CVE-2026-27140

HIGH WAF: Low
CVSS 8.8 Published: 2026-04-08
CWE-863

SWIG file names containing 'cgo' and well-crafted payloads could lead to code smuggling and arbitrary code execution at build time due to trust layer bypass.

WAF Coverage Analysis

Incorrect Authorization Low WAF Coverage

OWASP: A01:2021 Broken Access Control

Affected Software

VendorProductVersion
golanggoup to 1.25.9
golanggo1.26.0 - 1.26.2

References

Back to CVE Database