Vulnerability Report: GO-2026-4433
- CVE-2025-61732
- Affects: cmd/cgo
- Published: Feb 05, 2026
A discrepancy between how Go and C/C++ comments were parsed allowed for code smuggling into the resulting cgo binary.
Affected Packages
-
PathVersionsSymbols
-
before go1.24.13, from go1.25.0-0 before go1.25.7all symbols
Aliases
References
- https://go.dev/cl/734220
- https://go.dev/issue/76697
- https://groups.google.com/g/golang-announce/c/K09ubi9FQFk
- https://vuln.go.dev/ID/GO-2026-4433.json
Credits
- RyotaK (https://ryotak.net) of GMO Flatt Security Inc.
Feedback
See anything missing or incorrect?
Suggest an edit to this report.