File tree Expand file tree Collapse file tree 6 files changed +314
-0
lines changed Expand file tree Collapse file tree 6 files changed +314
-0
lines changed Original file line number Diff line number Diff line change 1+ {
2+ "schema_version" : " 1.3.1" ,
3+ "id" : " GO-2025-4027" ,
4+ "modified" : " 0001-01-01T00:00:00Z" ,
5+ "published" : " 0001-01-01T00:00:00Z" ,
6+ "aliases" : [
7+ " GHSA-fr8m-434r-g3xp"
8+ ],
9+ "summary" : " Gnark-crypto doesn't range check input values during ECDSA and EdDSA deserialization in github.com/consensys/gnark-crypto" ,
10+ "details" : " Gnark-crypto doesn't range check input values during ECDSA and EdDSA deserialization in github.com/consensys/gnark-crypto" ,
11+ "affected" : [
12+ {
13+ "package" : {
14+ "name" : " github.com/consensys/gnark-crypto" ,
15+ "ecosystem" : " Go"
16+ },
17+ "ranges" : [
18+ {
19+ "type" : " SEMVER" ,
20+ "events" : [
21+ {
22+ "introduced" : " 0"
23+ },
24+ {
25+ "fixed" : " 0.12.0"
26+ }
27+ ]
28+ }
29+ ],
30+ "ecosystem_specific" : {}
31+ }
32+ ],
33+ "references" : [
34+ {
35+ "type" : " ADVISORY" ,
36+ "url" : " https://github.com/Consensys/gnark-crypto/security/advisories/GHSA-fr8m-434r-g3xp"
37+ },
38+ {
39+ "type" : " WEB" ,
40+ "url" : " https://github.com/Consensys/gnark-crypto/pull/449"
41+ },
42+ {
43+ "type" : " WEB" ,
44+ "url" : " https://github.com/Consensys/gnark-crypto/releases/tag/v0.12.0"
45+ },
46+ {
47+ "type" : " WEB" ,
48+ "url" : " https://github.com/advisories/GHSA-9xfq-8j3r-xp5g"
49+ },
50+ {
51+ "type" : " WEB" ,
52+ "url" : " https://go.dev/blog/defer-panic-and-recover"
53+ }
54+ ],
55+ "database_specific" : {
56+ "url" : " https://pkg.go.dev/vuln/GO-2025-4027" ,
57+ "review_status" : " REVIEWED"
58+ }
59+ }
Original file line number Diff line number Diff line change 1+ {
2+ "schema_version" : " 1.3.1" ,
3+ "id" : " GO-2025-4038" ,
4+ "modified" : " 0001-01-01T00:00:00Z" ,
5+ "published" : " 0001-01-01T00:00:00Z" ,
6+ "aliases" : [
7+ " CVE-2025-26625" ,
8+ " GHSA-6pvw-g552-53c5"
9+ ],
10+ "summary" : " Git LFS may write to arbitrary files via crafted symlinks in github.com/git-lfs/git-lfs" ,
11+ "details" : " Git LFS may write to arbitrary files via crafted symlinks in github.com/git-lfs/git-lfs" ,
12+ "affected" : [
13+ {
14+ "package" : {
15+ "name" : " github.com/git-lfs/git-lfs" ,
16+ "ecosystem" : " Go"
17+ },
18+ "ranges" : [
19+ {
20+ "type" : " SEMVER" ,
21+ "events" : [
22+ {
23+ "introduced" : " 0.5.2"
24+ }
25+ ]
26+ }
27+ ],
28+ "ecosystem_specific" : {}
29+ },
30+ {
31+ "package" : {
32+ "name" : " github.com/git-lfs/git-lfs/v3" ,
33+ "ecosystem" : " Go"
34+ },
35+ "ranges" : [
36+ {
37+ "type" : " SEMVER" ,
38+ "events" : [
39+ {
40+ "introduced" : " 0"
41+ },
42+ {
43+ "fixed" : " 3.7.1"
44+ }
45+ ]
46+ }
47+ ],
48+ "ecosystem_specific" : {
49+ "imports" : [
50+ {
51+ "path" : " github.com/git-lfs/git-lfs/v3/commands" ,
52+ "symbols" : [
53+ " checkoutCommand" ,
54+ " checkoutConflict" ,
55+ " newSingleCheckout" ,
56+ " singleCheckout.Run"
57+ ]
