CVE-2020-28367: Golang Go
High severity, CVSS 7.5. EPSS: 2.4% chance of exploitation in the next 30 days.
Code injection in the go command with cgo before Go 1.14.12 and Go 1.15.5 allows arbitrary code execution at build time via malicious gcc flags specified via a #cgo directive.
Affected products
- Golang Go: before 1.14.12 (fixed in 1.14.12); from 1.15, before 1.15.5 (fixed in 1.15.5)
Published 2020-11-18. Last modified 2026-06-17.