CVE-2026-27143: Golang Go

Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.

Arithmetic over induction variables in loops were not correctly checked for underflow or overflow. As a result, the compiler would allow for invalid indexing to occur at runtime, potentially leading to memory corruption.

Affected products

  • Golang Go: before 1.25.9 (fixed in 1.25.9); from 1.26.0, before 1.26.2 (fixed in 1.26.2)

Published 2026-04-08. Last modified 2026-07-25.