golang: "go get" command vulnerable to RCE via import of malicious package
Published Dec 14, 2018
8.1
HIGHCVSS 3.1
EPSS 66.25%
Description
In Go before 1.10.6 and 1.11.x before 1.11.3, the "go get" command is vulnerable to remote code execution when executed with the -u flag and the import path of a malicious Go package, or a package that imports it directly or indirectly. Specifically, it is only vulnerable in GOPATH mode, but not in module mode (the distinction is documented at https://golang.org/cmd/go/#hdr-Module_aware_go_get). Using custom domains, it's possible to arrange things so that a Git repository is cloned to a folder named ".git" by using a vanity import path that ends with "/.git". If the Git repository root contains a "HEAD" file, a "config" file, an "objects" directory, a "refs" directory, with some work to ensure the proper ordering of operations, "go get -u" can be tricked into considering the parent directory as a repository root, and running Git commands on it. That will use the "config" file in the original Git repository root for its configuration, and if that config file contains malicious commands, they will execute on the system running "go get -u".
Affected products
- Vendor n/a Product Golang Defaultn/a
- Version 1.10.6StatusaffectedConstraints-
- Version 1.11.3StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| n/a | Golang | n/a |
|
Configuration 2
- 15.0
- 15.0
- 15.1
- 42.3
- 12
Configuration 3
- 9.0
No data.
Red Hat Ceph Storage 2
golang
Will not fix
Red Hat Ceph Storage 3
golang
Will not fix
Red Hat Enterprise Linux 7
golang
Will not fix
Red Hat Enterprise Linux 8
go-toolset:rhel8/golang
Not affected
Red Hat OpenShift Container Platform 3.10
atomic-openshift
Fix deferred
Red Hat OpenShift Container Platform 3.11
atomic-openshift
Not affected
Red Hat OpenShift Container Platform 3.7
atomic-openshift
Out of support scope
Red Hat OpenShift Container Platform 3.9
atomic-openshift
Fix deferred
Red Hat OpenShift Container Platform 4
openshift
Not affected
Red Hat OpenStack Platform 8 (Liberty) Operational Tools
golang
Will not fix
Red Hat OpenStack Platform 9 (Mitaka) Operational Tools
golang
Will not fix
Red Hat Storage 3
golang
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Ceph Storage 2 | golang | Will not fix | n/a |
| Red Hat Ceph Storage 3 | golang | Will not fix | n/a |
| Red Hat Enterprise Linux 7 | golang | Will not fix | n/a |
| Red Hat Enterprise Linux 8 | go-toolset:rhel8/golang | Not affected | n/a |
| Red Hat OpenShift Container Platform 3.10 | atomic-openshift | Fix deferred | n/a |
| Red Hat OpenShift Container Platform 3.11 | atomic-openshift | Not affected | n/a |
| Red Hat OpenShift Container Platform 3.7 | atomic-openshift | Out of support scope | n/a |
| Red Hat OpenShift Container Platform 3.9 | atomic-openshift | Fix deferred | n/a |
| Red Hat OpenShift Container Platform 4 | openshift | Not affected | n/a |
| Red Hat OpenStack Platform 8 (Liberty) Operational Tools | golang | Will not fix | n/a |
| Red Hat OpenStack Platform 9 (Mitaka) Operational Tools | golang | Will not fix | n/a |
| Red Hat Storage 3 | golang | Will not fix | n/a |
toolchain
Go
Introduced 1.11.0-0 Fixed 1.11.3toolchain
Go
Introduced 0 Fixed 1.10.6
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | toolchain | 1.11.0-0 | 1.11.3 |
| Go | toolchain | 0 | 1.10.6 |
Remediation
Red Hat statement
This issue affects the version of golang package in Red Hat Enterprise Linux 7. The golang package, previously available in the Optional channel, will no longer receive updates in Red Hat Enterprise Linux 7. Developers are encouraged to use the Go Toolset instead, which is available through the Red Hat Developer program. https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/7/html/7.6_release_notes/chap-red_hat_enterprise_linux-7.6_release_notes-deprecated_functionality_in_rhel7#idm139716309923696
