xrootd
eXtended ROOT daemon
Activity
- Latest release
- 1mo ago
- Total releases
- 70
- Cadence
- ~27 days
- Last 12 months
- 14
Details
- License
- unknown
- First release
- Jul 11, 2018
| Version | Released | |
|---|---|---|
6.1.1
patch
|
6.1.1
patch
|
|
5.9.7
patch
|
5.9.7
patch
|
|
6.1.0
minor
|
6.1.0
minor
|
|
5.9.6
patch
|
5.9.6
patch
|
|
6.0.3
patch
|
6.0.3
patch
|
|
5.9.5
patch
|
5.9.5
patch
|
|
6.0.2
patch
|
6.0.2
patch
|
|
5.9.4
patch
|
5.9.4
patch
|
|
6.0.1
patch
|
6.0.1
patch
|
|
5.9.3
patch
|
5.9.3
patch
|
|
6.0.0
major
|
6.0.0
major
|
|
5.9.2
patch
|
5.9.2
patch
|
|
5.9.1
patch
1 CVE
GHSA-vj8v-p5vw-m6v5
Apr 10, 2026
xrootd has path traversal in directory listing that allows access to the parent directory via trailing ".." pattern
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryA path traversal vulnerability in XRootD allows users to escape the exported directory scope and enumerate the contents of the parent directory by appending This bypass ignores the Affected component
PoCConfiguration
Steps to reproduceNormal behavior (access outside export is denied):
Bypass via trailing
Also exploitable via HTTP PROPFIND:
Returns HTTP 200 with full listing of the parent directory, including unexported entries ( However, file download via this path traversal is blocked:
ImpactAn attacker can enumerate directories and filenames outside the authorized export scope defined by File download is not possible through this vector, as This vulnerability could affect all XRootD deployments regardless of authentication configuration, as it bypasses the export path restriction itself. Suggested fixIn
Affected versions
4.10.0
4.11.0
4.11.1
4.11.2
4.11.3
4.12.0
4.12.2
4.12.3
4.12.4
4.12.5
4.12.6
4.12.7
+ 46 more Show less
4.8.4
4.8.5
4.9.0
4.9.1
5.0.0
5.0.1
5.0.2
5.0.3
5.1.1
5.2.0
5.3.0
5.3.1
5.3.2
5.3.3
5.3.4
5.4.0
5.4.1
5.4.2
5.4.3
5.5.0
5.5.1
5.5.2
5.5.3
5.5.4
5.5.5
5.6.0
5.6.1
5.6.2
5.6.3
5.6.4
5.6.5
5.6.6
5.6.7
5.6.8
5.6.9
5.7.0
5.7.1
5.7.2
5.7.3
5.8.0
5.8.1
5.8.2
5.8.3
5.8.4
5.9.0
5.9.1
Fixed in
5.9.2
References Updated Apr 10, 2026 · Source: OSV.dev |
5.9.1
patch
|
|
5.9.0
minor
1 CVE
GHSA-vj8v-p5vw-m6v5
Apr 10, 2026
xrootd has path traversal in directory listing that allows access to the parent directory via trailing ".." pattern
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryA path traversal vulnerability in XRootD allows users to escape the exported directory scope and enumerate the contents of the parent directory by appending This bypass ignores the Affected component
PoCConfiguration
Steps to reproduceNormal behavior (access outside export is denied):
Bypass via trailing
Also exploitable via HTTP PROPFIND:
Returns HTTP 200 with full listing of the parent directory, including unexported entries ( However, file download via this path traversal is blocked:
ImpactAn attacker can enumerate directories and filenames outside the authorized export scope defined by File download is not possible through this vector, as This vulnerability could affect all XRootD deployments regardless of authentication configuration, as it bypasses the export path restriction itself. Suggested fixIn
Affected versions
4.10.0
4.11.0
4.11.1
4.11.2
4.11.3
4.12.0
4.12.2
4.12.3
4.12.4
4.12.5
4.12.6
4.12.7
+ 46 more Show less
4.8.4
4.8.5
4.9.0
4.9.1
5.0.0
5.0.1
5.0.2
5.0.3
5.1.1
5.2.0
5.3.0
5.3.1
5.3.2
5.3.3
5.3.4
5.4.0
5.4.1
5.4.2
5.4.3
5.5.0
5.5.1
5.5.2
5.5.3
5.5.4
5.5.5
5.6.0
5.6.1
5.6.2
5.6.3
5.6.4
5.6.5
5.6.6
5.6.7
5.6.8
5.6.9
5.7.0
5.7.1
5.7.2
5.7.3
5.8.0
5.8.1
5.8.2
5.8.3
5.8.4
5.9.0
5.9.1
Fixed in
5.9.2
References Updated Apr 10, 2026 · Source: OSV.dev |
5.9.0
minor
|
|
5.8.4
patch
1 CVE
GHSA-vj8v-p5vw-m6v5
Apr 10, 2026
xrootd has path traversal in directory listing that allows access to the parent directory via trailing ".." pattern
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryA path traversal vulnerability in XRootD allows users to escape the exported directory scope and enumerate the contents of the parent directory by appending This bypass ignores the Affected component
PoCConfiguration
Steps to reproduceNormal behavior (access outside export is denied):
Bypass via trailing
Also exploitable via HTTP PROPFIND:
Returns HTTP 200 with full listing of the parent directory, including unexported entries ( However, file download via this path traversal is blocked:
ImpactAn attacker can enumerate directories and filenames outside the authorized export scope defined by File download is not possible through this vector, as This vulnerability could affect all XRootD deployments regardless of authentication configuration, as it bypasses the export path restriction itself. Suggested fixIn
Affected versions
4.10.0
4.11.0
4.11.1
4.11.2
4.11.3
4.12.0
4.12.2
4.12.3
4.12.4
4.12.5
4.12.6
4.12.7
+ 46 more Show less
4.8.4
4.8.5
4.9.0
4.9.1
5.0.0
5.0.1
5.0.2
5.0.3
5.1.1
5.2.0
5.3.0
5.3.1
5.3.2
5.3.3
5.3.4
5.4.0
5.4.1
5.4.2
5.4.3
5.5.0
5.5.1
5.5.2
5.5.3
5.5.4
5.5.5
5.6.0
5.6.1
5.6.2
5.6.3
5.6.4
5.6.5
5.6.6
5.6.7
5.6.8
5.6.9
5.7.0
5.7.1
5.7.2
5.7.3
5.8.0
5.8.1
5.8.2
5.8.3
5.8.4
5.9.0
5.9.1
Fixed in
5.9.2
References Updated Apr 10, 2026 · Source: OSV.dev |
5.8.4
patch
|
|
5.8.3
patch
1 CVE
GHSA-vj8v-p5vw-m6v5
Apr 10, 2026
xrootd has path traversal in directory listing that allows access to the parent directory via trailing ".." pattern
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryA path traversal vulnerability in XRootD allows users to escape the exported directory scope and enumerate the contents of the parent directory by appending This bypass ignores the Affected component
PoCConfiguration
Steps to reproduceNormal behavior (access outside export is denied):
Bypass via trailing
Also exploitable via HTTP PROPFIND:
Returns HTTP 200 with full listing of the parent directory, including unexported entries ( However, file download via this path traversal is blocked:
ImpactAn attacker can enumerate directories and filenames outside the authorized export scope defined by File download is not possible through this vector, as This vulnerability could affect all XRootD deployments regardless of authentication configuration, as it bypasses the export path restriction itself. Suggested fixIn
Affected versions
4.10.0
4.11.0
4.11.1
4.11.2
4.11.3
4.12.0
4.12.2
4.12.3
4.12.4
4.12.5
4.12.6
4.12.7
+ 46 more Show less
4.8.4
4.8.5
4.9.0
4.9.1
5.0.0
5.0.1
5.0.2
5.0.3
5.1.1
5.2.0
5.3.0
5.3.1
5.3.2
5.3.3
5.3.4
5.4.0
5.4.1
5.4.2
5.4.3
5.5.0
5.5.1
5.5.2
5.5.3
5.5.4
5.5.5
5.6.0
5.6.1
5.6.2
5.6.3
5.6.4
5.6.5
5.6.6
5.6.7
5.6.8
5.6.9
5.7.0
5.7.1
5.7.2
5.7.3
5.8.0
5.8.1
5.8.2
5.8.3
5.8.4
5.9.0
5.9.1
Fixed in
5.9.2
References Updated Apr 10, 2026 · Source: OSV.dev |
5.8.3
patch
|
|
5.8.2
patch
1 CVE
GHSA-vj8v-p5vw-m6v5
Apr 10, 2026
xrootd has path traversal in directory listing that allows access to the parent directory via trailing ".." pattern
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryA path traversal vulnerability in XRootD allows users to escape the exported directory scope and enumerate the contents of the parent directory by appending This bypass ignores the Affected component
PoCConfiguration
Steps to reproduceNormal behavior (access outside export is denied):
Bypass via trailing
Also exploitable via HTTP PROPFIND:
