Go toolchain cmd/go
8 known vulnerabilities in Go toolchain cmd/go, with patch priority, exploit likelihood and the news covering them.
Latest vulnerabilities
- CVE-2026-56865 CVSS 8.4 high A malicious GOPROXY was previously capable of forging up to two sumdb tiles that allow for a requested module to bypass the GOSUMDB check…
- CVE-2026-56864 CVSS 7.5 high A malicious GOSUMDB was capable of serving arbitrary module content not contained within the transparency log. This attack allows for a…
- CVE-2026-42501 CVSS 7.5 high A malicious module proxy can exploit a flaw in the go command's validation of module checksums to bypass checksum database validation…
- CVE-2026-39819 CVSS 5.3 medium The "go bug" command writes to two files with predictable names in the system temporary directory (for example, "/tmp"). An attacker with…
- CVE-2026-39817 CVSS 5.9 medium The "go tool pack" subcommand (usually used only by the compiler as an internal tool with known-good inputs) does not sanitize output…
- CVE-2026-27140 CVSS 8.8 high SWIG file names containing 'cgo' and well-crafted payloads could lead to code smuggling and arbitrary code execution at build time due to…
- CVE-2025-61731 CVSS 7.8 high Building a malicious file with cmd/go can cause can cause a write to an attacker-controlled file with partial control of the file content…
- CVE-2025-4674 CVSS 8.6 high The go command may execute unexpected commands when operating in untrusted VCS repositories. This occurs when possibly dangerous VCS…