Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-56857: Go file‑creation functions can write outside intended folder on Windows
CVE-2026-56857 · published 1 day ago
Summary
On Windows, the Go language's standard library functions that create directories (Root.Mkdir and Root.MkdirAll) can be tricked by a special shortcut (junction) to place a new folder outside the designated root directory. This means a program that assumes it is confined to a specific area could unintentionally modify other parts of the file system. Upgrade to a Go version where the fix is applied or avoid using these functions on paths that may contain junctions.
What to do
- Update stdlib to version 1.27.2.
- Update go standard library os to version 1.26.9 or later.
- Update go standard library internal/syscall/windows to version 1.26.9 or later.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | go standard library | os | < 1.26.9 |
| – | go standard library | internal/syscall/windows | < 1.26.9 |
| Go | – | stdlib |
>= 1.27.0-0, < 1.27.2 Fix: upgrade to 1.27.2
|
| Ubuntu:14.04:LTS | canonical | golang-1.10 | All versions |
| Ubuntu:16.04:LTS | canonical | golang-1.6 | All versions |
| Ubuntu:Pro:16.04:LTS | canonical | golang-1.13 | All versions |
| Ubuntu:Pro:16.04:LTS | canonical | golang-1.18 | All versions |
| Ubuntu:Pro:18.04:LTS | canonical | golang-1.16 | All versions |
| Ubuntu:18.04:LTS | canonical | golang-1.8 | All versions |
| Ubuntu:18.04:LTS | canonical | golang-1.9 | All versions |
| Ubuntu:20.04:LTS | canonical | golang-1.14 | All versions |
| Ubuntu:20.04:LTS | canonical | golang-1.20 | All versions |
| Ubuntu:20.04:LTS | canonical | golang-1.21 | All versions |
| Ubuntu:20.04:LTS | canonical | golang-1.22 | All versions |
| Ubuntu:22.04:LTS | canonical | golang-1.17 | All versions |
| Ubuntu:22.04:LTS | canonical | golang-1.23 | All versions |
| Ubuntu:22.04:LTS | canonical | golang-1.24 | All versions |
| Ubuntu:26.04:LTS | canonical | golang-1.25 | All versions |
| Ubuntu:26.04:LTS | canonical | golang-1.26 | All versions |
Original advisory text
Root.Mkdir(All) can follow junctions out of the root on Windows in os
On Windows, when the target of Root.Mkdir or Root.MkdirAll is a junction pointing to an empty location, the operation can create a directory at the junction target even when that target is located outside the root. This only applies to operations where the last path component is a junction (path/to/junction, but not path/junction/target).
References
- https://go.dev/cl/847305
- https://go.dev/issue/81739
- https://pkg.go.dev/vuln/GO-2026-6604
- https://groups.google.com/g/golang-announce/c/U2fTuyDJznI
- https://ubuntu.com/security/CVE-2026-56857 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-56857 Third Party Advisory
- https://www.openwall.com/lists/oss-security/2026/10/08/9 Third Party Advisory
- https://github.com/golang/go/issues/81739 Third Party Advisory
Internet-facing
3 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically
- Gives an attacker full control
Severity
9.8
Critical
Type
CWE-1386Insecure Operation on Windows Junction / Mount Point
Timeline
Published8 Oct 2026
Updated10 Oct 2026
First seen8 Oct 2026
Track software like this
Free during beta