{"id":"AZL-92303","summary":"CVE-2026-39822 affecting package golang for versions less than 1.25.12-1","details":"On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the final path component of the a path is a symbolic link and the path ends in /. For example, 'root.Open(\"symlink/\")' will open \"symlink\" even when \"symlink\" is a symbolic link pointing outside of the root.","modified":"2026-08-30T05:26:50Z","published":"2026-07-08T17:17:21Z","upstream":["CVE-2026-39822"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-39822"}],"affected":[{"package":{"name":"golang","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/golang"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.25.12-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-92303.json"}}],"schema_version":"1.9.0"}