Skip to content

Commit 3d89fef

Browse files
committed
data/reports: add 15 reports
- data/reports/GO-2025-4133.yaml - data/reports/GO-2025-4138.yaml - data/reports/GO-2025-4139.yaml - data/reports/GO-2025-4146.yaml - data/reports/GO-2025-4147.yaml - data/reports/GO-2025-4149.yaml - data/reports/GO-2025-4150.yaml - data/reports/GO-2025-4151.yaml - data/reports/GO-2025-4152.yaml - data/reports/GO-2025-4153.yaml - data/reports/GO-2025-4156.yaml - data/reports/GO-2025-4157.yaml - data/reports/GO-2025-4158.yaml - data/reports/GO-2025-4159.yaml - data/reports/GO-2025-4160.yaml Fixes #4133 Fixes #4138 Fixes #4139 Fixes #4146 Fixes #4147 Fixes #4149 Fixes #4150 Fixes #4151 Fixes #4152 Fixes #4153 Fixes #4156 Fixes #4157 Fixes #4158 Fixes #4159 Fixes #4160 Change-Id: I1d079723dbf4583ea3c0bbc2ac2fb3330a304bce Reviewed-on: https://go-review.googlesource.com/c/vulndb/+/723981 Reviewed-by: Nicholas Husin <[email protected]> LUCI-TryBot-Result: Go LUCI <[email protected]> Reviewed-by: Ethan Lee <[email protected]>
1 parent d02edb6 commit 3d89fef

30 files changed

+1416
-0
lines changed

data/osv/GO-2025-4133.json

Lines changed: 143 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,143 @@
1+
{
2+
"schema_version": "1.3.1",
3+
"id": "GO-2025-4133",
4+
"modified": "0001-01-01T00:00:00Z",
5+
"published": "0001-01-01T00:00:00Z",
6+
"aliases": [
7+
"CVE-2025-55074",
8+
"GHSA-9hh7-6558-qfp2"
9+
],
10+
"summary": "Mattermost allows other users to determine when users had read channels via channel member objects in github.com/mattermost/mattermost-server",
11+
"details": "Mattermost allows other users to determine when users had read channels via channel member objects in github.com/mattermost/mattermost-server.\n\nNOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.\n\n(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)\n\nThe additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.0.0-20250905150616-ba86dfc5876b6.",
12+
"affected": [
13+
{
14+
"package": {
15+
"name": "github.com/mattermost/mattermost-server",
16+
"ecosystem": "Go"
17+
},
18+
"ranges": [
19+
{
20+
"type": "SEMVER",
21+
"events": [
22+
{
23+
"introduced": "10.5.0+incompatible"
24+
},
25+
{
26+
"fixed": "10.5.12+incompatible"
27+
},
28+
{
29+
"introduced": "10.11.0+incompatible"
30+
},
31+
{
32+
"fixed": "10.11.4+incompatible"
33+
}
34+
]
35+
}
36+
],
37+
"ecosystem_specific": {}
38+
},
39+
{
40+
"package": {
41+
"name": "github.com/mattermost/mattermost-server/v5",
42+
"ecosystem": "Go"
43+
},
44+
"ranges": [
45+
{
46+
"type": "SEMVER",
47+
"events": [
48+
{
49+
"introduced": "0"
50+
}
51+
]
52+
}
53+
],
54+
"ecosystem_specific": {}
55+
},
56+
{
57+
"package": {
58+
"name": "github.com/mattermost/mattermost-server/v6",
59+
"ecosystem": "Go"
60+
},
61+
"ranges": [
62+
{
63+
"type": "SEMVER",
64+
"events": [
65+
{
66+
"introduced": "0"
67+
}
68+
]
69+
}
70+
],
71+
"ecosystem_specific": {}
72+
},
73+
{
74+
"package": {
75+
"name": "github.com/mattermost/mattermost/server/v8",
76+
"ecosystem": "Go"
77+
},
78+
"ranges": [
79+
{
80+
"type": "SEMVER",
81+
"events": [
82+
{
83+
"introduced": "0"
84+
}
85+
]
86+
}
87+
],
88+
"ecosystem_specific": {
89+
"custom_ranges": [
90+
{
91+
"type": "ECOSYSTEM",
92+
"events": [
93+
{
94+
"introduced": "0"
95+
},
96+
{
97+
"fixed": "8.0.0-20250905150616-ba86dfc5876b6"
98+
}
99+
]
100+
}
101+
]
102+
}
103+
}
104+
],
105+
"references": [
106+
{
107+
"type": "ADVISORY",
108+
"url": "https://github.com/advisories/GHSA-9hh7-6558-qfp2"
109+
},
110+
{
111+
"type": "ADVISORY",
112+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-55074"
113+
},
114+
{
115+
"type": "WEB",
116+
"url": "https://github.com/mattermost/mattermost/commit/98acefe911dd9de7edf47a7d825dd99f53141a52"
117+
},
118+
{
119+
"type": "WEB",
120+
"url": "https://github.com/mattermost/mattermost/commit/ba86dfc5876b354b9d3c20ff45c08ca6f8426149"
121+
},
122+
{
123+
"type": "WEB",
124+
"url": "https://github.com/mattermost/mattermost/commit/d72d437f1567ba0b639b6e4fd73bab06c51baab5"
125+
},
126+
{
127+
"type": "WEB",
128+
"url": "https://github.com/mattermost/mattermost/pull/33835"
129+
},
130+
{
131+
"type": "WEB",
132+
"url": "https://github.com/mattermost/mattermost/pull/33905"
133+
},
134+
{
135+
"type": "WEB",
136+
"url": "https://mattermost.com/security-updates"
137+
}
138+
],
139+
"database_specific": {
140+
"url": "https://pkg.go.dev/vuln/GO-2025-4133",
141+
"review_status": "UNREVIEWED"
142+
}
143+
}

