{
  "threat_severity" : "Moderate",
  "public_date" : "2026-05-07T19:41:18Z",
  "bugzilla" : {
    "description" : "cmd/go: golang: Go tool pack: Arbitrary file write via malicious archive extraction",
    "id" : "2467825",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2467825"
  },
  "cvss3" : {
    "cvss3_base_score" : "5.9",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:N",
    "status" : "verified"
  },
  "cwe" : "CWE-22",
  "details" : [ "The \"go tool pack\" subcommand (usually used only by the compiler as an internal tool with known-good inputs) does not sanitize output filenames. Extracting a malicious archive file with the \"pack\" subcommand can write files to arbitrary locations on the filesystem.", "A flaw was found in the \"go tool pack\" subcommand, a component of the Go programming language tools. This vulnerability allows an attacker to craft a malicious archive file. When this archive is extracted using the \"pack\" subcommand, it can lead to arbitrary file writes on the filesystem, potentially allowing an attacker to create or modify files in unintended locations." ],
  "affected_release" : [ {
    "product_name" : "Red Hat Enterprise Linux 10",
    "release_date" : "2026-06-01T00:00:00Z",
    "advisory" : "RHSA-2026:22120",
    "cpe" : "cpe:/o:redhat:enterprise_linux:10.2",
    "package" : "golang-0:1.26.3-4.el10_2"
  }, {
    "product_name" : "Red Hat Enterprise Linux 10.0 Extended Update Support",
    "release_date" : "2026-08-03T00:00:00Z",
    "advisory" : "RHSA-2026:49702",
    "cpe" : "cpe:/o:redhat:enterprise_linux_eus:10.0",
    "package" : "golang-0:1.26.5-1.el10_0"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "release_date" : "2026-06-01T00:00:00Z",
    "advisory" : "RHSA-2026:22112",
    "cpe" : "cpe:/a:redhat:enterprise_linux:8",
    "package" : "go-toolset:rhel8-8100020260518131104.a3795dee"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "release_date" : "2026-06-01T00:00:00Z",
    "advisory" : "RHSA-2026:22121",
    "cpe" : "cpe:/a:redhat:enterprise_linux:9",
    "package" : "golang-0:1.26.3-1.el9_8"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
    "release_date" : "2026-08-31T00:00:00Z",
    "advisory" : "RHSA-2026:61253",
    "cpe" : "cpe:/a:redhat:rhel_e4s:9.2",
    "package" : "golang-0:1.26.5-1.el9_2"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
    "release_date" : "2026-08-20T00:00:00Z",
    "advisory" : "RHSA-2026:57649",
    "cpe" : "cpe:/a:redhat:rhel_e4s:9.4",
    "package" : "golang-0:1.26.5-1.el9_4"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9.6 Extended Update Support",
    "release_date" : "2026-08-03T00:00:00Z",
    "advisory" : "RHSA-2026:49712",
    "cpe" : "cpe:/a:redhat:rhel_eus:9.6",
    "package" : "golang-0:1.26.5-1.el9_6"
  }, {
    "product_name" : "multicluster engine for Kubernetes 2.11",
    "release_date" : "2026-08-19T00:00:00Z",
    "advisory" : "RHSA-2026:57194",
    "cpe" : "cpe:/a:redhat:multicluster_engine:2.11::el9",
    "package" : "multicluster-engine/hypershift-addon-rhel9-operator:1786912006"
  }, {
    "product_name" : "OpenShift API for Data Protection 1.6",
    "release_date" : "2026-07-22T00:00:00Z",
    "advisory" : "RHSA-2026:43692",
    "cpe" : "cpe:/a:redhat:openshift_api_data_protection:1.6::el9",
    "package" : "oadp/oadp-velero-rhel9:1784058822"
  } ],
  "package_state" : [ {
    "product_name" : "Multicluster Engine for Kubernetes",
    "fix_state" : "Under investigation",
