---
id: CVE-2026-44973
title: >-
  github.com/go-git/go-billy: Go-billy: Arbitrary file access due to path
  traversal vulnerability (CVE-2026-44973)
summary: >-
  A flaw was found in go-billy, an interface filesystem abstraction for Go.
  Multiple path traversal vulnerabilities exist due to insufficient path
  sanitization and boundary enforcement. A remote attacker could exploit this by
  crafting malici…
severity: high
cvss: 8.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'
cvssSource: vendor
cwe: CWE-22
vendor: Red Hat
product: Multicluster Engine for Kubernetes
affected:
  - multicluster_engine_for_kubernetes
  - advanced_cluster_management_for_kubernetes 2
patched:
  - github.com/go-git/go-billy/v5 5.9.0
  - github.com/go-git/go-billy/v6 6.0.0-alpha.1
published: '2026-05-28'
updated: '2026-09-14'
sourceUpdated: '2026-09-14T15:52:36+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-44973.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-44973.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-44973'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2483029'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-44973'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-44973'
  - url: 'https://github.com/go-git/go-billy/security/advisories/GHSA-qw64-3x98-g7q2'
  - url: 'https://github.com/go-git/go-billy'
  - url: 'https://github.com/go-git/go-billy/releases/tag/v5.9.0'
  - url: 'https://github.com/go-git/go-billy/releases/tag/v6.0.0-alpha.1'
tags:
  - csaf
  - vex
  - red-hat
  - osv
  - go
epss: 0.00468
epssPercentile: 0.37967
aliases:
  - GHSA-qw64-3x98-g7q2
  - GO-2026-5597
ecosystem: go
ingestedAt: '2026-07-25T19:08:11.946Z'
---

## Overview

A flaw was found in go-billy, an interface filesystem abstraction for Go. Multiple path traversal vulnerabilities exist due to insufficient path sanitization and boundary enforcement. A remote attacker could exploit this by crafting malicious paths, allowing them to escape intended base directories. This could lead to unauthorized access to sensitive filesystem locations, potentially resulting in information disclosure or modification of files.

## Vendor advisories

- **Red Hat VEX** · Important · affected: Multicluster Engine for Kubernetes, Red Hat Advanced Cluster Management for Kubernetes 2 · no fix planned: Multicluster Engine for Kubernetes, Red Hat Advanced Cluster Management for Kubernetes 2 · updated 2026-09-14 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-44973.json)

**github.com/go-git/go-billy: Go-billy: Arbitrary file access due to path traversal vulnerability** — rated Important by Red Hat. Released 2026-05-28, updated 2026-09-14.

Affected:

- Multicluster Engine for Kubernetes
- Red Hat Advanced Cluster Management for Kubernetes 2

No fix planned:

- Multicluster Engine for Kubernetes
- Red Hat Advanced Cluster Management for Kubernetes 2

## Remediation

Will not fix

## Package advisory (CVE-2026-44973)

Affected packages:

- `github.com/go-git/go-billy/v5 < 5.9.0`
- `github.com/go-git/go-billy/v6 < 6.0.0-alpha.1`

Patched in:

- `github.com/go-git/go-billy/v5 5.9.0`
- `github.com/go-git/go-billy/v6 6.0.0-alpha.1`

Source: https://osv.dev/vulnerability/GHSA-qw64-3x98-g7q2
