Wiz Agents & Workflows are here

CVE-2021-3115
NixOS vulnerability analysis and mitigation

Overview

CVE-2021-3115 affects Go versions before 1.14.14 and 1.15.x before 1.15.7 on Windows systems. The vulnerability involves command injection and remote code execution when using the "go get" command to fetch modules that make use of cgo. The issue was discovered in January 2021 and was fixed with the release of Go 1.14.14 and 1.15.7 (Golang Blog, Golang Announce).

Technical details

The vulnerability stems from how the Go command handles PATH lookups during cgo operations. When building packages that use cgo, the compiler executes in the package source directory, which can lead to executing malicious gcc.exe files from the current directory instead of the system gcc compiler. This occurs due to Windows' behavior of always searching the current directory first for executables, regardless of PATH settings. The vulnerability has a CVSS score of 7.5 (HIGH) with a vector of CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H (NetApp Advisory).

Impact

Successful exploitation of this vulnerability could lead to arbitrary code execution during the build process when using the "go get" command or any other command that builds code. While primarily affecting Windows users, Unix users who have "." listed explicitly in their PATH and are running "go get" or build commands outside of a module or with module mode disabled are also vulnerable (Golang Blog).

Mitigation and workarounds

The issue has been fixed in Go versions 1.14.14 and 1.15.7. Users should upgrade to one of these versions or later. The fix includes changes to the go command to pass the full host C compiler path to cgo and modifications to prevent execution of programs from the current directory during PATH lookups (Golang Announce).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-2370HIGH8.8
  • GitLabGitLab
  • gitlab
NoYesMar 30, 2026
CVE-2026-33206HIGH8.2
  • NixOSNixOS
  • calibre
NoYesMar 27, 2026
CVE-2026-33868MEDIUM6.1
  • NixOSNixOS
  • mastodon
NoYesMar 27, 2026
CVE-2026-33869MEDIUM4.8
  • NixOSNixOS
  • cpe:2.3:a:joinmastodon:mastodon
NoYesMar 27, 2026
CVE-2026-33205MEDIUM4.8
  • NixOSNixOS
  • cpe:2.3:a:calibre-ebook:calibre
NoYesMar 27, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management