CVE-2020-36559
Status: ModifiedHigh (7.5)—
Due to improper sanitization of user input, HTTPEngine.Handle allows for directory traversal, allowing an attacker to read files outside of the target directory that the server has permission to read.
CVSS
- Version: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Base score: 7.5
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 1.20%
- Percentile among all scored CVEs: 67
- Score date: 10/7/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
CWEs
- CWE-22
References
- https://github.com/go-aah/aah/commit/881dc9f71d1f7a4e8a9a39df9c5c081d3a2da1ec
- https://github.com/go-aah/aah/issues/266
- https://github.com/go-aah/aah/pull/267
- https://pkg.go.dev/vuln/GO-2020-0033
- https://github.com/go-aah/aah/commit/881dc9f71d1f7a4e8a9a39df9c5c081d3a2da1ec
- https://github.com/go-aah/aah/issues/266
- https://github.com/go-aah/aah/pull/267
- https://pkg.go.dev/vuln/GO-2020-0033
Raw JSON (NVD)
Show
{
"id": "CVE-2020-36559",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2020-36559",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2025-04-11T16:12:47.644464Z"
}
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 3.6,
"exploitabilityScore": 3.9
},
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 3.6,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "security@golang.org",
"affectedData": [
{
"vendor": "aahframe.work",
"product": "aahframe.work",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "0.12.4",
"versionType": "semver"
}
],
"packageName": "aahframe.work",
"collectionURL": "https://pkg.go.dev",
"defaultStatus": "unaffected",
"programRoutines": [
{
"name": "HTTPEngine.Handle"
},
{
"name": "Application.Run"
},
{
"name": "Application.ServeHTTP"
},
{
"name": "Application.Start"
}
]
}
]
}
],
"published": "2022-12-27T22:15:11.500",
"references": [
{
"url": "https://github.com/go-aah/aah/commit/881dc9f71d1f7a4e8a9a39df9c5c081d3a2da1ec",
"tags": [
"Patch",
"Third Party Advisory"
],
"source": "security@golang.org"
},
{
"url": "https://github.com/go-aah/aah/issues/266",
"tags": [
"Issue Tracking",
"Third Party Advisory"
],
"source": "security@golang.org"
},
{
"url": "https://github.com/go-aah/aah/pull/267",
"tags": [
"Third Party Advisory"
],
"source": "security@golang.org"
},
{
"url": "https://pkg.go.dev/vuln/GO-2020-0033",
"tags": [
"Third Party Advisory"
],
"source": "security@golang.org"
},
{
"url": "https://github.com/go-aah/aah/commit/881dc9f71d1f7a4e8a9a39df9c5c081d3a2da1ec",
"tags": [
"Patch",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/go-aah/aah/issues/266",
"tags": [
"Issue Tracking",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/go-aah/aah/pull/267",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://pkg.go.dev/vuln/GO-2020-0033",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-22"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Due to improper sanitization of user input, HTTPEngine.Handle allows for directory traversal, allowing an attacker to read files outside of the target directory that the server has permission to read."
},
{
"lang": "es",
"value": "Debido a una desinfección inadecuada de la entrada del usuario, HTTPEngine.Handle permite directory traversal, lo que permite a un atacante leer archivos fuera del directorio de destino para los que el servidor tiene permiso de lectura."
}
],
"lastModified": "2026-06-17T03:15:43.900",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:aahframework:aah:*:*:*:*:*:go:*:*",
"vulnerable": true,
"matchCriteriaId": "D7F9E1A9-0E79-4115-B596-DAFFB5854FF0",
"versionEndExcluding": "0.12.4"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security@golang.org"
}