golang.org/x/tools Vulnerabilities and Affected Products
Explore source-attributed vulnerabilities associated with golang.org/x/tools products.
Products
- golang.org/x/tools/gopls1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-42503HIGH | Accidental binding to INADDR_ANY might lead to RCE in golang.org/x/tools/goplsgopls by default communicates via pipe. However, -port and -listen flags are supported as means of debugging. If -listen is given a value without an explicit host (e.g. :8080), or -port is used, gopls will listen on 0.0.0.0. As a result, users might inadvertently cause gopls to bind 0.0.0.0. This can allow a malicious party on the same network to execute code arbitrarily via gopls. CWE-1327May 6, 2026 | CVSS8.8v3.1 | EPSS0.223% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |