CVE-2026-27139
Go vulnerability analysis and mitigation

Overview

CVE-2026-27139 is a path traversal vulnerability (CWE-22) in the Go standard library's os package affecting Unix platforms. When listing directory contents using File.ReadDir or File.Readdir, the returned FileInfo can reference a file outside the Root in which the File was opened, constituting a directory escape. The vulnerability affects Go versions prior to 1.25.8 and version 1.26.0 (fixed in 1.26.1). It was published on March 6, 2026, and carries a CVSS v3.1 base score of 2.5 (Low) (Go Vuln DB, IBM Advisory).

Technical details

The root cause is improper limitation of a pathname to a restricted directory (CWE-22) within Go's os package on Unix systems. When a File object opened within a restricted Root is used to call ReadDir or Readdir, the resulting FileInfo entries can point to filesystem paths outside the intended root boundary due to insufficient path validation. The impact is constrained to reading file metadata (via lstat) from arbitrary filesystem locations — it does not permit reading or writing file contents outside the root. The issue is tracked as Go issue #77827 and fixed via CL 749480 (Go Vuln DB, Go Issue).

Impact

Exploitation is limited to a low-severity confidentiality impact: an attacker with local access can read filesystem metadata (e.g., file names, sizes, permissions, timestamps) from arbitrary locations outside a sandboxed root directory. There is no impact on integrity or availability, and file contents cannot be read or written outside the root. The scope is unchanged, meaning the vulnerability does not enable privilege escalation or lateral movement beyond metadata disclosure (Go Vuln DB).

Exploitability

No public proof-of-concept exploit code or in-the-wild exploitation has been reported for CVE-2026-27139. The vulnerability requires local access with low privileges and high attack complexity, significantly limiting its practical exploitability. The EPSS score is approximately 0.005% (0.000050), indicating a very low probability of exploitation in the wild. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Go Vuln DB).

Mitigation and workarounds

Users should upgrade to Go 1.25.8 or Go 1.26.1, which contain the fix (CL 749480). IBM has released patches for affected products including IBM Instana Observability and IBM App Connect Enterprise Certified Container; users of those products should apply the vendor-supplied updates. No configuration-based workarounds have been published; upgrading the Go runtime is the recommended remediation (Go Vuln DB, IBM Instana Advisory, IBM ACE Advisory).

Community reactions

The Go security team disclosed the vulnerability via the golang-announce mailing list and the Go vulnerability database. IBM issued security bulletins for affected products (Instana Observability and App Connect Enterprise). The vulnerability received routine coverage from Linux distribution security teams (openSUSE, Amazon Linux, SUSE) and scanner vendors (Tenable, Qualys), reflecting standard patch-cycle handling for a low-severity issue (golang-announce, IBM Instana Advisory).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Affected

bookworm

golang-1.19

Affected

sid

golang-1.26: 1.26.1-1

Fixed

trixie

golang-1.24

Affected

Ubuntu

Unknown

devel

golang-1.24

Unknown

jammy

golang-1.24

Unknown

jammy (esm-apps)

golang-1.24

Unknown

noble

golang-1.24

Unknown

noble (esm-apps)

golang-1.24

Unknown

resolute

golang-1.24

Unknown

RHEL / CentOS

Affected

RHEL 8

go-toolset:rhel8/golang.src

Affected

RHEL 9

golang.src

Affected

RHEL 10

golang.src

Affected

Alpine

Fixed

edge

go: 1.25.8-r0

Fixed

v3.23

go: 1.25.8-r0

Fixed

SourceThis report was generated using AI

Related Go vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-56865HIGH8.4
  • Go logoGo
  • gitlab-cng-19.1
NoYesAug 13, 2026
CVE-2026-56864HIGH7.5
  • Go logoGo
  • kyverno-readiness-checker-1.17
NoYesAug 13, 2026
CVE-2026-56862HIGH7.5
  • Go logoGo
  • kepler-fips
NoYesAug 13, 2026
CVE-2026-56859HIGH7.5
  • Go logoGo
  • grafana-elasticsearch
NoYesAug 13, 2026
CVE-2026-56860MEDIUM5.9
  • Go logoGo
  • crossplane-provider-aws-cur-fips
NoYesAug 13, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management