{"id":"CVE-2021-23772","aliases":["GHSA-jcxc-rh6w-wf49","GO-2022-0272"],"url":"https://o3.security/vulnerability/CVE-2021-23772","summary":"Link Following in Iris","details":"This affects all versions of package github.com/kataras/iris; all versions of package github.com/kataras/iris/v12. The unsafe handling of file names during upload using UploadFormFiles method may enable attackers to write to arbitrary locations outside the designated target folder.","published":"2021-12-24T12:15:07.697Z","modified":"2026-07-08T05:57:08.178918758Z","cvss":{"score":8.8,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},"epss":{"score":0.01822,"percentile":0.76785,"asOf":"2026-08-23"},"cisaKev":null,"exploitsKnown":2,"affectedPackages":[{"ecosystem":"Go","name":"github.com/kataras/iris/v12","fixedVersion":"12.2.0-alpha8"},{"ecosystem":"Go","name":"github.com/kataras/iris","fixedVersion":null}],"fix":{"url":"https://github.com/kataras/iris/commit/e213dba0d32ff66653e0ef124bc5088817264b08","label":"kataras/iris@e213dba"},"references":[{"type":"FIX","url":"https://github.com/kataras/iris/commit/e213dba0d32ff66653e0ef124bc5088817264b08"},{"type":"FIX","url":"https://snyk.io/vuln/SNYK-GOLANG-GITHUBCOMKATARASIRIS-2325169"},{"type":"FIX","url":"https://snyk.io/vuln/SNYK-GOLANG-GITHUBCOMKATARASIRISV12-2325170"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T05:57:08.178918758Z"}}