CVE-2026-27140

SWIG file names containing 'cgo' and well-crafted payloads could lead to code smuggling and arbitrary code execution at build time due to trust layer bypass.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:golang:go:*:*:*:*:*:*:*:*
cpe:2.3:a:golang:go:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-04-08 02:16

Updated : 2026-09-10 13:17


NVD link : CVE-2026-27140

Mitre link : CVE-2026-27140

CVE.ORG link : CVE-2026-27140


JSON object : View

Products Affected

golang

  • go
CWE
CWE-863

Incorrect Authorization

CWE-641

Improper Restriction of Names for Files and Other Resources