7.5

CVE-2026-56864

Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb

A malicious GOSUMDB was capable of serving arbitrary module content not contained within the transparency log. This attack allows for a coordinating GOPROXY and GOSUMDB to serve a client malicious module content that cannot be detected by evaluating the transparency log. In order to determine if you have been affected:   rm -r go.sum go.work.sum vendor/ && go mod tidy
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerGo toolchain
≫
Produkt cmd/go
Default Statusunaffected
Version 0
Version < 1.25.13
Status affected
Version 1.26.0-0
Version < 1.26.6
Status affected
Version 1.27.0-0
Version < 1.27.0-rc.3
Status affected
Herstellergolang.org/x/mod
≫
Produkt golang.org/x/mod/sumdb
Default Statusunaffected
Version 0
Version < 0.40.0
Status affected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.25% 0.164
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
CISA-ADP 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CWE-347 Improper Verification of Cryptographic Signature

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

https://groups.google.com/g/golang-announce/c/94pEornpRlI
https://go.dev/issue/80745
https://go.dev/cl/815000
https://go.dev/cl/815020
https://pkg.go.dev/vuln/GO-2026-6180