SWIG cgo filename execution in Go cmd/go <1.26.2
CVE-2026-27140 Published on April 8, 2026

Code execution vulnerability in SWIG code generation in cmd/go
SWIG file names containing 'cgo' and well-crafted payloads could lead to code smuggling and arbitrary code execution at build time due to trust layer bypass.

NVD

Vulnerability Analysis

CVE-2026-27140 is exploitable with network access, requires user interaction and a small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to be critical as this vulnerability has a high impact to the confidentiality, integrity and availability of this component.

Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
LOW
User Interaction:
REQUIRED
Scope:
CHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
HIGH

Weakness Type

Improper Restriction of Names for Files and Other Resources

The application constructs the name of a file or other resource using input from an upstream component, but it does not restrict or incorrectly restricts the resulting name. This may produce resultant weaknesses. For instance, if the names of these resources contain scripting characters, it is possible that a script may get executed in the client's browser if the application ever displays the name of the resource on a dynamically generated web page. Alternately, if the resources are consumed by some application parser, a specially crafted name can exploit some vulnerability internal to the parser, potentially resulting in execution of arbitrary code on the server machine. The problems will vary based on the context of usage of such malformed resource names and whether vulnerabilities are present in or assumptions are made by the targeted technology that would make code execution possible.


Products Associated with CVE-2026-27140

You can be notified by email with stack.watch whenever vulnerabilities like CVE-2026-27140 are published in these products:

 
 
 
 
 
 
 
 
 
 
 
 

Affected Versions

Go toolchain cmd/go: Red Hat Enterprise Linux 10: Red Hat Enterprise Linux 10.0 Extended Update Support: Red Hat Enterprise Linux 8: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support: Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support: Red Hat Enterprise Linux 8.6 Telecommunications Update Service: Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions: Red Hat Enterprise Linux 8.8 Telecommunications Update Service: Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions: Red Hat Enterprise Linux 9: Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions: Red Hat Enterprise Linux 9.4 Extended Update Support: Red Hat Enterprise Linux 9.6 Extended Update Support: Red Hat OpenShift Container Platform 4.17: Red Hat OpenShift Container Platform 4.18: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Service Mesh 2: Red Hat OpenShift Service Mesh 2: Red Hat OpenShift Service Mesh 2: Red Hat OpenShift Service Mesh 2: Red Hat OpenShift Service Mesh 2: Red Hat OpenShift Service Mesh 2: Red Hat OpenShift Service Mesh 2: Red Hat OpenShift Service Mesh 3: Red Hat OpenShift Service Mesh 3: Red Hat OpenShift Service Mesh 3: Red Hat OpenShift Service Mesh 3: Red Hat OpenShift Service Mesh 3: Red Hat OpenShift Service Mesh 3: Red Hat Enterprise Linux 8: Red Hat Hardened Images: Red Hat Hardened Images: Red Hat OpenShift Container Platform 4: Red Hat OpenShift Virtualization 4: Red Hat OpenShift Virtualization 4:

Exploit Probability

EPSS
0.66%
Percentile
47.78%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.