Go GoLang Go

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in GoLang Go.

GoLang Go EOL Dates

Ensure that you are using a supported version of GoLang Go. Here are some end of life, and end of support dates for GoLang Go.

Release EOL Date Status
1.27 -
Active

1.26 -
Active

1.25 August 19, 2026
EOL

GoLang Go 1.25 became EOL in 2026.

1.24 February 10, 2026
EOL

GoLang Go 1.24 became EOL in 2026.

1.23 August 12, 2025
EOL

GoLang Go 1.23 became EOL in 2025.

1.22 February 11, 2025
EOL

GoLang Go 1.22 became EOL in 2025.

1.21 August 13, 2024
EOL

GoLang Go 1.21 became EOL in 2024.

1.20 February 6, 2024
EOL

GoLang Go 1.20 became EOL in 2024.

1.19 September 6, 2023
EOL

GoLang Go 1.19 became EOL in 2023.

1.18 February 1, 2023
EOL

GoLang Go 1.18 became EOL in 2023.

1.17 August 2, 2022
EOL

GoLang Go 1.17 became EOL in 2022.

1.16 March 15, 2022
EOL

GoLang Go 1.16 became EOL in 2022.

1.15 August 16, 2021
EOL

GoLang Go 1.15 became EOL in 2021.

1.14 February 16, 2021
EOL

GoLang Go 1.14 became EOL in 2021.

1.13 August 11, 2020
EOL

GoLang Go 1.13 became EOL in 2020.

1.12 February 25, 2020
EOL

GoLang Go 1.12 became EOL in 2020.

1.11 September 3, 2019
EOL

GoLang Go 1.11 became EOL in 2019.

1.10 February 25, 2019
EOL

GoLang Go 1.10 became EOL in 2019.

By the Year

In 2026 there have been 30 vulnerabilities in GoLang Go with an average score of 7.1 out of ten. Last year, in 2025 Go had 9 security vulnerabilities published. That is, 21 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.55.




Year Vulnerabilities Average Score
2026 30 7.09
2025 9 6.54
2024 7 8.37
2023 35 7.56
2022 30 7.20
2021 17 7.04
2020 13 6.72
2019 5 7.85
2018 5 7.90

It may take a day or so for new Go vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent GoLang Go Security Vulnerabilities

Go HTTP/2 SETTINGS Frame DoS Excessive CPU
CVE-2026-78669 - October 08, 2026

A malicious HTTP/2 peer can cause excessive CPU consumption in the client or server by opening a large number of streams and then sending many small SETTINGS frames containing SETTINGS_INITIAL_WINDOW_SIZE values.

Go http.Transport CONNECT Body Desync Causing Cross-User Response Poisoning
CVE-2026-56866 - October 08, 2026

When http.Transport sends an HTTP/1 CONNECT request with a non-empty Request.Body, it writes the body directly to the connection without framing after the request headers. If the server rejects the CONNECT request with a non-2xx keep-alive response, Transport returns the connection to the idle pool. Because CONNECT requests do not have a request body, the server may interpret the trailing body bytes as a subsequent pipelined HTTP/1.1 request on the connection, leaving the pooled connection desynchronized and causing the next caller that reuses it to read the response to the injected request. In reverse proxies (including httputil.ReverseProxy) that forward CONNECT requests through a shared Transport, this can lead to cross-user response poisoning.

Windows Go Mkdir Junction Traversal (CVE-2026-56857)
CVE-2026-56857 - October 08, 2026

On Windows, when the target of Root.Mkdir or Root.MkdirAll is a junction pointing to an empty location, the operation can create a directory at the junction target even when that target is located outside the root. This only applies to operations where the last path component is a junction (path/to/junction, but not path/junction/target).

Go net/http HTTP/2 Trailer Header Memory Exhaustion
CVE-2026-78659 - October 08, 2026

When "Trailer" headers are sent by a client, the HTTP server internally uses the header values to populate the Request.Trailer map passed to the server handler. Because Request.Trailer is a map, each entry incurs memory overhead. For HTTP/2 servers, a malicious client can exploit this by sending a "Trailer" header that declares a large number of fields, causing the server to allocate a disproportionate amount of memory while bypassing Server.MaxHeaderValueCount and Server.MaxHeaderBytes limits. This exploit is not applicable for HTTP/1 servers, which do not support multiplexing a large number of requests over one TCP connection, and whose Server.MaxHeaderBytes are calculated differently.

