TopVuln

High-risk vulnerability digests

CVE-2025-61731

  • HIGH

RHSA-2026:7883 Red Hat Security Advisory: golang security update

Details

CVSS v3
7.8
NVD published
2026-01-28 20:16:10
EPSS
<0.1% probability · 1.1th percentile — 2026-04-13
Affected versions
cpe:2.3:a:golang:go:*:*:*:*:*:*:*:* cpe:2.3:a:golang:go:*:*:*:*:*:*:*:*
Summary
Building a malicious file with cmd/go can cause can cause a write to an attacker-controlled file with partial control of the file content. The "#cgo pkg-config:" directive in a Go source file provides command-line arguments to provide to the Go pkg-config command. An attacker can provide a "--log-file" argument to this directive, causing pkg-config to write to an attacker-controlled location.
Remediation
Not available in our cache.
Exploit info
Not available in our cache.

View on NVD

TopVuln sends digest emails with high-risk CVE picks across multiple authoritative sources—curated with EPSS and AI. Choose daily per-stream emails and optional weekly or monthly roundups.

Subscribe — free email digest or paid plan

Information is aggregated from multiple authoritative sources for convenience; verify with NVD and vendors before operational decisions.