Go Compiler No-Op Interface Conversion Memory Corruption Vulnerability

Vulnerability

A vulnerability exists in the Go compiler's handling of pointers during memory move operations. A no-op interface conversion interfered with the compiler's ability to correctly assess non-overlapping moves, which could lead to memory corruption at runtime. This issue is present in Go versions prior to 1.25.9 and in the 1.26.0 release up to but not including 1.26.2.

Impact

Exploitation of this vulnerability can cause memory corruption during program execution.

Remediation

Users can upgrade to Go versions 1.26.2 or 1.25.9, both of which include the necessary fix. Instructions for downloading these versions are available on the Go website.

Added: Apr 8, 2026, 2:24 AM
Updated: Apr 8, 2026, 2:24 AM

Vulnerability Rating

Custom Algorithm
spread
5.4
impact
0.6
exploitability
4.9
remediation
7.7
relevance
5.5
threat
3.2
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.