CVE-2026-32282Patch(golang / go)

LOWCVSS 6.4 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch golang go systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

On Linux, if the target of Root.Chmod is replaced with a symlink while the chmod operation is in progress, Chmod can operate on the target of the symlink, even when the target lies outside the root. The Linux fchmodat syscall silently ignores the AT_SYMLINK_NOFOLLOW flag, which Root.Chmod uses to avoid symlink traversal. Root.Chmod checks its target before acting and returns an error if the target is a symlink lying outside the root, so the impact is limited to cases where the target is replaced with a symlink between the check and operation.

0.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-59

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • go

Threat summary

  • Patch or workaround signal is available
  • 7 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 2 classified signals
  • Peaked 4d ago at 3 mentions (2026-04-08); latest day: 1
  • 7 total mentions across 5 days

Affected systems

Vendors
Products
go

Deep dive

Activity timeline7 mentions / 5d
01223Mentions · 2026-04-08: 3Mentions · 2026-04-17: 1Mentions · 2026-04-18: 1Mentions · 2026-05-05: 1Mentions · 2026-06-21: 1Patch / Workaround · 2026-04-17: 1Patch / Workaround · 2026-04-18: 1Patch / Workaround · 2026-05-05: 1Technical Details · 2026-04-08: 1Technical Details · 2026-05-05: 1Technical Details · 2026-06-21: 104-0804-1704-1805-0506-21
Signal classification3 categories
Patch
342.9%
Disclosure
228.6%
General
228.6%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-04-083
Disclosure2General1
2026-04-171
Patch1
2026-04-181
Patch1
2026-05-051
Patch1
2026-06-211
General1
Full discourse7 posts
  • HeroDevs@herodevs
    Patch

    🚨 Never-Ending Support for Ingress NGINX is here 🚨 With Ingress NGINX reaching end of life, every unresolved CVE in your ingress layer becomes a security, compliance, and operational problem — and ingress controllers sit directly in the request path for production traffic. NES for Ingress NGINX is a drop-in replacement for 1.15.1 that resolves CVE-2026-32282 plus four additional dependency vulnerabilities across Helm and gomarkdown, including two High-severity Helm issues (CVSS 8.4). If your team is planning a Gateway API migration but can't finish it before risk and compliance deadlines hit, this is the bridge. #Kubernetes #IngressNGINX #CVE #DevSecOps #OpenSource #EOL

    Post summary

    The message announces a new patch (NES) for Ingress NGINX that resolves CVE-2026-32282 and related dependencies, emphasizing remediation rather than exploit details.

    01022402
    2.7K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    General

    🛡️ CVE-2026-32282 no Rocky Linux 10: o yggdrasil-worker-package-manager tem uma falha onde Root.Chmod pode seguir symlinks fora da raiz. Saiba mais: -> http://tinyurl.com/kufbpen5 #RockyLinux https://t.co/p5iZ0MkDX7

    Post summary

    The tweet announces CVE-2026-32282 affecting Rocky Linux 10, noting a root-chmod symlink traversal flaw in yggdrasil-worker-package-manager, but provides only basic details with no mention of patches, exploitation, or PoC.

    1000175
    1.5K followersView on X
  • Lambda Watchdog@LambdaWatchdog
    Patch

    🔍 Lambda Watchdog detected that CVE-2026-32282 is no longer present in latest AWS Lambda base image scans. https://github.com/aws/aws-lambda-base-images/issues/459 #AWS #Lambda #Security #CVE #DevOps #SecOps

    Post summary

    The tweet indicates that CVE‑2026‑32282 has been removed from the latest AWS Lambda base image scans, suggesting that the vulnerability has been patched.

    0000044
    31 followersView on X
  • Lambda Watchdog@LambdaWatchdog
    Patch

    🔍 Lambda Watchdog detected that CVE-2026-32282 is no longer present in latest AWS Lambda base image scans. https://github.com/aws/aws-lambda-base-images/issues/459 #AWS #Lambda #Security #CVE #DevOps #SecOps

    Post summary

    AWS has removed CVE‑2026‑32282 from its latest Lambda base images, as reported by Lambda Watchdog and the GitHub issue, indicating that the vulnerability has been patched.

    0000019
    34 followersView on X
  • Lambda Watchdog@LambdaWatchdog
    Disclosure

    🚨 New UNKNOWN CVE detected in AWS Lambda 🚨 CVE-2026-32282 impacts stdlib in 26 Lambda base images. Details: https://github.com/aws/aws-lambda-base-images/issues/459 More: https://lambdawatchdog.com/ #AWS #Lambda #CVE #CloudSecurity #Serverless

    Post summary

    A new CVE (CVE‑2026‑32282) affecting the standard library in 26 AWS Lambda base images was reported, with references to a GitHub issue and a monitoring website, but no proof of exploitation or mitigations are provided.

    0000039
    31 followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-32282 🚨 Risk Level: Unknown 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-32282 #CVE-2026-32282 #CVE #CyberSecurity #InfoSec https://t.co/sI97iDcjp3

    Post summary

    The tweet simply announces the existence of CVE-2026-32282 with no additional technical details, PoCs, exploits, or mitigation information.

    0000037
    123 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-32282 On Linux, if the target of Root.Chmod is replaced with a symlink while the chmod operation is in progress, Chmod can operate on the target of the symlink, even when t… https://www.cve.org/CVERecord?id=CVE-2026-32282

    Post summary

    The excerpt is a brief disclosure of CVE-2026-32282, describing a Linux chmod issue involving symlinks with no mention of PoC, exploits, patch, or active attacks.

    00000121
    57.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgolanggo---

Explore more