CVE-2026-44973High· 8.1▾ TwilightA flaw was found in go-billy, an interface filesystem abstraction for Go. Multiple path traversal vulnerabilities exist due to insufficient path sanitization and boundary enforcement. A remote attacker could exploit this by crafting malici…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 44.6 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 25.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
0.3%
Last analysed / modified upstream
A flaw was found in go-billy, an interface filesystem abstraction for Go. Multiple path traversal vulnerabilities exist due to insufficient path sanitization and boundary enforcement. A remote attacker could exploit this by crafting malicious paths, allowing them to escape intended base directories. This could lead to unauthorized access to sensitive filesystem locations, potentially resulting in information disclosure or modification of files.
github.com/go-git/go-billy: Go-billy: Arbitrary file access due to path traversal vulnerability — rated Important by Red Hat. Released 2026-05-28, updated 2026-09-14.
Affected:
No fix planned:
Will not fix
Affected packages:
github.com/go-git/go-billy/v5 < 5.9.0github.com/go-git/go-billy/v6 < 6.0.0-alpha.1Patched in:
github.com/go-git/go-billy/v5 5.9.0github.com/go-git/go-billy/v6 6.0.0-alpha.1Connected by shared product, vendor, weakness, or advisory.
CVE-2026-46600High· 7.5golang.org/x/net/dns/dnsmessage: golang.org/x/net/dns/dnsmessage: Denial of Service via invalid DNS record parsing (CVE-2026-46600)
CVE-2025-59682High· 8.8django: Potential partial directory-traversal via archive.extract() (CVE-2025-59682)
CVE-2026-15801High· 8.0A vulnerability was found in CRI-O related to the container checkpoint and restore feature
CVE-2023-27534Low· 3.7curl: SFTP path ~ resolving discrepancy (CVE-2023-27534)
CVE-2026-81829Medium· 5.3A flaw was found in SmallRye JWT's AwsAlbKeyResolver, which is used by applications to verify JSON Web Tokens signed by AWS Application Load Balancers
CVE-2026-79705Medium· 4.5A flaw was found in the buildah/copier Go package