CVE-2026-27144: Golang Go
High severity, CVSS 7.1. EPSS: 0.3% chance of exploitation in the next 30 days.
The compiler is meant to unwrap pointers which are the operands of a memory move; a no-op interface conversion prevented the compiler from making the correct determination about non-overlapping moves, potentially leading to memory corruption at runtime.
Affected products
- Golang Go: before 1.25.9 (fixed in 1.25.9); from 1.26.0, before 1.26.2 (fixed in 1.26.2)
Published 2026-04-08. Last modified 2026-07-25.