CVE-2026-35583 is a medium-severity (CVSS 5.3) Path Traversal vulnerability in gov.nsa.emissary:emissary. A fix is available for gov.nsa.emissary:emissary — see the affected versions and patch details below.
Emissary has a Path Traversal via Blacklist Bypass in Configuration API
Exploitation Status
No confirmed exploitation observed yet
- CISA assesses this as automatable — exploitation doesn’t require manual, per-target effort, which raises the odds of mass scanning and opportunistic attacks.
- CISA’s own triage has not observed active exploitation or public proof-of-concept code for this CVE as of its last assessment.
Exploitation and automatability from CISA’s SSVC triage for CVE-2026-35583.
EPSS Exploitation Probability
EPSS (Exploit Prediction Scoring System) is a daily probability model maintained by FIRST.org. It estimates the likelihood a CVE will be exploited in production environments within the next 30 days, derived from real-world threat intelligence signals.
How urgent is this, really
CVE-2026-35583 plotted by exploitation likelihood (EPSS) against impact (CVSS). The shaded corner — EPSS 50%+ and CVSS 7.0+ — is where this CVE doesn't sit, though severity or exploitability alone can still warrant action.
Where this sits among everything scored
Of 377,333 CVEs with a current EPSS score, this one falls in the < 10% band (highlighted). Real counts from FIRST.org, not a sample — log-scaled since the landscape is heavily right-skewed.
Real-World Exposure
gov.nsa.emissary:emissaryReal-time download stats are indexed for npm and PyPI packages. This vulnerability affects Maven packages — download data is not available via public APIs for these ecosystems.
Description
Summary
The configuration API endpoint (/api/configuration/{name}) validated
configuration names using a blacklist approach that checked for \, /, ..,
and trailing .. This could potentially be bypassed using URL-encoded variants,
double-encoding, or Unicode normalization to achieve path traversal and read
configuration files outside the intended directory.
Details
Vulnerable code — Configs.java (line 126)
protected static String validate(String config) {
if (StringUtils.isBlank(config) || config.contains("\\") || config.contains("/")
|| config.contains("..") || config.endsWith(".")) {
throw new IllegalArgumentException("Invalid config name: " + config);
}
return Strings.CS.appendIfMissing(config.trim(), CONFIG_FILE_ENDING);
}
Weakness
The blacklist blocked literal \, /, .., and trailing . but could
potentially miss:
- URL-encoded variants (
%2e%2e%2f) if decoded after validation - Double-encoded sequences (
%252e%252e%252f) - Unicode normalization bypasses
- The approach relies on string matching rather than canonical path resolution
Impact
- Potential read access to configuration files outside the intended config directory
- Information disclosure of sensitive configuration values
Remediation
Fixed in PR #1292, merged into release 8.39.0.
The blacklist was replaced with an allowlist regex that only permits characters
matching ^[a-zA-Z0-9._-]+$:
protected static final Pattern VALID_CONFIG_NAME = Pattern.compile("^[a-zA-Z0-9._-]+$");
protected static String validate(String config) {
if (!VALID_CONFIG_NAME.matcher(config).matches() || config.contains("..") || config.endsWith(".")) {
throw new IllegalArgumentException("Invalid config name: " + config);
}
return Strings.CS.appendIfMissing(config.trim(), CONFIG_FILE_ENDING);
}
This ensures that any character outside the allowed set — including encoded slashes, percent signs, and Unicode sequences — is rejected before the config name reaches the filesystem.
Tests were added to verify that URL-encoded (%2e%2e%2f), double-encoded
(%252e%252e%252f), and Unicode (U+002F) traversal attempts are blocked.
Workarounds
If upgrading is not immediately possible, deploy a reverse proxy or WAF rule
that rejects requests to /api/configuration/ containing encoded path traversal
sequences.
References
- PR #1292 — validate config name with an allowlist
- Original report: GHSA-wjqm-p579-x3ww
Affected Packages
| Ecosystem | Package | Vulnerable range | Fix |
|---|---|---|---|
| ☕Maven | gov.nsa.emissary:emissary | all versions | 8.39.0gov.nsa.emissary:emissary:8.39.0 |
Detection & mitigation playbook
Open-source dependencyDetect
Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for gov.nsa.emissary:emissary, including transitive dependencies — a direct dependency you never call can still pull in a vulnerable version.
Fix
Update gov.nsa.emissary:emissary to 8.39.0 or later, then make sure no transitive (indirect) dependency still pins the vulnerable range — O3 confirms CVE-2026-35583 is resolved across your whole dependency graph.
Workarounds
If you can't upgrade right away: gate or disable the affected feature, validate untrusted input at the boundary, and avoid passing attacker-controlled data into the vulnerable path. O3's runtime protection blocks exploitation in production as an interim safeguard until the upgrade lands.
How O3 protects you
O3 Security's impact-aware SCA analyses which vulnerable code paths your application actually calls, so a match like CVE-2026-35583 can be triaged on real exposure rather than presence alone.
Tailored to CVE-2026-35583. Runtime protection reduces exposure until a permanent patch is applied and verified — it complements patching, it doesn't replace it.
Frequently Asked Questions
Is CVE-2026-35583 in your dependencies?
O3 Security finds CVE-2026-35583 across Maven dependencies, including transitive ones, and its impact-aware SCA ranks findings by whether your code actually calls the vulnerable path.