Returns HTTP 200 with full listing of the parent directory, including unexported entries ( However, file download via this path traversal is blocked:
ImpactAn attacker can enumerate directories and filenames outside the authorized export scope defined by File download is not possible through this vector, as This vulnerability could affect all XRootD deployments regardless of authentication configuration, as it bypasses the export path restriction itself. Suggested fixIn
Affected versions
4.10.0
4.11.0
4.11.1
4.11.2
4.11.3
4.12.0
4.12.2
4.12.3
4.12.4
4.12.5
4.12.6
4.12.7
+ 46 more Show less
4.8.4
4.8.5
4.9.0
4.9.1
5.0.0
5.0.1
5.0.2
5.0.3
5.1.1
5.2.0
5.3.0
5.3.1
5.3.2
5.3.3
5.3.4
5.4.0
5.4.1
5.4.2
5.4.3
5.5.0
5.5.1
5.5.2
5.5.3
5.5.4
5.5.5
5.6.0
5.6.1
5.6.2
5.6.3
5.6.4
5.6.5
5.6.6
5.6.7
5.6.8
5.6.9
5.7.0
5.7.1
5.7.2
5.7.3
5.8.0
5.8.1
5.8.2
5.8.3
5.8.4
5.9.0
5.9.1
Fixed in
5.9.2
References Updated Apr 10, 2026 · Source: OSV.dev |
5.8.2
patch
|
|
5.8.1
patch
1 CVE
GHSA-vj8v-p5vw-m6v5
Apr 10, 2026
xrootd has path traversal in directory listing that allows access to the parent directory via trailing ".." pattern
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryA path traversal vulnerability in XRootD allows users to escape the exported directory scope and enumerate the contents of the parent directory by appending This bypass ignores the Affected component
PoCConfiguration
Steps to reproduceNormal behavior (access outside export is denied):
Bypass via trailing
Also exploitable via HTTP PROPFIND:
Returns HTTP 200 with full listing of the parent directory, including unexported entries ( However, file download via this path traversal is blocked:
ImpactAn attacker can enumerate directories and filenames outside the authorized export scope defined by File download is not possible through this vector, as This vulnerability could affect all XRootD deployments regardless of authentication configuration, as it bypasses the export path restriction itself. Suggested fixIn
Affected versions
4.10.0
4.11.0
4.11.1
4.11.2
4.11.3
4.12.0
4.12.2
4.12.3
4.12.4
4.12.5
4.12.6
4.12.7
+ 46 more Show less
4.8.4
4.8.5
4.9.0
4.9.1
5.0.0
5.0.1
5.0.2
5.0.3
5.1.1
5.2.0
5.3.0
5.3.1
5.3.2
5.3.3
5.3.4
5.4.0
5.4.1
5.4.2
5.4.3
5.5.0
5.5.1
5.5.2
5.5.3
5.5.4
5.5.5
5.6.0
5.6.1
5.6.2
5.6.3
5.6.4
5.6.5
5.6.6
5.6.7
5.6.8
5.6.9
5.7.0
5.7.1
5.7.2
5.7.3
5.8.0
5.8.1
5.8.2
5.8.3
5.8.4
5.9.0
5.9.1
Fixed in
5.9.2
References Updated Apr 10, 2026 · Source: OSV.dev |
5.8.1
patch
|
|
5.8.0
minor
1 CVE
GHSA-vj8v-p5vw-m6v5
Apr 10, 2026
xrootd has path traversal in directory listing that allows access to the parent directory via trailing ".." pattern
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryA path traversal vulnerability in XRootD allows users to escape the exported directory scope and enumerate the contents of the parent directory by appending This bypass ignores the Affected component
PoCConfiguration
Steps to reproduceNormal behavior (access outside export is denied):
Bypass via trailing
Also exploitable via HTTP PROPFIND:
Returns HTTP 200 with full listing of the parent directory, including unexported entries ( However, file download via this path traversal is blocked:
ImpactAn attacker can enumerate directories and filenames outside the authorized export scope defined by File download is not possible through this vector, as This vulnerability could affect all XRootD deployments regardless of authentication configuration, as it bypasses the export path restriction itself. Suggested fixIn
Affected versions
4.10.0
4.11.0
4.11.1
4.11.2
4.11.3
4.12.0
4.12.2
4.12.3
4.12.4
4.12.5
4.12.6
4.12.7
+ 46 more Show less
4.8.4
4.8.5
4.9.0
4.9.1
5.0.0
5.0.1
5.0.2
5.0.3
5.1.1
5.2.0
5.3.0
5.3.1
5.3.2
5.3.3
5.3.4
5.4.0
5.4.1
5.4.2
5.4.3
5.5.0
5.5.1
5.5.2
5.5.3
5.5.4
5.5.5
5.6.0
5.6.1
5.6.2
5.6.3
5.6.4
5.6.5
5.6.6
5.6.7
5.6.8
5.6.9
5.7.0
5.7.1
5.7.2
5.7.3
5.8.0
5.8.1
5.8.2
5.8.3
5.8.4
5.9.0
5.9.1
Fixed in
5.9.2
References Updated Apr 10, 2026 · Source: OSV.dev |
5.8.0
minor
|
|
5.7.3
patch
1 CVE
GHSA-vj8v-p5vw-m6v5
Apr 10, 2026
xrootd has path traversal in directory listing that allows access to the parent directory via trailing ".." pattern
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryA path traversal vulnerability in XRootD allows users to escape the exported directory scope and enumerate the contents of the parent directory by appending This bypass ignores the Affected component
PoCConfiguration
Steps to reproduceNormal behavior (access outside export is denied):
Bypass via trailing
Also exploitable via HTTP PROPFIND:
Returns HTTP 200 with full listing of the parent directory, including unexported entries ( However, file download via this path traversal is blocked:
ImpactAn attacker can enumerate directories and filenames outside the authorized export scope defined by File download is not possible through this vector, as This vulnerability could affect all XRootD deployments regardless of authentication configuration, as it bypasses the export path restriction itself. Suggested fixIn
Affected versions
4.10.0
4.11.0
4.11.1
4.11.2
4.11.3
4.12.0
4.12.2
4.12.3
4.12.4
4.12.5
4.12.6
4.12.7
+ 46 more Show less
4.8.4
4.8.5
4.9.0
4.9.1
5.0.0
5.0.1
5.0.2
5.0.3
5.1.1
5.2.0
5.3.0
5.3.1
5.3.2
5.3.3
5.3.4
5.4.0
5.4.1
5.4.2
5.4.3
5.5.0
5.5.1
5.5.2
5.5.3
5.5.4
5.5.5
5.6.0
5.6.1
5.6.2
5.6.3
5.6.4
5.6.5
5.6.6
5.6.7
5.6.8
5.6.9
5.7.0
5.7.1
5.7.2
5.7.3
5.8.0
5.8.1
5.8.2
5.8.3
5.8.4
5.9.0
5.9.1
Fixed in
5.9.2
References Updated Apr 10, 2026 · Source: OSV.dev |
5.7.3
patch
|
|
5.7.2
patch
1 CVE
GHSA-vj8v-p5vw-m6v5
Apr 10, 2026
xrootd has path traversal in directory listing that allows access to the parent directory via trailing ".." pattern
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryA path traversal vulnerability in XRootD allows users to escape the exported directory scope and enumerate the contents of the parent directory by appending This bypass ignores the Affected component
PoCConfiguration
Steps to reproduceNormal behavior (access outside export is denied):
Bypass via trailing
Also exploitable via HTTP PROPFIND:
Returns HTTP 200 with full listing of the parent directory, including unexported entries ( However, file download via this path traversal is blocked:
ImpactAn attacker can enumerate directories and filenames outside the authorized export scope defined by File download is not possible through this vector, as This vulnerability could affect all XRootD deployments regardless of authentication configuration, as it bypasses the export path restriction itself. Suggested fixIn
Affected versions
4.10.0
4.11.0
4.11.1
4.11.2
4.11.3
4.12.0
4.12.2
4.12.3
4.12.4
4.12.5
4.12.6
4.12.7
+ 46 more Show less
4.8.4
4.8.5
4.9.0
4.9.1
5.0.0
5.0.1
5.0.2
5.0.3
5.1.1
5.2.0
5.3.0
5.3.1
5.3.2
5.3.3
5.3.4
5.4.0
5.4.1
5.4.2
5.4.3
5.5.0
5.5.1
5.5.2
5.5.3
5.5.4
5.5.5
5.6.0
5.6.1
5.6.2
5.6.3
5.6.4
5.6.5
5.6.6
5.6.7
5.6.8
5.6.9
5.7.0
5.7.1
5.7.2
5.7.3
5.8.0
5.8.1
5.8.2
5.8.3
5.8.4
5.9.0
5.9.1
Fixed in
5.9.2
References Updated Apr 10, 2026 · Source: OSV.dev |
5.7.2
patch
|
|
5.7.1
patch
1 CVE
GHSA-vj8v-p5vw-m6v5
Apr 10, 2026
xrootd has path traversal in directory listing that allows access to the parent directory via trailing ".." pattern
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryA path traversal vulnerability in XRootD allows users to escape the exported directory scope and enumerate the contents of the parent directory by appending This bypass ignores the Affected component
