CVE-2026-32288Disclosure(golang / go)

LOWCVSS 5.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch golang go systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

tar.Reader can allocate an unbounded amount of memory when reading a maliciously-crafted archive containing a large number of sparse regions encoded in the "old GNU sparse map" format.

0.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-770

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • go

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 3 mentions (2026-04-08); latest day: 1
  • 6 total mentions across 4 days

Affected systems

Vendors
Products
go

Deep dive

Activity timeline6 mentions / 4d
01223Mentions · 2026-04-08: 3Mentions · 2026-04-15: 1Mentions · 2026-04-17: 1Mentions · 2026-04-18: 1Patch / Workaround · 2026-04-17: 1Patch / Workaround · 2026-04-18: 1Technical Details · 2026-04-08: 1Technical Details · 2026-04-15: 104-0804-1504-1704-18
Signal classification3 categories
Disclosure
350.0%
Patch
233.3%
General
116.7%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-04-083
Disclosure3
2026-04-151
General1
2026-04-171
Patch1
2026-04-181
Patch1
Full discourse6 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-32288 tar.Reader can allocate an unbounded amount of memory when reading a maliciously-crafted archive containing a large number of sparse regions encoded in the "old GNU s… https://www.cve.org/CVERecord?id=CVE-2026-32288

    Post summary

    The CVE report explains that tar.Reader may allocate unbounded memory when parsing malicious archives with numerous sparse regions.

    0001098
    57.0K followersView on X
  • Lambda Watchdog@LambdaWatchdog
    Patch

    🔍 Lambda Watchdog detected that CVE-2026-32288 is no longer present in latest AWS Lambda base image scans. https://github.com/aws/aws-lambda-base-images/issues/461 #AWS #Lambda #Security #CVE #DevOps #SecOps

    Post summary

    The post announces that CVE-2026-32288 has been removed from the latest AWS Lambda base images, indicating the vulnerability is no longer present. This confirms a patch or fix has been applied.

    0000045
    31 followersView on X
  • Lambda Watchdog@LambdaWatchdog
    Patch

    🔍 Lambda Watchdog detected that CVE-2026-32288 is no longer present in latest AWS Lambda base image scans. https://github.com/aws/aws-lambda-base-images/issues/461 #AWS #Lambda #Security #CVE #DevOps #SecOps

    Post summary

    The post announces that CVE-2026-32288 has been removed from AWS Lambda base images, indicating a fix without providing exploit or technical details.

    0000023
    34 followersView on X
  • DailyCVE@dailycve
    General

    🟠 OpenTofu, Denial of Service, #CVE-2026-32280, #CVE-2026-32281, #CVE-2026-32283, #CVE-2026-32288 (Medium) https://dailycve.com/opentofu-denial-of-service-cve-2026-32280-cve-2026-32281-cve-2026-32283-cve-2026-32288-medium/

    Post summary

    The post announces four medium‑severity denial‑of‑service CVEs for OpenTofu, providing identifiers and a link to an article but lacking PoC, exploitation, or patch details.

    0000015
    181 followersView on X
  • Lambda Watchdog@LambdaWatchdog
    Disclosure

    🚨 New UNKNOWN CVE detected in AWS Lambda 🚨 CVE-2026-32288 impacts stdlib in 26 Lambda base images. Details: https://github.com/aws/aws-lambda-base-images/issues/461 More: https://lambdawatchdog.com/ #AWS #Lambda #CVE #CloudSecurity #Serverless

    Post summary

    A new CVE-2026-32288 affecting the standard library in 26 AWS Lambda base images has been reported, with links to a GitHub issue and additional resources for details.

    0000049
    31 followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-32288 🚨 Risk Level: Unknown 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-32288 #CVE-2026-32288 #CVE #CyberSecurity #InfoSec https://t.co/4NmHvVEKJf

    Post summary

    The tweet is purely an alert announcing the existence of CVE‑2026‑32288 with no additional technical, exploit, or mitigation information.

    0000042
    123 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgolanggo---

Explore more