CVE-2026-56857: Go Standard Library Internal/syscall/windows
Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.
On Windows, when the target of Root.Mkdir or Root.MkdirAll is a junction pointing to an empty location, the operation can create a directory at the junction target even when that target is located outside the root. This only applies to operations where the last path component is a junction (path/to/junction, but not path/junction/target).
Affected products
- Go Standard Library Internal/syscall/windows: before 1.26.9 (fixed in 1.26.9); from 1.27.0-0, before 1.27.2 (fixed in 1.27.2)
- Go Standard Library OS: before 1.26.9 (fixed in 1.26.9); from 1.27.0-0, before 1.27.2 (fixed in 1.27.2)
Published 2026-10-08. Last modified 2026-10-09.