PoCConfiguration
Steps to reproduceNormal behavior (access outside export is denied):
Bypass via trailing
Also exploitable via HTTP PROPFIND:
Returns HTTP 200 with full listing of the parent directory, including unexported entries ( However, file download via this path traversal is blocked:
ImpactAn attacker can enumerate directories and filenames outside the authorized export scope defined by File download is not possible through this vector, as This vulnerability could affect all XRootD deployments regardless of authentication configuration, as it bypasses the export path restriction itself. Suggested fixIn
Affected versions
4.10.0
4.11.0
4.11.1
4.11.2
4.11.3
4.12.0
4.12.2
4.12.3
4.12.4
4.12.5
4.12.6
4.12.7
+ 46 more Show less
4.8.4
4.8.5
4.9.0
4.9.1
5.0.0
5.0.1
5.0.2
5.0.3
5.1.1
5.2.0
5.3.0
5.3.1
5.3.2
5.3.3
5.3.4
5.4.0
5.4.1
5.4.2
5.4.3
5.5.0
5.5.1
5.5.2
5.5.3
5.5.4
5.5.5
5.6.0
5.6.1
5.6.2
5.6.3
5.6.4
5.6.5
5.6.6
5.6.7
5.6.8
5.6.9
5.7.0
5.7.1
5.7.2
5.7.3
5.8.0
5.8.1
5.8.2
5.8.3
5.8.4
5.9.0
5.9.1
Fixed in
5.9.2
References Updated Apr 10, 2026 · Source: OSV.dev |
5.7.1
patch
|
|
5.7.0
minor
1 CVE
GHSA-vj8v-p5vw-m6v5
Apr 10, 2026
xrootd has path traversal in directory listing that allows access to the parent directory via trailing ".." pattern
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryA path traversal vulnerability in XRootD allows users to escape the exported directory scope and enumerate the contents of the parent directory by appending This bypass ignores the Affected component
PoCConfiguration
Steps to reproduceNormal behavior (access outside export is denied):
Bypass via trailing
Also exploitable via HTTP PROPFIND:
Returns HTTP 200 with full listing of the parent directory, including unexported entries ( However, file download via this path traversal is blocked:
ImpactAn attacker can enumerate directories and filenames outside the authorized export scope defined by File download is not possible through this vector, as This vulnerability could affect all XRootD deployments regardless of authentication configuration, as it bypasses the export path restriction itself. Suggested fixIn
Affected versions
4.10.0
4.11.0
4.11.1
4.11.2
4.11.3
4.12.0
4.12.2
4.12.3
4.12.4
4.12.5
4.12.6
4.12.7
+ 46 more Show less
4.8.4
4.8.5
4.9.0
4.9.1
5.0.0
5.0.1
5.0.2
5.0.3
5.1.1
5.2.0
5.3.0
5.3.1
5.3.2
5.3.3
5.3.4
5.4.0
5.4.1
5.4.2
5.4.3
5.5.0
5.5.1
5.5.2
5.5.3
5.5.4
5.5.5
5.6.0
5.6.1
5.6.2
5.6.3
5.6.4
5.6.5
5.6.6
5.6.7
5.6.8
5.6.9
5.7.0
5.7.1
5.7.2
5.7.3
5.8.0
5.8.1
5.8.2
5.8.3
5.8.4
5.9.0
5.9.1
Fixed in
5.9.2
References Updated Apr 10, 2026 · Source: OSV.dev |
5.7.0
minor
|
|
5.6.9
patch
1 CVE
GHSA-vj8v-p5vw-m6v5
Apr 10, 2026
xrootd has path traversal in directory listing that allows access to the parent directory via trailing ".." pattern
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryA path traversal vulnerability in XRootD allows users to escape the exported directory scope and enumerate the contents of the parent directory by appending This bypass ignores the Affected component
PoCConfiguration
Steps to reproduceNormal behavior (access outside export is denied):
Bypass via trailing
Also exploitable via HTTP PROPFIND:
Returns HTTP 200 with full listing of the parent directory, including unexported entries ( However, file download via this path traversal is blocked:
ImpactAn attacker can enumerate directories and filenames outside the authorized export scope defined by File download is not possible through this vector, as This vulnerability could affect all XRootD deployments regardless of authentication configuration, as it bypasses the export path restriction itself. Suggested fixIn
Affected versions
4.10.0
4.11.0
4.11.1
4.11.2
4.11.3
4.12.0
4.12.2
4.12.3
4.12.4
4.12.5
4.12.6
4.12.7
+ 46 more Show less
4.8.4
4.8.5
4.9.0
4.9.1
5.0.0
5.0.1
5.0.2
5.0.3
5.1.1
5.2.0
5.3.0
5.3.1
5.3.2
5.3.3
5.3.4
5.4.0
5.4.1
5.4.2
5.4.3
5.5.0
5.5.1
5.5.2
5.5.3
5.5.4
5.5.5
5.6.0
5.6.1
5.6.2
5.6.3
5.6.4
5.6.5
5.6.6
5.6.7
5.6.8
5.6.9
5.7.0
5.7.1
5.7.2
5.7.3
5.8.0
5.8.1
5.8.2
5.8.3
5.8.4
5.9.0
5.9.1
Fixed in
5.9.2
References Updated Apr 10, 2026 · Source: OSV.dev |
5.6.9
patch
|
|
5.6.8
patch
1 CVE
GHSA-vj8v-p5vw-m6v5
Apr 10, 2026
xrootd has path traversal in directory listing that allows access to the parent directory via trailing ".." pattern
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryA path traversal vulnerability in XRootD allows users to escape the exported directory scope and enumerate the contents of the parent directory by appending This bypass ignores the Affected component
PoCConfiguration
Steps to reproduceNormal behavior (access outside export is denied):
Bypass via trailing
Also exploitable via HTTP PROPFIND:
Returns HTTP 200 with full listing of the parent directory, including unexported entries ( However, file download via this path traversal is blocked:
ImpactAn attacker can enumerate directories and filenames outside the authorized export scope defined by File download is not possible through this vector, as This vulnerability could affect all XRootD deployments regardless of authentication configuration, as it bypasses the export path restriction itself. Suggested fixIn
Affected versions
4.10.0
4.11.0
4.11.1
4.11.2
4.11.3
4.12.0
4.12.2
4.12.3
4.12.4
4.12.5
4.12.6
4.12.7
+ 46 more Show less
4.8.4
4.8.5
4.9.0
4.9.1
5.0.0
5.0.1
5.0.2
5.0.3
5.1.1
5.2.0
5.3.0
5.3.1
5.3.2
5.3.3
5.3.4
5.4.0
5.4.1
5.4.2
5.4.3
5.5.0
5.5.1
5.5.2
5.5.3
5.5.4
5.5.5
5.6.0
5.6.1
5.6.2
5.6.3
5.6.4
5.6.5
5.6.6
5.6.7
5.6.8
5.6.9
5.7.0
5.7.1
5.7.2
5.7.3
5.8.0
5.8.1
5.8.2
5.8.3
5.8.4
5.9.0
5.9.1
Fixed in
5.9.2
References Updated Apr 10, 2026 · Source: OSV.dev |
5.6.8
patch
|
|
5.6.7
patch
1 CVE
GHSA-vj8v-p5vw-m6v5
Apr 10, 2026
xrootd has path traversal in directory listing that allows access to the parent directory via trailing ".." pattern
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryA path traversal vulnerability in XRootD allows users to escape the exported directory scope and enumerate the contents of the parent directory by appending This bypass ignores the Affected component
PoCConfiguration
Steps to reproduceNormal behavior (access outside export is denied):
Bypass via trailing
Also exploitable via HTTP PROPFIND:
Returns HTTP 200 with full listing of the parent directory, including unexported entries ( However, file download via this path traversal is blocked:
ImpactAn attacker can enumerate directories and filenames outside the authorized export scope defined by File download is not possible through this vector, as This vulnerability could affect all XRootD deployments regardless of authentication configuration, as it bypasses the export path restriction itself. Suggested fixIn
Affected versions
4.10.0
4.11.0
4.11.1
4.11.2
4.11.3
4.12.0
4.12.2
4.12.3
4.12.4
4.12.5
4.12.6
4.12.7
+ 46 more Show less
4.8.4
4.8.5
4.9.0
4.9.1
5.0.0
5.0.1
5.0.2
5.0.3
5.1.1
5.2.0
5.3.0
5.3.1
5.3.2
5.3.3
5.3.4
5.4.0
5.4.1
5.4.2
5.4.3
5.5.0
5.5.1
5.5.2
5.5.3
5.5.4
5.5.5
5.6.0
5.6.1
5.6.2
5.6.3
5.6.4
5.6.5
5.6.6
5.6.7
5.6.8
5.6.9
5.7.0
5.7.1
5.7.2
5.7.3
5.8.0
5.8.1
5.8.2
5.8.3
5.8.4
5.9.0
5.9.1
Fixed in
5.9.2
References Updated Apr 10, 2026 · Source: OSV.dev |
5.6.7
patch
|
|
5.6.6
patch
