+            - onceCloseListener.Close
+            - persistConn.Read
+            - persistConnWriter.ReadFrom
+            - persistConnWriter.Write
+            - populateResponse.Write
+            - populateResponse.WriteHeader
+            - readTrackingBody.Close
+            - readTrackingBody.Read
+            - readWriteCloserBody.CloseWrite
+            - readWriteCloserBody.Read
+            - redirectHandler.ServeHTTP
+            - response.Flush
+            - response.FlushError
+            - response.Hijack
+            - response.ReadFrom
+            - response.Write
+            - response.WriteHeader
+            - response.WriteString
+            - serverHandler.ServeHTTP
+            - socksDialer.DialWithConn
+            - socksUsernamePassword.Authenticate
+            - stringWriter.WriteString
+            - timeoutHandler.ServeHTTP
+            - timeoutWriter.Write
+            - timeoutWriter.WriteHeader
+            - transportReadFromServerError.Error
+            - unencryptedHTTP2Request.ServeHTTP
+summary: HTTP/1 server connection desynchronization after 2xx CONNECT response in net/http
+description: |-
+    When an HTTP server handler sends a 2xx response to an HTTP/1 CONNECT request
+    and returns without hijacking the connection, the server improperly continues
+    to read and serve requests from the connection. Since a 2xx response to an
+    HTTP/1 CONNECT converts the connection into a tunnel, the server should not
+    treat the connection as continuing to contain HTTP.
+
+    The impact of this misbehavior is mostly limited to potential request smuggling,
+    where an intermediate proxy considers the data on the connection to be tunneled
+    and the server considers it to be HTTP.
+credits:
+    - Jakub Ciolek (https://ciolek.dev)
+references:
+    - fix: https://go.dev/cl/847311
+    - report: https://go.dev/issue/81744
+    - web: https://groups.google.com/g/golang-announce/c/U2fTuyDJznI
+cve_metadata:
+    id: CVE-2026-94439
+    cwe: 'CWE-444: Inconsistent Interpretation of HTTP Requests (''HTTP Request/Response Smuggling'')'
+source:
+    id: go-security-team
+    created: 2026-10-08T00:00:00Z
+review_status: REVIEWED
diff --git a/data/reports/GO-2026-6617.yaml b/data/reports/GO-2026-6617.yaml
new file mode 100644
index 0000000..2df3088
--- /dev/null
+++ b/data/reports/GO-2026-6617.yaml
@@ -0,0 +1,409 @@
+id: GO-2026-6617
+modules:
+    - module: std
+      versions:
+        - fixed: 1.26.9
+      vulnerable_at: 1.26.8
+      packages:
+        - package: net/http
+          symbols:
+            - http2serverConn.processSetting
+            - http2serverConn.startFrameWrite
+          derived_symbols:
+            - CanonicalHeaderKey
+            - Client.CloseIdleConnections
+            - Client.Do
+            - Client.Get
+            - Client.Head
+            - Client.Post
+            - Client.PostForm
+            - ClientConn.Close
+            - ClientConn.RoundTrip
+            - Cookie.String
+            - Cookie.Valid
+            - CrossOriginProtection.AddInsecureBypassPattern
+            - CrossOriginProtection.AddTrustedOrigin
+            - CrossOriginProtection.Check
+            - Dir.Open
+            - Error
+            - Get
+            - Handle
+            - HandleFunc
+            - HandlerFunc.ServeHTTP
+            - Head
+            - Header.Add
+            - Header.Del
+            - Header.Get
+            - Header.Set
+            - Header.Values
+            - Header.Write
+            - Header.WriteSubset
+            - ListenAndServe
+            - ListenAndServeTLS
+            - NewRequest
+            - NewRequestWithContext
+            - NotFound
+            - ParseCookie
+            - ParseSetCookie
+            - ParseTime
+            - Post
+            - PostForm
+            - ProxyFromEnvironment
+            - ReadRequest
+            - ReadResponse
+            - Redirect
+            - Request.AddCookie
+            - Request.BasicAuth
+            - Request.Cookie
+            - Request.Cookies
+            - Request.CookiesNamed
+            - Request.FormFile
+            - Request.FormValue
+            - Request.MultipartReader
+            - Request.ParseForm
+            - Request.ParseMultipartForm
+            - Request.PostFormValue
+            - Request.Referer
+            - Request.SetBasicAuth
+            - Request.UserAgent
