CVE-2025-61732: Golang Go
High severity, CVSS 8.6. EPSS: 0.5% chance of exploitation in the next 30 days.
A discrepancy between how Go and C/C++ comments were parsed allowed for code smuggling into the resulting cgo binary.
Affected products
- Golang Go: before 1.24.13 (fixed in 1.24.13); from 1.25.0, before 1.25.7 (fixed in 1.25.7)
Published 2026-02-05. Last modified 2026-09-10.