CVE-2026-27140 is a critical build-time vulnerability affecting SWIG (Simplified Wrapper and Interface Generator) that allows arbitrary code execution through maliciously crafted SWIG files containing 'cgo' references. The vulnerability exploits a trust layer bypass mechanism, enabling attackers to smuggle malicious code into the build process. This affects any development environment using SWIG for generating language bindings. The vulnerability carries a CVSS score of 8.8 (HIGH) with a network-based attack vector requiring minimal complexity and user interaction but no special privileges. An attacker can achieve complete compromise of confidentiality, integrity, and availability on the affected system during the build phase. The FAUCET Risk Score of 52.0 indicates moderate concern, though the EPSS score of 0.000140000 suggests current exploitation attempts are minimal. The vulnerability is not currently listed on CISA's Known Exploited Vulnerabilities catalog and has inactive status on the hot list, indicating no widespread active exploitation at this time. However, the relatively low EPSS percentile should not provide false assurance, as build-time vulnerabilities in development tools can pose significant supply chain risks if weaponized. Organizations using SWIG in their development pipeline should monitor for exploit availability and apply patches when released.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.25.9CPE matchmatch criteria | cpe:2.3:a:golang:go:*:*:*:*:*:*:*:* | ||
>= 1.26.0, < 1.26.2CPE matchmatch criteria | cpe:2.3:a:golang:go:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.