58+ },
59+ {
60+ "path" : " github.com/git-lfs/git-lfs/v3/lfs" ,
61+ "symbols" : [
62+ " GitFilter.SmudgeToFile"
63+ ]
64+ }
65+ ]
66+ }
67+ }
68+ ],
69+ "references" : [
70+ {
71+ "type" : " ADVISORY" ,
72+ "url" : " https://github.com/git-lfs/git-lfs/security/advisories/GHSA-6pvw-g552-53c5"
73+ },
74+ {
75+ "type" : " FIX" ,
76+ "url" : " https://github.com/git-lfs/git-lfs/commit/0cffe93176b870055c9dadbb3cc9a4a440e98396"
77+ },
78+ {
79+ "type" : " FIX" ,
80+ "url" : " https://github.com/git-lfs/git-lfs/commit/5c11ffce9a4f095ff356bc781e2a031abb46c1a8"
81+ },
82+ {
83+ "type" : " FIX" ,
84+ "url" : " https://github.com/git-lfs/git-lfs/commit/d02bd13f02ef76f6807581cd6b34709069cb3615"
85+ },
86+ {
87+ "type" : " WEB" ,
88+ "url" : " https://github.com/git-lfs/git-lfs/releases/tag/v3.7.1"
89+ }
90+ ],
91+ "database_specific" : {
92+ "url" : " https://pkg.go.dev/vuln/GO-2025-4038" ,
93+ "review_status" : " REVIEWED"
94+ }
95+ }
Original file line number Diff line number Diff line change 1+ {
2+ "schema_version" : " 1.3.1" ,
3+ "id" : " GO-2025-4044" ,
4+ "modified" : " 0001-01-01T00:00:00Z" ,
5+ "published" : " 0001-01-01T00:00:00Z" ,
6+ "aliases" : [
7+ " CVE-2025-54470" ,
8+ " GHSA-qqj3-g7mx-5p4w"
9+ ],
10+ "summary" : " NeuVector telemetry sender is vulnerable to MITM and DoS in github.com/neuvector/neuvector" ,
11+ "details" : " NeuVector telemetry sender is vulnerable to MITM and DoS in github.com/neuvector/neuvector" ,
12+ "affected" : [
13+ {
14+ "package" : {
15+ "name" : " github.com/neuvector/neuvector" ,
16+ "ecosystem" : " Go"
17+ },
18+ "ranges" : [
19+ {
20+ "type" : " SEMVER" ,
21+ "events" : [
22+ {
23+ "introduced" : " 0"
24+ }
25+ ]
26+ }
27+ ],
28+ "ecosystem_specific" : {
29+ "custom_ranges" : [
30+ {
31+ "type" : " ECOSYSTEM" ,
32+ "events" : [
33+ {
34+ "introduced" : " 0.0.0-20230727023453-1c4957d53911"
35+ },
36+ {
37+ "fixed" : " 0.0.0-20251020133207-084a437033b4"
38+ },
39+ {
40+ "introduced" : " 5.3.0"
41+ },
42+ {
43+ "fixed" : " 5.3.5"
44+ },
45+ {
46+ "introduced" : " 5.4.0"
47+ },
48+ {
49+ "fixed" : " 5.4.7"
50+ }
51+ ]
52+ }
53+ ]
54+ }
55+ }
56+ ],
57+ "references" : [
58+ {
59+ "type" : " ADVISORY" ,
60+ "url" : " https://github.com/neuvector/neuvector/security/advisories/GHSA-qqj3-g7mx-5p4w"
61+ },
62+ {
63+ "type" : " WEB" ,
64+ "url" : " https://github.com/neuvector/neuvector/commit/06424701e69bf1eb76ff90180d78853fded93021"
65+ },
66+ {
67+ "type" : " WEB" ,
68+ "url" : " https://github.com/neuvector/neuvector/commit/415737cbec581a5dc5f204fac1c78b7f29ad7dc2"
69+ }
70+ ],
71+ "database_specific" : {
72+ "url" : " https://pkg.go.dev/vuln/GO-2025-4044" ,
73+ "review_status" : " REVIEWED"
74+ }
75+ }
Original file line number Diff line number Diff line change 1+ id : GO-2025-4027
2+ modules :
3+ - module : github.com/consensys/gnark-crypto
4+ versions :
5+ - fixed : 0.12.0
6+ vulnerable_at : 0.11.2
7+ summary : |-
8+ Gnark-crypto doesn't range check input values during ECDSA and EdDSA
9+ deserialization in github.com/consensys/gnark-crypto
