HashiCorp go-getter versions before 1.8.10 and go-getter/v2 versions before 2.2.5 are vulnerable to path traversal during S3 and GCS directory downloads, which may allow files to be written outside the requested destination. This vulnerability (CVE-2026-19585) is fixed in go-getter 1.8.10 and go-getter/v2 2.2.5.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 08 Oct 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Hashicorp
Hashicorp shared Library |
|
| Vendors & Products |
Hashicorp
Hashicorp shared Library |
Thu, 08 Oct 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | HashiCorp go-getter versions before 1.8.10 and go-getter/v2 versions before 2.2.5 are vulnerable to path traversal during S3 and GCS directory downloads, which may allow files to be written outside the requested destination. This vulnerability (CVE-2026-19585) is fixed in go-getter 1.8.10 and go-getter/v2 2.2.5. | |
| Title | Go-getter vulnerable to a path traversal in S3/GCS directory download handling | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: HashiCorp
Published:
Updated: 2026-10-08T19:11:51.256Z
Reserved: 2026-08-11T23:43:34.691Z
Link: CVE-2026-19585
No data.
Status : Awaiting Analysis
Published: 2026-10-08T16:17:10.490
Modified: 2026-10-08T21:07:57.460
Link: CVE-2026-19585
No data.
OpenCVE Enrichment
Updated: 2026-10-08T20:00:02Z
Weaknesses