CVE-2026-56860

ADVISORY - golang

Summary

Previously, resolving relative paths containing parent directory ('..') segments performed string conversions and buffer rewrites on each step, resulting in quadratic time complexity and high memory allocation overhead.

Now, path resolution operates on a byte buffer using index-based backtracking for '..' segments, eliminating the quadratic time complexity and significantly reducing memory allocations.

Common Weakness Enumeration (CWE)


GoLang

CREATED

UPDATED

ADVISORY IDGO-2026-6218
EXPLOITABILITY SCORE

-

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
RATING UNAVAILABLE FROM ADVISORY
PackageTypeOS NameOS VersionAffected RangesFix Versions
stdlibgolang-->=1.26.0-0,<1.26.61.26.6
stdlibgolang--<1.25.131.25.13
stdlibgolang-->=1.27.0-0,<1.27.0-rc.31.27.0-rc.3

Severity and metrics

No CVSS data available from this advisory.