CVE-2026-27143
Critical · CVSS 9.8- CVSS
- 9.8
- nvd
- EPSS
- —
- KEV
- No
- Class
- oss containerizable
- NVD-CWE-Other
Description
Arithmetic over induction variables in loops were not correctly checked for underflow or overflow. As a result, the compiler would allow for invalid indexing to occur at runtime, potentially leading to memory corruption.
Affected packages
| Bitnami | golang | 0 → 1.25.9 |
| Bitnami | golang | 1.26.0 → 1.26.2 |
| Go | toolchain | 0 → 1.25.9 |
| Go | toolchain | 1.26.0-0 → 1.26.2 |
References
Status: profiled · ingested 2026-07-25T12:00:18.000Z