Red Hat released a broad set of Important security updates for Go and Go-based packages across RHEL 8, 9, and 10, fixing multiple vulnerabilities that include build-time arbitrary code execution, denial of service, memory corruption, certificate validation failures, and a symlink-following flaw. Core golang and go-toolset:rhel8 updates moved affected platforms to fixed Go builds such as 1.25.9 variants, addressing CVEs including CVE-2026-27140, CVE-2026-27143, CVE-2026-27144, CVE-2026-32280, CVE-2026-32282, and CVE-2026-32283. Red Hat said CVE-2026-27140 could allow arbitrary code execution during builds through malicious SWIG filenames containing cgo, a flaw it scored CVSS 9.0.
The fixes also cascaded into Red Hat packages that embed or depend on Go components, including osbuild-composer, go-fdo-client, go-fdo-server, yggdrasil, delve, gvisor-tap-vsock, and golang-github-openprinting-ipp-usb. Several advisories specifically remediated Go crypto/x509 and crypto/tls issues tied to certificate chain validation and building (CVE-2026-32280, CVE-2026-32281, CVE-2026-32283), net/url parsing flaws such as CVE-2026-25679, and the internal/syscall/unix Root.Chmod symlink issue (CVE-2026-32282). Updated packages were published across standard, Extended Update Support, Advanced Update Support, SAP, and Extended Life Cycle channels for x86_64, aarch64, ppc64le, and s390x systems.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
15 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued RHSA-2026:49838 for osbuild-composer on Red Hat Enterprise Linux 9, releasing version 165.1-4.el9_8. The update fixed CVE-2026-32281 and CVE-2026-32280 and also included bug fix RHEL-185745 for a bootupctl backend install --auto failure.
Red Hat issued RHSA-2026:49526 for osbuild-composer on Red Hat Enterprise Linux 10, releasing version 165.1-3.el10_2.1. The update addressed CVE-2026-32281 and CVE-2026-32280 across standard, EUS, 4-year, and ELC channels for RHEL 10.2.
Red Hat issued RHSA-2026:22709 for osbuild-composer on RHEL 9.6 channels, releasing version 132.2-7.el9_6. The update fixed CVE-2026-32282, CVE-2026-32283, and CVE-2026-32280 across multiple RHEL 9.6 support offerings.
Red Hat issued RHSA-2026:22141 for go-fdo-client and go-fdo-server on Red Hat Enterprise Linux 10. The update released go-fdo-client 1.0.0-4.el10_2 and go-fdo-server 1.0.1-2.el10_2 to fix CVE-2025-68121, CVE-2026-32281, CVE-2026-32282, and CVE-2026-32280.
Red Hat issued RHSA-2026:19750 for osbuild-composer on Red Hat Enterprise Linux 10.0, releasing version 134.1-7.el10_0. The update fixed CVE-2026-25679, CVE-2026-32282, CVE-2026-32283, and CVE-2026-32280.
Red Hat issued RHSA-2026:19049 for golang-github-openprinting-ipp-usb on Red Hat Enterprise Linux 10, releasing ipp-usb version 0.9.27-6.el10_2. The update addressed CVE-2026-27137 and CVE-2026-25679 across multiple architectures and support channels.
Red Hat issued RHSA-2026:17075 for yggdrasil on Red Hat Enterprise Linux 10, releasing version 0.4.8-5.el10_1. The update fixed CVE-2026-32282 and CVE-2026-32283 across standard, EUS, ELC, and CodeReady Linux Builder channels.
Red Hat issued RHSA-2026:16021 for golang packages in RHEL 9.6 channels, releasing golang version 1.25.9-1.el9_6. The update fixed CVE-2026-27140, CVE-2026-27143, CVE-2026-27144, CVE-2026-32280, CVE-2026-32282, and CVE-2026-32283 across multiple RHEL 9.6 variants.
Red Hat issued RHSA-2026:10704 for the go-toolset:rhel8 module, updating Go Toolset to version 1.25.9+2 for RHEL 8.10.z. The advisory fixed six Go vulnerabilities including CVE-2026-27140, CVE-2026-27143, CVE-2026-27144, CVE-2026-32280, CVE-2026-32282, and CVE-2026-32283.
Red Hat issued RHSA-2026:10217 for golang packages in Red Hat Enterprise Linux 10, updating Go to 1.25.9+2 and shipping golang/go-toolset packages version 1.25.9-3.el10_1. The advisory fixed CVE-2026-27140, CVE-2026-27143, CVE-2026-27144, CVE-2026-32280, CVE-2026-32282, and CVE-2026-32283.
Red Hat issued RHSA-2026:9108 for gvisor-tap-vsock on RHEL 9.6 channels, releasing version 0.8.5-2.el9_6.1. The update addressed CVE-2025-61729, CVE-2025-61726, CVE-2025-68121, and CVE-2026-25679 across multiple RHEL 9.6 support streams and architectures.
Red Hat issued RHSA-2026:8842 for delve on Red Hat Enterprise Linux 10, releasing version 1.25.2-3.el10_1 to fix CVE-2026-27137 and CVE-2026-25679. The update covered standard, Extended Update Support, 4-year, and Extended Life Cycle channels.
Red Hat's Bugzilla entry states the CVE-2026-27140 issue was recorded in OSIDB, tracking the SWIG-related trust-layer bypass that can lead to code smuggling and arbitrary code execution at build time.
Red Hat's CVE entry for CVE-2026-27140 was made public, describing an arbitrary code execution flaw in Go and cmd/go exploitable through malicious SWIG file names. The issue was rated Important by Red Hat.
Red Hat's public CVE page for CVE-2026-27140 was updated, reflecting the vulnerability's status and linked fixes across Red Hat product streams.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 10 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
14 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceredhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.