CVE-2025-22873: Golang Go
Low severity, CVSS 3.8. EPSS: 0.2% chance of exploitation in the next 30 days.
It was possible to improperly access the parent directory of an os.Root by opening a filename ending in "../". For example, Root.Open("../") would open the parent directory of the Root. This escape only permits opening the parent directory itself, not ancestors of the parent or files contained within the parent.
Affected products
- Golang Go: before 1.23.9 (fixed in 1.23.9); from 1.24.0, before 1.24.3 (fixed in 1.24.3)
Published 2026-02-04. Last modified 2026-06-17.