VDB

CVE-2026-56860

CVE-2026-56860 PUBLISHED CVSS 5.9 MEDIUM

Reported by Go · Published August 13, 2026

Previously, resolving relative paths containing parent directory ('..') segments performed string conversions and buffer rewrites on each step, resulting in quadratic time complexity and high memory allocation overhead. Now, path resolution operates on a byte buffer using index-based backtracking for '..' segments, eliminating the quadratic time complexity and significantly reducing memory allocations.

Risk Scores

CVSS 3.1
5.9
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected Products

VendorProductVersions
Go standard librarynet/url0, 1.26.0-0, 1.27.0-0
wolfikubernetes-1.360, 0, 0
chainguardcrossplane-provider-aws-codestarnotifications0
chainguardk6-fips0
chainguardkapp-fips0
chainguardnova-fips0
chainguardnri-memcached-fips*, *
wolfiloki-3.60, 0, 0
chainguardkueue-0.150
chainguardaws-flb-firehose0
chainguardvirt-operator-fips-1.60
chainguardcrossplane-provider-aws-eks-fips0
chainguardcluster-api-1.100
chainguardnats-top0, 0
chainguardatlas-1.0-fips0
chainguardchaos-mesh*
chainguardcrossplane-provider-aws-networkfirewall-fips0
chainguardgatekeeper-3.22*
chainguardcrossplane-provider-aws-cloudformation0
chainguarddatadog-operator-fips0

…and 2810 more

Timeline

  • Aug 13, 2026 CVE Published
  • Aug 14, 2026 CVE Updated
  • Aug 15, 2026 Coalition ESS Score
  • Aug 20, 2026 Security Advisory
  • Aug 24, 2026 EPSS Score

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›