CVE-2026-19585: Hashicorp Shared Library
Medium severity, CVSS 5.3. EPSS: 0.2% chance of exploitation in the next 30 days.
HashiCorp go-getter versions before 1.8.10 and go-getter/v2 versions before 2.2.5 are vulnerable to path traversal during S3 and GCS directory downloads, which may allow files to be written outside the requested destination. This vulnerability (CVE-2026-19585) is fixed in go-getter 1.8.10 and go-getter/v2 2.2.5.
Affected products
- Hashicorp Shared Library: from 1.0.1, before 2.2.5 (fixed in 2.2.5)
Published 2026-10-08. Last modified 2026-10-08.