Multiple CVEs Identified in Go Command's LDFLAGS Handling
First seen 18 Feb 2026, 13:23 UTC
•
•39
Export
Article Content
Browse articles
Two vulnerabilities, CVE-2023-29405 and CVE-2023-29404, were published on June 8, 2023, affecting the Go programming language's handling of LDFLAGS in the cmd/go tool when using cgo. CVE-2023-29405 involves improper sanitization of LDFLAGS with embedded spaces, while CVE-2023-29404 relates to improper handling of non-optional LDFLAGS. These vulnerabilities could impact developers using Go for building applications.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Timeline
2023-06-08
CVE-2023-29405 published
2023-06-08
CVE-2023-29404 published
2026-02-18
Information published about CVE-2023-29405
2026-02-18
Information published about CVE-2023-29404