1 CVE
GHSA-vj8v-p5vw-m6v5
Apr 10, 2026
xrootd has path traversal in directory listing that allows access to the parent directory via trailing ".." pattern
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryA path traversal vulnerability in XRootD allows users to escape the exported directory scope and enumerate the contents of the parent directory by appending This bypass ignores the Affected component
PoCConfiguration
Steps to reproduceNormal behavior (access outside export is denied):
Bypass via trailing
Also exploitable via HTTP PROPFIND:
Returns HTTP 200 with full listing of the parent directory, including unexported entries ( However, file download via this path traversal is blocked:
ImpactAn attacker can enumerate directories and filenames outside the authorized export scope defined by File download is not possible through this vector, as This vulnerability could affect all XRootD deployments regardless of authentication configuration, as it bypasses the export path restriction itself. Suggested fixIn
Affected versions
4.10.0
4.11.0
4.11.1
4.11.2
4.11.3
4.12.0
4.12.2
4.12.3
4.12.4
4.12.5
4.12.6
4.12.7
+ 46 more Show less
4.8.4
4.8.5
4.9.0
4.9.1
5.0.0
5.0.1
5.0.2
5.0.3
5.1.1
5.2.0
5.3.0
5.3.1
5.3.2
5.3.3
5.3.4
5.4.0
5.4.1
5.4.2
5.4.3
5.5.0
5.5.1
5.5.2
5.5.3
5.5.4
5.5.5
5.6.0
5.6.1
5.6.2
5.6.3
5.6.4
5.6.5
5.6.6
5.6.7
5.6.8
5.6.9
5.7.0
5.7.1
5.7.2
5.7.3
5.8.0
5.8.1
5.8.2
5.8.3
5.8.4
5.9.0
5.9.1
Fixed in
5.9.2
References Updated Apr 10, 2026 · Source: OSV.dev |
5.6.6
patch
|
|
5.6.5
patch
1 CVE
GHSA-vj8v-p5vw-m6v5
Apr 10, 2026
xrootd has path traversal in directory listing that allows access to the parent directory via trailing ".." pattern
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryA path traversal vulnerability in XRootD allows users to escape the exported directory scope and enumerate the contents of the parent directory by appending This bypass ignores the Affected component
PoCConfiguration
Steps to reproduceNormal behavior (access outside export is denied):
Bypass via trailing
Also exploitable via HTTP PROPFIND:
Returns HTTP 200 with full listing of the parent directory, including unexported entries ( However, file download via this path traversal is blocked:
ImpactAn attacker can enumerate directories and filenames outside the authorized export scope defined by File download is not possible through this vector, as This vulnerability could affect all XRootD deployments regardless of authentication configuration, as it bypasses the export path restriction itself. Suggested fixIn
Affected versions
4.10.0
4.11.0
4.11.1
4.11.2
4.11.3
4.12.0
4.12.2
4.12.3
4.12.4
4.12.5
4.12.6
4.12.7
+ 46 more Show less
4.8.4
4.8.5
4.9.0
4.9.1
5.0.0
5.0.1
5.0.2
5.0.3
5.1.1
5.2.0
5.3.0
5.3.1
5.3.2
5.3.3
5.3.4
5.4.0
5.4.1
5.4.2
5.4.3
5.5.0
5.5.1
5.5.2
5.5.3
5.5.4
5.5.5
5.6.0
5.6.1
5.6.2
5.6.3
5.6.4
5.6.5
5.6.6
5.6.7
5.6.8
5.6.9
5.7.0
5.7.1
5.7.2
5.7.3
5.8.0
5.8.1
5.8.2
5.8.3
5.8.4
5.9.0
5.9.1
Fixed in
5.9.2
References Updated Apr 10, 2026 · Source: OSV.dev |
5.6.5
patch
|
|
5.6.4
patch
1 CVE
GHSA-vj8v-p5vw-m6v5
Apr 10, 2026
xrootd has path traversal in directory listing that allows access to the parent directory via trailing ".." pattern
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryA path traversal vulnerability in XRootD allows users to escape the exported directory scope and enumerate the contents of the parent directory by appending This bypass ignores the Affected component
PoCConfiguration
Steps to reproduceNormal behavior (access outside export is denied):
Bypass via trailing
Also exploitable via HTTP PROPFIND:
Returns HTTP 200 with full listing of the parent directory, including unexported entries ( However, file download via this path traversal is blocked:
ImpactAn attacker can enumerate directories and filenames outside the authorized export scope defined by File download is not possible through this vector, as This vulnerability could affect all XRootD deployments regardless of authentication configuration, as it bypasses the export path restriction itself. Suggested fixIn
Affected versions
4.10.0
4.11.0
4.11.1
4.11.2
4.11.3
4.12.0
4.12.2
4.12.3
4.12.4
4.12.5
4.12.6
4.12.7
+ 46 more Show less
4.8.4
4.8.5
4.9.0
4.9.1
5.0.0
5.0.1
5.0.2
5.0.3
5.1.1
5.2.0
5.3.0
5.3.1
5.3.2
5.3.3
5.3.4
5.4.0
5.4.1
5.4.2
5.4.3
5.5.0
5.5.1
5.5.2
5.5.3
5.5.4
5.5.5
5.6.0
5.6.1
5.6.2
5.6.3
5.6.4
5.6.5
5.6.6
5.6.7
5.6.8
5.6.9
5.7.0
5.7.1
5.7.2
5.7.3
5.8.0
5.8.1
5.8.2
5.8.3
5.8.4
5.9.0
5.9.1
Fixed in
5.9.2
References Updated Apr 10, 2026 · Source: OSV.dev |
5.6.4
patch
|
|
5.6.3
patch
1 CVE
GHSA-vj8v-p5vw-m6v5
Apr 10, 2026
xrootd has path traversal in directory listing that allows access to the parent directory via trailing ".." pattern
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryA path traversal vulnerability in XRootD allows users to escape the exported directory scope and enumerate the contents of the parent directory by appending This bypass ignores the Affected component
PoCConfiguration
Steps to reproduceNormal behavior (access outside export is denied):
Bypass via trailing
Also exploitable via HTTP PROPFIND:
Returns HTTP 200 with full listing of the parent directory, including unexported entries ( However, file download via this path traversal is blocked:
ImpactAn attacker can enumerate directories and filenames outside the authorized export scope defined by File download is not possible through this vector, as This vulnerability could affect all XRootD deployments regardless of authentication configuration, as it bypasses the export path restriction itself. Suggested fixIn
Affected versions
4.10.0
4.11.0
4.11.1
4.11.2
4.11.3
4.12.0
4.12.2
4.12.3
4.12.4
4.12.5
4.12.6
4.12.7
+ 46 more Show less
4.8.4
4.8.5
4.9.0
4.9.1
5.0.0
5.0.1
5.0.2
5.0.3
5.1.1
5.2.0
5.3.0
5.3.1
5.3.2
5.3.3
5.3.4
5.4.0
5.4.1
5.4.2
5.4.3
5.5.0
5.5.1
5.5.2
5.5.3
5.5.4
5.5.5
5.6.0
5.6.1
5.6.2
5.6.3
5.6.4
5.6.5
5.6.6
5.6.7
5.6.8
5.6.9
5.7.0
5.7.1
5.7.2
5.7.3
5.8.0
5.8.1
5.8.2
5.8.3
5.8.4
5.9.0
5.9.1
Fixed in
5.9.2
References Updated Apr 10, 2026 · Source: OSV.dev |
5.6.3
patch
|
|
5.6.2
patch
1 CVE
GHSA-vj8v-p5vw-m6v5
Apr 10, 2026
xrootd has path traversal in directory listing that allows access to the parent directory via trailing ".." pattern
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryA path traversal vulnerability in XRootD allows users to escape the exported directory scope and enumerate the contents of the parent directory by appending This bypass ignores the Affected component
PoCConfiguration
Steps to reproduceNormal behavior (access outside export is denied):
Bypass via trailing
Also exploitable via HTTP PROPFIND:
Returns HTTP 200 with full listing of the parent directory, including unexported entries ( However, file download via this path traversal is blocked:
ImpactAn attacker can enumerate directories and filenames outside the authorized export scope defined by File download is not possible through this vector, as This vulnerability could affect all XRootD deployments regardless of authentication configuration, as it bypasses the export path restriction itself. Suggested fixIn
Affected versions
4.10.0
4.11.0
4.11.1
4.11.2
4.11.3
4.12.0
4.12.2
4.12.3
4.12.4
4.12.5
4.12.6
4.12.7
+ 46 more Show less
4.8.4
4.8.5
4.9.0
4.9.1
5.0.0
5.0.1
5.0.2
5.0.3
5.1.1
5.2.0
5.3.0
