CVE-2026-56864
EUVD-2026-5851413.08.2026, 22:17
A malicious GOSUMDB was capable of serving arbitrary module content not contained within the transparency log. This attack allows for a coordinating GOPROXY and GOSUMDB to serve a client malicious module content that cannot be detected by evaluating the transparency log. In order to determine if you have been affected: rm -r go.sum go.work.sum vendor/ && go mod tidyEnginsight
Awaiting analysis
This vulnerability is currently awaiting analysis.
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| golang |
| ||||||||||||
| golang-1.6 |
| ||||||||||||
| golang-1.8 |
| ||||||||||||
| golang-1.9 |
| ||||||||||||
| golang-1.10 |
| ||||||||||||
| golang-1.13 |
| ||||||||||||
| golang-1.14 |
| ||||||||||||
| golang-1.16 |
| ||||||||||||
| golang-1.17 |
| ||||||||||||
| golang-1.18 |
| ||||||||||||
| golang-1.20 |
| ||||||||||||
| golang-1.21 |
| ||||||||||||
| golang-1.22 |
| ||||||||||||
| golang-1.23 |
| ||||||||||||
| golang-1.24 |
| ||||||||||||
| golang-1.25 |
|
Amazon Linux Releases
Amazon Package | |||||
|---|---|---|---|---|---|
| golang |
| ||||
| golang-bin |
| ||||
| golang-docs |
| ||||
| golang-misc |
| ||||
| golang-shared |
| ||||
| golang-src |
| ||||
| golang-tests |
|
Common Weakness Enumeration
Vulnerability Media Exposure