ThreatCluster

Multiple CVEs Identified in Go Command's LDFLAGS Handling

First seen 18 Feb 2026, 13:23 UTC Api.Msrc.Microsoft 39

Article Content

Browse articles
ThreatCluster

Two vulnerabilities, CVE-2023-29405 and CVE-2023-29404, were published on June 8, 2023, affecting the Go programming language's handling of LDFLAGS in the cmd/go tool when using cgo. CVE-2023-29405 involves improper sanitization of LDFLAGS with embedded spaces, while CVE-2023-29404 relates to improper handling of non-optional LDFLAGS. These vulnerabilities could impact developers using Go for building applications.

Timeline

2023-06-08
CVE-2023-29405 published
2023-06-08
CVE-2023-29404 published
2026-02-18
Information published about CVE-2023-29405
2026-02-18
Information published about CVE-2023-29404