+            - Request.Write
+            - Request.WriteProxy
+            - Response.Cookies
+            - Response.Location
+            - Response.Write
+            - ResponseController.EnableFullDuplex
+            - ResponseController.Flush
+            - ResponseController.Hijack
+            - ResponseController.SetReadDeadline
+            - ResponseController.SetWriteDeadline
+            - Serve
+            - ServeContent
+            - ServeFile
+            - ServeFileFS
+            - ServeMux.Handle
+            - ServeMux.HandleFunc
+            - ServeMux.ServeHTTP
+            - ServeTLS
+            - Server.Close
+            - Server.ListenAndServe
+            - Server.ListenAndServeTLS
+            - Server.Serve
+            - Server.ServeTLS
+            - Server.SetKeepAlivesEnabled
+            - Server.Shutdown
+            - SetCookie
+            - Transport.CancelRequest
+            - Transport.Clone
+            - Transport.CloseIdleConnections
+            - Transport.NewClientConn
+            - Transport.RoundTrip
+            - body.Close
+            - body.Read
+            - bodyEOFSignal.Close
+            - bodyEOFSignal.Read
+            - bodyLocked.Read
+            - bufioFlushWriter.Write
+            - cancelTimerBody.Close
+            - cancelTimerBody.Read
+            - checkConnErrorWriter.Write
+            - chunkWriter.Write
+            - connReader.Read
+            - connectMethodKey.String
+            - expectContinueReader.Close
+            - expectContinueReader.Read
+            - extraHeader.Write
+            - fileHandler.ServeHTTP
+            - fileTransport.RoundTrip
+            - globalOptionsHandler.ServeHTTP
+            - gzipReader.Close
+            - gzipReader.Read
+            - http1ClientConn.Close
+            - http1ClientConn.RoundTrip
+            - http2ClientConn.Close
+            - http2ClientConn.Ping
+            - http2ClientConn.RoundTrip
+            - http2ClientConn.Shutdown
+            - http2ConnectionError.Error
+            - http2ErrCode.String
+            - http2FrameHeader.String
+            - http2FrameType.String
+            - http2FrameWriteRequest.String
+            - http2Framer.ReadFrame
+            - http2Framer.ReadFrameForHeader
+            - http2Framer.ReadFrameHeader
+            - http2Framer.WriteContinuation
+            - http2Framer.WriteData
+            - http2Framer.WriteDataPadded
+            - http2Framer.WriteGoAway
+            - http2Framer.WriteHeaders
+            - http2Framer.WritePing
+            - http2Framer.WritePriority
+            - http2Framer.WritePushPromise
+            - http2Framer.WriteRSTStream
+            - http2Framer.WriteRawFrame
+            - http2Framer.WriteSettings
+            - http2Framer.WriteSettingsAck
+            - http2Framer.WriteWindowUpdate
+            - http2GoAwayError.Error
+            - http2Server.ServeConn
+            - http2Setting.String
+            - http2SettingID.String
+            - http2SettingsFrame.ForeachSetting
+            - http2StreamError.Error
+            - http2Transport.CloseIdleConnections
+            - http2Transport.NewClientConn
+            - http2Transport.RoundTrip
+            - http2Transport.RoundTripOpt
+            - http2bufferedWriter.Flush
+            - http2bufferedWriter.Write
+            - http2bufferedWriterTimeoutWriter.Write
+            - http2chunkWriter.Write
+            - http2clientConnPool.GetClientConn
+            - http2connError.Error
+            - http2dataBuffer.Read
+            - http2duplicatePseudoHeaderError.Error
+            - http2gzipReader.Close
+            - http2gzipReader.Read
+            - http2headerFieldNameError.Error
+            - http2headerFieldValueError.Error
+            - http2netHTTPClientConn.Close
+            - http2netHTTPClientConn.RoundTrip
+            - http2noDialClientConnPool.GetClientConn
+            - http2noDialH2RoundTripper.NewClientConn
+            - http2noDialH2RoundTripper.RoundTrip
+            - http2pipe.Read
+            - http2priorityWriteSchedulerRFC7540.CloseStream
+            - http2priorityWriteSchedulerRFC7540.OpenStream
+            - http2priorityWriteSchedulerRFC9218.OpenStream
+            - http2pseudoHeaderError.Error
+            - http2requestBody.Close
+            - http2requestBody.Read
+            - http2responseWriter.Flush