5.3.1
5.3.2
5.3.3
5.3.4
5.4.0
5.4.1
5.4.2
5.4.3
5.5.0
5.5.1
5.5.2
5.5.3
5.5.4
5.5.5
5.6.0
5.6.1
5.6.2
5.6.3
5.6.4
5.6.5
5.6.6
5.6.7
5.6.8
5.6.9
5.7.0
5.7.1
5.7.2
5.7.3
5.8.0
5.8.1
5.8.2
5.8.3
5.8.4
5.9.0
5.9.1
Fixed in
5.9.2
References Updated Apr 10, 2026 · Source: OSV.dev |
5.6.2
patch
|
|
5.6.1
patch
1 CVE
GHSA-vj8v-p5vw-m6v5
Apr 10, 2026
xrootd has path traversal in directory listing that allows access to the parent directory via trailing ".." pattern
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryA path traversal vulnerability in XRootD allows users to escape the exported directory scope and enumerate the contents of the parent directory by appending This bypass ignores the Affected component
PoCConfiguration
Steps to reproduceNormal behavior (access outside export is denied):
Bypass via trailing
Also exploitable via HTTP PROPFIND:
Returns HTTP 200 with full listing of the parent directory, including unexported entries ( However, file download via this path traversal is blocked:
ImpactAn attacker can enumerate directories and filenames outside the authorized export scope defined by File download is not possible through this vector, as This vulnerability could affect all XRootD deployments regardless of authentication configuration, as it bypasses the export path restriction itself. Suggested fixIn
Affected versions
4.10.0
4.11.0
4.11.1
4.11.2
4.11.3
4.12.0
4.12.2
4.12.3
4.12.4
4.12.5
4.12.6
4.12.7
+ 46 more Show less
4.8.4
4.8.5
4.9.0
4.9.1
5.0.0
5.0.1
5.0.2
5.0.3
5.1.1
5.2.0
5.3.0
5.3.1
5.3.2
5.3.3
5.3.4
5.4.0
5.4.1
5.4.2
5.4.3
5.5.0
5.5.1
5.5.2
5.5.3
5.5.4
5.5.5
5.6.0
5.6.1
5.6.2
5.6.3
5.6.4
5.6.5
5.6.6
5.6.7
5.6.8
5.6.9
5.7.0
5.7.1
5.7.2
5.7.3
5.8.0
5.8.1
5.8.2
5.8.3
5.8.4
5.9.0
5.9.1
Fixed in
5.9.2
References Updated Apr 10, 2026 · Source: OSV.dev |
5.6.1
patch
|
|
5.6.0
minor
1 CVE
GHSA-vj8v-p5vw-m6v5
Apr 10, 2026
xrootd has path traversal in directory listing that allows access to the parent directory via trailing ".." pattern
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryA path traversal vulnerability in XRootD allows users to escape the exported directory scope and enumerate the contents of the parent directory by appending This bypass ignores the Affected component
PoCConfiguration
Steps to reproduceNormal behavior (access outside export is denied):
Bypass via trailing
Also exploitable via HTTP PROPFIND:
Returns HTTP 200 with full listing of the parent directory, including unexported entries ( However, file download via this path traversal is blocked:
ImpactAn attacker can enumerate directories and filenames outside the authorized export scope defined by File download is not possible through this vector, as This vulnerability could affect all XRootD deployments regardless of authentication configuration, as it bypasses the export path restriction itself. Suggested fixIn
Affected versions
4.10.0
4.11.0
4.11.1
4.11.2
4.11.3
4.12.0
4.12.2
4.12.3
4.12.4
4.12.5
4.12.6
4.12.7
+ 46 more Show less
4.8.4
4.8.5
4.9.0
4.9.1
5.0.0
5.0.1
5.0.2
5.0.3
5.1.1
5.2.0
5.3.0
5.3.1
5.3.2
5.3.3
5.3.4
5.4.0
5.4.1
5.4.2
5.4.3
5.5.0
5.5.1
5.5.2
5.5.3
5.5.4
5.5.5
5.6.0
5.6.1
5.6.2
5.6.3
5.6.4
5.6.5
5.6.6
5.6.7
5.6.8
5.6.9
5.7.0
5.7.1
5.7.2
5.7.3
5.8.0
5.8.1
5.8.2
5.8.3
5.8.4
5.9.0
5.9.1
Fixed in
5.9.2
References Updated Apr 10, 2026 · Source: OSV.dev |
5.6.0
minor
|
|
5.5.5
patch
1 CVE
GHSA-vj8v-p5vw-m6v5
Apr 10, 2026
xrootd has path traversal in directory listing that allows access to the parent directory via trailing ".." pattern
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryA path traversal vulnerability in XRootD allows users to escape the exported directory scope and enumerate the contents of the parent directory by appending This bypass ignores the Affected component
PoCConfiguration
Steps to reproduceNormal behavior (access outside export is denied):
Bypass via trailing
Also exploitable via HTTP PROPFIND:
Returns HTTP 200 with full listing of the parent directory, including unexported entries ( However, file download via this path traversal is blocked:
ImpactAn attacker can enumerate directories and filenames outside the authorized export scope defined by File download is not possible through this vector, as This vulnerability could affect all XRootD deployments regardless of authentication configuration, as it bypasses the export path restriction itself. Suggested fixIn
Affected versions
4.10.0
4.11.0
4.11.1
4.11.2
4.11.3
4.12.0
4.12.2
4.12.3
4.12.4
4.12.5
4.12.6
4.12.7
+ 46 more Show less
4.8.4
4.8.5
4.9.0
4.9.1
5.0.0
5.0.1
5.0.2
5.0.3
5.1.1
5.2.0
5.3.0
5.3.1
5.3.2
5.3.3
5.3.4
5.4.0
5.4.1
5.4.2
5.4.3
5.5.0
5.5.1
5.5.2
5.5.3
5.5.4
5.5.5
5.6.0
5.6.1
5.6.2
5.6.3
5.6.4
5.6.5
5.6.6
5.6.7
5.6.8
5.6.9
5.7.0
5.7.1
5.7.2
5.7.3
5.8.0
5.8.1
5.8.2
5.8.3
5.8.4
5.9.0
5.9.1
Fixed in
5.9.2
References Updated Apr 10, 2026 · Source: OSV.dev |
5.5.5
patch
|
|
5.5.4
patch
1 CVE
GHSA-vj8v-p5vw-m6v5
Apr 10, 2026
xrootd has path traversal in directory listing that allows access to the parent directory via trailing ".." pattern
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryA path traversal vulnerability in XRootD allows users to escape the exported directory scope and enumerate the contents of the parent directory by appending This bypass ignores the Affected component
PoCConfiguration
Steps to reproduceNormal behavior (access outside export is denied):
Bypass via trailing
Also exploitable via HTTP PROPFIND:
Returns HTTP 200 with full listing of the parent directory, including unexported entries ( However, file download via this path traversal is blocked:
ImpactAn attacker can enumerate directories and filenames outside the authorized export scope defined by File download is not possible through this vector, as This vulnerability could affect all XRootD deployments regardless of authentication configuration, as it bypasses the export path restriction itself. Suggested fixIn
Affected versions
4.10.0
4.11.0
4.11.1
4.11.2
4.11.3
4.12.0
4.12.2
4.12.3
4.12.4
4.12.5
4.12.6
4.12.7
+ 46 more Show less
4.8.4
4.8.5
4.9.0
4.9.1
5.0.0
5.0.1
5.0.2
5.0.3
5.1.1
5.2.0
5.3.0
5.3.1
5.3.2
5.3.3
5.3.4
5.4.0
5.4.1
5.4.2
5.4.3
5.5.0
5.5.1
5.5.2
5.5.3
5.5.4
5.5.5
5.6.0
5.6.1
5.6.2
5.6.3
5.6.4
5.6.5
5.6.6
5.6.7
5.6.8
5.6.9
5.7.0
5.7.1
5.7.2
5.7.3
5.8.0
5.8.1
5.8.2
5.8.3
5.8.4
5.9.0
5.9.1
Fixed in
5.9.2
References Updated Apr 10, 2026 · Source: OSV.dev |
5.5.4
patch
|
|
5.5.3
patch
1 CVE
GHSA-vj8v-p5vw-m6v5
Apr 10, 2026
xrootd has path traversal in directory listing that allows access to the parent directory via trailing ".." pattern
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryA path traversal vulnerability in XRootD allows users to escape the exported directory scope and enumerate the contents of the parent directory by appending This bypass ignores the Affected component
PoCConfiguration
Steps to reproduceNormal behavior (access outside export is denied):
Bypass via trailing
Also exploitable via HTTP PROPFIND:
Returns HTTP 200 with full listing of the parent directory, including unexported entries ( However, file download via this path traversal is blocked:
ImpactAn attacker can enumerate directories and filenames outside the authorized export scope defined by File download is not possible through this vector, as This vulnerability could affect all XRootD deployments regardless of authentication configuration, as it bypasses the export path restriction itself. Suggested fixIn