Go cmd/go Module Injection via bogus golang.org/fips140 (<=1.27.1)
CVE-2026-94444 - October 08, 2026

Previously, a user operating inside of a malicious Go project that defines a bogus golang.org/fips140 and operates a malicious GOMODPROXY the user chooses to connect to can serve an arbitrary module in its place. We now unpack the trusted ziphash for the bundled golang.org/fips140 module and construct its entry in the GOMODCACHE such that it can be verified by the toolchain.

Go cmd/go Checksum Bypass (Go <1.26.9, 1.27.0-1.27.2)
CVE-2026-94447 - October 08, 2026

Previously, a user operating inside of a malicious Go project that defines a bogus golang.org/toolchain go.sum entry and operates a malicious GOMODPROXY the user chooses to use can bypass the intended checksum. We now ensure that golang.org/toolchain always goes to the network for the canonical checksum.

Go net/url quadratic path resolution DoS before 1.27.0-rc.3
CVE-2026-56860 5.9 - Medium - August 13, 2026

Previously, resolving relative paths containing parent directory ('..') segments performed string conversions and buffer rewrites on each step, resulting in quadratic time complexity and high memory allocation overhead. Now, path resolution operates on a byte buffer using index-based backtracking for '..' segments, eliminating the quadratic time complexity and significantly reducing memory allocations.

Inefficient Algorithmic Complexity

Go Module Auth Bypass via Malicious GOSUMDB (before 1.26.6, 1.27.0-rc.3)
CVE-2026-56864 7.5 - High - August 13, 2026

A malicious GOSUMDB was capable of serving arbitrary module content not contained within the transparency log. This attack allows for a coordinating GOPROXY and GOSUMDB to serve a client malicious module content that cannot be detected by evaluating the transparency log. In order to determine if you have been affected: rm -r go.sum go.work.sum vendor/ && go mod tidy

Improper Verification of Cryptographic Signature

Go encoding/asn1 Recursion Cap 1.25.12 to Prevent Stack Exhaustion
CVE-2026-33818 7.5 - High - August 13, 2026

Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures.

Resource Exhaustion

Go net/http Unencrypted HTTP/2 Preface Read Skips ReadHeaderTimeout (<1.25.13, 1.26.0<1.26.6, 1.27.0
CVE-2026-56853 7.5 - High - August 13, 2026

When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client preface. ReadHeaderTimeout is unexpectedly not being applied when doing this.

Allocation of Resources Without Limits or Throttling

Go cmd/go GOSUMDB Bypass via Malicious GOPROXY (1.27.0-rc.3)
CVE-2026-56865 8.4 - High - August 13, 2026

A malicious GOPROXY was previously capable of forging up to two sumdb tiles that allow for a requested module to bypass the GOSUMDB check and persist attacker-controlled module content to a local Go module cache. This attack allows for a malicious GOPROXY to serve malicious module content that cannot be detected by evaluating the transparency log. All tiles are now correctly verified against their parents. In order to determine if you have been affected: rm -r go.sum go.work.sum vendor/ && go mod tidy

Improper Verification of Cryptographic Signature

Go os Root symlink traversal before 1.27 (v1.25.12 & 1.26 <1.26.5)
CVE-2026-39822 7.8 - High - July 08, 2026

On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the final path component of the a path is a symbolic link and the path ends in /. For example, 'root.Open("symlink/")' will open "symlink" even when "symlink" is a symbolic link pointing outside of the root.

Symlink following

High CPU Overuse via Invalid MIME Header in Go mime before 1.25.11/1.26.4
CVE-2026-42504 7.5 - High - June 02, 2026

Decoding a maliciously-crafted MIME header containing many invalid encoded-words can consume excessive CPU.

Inefficient Algorithmic Complexity

Go net/mail 1.25.x-1.26.3: ParseAddress/Date CPU/Memory Exhaustion
CVE-2026-39820 7.5 - High - May 07, 2026

Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion and memory allocations.

