CVE-2026-27143
Missing bound checks can lead to memory corruption in safe Go in cmd/compile
CVSS Score
9.8
EPSS Score
0.0%
EPSS Percentile
1th
Arithmetic over induction variables in loops were not correctly checked for underflow or overflow. As a result, the compiler would allow for invalid indexing to occur at runtime, potentially leading to memory corruption.
| Vendor | go toolchain |
| Product | cmd/compile |
| Published | Apr 8, 2026 |
| Last Updated | Apr 13, 2026 |
Stay Ahead of the Next One
Get instant alerts for go toolchain cmd/compile
Be the first to know when new critical vulnerabilities affecting go toolchain cmd/compile are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Go toolchain / cmd/compile
0 < 1.25.9 1.26.0-0 < 1.26.2
References
Credits
Jakub Ciolek - https://ciolek.dev/