10+ ghsas :
11+ - GHSA-fr8m-434r-g3xp
12+ references :
13+ - advisory : https://github.com/Consensys/gnark-crypto/security/advisories/GHSA-fr8m-434r-g3xp
14+ - web : https://github.com/Consensys/gnark-crypto/pull/449
15+ - web : https://github.com/Consensys/gnark-crypto/releases/tag/v0.12.0
16+ - web : https://github.com/advisories/GHSA-9xfq-8j3r-xp5g
17+ - web : https://go.dev/blog/defer-panic-and-recover
18+ notes :
19+ - Symbols failed due to Go tooling being unable to determine what version to build dependencies
20+ source :
21+ id : GHSA-fr8m-434r-g3xp
22+ created : 2025-10-28T17:37:04.938126994Z
23+ review_status : REVIEWED
Original file line number Diff line number Diff line change 1+ id : GO-2025-4038
2+ modules :
3+ - module : github.com/git-lfs/git-lfs
4+ versions :
5+ - introduced : 0.5.2
6+ vulnerable_at : 1.5.6
7+ - module : github.com/git-lfs/git-lfs/v3
8+ versions :
9+ - fixed : 3.7.1
10+ vulnerable_at : 3.7.0
11+ packages :
12+ - package : github.com/git-lfs/git-lfs/v3/commands
13+ symbols :
14+ - singleCheckout.Run
15+ - checkoutConflict
16+ - checkoutCommand
17+ - newSingleCheckout
18+ - package : github.com/git-lfs/git-lfs/v3/lfs
19+ symbols :
20+ - GitFilter.SmudgeToFile
21+ summary : |-
22+ Git LFS may write to arbitrary files via crafted symlinks in
23+ github.com/git-lfs/git-lfs
24+ cves :
25+ - CVE-2025-26625
26+ ghsas :
27+ - GHSA-6pvw-g552-53c5
28+ references :
29+ - advisory : https://github.com/git-lfs/git-lfs/security/advisories/GHSA-6pvw-g552-53c5
30+ - fix : https://github.com/git-lfs/git-lfs/commit/0cffe93176b870055c9dadbb3cc9a4a440e98396
31+ - fix : https://github.com/git-lfs/git-lfs/commit/5c11ffce9a4f095ff356bc781e2a031abb46c1a8
32+ - fix : https://github.com/git-lfs/git-lfs/commit/d02bd13f02ef76f6807581cd6b34709069cb3615
33+ - web : https://github.com/git-lfs/git-lfs/releases/tag/v3.7.1
34+ source :
35+ id : GHSA-6pvw-g552-53c5
36+ created : 2025-10-28T17:30:07.668806596Z
37+ review_status : REVIEWED
Original file line number Diff line number Diff line change 1+ id : GO-2025-4044
2+ modules :
3+ - module : github.com/neuvector/neuvector
4+ non_go_versions :
5+ - introduced : 0.0.0-20230727023453-1c4957d53911
6+ - fixed : 0.0.0-20251020133207-084a437033b4
7+ - introduced : 5.3.0
8+ - fixed : 5.3.5
9+ - introduced : 5.4.0
10+ - fixed : 5.4.7
11+ summary : |-
12+ NeuVector telemetry sender is vulnerable to MITM and DoS in
13+ github.com/neuvector/neuvector
14+ cves :
15+ - CVE-2025-54470
16+ ghsas :
17+ - GHSA-qqj3-g7mx-5p4w
18+ references :
19+ - advisory : https://github.com/neuvector/neuvector/security/advisories/GHSA-qqj3-g7mx-5p4w
20+ - web : https://github.com/neuvector/neuvector/commit/06424701e69bf1eb76ff90180d78853fded93021
21+ - web : https://github.com/neuvector/neuvector/commit/415737cbec581a5dc5f204fac1c78b7f29ad7dc2
22+ source :
23+ id : GHSA-qqj3-g7mx-5p4w
24+ created : 2025-10-28T17:29:19.513717805Z
25+ review_status : REVIEWED
You can’t perform that action at this time.
0 commit comments