—
GO-2026-5903
Algernon vulnerable to server-side script source disclosure on Windows via NTFS filename in github.com/xyproto/algernon
Quick fix
GO-2026-5903 — github.com/xyproto/algernon: upgrade to the fixed version with the command below.
go get github.com/xyproto/algernon@v1.17.9Details
Algernon vulnerable to server-side script source disclosure on Windows via NTFS filename in github.com/xyproto/algernon
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/xyproto/algernon
Introduced in:
0Fixed in: 1.17.9Fix
go get github.com/xyproto/algernon@v1.17.9