CVE-2026-56857: os: golang: golang: Directory traversal via Windows junction handling

Severity: Critical

CVSS Score: 9.8

On Windows, when the target of Root.Mkdir or Root.MkdirAll is a junction pointing to an empty location, the operation can create a directory at the junction target even when that target is located outside the root. This only applies to operations where the last path component is a junction (path/to/junction, but not path/junction/target).