Non-recursive certificate listing bypasses per-object authorization and leaks all fingerprints in github.com/canonical/lxd
{ "url": "https://pkg.go.dev/vuln/GO-2026-4595", "review_status": "REVIEWED" }
{ "custom_ranges": [ { "type": "ECOSYSTEM", "events": [ { "introduced": "6.6" }, { "fixed": "6.7" } ] } ] }
"https://vuln.go.dev/ID/GO-2026-4595.json"