Skip to content

Commit b8756f6

Browse files
jitsu-netgopherbot
authored andcommitted
data/reports: add 92 reports
- data/reports/GO-2026-6097.yaml - data/reports/GO-2026-6098.yaml - data/reports/GO-2026-6099.yaml - data/reports/GO-2026-6100.yaml - data/reports/GO-2026-6101.yaml - data/reports/GO-2026-6102.yaml - data/reports/GO-2026-6103.yaml - data/reports/GO-2026-6104.yaml - data/reports/GO-2026-6105.yaml - data/reports/GO-2026-6106.yaml - data/reports/GO-2026-6108.yaml - data/reports/GO-2026-6109.yaml - data/reports/GO-2026-6110.yaml - data/reports/GO-2026-6111.yaml - data/reports/GO-2026-6113.yaml - data/reports/GO-2026-6117.yaml - data/reports/GO-2026-6118.yaml - data/reports/GO-2026-6119.yaml - data/reports/GO-2026-6120.yaml - data/reports/GO-2026-6121.yaml - data/reports/GO-2026-6122.yaml - data/reports/GO-2026-6123.yaml - data/reports/GO-2026-6124.yaml - data/reports/GO-2026-6125.yaml - data/reports/GO-2026-6126.yaml - data/reports/GO-2026-6127.yaml - data/reports/GO-2026-6128.yaml - data/reports/GO-2026-6129.yaml - data/reports/GO-2026-6130.yaml - data/reports/GO-2026-6131.yaml - data/reports/GO-2026-6132.yaml - data/reports/GO-2026-6133.yaml - data/reports/GO-2026-6134.yaml - data/reports/GO-2026-6135.yaml - data/reports/GO-2026-6136.yaml - data/reports/GO-2026-6137.yaml - data/reports/GO-2026-6140.yaml - data/reports/GO-2026-6141.yaml - data/reports/GO-2026-6142.yaml - data/reports/GO-2026-6143.yaml - data/reports/GO-2026-6144.yaml - data/reports/GO-2026-6145.yaml - data/reports/GO-2026-6146.yaml - data/reports/GO-2026-6147.yaml - data/reports/GO-2026-6148.yaml - data/reports/GO-2026-6151.yaml - data/reports/GO-2026-6152.yaml - data/reports/GO-2026-6153.yaml - data/reports/GO-2026-6154.yaml - data/reports/GO-2026-6155.yaml - data/reports/GO-2026-6156.yaml - data/reports/GO-2026-6157.yaml - data/reports/GO-2026-6158.yaml - data/reports/GO-2026-6159.yaml - data/reports/GO-2026-6160.yaml - data/reports/GO-2026-6161.yaml - data/reports/GO-2026-6162.yaml - data/reports/GO-2026-6164.yaml - data/reports/GO-2026-6192.yaml - data/reports/GO-2026-6198.yaml - data/reports/GO-2026-6201.yaml - data/reports/GO-2026-6202.yaml - data/reports/GO-2026-6203.yaml - data/reports/GO-2026-6204.yaml - data/reports/GO-2026-6205.yaml - data/reports/GO-2026-6207.yaml - data/reports/GO-2026-6208.yaml - data/reports/GO-2026-6209.yaml - data/reports/GO-2026-6211.yaml - data/reports/GO-2026-6212.yaml - data/reports/GO-2026-6219.yaml - data/reports/GO-2026-6220.yaml - data/reports/GO-2026-6221.yaml - data/reports/GO-2026-6223.yaml - data/reports/GO-2026-6224.yaml - data/reports/GO-2026-6227.yaml - data/reports/GO-2026-6228.yaml - data/reports/GO-2026-6229.yaml - data/reports/GO-2026-6230.yaml - data/reports/GO-2026-6231.yaml - data/reports/GO-2026-6232.yaml - data/reports/GO-2026-6233.yaml - data/reports/GO-2026-6240.yaml - data/reports/GO-2026-6241.yaml - data/reports/GO-2026-6242.yaml - data/reports/GO-2026-6243.yaml - data/reports/GO-2026-6244.yaml - data/reports/GO-2026-6245.yaml - data/reports/GO-2026-6246.yaml - data/reports/GO-2026-6247.yaml - data/reports/GO-2026-6248.yaml - data/reports/GO-2026-6249.yaml Fixes #6097 Fixes #6098 Fixes #6099 Fixes #6100 Fixes #6101 Fixes #6102 Fixes #6103 Fixes #6104 Fixes #6105 Fixes #6106 Fixes #6108 Fixes #6109 Fixes #6110 Fixes #6111 Fixes #6113 Fixes #6117 Fixes #6118 Fixes #6119 Fixes #6120 Fixes #6121 Fixes #6122 Fixes #6123 Fixes #6124 Fixes #6125 Fixes #6126 Fixes #6127 Fixes #6128 Fixes #6129 Fixes #6130 Fixes #6131 Fixes #6132 Fixes #6133 Fixes #6134 Fixes #6135 Fixes #6136 Fixes #6137 Fixes #6140 Fixes #6141 Fixes #6142 Fixes #6143 Fixes #6144 Fixes #6145 Fixes #6146 Fixes #6147 Fixes #6148 Fixes #6151 Fixes #6152 Fixes #6153 Fixes #6154 Fixes #6155 Fixes #6156 Fixes #6157 Fixes #6158 Fixes #6159 Fixes #6160 Fixes #6161 Fixes #6162 Fixes #6164 Fixes #6192 Fixes #6198 Fixes #6201 Fixes #6202 Fixes #6203 Fixes #6204 Fixes #6205 Fixes #6207 Fixes #6208 Fixes #6209 Fixes #6211 Fixes #6212 Fixes #6219 Fixes #6220 Fixes #6221 Fixes #6223 Fixes #6224 Fixes #6227 Fixes #6228 Fixes #6229 Fixes #6230 Fixes #6231 Fixes #6232 Fixes #6233 Fixes #6240 Fixes #6241 Fixes #6242 Fixes #6243 Fixes #6244 Fixes #6245 Fixes #6246 Fixes #6247 Fixes #6248 Fixes #6249 Change-Id: Ib272a4454aab41304af15e36c23bba5b6a207968 Reviewed-on: https://go-review.googlesource.com/c/vulndb/+/816760 SLSA-Policy-Verified: SLSA Policy Verification Service <devtools-gerritcodereview-exitgate@google.com> LUCI-TryBot-Result: golang-scoped@luci-project-accounts.iam.gserviceaccount.com <golang-scoped@luci-project-accounts.iam.gserviceaccount.com> Auto-Submit: Ian Alexander <jitsu@google.com> Reviewed-by: Ethan Lee <ethanalee@google.com>
1 parent 8fa0f30 commit b8756f6

