Skip to main content
Version: latest

CVE-2020-28367

CVE Details

Visit the official vulnerability details page for CVE-2020-28367 to learn more.

Initial Publication

01/20/2025

Last Update

10/14/2025

Third Party Dependency

go

NIST CVE Summary

Code injection in the go command with cgo before Go 1.14.12 and Go 1.15.5 allows arbitrary code execution at build time via malicious gcc flags specified via a #cgo directive.

CVE Severity

7.5

Our Official Summary

This vulnerability is a false positive. Although this is reported by the scanning tools on some of the components, further checks indicate the symbol/function with the vulnerability while present is not being used.

Status

Ongoing

Affected Products & Versions

This CVE is non-impacting as the impacting symbol and/or function is not used in the product

Revision History

DateRevision
10/14/2025Status changed from Open to Ongoing