CVE-2026-27140
🟡 Monitoruj
Błąd w SWIG umożliwia smuggling kodu i wykonanie dowolnego kodu podczas budowy.
CVSS
8.8
EPSS
0.7%
Exploit
none
Vendor
golang
Opis źródłowy (NVD)
SWIG file names containing 'cgo' and well-crafted payloads could lead to code smuggling and arbitrary code execution at build time due to trust layer bypass.
rce
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 8.8 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.7% |
| Opublikowano (NVD) | 2026-04-08 02:16:02 UTC |
| Ostatnia modyfikacja (NVD) | 2026-08-27 13:17:15 UTC |
Referencje
- https://go.dev/cl/763768 (security@golang.org) [Release Notes]
- https://go.dev/issue/78335 (security@golang.org) [Issue Tracking]
- https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU (security@golang.org) [Mailing List, Release Notes]
- https://pkg.go.dev/vuln/GO-2026-4871 (security@golang.org) [Vendor Advisory]
- https://access.redhat.com/errata/RHSA-2026:10217 (0b0ca135-0b70-47e7-9f44-1890c2a1c46c)
- https://access.redhat.com/errata/RHSA-2026:10219 (0b0ca135-0b70-47e7-9f44-1890c2a1c46c)
- https://access.redhat.com/errata/RHSA-2026:10704 (0b0ca135-0b70-47e7-9f44-1890c2a1c46c)
- https://access.redhat.com/errata/RHSA-2026:16021 (0b0ca135-0b70-47e7-9f44-1890c2a1c46c)
- https://access.redhat.com/errata/RHSA-2026:16024 (0b0ca135-0b70-47e7-9f44-1890c2a1c46c)
- https://access.redhat.com/errata/RHSA-2026:16494 (0b0ca135-0b70-47e7-9f44-1890c2a1c46c)
- https://access.redhat.com/errata/RHSA-2026:16497 (0b0ca135-0b70-47e7-9f44-1890c2a1c46c)
- https://access.redhat.com/errata/RHSA-2026:16498 (0b0ca135-0b70-47e7-9f44-1890c2a1c46c)
- https://access.redhat.com/errata/RHSA-2026:16694 (0b0ca135-0b70-47e7-9f44-1890c2a1c46c)
- https://access.redhat.com/errata/RHSA-2026:16697 (0b0ca135-0b70-47e7-9f44-1890c2a1c46c)
- https://access.redhat.com/errata/RHSA-2026:16698 (0b0ca135-0b70-47e7-9f44-1890c2a1c46c)
- https://access.redhat.com/errata/RHSA-2026:23246 (0b0ca135-0b70-47e7-9f44-1890c2a1c46c)
- https://access.redhat.com/errata/RHSA-2026:25182 (0b0ca135-0b70-47e7-9f44-1890c2a1c46c)
- https://access.redhat.com/errata/RHSA-2026:34099 (0b0ca135-0b70-47e7-9f44-1890c2a1c46c)
- https://access.redhat.com/errata/RHSA-2026:56854 (0b0ca135-0b70-47e7-9f44-1890c2a1c46c)
- https://access.redhat.com/errata/RHSA-2026:57408 (0b0ca135-0b70-47e7-9f44-1890c2a1c46c)
- https://access.redhat.com/errata/RHSA-2026:57545 (0b0ca135-0b70-47e7-9f44-1890c2a1c46c)
- https://access.redhat.com/security/cve/CVE-2026-27140 (0b0ca135-0b70-47e7-9f44-1890c2a1c46c)
- https://bugzilla.redhat.com/show_bug.cgi?id=2456341 (0b0ca135-0b70-47e7-9f44-1890c2a1c46c)
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-27140.json (0b0ca135-0b70-47e7-9f44-1890c2a1c46c)