CVE-2026-19585Medium· 5.3▾ SunlitHashiCorp go-getter versions before 1.8.10 and go-getter/v2 versions before 2.2.5 are vulnerable to path traversal during S3 and GCS directory downloads, which may allow files to be written outside the requested destination. This vulnera…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.2 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
HashiCorp go-getter versions before 1.8.10 and go-getter/v2 versions before 2.2.5 are vulnerable to path traversal during S3 and GCS directory downloads, which may allow files to be written outside the requested destination. This vulnerability (CVE-2026-19585) is fixed in go-getter 1.8.10 and go-getter/v2 2.2.5.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-105820Medium· 5.4Vault's ACL policy cache allowed namespace traversal when policy names contained path traversal constructs
CVE-2026-105816High· 8.0Vault and Vault Enterprise did not consistently verify that stored plugin catalog entries reference binaries within the configured plugin directory
CVE-2026-88922Medium· 6.7The go-getter library up to versions 1.8.8 and 2.2.3 is vulnerable to a privilege escalation issue in its archive decompression handling that may allow a crafted archive to cause extracted files to be created with elevated permission bit…
CVE-2022-37906Medium· 6.5An authenticated path traversal vulnerability exists in the ArubaOS command line interface
CVE-2026-89322High· 7.2Vault and Vault Enterprise did not consistently evaluate ACL policies against the canonical form of resource and policy names
CVE-2026-105818Medium· 5.9Vault's PKI secrets engine ACME server did not restrict certificate identities that ACME challenges do not validate when issuing certificates under the default directory policy