{"schema_version":1,"title":"toolchain (Go) vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 32 vulnerabilities in toolchain (Go): 0 in the last 7 days and 2 in the last 90 days, 1 of them critical and 0 exploited in the wild. The most recent, CVE-2026-56865, was published on 13 August 2026.","url":"https://junglewise.ai/threats/technologies/toolchain","json_url":"https://junglewise.ai/threats/technologies/toolchain.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/toolchain","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":7,"all_time":32,"critical":1,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":2,"last_365_days":11},"latest":[{"cve":"CVE-2026-56865","cvss":8.4,"epss":0.0014,"slug":"cve-2026-56865-go-malicious-goproxy-sumdb-tile-forgery-bypass","title":"Go malicious GOPROXY sumdb tile forgery bypass","severity":"high","exploited":false,"published_at":"2026-08-13T22:17:22.797+00:00","url":"https://junglewise.ai/threats/cve-2026-56865-go-malicious-goproxy-sumdb-tile-forgery-bypass"},{"cve":"CVE-2026-56864","cvss":7.5,"epss":0.0032,"slug":"cve-2026-56864-go-gosumdb-malicious-module-content-bypass","title":"Go GOSUMDB malicious module content bypass","severity":"high","exploited":false,"published_at":"2026-08-13T22:17:22.677+00:00","url":"https://junglewise.ai/threats/cve-2026-56864-go-gosumdb-malicious-module-content-bypass"},{"cve":"CVE-2026-42501","cvss":7.5,"epss":0.0029,"slug":"cve-2026-42501-google-go-checksum-validation-bypass-in-cmd-go","title":"Google Go checksum validation bypass in cmd/go","severity":"high","exploited":false,"published_at":"2026-05-07T20:16:44.643+00:00","url":"https://junglewise.ai/threats/cve-2026-42501-google-go-checksum-validation-bypass-in-cmd-go"},{"cve":"CVE-2026-39819","cvss":5.3,"epss":0.0015,"slug":"cve-2026-39819-google-go-symlink-attack-in-go-bug-command","title":"Google Go symlink attack in go bug command","severity":"medium","exploited":false,"published_at":"2026-05-07T20:16:43.083+00:00","url":"https://junglewise.ai/threats/cve-2026-39819-google-go-symlink-attack-in-go-bug-command"},{"cve":"CVE-2026-39817","cvss":5.9,"epss":0.0016,"slug":"cve-2026-39817-google-go-arbitrary-file-write-in-go-tool-pack","title":"Google Go arbitrary file write in go tool pack","severity":"medium","exploited":false,"published_at":"2026-05-07T20:16:42.983+00:00","url":"https://junglewise.ai/threats/cve-2026-39817-google-go-arbitrary-file-write-in-go-tool-pack"},{"cve":"CVE-2026-27144","cvss":7.1,"epss":0.0018,"slug":"cve-2026-27144-google-go-toolchain-memory-corruption-in-cmd-compile","title":"Google Go toolchain memory corruption in cmd/compile","severity":"high","exploited":false,"published_at":"2026-04-08T02:16:03.13+00:00","url":"https://junglewise.ai/threats/cve-2026-27144-google-go-toolchain-memory-corruption-in-cmd-compile"},{"cve":"CVE-2026-27143","cvss":9.8,"epss":0.0066,"slug":"cve-2026-27143-go-toolchain-memory-corruption-in-cmd-compile-loop-induction","title":"Go toolchain memory corruption in cmd/compile loop induction","severity":"critical","exploited":false,"published_at":"2026-04-08T02:16:03.017+00:00","url":"https://junglewise.ai/threats/cve-2026-27143-go-toolchain-memory-corruption-in-cmd-compile-loop-induction"},{"cve":"CVE-2026-27140","cvss":8.8,"epss":0.0081,"slug":"cve-2026-27140-google-go-arbitrary-code-execution-via-malicious-swig-file-names","title":"Google