CVE-2026-27140 PUBLISHED

Code execution vulnerability in SWIG code generation in cmd/go

Assigner: Go
Reserved: 17.02.2026 Published: 08.04.2026 Updated: 08.04.2026

SWIG file names containing 'cgo' and well-crafted payloads could lead to code smuggling and arbitrary code execution at build time due to trust layer bypass.

Product Status

Vendor Go toolchain
Product cmd/go
Versions Default: unaffected
  • affected from 0 to 1.25.9 (excl.)
  • affected from 1.26.0-0 to 1.26.2 (excl.)

Credits

  • Juho Forsén of Mattermost

References

Problem Types

  • CWE-501: Trust Boundary Violation