← Back

CVE-2026-39822

nvd nist
Published: Jul 8, 2026Modified: Jul 13, 2026

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the final path component of the a path is a symbolic link and the path ends in /. For example, 'root.Open("symlink/")' will open "symlink" even when "symlink" is a symbolic link pointing outside of the root.

Affected (3)

Products: Golang: Go
1 product
Go
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Golang
Before 1.25.12
From 1.26.0 to 1.26.5
Version 1.27 rc1

References (4)

Source: security@golang.org
Patch
Source: security@golang.org
Issue TrackingPatch
Source: security@golang.org
Mailing ListPatchVendor Advisory
Source: security@golang.org
Vendor Advisory

Timeline

No history available yet.