CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-27143

Critical · CVSS 9.8
CVSS
9.8
nvd
EPSS
KEV
No
Class
oss containerizable
NVD-CWE-Other

Description

Arithmetic over induction variables in loops were not correctly checked for underflow or overflow. As a result, the compiler would allow for invalid indexing to occur at runtime, potentially leading to memory corruption.

Affected packages

Bitnami golang 0 → 1.25.9
Bitnami golang 1.26.0 → 1.26.2
Go toolchain 0 → 1.25.9
Go toolchain 1.26.0-0 → 1.26.2

References

Status: profiled · ingested 2026-07-25T12:00:18.000Z