CVE-2025-22873: Golang Go

Low severity, CVSS 3.8. EPSS: 0.2% chance of exploitation in the next 30 days.

It was possible to improperly access the parent directory of an os.Root by opening a filename ending in "../". For example, Root.Open("../") would open the parent directory of the Root. This escape only permits opening the parent directory itself, not ancestors of the parent or files contained within the parent.

Affected products

  • Golang Go: before 1.23.9 (fixed in 1.23.9); from 1.24.0, before 1.24.3 (fixed in 1.24.3)

Published 2026-02-04. Last modified 2026-06-17.