Junglewise Threat Intelligence

CVE-2025-70950: itang gohttp directory traversal in FileServer

CVE-2025-70950 · Severity: high · CVSS 7.3 · Published 2026-05-19

Vendors: Go.

Executive brief

gohttp, a Go-based HTTP file server, is vulnerable to a security flaw that allows unauthorized access to files on the host system. By sending a specially crafted web request, an attacker can bypass folder restrictions to view sensitive system files or directory listings. This could lead to the exposure of confidential data, such as configuration files or system credentials, depending on the permissions of the server process.

Technical details

A directory traversal vulnerability (CWE-22) exists in the FileServer component of gohttp. The application constructs filesystem paths by directly concatenating the Webroot with untrusted URI data from the request without proper normalization or boundary enforcement. An unauthenticated remote attacker can exploit this by supplying a crafted request containing traversal sequences (e.g., '../') to access files outside the intended web root. This can result in arbitrary file read or directory listing, limited only by the permissions of the process. As of the advisory date, no official patch has been released.

Affected products

  • itang gohttp <= 0.0.0-20170713062009-34ea516ae408

Timeline

  • 2026-01-06: disclosed: Issue reported on GitHub repository
  • 2026-05-19: advisory: NVD and GitHub Advisory published

References