Back to search
CVE-2026-27140
Published: Apr 8, 2026
Modified: Apr 13, 2026
PUBLISHED
Description
SWIG file names containing 'cgo' and well-crafted payloads could lead to code smuggling and arbitrary code execution at build time due to trust layer bypass.
| Vendor | Product | Versions |
|---|---|---|
Go toolchain | cmd/go | affected 0 - < 1.25.9affected 1.26.0-0 - < 1.26.2 |
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now