It was possible to improperly access the parent directory of an os.Root by opening a filename ending in "../". For example, Root.Open("../") would open the parent directory of the Root. This escape only permits opening the parent directory itself, not ancestors of the parent or files contained within the parent.
CVSS Details
- CVSS 3.1 Base Score: 3.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade go | Feb 6, 2026 | Feb 4, 2026 |
| Amazon_linux_2023 | — | Upgrade golangUpgrade golang-srcUpgrade golang-miscUpgrade golang-docsUpgrade golang-binUpgrade golang-sharedUpgrade golang-tests | Feb 6, 2026 | Feb 4, 2026 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Feb 6, 2026 | Feb 4, 2026 |
| Debian | — | Upgrade golang-1.24 | Jul 23, 2026 | Jul 23, 2026 |
| Redhat_linux | — | No solution exists | Jul 17, 2026 | Feb 4, 2026 |
| Suse | — | Upgrade go1.24-openssl-raceUpgrade go1.24-opensslUpgrade go1.24-docUpgrade go1.24Upgrade go1.24-raceUpgrade go1.24-libstd | Dec 5, 2025 | May 29, 2025 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jun 15, 2026 | Feb 4, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub