{"id":"CVE-2026-44973","title":"github.com/go-git/go-billy: Go-billy: Arbitrary file access due to path traversal vulnerability (CVE-2026-44973)","summary":"A flaw was found in go-billy, an interface filesystem abstraction for Go. Multiple path traversal vulnerabilities exist due to insufficient path sanitization and boundary enforcement. A remote attacker could exploit this by crafting malici…","severity":"high","cvss":8.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","cvssSource":"vendor","cwe":"CWE-22","vendor":"Red Hat","product":"Multicluster Engine for Kubernetes","affected":["multicluster_engine_for_kubernetes","advanced_cluster_management_for_kubernetes 2"],"patched":["github.com/go-git/go-billy/v5 5.9.0","github.com/go-git/go-billy/v6 6.0.0-alpha.1"],"published":"2026-05-28","updated":"2026-09-14","sourceUpdated":"2026-09-14T15:52:36+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-44973.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-44973.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-44973"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2483029"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-44973"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-44973"},{"url":"https://github.com/go-git/go-billy/security/advisories/GHSA-qw64-3x98-g7q2"},{"url":"https://github.com/go-git/go-billy"},{"url":"https://github.com/go-git/go-billy/releases/tag/v5.9.0"},{"url":"https://github.com/go-git/go-billy/releases/tag/v6.0.0-alpha.1"}],"tags":["csaf","vex","red-hat","osv","go"],"epss":0.0031,"epssPercentile":0.24011,"aliases":["GHSA-qw64-3x98-g7q2","GO-2026-5597"],"ecosystem":"go","ingestedAt":"2026-07-25T19:08:11.946Z","slug":"CVE-2026-44973","body":"## Overview\n\nA flaw was found in go-billy, an interface filesystem abstraction for Go. Multiple path traversal vulnerabilities exist due to insufficient path sanitization and boundary enforcement. A remote attacker could exploit this by crafting malicious paths, allowing them to escape intended base directories. This could lead to unauthorized access to sensitive filesystem locations, potentially resulting in information disclosure or modification of files.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Important · affected: Multicluster Engine for Kubernetes, Red Hat Advanced Cluster Management for Kubernetes 2 · no fix planned: Multicluster Engine for Kubernetes, Red Hat Advanced Cluster Management for Kubernetes 2 · updated 2026-09-14 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-44973.json)\n\n**github.com/go-git/go-billy: Go-billy: Arbitrary file access due to path traversal vulnerability** — rated Important by Red Hat. Released 2026-05-28, updated 2026-09-14.\n\nAffected:\n\n- Multicluster Engine for Kubernetes\n- Red Hat Advanced Cluster Management for Kubernetes 2\n\nNo fix planned:\n\n- Multicluster Engine for Kubernetes\n- Red Hat Advanced Cluster Management for Kubernetes 2\n\n## Remediation\n\nWill not fix\n\n## Package advisory (CVE-2026-44973)\n\nAffected packages:\n\n- `github.com/go-git/go-billy/v5 < 5.9.0`\n- `github.com/go-git/go-billy/v6 < 6.0.0-alpha.1`\n\nPatched in:\n\n- `github.com/go-git/go-billy/v5 5.9.0`\n- `github.com/go-git/go-billy/v6 6.0.0-alpha.1`\n\nSource: https://osv.dev/vulnerability/GHSA-qw64-3x98-g7q2","depth":"twilight","depthScore":45,"depthScoreParts":{"impact":44.6,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}