Unchecked Input for Loop Condition

GO cmd/go Validation Bypass for Module Checksum in 1.25.10/1.26.2
CVE-2026-42501 7.5 - High - May 07, 2026

A malicious module proxy can exploit a flaw in the go command's validation of module checksums to bypass checksum database validation. This vulnerability affects any user using an untrusted module proxy (GOMODPROXY) or checksum database (GOSUMDB). A malicious module proxy can serve altered versions of the Go toolchain. When selecting a different version of the Go toolchain than the currently installed toolchain (due to the GOTOOLCHAIN environment variable, or a go.work or go.mod with a toolchain line), the go command will download and execute a toolchain provided by the module proxy. A malicious module proxy can bypass checksum database validation for this downloaded toolchain. Since this vulnerability affects the security of toolchain downloads, setting GOTOOLCHAIN to a fixed version is not sufficient. You must upgrade your base Go toolchain. The go tool always validates the hash of a toolchain before executing it, so fixed versions will refuse to execute any cached, altered versions of the toolchain. The go tool trusts go.sum files to contain accurate hashes of the current module's dependencies. A malicious proxy exploiting this vulnerability to serve an altered module will have caused an incorrect hash to be recorded in the go.sum. Users who have configured a non-trusted GOPROXY can determine if they have been affected by running "rm go.sum ; go mod tidy ; go mod verify", which will revalidate all dependencies of the current module. The specific flaw in more detail: The go command consults the checksum database to validate downloaded modules, when a module is not listed in the go.sum file. It verifies that the module hash reported by the checksum database matches the hash of the downloaded module. If, however, the checksum database returns a successful response that contains no entry for the module, the go command incorrectly permitted validation to succeed. A module proxy may mirror or proxy the checksum database, in which case the go command will not connect to the checksum database directly. Checksums reported by the checksum database are cryptographically signed, so a malicious proxy cannot alter the reported checksum for a module. However, a proxy which returns an empty checksum response, or a checksum response for an unrelated module, could cause the go command to proceed as if a downloaded module has been validated.

Improper Verification of Cryptographic Signature

Go Toolchain Pack Subcmd Arbitrary File Write (1.251.26.2)
CVE-2026-39817 5.9 - Medium - May 07, 2026

The "go tool pack" subcommand (usually used only by the compiler as an internal tool with known-good inputs) does not sanitize output filenames. Extracting a malicious archive file with the "pack" subcommand can write files to arbitrary locations on the filesystem.

Go toolchain cmd/go 1.25.10, 1.26.3: temp file overwrite
CVE-2026-39819 5.3 - Medium - May 07, 2026

The "go bug" command writes to two files with predictable names in the system temporary directory (for example, "/tmp"). An attacker with access to the temporary directory can create a symlink in one of these names, causing "go bug" to overwrite the target of the symlink.

Go html/template <script> type attr escape flaw before 1.25.10 & <1.26.3
CVE-2026-39826 6.1 - Medium - May 07, 2026

If a trusted template author were to write a <script> tag containing an empty 'type' attribute or a 'type' attribute with an ASCII whitespace, the execution of the template would incorrectly escape any data passed into the <script> block.

Go HTTP/2 Infinity Loop from SETTINGS_MAX_FRAME_SIZE=0
CVE-2026-33814 7.5 - High - May 07, 2026

When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it receives a SETTINGS_MAX_FRAME_SIZE with a value of 0.

Unchecked Input for Loop Condition

Go crypto/x509 Intermediates DoS (<=1.26.2)
CVE-2026-32280 7.5 - High - April 08, 2026

During chain building, the amount of work that is done is not correctly limited when a large number of intermediate certificates are passed in VerifyOptions.Intermediates, which can lead to a denial of service. This affects both direct users of crypto/x509 and users of crypto/tls.

Allocation of Resources Without Limits or Throttling

SWIG cgo filename execution in Go cmd/go <1.26.2
CVE-2026-27140 9 - Critical - April 08, 2026

SWIG file names containing 'cgo' and well-crafted payloads could lead to code smuggling and arbitrary code execution at build time due to trust layer bypass.

Improper Restriction of Names for Files and Other Resources

CVE-2026-32281: DoS via Policy Map Ineff in Go crypto/x509 <1.25.9, <1.26.2
CVE-2026-32281 7.5 - High - April 08, 2026

Validating certificate chains which use policies is unexpectedly inefficient when certificates in the chain contain a very large number of policy mappings, possibly causing denial of service. This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in the system certificate pool.

