go

command standard library

Versions in this module

go1
Aug 19, 2026
Aug 13, 2026
Jul 7, 2026 GO-2026-6179 +1 more
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Jun 18, 2026 GO-2026-6179 +1 more
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Aug 19, 2026
Aug 13, 2026
Jul 7, 2026 GO-2026-6179 +1 more
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Jun 2, 2026 GO-2026-6179 +1 more
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
May 7, 2026 GO-2026-6179 +1 more
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Apr 7, 2026 GO-2026-4978 +4 more
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Mar 6, 2026 GO-2026-4871 +5 more
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Feb 10, 2026 GO-2026-4871 +5 more
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Feb 4, 2026 GO-2026-4871 +5 more
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Jan 15, 2026 GO-2026-4871 +5 more
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Dec 16, 2025 GO-2026-4871 +5 more
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Aug 19, 2026
Aug 13, 2026
Jul 7, 2026 GO-2026-6179 +1 more
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Jun 2, 2026 GO-2026-6179 +1 more
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
May 7, 2026 GO-2026-6179 +1 more
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Apr 7, 2026 GO-2026-4978 +4 more
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Mar 6, 2026 GO-2026-4871 +5 more
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Feb 4, 2026 GO-2026-4871 +5 more
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Jan 15, 2026 GO-2026-4871 +5 more
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Dec 2, 2025 GO-2026-4338 +7 more
Alert  GO-2026-4338: Unexpected code execution when invoking toolchain in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Nov 5, 2025 GO-2026-4338 +7 more
Alert  GO-2026-4338: Unexpected code execution when invoking toolchain in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Oct 13, 2025 GO-2026-4338 +7 more
Alert  GO-2026-4338: Unexpected code execution when invoking toolchain in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Oct 7, 2025 GO-2026-4338 +7 more
Alert  GO-2026-4338: Unexpected code execution when invoking toolchain in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Sep 3, 2025 GO-2026-4338 +7 more
Alert  GO-2026-4338: Unexpected code execution when invoking toolchain in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Aug 12, 2025 GO-2026-4338 +7 more
Alert  GO-2026-4338: Unexpected code execution when invoking toolchain in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Aug 6, 2025 GO-2026-4871 +5 more
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Jul 8, 2025 GO-2026-4871 +5 more
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Jun 11, 2025 GO-2026-4871 +5 more
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Feb 4, 2026 GO-2026-4871 +5 more
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Jan 15, 2026 GO-2026-4871 +5 more
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Dec 2, 2025 GO-2026-4339 +6 more
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Nov 5, 2025 GO-2026-4339 +6 more
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Oct 13, 2025 GO-2026-4339 +6 more
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Oct 7, 2025 GO-2026-4339 +6 more
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Sep 3, 2025 GO-2026-4339 +6 more
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Aug 6, 2025 GO-2026-4339 +6 more
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Jul 8, 2025 GO-2026-4339 +6 more
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Jun 5, 2025 GO-2025-3828 +7 more
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
May 6, 2025 GO-2025-3828 +7 more
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Apr 1, 2025 GO-2025-3828 +7 more
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Mar 4, 2025 GO-2025-3828 +7 more
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Feb 11, 2025 GO-2025-3828 +7 more
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Feb 5, 2025 GO-2025-3828 +7 more
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Jan 16, 2025 GO-2025-3428 +8 more
Alert  GO-2025-3428: Arbitrary code execution during build on darwin in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Dec 13, 2024 GO-2025-3383 +8 more
Alert  GO-2025-3383: GOAUTH credential leak in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Aug 6, 2025 GO-2026-4339 +6 more
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Jul 8, 2025 GO-2026-4339 +6 more
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Jun 5, 2025 GO-2025-3828 +7 more
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
May 6, 2025 GO-2025-3828 +7 more
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Apr 1, 2025 GO-2025-3828 +7 more
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Mar 4, 2025 GO-2025-3828 +7 more
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Feb 4, 2025 GO-2025-3828 +7 more
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Jan 16, 2025 GO-2025-3828 +7 more
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Dec 3, 2024 GO-2025-3828 +7 more
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Nov 6, 2024 GO-2025-3828 +7 more
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Oct 1, 2024 GO-2025-3828 +7 more
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Sep 5, 2024 GO-2025-3828 +7 more
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Aug 13, 2024 GO-2025-3828 +7 more
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Jul 16, 2024 GO-2025-3828 +7 more
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Jun 21, 2024 GO-2025-3828 +7 more
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Feb 4, 2025 GO-2025-3828 +7 more
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Jan 16, 2025 GO-2025-3828 +7 more
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Dec 3, 2024 GO-2025-3828 +7 more
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Nov 6, 2024 GO-2025-3828 +7 more
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Oct 1, 2024 GO-2025-3828 +7 more
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Sep 5, 2024 GO-2025-3828 +7 more
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Aug 6, 2024 GO-2025-3828 +7 more
