- Description
- A discrepancy between how Go and C/C++ comments were parsed allowed for code smuggling into the resulting cgo binary.
- Source
- security@golang.org
- NVD status
- Analyzed
- Products
- go
CVSS 3.1
- Type
- Secondary
- Base score
- 8.6
- Impact score
- 6
- Exploitability score
- 1.8
- Vector string
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
- Severity
- HIGH
- 134c704f-9b21-4f2e-91b3-4a467353bcc0
- CWE-94
- Hype score
- Not currently trending
Top 5 Trending CVEs: 1 - CVE-2025-32711 2 - CVE-2026-1731 3 - CVE-2025-61732 4 - CVE-2026-20817 5 - CVE-2026-25526 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W
@CVEShield
10 Feb 2026
10 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Go 1.25.7, 1.24.13 fix 2 CVEs https://t.co/bf31PXLyCI CVE-2025-61732: cmd/cgo: Discrepancy between how Go and C/C++ comments were parsed allowed for code smuggling into the cgo binary CVE-2025-68121: crypto/tls: Unexpected session resumption when using Config.GetConfigForClient
@oss_security
8 Feb 2026
355 Impressions
0 Retweets
5 Likes
0 Bookmarks
0 Replies
0 Quotes
๐จ CVE-2025-61732 : GO CGO BUILD-TIME CODE INJECTION ALERT ๐จ A high-severity build-time code injection vulnerability has been disclosed in Goโs cgo toolchain, allowing attackers to smuggle malicious C/C++ code inside comments that execute during compilation, completely
@OstorlabSec
6 Feb 2026
46 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
[CVE-2025-61732: HIGH] A discrepancy between how Go and C/C++ comments were parsed allowed for code smuggling into the resulting cgo binary.#cve,CVE-2025-61732,#cybersecurity https://t.co/FVI59rzvWe
@CveFindCom
5 Feb 2026
72 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
๐ CVE-2025-61732 - High A discrepancy between how Go and C/C++ comments were parsed allowed for code smuggling into the resulting cgo binary. https://t.co/BzPIeGG7I2 https://t.co/9Ua9pFQExa
@TheHackerWire
5 Feb 2026
47 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-61732 A discrepancy between how Go and C/C++ comments were parsed allowed for code smuggling into the resulting cgo binary. https://t.co/uDbk6eiG9g
@CVEnew
5 Feb 2026
7 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
๐ Go 1.25.7 and 1.24.13 are released! ๐ Security: Includes a security fix for cmd/cgo (CVE-2025-61732) and an update for crypto/tls (CVE-2025-68121). ๐ฃ Announcement: https://t.co/gn4BwmFBh4 ๐ฆ Download: https://t.co/cZRQix5aeM #golang https://t.co/NnF8ayxKrK
@golang
4 Feb 2026
12719 Impressions
44 Retweets
308 Likes
18 Bookmarks
2 Replies
2 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:golang:go:*:*:*:*:*:*:*:*",
"matchCriteriaId": "9FEE539A-EDC2-4044-A38C-5A0FDF567509",
"versionEndExcluding": "1.24.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:golang:go:*:*:*:*:*:*:*:*",
"matchCriteriaId": "B275853C-E253-485B-B469-31D1A7383965",
"versionEndExcluding": "1.25.7",
"versionStartIncluding": "1.25.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]