+            - http2responseWriter.FlushError
+            - http2responseWriter.Push
+            - http2responseWriter.SetReadDeadline
+            - http2responseWriter.SetWriteDeadline
+            - http2responseWriter.Write
+            - http2responseWriter.WriteHeader
+            - http2responseWriter.WriteString
+            - http2roundRobinWriteScheduler.OpenStream
+            - http2serverConn.CloseConn
+            - http2serverConn.Flush
+            - http2stickyErrWriter.Write
+            - http2transportResponseBody.Close
+            - http2transportResponseBody.Read
+            - http2unencryptedTransport.RoundTrip
+            - http2writeData.String
+            - initALPNRequest.ServeHTTP
+            - loggingConn.Close
+            - loggingConn.Read
+            - loggingConn.Write
+            - maxBytesReader.Close
+            - maxBytesReader.Read
+            - onceCloseListener.Close
+            - persistConn.Read
+            - persistConnWriter.ReadFrom
+            - persistConnWriter.Write
+            - populateResponse.Write
+            - populateResponse.WriteHeader
+            - readTrackingBody.Close
+            - readTrackingBody.Read
+            - readWriteCloserBody.CloseWrite
+            - readWriteCloserBody.Read
+            - redirectHandler.ServeHTTP
+            - response.Flush
+            - response.FlushError
+            - response.Hijack
+            - response.ReadFrom
+            - response.Write
+            - response.WriteHeader
+            - response.WriteString
+            - serverHandler.ServeHTTP
+            - socksDialer.DialWithConn
+            - socksUsernamePassword.Authenticate
+            - stringWriter.WriteString
+            - timeoutHandler.ServeHTTP
+            - timeoutWriter.Write
+            - timeoutWriter.WriteHeader
+            - transportReadFromServerError.Error
+            - unencryptedHTTP2Request.ServeHTTP
+    - module: std
+      versions:
+        - introduced: 1.27.0-0
+        - fixed: 1.27.2
+      vulnerable_at: 1.27.1
+      packages:
+        - package: net/http/internal/http2
+          symbols:
+            - serverConn.processSetting
+            - serverConn.startFrameWrite
+          derived_symbols:
+            - ClientConn.Close
+            - ClientConn.Ping
+            - ClientConn.RoundTrip
+            - ClientConn.Shutdown
+            - Framer.ReadFrame
+            - Framer.ReadFrameForHeader
+            - Framer.ReadFrameHeader
+            - Framer.WriteContinuation
+            - Framer.WriteData
+            - Framer.WriteDataPadded
+            - Framer.WriteGoAway
+            - Framer.WriteHeaders
+            - Framer.WritePing
+            - Framer.WritePriority
+            - Framer.WritePriorityUpdate
+            - Framer.WritePushPromise
+            - Framer.WriteRSTStream
+            - Framer.WriteRawFrame
+            - Framer.WriteSettings
+            - Framer.WriteSettingsAck
+            - Framer.WriteWindowUpdate
+            - NetHTTPClientConn.Close
+            - NetHTTPClientConn.Ping
+            - NetHTTPClientConn.RoundTrip
+            - ReadFrameHeader
+            - Server.GracefulShutdown
+            - Server.ServeConn
+            - SettingsFrame.ForeachSetting
+            - Transport.AddConn
+            - Transport.CloseIdleConnections
+            - Transport.NewClientConn
+            - Transport.RoundTrip
+            - Transport.RoundTripOpt
+            - bufferedWriter.Flush
+            - bufferedWriter.Write
+            - bufferedWriterTimeoutWriter.Write
+            - chunkWriter.Write
+            - clientConnPool.GetClientConn
+            - gzipReader.Close
+            - gzipReader.Read
+            - noDialClientConnPool.GetClientConn
+            - requestBody.Close
+            - responseWriter.Flush
+            - responseWriter.FlushError
+            - responseWriter.Push
+            - responseWriter.Write
+            - responseWriter.WriteHeader
+            - responseWriter.WriteString
+            - serve400Handler.ServeHTTP
+            - serverConn.Flush
+            - stickyErrWriter.Write
+            - transportResponseBody.Close
+            - transportResponseBody.Read
+    - module: golang.org/x/net
+      versions:
+        - fixed: 0.60.0
+      vulnerable_at: 0.59.0
+      packages:
+        - package: golang.org/x/net/http2
