7.5
CVE-2026-56864
- EPSS 0.25%
- Veröffentlicht 13.08.2026 21:58:53
- Zuletzt bearbeitet 03.09.2026 16:37:52
- Erkennungen
Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
A malicious GOSUMDB was capable of serving arbitrary module content not contained within the transparency log. This attack allows for a coordinating GOPROXY and GOSUMDB to serve a client malicious module content that cannot be detected by evaluating the transparency log. In order to determine if you have been affected: rm -r go.sum go.work.sum vendor/ && go mod tidy
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerGo toolchain
≫
Produkt
cmd/go
Default Statusunaffected
Version
0
Version <
1.25.13
Status
affected
Version
1.26.0-0
Version <
1.26.6
Status
affected
Version
1.27.0-0
Version <
1.27.0-rc.3
Status
affected
Herstellergolang.org/x/mod
≫
Produkt
golang.org/x/mod/sumdb
Default Statusunaffected
Version
0
Version <
0.40.0
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.25% | 0.164 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| CISA-ADP | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
CWE-347 Improper Verification of Cryptographic Signature
The product does not verify, or incorrectly verifies, the cryptographic signature for data.
https://groups.google.com/g/golang-announce/c/94pEornpRlI
https://go.dev/issue/80745
https://go.dev/cl/815000
https://go.dev/cl/815020
https://pkg.go.dev/vuln/GO-2026-6180