CVE-2026-35392: Go Http Request Path To File Write Without Containment Check

A filesystem write path is derived from `req.URL.Path` and reaches `os.Create` / `os.OpenFile` / `os.WriteFile` / `ioutil.WriteFile` without being passed through a sanitizer that URL-decodes, cleans, and verifies the resolved absolute path is contained within the intended root directory. An attacker can supply traversal segments such as `..` or URL-encoded `

Provally CuratedPublic repositoryHighHigh confidenceVerifiedApache-2.0Go
greprules fetch cve-2026-35392-go-http-request-path-to-file-write-without-containment-check --engine opengrep

Description

A filesystem write path is derived from `req.URL.Path` and reaches `os.Create` / `os.OpenFile` / `os.WriteFile` / `ioutil.WriteFile` without being passed through a sanitizer that URL-decodes, cleans, and verifies the resolved absolute path is contained within the intended root directory. An attacker can supply traversal segments such as `..` or URL-encoded `