CVE-2026-70455: Path Resolution Toctou Symlink Race

File operation relies on incomplete daemon/chroot state checks rather than checking active relative path confinement or using race-free directory file descriptor operations. This can expose path resolution to TOCTOU symlink races.

Provally CuratedPublic repositoryMediumMedium confidenceVerifiedApache-2.0C
greprules fetch cve-2026-70455-path-resolution-toctou-symlink-race --engine opengrep

Description

File operation relies on incomplete daemon/chroot state checks rather than checking active relative path confinement or using race-free directory file descriptor operations. This can expose path resolution to TOCTOU symlink races.