discrepancy between how Go and C/C++ comments were parsed allowed for code smuggling into the resulting cgo binary
Details
CVE-2025-61732 affects multiple packages. A discrepancy between how Go and C/C++ comments were parsed allowed for code smuggling into the resulting cgo binary. See references for individual vulnerability details.