Name
CVE-2026-27139
Description
On Unix platforms, when listing the contents of a directory using File.ReadDir or File.Readdir the returned FileInfo could reference a file outside of the Root in which the File was opened. The impact of this escape is limited to reading metadata provided by lstat from arbitrary locations on the filesystem without permitting reading or writing files outside the root.
CWEs
Published Date
Updated Date
Workaround
-
Advisories
https://go.dev/cl/749480Mailing List
https://go.dev/issue/77827Issue Tracking
https://pkg.go.dev/vuln/GO-2026-4602Vendor Advisory
Analysis#
Vulnerability Ratings#
2.5
CVSSv31
NaN
other
Others affected components#
Name
Project
Project Version
Version
Status
openwrt
master
1.24.13-r1
Exploitable
openwrt
master
1.26.4-r1
Not Affected
openwrt
openwrt-25.12
1.24.13-r1
Exploitable
openwrt
openwrt-25.12
1.26.4-r1
Not Affected
yocto
master
1.26.4
Not Affected
yocto
master
1.26.4
Not Affected
yocto
scarthgap
1.22.12
Exploitable
yocto
scarthgap
1.22.12
Exploitable