Affected versions
4.10.0
4.11.0
4.11.1
4.11.2
4.11.3
4.12.0
4.12.2
4.12.3
4.12.4
4.12.5
4.12.6
4.12.7
+ 46 more Show less
4.8.4
4.8.5
4.9.0
4.9.1
5.0.0
5.0.1
5.0.2
5.0.3
5.1.1
5.2.0
5.3.0
5.3.1
5.3.2
5.3.3
5.3.4
5.4.0
5.4.1
5.4.2
5.4.3
5.5.0
5.5.1
5.5.2
5.5.3
5.5.4
5.5.5
5.6.0
5.6.1
5.6.2
5.6.3
5.6.4
5.6.5
5.6.6
5.6.7
5.6.8
5.6.9
5.7.0
5.7.1
5.7.2
5.7.3
5.8.0
5.8.1
5.8.2
5.8.3
5.8.4
5.9.0
5.9.1
Fixed in
5.9.2
References Updated Apr 10, 2026 · Source: OSV.dev |
5.5.3
patch
|
|
5.5.2
patch
1 CVE
GHSA-vj8v-p5vw-m6v5
Apr 10, 2026
xrootd has path traversal in directory listing that allows access to the parent directory via trailing ".." pattern
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryA path traversal vulnerability in XRootD allows users to escape the exported directory scope and enumerate the contents of the parent directory by appending This bypass ignores the Affected component
PoCConfiguration
Steps to reproduceNormal behavior (access outside export is denied):
Bypass via trailing
Also exploitable via HTTP PROPFIND:
Returns HTTP 200 with full listing of the parent directory, including unexported entries ( However, file download via this path traversal is blocked:
ImpactAn attacker can enumerate directories and filenames outside the authorized export scope defined by File download is not possible through this vector, as This vulnerability could affect all XRootD deployments regardless of authentication configuration, as it bypasses the export path restriction itself. Suggested fixIn
Affected versions
4.10.0
4.11.0
4.11.1
4.11.2
4.11.3
4.12.0
4.12.2
4.12.3
4.12.4
4.12.5
4.12.6
4.12.7
+ 46 more Show less
4.8.4
4.8.5
4.9.0
4.9.1
5.0.0
5.0.1
5.0.2
5.0.3
5.1.1
5.2.0
5.3.0
5.3.1
5.3.2
5.3.3
5.3.4
5.4.0
5.4.1
5.4.2
5.4.3
5.5.0
5.5.1
5.5.2
5.5.3
5.5.4
5.5.5
5.6.0
5.6.1
5.6.2
5.6.3
5.6.4
5.6.5
5.6.6
5.6.7
5.6.8
5.6.9
5.7.0
5.7.1
5.7.2
5.7.3
5.8.0
5.8.1
5.8.2
5.8.3
5.8.4
5.9.0
5.9.1
Fixed in
5.9.2
References Updated Apr 10, 2026 · Source: OSV.dev |
5.5.2
patch
|
|
5.5.1
patch
1 CVE
GHSA-vj8v-p5vw-m6v5
Apr 10, 2026
xrootd has path traversal in directory listing that allows access to the parent directory via trailing ".." pattern
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryA path traversal vulnerability in XRootD allows users to escape the exported directory scope and enumerate the contents of the parent directory by appending This bypass ignores the Affected component
PoCConfiguration
Steps to reproduceNormal behavior (access outside export is denied):
Bypass via trailing
Also exploitable via HTTP PROPFIND:
Returns HTTP 200 with full listing of the parent directory, including unexported entries ( However, file download via this path traversal is blocked:
ImpactAn attacker can enumerate directories and filenames outside the authorized export scope defined by File download is not possible through this vector, as This vulnerability could affect all XRootD deployments regardless of authentication configuration, as it bypasses the export path restriction itself. Suggested fixIn
Affected versions
4.10.0
4.11.0
4.11.1
4.11.2
4.11.3
4.12.0
4.12.2
4.12.3
4.12.4
4.12.5
4.12.6
4.12.7
+ 46 more Show less
4.8.4
4.8.5
4.9.0
4.9.1
5.0.0
5.0.1
5.0.2
5.0.3
5.1.1
5.2.0
5.3.0
5.3.1
5.3.2
5.3.3
5.3.4
5.4.0
5.4.1
5.4.2
5.4.3
5.5.0
5.5.1
5.5.2
5.5.3
5.5.4
5.5.5
5.6.0
5.6.1
5.6.2
5.6.3
5.6.4
5.6.5
5.6.6
5.6.7
5.6.8
5.6.9
5.7.0
5.7.1
5.7.2
5.7.3
5.8.0
5.8.1
5.8.2
5.8.3
5.8.4
5.9.0
5.9.1
Fixed in
5.9.2
References Updated Apr 10, 2026 · Source: OSV.dev |
5.5.1
patch
|
|
5.5.0
minor
1 CVE
GHSA-vj8v-p5vw-m6v5
Apr 10, 2026
xrootd has path traversal in directory listing that allows access to the parent directory via trailing ".." pattern
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryA path traversal vulnerability in XRootD allows users to escape the exported directory scope and enumerate the contents of the parent directory by appending This bypass ignores the Affected component
PoCConfiguration
Steps to reproduceNormal behavior (access outside export is denied):
Bypass via trailing
Also exploitable via HTTP PROPFIND:
Returns HTTP 200 with full listing of the parent directory, including unexported entries ( However, file download via this path traversal is blocked:
ImpactAn attacker can enumerate directories and filenames outside the authorized export scope defined by File download is not possible through this vector, as This vulnerability could affect all XRootD deployments regardless of authentication configuration, as it bypasses the export path restriction itself. Suggested fixIn
Affected versions
4.10.0
4.11.0
4.11.1
4.11.2
4.11.3
4.12.0
4.12.2
4.12.3
4.12.4
4.12.5
4.12.6
4.12.7
+ 46 more Show less
4.8.4
4.8.5
4.9.0
4.9.1
5.0.0
5.0.1
5.0.2
5.0.3
5.1.1
5.2.0
5.3.0
5.3.1
5.3.2
5.3.3
5.3.4
5.4.0
5.4.1
5.4.2
5.4.3
5.5.0
5.5.1
5.5.2
5.5.3
5.5.4
5.5.5
5.6.0
5.6.1
5.6.2
5.6.3
5.6.4
5.6.5
5.6.6
5.6.7
5.6.8
5.6.9
5.7.0
5.7.1
5.7.2
5.7.3
5.8.0
5.8.1
5.8.2
5.8.3
5.8.4
5.9.0
5.9.1
Fixed in
5.9.2
References Updated Apr 10, 2026 · Source: OSV.dev |
5.5.0
minor
|
|
5.4.3
patch
1 CVE
GHSA-vj8v-p5vw-m6v5
Apr 10, 2026
xrootd has path traversal in directory listing that allows access to the parent directory via trailing ".." pattern
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryA path traversal vulnerability in XRootD allows users to escape the exported directory scope and enumerate the contents of the parent directory by appending This bypass ignores the Affected component
PoCConfiguration
Steps to reproduceNormal behavior (access outside export is denied):
Bypass via trailing
Also exploitable via HTTP PROPFIND:
Returns HTTP 200 with full listing of the parent directory, including unexported entries ( However, file download via this path traversal is blocked:
ImpactAn attacker can enumerate directories and filenames outside the authorized export scope defined by File download is not possible through this vector, as This vulnerability could affect all XRootD deployments regardless of authentication configuration, as it bypasses the export path restriction itself. Suggested fixIn
Affected versions
4.10.0
4.11.0
4.11.1
4.11.2
4.11.3
4.12.0
4.12.2
4.12.3
4.12.4
4.12.5
4.12.6
4.12.7
+ 46 more Show less
4.8.4
4.8.5
4.9.0
4.9.1
5.0.0
5.0.1
5.0.2
5.0.3
5.1.1
5.2.0
5.3.0
5.3.1
5.3.2
5.3.3
5.3.4
5.4.0
5.4.1
5.4.2
5.4.3
5.5.0
5.5.1
5.5.2
5.5.3
5.5.4
5.5.5
5.6.0
5.6.1
5.6.2
5.6.3
5.6.4
5.6.5
5.6.6
5.6.7
5.6.8
5.6.9
5.7.0
5.7.1
5.7.2
5.7.3
5.8.0
5.8.1
5.8.2
5.8.3
5.8.4
5.9.0
5.9.1
Fixed in
5.9.2
References Updated Apr 10, 2026 · Source: OSV.dev |
5.4.3
patch
|
|
5.4.2
patch
1 CVE
GHSA-vj8v-p5vw-m6v5
Apr 10, 2026
xrootd has path traversal in directory listing that allows access to the parent directory via trailing ".." pattern
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryA path traversal vulnerability in XRootD allows users to escape the exported directory scope and enumerate the contents of the parent directory by appending This bypass ignores the Affected component
PoCConfiguration
Steps to reproduceNormal behavior (access outside export is denied):
Bypass via trailing
Also exploitable via HTTP PROPFIND:
