๐Ÿ” CVE Alert

CVE-2026-56857

UNKNOWN 0.0

Root.Mkdir(All) can follow junctions out of the root on Windows in os

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

On Windows, when the target of Root.Mkdir or Root.MkdirAll is a junction pointing to an empty location, the operation can create a directory at the junction target even when that target is located outside the root. This only applies to operations where the last path component is a junction (path/to/junction, but not path/junction/target).

Vendor go standard library
Product os
Published Oct 8, 2026
Stay Ahead of the Next One

Get instant alerts for go standard library os

Be the first to know when new unknown vulnerabilities affecting go standard library os are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Go standard library / os
0 < 1.26.9 1.27.0-0 < 1.27.2
Go standard library / internal/syscall/windows
0 < 1.26.9 1.27.0-0 < 1.27.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
go.dev: https://go.dev/cl/847305 go.dev: https://go.dev/issue/81739 groups.google.com: https://groups.google.com/g/golang-announce/c/U2fTuyDJznI pkg.go.dev: https://pkg.go.dev/vuln/GO-2026-6604

Credits

Daniele Ballarini