184 files changed

Lines changed: 8638 additions & 0 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

data/osv/GO-2026-6097.json

Lines changed: 86 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,86 @@
1+
{
2+
"schema_version": "1.3.1",
3+
"id": "GO-2026-6097",
4+
"modified": "0001-01-01T00:00:00Z",
5+
"published": "0001-01-01T00:00:00Z",
6+
"aliases": [
7+
"CVE-2026-55495",
8+
"GHSA-49h3-cwhj-4737"
9+
],
10+
"summary": "Cloudreve: Path Traversal in WOPI PUT_RELATIVE Allows Arbitrary File Creation in Owner Account in github.com/cloudreve/Cloudreve",
11+
"details": "Cloudreve: Path Traversal in WOPI PUT_RELATIVE Allows Arbitrary File Creation in Owner Account in github.com/cloudreve/Cloudreve",
12+
"affected": [
13+
{
14+
"package": {
15+
"name": "github.com/cloudreve/Cloudreve",
16+
"ecosystem": "Go"
17+
},
18+
"ranges": [
19+
{
20+
"type": "SEMVER",
21+
"events": [
22+
{
23+
"introduced": "0"
24+
}
25+
]
26+
}
27+
],
28+
"ecosystem_specific": {}
29+
},
30+
{
31+
"package": {
32+
"name": "github.com/cloudreve/Cloudreve/v3",
33+
"ecosystem": "Go"
34+
},
35+
"ranges": [
36+
{
37+
"type": "SEMVER",
38+
"events": [
39+
{
40+
"introduced": "0"
41+
}
42+
]
43+
}
44+
],
45+
"ecosystem_specific": {}
46+
},
47+
{
48+
"package": {
49+
"name": "github.com/cloudreve/Cloudreve/v4",
50+
"ecosystem": "Go"
51+
},
52+
"ranges": [
53+
{
54+
"type": "SEMVER",
55+
"events": [
56+
{
57+
"introduced": "0"
58+
},
59+
{
60+
"fixed": "4.0.0-20260613023150-7968e50429ef"
61+
}
62+
]
63+
}
64+
],
65+
"ecosystem_specific": {}
66+
}
67+
],
68+
"references": [
69+
{
70+
"type": "ADVISORY",
71+
"url": "https://github.com/cloudreve/cloudreve/security/advisories/GHSA-49h3-cwhj-4737"
72+
},
73+
{
74+
"type": "WEB",
75+
"url": "https://github.com/cloudreve/cloudreve/commit/7968e50429efab40ffa8f57fecdfbd5a73d23630"
76+
},
77+
{
78+
"type": "WEB",
79+
"url": "https://github.com/cloudreve/cloudreve/releases/tag/4.17.0"
80+
}
81+
],
82+
"database_specific": {
83+
"url": "https://pkg.go.dev/vuln/GO-2026-6097",
84+
"review_status": "UNREVIEWED"
85+
}
86+
}