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Jul 2, 2024 GO-2025-3828 +7 more
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Jun 4, 2024 GO-2025-3828 +7 more
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
May 7, 2024 GO-2025-3828 +7 more
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Apr 3, 2024 GO-2024-2825 +8 more
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Mar 5, 2024 GO-2024-2825 +8 more
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Feb 6, 2024 GO-2024-2825 +8 more
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Jan 24, 2024 GO-2024-2825 +8 more
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Dec 19, 2023 GO-2024-2825 +8 more
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Aug 6, 2024 GO-2025-3828 +7 more
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Jul 2, 2024 GO-2025-3828 +7 more
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Jun 4, 2024 GO-2025-3828 +7 more
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
May 7, 2024 GO-2025-3828 +7 more
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Apr 3, 2024 GO-2024-2825 +8 more
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Mar 5, 2024 GO-2024-2825 +8 more
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Feb 6, 2024 GO-2024-2825 +8 more
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Jan 9, 2024 GO-2024-2825 +8 more
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Dec 5, 2023 GO-2024-2825 +8 more
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Nov 7, 2023 GO-2023-2383 +9 more
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Oct 10, 2023 GO-2023-2383 +9 more
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Oct 5, 2023 GO-2023-2383 +9 more
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Sep 6, 2023 GO-2023-2095 +10 more
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Aug 8, 2023 GO-2023-2042 +11 more
Alert  GO-2023-2042: Arbitrary code execution via go.mod toolchain directive in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Aug 2, 2023 GO-2023-2042 +11 more
Alert  GO-2023-2042: Arbitrary code execution via go.mod toolchain directive in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Jul 14, 2023 GO-2023-2042 +11 more
Alert  GO-2023-2042: Arbitrary code execution via go.mod toolchain directive in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Jun 21, 2023 GO-2023-2042 +11 more
Alert  GO-2023-2042: Arbitrary code execution via go.mod toolchain directive in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Jun 16, 2023 GO-2023-2042 +11 more
Alert  GO-2023-2042: Arbitrary code execution via go.mod toolchain directive in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Feb 6, 2024 GO-2024-2825 +9 more
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Jan 9, 2024 GO-2024-2825 +9 more
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Dec 5, 2023 GO-2024-2825 +9 more
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Nov 7, 2023 GO-2023-2383 +10 more
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Oct 10, 2023 GO-2023-2383 +10 more
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Oct 5, 2023 GO-2023-2383 +10 more
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Sep 6, 2023 GO-2023-2095 +11 more
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Aug 1, 2023 GO-2023-2095 +11 more
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Jul 11, 2023 GO-2023-2095 +11 more
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Jun 6, 2023 GO-2023-2095 +11 more
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
May 2, 2023 GO-2023-1839 +14 more
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Apr 4, 2023 GO-2023-1839 +14 more
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Mar 7, 2023 GO-2023-1839 +14 more
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Feb 14, 2023 GO-2023-1839 +14 more
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Feb 1, 2023 GO-2023-1839 +14 more
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Jan 12, 2023 GO-2023-1839 +14 more
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Jan 4, 2023 GO-2023-1839 +14 more
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Dec 7, 2022 GO-2023-1839 +14 more
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Sep 6, 2023 GO-2023-2095 +11 more
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Aug 1, 2023 GO-2023-2095 +11 more
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Jul 11, 2023 GO-2023-2095 +11 more
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Jun 6, 2023 GO-2023-2095 +11 more
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
May 2, 2023 GO-2023-1839 +14 more
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Apr 4, 2023 GO-2023-1839 +14 more
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Mar 7, 2023 GO-2023-1839 +14 more
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Feb 14, 2023 GO-2023-1839 +14 more
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Jan 10, 2023 GO-2023-1839 +14 more
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Dec 6, 2022 GO-2023-1839 +14 more
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Nov 1, 2022 GO-2023-1839 +14 more
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Oct 4, 2022 GO-2023-1839 +14 more
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Sep 6, 2022 GO-2023-1839 +14 more
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Aug 2, 2022 GO-2023-1839 +14 more
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Jul 12, 2022 GO-2023-1839 +14 more
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Jul 6, 2022 GO-2023-1839 +14 more
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Jun 9, 2022 GO-2023-1839 +14 more
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Jan 10, 2023 GO-2023-1839 +14 more
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Dec 6, 2022 GO-2023-1839 +14 more
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Nov 1, 2022 GO-2023-1839 +14 more
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Oct 4, 2022 GO-2023-1839 +14 more
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Sep 6, 2022 GO-2023-1839 +14 more
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Aug 1, 2022 GO-2023-1839 +14 more
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Jul 12, 2022 GO-2023-1839 +14 more