Go cmd/compile 1.25.9/1.26.2 Induction Variable Underflow Vulnerability
CVE-2026-27143 9.8 - Critical - April 08, 2026

Arithmetic over induction variables in loops were not correctly checked for underflow or overflow. As a result, the compiler would allow for invalid indexing to occur at runtime, potentially leading to memory corruption.

Memory Corruption in Go Compiler (cmd/compile) <1.25.9, 1.26.0-1.26.2
CVE-2026-27144 7.1 - High - April 08, 2026

The compiler is meant to unwrap pointers which are the operands of a memory move; a no-op interface conversion prevented the compiler from making the correct determination about non-overlapping moves, potentially leading to memory corruption at runtime.

Go html/template XSS via meta content URL unescape <1.25.8, 1.26.0
CVE-2026-27142 6.1 - Medium - March 06, 2026

Actions which insert URLs into the content attribute of HTML meta tags are not escaped. This can allow XSS if the meta tag also has an http-equiv attribute with the value "refresh". A new GODEBUG setting has been added, htmlmetacontenturlescape, which can be used to disable escaping URLs in actions in the meta content attribute which follow "url=" by setting htmlmetacontenturlescape=0.

go stdlib: os ReadDir/FileInfo path escape before 1.25.8 & 1.26.1
CVE-2026-27139 2.5 - Low - March 06, 2026

On Unix platforms, when listing the contents of a directory using File.ReadDir or File.Readdir the returned FileInfo could reference a file outside of the Root in which the File was opened. The impact of this escape is limited to reading metadata provided by lstat from arbitrary locations on the filesystem without permitting reading or writing files outside the root.

CVE2025-68121: Go TLS Session Resumption with Mutated ClientCAs/RootCAs
CVE-2025-68121 9.1 - Critical - February 05, 2026

During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between the initial handshake and the resumed handshake, the resumed handshake may succeed when it should have failed. This may happen when a user calls Config.Clone and mutates the returned Config, or uses Config.GetConfigForClient. This can cause a client to resume a session with a server that it would not have resumed with during the initial handshake, or cause a server to resume a session with a client that it would not have resumed with during the initial handshake.

Improper Certificate Validation

Go cgo Comment Parsing Discrepancy Enables Code Smuggling
CVE-2025-61732 7.4 - High - February 05, 2026

A discrepancy between how Go and C/C++ comments were parsed allowed for code smuggling into the resulting cgo binary.

Code Injection

TLS 1.3 Info Disclosure in Go TLS Library (Pre 1.22)
CVE-2025-61730 5.3 - Medium - January 28, 2026

During the TLS 1.3 handshake if multiple messages are sent in records that span encryption level boundaries (for instance the Client Hello and Encrypted Extensions messages), the subsequent messages may be processed before the encryption level changes. This can cause some minor information disclosure if a network-local attacker can inject messages during the handshake.

Go cmd/go <1.25.6 Local Code Exec via Malicious Version Strings in VCS Modules
CVE-2025-68119 7 - High - January 28, 2026

Downloading and building modules with malicious version strings can cause local code execution. On systems with Mercurial (hg) installed, downloading modules from non-standard sources (e.g., custom domains) can cause unexpected code execution due to how external VCS commands are constructed. This issue can also be triggered by providing a malicious version string to the toolchain. On systems with Git installed, downloading and building modules with malicious version strings can allow an attacker to write to arbitrary files on the filesystem. This can only be triggered by explicitly providing the malicious version strings to the toolchain and does not affect usage of @latest or bare module paths.

URL Parse Allows NonIPv6 in Brackets Host Validation Flaw
CVE-2025-47912 5.3 - Medium - October 29, 2025

The Parse function permits values other than IPv6 addresses to be included in square brackets within the host component of a URL. RFC 3986 permits IPv6 addresses to be included within the host component, enclosed within square brackets. For example: "http://[::1]/". IPv4 addresses and hostnames must not appear within square brackets. Parse did not enforce this requirement.

Go TLS Conn.Handshake leaks attackersupplied ALPN data
CVE-2025-58189 5.3 - Medium - October 29, 2025

When Conn.Handshake fails during ALPN negotiation the error contains attacker controlled information (the ALPN protocols sent by the client) which is not escaped.

