Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

cmd/go — Vulnerabilities & Security Advisories 21

All 21 CVE vulnerabilities found in cmd/go, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerability data for the vendor and product combination identified as "Product: cmd/go", specifically categorizing findings by weakness type and associated tags. It collects historical security advisories and vulnerability reports linked to the Go standard library's command-line tools, covering the period during which such issues were identified and documented in public databases. Readers can use this index to track the vendor’s advisory history, understand the specific weakness classes that have affected this product component, and review the chronological sequence of discovered vulnerabilities. The aggregation provides a structured view of how the security posture of cmd/go has evolved over time, highlighting recurring defect patterns rather than individual incident details. By consolidating disparate vulnerability records, this resource enables security professionals and developers to analyze trends, compare fix timelines, and assess the impact of specific software flaws on the cmd/go module without manually searching through scattered sources. The focus remains on data integrity and temporal context, ensuring that each entry is mapped to its corresponding weakness category and publication date.

Vendor: Go toolchain

CVE ID Title CVSS Severity Published
CVE-2026-56864 Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb - - 2026-08-13
CVE-2026-56865 Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog - - 2026-08-13
CVE-2026-42501 Malicious module proxy can bypass checksum database in cmd/go 9.8AI Critical AI 2026-05-07
CVE-2026-39819 Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go 6.5AI Medium AI 2026-05-07
CVE-2026-39817 Invoking "go tool pack" does not sanitize output paths in cmd/go 6.5AI Medium AI 2026-05-07
CVE-2026-27140 Code execution vulnerability in SWIG code generation in cmd/go 7.8AI High AI 2026-04-08
CVE-2025-61731 Arbitrary file write using cgo pkg-config directive in cmd/go 5.5AI Medium AI 2026-01-28
CVE-2025-68119 Unexpected code execution when invoking toolchain in cmd/go 9.8AI Critical AI 2026-01-28
CVE-2025-4674 Unexpected command execution in untrusted VCS repositories in cmd/go 9.8AI Critical AI 2025-07-29
CVE-2025-22867 Arbitrary code execution during build on darwin in cmd/go 9.8 - 2025-02-06
CVE-2024-45340 GOAUTH credential leak in cmd/go 9.1 - 2025-01-28
CVE-2023-24531 Output of "go env" does not sanitize values in cmd/go 9.8AI Critical AI 2024-07-02
CVE-2024-24787 Arbitrary code execution during build on Darwin in cmd/go 8.8AI High AI 2024-05-08
CVE-2023-45285 Command 'go get' may unexpectedly fallback to insecure git in cmd/go 9.1 - 2023-12-06
CVE-2023-39323 Arbitrary code execution during build via line directives in cmd/go 7.4 - 2023-10-05
CVE-2023-39320 Arbitrary code execution via go.mod toolchain directive in cmd/go 9.8 - 2023-09-08
CVE-2023-29405 Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go 9.8 - 2023-06-08
CVE-2023-29404 Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go 9.8 - 2023-06-08
CVE-2023-29402 Code injection via go command with cgo in cmd/go 8.4 - 2023-06-08
CVE-2020-28366 Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo 8.0 - 2020-11-18
CVE-2020-28367 Arbitrary code execution via the go command with cgo in cmd/go 8.8 - 2020-11-18

All 21 known CVE vulnerabilities affecting cmd/go with full Chinese analysis, references, and POCs where available.