Directory Creation Vulnerability in Windows Affecting Go Programming Language
CVE-2026-56857
Currently unrated
What is CVE-2026-56857?
A security vulnerability in the Go programming language on Windows allows for improper directory creation at junction points. Specifically, when operations like Root.Mkdir or Root.MkdirAll are executed, if the target is a junction pointing to an empty location, it can inadvertently create a directory at that junction target. This occurs even if the target is located outside the designated root path, presenting potential risks for unauthorized access or data manipulation. It is crucial for developers to be aware of this behavior when handling directory operations in Go, especially in conjunction environments.
Affected Version(s)
internal/syscall/windows windows 0 < 1.26.9
internal/syscall/windows windows 1.27.0-0 < 1.27.2
os windows 0 < 1.26.9
