CVE-2026-39822
Go standard library os, go 취약점
On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the final path component of the a path is a symbolic link and the path ends in /. For example, 'root.Open("symlink/")' will open "symlink" even when "symlink" is a symbolic link pointing outside of the root.
- 대응 우선순위
- 점검
- CVSS
- 7.8
- EPSS
- 0.23% 백분위 14.2% · 2026.08.02 기준
- CISA KEV
- 미등록
- 조치 기한
- -
- 공개일
- 2026.07.09