data/osv/GO-2025-4138.json

Lines changed: 52 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,52 @@
1+
{
2+
"schema_version": "1.3.1",
3+
"id": "GO-2025-4138",
4+
"modified": "0001-01-01T00:00:00Z",
5+
"published": "0001-01-01T00:00:00Z",
6+
"aliases": [
7+
"CVE-2025-65025",
8+
"GHSA-h3mw-4f23-gwpw"
9+
],
10+
"summary": "esm.sh CDN service has arbitrary file write via tarslip in github.com/esm-dev/esm.sh",
11+
"details": "esm.sh CDN service has arbitrary file write via tarslip in github.com/esm-dev/esm.sh",
12+
"affected": [
13+
{
14+
"package": {
15+
"name": "github.com/esm-dev/esm.sh",
16+
"ecosystem": "Go"
17+
},
18+
"ranges": [
19+
{
20+
"type": "SEMVER",
21+
"events": [
22+
{
23+
"introduced": "0"
24+
},
25+
{
26+
"fixed": "0.0.0-20251117232647-9d77b88c3207"
27+
}
28+
]
29+
}
30+
],
31+
"ecosystem_specific": {}
32+
}
33+
],
34+
"references": [
35+
{
36+
"type": "ADVISORY",
37+
"url": "https://github.com/esm-dev/esm.sh/security/advisories/GHSA-h3mw-4f23-gwpw"
38+
},
39+
{
40+
"type": "ADVISORY",
41+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-65025"
42+
},
43+
{
44+
"type": "FIX",
45+
"url": "https://github.com/esm-dev/esm.sh/commit/9d77b88c320733ff6689d938d85d246a3af9af16"
46+
}
47+
],
48+
"database_specific": {
49+
"url": "https://pkg.go.dev/vuln/GO-2025-4138",
50+
"review_status": "UNREVIEWED"
51+
}
52+
}

data/osv/GO-2025-4139.json

Lines changed: 52 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,52 @@
1+
{
2+
"schema_version": "1.3.1",
3+
"id": "GO-2025-4139",
4+
"modified": "0001-01-01T00:00:00Z",
5+
"published": "0001-01-01T00:00:00Z",
6+
"aliases": [
7+
"CVE-2025-65026",
8+
"GHSA-hcpf-qv9m-vfgp"
9+
],
10+
"summary": "esm.sh CDN service has JS Template Literal Injection in CSS-to-JavaScript in github.com/esm-dev/esm.sh",
11+
"details": "esm.sh CDN service has JS Template Literal Injection in CSS-to-JavaScript in github.com/esm-dev/esm.sh",
12+
"affected": [
13+
{
14+
"package": {
15+
"name": "github.com/esm-dev/esm.sh",
16+
"ecosystem": "Go"
17+
},
18+
"ranges": [
19+
{
20+
"type": "SEMVER",
21+
"events": [
22+
{
23+
"introduced": "0"
24+
},
25+
{
26+
"fixed": "0.0.0-20251118065157-87d2f6497574"
27+
}
28+
]
29+
}
30+
],
31+
"ecosystem_specific": {}
32+
}
33+
],
34+
"references": [
35+
{
36+
"type": "ADVISORY",
37+
"url": "https://github.com/esm-dev/esm.sh/security/advisories/GHSA-hcpf-qv9m-vfgp"
38+
},
39+
{
40+
"type": "ADVISORY",
41+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-65026"
42+
},
43+
{
44+
"type": "FIX",
45+
"url": "https://github.com/esm-dev/esm.sh/commit/87d2f6497574bf4448641a5527a3ac2beba5fd6c"
46+
}
47+
],
48+
"database_specific": {
49+
"url": "https://pkg.go.dev/vuln/GO-2025-4139",
50+
"review_status": "UNREVIEWED"
51+
}
52+
}

