Go standard library os

3 known vulnerabilities in Go standard library os, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-39822 CVSS 7.8 high On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the final path component…
  • CVE-2026-27139 CVSS 2.5 low On Unix platforms, when listing the contents of a directory using File.ReadDir or File.Readdir the returned FileInfo could reference a…
  • CVE-2025-22873 CVSS 3.8 low It was possible to improperly access the parent directory of an os.Root by opening a filename ending in "../". For example…