CVE-2026-19585: Hashicorp Shared Library

Medium severity, CVSS 5.3. EPSS: 0.2% chance of exploitation in the next 30 days.

HashiCorp go-getter versions before 1.8.10 and go-getter/v2 versions before 2.2.5 are vulnerable to path traversal during S3 and GCS directory downloads, which may allow files to be written outside the requested destination. This vulnerability (CVE-2026-19585) is fixed in go-getter 1.8.10 and go-getter/v2 2.2.5.

Affected products

  • Hashicorp Shared Library: from 1.0.1, before 2.2.5 (fixed in 2.2.5)

Published 2026-10-08. Last modified 2026-10-08.