---
id: CVE-2026-39819
aliases:
  - GO-2026-4978
  - BIT-golang-2026-39819
title: >-
  Invoking "go bug" follows symlinks in predictable temporary filenames in
  cmd/go
summary: >-
  Invoking "go bug" follows symlinks in predictable temporary filenames in
  cmd/go
severity: medium
cvss: 4.4
cvssVector: 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N'
vendor: toolchain
product: toolchain
ecosystem: go
affected:
  - 'toolchain >= 1.26.0-0, < 1.26.3'
patched:
  - toolchain 1.26.3
published: '2026-05-07'
updated: '2026-09-22'
sourceUpdated: '2026-09-22T10:41:48.065334746Z'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GO-2026-4978'
references:
  - url: 'https://go.dev/issue/78584'
  - url: 'https://go.dev/cl/763882'
  - url: 'https://groups.google.com/g/golang-announce/c/qcCIEXso47M'
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39819.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-39819'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2467813'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-39819'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-39819'
  - url: 'https://pkg.go.dev/vuln/GO-2026-4978'
  - url: 'https://access.redhat.com/errata/RHSA-2026:49702'
  - url: 'https://access.redhat.com/errata/RHSA-2026:22120'
  - url: 'https://access.redhat.com/errata/RHSA-2026:22112'
  - url: 'https://access.redhat.com/errata/RHSA-2026:61253'
  - url: 'https://access.redhat.com/errata/RHSA-2026:57649'
  - url: 'https://access.redhat.com/errata/RHSA-2026:49712'
  - url: 'https://access.redhat.com/errata/RHSA-2026:22121'
  - url: 'https://access.redhat.com/errata/RHSA-2026:62391'
  - url: 'https://access.redhat.com/errata/RHSA-2026:66561'
  - url: 'https://access.redhat.com/errata/RHSA-2026:57194'
tags:
  - osv
  - go
  - csaf
  - vex
  - red-hat
epss: 0.00148
epssPercentile: 0.03339
cvssSource: vendor
cwe:
  - CWE-59
ingestedAt: '2026-08-26T19:27:02.357Z'
---

## Overview

The "go bug" command writes to two files with predictable names in the system temporary directory (for example, "/tmp").

An attacker with access to the temporary directory can create a symlink in one of these names, causing "go bug" to overwrite the target of the symlink.

## Affected packages

- `toolchain >= 1.26.0-0, < 1.26.3`

## Remediation

Upgrade to a patched release:

- `toolchain 1.26.3`

## Vendor advisories

- **RHSA-2026:49702** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v. 10.0) · released 2026-08-03 · [advisory](https://access.redhat.com/errata/RHSA-2026:49702)
- **RHSA-2026:22120** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 10) · released 2026-06-01 · [advisory](https://access.redhat.com/errata/RHSA-2026:22120)
- **RHSA-2026:22112** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 8) · released 2026-06-01 · [advisory](https://access.redhat.com/errata/RHSA-2026:22112)
- **RHSA-2026:61253** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream E4S (v.9.2) · released 2026-08-31 · [advisory](https://access.redhat.com/errata/RHSA-2026:61253)
- **RHSA-2026:57649** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream E4S (v.9.4) · released 2026-08-20 · [advisory](https://access.redhat.com/errata/RHSA-2026:57649)
- **RHSA-2026:49712** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v.9.6) · released 2026-08-03 · [advisory](https://access.redhat.com/errata/RHSA-2026:49712)
- **RHSA-2026:22121** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 9) · released 2026-06-01 · [advisory](https://access.redhat.com/errata/RHSA-2026:22121)
- **RHSA-2026:62391** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-09-02 · [advisory](https://access.redhat.com/errata/RHSA-2026:62391)
- **RHSA-2026:66561** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-09-11 · [advisory](https://access.redhat.com/errata/RHSA-2026:66561)
- **RHSA-2026:57194** · Red Hat · fixed in: multicluster engine for Kubernetes 2.11 · released 2026-08-19 · [advisory](https://access.redhat.com/errata/RHSA-2026:57194)
- **Red Hat VEX** · Moderate · affected: Red Hat Hardened Images, Multicluster Engine for Kubernetes, OpenShift API for Data Protection, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat OpenShift Container Platform 4 · no fix planned: Red Hat Hardened Images · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39819.json)
