CVE-2025-61732
A discrepancy between how Go and C/C++ comments were parsed allowed for code smuggling into the resulting cgo binary.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.4
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
- EPSS probability
- 0.48%
- Published
- 2026-02-05
- Last modified
- 2026-09-14
Affected products
- Go toolchain cmd/cgo
- Go toolchain cmd/cgo