Vulnerability GO-2026-4978
Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
5 months ago
May 07, 2026 at 07:21 PM UTC
Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
<1.25.10
<1.25.10
Summary
Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Details
The "go bug" command writes to two files with predictable names in the system temporary directory (for example, "/tmp").
An attacker with access to the temporary directory can create a symlink in one of these names, causing "go bug" to overwrite the target of the symlink.
References
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Unknown
9 hours ago
Checksum bypass for golang.org/fips140 in cmd/go
<1.26.9 GO-2026-6601
<1.26.9 GO-2026-6601
Unknown
9 hours ago
Checksum database bypass for golang.org/toolchain in cmd/go
<1.26.9 GO-2026-6602
<1.26.9 GO-2026-6602
Unknown
1 month ago
Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
<1.25.13 GO-2026-6179
<1.25.13 GO-2026-6179
Unknown
1 month ago
Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
<1.25.13 GO-2026-6180
<1.25.13 GO-2026-6180
Unknown
5 months ago
Invoking "go tool pack" does not sanitize output paths in cmd/go
<1.25.10 GO-2026-4979
<1.25.10 GO-2026-4979
Impacted packages
Timeline
Published
5 months ago
May 07, 2026 at 07:21 PM UTC
Last Modified
16 days ago
September 22, 2026 at 10:41 AM UTC