data/osv/GO-2026-6098.json

Lines changed: 86 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,86 @@
1+
{
2+
"schema_version": "1.3.1",
3+
"id": "GO-2026-6098",
4+
"modified": "0001-01-01T00:00:00Z",
5+
"published": "0001-01-01T00:00:00Z",
6+
"aliases": [
7+
"CVE-2026-55496",
8+
"GHSA-8r7f-r8hj-r3rv"
9+
],
10+
"summary": "Cloudreve: Information Exposure in `GET /api/v4/user/search`: `SearchActive` omits the active-status predicate, leaking inactive/banned account emails in github.com/cloudreve/Cloudreve",
11+
"details": "Cloudreve: Information Exposure in `GET /api/v4/user/search`: `SearchActive` omits the active-status predicate, leaking inactive/banned account emails in github.com/cloudreve/Cloudreve",
12+
"affected": [
13+
{
14+
"package": {
15+
"name": "github.com/cloudreve/Cloudreve",
16+
"ecosystem": "Go"
17+
},
18+
"ranges": [
19+
{
20+
"type": "SEMVER",
21+
"events": [
22+
{
23+
"introduced": "0"
24+
}
25+
]
26+
}
27+
],
28+
"ecosystem_specific": {}
29+
},
30+
{
31+
"package": {
32+
"name": "github.com/cloudreve/Cloudreve/v3",
33+
"ecosystem": "Go"
34+
},
35+
"ranges": [
36+
{
37+
"type": "SEMVER",
38+
"events": [
39+
{
40+
"introduced": "0"
41+
}
42+
]
43+
}
44+
],
45+
"ecosystem_specific": {}
46+
},
47+
{
48+
"package": {
49+
"name": "github.com/cloudreve/Cloudreve/v4",
50+
"ecosystem": "Go"
51+
},
52+
"ranges": [
53+
{
54+
"type": "SEMVER",
55+
"events": [
56+
{
57+
"introduced": "0"
58+
},
59+
{
60+
"fixed": "4.0.0-20260613023921-7e1289d55279"
61+
}
62+
]
63+
}
64+
],
65+
"ecosystem_specific": {}
66+
}
67+
],
68+
"references": [
69+
{
70+
"type": "ADVISORY",
71+
"url": "https://github.com/cloudreve/cloudreve/security/advisories/GHSA-8r7f-r8hj-r3rv"
72+
},
73+
{
74+
"type": "WEB",
75+
"url": "https://github.com/cloudreve/cloudreve/commit/7e1289d552794bdbeb551be78456115c87dcb3da"
76+
},
77+
{
78+
"type": "WEB",
79+
"url": "https://github.com/cloudreve/cloudreve/releases/tag/4.17.0"
80+
}
81+
],
82+
"database_specific": {
83+
"url": "https://pkg.go.dev/vuln/GO-2026-6098",
84+
"review_status": "UNREVIEWED"
85+
}
86+
}

