CVE-2026-27140: CWE-501: Trust Boundary Violation in Go toolchain cmd/go
SWIG file names containing 'cgo' and well-crafted payloads could lead to code smuggling and arbitrary code execution at build time due to trust layer bypass.
AI Analysis
Technical Summary
This vulnerability (CVE-2026-27140) in the Go toolchain's cmd/go arises from improper handling of SWIG file names containing 'cgo'. Maliciously crafted payloads can exploit this trust boundary violation to smuggle code and achieve arbitrary code execution at build time. The issue is tracked under CWE-501 (Trust Boundary Violation) and CWE-641 (Improper Control of a Resource Through its Lifetime). The vulnerability is rated high severity with a CVSS 3.1 base score of 8.8 (AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Red Hat advisories provide updated golang packages that fix this and related vulnerabilities. The affected versions include golang prior to 1.26.0-0 as indicated in the input data.
Potential Impact
Successful exploitation allows an attacker to execute arbitrary code during the build process by bypassing trust boundaries in cmd/go when processing SWIG file names. This compromises confidentiality, integrity, and availability of the build environment and potentially the resulting binaries. The vulnerability requires no privileges and no user interaction other than triggering the build with malicious input. The high CVSS score reflects the critical impact on system security.
Mitigation Recommendations
Red Hat has released security updates for golang packages that address CVE-2026-27140. Users should apply these official patches as provided in the referenced Red Hat advisories (e.g., RHSA-2026:16024 and others). Since this is a vulnerability in the build toolchain, updating to the fixed golang package version is the recommended remediation. Patch status is not explicitly stated in the input but the presence of multiple Red Hat errata indicates that fixes are available. Check the vendor advisories for detailed update instructions and apply them promptly.
CVE-2026-27140: CWE-501: Trust Boundary Violation in Go toolchain cmd/go
Description
SWIG file names containing 'cgo' and well-crafted payloads could lead to code smuggling and arbitrary code execution at build time due to trust layer bypass.
CVSS v3.1
Score 8.8high
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability (CVE-2026-27140) in the Go toolchain's cmd/go arises from improper handling of SWIG file names containing 'cgo'. Maliciously crafted payloads can exploit this trust boundary violation to smuggle code and achieve arbitrary code execution at build time. The issue is tracked under CWE-501 (Trust Boundary Violation) and CWE-641 (Improper Control of a Resource Through its Lifetime). The vulnerability is rated high severity with a CVSS 3.1 base score of 8.8 (AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Red Hat advisories provide updated golang packages that fix this and related vulnerabilities. The affected versions include golang prior to 1.26.0-0 as indicated in the input data.
Potential Impact
Successful exploitation allows an attacker to execute arbitrary code during the build process by bypassing trust boundaries in cmd/go when processing SWIG file names. This compromises confidentiality, integrity, and availability of the build environment and potentially the resulting binaries. The vulnerability requires no privileges and no user interaction other than triggering the build with malicious input. The high CVSS score reflects the critical impact on system security.
Mitigation Recommendations
Red Hat has released security updates for golang packages that address CVE-2026-27140. Users should apply these official patches as provided in the referenced Red Hat advisories (e.g., RHSA-2026:16024 and others). Since this is a vulnerability in the build toolchain, updating to the fixed golang package version is the recommended remediation. Patch status is not explicitly stated in the input but the presence of multiple Red Hat errata indicates that fixes are available. Check the vendor advisories for detailed update instructions and apply them promptly.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- Go
- Date Reserved
- 2026-02-17T19:57:28.435Z
- Cvss Version
- null
- State
- PUBLISHED
- Remediation Level
- null
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2026-27140","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:16024","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:10217","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:10704","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:16698","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:16697","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:16694","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:16494","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:16498","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:16497","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:16021","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:10219","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:25182","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:23246","vendor":"Red Hat"}]
Threat ID: 69d5da2a43e2781badfbe636
Added to database: 04/08/2026, 04:31:38 UTC
Last enriched: 07/17/2026, 08:50:21 UTC
Last updated: 07/31/2026, 19:22:58 UTC
Views: 163
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.