CVE-2026-27140: Golang Go
High severity, CVSS 8.8. EPSS: 0.7% chance of exploitation in the next 30 days.
SWIG file names containing 'cgo' and well-crafted payloads could lead to code smuggling and arbitrary code execution at build time due to trust layer bypass.
Affected products
- Golang Go: before 1.25.9 (fixed in 1.25.9); from 1.26.0, before 1.26.2 (fixed in 1.26.2)
Published 2026-04-08. Last modified 2026-09-10.