Go-toolchain
2 CVEs tracked since 2020. Since Nov 2020, none of them reached CISA KEV.
Go-toolchain CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2020-11 | 2 | 0 |
Products
The products that kept showing up in Go-toolchain's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Go-toolchain.
- CVE-2026-56865Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog8.4
- CVE-2026-56864Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb7.5
- CVE-2026-42501Malicious module proxy can bypass checksum database in cmd/go7.5
- CVE-2026-39819Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go5.3
- CVE-2026-39817Invoking "go tool pack" does not sanitize output paths in cmd/go5.9
- CVE-2026-27143Missing bound checks can lead to memory corruption in safe Go in cmd/compile9.8
- CVE-2026-27140Code execution vulnerability in SWIG code generation in cmd/go8.8
- CVE-2026-27144Miscompilation allows memory corruption via CONVNOP-wrapped array copy in cmd/compile7.1
- CVE-2025-61732Potential code smuggling via doc comments in cmd/cgo8.6
- CVE-2025-61731Arbitrary file write using cgo pkg-config directive in cmd/go7.8
- CVE-2025-68119Unexpected code execution when invoking toolchain in cmd/go7.0
- CVE-2025-4674Unexpected command execution in untrusted VCS repositories in cmd/go8.6
- CVE-2025-22867Arbitrary code execution during build on darwin in cmd/go7.5
- CVE-2024-45340GOAUTH credential leak in cmd/go8.8
- CVE-2023-24531Output of "go env" does not sanitize values in cmd/go9.8
The record
- Peak rank
- #151 in Nov 2020
- Busiest month shown
- Nov 2020, 2 CVEs
- Months with a KEV entry
- 0 since Nov 2020
- Monthly snapshots
- 1 since 2020