CVE-2025-61732Patch(golang / go)

LOWCVSS 8.6 · HIGH

Exploit discussion active in current signal (4 latest mentions)

Immediate actions

  • Patch golang go systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

A discrepancy between how Go and C/C++ comments were parsed allowed for code smuggling into the resulting cgo binary.

2.0/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • go

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 12 mentions across 7 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 7 signals
  • Technical details provided in 7 signals
  • Disclosure: 3 classified signals
  • General: 2 classified signals
  • Peaked at 4 mentions on most recent observed day (2026-03-11)
  • 12 total mentions across 7 days

Affected systems

Vendors
Products
go

Deep dive

Activity timeline12 mentions / 7d
01234Mentions · 2026-02-04: 1Mentions · 2026-02-05: 3Mentions · 2026-02-06: 1Mentions · 2026-02-08: 1Mentions · 2026-02-10: 1Mentions · 2026-02-12: 1Mentions · 2026-03-11: 4PoC Mentioned / Linked · 2026-02-06: 1Patch / Workaround · 2026-02-04: 1Patch / Workaround · 2026-02-06: 1Patch / Workaround · 2026-02-08: 1Patch / Workaround · 2026-02-12: 1Patch / Workaround · 2026-03-11: 3Technical Details · 2026-02-04: 1Technical Details · 2026-02-05: 3Technical Details · 2026-02-06: 1Technical Details · 2026-02-08: 1Technical Details · 2026-02-12: 102-0402-0502-0602-0802-1002-1203-11
Signal classification3 categories
Patch
758.3%
Disclosure
325.0%
General
216.7%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-02-041
Patch1
2026-02-053
Disclosure3
2026-02-061
Patch1
2026-02-081
Patch1
2026-02-101
General1
2026-02-121
Patch1
2026-03-114
General1Patch3
Full discourse12 posts
  • Go@golang
    Patch

    🎉 Go 1.25.7 and 1.24.13 are released! 🔐 Security: Includes a security fix for cmd/cgo (CVE-2025-61732) and an update for crypto/tls (CVE-2025-68121). 🗣 Announcement: https://groups.google.com/g/golang-announce/c/K09ubi9FQFk/m/oQiZUMk9AQAJ 📦 Download: https://go.dev/dl/#go1.25.7 #golang https://t.co/NnF8ayxKrK

    Post summary

    The tweet announces the release of Go 1.25.7, highlighting security fixes for CVE-2025-61732 (cmd/cgo) and CVE-2025-68121 (crypto/tls), with download and announcement links provided.

    34823431816.7K
    206.6K followersView on X
  • Open Source Security mailing list@oss_security
    Patch

    Go 1.25.7, 1.24.13 fix 2 CVEs https://www.openwall.com/lists/oss-security/2026/02/07/2 CVE-2025-61732: cmd/cgo: Discrepancy between how Go and C/C++ comments were parsed allowed for code smuggling into the cgo binary CVE-2025-68121: crypto/tls: Unexpected session resumption when using Config.GetConfigForClient

    Post summary

    Go releases 1.25.7 and 1.24.13 patch CVE‑2025‑61732 (cgo code smuggling) and CVE‑2025‑68121 (TLS session resumption issue).

    01071576
    4.4K followersView on X
  • GCP Weekly@gcpweekly
    General

    This addresses the following vulnerabilities: CVE-2025-68121 CVE-2025-68119 CVE-2025-61732 CVE-2025-61731 CVE-2025-61729 CVE-2025-61726 CVE-2025-61725 CVE-2025-61723 CVE-2025-58188 CVE-2025-58187 CVE-2025-47907 CVE-2025-4674 N/A Security fixes for 18/19

    Post summary

    The text merely lists a series of CVE identifiers without offering additional context or technical details.

    10000108
    1.8K followersView on X
  • GCP Weekly@gcpweekly
    Patch

    N/A Security fixes for apigee-hybrid-cassandra-client. This addresses the following vulnerabilities: CVE-2026-24051 CVE-2025-68121 CVE-2025-68119 CVE-2025-61732 CVE-2025-61731 CVE-2025-61729 CVE-2025-61726 CVE-2025-61725 CVE-2025-61723 CVE-2025-58188 CVE-2025-58187 12/19

    Post summary

    Security fixes have been released for multiple CVEs affecting apigee-hybrid-cassandra-client, but no exploit, PoC, or active exploitation details are included.

    1000081
    1.8K followersView on X
  • GCP Weekly@gcpweekly
    Patch

    apigee-asm-ingress. This addresses the following vulnerability: CVE-2026-24051 N/A Security fixes for apigee-connect-agent. This addresses the following vulnerabilities: CVE-2025-68121 CVE-2025-68119 CVE-2025-61732 CVE-2025-61731 CVE-2025-61729 CVE-2025-61726 CVE-2025-4674 11/19

    Post summary

    The statement lists several CVEs and announces that security fixes have been applied to apigee-connect-agent and apigee-asm-ingress, indicating a patch release.