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Jun 1, 2022 GO-2023-1839 +14 more
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
May 10, 2022 GO-2023-1839 +14 more
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Apr 12, 2022 GO-2023-1839 +14 more
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Mar 15, 2022 GO-2023-1839 +14 more
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Feb 16, 2022 GO-2023-1839 +14 more
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Jan 31, 2022 GO-2023-1839 +14 more
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Dec 14, 2021 GO-2023-1839 +14 more
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Aug 1, 2022 GO-2023-1839 +14 more
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Jul 12, 2022 GO-2023-1839 +14 more
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Jun 1, 2022 GO-2023-1839 +14 more
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
May 10, 2022 GO-2023-1839 +14 more
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Apr 12, 2022 GO-2023-1839 +14 more
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Mar 3, 2022 GO-2023-1839 +14 more
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Feb 9, 2022 GO-2023-1839 +14 more
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Jan 6, 2022 GO-2023-1839 +14 more
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Dec 9, 2021 GO-2023-1839 +14 more
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Dec 2, 2021 GO-2023-1839 +14 more
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Nov 4, 2021 GO-2023-1839 +14 more
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Oct 7, 2021 GO-2023-1839 +14 more
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Sep 9, 2021 GO-2023-1839 +14 more
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Aug 16, 2021 GO-2023-1839 +14 more
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Aug 2, 2021 GO-2023-1839 +14 more
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Jul 13, 2021 GO-2023-1839 +14 more
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Jun 10, 2021 GO-2023-1839 +14 more
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Mar 3, 2022 GO-2023-1839 +14 more
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Feb 9, 2022 GO-2023-1839 +14 more
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Jan 6, 2022 GO-2023-1839 +14 more
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Dec 9, 2021 GO-2023-1839 +14 more
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Dec 2, 2021 GO-2023-1839 +14 more
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Nov 4, 2021 GO-2023-1839 +14 more
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Oct 7, 2021 GO-2023-1839 +14 more
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Sep 9, 2021 GO-2023-1839 +14 more
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Aug 4, 2021 GO-2023-1839 +14 more
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Jul 12, 2021 GO-2023-1839 +14 more
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Jun 3, 2021 GO-2023-1839 +14 more
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
May 6, 2021 GO-2023-1839 +14 more
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Apr 1, 2021 GO-2023-1839 +14 more
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Mar 11, 2021 GO-2023-1839 +14 more
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Mar 10, 2021 GO-2023-1839 +14 more
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Feb 16, 2021 GO-2023-1839 +14 more
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Jan 27, 2021 GO-2023-1839 +14 more
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Dec 17, 2020 GO-2023-1839 +14 more
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Aug 4, 2021 GO-2023-1839 +14 more
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Jul 12, 2021 GO-2023-1839 +14 more
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Jun 3, 2021 GO-2023-1839 +14 more
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
May 6, 2021 GO-2023-1839 +14 more
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Apr 1, 2021 GO-2023-1839 +14 more
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Mar 11, 2021 GO-2023-1839 +14 more
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Mar 10, 2021 GO-2023-1839 +14 more
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Feb 4, 2021 GO-2023-1839 +14 more
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Jan 19, 2021 GO-2023-1839 +14 more
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Dec 3, 2020 GO-2021-0068 +15 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Nov 12, 2020 GO-2021-0068 +15 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Nov 5, 2020 GO-2021-0068 +17 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Oct 14, 2020 GO-2021-0068 +17 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Sep 9, 2020 GO-2021-0068 +17 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Sep 1, 2020 GO-2021-0068 +17 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Aug 11, 2020 GO-2021-0068 +17 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Aug 7, 2020 GO-2021-0068 +17 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Jul 24, 2020 GO-2021-0068 +17 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Jun 10, 2020 GO-2021-0068 +17 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Feb 4, 2021 GO-2023-1839 +14 more
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Jan 19, 2021 GO-2023-1839 +14 more
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Dec 3, 2020 GO-2021-0068 +15 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Nov 12, 2020 GO-2021-0068 +15 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Nov 5, 2020 GO-2021-0068 +17 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Oct 14, 2020 GO-2021-0068 +17 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Sep 9, 2020 GO-2021-0068 +17 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Sep 1, 2020 GO-2021-0068 +17 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Aug 6, 2020 GO-2021-0068 +17 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Jul 16, 2020 GO-2021-0068 +17 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Jul 14, 2020 GO-2021-0068 +17 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Jun 1, 2020 GO-2021-0068 +17 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
