CVE-2026-27140: Code execution vulnerability in SWIG code generation in cmd/go
Published Apr 8, 2026
·Updated
SWIG file names containing 'cgo' and well-crafted payloads could lead to code smuggling and arbitrary code execution at build time due to trust layer bypass.
Affected Software
3 affected components
go cmd/go
Golang Go<1.25.9
Golang Go>=1.26.0<1.26.2
Event History
Apr 8, 2026
CVE Published
via MITRE·01:06 AM
Data Sourced
via MITRE·01:06 AM
DescriptionWeakness
Data Sourced
via Red Hat·02:01 AM
DescriptionSeverityAffected Software
Data Sourced
via NVD·02:16 AM
DescriptionSeverityWeaknessAffected Software
Jan 23, 58467
Event
via NVD·02:47 PM
Frequently Asked Questions
1
What is the severity of CVE-2026-27140?
CVE-2026-27140 has a high severity level due to its potential for arbitrary code execution.
2
How do I fix CVE-2026-27140?
To fix CVE-2026-27140, update to Go versions 1.26.2 or later, or versions lower than 1.25.9.
3
What causes CVE-2026-27140?
CVE-2026-27140 is caused by code execution vulnerabilities in SWIG code generation within cmd/go.
4
Which software versions are affected by CVE-2026-27140?
CVE-2026-27140 affects Go cmd/go versions prior to 1.25.9 and between 1.26.0 and 1.26.2.
5
What are the potential impacts of CVE-2026-27140?
The potential impacts of CVE-2026-27140 include code smuggling and arbitrary code execution at build time.