Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-39822

Опубликовано: 08 июл. 2026
Источник: nvd
CVSS3: 7.8
EPSS Низкий

Описание

On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the final path component of the a path is a symbolic link and the path ends in /. For example, 'root.Open("symlink/")' will open "symlink" even when "symlink" is a symbolic link pointing outside of the root.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:golang:go:*:*:*:*:*:*:*:*
Версия до 1.25.12 (исключая)
cpe:2.3:a:golang:go:*:*:*:*:*:*:*:*
Версия от 1.26.0 (включая) до 1.26.5 (исключая)
cpe:2.3:a:golang:go:1.27:rc1:*:*:*:*:*:*

EPSS

Процентиль: 14%
0.00232
Низкий

7.8 High

CVSS3

Дефекты

CWE-61

Связанные уязвимости

CVSS3: 7.8
ubuntu
23 дня назад

On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the final path component of the a path is a symbolic link and the path ends in /. For example, 'root.Open("symlink/")' will open "symlink" even when "symlink" is a symbolic link pointing outside of the root.

CVSS3: 7.8
redhat
23 дня назад

On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the final path component of the a path is a symbolic link and the path ends in /. For example, 'root.Open("symlink/")' will open "symlink" even when "symlink" is a symbolic link pointing outside of the root.

msrc
16 дней назад

Root escape via symlink plus trailing slash in os

CVSS3: 7.8
debian
23 дня назад

On Unix systems, opening a file in an os.Root improperly follows symli ...

rocky
17 дней назад

Important: podman security update

EPSS

Процентиль: 14%
0.00232
Низкий

7.8 High

CVSS3

Дефекты

CWE-61