HomeDefault status
unaffected
Any version before 1.25.9
affected
1.26.0-0 (semver) before 1.26.2
affected
Description
SWIG file names containing 'cgo' and well-crafted payloads could lead to code smuggling and arbitrary code execution at build time due to trust layer bypass.
Problem types
CWE-501: Trust Boundary Violation
Product status
Any version before 1.25.9
1.26.0-0 (semver) before 1.26.2
Credits
Juho Forsén of Mattermost
References
groups.google.com/g/golang-announce/c/0uYbvbPZRWU