pkg:Go/toolchain
30 total CVEsCRITICAL7HIGH15MEDIUM3
✅ Check your installed version
All known vulnerabilities
- CRITICAL9.8CVE-2026-27143Missing bound checks can lead to memory corruption in safe Go in cmd/compilefrom 0, < 1.25.9, >= 1.26.0-0, < 1.26.2
- from 0, < 1.21.0-0
- >= 1.21.0-0, < 1.21.1
- from 0, < 1.19.10, >= 1.20.0-0, < 1.20.5
- CRITICAL9.8CVE-2023-29405Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/gofrom 0, < 1.19.10, >= 1.20.0-0, < 1.20.5
- from 0, < 1.19.10, >= 1.20.0-0, < 1.20.5
- from 0, < 1.16.9, >= 1.17.0-0, < 1.17.2
- from 0, < 1.25.9, >= 1.26.0-0, < 1.26.2
- >= 1.24.0-0, < 1.24.0-rc.2
- from 0, < 1.24.13, >= 1.25.0-0, < 1.25.7
- from 0, < 1.23.11, >= 1.24.0-0, < 1.24.5
- from 0, < 1.20.9, >= 1.21.0-0, < 1.21.2
- from 0, < 1.24.12, >= 1.25.0, < 1.25.6
- from 0, < 1.25.10, >= 1.26.0-0, < 1.26.3
- >= 1.24.0-rc.2, < 1.24.0-rc.3
- from 0, < 1.20.12, >= 1.21.0-0, < 1.21.5
- from 0, < 1.16.14, >= 1.17.0-0, < 1.17.7
- from 0, < 1.14.12, >= 1.15.0-0, < 1.15.5
- from 0, < 1.14.12, >= 1.15.0-0, < 1.15.5
- from 0, < 1.14.14, >= 1.15.0-0, < 1.15.7
- HIGH7.1CVE-2026-27144Miscompilation allows memory corruption via CONVNOP-wrapped array copy in cmd/compilefrom 0, < 1.25.9, >= 1.26.0-0, < 1.26.2
- >= 1.25.0, < 1.25.6
- from 0, < 1.21.10, >= 1.22.0-0, < 1.22.3
- from 0, < 1.25.10, >= 1.26.0-0, < 1.26.3
- MEDIUM5.3CVE-2026-39819Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/gofrom 0, < 1.25.10, >= 1.26.0-0, < 1.26.3
- from 0, < 1.9.5, >= 1.10.0-0, < 1.10.1
- from 0, < 1.8.7, >= 1.9.0-0, < 1.9.4
- from 0, < 1.8.4, >= 1.9.0-0, < 1.9.1
- from 0, < 1.10.6, >= 1.11.0-0, < 1.11.3
- from 0, < 1.10.6, >= 1.11.0-0, < 1.11.3