May 14, 2020 GO-2021-0068 +17 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Apr 8, 2020 GO-2021-0068 +17 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Mar 19, 2020 GO-2021-0068 +17 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Feb 25, 2020 GO-2021-0068 +17 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Feb 5, 2020 GO-2021-0068 +17 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Dec 17, 2019 GO-2021-0068 +17 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Aug 6, 2020 GO-2021-0068 +17 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Jul 16, 2020 GO-2021-0068 +17 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Jul 14, 2020 GO-2021-0068 +17 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Jun 1, 2020 GO-2021-0068 +17 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
May 14, 2020 GO-2021-0068 +17 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Apr 8, 2020 GO-2021-0068 +17 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Mar 19, 2020 GO-2021-0068 +17 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Feb 12, 2020 GO-2021-0068 +17 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Jan 27, 2020 GO-2021-0068 +17 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Jan 9, 2020 GO-2021-0068 +17 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Dec 4, 2019 GO-2021-0068 +17 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Oct 31, 2019 GO-2021-0068 +17 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Oct 17, 2019 GO-2021-0068 +17 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Oct 17, 2019 GO-2021-0068 +17 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Sep 25, 2019 GO-2021-0068 +17 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Sep 3, 2019 GO-2021-0068 +17 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Aug 29, 2019 GO-2021-0068 +17 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Aug 21, 2019 GO-2021-0068 +17 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Jun 26, 2019 GO-2021-0068 +17 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Feb 12, 2020 GO-2021-0068 +17 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Jan 27, 2020 GO-2021-0068 +17 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Jan 9, 2020 GO-2021-0068 +17 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Dec 4, 2019 GO-2021-0068 +17 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Oct 31, 2019 GO-2021-0068 +17 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Oct 17, 2019 GO-2021-0068 +17 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Oct 17, 2019 GO-2021-0068 +17 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Sep 25, 2019 GO-2021-0068 +17 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Aug 15, 2019 GO-2021-0068 +17 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Aug 13, 2019 GO-2021-0068 +17 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Jul 8, 2019 GO-2021-0068 +17 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Jun 11, 2019 GO-2021-0068 +17 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
May 6, 2019 GO-2021-0068 +17 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Apr 11, 2019 GO-2021-0068 +17 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Apr 8, 2019 GO-2021-0068 +17 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Apr 5, 2019 GO-2021-0068 +17 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Mar 14, 2019 GO-2021-0068 +17 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Feb 25, 2019 GO-2021-0068 +17 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Feb 11, 2019 GO-2021-0068 +17 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Jan 10, 2019 GO-2021-0068 +17 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Dec 18, 2018 GO-2021-0068 +17 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Aug 13, 2019 GO-2021-0068 +17 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Jul 8, 2019 GO-2021-0068 +17 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Jun 11, 2019 GO-2021-0068 +17 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
May 6, 2019 GO-2021-0068 +17 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Apr 11, 2019 GO-2021-0068 +17 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Apr 8, 2019 GO-2021-0068 +17 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Apr 5, 2019 GO-2021-0068 +17 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Mar 14, 2019 GO-2021-0068 +17 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Jan 23, 2019 GO-2021-0068 +17 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Dec 14, 2018 GO-2021-0068 +17 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Dec 13, 2018 GO-2021-0068 +17 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Nov 2, 2018 GO-2021-0068 +17 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Oct 1, 2018 GO-2021-0068 +17 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Aug 24, 2018 GO-2021-0068 +17 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Aug 22, 2018 GO-2021-0068 +17 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Aug 13, 2018 GO-2021-0068 +17 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Aug 3, 2018 GO-2021-0068 +17 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Jul 19, 2018 GO-2021-0068 +17 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Jun 26, 2018 GO-2021-0068 +17 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Jan 23, 2019 GO-2021-0068 +17 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Dec 14, 2018 GO-2021-0068 +17 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Dec 13, 2018 GO-2021-0068 +17 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Nov 2, 2018 GO-2021-0068 +17 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Aug 24, 2018 GO-2021-0068 +17 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Jun 6, 2018 GO-2021-0068 +17 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Apr 30, 2018 GO-2021-0068 +17 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Mar 29, 2018 GO-2021-0068 +17 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Feb 16, 2018 GO-2021-0068 +18 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0203: Remote command execution via "go get" command with "-insecure" option in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Feb 7, 2018 GO-2021-0068 +18 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0203: Remote command execution via "go get" command with "-insecure" option in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Jan 25, 2018 GO-2021-0068 +18 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0203: Remote command execution via "go get" command with "-insecure" option in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Jan 11, 2018 GO-2021-0068 +18 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0203: Remote command execution via "go get" command with "-insecure" option in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Dec 7, 2017 GO-2021-0068 +18 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0203: Remote command execution via "go get" command with "-insecure" option in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Jun 6, 2018 GO-2021-0068 +17 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Apr 30, 2018 GO-2021-0068 +17 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Mar 29, 2018 GO-2021-0068 +17 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Feb 7, 2018 GO-2021-0068 +18 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0203: Remote command execution via "go get" command with "-insecure" option in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Jan 22, 2018 GO-2021-0068 +19 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0201: Remote command execution via "go get" command with cgo in cmd/go
Alert  GO-2022-0203: Remote command execution via "go get" command with "-insecure" option in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Oct 25, 2017 GO-2021-0068 +19 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0201: Remote command execution via "go get" command with cgo in cmd/go
Alert  GO-2022-0203: Remote command execution via "go get" command with "-insecure" option in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Oct 4, 2017 GO-2021-0068 +19 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0201: Remote command execution via "go get" command with cgo in cmd/go
Alert  GO-2022-0203: Remote command execution via "go get" command with "-insecure" option in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Aug 24, 2017 GO-2021-0068 +20 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0177: Remote command execution via "go get" in cmd/go
Alert  GO-2022-0201: Remote command execution via "go get" command with cgo in cmd/go
Alert  GO-2022-0203: Remote command execution via "go get" command with "-insecure" option in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Aug 7, 2017 GO-2021-0068 +20 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0177: Remote command execution via "go get" in cmd/go
Alert  GO-2022-0201: Remote command execution via "go get" command with cgo in cmd/go
Alert  GO-2022-0203: Remote command execution via "go get" command with "-insecure" option in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Jul 24, 2017 GO-2021-0068 +20 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0177: Remote command execution via "go get" in cmd/go
Alert  GO-2022-0201: Remote command execution via "go get" command with cgo in cmd/go
Alert  GO-2022-0203: Remote command execution via "go get" command with "-insecure" option in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Jun 26, 2017 GO-2021-0068 +20 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0177: Remote command execution via "go get" in cmd/go
Alert  GO-2022-0201: Remote command execution via "go get" command with cgo in cmd/go
Alert  GO-2022-0203: Remote command execution via "go get" command with "-insecure" option in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Jun 14, 2017 GO-2021-0068 +20 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0177: Remote command execution via "go get" in cmd/go
Alert  GO-2022-0201: Remote command execution via "go get" command with cgo in cmd/go
Alert  GO-2022-0203: Remote command execution via "go get" command with "-insecure" option in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Feb 7, 2018 GO-2021-0068 +18 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0203: Remote command execution via "go get" command with "-insecure" option in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Jan 23, 2018 GO-2021-0068 +19 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0201: Remote command execution via "go get" command with cgo in cmd/go
Alert  GO-2022-0203: Remote command execution via "go get" command with "-insecure" option in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Oct 25, 2017 GO-2021-0068 +19 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0201: Remote command execution via "go get" command with cgo in cmd/go
Alert  GO-2022-0203: Remote command execution via "go get" command with "-insecure" option in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Oct 25, 2017 GO-2021-0068 +19 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0201: Remote command execution via "go get" command with cgo in cmd/go
Alert  GO-2022-0203: Remote command execution via "go get" command with "-insecure" option in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Oct 20, 2017 GO-2021-0068 +19 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0201: Remote command execution via "go get" command with cgo in cmd/go
Alert  GO-2022-0203: Remote command execution via "go get" command with "-insecure" option in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Oct 4, 2017 GO-2021-0068 +19 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0201: Remote command execution via "go get" command with cgo in cmd/go
Alert  GO-2022-0203: Remote command execution via "go get" command with "-insecure" option in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
May 24, 2017 GO-2021-0068 +20 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0177: Remote command execution via "go get" in cmd/go
Alert  GO-2022-0201: Remote command execution via "go get" command with cgo in cmd/go
Alert  GO-2022-0203: Remote command execution via "go get" command with "-insecure" option in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
May 23, 2017 GO-2021-0068 +20 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0177: Remote command execution via "go get" in cmd/go
