CVE-2026-39817
published 2026-05-07CVE-2026-39817: The "go tool pack" subcommand (usually used only by the compiler as an internal tool with known-good inputs) does not sanitize output filenames. Extracting a…
PriorityP429medium5.9CVSS 3.1
AVLACLPRLUIRSCCNIHAN
EPSS
0.17%
6.5th percentile
The "go tool pack" subcommand (usually used only by the compiler as an internal tool with known-good inputs) does not sanitize output filenames. Extracting a malicious archive file with the "pack" subcommand can write files to arbitrary locations on the filesystem.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| go_toolchain | cmd_go | < 1.25.10 | 1.25.10 |
| go_toolchain | cmd_go | >= 1.26.0-0 < 1.26.3 | 1.26.3 |
| golang | go | < 1.25.10 | 1.25.10 |
| golang | go | >= 1.26.0 < 1.26.3 | 1.26.3 |
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:N
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
cmd/go: golang: Go tool pack: Arbitrary file write via malicious archive extraction
vendor_redhat·2026-05-07·CVSS 5.9
CVE-2026-39817 [MEDIUM] CWE-22 cmd/go: golang: Go tool pack: Arbitrary file write via malicious archive extraction
cmd/go: golang: Go tool pack: Arbitrary file write via malicious archive extraction
The "go tool pack" subcommand (usually used only by the compiler as an internal tool with known-good inputs) does not sanitize output filenames. Extracting a malicious archive file with the "pack" subcommand can write files to arbitrary locations on the filesystem.
A flaw was found in the "go tool pack" subcommand, a component of the Go programming language tools. This vulnerability allows an attacker to craft a malicious archive file. When this archive is extracted using the "pack" subcommand, it can lead to arbitrary file writes on the filesystem, potentially allowing an attacker to create or modify files in unintended locations.
VulDB
cmd-go up to 1.25.9/1.26.2 on Go Archive path traversal (EUVD-2026-28421)
vuldb·2026-05-07
CVE-2026-39817 [CRITICAL] cmd-go up to 1.25.9/1.26.2 on Go Archive path traversal (EUVD-2026-28421)
A vulnerability, which was classified as critical, was found in cmd-go up to 1.25.9/1.26.2 on Go. Affected by this vulnerability is an unknown functionality of the component Archive Handler. The manipulation results in path traversal.
This vulnerability is cataloged as CVE-2026-39817. The attack may be launched remotely. There is no exploit available.
You should upgrade the affected component.
GHSA
GHSA-qc64-m6c2-v4x7: The "go tool pack" subcommand (usually used only by the compiler as an internal tool with known-good inputs) does not sanitize output filenames
ghsa_unreviewed·2026-05-07
CVE-2026-39817 [MEDIUM] GHSA-qc64-m6c2-v4x7: The "go tool pack" subcommand (usually used only by the compiler as an internal tool with known-good inputs) does not sanitize output filenames
The "go tool pack" subcommand (usually used only by the compiler as an internal tool with known-good inputs) does not sanitize output filenames. Extracting a malicious archive file with the "pack" subcommand can write files to arbitrary locations on the filesystem.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-39817 cmd/go: golang: Go tool pack: Arbitrary file write via malicious archive extraction
bugzilla·2026-05-07·CVSS 5.9
CVE-2026-39817 [MEDIUM] CVE-2026-39817 cmd/go: golang: Go tool pack: Arbitrary file write via malicious archive extraction
CVE-2026-39817 cmd/go: golang: Go tool pack: Arbitrary file write via malicious archive extraction
The "go tool pack" subcommand (usually used only by the compiler as an internal tool with known-good inputs) does not sanitize output filenames. Extracting a malicious archive file with the "pack" subcommand can write files to arbitrary locations on the filesystem.
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 10
Via RHSA-2026:22120 https://access.redhat.com/errata/RHSA-2026:22120
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2026:22121 https://access.redhat.com/errata/RHSA-2026:22121
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-20
Rapid7
Patch Tuesday - May 2026
blogs_rapid7·2026-05-13·CVSS 10.0
CVE-2026-41089 [CRITICAL] Patch Tuesday - May 2026
Microsoft is publishing 137 vulnerabilities on May 2026 Patch Tuesday . Microsoft is not aware of exploitation in the wild or public disclosure for any of these vulnerabilities. So far this month, Microsoft has provided patches to address 133 browser vulnerabilities, which are not included in the Patch Tuesday count above.
## Windows Netlogon: critical RCE
Anyone responsible for securing a domain controller should prioritize remediation of CVE-2026-41089 , which is a critical stack-based buffer overflow in Windows Netlogon with a CVSS v3 base score of 9.8. Exploitation leads to execution in the context of the Netlogon service, so that’s SYSTEM privileges on the domain controller. For most pentesters, that’s the point at which the customer report more or less writes itself. No privileges
2026-05-07
Published