Directory Creation Vulnerability in Windows Affecting Go Programming Language
CVE-2026-56857

Currently unrated

Key Information:

Vendor
CVE Published:
8 October 2026

What is CVE-2026-56857?

A security vulnerability in the Go programming language on Windows allows for improper directory creation at junction points. Specifically, when operations like Root.Mkdir or Root.MkdirAll are executed, if the target is a junction pointing to an empty location, it can inadvertently create a directory at that junction target. This occurs even if the target is located outside the designated root path, presenting potential risks for unauthorized access or data manipulation. It is crucial for developers to be aware of this behavior when handling directory operations in Go, especially in conjunction environments.

Affected Version(s)

internal/syscall/windows windows 0 < 1.26.9

internal/syscall/windows windows 1.27.0-0 < 1.27.2

os windows 0 < 1.26.9

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Daniele Ballarini
.