    1000097
    1.8K followersView on X
  • iototsecnews@iototsecnews
    Patch

    Go の脆弱性 CVE-2025-61732/68121 が FIX:コード・スマグリングと認証バイパスの恐れ https://iototsecnews.jp/2026/02/05/go-1-25-7-and-go-1-24-13-released-with-patches-for-multiple-security-vulnerabilities/ この問題の原因は、プログラムを組み立てるツールや安全な通信を守る仕組みの中に、解釈のズレやチェックの漏れが生じていたことにあります。具体的には、Go から C 言語を呼び出すための cgo ツールにおいて、Go と C/C++ で異なるコメント注釈という隙を突かれ、コメントに見せかけた悪意のコードをバイナリに紛れ込ませる、コード・スマグリングが可能になっていました。また、TLS 暗号通信においては、一度確立した接続を再開する際に、新しい設定で証明書の認証要件を正しく引き継げず、古い許可証で認証をすり抜けられてしまう、認証バイパスのリスクが存在していました。ご利用のチームは、ご注意ください。 #CVE202561732 #CVE202568121 #Golang #Vulnerability

    Post summary

    The post announces that Go 1.25.7 and 1.24.13 have released patches for CVE-2025-61732 and CVE-2025-68121, which involve code smuggling via cgo and TLS authentication bypass, and urges teams to apply the updates.

    01000183
    483 followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2025-32711 2 - CVE-2026-1731 3 - CVE-2025-61732 4 - CVE-2026-20817 5 - CVE-2026-25526 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post simply lists five trending CVEs without any further technical details or context.

    00010220
    1.7K followersView on X
  • Ostorlab@OstorlabSec
    Patch

    🚨 CVE-2025-61732 : GO CGO BUILD-TIME CODE INJECTION ALERT 🚨 A high-severity build-time code injection vulnerability has been disclosed in Go’s cgo toolchain, allowing attackers to smuggle malicious C/C++ code inside comments that execute during compilation, completely invisible at runtime. Risk Severity: - High (CVSS 8.6, trending, public PoC available) Impact: - Build-time code injection - Supply-chain compromise of Go binaries - Persistent backdoors embedded in compiled artifacts - CI/CD and build server takeover - Complete bypass of runtime security controls and code review Root Cause: - CWE-159 (Failure to Sanitize Special Elements). A parsing mismatch between Go’s cgo lexer and the underlying C/C++ preprocessor allows comment-encapsulated payloads to be ignored by Go while executed by GCC/Clang during compilation. Attackers can: - Hide malicious C/C++ logic inside comment blocks - Inject payloads during `go build` when `import "C"` is used - Poison intermediate `_cgo_*.c` files generated at build time - Ship compromised binaries with no visible source changes Why this is dangerous: - This attack happens at build time, not runtime. - EDR, WAFs, runtime scanners, and application security tools provide **zero protection**. - The final binary fully trusts and executes attacker-controlled machine code. Are You Affected? Vulnerable: • Go 1.24.0 → 1.24.12 • Go 1.25.0 → 1.25.6 Patched: • Go 1.24.13 • Go 1.25.7 (February 2026) Immediate Action Required: - Update: Upgrade all Go toolchains on CI/CD, build servers, and dev machines - Rebuild: Recompile and redeploy all production binaries - Mitigate: Disable cgo (`CGO_ENABLED=0`) if not strictly required - Audit: Review all `import "C"` usage and large comment blocks This is a supply-chain vulnerability targeting trust in the build process itself. Unpatched environments should be considered compromised by design. 🛠️🛡️ #ostorlabCVE

    Post summary

    The post discloses a high‑severity build‑time code injection in Go’s cgo toolchain, notes a public PoC, and provides patch versions and mitigation steps, urging immediate action.

    0001069
    582 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2025-61732: HIGH] A discrepancy between how Go and C/C++ comments were parsed allowed for code smuggling into the resulting cgo binary.#cve,CVE-2025-61732,#cybersecurity https://cvefind.com/CVE-2025-61732

    Post summary

    CVE-2025-61732 reveals a parsing discrepancy between Go and C/C++ comments that enables code smuggling into cgo binaries, indicating a high‑severity vulnerability.

    0001089
    583 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-61732 A discrepancy between how Go and C/C++ comments were parsed allowed for code smuggling into the resulting cgo binary. https://www.cve.org/CVERecord?id=CVE-2025-61732

    Post summary

    The CVE describes a code smuggling vulnerability in cgo binaries caused by differences in comment parsing between Go and C/C++.

    00010197
    56.5K followersView on X
  • GCP Weekly@gcpweekly
    Patch

    apigee-stackdriver-logging-agent. This addresses the following vulnerabilities: CVE-2026-24051 CVE-2025-68121 CVE-2025-68119 CVE-2025-61732 CVE-2025-61731 CVE-2025-61729 CVE-2025-61726 CVE-2025-61725 CVE-2025-61723 CVE-2025-58188 CVE-2025-58187 CVE-2025-47907. 19/19

    Post summary

    The text lists CVEs that are reportedly fixed by the apigee‑stackdriver‑logging‑agent, indicating the availability of a patch or update.

    00000116
    1.8K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2025-61732 - High A discrepancy between how Go and C/C++ comments were parsed allowed for code smuggling into the resulting cgo binary. https://www.thehackerwire.com/vulnerability/CVE-2025-61732/ https://t.co/9Ua9pFQExa

    Post summary

    A high‑severity vulnerability (CVE‑2025‑61732) involves a parsing discrepancy between Go and C/C++ comments that allows code smuggling into cgo binaries, with no PoC, patch, or active exploitation reported.

    0000068
    113 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgolanggo---

Explore more