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
AV:N/AC:M/Au:N/C:P/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (36 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 66.25% (0.66252) | 99.26th | v5 (v2026.06.15) |
| Jun 15, 2026 | 66.25% (0.66252) | 99.18th | v5 (v2026.06.15) |
| Mar 11, 2026 | 56.80% (0.56804) | 98.09th | v4 (v2025.03.14) |
| Jan 16, 2026 | 60.61% (0.60608) | 98.22th | v4 (v2025.03.14) |
| Jan 5, 2026 | 36.42% (0.36424) | 96.98th | v4 (v2025.03.14) |
| Nov 27, 2025 | 31.34% (0.31338) | 96.58th | v4 (v2025.03.14) |
| Nov 25, 2025 | 36.42% (0.36424) | 96.94th | v4 (v2025.03.14) |
| Nov 24, 2025 | 60.61% (0.60608) | 98.19th | v4 (v2025.03.14) |
| Nov 21, 2025 | 63.39% (0.63393) | 98.31th | v4 (v2025.03.14) |
| Nov 18, 2025 | 24.37% (0.24368) | 95.74th | v4 (v2025.03.14) |
| Oct 21, 2025 | 63.89% (0.63890) | 98.32th | v4 (v2025.03.14) |
| Oct 14, 2025 | 60.58% (0.60576) | 98.18th | v4 (v2025.03.14) |
| Oct 11, 2025 | 68.15% (0.68146) | 98.52th | v4 (v2025.03.14) |
| Oct 3, 2025 | 63.39% (0.63393) | 98.36th | v4 (v2025.03.14) |
| Aug 20, 2025 | 60.65% (0.60654) | 98.22th | v4 (v2025.03.14) |
| Aug 17, 2025 | 81.53% (0.81526) | 99.13th | v4 (v2025.03.14) |
| Aug 16, 2025 | 79.83% (0.79834) | 99.06th | v4 (v2025.03.14) |
| Mar 17, 2025 | 81.83% (0.81828) | 99.15th | v4 (v2025.03.14) |
| Dec 17, 2024 | 28.79% (0.28793) | 96.86th | v3 (v2023.03.01) |
| Dec 12, 2024 | 20.49% (0.20489) | 96.56th | v3 (v2023.03.01) |
| Oct 23, 2024 | 21.30% (0.21302) | 96.54th | v3 (v2023.03.01) |
| Jul 9, 2024 | 26.33% (0.26334) | 96.78th | v3 (v2023.03.01) |
| Jun 15, 2024 | 33.13% (0.33125) | 97.07th | v3 (v2023.03.01) |
| May 27, 2024 | 33.23% (0.33225) | 97.05th | v3 (v2023.03.01) |
| May 6, 2024 | 39.21% (0.39209) | 97.22th | v3 (v2023.03.01) |
| Mar 24, 2024 | 41.34% (0.41345) | 97.21th | v3 (v2023.03.01) |
| Dec 8, 2023 | 49.10% (0.49099) | 97.19th | v3 (v2023.03.01) |
| Nov 8, 2023 | 50.59% (0.50591) | 97.19th | v3 (v2023.03.01) |
| Mar 7, 2023 | 62.53% (0.62533) | 97.21th | v3 (v2023.03.01) |
| Mar 6, 2023 | 9.80% (0.09801) | 94.34th | v2 (v2022.01.01) |
| Apr 1, 2022 | 9.80% (0.09801) | 93.83th | v2 (v2022.01.01) |
| Feb 4, 2022 | 9.80% (0.09801) | 87.26th | v2 (v2022.01.01) |
| Feb 3, 2022 | 5.75% (0.05752) | 80.55th | v1 |
| Jan 6, 2022 | 5.75% (0.05752) | 80.36th | v1 |
| Sep 1, 2021 | 5.75% (0.05752) | 89.03th | v1 |
| Apr 14, 2021 | 5.75% (0.05752) | 0.00th | v1 |
References (17)
- http://lists.opensuse.org/opensuse-security-announce/2019-03/msg00044.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00060.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00011.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00015.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00010.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00041.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://www.securityfocus.com/bid/106226 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- https://access.redhat.com/security/cve/CVE-2018-16873 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1657563 Issue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16873 x_refsource_CONFIRMIssue TrackingThird Party Advisory
- https://groups.google.com/forum/?pli=1#!topic/golang-announce/Kw31K8G7Fi0
- https://groups.google.com/forum/?pli=1#%21topic/golang-announce/Kw31K8G7Fi0 x_refsource_MISC
- https://lists.debian.org/debian-lts-announce/2021/03/msg00014.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/03/msg00015.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2018-16873
- https://security.gentoo.org/glsa/201812-09 vendor-advisoryx_refsource_GENTOOMitigationThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2018-16873
Change history (0)
No recorded changes yet.