CVE detail
CVE-2026-27140
SWIG file names containing 'cgo' and well-crafted payloads could lead to code smuggling and arbitrary code execution at build time due to trust layer bypass.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 30.0 · diversity 20.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
22 source links · newest first
Information published.
vendormsrc.microsoft.comJun 3, 2026, 8:48 AM- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-27140.jsonsecurity.access.redhat.com
No excerpt available.
Vendor Advisorysecurity.access.redhat.comApr 8, 2026, 2:16 AM - https://bugzilla.redhat.com/show_bug.cgi?id=2456341bugzilla.redhat.com
No excerpt available.
Exploitbugzilla.redhat.comApr 8, 2026, 2:16 AM - https://access.redhat.com/security/cve/CVE-2026-27140access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comApr 8, 2026, 2:16 AM - https://access.redhat.com/errata/RHSA-2026:34099access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comApr 8, 2026, 2:16 AM - https://access.redhat.com/errata/RHSA-2026:25182access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comApr 8, 2026, 2:16 AM - https://access.redhat.com/errata/RHSA-2026:23246access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comApr 8, 2026, 2:16 AM - https://access.redhat.com/errata/RHSA-2026:16698access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comApr 8, 2026, 2:16 AM - https://access.redhat.com/errata/RHSA-2026:16697access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comApr 8, 2026, 2:16 AM - https://access.redhat.com/errata/RHSA-2026:16694access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comApr 8, 2026, 2:16 AM - https://access.redhat.com/errata/RHSA-2026:16498access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comApr 8, 2026, 2:16 AM - https://access.redhat.com/errata/RHSA-2026:16497access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comApr 8, 2026, 2:16 AM - https://access.redhat.com/errata/RHSA-2026:16494access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comApr 8, 2026, 2:16 AM - https://access.redhat.com/errata/RHSA-2026:16024access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comApr 8, 2026, 2:16 AM - https://access.redhat.com/errata/RHSA-2026:16021access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comApr 8, 2026, 2:16 AM - https://access.redhat.com/errata/RHSA-2026:10704access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comApr 8, 2026, 2:16 AM - https://access.redhat.com/errata/RHSA-2026:10219access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comApr 8, 2026, 2:16 AM - https://access.redhat.com/errata/RHSA-2026:10217access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comApr 8, 2026, 2:16 AM - https://pkg.go.dev/vuln/GO-2026-4871pkg.go.dev
No excerpt available.
Exploitpkg.go.devApr 8, 2026, 2:16 AM - https://groups.google.com/g/golang-announce/c/0uYbvbPZRWUgroups.google.com
No excerpt available.
Patchgroups.google.comApr 8, 2026, 2:16 AM No excerpt available.
Vendor Advisorygo.devApr 8, 2026, 2:16 AM- https://go.dev/cl/763768go.dev
No excerpt available.
Vendor Advisorygo.devApr 8, 2026, 2:16 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-48396CVSS 8.6 · High
Bridge is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vul…
- CVE-2026-48390CVSS 8.2 · High
Bridge is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain unauthorized read a…
- CVE-2026-7868CVSS 6.5 · Medium
IBM OPENBMC FW1110.00 through FW1110.20, and FW1060.00 through FW1060.71 allows ReadOnly users to escalate privileges and give themselves administrator privileges.
- CVE-2026-14167CVSS 8.7 · High
A low privileged remote attacker can perform privileged configuration changes reserved for the administrator level including permission management due to incorrect authorization.
- CVE-2026-43672CVSS 7.1 · High
An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A malicious application ma…
- CVE-2026-42016CVSS 8.1 · High
JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’…