Alert  GO-2022-0201: Remote command execution via "go get" command with cgo in cmd/go
Alert  GO-2022-0203: Remote command execution via "go get" command with "-insecure" option in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Apr 7, 2017 GO-2021-0068 +20 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0177: Remote command execution via "go get" in cmd/go
Alert  GO-2022-0201: Remote command execution via "go get" command with cgo in cmd/go
Alert  GO-2022-0203: Remote command execution via "go get" command with "-insecure" option in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Feb 16, 2017 GO-2021-0068 +20 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0177: Remote command execution via "go get" in cmd/go
Alert  GO-2022-0201: Remote command execution via "go get" command with cgo in cmd/go
Alert  GO-2022-0203: Remote command execution via "go get" command with "-insecure" option in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Jan 26, 2017 GO-2021-0068 +20 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0177: Remote command execution via "go get" in cmd/go
Alert  GO-2022-0201: Remote command execution via "go get" command with cgo in cmd/go
Alert  GO-2022-0203: Remote command execution via "go get" command with "-insecure" option in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Jan 19, 2017 GO-2021-0068 +20 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0177: Remote command execution via "go get" in cmd/go
Alert  GO-2022-0201: Remote command execution via "go get" command with cgo in cmd/go
Alert  GO-2022-0203: Remote command execution via "go get" command with "-insecure" option in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Jan 10, 2017 GO-2021-0068 +20 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0177: Remote command execution via "go get" in cmd/go
Alert  GO-2022-0201: Remote command execution via "go get" command with cgo in cmd/go
Alert  GO-2022-0203: Remote command execution via "go get" command with "-insecure" option in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Dec 15, 2016 GO-2021-0068 +20 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0177: Remote command execution via "go get" in cmd/go
Alert  GO-2022-0201: Remote command execution via "go get" command with cgo in cmd/go
Alert  GO-2022-0203: Remote command execution via "go get" command with "-insecure" option in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Dec 1, 2016 GO-2021-0068 +20 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0177: Remote command execution via "go get" in cmd/go
Alert  GO-2022-0201: Remote command execution via "go get" command with cgo in cmd/go
Alert  GO-2022-0203: Remote command execution via "go get" command with "-insecure" option in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
May 23, 2017 GO-2021-0068 +20 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0177: Remote command execution via "go get" in cmd/go
Alert  GO-2022-0201: Remote command execution via "go get" command with cgo in cmd/go
Alert  GO-2022-0203: Remote command execution via "go get" command with "-insecure" option in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Jan 26, 2017 GO-2021-0068 +20 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0177: Remote command execution via "go get" in cmd/go
Alert  GO-2022-0201: Remote command execution via "go get" command with cgo in cmd/go
Alert  GO-2022-0203: Remote command execution via "go get" command with "-insecure" option in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Dec 1, 2016 GO-2021-0068 +20 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0177: Remote command execution via "go get" in cmd/go
Alert  GO-2022-0201: Remote command execution via "go get" command with cgo in cmd/go
Alert  GO-2022-0203: Remote command execution via "go get" command with "-insecure" option in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Oct 19, 2016 GO-2021-0068 +20 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0177: Remote command execution via "go get" in cmd/go
Alert  GO-2022-0201: Remote command execution via "go get" command with cgo in cmd/go
Alert  GO-2022-0203: Remote command execution via "go get" command with "-insecure" option in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Oct 17, 2016 GO-2021-0068 +20 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0177: Remote command execution via "go get" in cmd/go
Alert  GO-2022-0201: Remote command execution via "go get" command with cgo in cmd/go
Alert  GO-2022-0203: Remote command execution via "go get" command with "-insecure" option in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Sep 7, 2016 GO-2021-0068 +20 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0177: Remote command execution via "go get" in cmd/go
Alert  GO-2022-0201: Remote command execution via "go get" command with cgo in cmd/go
Alert  GO-2022-0203: Remote command execution via "go get" command with "-insecure" option in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Aug 15, 2016 GO-2021-0068 +20 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0177: Remote command execution via "go get" in cmd/go
Alert  GO-2022-0201: Remote command execution via "go get" command with cgo in cmd/go
Alert  GO-2022-0203: Remote command execution via "go get" command with "-insecure" option in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Aug 8, 2016 GO-2021-0068 +20 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0177: Remote command execution via "go get" in cmd/go
Alert  GO-2022-0201: Remote command execution via "go get" command with cgo in cmd/go
Alert  GO-2022-0203: Remote command execution via "go get" command with "-insecure" option in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Aug 2, 2016 GO-2021-0068 +20 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0177: Remote command execution via "go get" in cmd/go
Alert  GO-2022-0201: Remote command execution via "go get" command with cgo in cmd/go
Alert  GO-2022-0203: Remote command execution via "go get" command with "-insecure" option in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Aug 2, 2016 GO-2021-0068 +20 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0177: Remote command execution via "go get" in cmd/go
