CVE-2016-3958: Golang Go

High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.

Untrusted search path vulnerability in Go before 1.5.4 and 1.6.x before 1.6.1 on Windows allows local users to gain privileges via a Trojan horse DLL in the current working directory, related to use of the LoadLibrary function.

Affected products

  • Golang Go: from 1.5, before 1.5.4 (fixed in 1.5.4); from 1.6, before 1.6.1 (fixed in 1.6.1); version 1.6 only

Published 2016-05-23. Last modified 2026-06-17.