    "package_name" : "multicluster-engine/addon-manager-rhel9",
    "cpe" : "cpe:/a:redhat:multicluster_engine"
  }, {
    "product_name" : "Multicluster Engine for Kubernetes",
    "fix_state" : "Under investigation",
    "package_name" : "multicluster-engine/backplane-rhel9-operator",
    "cpe" : "cpe:/a:redhat:multicluster_engine"
  }, {
    "product_name" : "Multicluster Engine for Kubernetes",
    "fix_state" : "Under investigation",
    "package_name" : "multicluster-engine/clusterlifecycle-state-metrics-rhel9",
    "cpe" : "cpe:/a:redhat:multicluster_engine"
  }, {
    "product_name" : "Multicluster Engine for Kubernetes",
    "fix_state" : "Under investigation",
    "package_name" : "multicluster-engine/maestro-rhel9",
    "cpe" : "cpe:/a:redhat:multicluster_engine"
  }, {
    "product_name" : "Multicluster Engine for Kubernetes",
    "fix_state" : "Under investigation",
    "package_name" : "multicluster-engine/managedcluster-import-controller-rhel9",
    "cpe" : "cpe:/a:redhat:multicluster_engine"
  }, {
    "product_name" : "Multicluster Engine for Kubernetes",
    "fix_state" : "Under investigation",
    "package_name" : "multicluster-engine/multicloud-manager-rhel9",
    "cpe" : "cpe:/a:redhat:multicluster_engine"
  }, {
    "product_name" : "Multicluster Engine for Kubernetes",
    "fix_state" : "Under investigation",
    "package_name" : "multicluster-engine/placement-rhel9",
    "cpe" : "cpe:/a:redhat:multicluster_engine"
  }, {
    "product_name" : "Multicluster Engine for Kubernetes",
    "fix_state" : "Under investigation",
    "package_name" : "multicluster-engine/registration-operator-rhel9",
    "cpe" : "cpe:/a:redhat:multicluster_engine"
  }, {
    "product_name" : "Multicluster Engine for Kubernetes",
    "fix_state" : "Under investigation",
    "package_name" : "multicluster-engine/work-rhel9",
    "cpe" : "cpe:/a:redhat:multicluster_engine"
  }, {
    "product_name" : "Red Hat Advanced Cluster Management for Kubernetes 2",
    "fix_state" : "Under investigation",
    "package_name" : "rhacm2/acm-governance-policy-addon-controller-rhel9",
    "cpe" : "cpe:/a:redhat:acm:2"
  }, {
    "product_name" : "Red Hat Advanced Cluster Management for Kubernetes 2",
    "fix_state" : "Under investigation",
    "package_name" : "rhacm2/acm-governance-policy-framework-addon-rhel9",
    "cpe" : "cpe:/a:redhat:acm:2"
  }, {
    "product_name" : "Red Hat Advanced Cluster Management for Kubernetes 2",
    "fix_state" : "Under investigation",
    "package_name" : "rhacm2/config-policy-controller-rhel9",
    "cpe" : "cpe:/a:redhat:acm:2"
  }, {
    "product_name" : "Red Hat Advanced Cluster Management for Kubernetes 2",
    "fix_state" : "Under investigation",
    "package_name" : "rhacm2/governance-policy-propagator-rhel9",
    "cpe" : "cpe:/a:redhat:acm:2"
  }, {
    "product_name" : "Red Hat Advanced Cluster Management for Kubernetes 2",
    "fix_state" : "Under investigation",
    "package_name" : "rhacm2/klusterlet-addon-controller-rhel9",
    "cpe" : "cpe:/a:redhat:acm:2"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Under investigation",
    "package_name" : "openshift4/ose-hypershift-rhel9",
    "cpe" : "cpe:/a:redhat:openshift:4"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2026-39817\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-39817\nhttps://go.dev/cl/767520\nhttps://go.dev/issue/78778\nhttps://groups.google.com/g/golang-announce/c/qcCIEXso47M\nhttps://pkg.go.dev/vuln/GO-2026-4979" ],
  "name" : "CVE-2026-39817",
  "csaw" : false
}