CVE-2026-27143 is a compiler vulnerability involving improper arithmetic validation for induction variables within loops, allowing the compiler to generate code with invalid memory indexing that can lead to memory corruption at runtime. The vulnerability affects compiler implementations that fail to adequately check for integer underflow and overflow conditions during loop optimization. With a CVSS score of 9.8 (Critical), this vulnerability has a network attack vector with low complexity and no privilege requirements, enabling remote exploitation with high impact to confidentiality, integrity, and availability. The exploitation status indicates this vulnerability is not currently listed on the CISA Known Exploited Vulnerabilities (KEV) catalog and is inactive on threat tracking lists, suggesting limited to no active exploitation in the wild. However, the critical severity rating and low EPSS percentile indicate this represents a significant risk requiring prompt patching once fixes become available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.25.9CPE matchmatch criteria | cpe:2.3:a:golang:go:*:*:*:*:*:*:*:* | ||
>= 1.26.0, < 1.26.2CPE matchmatch criteria | cpe:2.3:a:golang:go:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.