{"source":"ghsa-go","note":"Free 5-item preview. The full feed is $0.05/call at GET /v1/ghsa-go/changes.","question":"Which new security vulnerabilities / CVEs affecting Go packages were published since T, and how severe (CVSS) are they?","sample":[{"source":"ghsa-go","entityId":"ghsa:GHSA-cwxq-rc9x-2jvv","type":"advisory","title":"GHSA-cwxq-rc9x-2jvv / CVE-2026-54247: Skipper: Unbounded Request Body Read in Admission Webhook Causes Memory Exhaustion DoS","summary":"MEDIUM severity. Affected: github.com/zalando/skipper.","significance":4,"detectedAt":"2026-07-18T23:42:09.854Z","effectiveDate":"2026-07-17T18:14:08Z","sourceUrl":"https://github.com/advisories/GHSA-cwxq-rc9x-2jvv","detail":{"severity":"medium","cve":"CVE-2026-54247","packages":"github.com/zalando/skipper","cvss":4.3}},{"source":"ghsa-go","entityId":"ghsa:GHSA-rjwr-m7qx-3fjr","type":"advisory","title":"GHSA-rjwr-m7qx-3fjr: oapi-codegen: OpenAPI Server Description Escapes Generated Go Comment and Injects Executable Code","summary":"LOW severity. Affected: github.com/oapi-codegen/oapi-codegen/v2.","significance":3,"detectedAt":"2026-07-18T23:42:09.854Z","effectiveDate":"2026-07-17T18:50:17Z","sourceUrl":"https://github.com/advisories/GHSA-rjwr-m7qx-3fjr","detail":{"severity":"low","cve":null,"packages":"github.com/oapi-codegen/oapi-codegen/v2","cvss":null}},{"source":"ghsa-go","entityId":"ghsa:GHSA-8qw8-rq86-9pc2","type":"advisory","title":"GHSA-8qw8-rq86-9pc2 / CVE-2026-27771: Gitea has insufficient permission checks for Composer package source links","summary":"HIGH severity. Affected: code.gitea.io/gitea.","significance":8,"detectedAt":"2026-07-18T23:42:09.854Z","effectiveDate":"2026-07-17T19:04:37Z","sourceUrl":"https://github.com/advisories/GHSA-8qw8-rq86-9pc2","detail":{"severity":"high","cve":"CVE-2026-27771","packages":"code.gitea.io/gitea","cvss":8.2}},{"source":"ghsa-go","entityId":"ghsa:GHSA-5587-2x54-jj6h","type":"advisory","title":"GHSA-5587-2x54-jj6h / CVE-2026-54246: Skipper's routesrv-no-auth component: All routesrv API Endpoints Lack Authentication","summary":"MEDIUM severity. Affected: github.com/zalando/skipper.","significance":6,"detectedAt":"2026-07-18T23:42:09.854Z","effectiveDate":"2026-07-17T21:46:18Z","sourceUrl":"https://github.com/advisories/GHSA-5587-2x54-jj6h","detail":{"severity":"medium","cve":"CVE-2026-54246","packages":"github.com/zalando/skipper","cvss":5.7}},{"source":"ghsa-go","entityId":"ghsa:GHSA-8qqm-fp2q-v734","type":"advisory","title":"GHSA-8qqm-fp2q-v734: Skipper: Incomplete fix for CVE-2026-50197: an oversized body can bypass OPA deny-on-presence Rego policies","summary":"HIGH severity. Affected: github.com/zalando/skipper.","significance":8,"detectedAt":"2026-07-18T23:42:09.854Z","effectiveDate":"2026-07-17T21:49:48Z","sourceUrl":"https://github.com/advisories/GHSA-8qqm-fp2q-v734","detail":{"severity":"high","cve":null,"packages":"github.com/zalando/skipper","cvss":8.2}}]}