CVE-2026-27140Disclosure(golang / go)

LOWCVSS 8.8 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

SWIG file names containing 'cgo' and well-crafted payloads could lead to code smuggling and arbitrary code execution at build time due to trust layer bypass.

0.0/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-863CWE-641

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • go

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
go

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-04-08: 2Technical Details · 2026-04-08: 104-08
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-27140 🚨 Risk Level: Unknown 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-27140 #CVE-2026-27140 #CVE #CyberSecurity #InfoSec https://t.co/eW4DjBk5FV

    Post summary

    A brief announcement of CVE‑2026‑27140 with no additional technical, exploit, or remediation details.

    0000039
    123 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-27140 SWIG file names containing 'cgo' and well-crafted payloads could lead to code smuggling and arbitrary code execution at build time due to trust layer bypass. https://www.cve.org/CVERecord?id=CVE-2026-27140

    Post summary

    The text discloses a new CVE (CVE-2026-27140) involving SWIG files with 'cgo', describing a code smuggling vulnerability that can lead to arbitrary code execution at build time via a trust layer bypass.

    0000083
    57.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgolanggo---

Explore more