cbcvebase.
CVE-2026-39822
published 2026-07-08

CVE-2026-39822: On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the final path component of the a path is a…

PriorityP342high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.23%
14.0th percentile
On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the final path component of the a path is a symbolic link and the path ends in /. For example, 'root.Open("symlink/")' will open "symlink" even when "symlink" is a symbolic link pointing outside of the root.

Affected

17 ranges
VendorProductVersion rangeFixed in
advanced-cluster-securityrhacs-main-rhel8
advanced-cluster-securityrhacs-main-rhel9
buildah_projectbuildah
go-toolset_rhel8golang
go_standard_libraryos< 1.25.121.25.12
go_standard_libraryos>= 1.26.0-0 < 1.26.51.26.5
go_standard_libraryos>= 1.27.0-0 < 1.27.0-rc.21.27.0-rc.2
golanggo< 1.25.121.25.12
golanggo
golanggo>= 1.26.0 < 1.26.51.26.5
podman_projectpodman
quayquay-rhel8
quayquay-rhel9
redhatopenshift
rh-osbsopenshift-golang-builder
rhacm2thanos-rhel9
rhcephgrafana-rhel9

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.