{"id":"CVE-2026-44973","aliases":["GHSA-qw64-3x98-g7q2","GO-2026-5597"],"url":"https://o3.security/vulnerability/CVE-2026-44973","summary":"Billy: Path traversal vulnerabilities","details":"Billy is an interface filesystem abstraction for Go. Prior to 5.9.0, multiple path traversal issues exist across different components of go-billy. Insufficient path sanitization and boundary enforcement may allow crafted paths (e.g., using ..) to escape intended base directories. While go-billy was not originally designed to provide a strong security boundary, some of these issues were inconsistent across some of the built-in implementations. This results in scenarios where applications relying on go-billy for some level of isolation may inadvertently expose access to unintended filesystem locations. This vulnerability is fixed in 5.9.0.","published":"2026-05-28T21:26:14.734Z","modified":"2026-08-12T18:48:01.031604278Z","cvss":{"score":8.1,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"},"epss":{"score":0.0031,"percentile":0.23548,"asOf":"2026-08-12"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/go-git/go-billy/v5","fixedVersion":"5.9.0"},{"ecosystem":"Go","name":"github.com/go-git/go-billy/v6","fixedVersion":"6.0.0-alpha.1"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/44xxx/CVE-2026-44973.json"},{"type":"ADVISORY","url":"https://github.com/go-git/go-billy/security/advisories/GHSA-qw64-3x98-g7q2"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-44973"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T18:48:01.031604278Z"}}