CVE-2026-56864
Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
A malicious GOSUMDB was capable of serving arbitrary module content not contained within the transparency log. This attack allows for a coordinating GOPROXY and GOSUMDB to serve a client malicious module content that cannot be detected by evaluating the transparency log. In order to determine if you have been affected: rm -r go.sum go.work.sum vendor/ && go mod tidy
| Vendor | go toolchain |
| Product | cmd/go |
| Published | Aug 13, 2026 |
Stay Ahead of the Next One
Get instant alerts for go toolchain cmd/go
Be the first to know when new unknown vulnerabilities affecting go toolchain cmd/go are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Go toolchain / cmd/go
0 < 1.25.13 1.26.0-0 < 1.26.6 1.27.0-0 < 1.27.0-rc.3
golang.org/x/mod / golang.org/x/mod/sumdb
0 < 0.40.0
References
Credits
mundur