Technology · Go
toolchain (Go) vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 32 vulnerabilities in toolchain (Go): 0 in the last 7 days and 2 in the last 90 days, 1 of them critical and 0 exploited in the wild. The most recent, CVE-2026-56865, was published on 13 August 2026.
- Last 7 days
- 0
- Last 90 days
- 2
- Critical, all time
- 1
- Exploited in the wild
- 0
Latest toolchain (Go) vulnerabilities
- CVE-2026-56865: Go malicious GOPROXY sumdb tile forgery bypasshighCVSS 8.4EPSS 0.1%
- CVE-2026-56864: Go GOSUMDB malicious module content bypasshighCVSS 7.5EPSS 0.3%
- CVE-2026-42501: Google Go checksum validation bypass in cmd/gohighCVSS 7.5EPSS 0.3%
- CVE-2026-39819: Google Go symlink attack in go bug commandmediumCVSS 5.3EPSS 0.1%
- CVE-2026-39817: Google Go arbitrary file write in go tool packmediumCVSS 5.9EPSS 0.2%
- CVE-2026-27144: Google Go toolchain memory corruption in cmd/compilehighCVSS 7.1EPSS 0.2%
- CVE-2026-27143: Go toolchain memory corruption in cmd/compile loop inductioncriticalCVSS 9.8EPSS 0.7%
- CVE-2026-27140: Google Go arbitrary code execution via malicious SWIG file nameshighCVSS 8.8EPSS 0.8%
- CVE-2025-61732: Google Go code smuggling in cgo via comment parsing discrepancyhighCVSS 8.6EPSS 0.5%
- CVE-2025-61731: Google Go argument injection in cmd/go cgo directivehighCVSS 7.8EPSS 0.6%
- CVE-2025-68119: GO-2026-4338 - Unexpected code execution when invoking toolchain in cmd/goinfoEPSS 0.4%
- CVE-2025-4674: GO-2025-3828 - Unexpected command execution in untrusted VCS repositories in cmd/goinfoEPSS 0.3%
- CVE-2025-22867: GO-2025-3428 - Arbitrary code execution during build on darwin in cmd/goinfoEPSS 0.7%
- CVE-2024-45340: GO-2025-3383 - GOAUTH credential leak in cmd/goinfoEPSS 0.7%
- CVE-2023-24531: GO-2024-2962 - Output of "go env" does not sanitize values in cmd/goinfoEPSS 0.8%
- CVE-2024-24787: GO-2024-2825 - Arbitrary code execution during build on Darwin in cmd/goinfoEPSS 0.8%
- CVE-2023-45285: GO-2023-2383 - Command 'go get' may unexpectedly fallback to insecure git in cmd/goinfoEPSS 1.1%
- CVE-2023-39323: GO-2023-2095 - Arbitrary code execution during build via line directives in cmd/goinfoEPSS 1.8%
- CVE-2023-39320: GO-2023-2042 - Arbitrary code execution via go.mod toolchain directive in cmd/goinfoEPSS 1.8%
- CVE-2023-29402: GO-2023-1839 - Code injection via go command with cgo in cmd/goinfoEPSS 1.7%
- CVE-2023-29405: GO-2023-1842 - Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/goinfoEPSS 1.7%
- CVE-2023-29404: GO-2023-1841 - Improper handling of non-optional LDFLAGS in go command with cgo in cmd/goinfoEPSS 1.8%
- CVE-2018-7187: GO-2022-0203 - Remote command execution via "go get" command with "-insecure" option in cmd/goinfoEPSS 63.0%
- CVE-2018-6574: GO-2022-0201 - Remote command execution via "go get" command with cgo in cmd/goinfoEPSS 7.6%
- CVE-2017-15041: GO-2022-0177 - Remote command execution via "go get" in cmd/goinfoEPSS 8.9%
Most severe toolchain (Go) vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-27143: Go toolchain memory corruption in cmd/compile loop inductioncriticalCVSS 9.8EPSS 0.7%
- CVE-2026-27140: Google Go arbitrary code execution via malicious SWIG file nameshighCVSS 8.8EPSS 0.8%
- CVE-2025-61732: Google Go code smuggling in cgo via comment parsing discrepancyhighCVSS 8.6EPSS 0.5%
- CVE-2026-56865: Go malicious GOPROXY sumdb tile forgery bypasshighCVSS 8.4EPSS 0.1%
- CVE-2025-61731: Google Go argument injection in cmd/go cgo directivehighCVSS 7.8EPSS 0.6%
- CVE-2026-56864: Go GOSUMDB malicious module content bypasshighCVSS 7.5EPSS 0.3%
- CVE-2026-42501: Google Go checksum validation bypass in cmd/gohighCVSS 7.5EPSS 0.3%
- CVE-2026-27144: Google Go toolchain memory corruption in cmd/compilehighCVSS 7.1EPSS 0.2%
- CVE-2026-39817: Google Go arbitrary file write in go tool packmediumCVSS 5.9EPSS 0.2%
- CVE-2026-39819: Google Go symlink attack in go bug commandmediumCVSS 5.3EPSS 0.1%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 2 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 | |
| 28 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/toolchain.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "toolchain (Go) vulnerabilities", https://junglewise.ai/threats/technologies/toolchain, 28 September 2026.