Skip to main content
EPSS 0.5%top 60%

Golang: Potential code smuggling via doc comments in cmd/cgo (CVE-2025-61732)

0
High
Published: 02/10/2026 (02/10/2026, 08:48:31 UTC)
Source: GCVE Database
Product: golang

Description

A discrepancy between how Go and C/C++ comments were parsed allowed for code smuggling into the resulting cgo binary.

Affected software

redhat/openshift-container-platform
pkg:rpm/redhat/openshift-container-platform
Affected versions
<4.19.27 >=4.19.0
Bitnamimore threats →ghsa
golang
pkg:bitnami/golang
Affected versions
<1.24.13>=1.25.0-0 <1.25.7

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/16/2026, 17:20:42 UTC

Technical Analysis

CVE-2025-61732 affects the cmd/cgo tool in the Go programming language toolchain. The vulnerability is caused by a difference in how Go and C/C++ comments are parsed, which enables an attacker to embed malicious code inside comments that are then smuggled into the compiled cgo binary. This flaw can be exploited when building untrusted Go modules that use cgo, potentially allowing arbitrary code execution and system compromise. The issue impacts Red Hat Enterprise Linux and OpenShift Container Platform 4.19. Red Hat has released OpenShift Container Platform 4.19.27 with updated container images and RPM packages to fix this vulnerability. Detailed upgrade instructions and image digests are provided by Red Hat. The CVSS v3 base score assigned by Red Hat is 7.4 (High), reflecting network attack vector, high attack complexity, no privileges required, and high confidentiality and integrity impact.

Potential Impact

The vulnerability allows an attacker to embed and execute arbitrary code in the compiled cgo binary by exploiting a comment parsing discrepancy. This can lead to significant system compromise on affected Red Hat OpenShift Container Platform 4.19 deployments, especially when building untrusted Go modules using cgo. The impact includes potential unauthorized code execution with high confidentiality and integrity impact. No known exploits in the wild have been reported at this time.

Mitigation Recommendations

A fix is available in Red Hat OpenShift Container Platform version 4.19.27. Users should upgrade to this version by applying the updated container images and RPM packages as per Red Hat's official advisories. Instructions for upgrading clusters are available in the Red Hat documentation. No additional mitigations are specified beyond applying the official update. Red Hat manages remediation for this on-premise/private cloud product; users must perform the upgrade to fully mitigate the vulnerability.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:5878
Cve Count
1
State
PUBLISHED

Threat ID: 6a55ff9c68715ace432f67b4

Added to database: 07/14/2026, 09:21:32 UTC

Last enriched: 08/16/2026, 17:20:42 UTC

Last updated: 09/12/2026, 21:54:11 UTC

Views: 67

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses