Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-27140

36
FAUCET Score

CVE-2026-27140 is a critical build-time vulnerability affecting SWIG (Simplified Wrapper and Interface Generator) that allows arbitrary code execution through maliciously crafted SWIG files containing 'cgo' references. The vulnerability exploits a trust layer bypass mechanism, enabling attackers to smuggle malicious code into the build process. This affects any development environment using SWIG for generating language bindings. The vulnerability carries a CVSS score of 8.8 (HIGH) with a network-based attack vector requiring minimal complexity and user interaction but no special privileges. An attacker can achieve complete compromise of confidentiality, integrity, and availability on the affected system during the build phase. The FAUCET Risk Score of 52.0 indicates moderate concern, though the EPSS score of 0.000140000 suggests current exploitation attempts are minimal. The vulnerability is not currently listed on CISA's Known Exploited Vulnerabilities catalog and has inactive status on the hot list, indicating no widespread active exploitation at this time. However, the relatively low EPSS percentile should not provide false assurance, as build-time vulnerabilities in development tools can pose significant supply chain risks if weaponized. Organizations using SWIG in their development pipeline should monitor for exploit availability and apply patches when released.

Impacted Technologies

VendorProductVersion(s)CPE
< 1.25.9CPE matchmatch criteria
cpe:2.3:a:golang:go:*:*:*:*:*:*:*:*
>= 1.26.0, < 1.26.2CPE matchmatch criteria
cpe:2.3:a:golang:go:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

8.8HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.66%
Probability of exploitation in next 30 days
EPSS Percentile
47.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-24
Model: v2026.06.15
This CVE's current EPSS score of 0.0066 is in the 49th percentile among its peer group of 14,824 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.

Remediation

Vendor Advisories (1)

microsoft2026-Apr/CVE-2026-27140Critical

Code execution vulnerability in SWIG code generation in cmd/go

Apr 2, 2026

References

access.redhat.com / errata/RHSA-2026:10217
access.redhat.com / errata/RHSA-2026:10219
access.redhat.com / errata/RHSA-2026:10704
access.redhat.com / errata/RHSA-2026:16021
access.redhat.com / errata/RHSA-2026:16024
access.redhat.com / errata/RHSA-2026:16494
access.redhat.com / errata/RHSA-2026:16497
access.redhat.com / errata/RHSA-2026:16498
access.redhat.com / errata/RHSA-2026:16694
access.redhat.com / errata/RHSA-2026:16697
access.redhat.com / errata/RHSA-2026:16698
access.redhat.com / errata/RHSA-2026:23246
access.redhat.com / errata/RHSA-2026:25182
access.redhat.com / errata/RHSA-2026:34099
access.redhat.com / security/cve/CVE-2026-27140
bugzilla.redhat.com / show_bug.cgi
security.access.redhat.com / data/csaf/v2/vex/2026/cve-2026-27140.json
go.dev / cl/763768
Release Notes
go.dev / issue/78335
Issue Tracking
groups.google.com / g/golang-announce/c/0uYbvbPZRWU
Mailing ListRelease Notes
pkg.go.dev / vuln/GO-2026-4871
Vendor Advisory