Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-56857: Go file‑creation functions can write outside intended folder on Windows

CVE-2026-56857 · published 1 day ago
Summary

On Windows, the Go language's standard library functions that create directories (Root.Mkdir and Root.MkdirAll) can be tricked by a special shortcut (junction) to place a new folder outside the designated root directory. This means a program that assumes it is confined to a specific area could unintentionally modify other parts of the file system. Upgrade to a Go version where the fix is applied or avoid using these functions on paths that may contain junctions.

What to do
  • Update stdlib to version 1.27.2.
  • Update go standard library os to version 1.26.9 or later.
  • Update go standard library internal/syscall/windows to version 1.26.9 or later.
Affected software
Ecosystem VendorProductAffected versions
– go standard library os < 1.26.9
– go standard library internal/syscall/windows < 1.26.9
Go – stdlib >= 1.27.0-0, < 1.27.2
Fix: upgrade to 1.27.2
Ubuntu:14.04:LTS canonical golang-1.10 All versions
Ubuntu:16.04:LTS canonical golang-1.6 All versions
Ubuntu:Pro:16.04:LTS canonical golang-1.13 All versions
Ubuntu:Pro:16.04:LTS canonical golang-1.18 All versions
Ubuntu:Pro:18.04:LTS canonical golang-1.16 All versions
Ubuntu:18.04:LTS canonical golang-1.8 All versions
Ubuntu:18.04:LTS canonical golang-1.9 All versions
Ubuntu:20.04:LTS canonical golang-1.14 All versions
Ubuntu:20.04:LTS canonical golang-1.20 All versions
Ubuntu:20.04:LTS canonical golang-1.21 All versions
Ubuntu:20.04:LTS canonical golang-1.22 All versions
Ubuntu:22.04:LTS canonical golang-1.17 All versions
Ubuntu:22.04:LTS canonical golang-1.23 All versions
Ubuntu:22.04:LTS canonical golang-1.24 All versions
Ubuntu:26.04:LTS canonical golang-1.25 All versions
Ubuntu:26.04:LTS canonical golang-1.26 All versions
Original advisory text
Root.Mkdir(All) can follow junctions out of the root on Windows in os
On Windows, when the target of Root.Mkdir or Root.MkdirAll is a junction pointing to an empty location, the operation can create a directory at the junction target even when that target is located outside the root. This only applies to operations where the last path component is a junction (path/to/junction, but not path/junction/target).
Fix within
Internet-facing 3 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker full control
Severity
9.8 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-1386Insecure Operation on Windows Junction / Mount Point
Timeline
Published8 Oct 2026
Updated10 Oct 2026
First seen8 Oct 2026
Sources
CVE-2026-56857 · MITRE
GO-2026-6604 · OSV
Track software like this
Free during beta