Bug 2483029 (CVE-2026-44973) - CVE-2026-44973 github.com/go-git/go-billy: Go-billy: Arbitrary file access due to path traversal vulnerability
Summary: CVE-2026-44973 github.com/go-git/go-billy: Go-billy: Arbitrary file access du...
Keywords:
Status: NEW
Alias: CVE-2026-44973
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2498958
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-05-28 23:03 UTC by OSIDB Bzimport
Modified: 2026-07-14 15:30 UTC (History)
2 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-05-28 23:03:57 UTC
Billy is an interface filesystem abstraction for Go. Prior to 5.9.0, multiple path traversal issues exist across different components of go-billy. Insufficient path sanitization and boundary enforcement may allow crafted paths (e.g., using ..) to escape intended base directories. While go-billy was not originally designed to provide a strong security boundary, some of these issues were inconsistent across some of the built-in implementations. This results in scenarios where applications relying on go-billy for some level of isolation may inadvertently expose access to unintended filesystem locations. This vulnerability is fixed in 5.9.0.


Note You need to log in before you can comment on or make changes to this bug.