CVE-2026-27143
CRITICALMissing bound checks can lead to memory corruption in safe Go in cmd/compile
Title source: cnaDescription
Arithmetic over induction variables in loops were not correctly checked for underflow or overflow. As a result, the compiler would allow for invalid indexing to occur at runtime, potentially leading to memory corruption.
References (4)
Core 4
Scores
CVSS v3
9.8
EPSS
0.0002
EPSS Percentile
6.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
total
Details
Status
published
Products (3)
Go toolchain/cmd/compile
< 1.25.9
Go toolchain/cmd/compile
1.26.0-0 - 1.26.2
golang/go
< 1.25.9
Published
Apr 08, 2026
Tracked Since
Apr 08, 2026