Go arbitrary code execution via malicious SWIG file names","severity":"high","exploited":false,"published_at":"2026-04-08T02:16:02.887+00:00","url":"https://junglewise.ai/threats/cve-2026-27140-google-go-arbitrary-code-execution-via-malicious-swig-file-names"},{"cve":"CVE-2025-61732","cvss":8.6,"epss":0.0049,"slug":"cve-2025-61732-google-go-code-smuggling-in-cgo-via-comment-parsing-discrepancy","title":"Google Go code smuggling in cgo via comment parsing discrepancy","severity":"high","exploited":false,"published_at":"2026-02-05T04:15:50.873+00:00","url":"https://junglewise.ai/threats/cve-2025-61732-google-go-code-smuggling-in-cgo-via-comment-parsing-discrepancy"},{"cve":"CVE-2025-61731","cvss":7.8,"epss":0.0062,"slug":"cve-2025-61731-google-go-argument-injection-in-cmd-go-cgo-directive","title":"Google Go argument injection in cmd/go cgo directive","severity":"high","exploited":false,"published_at":"2026-01-28T20:16:10.073+00:00","url":"https://junglewise.ai/threats/cve-2025-61731-google-go-argument-injection-in-cmd-go-cgo-directive"},{"cve":"CVE-2025-68119","epss":0.0038,"slug":"cve-2025-68119-go-2026-4338-unexpected-code-execution-when-invoking-toolchain-in","title":"GO-2026-4338 - Unexpected code execution when invoking toolchain in cmd/go","severity":"info","exploited":false,"published_at":"2026-01-28T19:07:48+00:00","url":"https://junglewise.ai/threats/cve-2025-68119-go-2026-4338-unexpected-code-execution-when-invoking-toolchain-in"},{"cve":"CVE-2025-4674","epss":0.003,"slug":"cve-2025-4674-go-2025-3828-unexpected-command-execution-in-untrusted-vcs","title":"GO-2025-3828 - Unexpected command execution in untrusted VCS repositories in cmd/go","severity":"info","exploited":false,"published_at":"2025-07-29T21:02:00+00:00","url":"https://junglewise.ai/threats/cve-2025-4674-go-2025-3828-unexpected-command-execution-in-untrusted-vcs"},{"cve":"CVE-2025-22867","epss":0.0065,"slug":"cve-2025-22867-go-2025-3428-arbitrary-code-execution-during-build-on-darwin-in","title":"GO-2025-3428 - Arbitrary code execution during build on darwin in cmd/go","severity":"info","exploited":false,"published_at":"2025-02-06T16:54:38+00:00","url":"https://junglewise.ai/threats/cve-2025-22867-go-2025-3428-arbitrary-code-execution-during-build-on-darwin-in"},{"cve":"CVE-2024-45340","epss":0.0071,"slug":"cve-2024-45340-go-2025-3383-goauth-credential-leak-in-cmd-go","title":"GO-2025-3383 - GOAUTH credential leak in cmd/go","severity":"info","exploited":false,"published_at":"2025-01-28T00:47:30+00:00","url":"https://junglewise.ai/threats/cve-2024-45340-go-2025-3383-goauth-credential-leak-in-cmd-go"},{"cve":"CVE-2023-24531","epss":0.0084,"slug":"cve-2023-24531-go-2024-2962-output-of-go-env-does-not-sanitize-values-in-cmd-go","title":"GO-2024-2962 - Output of \"go env\" does not sanitize values in cmd/go","severity":"info","exploited":false,"published_at":"2024-07-02T19:27:52+00:00","url":"https://junglewise.ai/threats/cve-2023-24531-go-2024-2962-output-of-go-env-does-not-sanitize-values-in-cmd-go"},{"cve":"CVE-2024-24787","epss":0.0077,"slug":"cve-2024-24787-go-2024-2825-arbitrary-code-execution-during-build-on-darwin-in","title":"GO-2024-2825 - Arbitrary code execution during build on Darwin in cmd/go","severity":"info","exploited":false,"published_at":"2024-05-08T15:17:04+00:00","url":"https://junglewise.ai/threats/cve-2024-24787-go-2024-2825-arbitrary-code-execution-during-build-on-darwin-in"},{"cve":"CVE-2023-45285","epss":0.0114,"slug":"cve-2023-45285-go-2023-2383-command-go-get-may-unexpectedly-fallback-to-insecure","title":"GO-2023-2383 - Command 'go get' may unexpectedly fallback to insecure git in cmd/go","severity":"info","exploited":false,"published_at":"2023-12-06T16:22:51+00:00","url":"https://junglewise.ai/threats/cve-2023-45285-go-2023-2383-command-go-get-may-unexpectedly-fallback-to-insecure"},{"cve":"CVE-2023-39323","epss":0.0176,"slug":"cve-2023-39323-go-2023-2095-arbitrary-code-execution-during-build-via-line","title":"GO-2023-2095 - Arbitrary code execution during build via line directives in cmd/go","severity":"info","exploited":false,"published_at":"2023-10-05T20:35:05+00:00","url":"https://junglewise.ai/threats/cve-2023-39323-go-2023-2095-arbitrary-code-execution-during-build-via-line"},{"cve":"CVE-2023-39320","epss":0.0176,"slug":"cve-2023-39320-go-2023-2042-arbitrary-code-execution-via-go-mod-toolchain","title":"GO-2023-2042 - Arbitrary code execution via go.mod toolchain directive in cmd/go","severity":"info","exploited":false,"published_at":"2023-09-07T16:11:28+00:00","url":"https://junglewise.ai/threats/cve-2023-39320-go-2023-2042-arbitrary-code-execution-via-go-mod-toolchain"},{"cve":"CVE-2023-29402","epss":0.0169,"slug":"cve-2023-29402-go-2023-1839-code-injection-via-go-command-with-cgo-in-cmd-go","title":"GO-2023-1839 - Code injection via go command with cgo in cmd/go","severity":"info","exploited":false,"published_at":"2023-06-08T20:16:16+00:00","url":"https://junglewise.ai/threats/cve-2023-29402-go-2023-1839-code-injection-via-go-command-with-cgo-in-cmd-go"},{"cve":"CVE-2023-29405","epss":0.0171,"slug":"cve-2023-29405-go-2023-1842-improper-sanitization-of-ldflags-with-embedded","title":"GO-2023-1842 - Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go","severity":"info","exploited":false,"published_at":"2023-06-08T20:15:53+00:00","url":"https://junglewise.ai/threats/cve-2023-29405-go-2023-1842-improper-sanitization-of-ldflags-with-embedded"},{"cve":"CVE-2023-29404","epss":0.0184,"slug":"cve-2023-29404-go-2023-1841-improper-handling-of-non-optional-ldflags-in-go","title":"GO-2023-1841 - Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go","severity":"info","exploited":false,"published_at":"2023-06-08T20:15:47+00:00","url":"https://junglewise.ai/threats/cve-2023-29404-go-2023-1841-improper-handling-of-non-optional-ldflags-in-go"},{"cve":"CVE-2018-7187","epss":0.6303,"slug":"cve-2018-7187-go-2022-0203-remote-command-execution-via-go-get-command-with","title":"GO-2022-0203 - Remote command execution via \"go get\" command with \"-insecure\" option in cmd/go","severity":"info","exploited":false,"published_at":"2022-08-09T23:19:00+00:00","url":"https://junglewise.ai/threats/cve-2018-7187-go-2022-0203-remote-command-execution-via-go-get-command-with"},{"cve":"CVE-2018-6574","epss":0.0763,"slug":"cve-2018-6574-go-2022-0201-remote-command-execution-via-go-get-command-with-cgo","title":"GO-2022-0201 - Remote command execution via \"go get\" command with cgo in cmd/go","severity":"info","exploited":false,"published_at":"2022-08-09T18:15:41+00:00","url":"https://junglewise.ai/threats/cve-2018-6574-go-2022-0201-remote-command-execution-via-go-get-command-with-cgo"},{"cve":"CVE-2017-15041","epss":0.0894,"slug":"cve-2017-15041-go-2022-0177-remote-command-execution-via-go-get-in-cmd-go","title":"GO-2022-0177 - Remote command execution via \"go get\" in cmd/go","severity":"info","exploited":false,"published_at":"2022-08-09T17:31:35+00:00","url":"https://junglewise.ai/threats/cve-2017-15041-go-2022-0177-remote-command-execution-via-go-get-in-cmd-go"}],"weekly":[{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-28","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"github.com/mattermost/mattermost-server (Go)","slug":"github-com-mattermost-mattermost-server","vulnerabilities":274,"url":"https://junglewise.ai/threats/technologies/github-com-mattermost-mattermost-server"},{"name":"github.com/mattermost/mattermost-server/v6 (Go)","slug":"github-com-mattermost-mattermost-server-v6","vulnerabilities":188,"url":"https://junglewise.ai/threats/technologies/github-com-mattermost-mattermost-server-v6"},{"name":"github.com/mattermost/mattermost-server/v5 (Go)","slug":"github-com-mattermost-mattermost-server-v5","vulnerabilities":186,"url":"https://junglewise.ai/threats/technologies/github-com-mattermost-mattermost-server-v5"},{"name":"github.com/mattermost/mattermost/server/v8 (Go)","slug":"github-com-mattermost-mattermost-server-v8","vulnerabilities":182,"url":"https://junglewise.ai/threats/technologies/github-com-mattermost-mattermost-server-v8"},{"name":"stdlib (Go)","slug":"go-stdlib","vulnerabilities":161,"url":"https://junglewise.ai/threats/technologies/go-stdlib"},{"name":"github.com/siyuan-note/siyuan/kernel (Go)","slug":"github-com-siyuan-note-siyuan-kernel","vulnerabilities":158,"url":"https://junglewise.ai/threats/technologies/github-com-siyuan-note-siyuan-kernel"},{"name":"code.gitea.io/gitea (Go)","slug":"code-gitea-io-gitea","vulnerabilities":128,"url":"https://junglewise.ai/threats/technologies/code-gitea-io-gitea"},{"name":"gogs.io/gogs (Go)","slug":"gogs-io-gogs","vulnerabilities":82,"url":"https://junglewise.ai/threats/technologies/gogs-io-gogs"},{"name":"github.com/traefik/traefik (Go)","slug":"github-com-traefik-traefik","vulnerabilities":75,"url":"https://junglewise.ai/threats/technologies/github-com-traefik-traefik"},{"name":"github.com/usememos/memos (Go)","slug":"github-com-usememos-memos","vulnerabilities":75,"url":"https://junglewise.ai/threats/technologies/github-com-usememos-memos"},{"name":"github.com/traefik/traefik/v2 (Go)","slug":"github-com-traefik-traefik-v2","vulnerabilities":73,"url":"https://junglewise.ai/threats/technologies/github-com-traefik-traefik-v2"},{"name":"github.com/traefik/traefik/v3 (Go)","slug":"github-com-traefik-traefik-v3","vulnerabilities":68,"url":"https://junglewise.ai/threats/technologies/github-com-traefik-traefik-v3"}],"technology":{"hub":true,"name":"toolchain (Go)","slug":"toolchain","vendor":{"name":"Go","slug":"go","url":"https://junglewise.ai/threats/vendors/go"},"aliases":[],"url":"https://junglewise.ai/threats/technologies/toolchain"},"most_severe":[{"cve":"CVE-2026-27143","cvss":9.8,"epss":0.0066,"slug":"cve-2026-27143-go-toolchain-memory-corruption-in-cmd-compile-loop-induction","title":"Go toolchain memory corruption in cmd/compile loop induction","severity":"critical","exploited":false,"published_at":"2026-04-08T02:16:03.017+00:00","url":"https://junglewise.ai/threats/cve-2026-27143-go-toolchain-memory-corruption-in-cmd-compile-loop-induction"},{"cve":"CVE-2026-27140","cvss":8.8,"epss":0.0081,"slug":"cve-2026-27140-google-go-arbitrary-code-execution-via-malicious-swig-file-names","title":"Google