CVE-2026-4660: Hashicorp Tooling
High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.
HashiCorp’s go-getter library up to v1.8.5 may allow arbitrary file reads on the file system during certain git operations through a maliciously crafted URL. This vulnerability, CVE-2026-4660, is fixed in go-getter v1.8.6. This vulnerability does not affect the go-getter/v2 branch and package.
Affected products
- Hashicorp Tooling: before 1.8.6 (fixed in 1.8.6)
- Red Hat Red Hat Openshift Container Platform 4
- Red Hat Red Hat Trusted Artifact Signer
- Red Hat Red Hat Trusted Artifact Signer 1.3: before 1780399582 (fixed in 1780399582)
Published 2026-04-09. Last modified 2026-07-15.