CVE-2026-39822: Golang Go

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the final path component of the a path is a symbolic link and the path ends in /. For example, 'root.Open("symlink/")' will open "symlink" even when "symlink" is a symbolic link pointing outside of the root.

Affected products

  • Golang Go: from 1.24.0, before 1.25.12 (fixed in 1.25.12); from 1.26.0, before 1.26.5 (fixed in 1.26.5); version 1.27 only

Published 2026-07-08. Last modified 2026-09-17.