← Vulnerability feed

Vulnerability record · CVE-2025-61732 · published 5 February 2026

CVE-2025-61732: Golang go code injection vulnerability

Golang · Go

A discrepancy between how Go and C/C++ comments were parsed allowed for code smuggling into the resulting cgo binary.

8.6 CVSS 3.1 High EPSS 0.49% · top 60.2% CWE-94 · Code injection
8.6CVSS 3.1 base score
0.49%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
38References
10 Sep 2026Last modified by NVD

Description

A discrepancy between how Go and C/C++ comments were parsed allowed for code smuggling into the resulting cgo binary.

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://go.dev/cl/734220 PatchProduct
https://go.dev/issue/76697 Issue TrackingVendor Advisory
https://groups.google.com/g/golang-announce/c/K09ubi9FQFk Mailing ListRelease Notes
https://pkg.go.dev/vuln/GO-2026-4433 PatchVendor Advisory
https://access.redhat.com/errata/RHSA-2026:10104
https://access.redhat.com/errata/RHSA-2026:12282
https://access.redhat.com/errata/RHSA-2026:14100
https://access.redhat.com/errata/RHSA-2026:14774
https://access.redhat.com/errata/RHSA-2026:15091
https://access.redhat.com/errata/RHSA-2026:17598
https://access.redhat.com/errata/RHSA-2026:21691
https://access.redhat.com/errata/RHSA-2026:2706
https://access.redhat.com/errata/RHSA-2026:2708
https://access.redhat.com/errata/RHSA-2026:2709
https://access.redhat.com/errata/RHSA-2026:2844
https://access.redhat.com/errata/RHSA-2026:3192
https://access.redhat.com/errata/RHSA-2026:3193
https://access.redhat.com/errata/RHSA-2026:3468
https://access.redhat.com/errata/RHSA-2026:3469
https://access.redhat.com/errata/RHSA-2026:3470
https://access.redhat.com/errata/RHSA-2026:3471
https://access.redhat.com/errata/RHSA-2026:3472
https://access.redhat.com/errata/RHSA-2026:3473
https://access.redhat.com/errata/RHSA-2026:3489
https://access.redhat.com/errata/RHSA-2026:3556
https://access.redhat.com/errata/RHSA-2026:3559
https://access.redhat.com/errata/RHSA-2026:3855
https://access.redhat.com/errata/RHSA-2026:4434
https://access.redhat.com/errata/RHSA-2026:5878
https://access.redhat.com/errata/RHSA-2026:5948
https://access.redhat.com/errata/RHSA-2026:5950
https://access.redhat.com/errata/RHSA-2026:5952
https://access.redhat.com/errata/RHSA-2026:7291
https://access.redhat.com/errata/RHSA-2026:7385
https://access.redhat.com/errata/RHSA-2026:8448
https://access.redhat.com/security/cve/CVE-2025-61732
https://bugzilla.redhat.com/show_bug.cgi?id=2437016
https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-61732.json

Track CVE-2025-61732 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.1CVE-2020-0601Windows CryptoAPI ECC certificate validation spoofing flawWindows CryptoAPI (Crypt32.dll) improperly validates Elliptic Curve Cryptography certificates, allowing a spoofed code-signing certificate to be trus…KEVEPSS 89%analysed7.5CVE-2023-44487HTTP/2 Rapid Reset stream cancellation denial of serviceThe HTTP/2 protocol permits a client to cancel many streams quickly, and the server's handling of those resets consumes disproportionate resources. T…KEVEPSS 100%analysed10.0CVE-2025-68121Golang go improper certificate validation vulnerabilityDuring session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between the initial handshake and the r…EPSS 0.86%9.8CVE-2026-27143Golang go vulnerabilityArithmetic over induction variables in loops were not correctly checked for underflow or overflow. As a result, the compiler would allow for invalid …EPSS 0.66%9.8CVE-2024-24790Golang go vulnerabilityThe various Is methods (IsPrivate, IsLoopback, etc) did not work as expected for IPv4-mapped IPv6 addresses, returning false for addresses which woul…EPSS 2.0%9.8CVE-2023-39320Golang go code injection vulnerabilityThe go.mod toolchain directive, introduced in Go 1.21, can be leveraged to execute scripts and binaries relative to the root of the module when the "…EPSS 1.8%9.8CVE-2023-29404Golang go code injection vulnerabilityThe go command may execute arbitrary code at build time when using cgo. This may occur when running "go get" on a malicious module, or when running a…EPSS 1.8%9.8CVE-2023-29405Golang go injection vulnerabilityThe go command may execute arbitrary code at build time when using cgo. This may occur when running "go get" on a malicious module, or when running a…EPSS 1.7%

Source: NIST National Vulnerability Database (record CVE-2025-61732), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.