Alert  GO-2022-0201: Remote command execution via "go get" command with cgo in cmd/go
Alert  GO-2022-0203: Remote command execution via "go get" command with "-insecure" option in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Jul 21, 2016 GO-2021-0068 +20 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0177: Remote command execution via "go get" in cmd/go
Alert  GO-2022-0201: Remote command execution via "go get" command with cgo in cmd/go
Alert  GO-2022-0203: Remote command execution via "go get" command with "-insecure" option in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Jul 18, 2016 GO-2021-0068 +20 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0177: Remote command execution via "go get" in cmd/go
Alert  GO-2022-0201: Remote command execution via "go get" command with cgo in cmd/go
Alert  GO-2022-0203: Remote command execution via "go get" command with "-insecure" option in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Jul 8, 2016 GO-2021-0068 +20 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0177: Remote command execution via "go get" in cmd/go
Alert  GO-2022-0201: Remote command execution via "go get" command with cgo in cmd/go
Alert  GO-2022-0203: Remote command execution via "go get" command with "-insecure" option in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Jun 16, 2016 GO-2021-0068 +20 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0177: Remote command execution via "go get" in cmd/go
Alert  GO-2022-0201: Remote command execution via "go get" command with cgo in cmd/go
Alert  GO-2022-0203: Remote command execution via "go get" command with "-insecure" option in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Jun 2, 2016 GO-2021-0068 +20 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0177: Remote command execution via "go get" in cmd/go
Alert  GO-2022-0201: Remote command execution via "go get" command with cgo in cmd/go
Alert  GO-2022-0203: Remote command execution via "go get" command with "-insecure" option in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Dec 1, 2016 GO-2021-0068 +20 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0177: Remote command execution via "go get" in cmd/go
Alert  GO-2022-0201: Remote command execution via "go get" command with cgo in cmd/go
Alert  GO-2022-0203: Remote command execution via "go get" command with "-insecure" option in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Jul 18, 2016 GO-2021-0068 +20 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0177: Remote command execution via "go get" in cmd/go
Alert  GO-2022-0201: Remote command execution via "go get" command with cgo in cmd/go
Alert  GO-2022-0203: Remote command execution via "go get" command with "-insecure" option in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Apr 19, 2016 GO-2021-0068 +20 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0177: Remote command execution via "go get" in cmd/go
Alert  GO-2022-0201: Remote command execution via "go get" command with cgo in cmd/go
Alert  GO-2022-0203: Remote command execution via "go get" command with "-insecure" option in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Apr 11, 2016 GO-2021-0068 +20 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0177: Remote command execution via "go get" in cmd/go
Alert  GO-2022-0201: Remote command execution via "go get" command with cgo in cmd/go
Alert  GO-2022-0203: Remote command execution via "go get" command with "-insecure" option in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Feb 17, 2016 GO-2021-0068 +20 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0177: Remote command execution via "go get" in cmd/go
Alert  GO-2022-0201: Remote command execution via "go get" command with cgo in cmd/go
Alert  GO-2022-0203: Remote command execution via "go get" command with "-insecure" option in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Feb 3, 2016 GO-2021-0068 +20 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0177: Remote command execution via "go get" in cmd/go
Alert  GO-2022-0201: Remote command execution via "go get" command with cgo in cmd/go
Alert  GO-2022-0203: Remote command execution via "go get" command with "-insecure" option in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Jan 28, 2016 GO-2021-0068 +20 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0177: Remote command execution via "go get" in cmd/go
Alert  GO-2022-0201: Remote command execution via "go get" command with cgo in cmd/go
Alert  GO-2022-0203: Remote command execution via "go get" command with "-insecure" option in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Jan 13, 2016 GO-2021-0068 +20 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0177: Remote command execution via "go get" in cmd/go
Alert  GO-2022-0201: Remote command execution via "go get" command with cgo in cmd/go
Alert  GO-2022-0203: Remote command execution via "go get" command with "-insecure" option in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Dec 17, 2015 GO-2021-0068 +20 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0177: Remote command execution via "go get" in cmd/go
Alert  GO-2022-0201: Remote command execution via "go get" command with cgo in cmd/go
Alert  GO-2022-0203: Remote command execution via "go get" command with "-insecure" option in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Apr 11, 2016 GO-2021-0068 +20 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0177: Remote command execution via "go get" in cmd/go
Alert  GO-2022-0201: Remote command execution via "go get" command with cgo in cmd/go
Alert  GO-2022-0203: Remote command execution via "go get" command with "-insecure" option in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Jan 13, 2016 GO-2021-0068 +20 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0177: Remote command execution via "go get" in cmd/go
Alert  GO-2022-0201: Remote command execution via "go get" command with cgo in cmd/go
Alert  GO-2022-0203: Remote command execution via "go get" command with "-insecure" option in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Dec 3, 2015 GO-2021-0068 +20 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0177: Remote command execution via "go get" in cmd/go
Alert  GO-2022-0201: Remote command execution via "go get" command with cgo in cmd/go
