Back to search
CVE-2026-39819
Published: May 7, 2026
Modified: May 8, 2026
PUBLISHED
Description
The "go bug" command writes to two files with predictable names in the system temporary directory (for example, "/tmp"). An attacker with access to the temporary directory can create a symlink in one of these names, causing "go bug" to overwrite the target of the symlink.
| Vendor | Product | Versions |
|---|---|---|
Go toolchain | cmd/go | affected 0 - < 1.25.10affected 1.26.0-0 - < 1.26.3 |
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now