Go LookPath PATH bug returns execs for empty/.. input
CVE-2025-47906 6.5 - Medium - September 18, 2025

If the PATH environment variable contains paths which are executables (rather than just directories), passing certain strings to LookPath ("", ".", and ".."), can result in the binaries listed in the PATH being unexpectedly returned.

Go database/sql Scan context cancellation race condition
CVE-2025-47907 7 - High - August 07, 2025

Cancelling a query (e.g. by cancelling the context passed to one of the query methods) during a call to the Scan method of the returned Rows can result in unexpected results if other queries are being made in parallel. This can result in a race condition that may overwrite the expected results with those of another query, causing the call to Scan to return either unexpected results from the other query or an error.

Go Tool Command Exe via Untrusted VCS Repository Config
CVE-2025-4674 8.6 - High - July 29, 2025

The go command may execute unexpected commands when operating in untrusted VCS repositories. This occurs when possibly dangerous VCS configuration is present in repositories. This can happen when a repository was fetched via one VCS (e.g. Git), but contains metadata for another VCS (e.g. Mercurial). Modules which are retrieved using the go command line, i.e. via "go get", are not affected.

External Control of File Name or Path

Go StdLib OpenFile O_CREATE/O_EXCL Symlink Handling Fix
CVE-2025-0913 - June 11, 2025

os.OpenFile(path, os.O_CREATE|O_EXCL) behaved differently on Unix and Windows systems when the target path was a dangling symlink. On Unix systems, OpenFile with O_CREATE and O_EXCL flags never follows symlinks. On Windows, when the target path was a symlink to a nonexistent location, OpenFile would create a file in that location. OpenFile now always returns an error when the O_CREATE and O_EXCL flags are both set and the target path is a symlink.

insecure temporary file

Go Cert Policy Validation Bypass via VerifyOptions with ExtKeyUsageAny
CVE-2025-22874 - June 11, 2025

Calling Verify with a VerifyOptions.KeyUsages that contains ExtKeyUsageAny unintentionally disabledpolicy validation. This only affected certificate chains which contain policy graphs, which are rather uncommon.

Arbitrary code exec via CGO LDFLAGS in Go1.24rc2 (Apple ld)
CVE-2025-22867 - February 06, 2025

On Darwin, building a Go module which contains CGO can trigger arbitrary code execution when using the Apple version of ld, due to usage of the @executable_path, @loader_path, or @rpath special values in a "#cgo LDFLAGS" directive. This issue only affected go1.24rc2.

Go ParsePKCS1PrivateKey Panic on Missing CRT
CVE-2025-22865 - January 28, 2025

Using ParsePKCS1PrivateKey to parse a RSA key that is missing the CRT values would panic when verifying that the key is well formed.

Go Parse Function Stack Exhaustion via Deeply Nested Literals
CVE-2024-34155 - September 06, 2024

Calling any of the Parse functions on Go source code which contains deeply nested literals can cause a panic due to stack exhaustion.

GO Compiler Parse Panic: Stack Exhaustion via Deeply Nested //+build tags
CVE-2024-34158 - September 06, 2024

Calling Parse on a "// +build" build tag line with deeply nested expressions can cause a panic due to stack exhaustion.

Go net/http Expect:100-continue mishandling before 1.20.7 leads to DDoS
CVE-2024-24791 - July 02, 2024

The net/http HTTP/1.1 client mishandled the case where a server responds to a request with an "Expect: 100-continue" header with a non-informational (200 or higher) status. This mishandling could leave a client connection in an invalid state, where the next request sent on the connection will fail. An attacker sending a request to a net/http/httputil.ReverseProxy proxy can exploit this mishandling to cause a denial of service by sending "Expect: 100-continue" requests which elicit a non-informational response from the backend. Each such request leaves the proxy with an invalid connection, and causes one subsequent request using that connection to fail.

Go net: IsPrivate/IsLoopback fail on IPv4-mapped IPv6 addresses
CVE-2024-24790 9.8 - Critical - June 05, 2024

The various Is methods (IsPrivate, IsLoopback, etc) did not work as expected for IPv4-mapped IPv6 addresses, returning false for addresses which would return true in their traditional IPv4 forms.