data/osv/GO-2025-4146.json

Lines changed: 73 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,73 @@
1+
{
2+
"schema_version": "1.3.1",
3+
"id": "GO-2025-4146",
4+
"modified": "0001-01-01T00:00:00Z",
5+
"published": "0001-01-01T00:00:00Z",
6+
"aliases": [
7+
"CVE-2018-21258",
8+
"GHSA-5mh6-p63g-3mv5"
9+
],
10+
"summary": "Mattermost Server is vulnerable to a Denial of Service attack through `invite_people` command in github.com/mattermost/mattermost-server",
11+
"details": "Mattermost Server is vulnerable to a Denial of Service attack through `invite_people` command in github.com/mattermost/mattermost-server",
12+
"affected": [
13+
{
14+
"package": {
15+
"name": "github.com/mattermost/mattermost-server",
16+
"ecosystem": "Go"
17+
},
18+
"ranges": [
19+
{
20+
"type": "SEMVER",
21+
"events": [
22+
{
23+
"introduced": "0"
24+
}
25+
]
26+
}
27+
],
28+
"ecosystem_specific": {}
29+
},
30+
{
31+
"package": {
32+
"name": "github.com/mattermost/mattermost-server/v5",
33+
"ecosystem": "Go"
34+
},
35+
"ranges": [
36+
{
37+
"type": "SEMVER",
38+
"events": [
39+
{
40+
"introduced": "0"
41+
},
42+
{
43+
"fixed": "5.1.0"
44+
}
45+
]
46+
}
47+
],
48+
"ecosystem_specific": {}
49+
}
50+
],
51+
"references": [
52+
{
53+
"type": "ADVISORY",
54+
"url": "https://github.com/advisories/GHSA-5mh6-p63g-3mv5"
55+
},
56+
{
57+
"type": "ADVISORY",
58+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2018-21258"
59+
},
60+
{
61+
"type": "WEB",
62+
"url": "https://github.com/mattermost/mattermost/commit/af615ffc24b774d76deef8c93282831432669dd8"
63+
},
64+
{
65+
"type": "WEB",
66+
"url": "https://mattermost.com/security-updates"
67+
}
68+
],
69+
"database_specific": {
70+
"url": "https://pkg.go.dev/vuln/GO-2025-4146",
71+
"review_status": "UNREVIEWED"
72+
}
73+
}

data/osv/GO-2025-4147.json

Lines changed: 47 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,47 @@
1+
{
2+
"schema_version": "1.3.1",
3+
"id": "GO-2025-4147",
4+
"modified": "0001-01-01T00:00:00Z",
5+
"published": "0001-01-01T00:00:00Z",
6+
"aliases": [
7+
"GHSA-6xvf-4vh9-mw47"
8+
],
9+
"summary": "Minder does not sandbox http.send in Rego programs in github.com/mindersec/minder",
10+
"details": "Minder does not sandbox http.send in Rego programs in github.com/mindersec/minder",
11+
"affected": [
12+
{
13+
"package": {
14+
"name": "github.com/mindersec/minder",
15+
"ecosystem": "Go"
16+
},
17+
"ranges": [
18+
{
19+
"type": "SEMVER",
20+
"events": [
21+
{
22+
"introduced": "0.0.72"
23+
},
24+
{
25+
"fixed": "0.0.84"
26+
}
27+
]
28+
}
29+
],
30+
"ecosystem_specific": {}
31+
}
32+
],
33+
"references": [
34+
{
35+
"type": "ADVISORY",
36+
"url": "https://github.com/mindersec/minder/security/advisories/GHSA-6xvf-4vh9-mw47"
37+
},
38+
{
39+
"type": "FIX",
40+
"url": "https://github.com/mindersec/minder/commit/f770400923984649a287d7215410ef108e845af8"
41+
}
42+
],
43+
"database_specific": {
44+
"url": "https://pkg.go.dev/vuln/GO-2025-4147",
45+
"review_status": "UNREVIEWED"
46+
}
47+
}

0 commit comments

Comments
 (0)