Returns HTTP 200 with full listing of the parent directory, including unexported entries ( However, file download via this path traversal is blocked:
ImpactAn attacker can enumerate directories and filenames outside the authorized export scope defined by File download is not possible through this vector, as This vulnerability could affect all XRootD deployments regardless of authentication configuration, as it bypasses the export path restriction itself. Suggested fixIn
Affected versions
4.10.0
4.11.0
4.11.1
4.11.2
4.11.3
4.12.0
4.12.2
4.12.3
4.12.4
4.12.5
4.12.6
4.12.7
+ 46 more Show less
4.8.4
4.8.5
4.9.0
4.9.1
5.0.0
5.0.1
5.0.2
5.0.3
5.1.1
5.2.0
5.3.0
5.3.1
5.3.2
5.3.3
5.3.4
5.4.0
5.4.1
5.4.2
5.4.3
5.5.0
5.5.1
5.5.2
5.5.3
5.5.4
5.5.5
5.6.0
5.6.1
5.6.2
5.6.3
5.6.4
5.6.5
5.6.6
5.6.7
5.6.8
5.6.9
5.7.0
5.7.1
5.7.2
5.7.3
5.8.0
5.8.1
5.8.2
5.8.3
5.8.4
5.9.0
5.9.1
Fixed in
5.9.2
References Updated Apr 10, 2026 · Source: OSV.dev |
5.4.2
patch
|
|
5.4.1
patch
1 CVE
GHSA-vj8v-p5vw-m6v5
Apr 10, 2026
xrootd has path traversal in directory listing that allows access to the parent directory via trailing ".." pattern
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryA path traversal vulnerability in XRootD allows users to escape the exported directory scope and enumerate the contents of the parent directory by appending This bypass ignores the Affected component
PoCConfiguration
Steps to reproduceNormal behavior (access outside export is denied):
Bypass via trailing
Also exploitable via HTTP PROPFIND:
Returns HTTP 200 with full listing of the parent directory, including unexported entries ( However, file download via this path traversal is blocked:
ImpactAn attacker can enumerate directories and filenames outside the authorized export scope defined by File download is not possible through this vector, as This vulnerability could affect all XRootD deployments regardless of authentication configuration, as it bypasses the export path restriction itself. Suggested fixIn
Affected versions
4.10.0
4.11.0
4.11.1
4.11.2
4.11.3
4.12.0
4.12.2
4.12.3
4.12.4
4.12.5
4.12.6
4.12.7
+ 46 more Show less
4.8.4
4.8.5
4.9.0
4.9.1
5.0.0
5.0.1
5.0.2
5.0.3
5.1.1
5.2.0
5.3.0
5.3.1
5.3.2
5.3.3
5.3.4
5.4.0
5.4.1
5.4.2
5.4.3
5.5.0
5.5.1
5.5.2
5.5.3
5.5.4
5.5.5
5.6.0
5.6.1
5.6.2
5.6.3
5.6.4
5.6.5
5.6.6
5.6.7
5.6.8
5.6.9
5.7.0
5.7.1
5.7.2
5.7.3
5.8.0
5.8.1
5.8.2
5.8.3
5.8.4
5.9.0
5.9.1
Fixed in
5.9.2
References Updated Apr 10, 2026 · Source: OSV.dev |
5.4.1
patch
|
|
5.4.0
minor
1 CVE
GHSA-vj8v-p5vw-m6v5
Apr 10, 2026
xrootd has path traversal in directory listing that allows access to the parent directory via trailing ".." pattern
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryA path traversal vulnerability in XRootD allows users to escape the exported directory scope and enumerate the contents of the parent directory by appending This bypass ignores the Affected component
PoCConfiguration
Steps to reproduceNormal behavior (access outside export is denied):
Bypass via trailing
Also exploitable via HTTP PROPFIND:
Returns HTTP 200 with full listing of the parent directory, including unexported entries ( However, file download via this path traversal is blocked:
ImpactAn attacker can enumerate directories and filenames outside the authorized export scope defined by File download is not possible through this vector, as This vulnerability could affect all XRootD deployments regardless of authentication configuration, as it bypasses the export path restriction itself. Suggested fixIn
Affected versions
4.10.0
4.11.0
4.11.1
4.11.2
4.11.3
4.12.0
4.12.2
4.12.3
4.12.4
4.12.5
4.12.6
4.12.7
+ 46 more Show less
4.8.4
4.8.5
4.9.0
4.9.1
5.0.0
5.0.1
5.0.2
5.0.3
5.1.1
5.2.0
5.3.0
5.3.1
5.3.2
5.3.3
5.3.4
5.4.0
5.4.1
5.4.2
5.4.3
5.5.0
5.5.1
5.5.2
5.5.3
5.5.4
5.5.5
5.6.0
5.6.1
5.6.2
5.6.3
5.6.4
5.6.5
5.6.6
5.6.7
5.6.8
5.6.9
5.7.0
5.7.1
5.7.2
5.7.3
5.8.0
5.8.1
5.8.2
5.8.3
5.8.4
5.9.0
5.9.1
Fixed in
5.9.2
References Updated Apr 10, 2026 · Source: OSV.dev |
5.4.0
minor
|
|
5.3.4
patch
1 CVE
GHSA-vj8v-p5vw-m6v5
Apr 10, 2026
xrootd has path traversal in directory listing that allows access to the parent directory via trailing ".." pattern
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryA path traversal vulnerability in XRootD allows users to escape the exported directory scope and enumerate the contents of the parent directory by appending This bypass ignores the Affected component
PoCConfiguration
Steps to reproduceNormal behavior (access outside export is denied):
Bypass via trailing
Also exploitable via HTTP PROPFIND:
Returns HTTP 200 with full listing of the parent directory, including unexported entries ( However, file download via this path traversal is blocked:
ImpactAn attacker can enumerate directories and filenames outside the authorized export scope defined by File download is not possible through this vector, as This vulnerability could affect all XRootD deployments regardless of authentication configuration, as it bypasses the export path restriction itself. Suggested fixIn
Affected versions
4.10.0
4.11.0
4.11.1
4.11.2
4.11.3
4.12.0
4.12.2
4.12.3
4.12.4
4.12.5
4.12.6
4.12.7
+ 46 more Show less
4.8.4
4.8.5
4.9.0
4.9.1
5.0.0
5.0.1
5.0.2
5.0.3
5.1.1
5.2.0
5.3.0
5.3.1
5.3.2
5.3.3
5.3.4
5.4.0
5.4.1
5.4.2
5.4.3
5.5.0
5.5.1
5.5.2
5.5.3
5.5.4
5.5.5
5.6.0
5.6.1
5.6.2
5.6.3
5.6.4
5.6.5
5.6.6
5.6.7
5.6.8
5.6.9
5.7.0
5.7.1
5.7.2
5.7.3
5.8.0
5.8.1
5.8.2
5.8.3
5.8.4
5.9.0
5.9.1
Fixed in
5.9.2
References Updated Apr 10, 2026 · Source: OSV.dev |
5.3.4
patch
|
|
4.12.7
patch
1 CVE
GHSA-vj8v-p5vw-m6v5
Apr 10, 2026
xrootd has path traversal in directory listing that allows access to the parent directory via trailing ".." pattern
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryA path traversal vulnerability in XRootD allows users to escape the exported directory scope and enumerate the contents of the parent directory by appending This bypass ignores the Affected component
PoCConfiguration
Steps to reproduceNormal behavior (access outside export is denied):
Bypass via trailing
Also exploitable via HTTP PROPFIND:
Returns HTTP 200 with full listing of the parent directory, including unexported entries ( However, file download via this path traversal is blocked:
ImpactAn attacker can enumerate directories and filenames outside the authorized export scope defined by File download is not possible through this vector, as This vulnerability could affect all XRootD deployments regardless of authentication configuration, as it bypasses the export path restriction itself. Suggested fixIn
Affected versions
4.10.0
4.11.0
4.11.1
4.11.2
4.11.3
4.12.0
4.12.2
4.12.3
4.12.4
4.12.5
4.12.6
4.12.7
+ 46 more Show less
4.8.4
4.8.5
4.9.0
4.9.1
5.0.0
5.0.1
5.0.2
5.0.3
5.1.1
5.2.0
5.3.0
5.3.1
5.3.2
5.3.3
5.3.4
5.4.0
5.4.1
5.4.2
5.4.3
5.5.0
5.5.1
5.5.2
5.5.3
5.5.4
5.5.5
5.6.0
5.6.1
5.6.2
5.6.3
5.6.4
5.6.5
5.6.6
5.6.7
5.6.8
5.6.9
5.7.0
5.7.1
5.7.2
5.7.3
5.8.0
5.8.1
5.8.2
5.8.3
5.8.4
5.9.0
5.9.1
Fixed in
5.9.2
References Updated Apr 10, 2026 · Source: OSV.dev |
4.12.7
patch
|
|
5.3.3
patch
1 CVE
GHSA-vj8v-p5vw-m6v5
Apr 10, 2026
xrootd has path traversal in directory listing that allows access to the parent directory via trailing ".." pattern
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryA path traversal vulnerability in XRootD allows users to escape the exported directory scope and enumerate the contents of the parent directory by appending This bypass ignores the Affected component