Go arbitrary code execution via malicious SWIG file names","severity":"high","exploited":false,"published_at":"2026-04-08T02:16:02.887+00:00","url":"https://junglewise.ai/threats/cve-2026-27140-google-go-arbitrary-code-execution-via-malicious-swig-file-names"},{"cve":"CVE-2025-61732","cvss":8.6,"epss":0.0049,"slug":"cve-2025-61732-google-go-code-smuggling-in-cgo-via-comment-parsing-discrepancy","title":"Google Go code smuggling in cgo via comment parsing discrepancy","severity":"high","exploited":false,"published_at":"2026-02-05T04:15:50.873+00:00","url":"https://junglewise.ai/threats/cve-2025-61732-google-go-code-smuggling-in-cgo-via-comment-parsing-discrepancy"},{"cve":"CVE-2026-56865","cvss":8.4,"epss":0.0014,"slug":"cve-2026-56865-go-malicious-goproxy-sumdb-tile-forgery-bypass","title":"Go malicious GOPROXY sumdb tile forgery bypass","severity":"high","exploited":false,"published_at":"2026-08-13T22:17:22.797+00:00","url":"https://junglewise.ai/threats/cve-2026-56865-go-malicious-goproxy-sumdb-tile-forgery-bypass"},{"cve":"CVE-2025-61731","cvss":7.8,"epss":0.0062,"slug":"cve-2025-61731-google-go-argument-injection-in-cmd-go-cgo-directive","title":"Google Go argument injection in cmd/go cgo directive","severity":"high","exploited":false,"published_at":"2026-01-28T20:16:10.073+00:00","url":"https://junglewise.ai/threats/cve-2025-61731-google-go-argument-injection-in-cmd-go-cgo-directive"},{"cve":"CVE-2026-56864","cvss":7.5,"epss":0.0032,"slug":"cve-2026-56864-go-gosumdb-malicious-module-content-bypass","title":"Go GOSUMDB malicious module content bypass","severity":"high","exploited":false,"published_at":"2026-08-13T22:17:22.677+00:00","url":"https://junglewise.ai/threats/cve-2026-56864-go-gosumdb-malicious-module-content-bypass"},{"cve":"CVE-2026-42501","cvss":7.5,"epss":0.0029,"slug":"cve-2026-42501-google-go-checksum-validation-bypass-in-cmd-go","title":"Google Go checksum validation bypass in cmd/go","severity":"high","exploited":false,"published_at":"2026-05-07T20:16:44.643+00:00","url":"https://junglewise.ai/threats/cve-2026-42501-google-go-checksum-validation-bypass-in-cmd-go"},{"cve":"CVE-2026-27144","cvss":7.1,"epss":0.0018,"slug":"cve-2026-27144-google-go-toolchain-memory-corruption-in-cmd-compile","title":"Google Go toolchain memory corruption in cmd/compile","severity":"high","exploited":false,"published_at":"2026-04-08T02:16:03.13+00:00","url":"https://junglewise.ai/threats/cve-2026-27144-google-go-toolchain-memory-corruption-in-cmd-compile"},{"cve":"CVE-2026-39817","cvss":5.9,"epss":0.0016,"slug":"cve-2026-39817-google-go-arbitrary-file-write-in-go-tool-pack","title":"Google Go arbitrary file write in go tool pack","severity":"medium","exploited":false,"published_at":"2026-05-07T20:16:42.983+00:00","url":"https://junglewise.ai/threats/cve-2026-39817-google-go-arbitrary-file-write-in-go-tool-pack"},{"cve":"CVE-2026-39819","cvss":5.3,"epss":0.0015,"slug":"cve-2026-39819-google-go-symlink-attack-in-go-bug-command","title":"Google Go symlink attack in go bug command","severity":"medium","exploited":false,"published_at":"2026-05-07T20:16:43.083+00:00","url":"https://junglewise.ai/threats/cve-2026-39819-google-go-symlink-attack-in-go-bug-command"}],"generated_at":"2026-09-28T03:07:00.154823+00:00"}