{"schema_version":"1.7.5","id":"GHSA-qw64-3x98-g7q2","published":"2026-05-14T18:25:38Z","modified":"2026-07-24T19:11:31.631883906Z","aliases":["CVE-2026-44973","GO-2026-5597"],"related":["CGA-w99c-3vgh-qrg5"],"summary":"go-billy has path traversal vulnerabilities","details":"### Impact\nMultiple path traversal issues exist across different components of `go-billy`. Insufficient path sanitization and boundary enforcement may allow crafted paths (e.g., using `..`) to escape intended base directories.\n\nWhile go-billy was not originally designed to provide a strong security boundary, some of these issues were inconsistent across some of the built-in implementations. This results in scenarios where applications relying on `go-billy` for some level of isolation may inadvertently expose access to unintended filesystem locations.\n\nThe `osfs.ChrootOS` implementation is notably affected by this vulnerability and is now deprecated in `v5`, removed at `v6`. Users are recommended to move on to `osfs.BoundOS` instead: `osfs.New(path, WithBoundOS())`.\n\nUsers requiring stronger security boundary enforcement are recommended to upgrade to `v6`, where the `osfs` implementation are backed by the [traversal-resistant](https://go.dev/blog/osroot) primitive [os.Root](https://pkg.go.dev/os#Root).\n\n### Patches\nUsers should upgrade to a patched version in order to mitigate this vulnerability. Versions prior to `v5` are likely to be affected, users are recommended to upgrade to a supported `go-billy` version.\n\n### Credits\nThanks to @faran66 and @vnykmshr for finding and separately reporting this issue privately to the go-git project. 🙇","affected":[{"package":{"name":"github.com/go-git/go-billy/v5","ecosystem":"Go","purl":"pkg:golang/github.com/go-git/go-billy/v5"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"5.9.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-qw64-3x98-g7q2/GHSA-qw64-3x98-g7q2.json"}},{"package":{"name":"github.com/go-git/go-billy/v6","ecosystem":"Go","purl":"pkg:golang/github.com/go-git/go-billy/v6"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"6.0.0-alpha.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-qw64-3x98-g7q2/GHSA-qw64-3x98-g7q2.json"}}],"references":[{"type":"WEB","url":"https://github.com/go-git/go-billy/security/advisories/GHSA-qw64-3x98-g7q2"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-44973"},{"type":"PACKAGE","url":"https://github.com/go-git/go-billy"},{"type":"WEB","url":"https://github.com/go-git/go-billy/releases/tag/v5.9.0"},{"type":"WEB","url":"https://github.com/go-git/go-billy/releases/tag/v6.0.0-alpha.1"}],"database_specific":{"cwe_ids":["CWE-22"],"github_reviewed":true,"github_reviewed_at":"2026-05-14T18:25:38Z","nvd_published_at":"2026-05-28T22:16:59Z","severity":"HIGH"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"}]}