+          symbols:
+            - serverConn.processSetting
+            - serverConn.startFrameWrite
+          derived_symbols:
+            - ClientConn.Close
+            - ClientConn.Ping
+            - ClientConn.RoundTrip
+            - ClientConn.Shutdown
+            - ConfigureServer
+            - ConfigureTransport
+            - ConfigureTransports
+            - ConnectionError.Error
+            - ErrCode.String
+            - FrameHeader.String
+            - FrameType.String
+            - FrameWriteRequest.String
+            - Framer.ReadFrame
+            - Framer.ReadFrameForHeader
+            - Framer.ReadFrameHeader
+            - Framer.WriteContinuation
+            - Framer.WriteData
+            - Framer.WriteDataPadded
+            - Framer.WriteGoAway
+            - Framer.WriteHeaders
+            - Framer.WritePing
+            - Framer.WritePriority
+            - Framer.WritePriorityUpdate
+            - Framer.WritePushPromise
+            - Framer.WriteRSTStream
+            - Framer.WriteRawFrame
+            - Framer.WriteSettings
+            - Framer.WriteSettingsAck
+            - Framer.WriteWindowUpdate
+            - GoAwayError.Error
+            - ReadFrameHeader
+            - Server.ServeConn
+            - Setting.String
+            - SettingID.String
+            - SettingsFrame.ForeachSetting
+            - StreamError.Error
+            - Transport.CloseIdleConnections
+            - Transport.NewClientConn
+            - Transport.RoundTrip
+            - Transport.RoundTripOpt
+            - bufferedWriter.Flush
+            - bufferedWriter.Write
+            - bufferedWriterTimeoutWriter.Write
+            - chunkWriter.Write
+            - clientConnPool.GetClientConn
+            - connError.Error
+            - dataBuffer.Read
+            - duplicatePseudoHeaderError.Error
+            - gzipReader.Close
+            - gzipReader.Read
+            - headerFieldNameError.Error
+            - headerFieldValueError.Error
+            - netHTTPClientConn.Close
+            - netHTTPClientConn.RoundTrip
+            - noDialClientConnPool.GetClientConn
+            - noDialH2RoundTripper.NewClientConn
+            - noDialH2RoundTripper.RoundTrip
+            - pipe.Read
+            - priorityWriteSchedulerRFC7540.CloseStream
+            - priorityWriteSchedulerRFC7540.OpenStream
+            - priorityWriteSchedulerRFC9218.OpenStream
+            - pseudoHeaderError.Error
+            - requestBody.Close
+            - requestBody.Read
+            - responseWriter.Flush
+            - responseWriter.FlushError
+            - responseWriter.Push
+            - responseWriter.SetReadDeadline
+            - responseWriter.SetWriteDeadline
+            - responseWriter.Write
+            - responseWriter.WriteHeader
+            - responseWriter.WriteString
+            - roundRobinWriteScheduler.OpenStream
+            - serverConn.CloseConn
+            - serverConn.Flush
+            - stickyErrWriter.Write
+            - transportResponseBody.Close
+            - transportResponseBody.Read
+            - unencryptedTransport.RoundTrip
+            - writeData.String
+summary: HTTP/2 server crash due to HPACK encoder race in net/http
+description: |-
+    HTTP/2 servers could end up crashing due to inadvertently
+    modifying its HPACK encoder concurrently. This happens because the
+    server modifies the HPACK encoder from two goroutines without
+    synchronization: one uses the encoder to encode a HEADERS frame as part
+    of a response sent to a client and the other modifies the encoder's
+    table size when handling a SETTINGS frame containing
+    SETTINGS_HEADER_TABLE_SIZE that a client sends. A malicious client can
+    repeatedly send a request while changing the header table size to crash
+    the server.
+credits:
+    - RyotaK (https://ryotak.net) of GMO Flatt Security Inc.
+references:
+    - fix: https://go.dev/cl/847188
+    - fix: https://go.dev/cl/847313
+    - report: https://go.dev/issue/81867
+    - web: https://groups.google.com/g/golang-announce/c/U2fTuyDJznI
+    - web: https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs
+cve_metadata:
+    id: CVE-2026-97032
+    cwe: 'CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization (''Race Condition'')'
+source:
+    id: go-security-team
+    created: 2026-10-08T00:00:00Z
+review_status: REVIEWED