golang
cpe:2.3:a:golang:go:*:*:*:*:*:*:*
- < go1.25.9
- >= go1.26.0-0, < go1.26.2
A vulnerability exists in the Go compiler's handling of pointers during memory move operations. A no-op interface conversion interfered with the compiler's ability to correctly assess non-overlapping moves, which could lead to memory corruption at runtime. This issue is present in Go versions prior to 1.25.9 and in the 1.26.0 release up to but not including 1.26.2.
Exploitation of this vulnerability can cause memory corruption during program execution.
Users can upgrade to Go versions 1.26.2 or 1.25.9, both of which include the necessary fix. Instructions for downloading these versions are available on the Go website.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.