PoCConfiguration
Steps to reproduceNormal behavior (access outside export is denied):
Bypass via trailing
Also exploitable via HTTP PROPFIND:
Returns HTTP 200 with full listing of the parent directory, including unexported entries ( However, file download via this path traversal is blocked:
ImpactAn attacker can enumerate directories and filenames outside the authorized export scope defined by File download is not possible through this vector, as This vulnerability could affect all XRootD deployments regardless of authentication configuration, as it bypasses the export path restriction itself. Suggested fixIn
Affected versions
4.10.0
4.11.0
4.11.1
4.11.2
4.11.3
4.12.0
4.12.2
4.12.3
4.12.4
4.12.5
4.12.6
4.12.7
+ 46 more Show less
4.8.4
4.8.5
4.9.0
4.9.1
5.0.0
5.0.1
5.0.2
5.0.3
5.1.1
5.2.0
5.3.0
5.3.1
5.3.2
5.3.3
5.3.4
5.4.0
5.4.1
5.4.2
5.4.3
5.5.0
5.5.1
5.5.2
5.5.3
5.5.4
5.5.5
5.6.0
5.6.1
5.6.2
5.6.3
5.6.4
5.6.5
5.6.6
5.6.7
5.6.8
5.6.9
5.7.0
5.7.1
5.7.2
5.7.3
5.8.0
5.8.1
5.8.2
5.8.3
5.8.4
5.9.0
5.9.1
Fixed in
5.9.2
References Updated Apr 10, 2026 · Source: OSV.dev |
5.3.3
patch
|
|
5.3.2
patch
1 CVE
GHSA-vj8v-p5vw-m6v5
Apr 10, 2026
xrootd has path traversal in directory listing that allows access to the parent directory via trailing ".." pattern
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryA path traversal vulnerability in XRootD allows users to escape the exported directory scope and enumerate the contents of the parent directory by appending This bypass ignores the Affected component
PoCConfiguration
Steps to reproduceNormal behavior (access outside export is denied):
Bypass via trailing
Also exploitable via HTTP PROPFIND:
Returns HTTP 200 with full listing of the parent directory, including unexported entries ( However, file download via this path traversal is blocked:
ImpactAn attacker can enumerate directories and filenames outside the authorized export scope defined by File download is not possible through this vector, as This vulnerability could affect all XRootD deployments regardless of authentication configuration, as it bypasses the export path restriction itself. Suggested fixIn
Affected versions
4.10.0
4.11.0
4.11.1
4.11.2
4.11.3
4.12.0
4.12.2
4.12.3
4.12.4
4.12.5
4.12.6
4.12.7
+ 46 more Show less
4.8.4
4.8.5
4.9.0
4.9.1
5.0.0
5.0.1
5.0.2
5.0.3
5.1.1
5.2.0
5.3.0
5.3.1
5.3.2
5.3.3
5.3.4
5.4.0
5.4.1
5.4.2
5.4.3
5.5.0
5.5.1
5.5.2
5.5.3
5.5.4
5.5.5
5.6.0
5.6.1
5.6.2
5.6.3
5.6.4
5.6.5
5.6.6
5.6.7
5.6.8
5.6.9
5.7.0
5.7.1
5.7.2
5.7.3
5.8.0
5.8.1
5.8.2
5.8.3
5.8.4
5.9.0
5.9.1
Fixed in
5.9.2
References Updated Apr 10, 2026 · Source: OSV.dev |
5.3.2
patch
|
|
5.3.1
patch
1 CVE
GHSA-vj8v-p5vw-m6v5
Apr 10, 2026
xrootd has path traversal in directory listing that allows access to the parent directory via trailing ".." pattern
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryA path traversal vulnerability in XRootD allows users to escape the exported directory scope and enumerate the contents of the parent directory by appending This bypass ignores the Affected component
PoCConfiguration
Steps to reproduceNormal behavior (access outside export is denied):
Bypass via trailing
Also exploitable via HTTP PROPFIND:
Returns HTTP 200 with full listing of the parent directory, including unexported entries ( However, file download via this path traversal is blocked:
ImpactAn attacker can enumerate directories and filenames outside the authorized export scope defined by File download is not possible through this vector, as This vulnerability could affect all XRootD deployments regardless of authentication configuration, as it bypasses the export path restriction itself. Suggested fixIn
Affected versions
4.10.0
4.11.0
4.11.1
4.11.2
4.11.3
4.12.0
4.12.2
4.12.3
4.12.4
4.12.5
4.12.6
4.12.7
+ 46 more Show less
4.8.4
4.8.5
4.9.0
4.9.1
5.0.0
5.0.1
5.0.2
5.0.3
5.1.1
5.2.0
5.3.0
5.3.1
5.3.2
5.3.3
5.3.4
5.4.0
5.4.1
5.4.2
5.4.3
5.5.0
5.5.1
5.5.2
5.5.3
5.5.4
5.5.5
5.6.0
5.6.1
5.6.2
5.6.3
5.6.4
5.6.5
5.6.6
5.6.7
5.6.8
5.6.9
5.7.0
5.7.1
5.7.2
5.7.3
5.8.0
5.8.1
5.8.2
5.8.3
5.8.4
5.9.0
5.9.1
Fixed in
5.9.2
References Updated Apr 10, 2026 · Source: OSV.dev |
5.3.1
patch
|
|
5.3.0
minor
1 CVE
GHSA-vj8v-p5vw-m6v5
Apr 10, 2026
xrootd has path traversal in directory listing that allows access to the parent directory via trailing ".." pattern
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryA path traversal vulnerability in XRootD allows users to escape the exported directory scope and enumerate the contents of the parent directory by appending This bypass ignores the Affected component
PoCConfiguration
Steps to reproduceNormal behavior (access outside export is denied):
Bypass via trailing
Also exploitable via HTTP PROPFIND:
Returns HTTP 200 with full listing of the parent directory, including unexported entries ( However, file download via this path traversal is blocked:
ImpactAn attacker can enumerate directories and filenames outside the authorized export scope defined by File download is not possible through this vector, as This vulnerability could affect all XRootD deployments regardless of authentication configuration, as it bypasses the export path restriction itself. Suggested fixIn
Affected versions
4.10.0
4.11.0
4.11.1
4.11.2
4.11.3
4.12.0
4.12.2
4.12.3
4.12.4
4.12.5
4.12.6
4.12.7
+ 46 more Show less
4.8.4
4.8.5
4.9.0
4.9.1
5.0.0
5.0.1
5.0.2
5.0.3
5.1.1
5.2.0
5.3.0
5.3.1
5.3.2
5.3.3
5.3.4
5.4.0
5.4.1
5.4.2
5.4.3
5.5.0
5.5.1
5.5.2
5.5.3
5.5.4
5.5.5
5.6.0
5.6.1
5.6.2
5.6.3
5.6.4
5.6.5
5.6.6
5.6.7
5.6.8
5.6.9
5.7.0
5.7.1
5.7.2
5.7.3
5.8.0
5.8.1
5.8.2
5.8.3
5.8.4
5.9.0
5.9.1
Fixed in
5.9.2
References Updated Apr 10, 2026 · Source: OSV.dev |
5.3.0
minor
|
|
5.2.0
minor
1 CVE
GHSA-vj8v-p5vw-m6v5
Apr 10, 2026
xrootd has path traversal in directory listing that allows access to the parent directory via trailing ".." pattern
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryA path traversal vulnerability in XRootD allows users to escape the exported directory scope and enumerate the contents of the parent directory by appending This bypass ignores the Affected component
PoCConfiguration
Steps to reproduceNormal behavior (access outside export is denied):
Bypass via trailing
Also exploitable via HTTP PROPFIND:
Returns HTTP 200 with full listing of the parent directory, including unexported entries ( However, file download via this path traversal is blocked:
ImpactAn attacker can enumerate directories and filenames outside the authorized export scope defined by File download is not possible through this vector, as This vulnerability could affect all XRootD deployments regardless of authentication configuration, as it bypasses the export path restriction itself. Suggested fixIn
Affected versions
4.10.0
4.11.0
4.11.1
4.11.2
4.11.3
4.12.0
4.12.2
4.12.3
4.12.4
4.12.5
4.12.6
4.12.7
+ 46 more Show less
4.8.4
4.8.5
4.9.0
4.9.1
5.0.0
5.0.1
5.0.2
5.0.3
5.1.1
5.2.0
5.3.0
5.3.1
5.3.2
5.3.3
5.3.4
5.4.0
5.4.1
5.4.2
5.4.3
5.5.0
5.5.1
5.5.2
5.5.3
5.5.4
5.5.5
5.6.0
5.6.1
5.6.2
5.6.3
5.6.4
5.6.5
5.6.6
5.6.7
5.6.8
5.6.9
5.7.0
5.7.1
5.7.2
5.7.3
5.8.0
5.8.1
5.8.2
5.8.3
5.8.4
5.9.0
5.9.1
Fixed in
5.9.2
References Updated Apr 10, 2026 · Source: OSV.dev |
5.2.0
minor
|