CVE-2015-8618: Golang Go
High severity, CVSS 7.5. EPSS: 2.6% chance of exploitation in the next 30 days.
The Int.Exp Montgomery code in the math/big library in Go 1.5.x before 1.5.3 mishandles carry propagation and produces incorrect output, which makes it easier for attackers to obtain private RSA keys via unspecified vectors.
Affected products
Published 2016-01-27. Last modified 2026-06-17.