Alert  GO-2022-0203: Remote command execution via "go get" command with "-insecure" option in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Sep 9, 2015 GO-2021-0068 +20 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0177: Remote command execution via "go get" in cmd/go
Alert  GO-2022-0201: Remote command execution via "go get" command with cgo in cmd/go
Alert  GO-2022-0203: Remote command execution via "go get" command with "-insecure" option in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Aug 19, 2015 GO-2021-0068 +20 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0177: Remote command execution via "go get" in cmd/go
Alert  GO-2022-0201: Remote command execution via "go get" command with cgo in cmd/go
Alert  GO-2022-0203: Remote command execution via "go get" command with "-insecure" option in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Aug 6, 2015 GO-2021-0068 +20 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0177: Remote command execution via "go get" in cmd/go
Alert  GO-2022-0201: Remote command execution via "go get" command with cgo in cmd/go
Alert  GO-2022-0203: Remote command execution via "go get" command with "-insecure" option in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Jul 29, 2015 GO-2021-0068 +20 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0177: Remote command execution via "go get" in cmd/go
Alert  GO-2022-0201: Remote command execution via "go get" command with cgo in cmd/go
Alert  GO-2022-0203: Remote command execution via "go get" command with "-insecure" option in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Jul 17, 2015 GO-2021-0068 +20 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0177: Remote command execution via "go get" in cmd/go
Alert  GO-2022-0201: Remote command execution via "go get" command with cgo in cmd/go
Alert  GO-2022-0203: Remote command execution via "go get" command with "-insecure" option in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Jul 7, 2015 GO-2021-0068 +20 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0177: Remote command execution via "go get" in cmd/go
Alert  GO-2022-0201: Remote command execution via "go get" command with cgo in cmd/go
Alert  GO-2022-0203: Remote command execution via "go get" command with "-insecure" option in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Sep 23, 2015 GO-2021-0068 +20 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0177: Remote command execution via "go get" in cmd/go
Alert  GO-2022-0201: Remote command execution via "go get" command with cgo in cmd/go
Alert  GO-2022-0203: Remote command execution via "go get" command with "-insecure" option in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Feb 18, 2015 GO-2021-0068 +20 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0177: Remote command execution via "go get" in cmd/go
Alert  GO-2022-0201: Remote command execution via "go get" command with cgo in cmd/go
Alert  GO-2022-0203: Remote command execution via "go get" command with "-insecure" option in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Jan 15, 2015 GO-2021-0068 +20 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0177: Remote command execution via "go get" in cmd/go
Alert  GO-2022-0201: Remote command execution via "go get" command with cgo in cmd/go
Alert  GO-2022-0203: Remote command execution via "go get" command with "-insecure" option in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Dec 11, 2014 GO-2021-0068 +20 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0177: Remote command execution via "go get" in cmd/go
Alert  GO-2022-0201: Remote command execution via "go get" command with cgo in cmd/go
Alert  GO-2022-0203: Remote command execution via "go get" command with "-insecure" option in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Dec 2, 2014 GO-2021-0068 +20 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0177: Remote command execution via "go get" in cmd/go
Alert  GO-2022-0201: Remote command execution via "go get" command with cgo in cmd/go
Alert  GO-2022-0203: Remote command execution via "go get" command with "-insecure" option in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Nov 17, 2014 GO-2021-0068 +20 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0177: Remote command execution via "go get" in cmd/go
Alert  GO-2022-0201: Remote command execution via "go get" command with cgo in cmd/go
Alert  GO-2022-0203: Remote command execution via "go get" command with "-insecure" option in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Oct 30, 2014 GO-2021-0068 +20 more
Alert  GO-2021-0068: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Alert  GO-2022-0177: Remote command execution via "go get" in cmd/go
Alert  GO-2022-0201: Remote command execution via "go get" command with cgo in cmd/go
Alert  GO-2022-0203: Remote command execution via "go get" command with "-insecure" option in cmd/go
Alert  GO-2022-0475: Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Alert  GO-2022-0476: Arbitrary code execution via the go command with cgo in cmd/go
Alert  GO-2023-1839: Code injection via go command with cgo in cmd/go
Alert  GO-2023-1841: Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Alert  GO-2023-1842: Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Alert  GO-2023-2095: Arbitrary code execution during build via line directives in cmd/go
Alert  GO-2023-2383: Command 'go get' may unexpectedly fallback to insecure git in cmd/go
Alert  GO-2024-2825: Arbitrary code execution during build on Darwin in cmd/go
Alert  GO-2024-2962: Output of "go env" does not sanitize values in cmd/go
Alert  GO-2025-3828: Unexpected command execution in untrusted VCS repositories in cmd/go
Alert  GO-2026-4339: Arbitrary file write using cgo pkg-config directive in cmd/go
Alert  GO-2026-4871: Code execution vulnerability in SWIG code generation in cmd/go
Alert  GO-2026-4978: Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Alert  GO-2026-4979: Invoking "go tool pack" does not sanitize output paths in cmd/go
Alert  GO-2026-4984: Malicious module proxy can bypass checksum database in cmd/go
Alert  GO-2026-6179: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Alert  GO-2026-6180: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL