Junglewise Threat Intelligence

CVE-2026-26187: GO-2026-4494 - lakeFS vulnerable to path traversal in local block adapter allow cross-namespace and sibling directory access in github.com/treeverse/lakefs

CVE-2026-26187 · Severity: low · CVSS 3.1 · Published 2026-02-17

Technologies: github.com/treeverse/lakefs (Go). Vendors: Go.

Executive brief

lakeFS vulnerable to path traversal in local block adapter allow cross-namespace and sibling directory access in github.com/treeverse/lakefs

Affected products

  • Go github.com/treeverse/lakefs

Related threats