data/osv/GO-2026-6099.json

Lines changed: 56 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,56 @@
1+
{
2+
"schema_version": "1.3.1",
3+
"id": "GO-2026-6099",
4+
"modified": "0001-01-01T00:00:00Z",
5+
"published": "0001-01-01T00:00:00Z",
6+
"aliases": [
7+
"CVE-2026-57497",
8+
"GHSA-g35j-m5xg-vh3q"
9+
],
10+
"summary": "webtransport-go: Memory Exhaustion Attack due to Buffering of Unknown Capsules in github.com/quic-go/webtransport-go",
11+
"details": "webtransport-go: Memory Exhaustion Attack due to Buffering of Unknown Capsules in github.com/quic-go/webtransport-go",
12+
"affected": [
13+
{
14+
"package": {
15+
"name": "github.com/quic-go/webtransport-go",
16+
"ecosystem": "Go"
17+
},
18+
"ranges": [
19+
{
20+
"type": "SEMVER",
21+
"events": [
22+
{
23+
"introduced": "0"
24+
},
25+
{
26+
"fixed": "0.11.1"
27+
}
28+
]
29+
}
30+
],
31+
"ecosystem_specific": {}
32+
}
33+
],
34+
"references": [
35+
{
36+
"type": "ADVISORY",
37+
"url": "https://github.com/quic-go/webtransport-go/security/advisories/GHSA-g35j-m5xg-vh3q"
38+
},
39+
{
40+
"type": "FIX",
41+
"url": "https://github.com/quic-go/webtransport-go/commit/3aecd11736579530ff067651c30a543eb0b4b8c4"
42+
},
43+
{
44+
"type": "FIX",
45+
"url": "https://github.com/quic-go/webtransport-go/pull/290"
46+
},
47+
{
48+
"type": "WEB",
49+
"url": "https://github.com/quic-go/webtransport-go/releases/tag/v0.11.1"
50+
}
51+
],
52+
"database_specific": {
53+
"url": "https://pkg.go.dev/vuln/GO-2026-6099",
54+
"review_status": "UNREVIEWED"
55+
}
56+
}

data/osv/GO-2026-6100.json

Lines changed: 86 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,86 @@
1+
{
2+
"schema_version": "1.3.1",
3+
"id": "GO-2026-6100",
4+
"modified": "0001-01-01T00:00:00Z",
5+
"published": "0001-01-01T00:00:00Z",
6+
"aliases": [
7+
"CVE-2026-55497",
8+
"GHSA-g9j2-8w95-3vwv"
9+
],
10+
"summary": "Cloudreve: Denial of Service - Image decompression / pixel bomb in thumbnail \u0026 avatar decoding crashes the server in github.com/cloudreve/Cloudreve",
11+
"details": "Cloudreve: Denial of Service - Image decompression / pixel bomb in thumbnail \u0026 avatar decoding crashes the server in github.com/cloudreve/Cloudreve",
12+
"affected": [
13+
{
14+
"package": {
15+
"name": "github.com/cloudreve/Cloudreve",
16+
"ecosystem": "Go"
17+
},
18+
"ranges": [
19+
{
20+
"type": "SEMVER",
21+
"events": [
22+
{
23+
"introduced": "0"
24+
}
25+
]
26+
}
27+
],
28+
"ecosystem_specific": {}
29+
},
30+
{
31+
"package": {
32+
"name": "github.com/cloudreve/Cloudreve/v3",
33+
"ecosystem": "Go"
34+
},
35+
"ranges": [
36+
{
37+
"type": "SEMVER",
38+
"events": [
39+
{
40+
"introduced": "0"
41+
}
42+
]
43+
}
44+
],
45+
"ecosystem_specific": {}
46+
},
47+
{
48+
"package": {
49+
"name": "github.com/cloudreve/Cloudreve/v4",
50+
"ecosystem": "Go"
51+
},
52+
"ranges": [
53+
{
54+
"type": "SEMVER",
55+
"events": [
56+
{
57+
"introduced": "0"
58+
},
59+
{
60+
"fixed": "4.0.0-20260613024411-3607f79bb44c"
61+
}
62+
]
63+
}
64+
],
65+
"ecosystem_specific": {}
66+
}
67+
],
68+
"references": [
69+
{
70+
"type": "ADVISORY",
71+
"url": "https://github.com/cloudreve/cloudreve/security/advisories/GHSA-g9j2-8w95-3vwv"
72+
},
73+
{
74+
"type": "WEB",
75+
"url": "https://github.com/cloudreve/cloudreve/commit/3607f79bb44c35d0be4fa8b6e24c0502b51415a9"
76+
},
77+
{
78+
"type": "WEB",
79+
"url": "https://github.com/cloudreve/cloudreve/releases/tag/4.17.0"
80+
}
81+
],
82+
"database_specific": {
83+
"url": "https://pkg.go.dev/vuln/GO-2026-6100",
84+
"review_status": "UNREVIEWED"
85+
}
86+
}

0 commit comments

Comments
 (0)