CVE-2026-27139Disclosure(golang / go)

LOWCVSS 2.5 · LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch golang go systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

On Unix platforms, when listing the contents of a directory using File.ReadDir or File.Readdir the returned FileInfo could reference a file outside of the Root in which the File was opened. The impact of this escape is limited to reading metadata provided by lstat from arbitrary locations on the filesystem without permitting reading or writing files outside the root.

0.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • go

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 2 mentions (2026-03-07); latest day: 1
  • 6 total mentions across 4 days

Affected systems

Vendors
Products
go

1 version affected across 1 product

Deep dive

Activity timeline6 mentions / 4d
01122Mentions · 2026-03-06: 1Mentions · 2026-03-07: 2Mentions · 2026-03-09: 2Mentions · 2026-03-20: 1Patch / Workaround · 2026-03-06: 1Patch / Workaround · 2026-03-09: 1Technical Details · 2026-03-07: 2Technical Details · 2026-03-09: 203-0603-0703-0903-20
Signal classification3 categories
Disclosure
350.0%
Patch
233.3%
General
116.7%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-03-061
Patch1
2026-03-072
Disclosure2
2026-03-092
Disclosure1Patch1
2026-03-201
General1
Full discourse6 posts
  • Go@golang
    Patch

    🌟 Go 1.26.1 and 1.25.8 are released! 🔐 Security: Includes security fixes for the standard library (CVE-2026-25679, CVE-2026-27137, CVE-2026-27138, CVE-2026-27139, CVE-2026-27142). 🗣 Announcement: https://groups.google.com/g/golang-announce/c/EdhZqrQ98hk/m/41DopX_WAAAJ ⬇️ Download: https://go.dev/dl/#go1.26.1 #golang https://t.co/20adn9vysT

    Post summary

    The tweet announces the Go 1.26.1/1.25.8 release, noting that it contains security fixes for several CVEs, but does not provide PoC, exploit, or vulnerability details.

    511196015260.9K
    207.1K followersView on X
  • Open Source Security mailing list@oss_security
    Disclosure

    Go CVE-2026-27142: html/template: URLs in meta content attribute actions are not escaped CVE-2026-25679: net/url: reject IPv6 literal not at start of host CVE-2026-27139: os: FileInfo can escape from a Root

    Post summary

    The text lists three new Go CVEs with brief technical descriptions, serving as a disclosure announcement without additional exploit or patch information.

    00010241
    4.4K followersView on X
  • Lambda Watchdog@LambdaWatchdog
    General

    🔍 Lambda Watchdog detected that CVE-2026-27139 is no longer present in latest AWS Lambda base image scans. https://github.com/aws/aws-lambda-base-images/issues/438 #AWS #Lambda #Security #CVE #DevOps #SecOps

    Post summary

    The tweet informs that CVE-2026-27139 has been removed from recent AWS Lambda base images, with no additional exploitation or patch details.

    0000031
    31 followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    🔒 Urgent: #openSUSE Tumbleweed patches 3 critical Go vulns (CVE-2026-25679, CVE-2026-27139, CVE-2026-27142). Update go1.25 to 1.25.8-1.1 now to mitigate crypto bypass, path traversal & HTTP DoS attacks. Read more: 👉 https://tinyurl.com/ym2ahjs8 #Security https://t.co/PLdX24JVrj

    Post summary

    The post announces that openSUSE Tumbleweed has patched three critical Go vulnerabilities and directs users to upgrade to mitigate crypto bypass, path traversal, and HTTP DoS risks.

    0000059
    1.3K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-27139 On Unix platforms, when listing the contents of a directory using File.ReadDir or File.Readdir the returned FileInfo could reference a file outside of the Root in whi… https://www.cve.org/CVERecord?id=CVE-2026-27139

    Post summary

    An announcement of CVE‑2026‑27139 reveals a directory‑listing bug on Unix that may expose files beyond the root, but does not provide PoC, exploit, or remediation details.

    0000090
    56.6K followersView on X
  • Lambda Watchdog@LambdaWatchdog
    Disclosure

    🚨 New UNKNOWN CVE detected in AWS Lambda 🚨 CVE-2026-27139 impacts stdlib in 27 Lambda base images. Details: https://github.com/aws/aws-lambda-base-images/issues/438 More: https://lambdawatchdog.com/ #AWS #Lambda #CVE #CloudSecurity #Serverless

    Post summary

    A new CVE (CVE-2026-27139) affecting the stdlib in AWS Lambda base images has been reported, with details available in a GitHub issue and on Lambdawatchdog.

    0000035
    31 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appgolanggo---
Appgolanggo1.26.0--

Explore more