CVE-2026-42503
High
Published: 06 May 2026
Published
06 May 2026
Modified
06 May 2026
KEV Added
—
Patch
—
CVSS Score
8.8
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
N/A
Risk Priority
18
60% EPSS · 20% KEV · 20% CVSS
Description
gopls by default communicates via pipe. However, -port and -listen flags are supported as means of debugging. If -listen is given a value without an explicit host (e.g. :8080), or -port is used, gopls will listen on 0.0.0.0. As a…
more
result, users might inadvertently cause gopls to bind 0.0.0.0. This can allow a malicious party on the same network to execute code arbitrarily via gopls.
Security SummaryAI
Automated synthesis unavailable for this CVE.
Details
- CWE(s)