Go archive/zip Improper Handling of Invalid ZIP Files (CVE-2024-24789)
CVE-2024-24789 5.5 - Medium - June 05, 2024

The archive/zip package's handling of certain types of invalid zip files differs from the behavior of most zip implementations. This misalignment could be exploited to create an zip file with contents that vary depending on the implementation reading the file. The archive/zip package now rejects files containing these errors.

CVE-2024-3566: CreateProcessBased Command Injection in Windows Apps
CVE-2024-3566 9.8 - Critical - April 10, 2024

A command inject vulnerability allows an attacker to perform command injection on Windows applications that indirectly depend on the CreateProcess function when the specific conditions are satisfied.

Go net/http ParseMultipartForm Mem Exhaustion using Long Form Lines
CVE-2023-45290 - March 05, 2024

When parsing a multipart form (either explicitly with Request.ParseMultipartForm or implicitly with Request.FormValue, Request.PostFormValue, or Request.FormFile), limits on the total size of the parsed form were not applied to the memory consumed while reading a single form line. This permits a maliciously crafted input containing very long lines to cause allocation of arbitrarily large amounts of memory, potentially leading to memory exhaustion. With fix, the ParseMultipartForm function now correctly limits the maximum size of form lines.

Go net/http Chunked Reader Vulnerability: HTTP Chunk Extension Overread
CVE-2023-39326 5.3 - Medium - December 06, 2023

A malicious HTTP sender can use chunk extensions to cause a receiver reading from a request or response body to read many more bytes from the network than are in the body. A malicious HTTP client can further exploit this to cause a server to automatically read a large amount of data (up to about 1GiB) when a handler fails to read the entire body of a request. Chunk extensions are a little-used HTTP feature which permit including additional metadata in a request or response body sent using the chunked encoding. The net/http chunked encoding reader discards this metadata. A sender can exploit this by inserting a large metadata segment with each byte transferred. The chunk reader now produces an error if the ratio of real body to encoded bytes grows too small.

Go Modules .git Suffix Causes Insecure git:// Fallback
CVE-2023-45285 7.5 - High - December 06, 2023

Using go get to fetch a module with the ".git" suffix may unexpectedly fallback to the insecure "git://" protocol if the module is unavailable via the secure "https://" and "git+ssh://" protocols, even if GOINSECURE is not set for said module. This only affects users who are not using the module proxy and are fetching modules directly (i.e. GOPROXY=off).

Go TLS RSA Timing SideChannel vulnerability before 1.20
CVE-2023-45287 7.5 - High - December 05, 2023

Before Go 1.20, the RSA based TLS key exchanges used the math/big library, which is not constant time. RSA blinding was applied to prevent timing attacks, but analysis shows this may not have been fully effective. In particular it appears as if the removal of PKCS#1 padding may leak timing information, which in turn could be used to recover session key bits. In Go 1.20, the crypto/tls library switched to a fully constant time RSA implementation, which we do not believe exhibits any timing side channels.

Side Channel Attack

Go filepath RLD path issue (1.20.11/1.21.4)
CVE-2023-45283 7.5 - High - November 09, 2023

The filepath package does not recognize paths with a \??\ prefix as special. On Windows, a path beginning with \??\ is a Root Local Device path equivalent to a path beginning with \\?\. Paths with a \??\ prefix may be used to access arbitrary locations on the system. For example, the path \??\c:\x is equivalent to the more common path c:\x. Before fix, Clean could convert a rooted path such as \a\..\??\b into the root local device path \??\b. Clean will now convert this to .\??\b. Similarly, Join(\, ??, b) could convert a seemingly innocent sequence of path elements into the root local device path \??\b. Join will now convert this to \.\??\b. In addition, with fix, IsAbs now correctly reports paths beginning with \??\ as absolute, and VolumeName correctly reports the \??\ prefix as a volume name. UPDATE: Go 1.20.11 and Go 1.21.4 inadvertently changed the definition of the volume name in Windows paths starting with \?, resulting in filepath.Clean(\?\c:) returning \?\c: rather than \?\c:\ (among other effects). The previous behavior has been restored.

Directory traversal

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for GoLang Go or by GoLang? Click the Watch button to subscribe.

GoLang
Vendor

GoLang Go
Product

subscribe