cmd/go vulnerability

SWIG file names containing 'cgo' and well-crafted payloads could lead to code smuggling and arbitrary code execution at build time due to trust layer bypass.

Published 8 Apr 2026Updated 7 Sep 202624 sources
CVSS 8.8

Record history

Record created from the first normalized source observation.
Metadata and source references refreshed.