Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-4660

Опубликовано: 09 апр. 2026
Источник: redhat
CVSS3: 7.5

Описание

HashiCorp’s go-getter library up to v1.8.5 may allow arbitrary file reads on the file system during certain git operations through a maliciously crafted URL. This vulnerability, CVE-2026-4660, is fixed in go-getter v1.8.6. This vulnerability does not affect the go-getter/v2 branch and package.

A flaw was found in the go-getter library. A remote attacker could exploit this vulnerability by providing a maliciously crafted URL during certain git operations. This could allow the attacker to perform arbitrary file reads on the file system, potentially leading to the disclosure of sensitive information.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift Container Platform 4redhat-user-workloads/art-imagesAffected
Red Hat Trusted Artifact Signerredhat-user-workloads/cli-v06Not affected
Red Hat Trusted Artifact Signerredhat-user-workloads/cli-v08Affected
Red Hat Trusted Artifact Signer 1.3rhtas/client-server-rhel9FixedRHSA-2026:2447808.06.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=2456909go-getter: go-getter: Arbitrary file reads via maliciously crafted URL

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
4 месяца назад

HashiCorp’s go-getter library up to v1.8.5 may allow arbitrary file reads on the file system during certain git operations through a maliciously crafted URL. This vulnerability, CVE-2026-4660, is fixed in go-getter v1.8.6. This vulnerability does not affect the go-getter/v2 branch and package.

CVSS3: 7.5
nvd
4 месяца назад

HashiCorp’s go-getter library up to v1.8.5 may allow arbitrary file reads on the file system during certain git operations through a maliciously crafted URL. This vulnerability, CVE-2026-4660, is fixed in go-getter v1.8.6. This vulnerability does not affect the go-getter/v2 branch and package.

CVSS3: 7.5
debian
4 месяца назад

HashiCorp\u2019s go-getter library up to v1.8.5 may allow arbitrary fi ...

CVSS3: 7.5
github
4 месяца назад

HashiCorp's go-getter library may allow arbitrary file reads

7.5 High

CVSS3