VDB
GO-2026-4979
GO-2026-4979
PUBLISHED
Invoking "go tool pack" does not sanitize output paths in cmd/go
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| wolfi | terraform-provider-pagerduty | 0, 0, 0 |
| chainguard | policy-bot-fips | 0, 0 |
| chainguard | crossplane-provider-aws-lambda-fips | 0 |
| wolfi | nri-nginx | 0, 0, 0 |
| chainguard | knative-operator-fips-1.21 | 0, 0 |
| chainguard | tigera-operator-1.42 | 0, 0 |
| chainguard | cyberark-secrets-provider-for-k8s | 0 |
| chainguard | kubernetes-dns-node-cache-fips | 0, 0 |
| chainguard | tekton-pipelines-fips-1.11 | 0, 0 |
| chainguard | boring-registry-fips | 0, 0 |
| chainguard | rancher-security-scan-fips-0.9 | 0, 0 |
| wolfi | manifest-tool | 0, 0, 0 |
| chainguard | go-fips-md5-1.24 | * |
| chainguard | gitlab-cng-18.11 | 0 |
| chainguard | step-ca | 0, 0 |
| chainguard | zarf | 0, 0 |
| chainguard | nri-memcached-fips | 0, 0 |
| chainguard | crossplane-provider-azure-powerbidedicated | 0 |
| chainguard | aws-fsx-csi-driver-fips | 0, 0 |
| chainguard | virt-api-1.6 | 0, 0 |
…and 1885 more
Timeline
- May 7, 2026 CVE Published
- Aug 31, 2026 CVE Updated