CVE-2026-56864

EUVD-2026-58514
A malicious GOSUMDB was capable of serving arbitrary module content not contained within the transparency log. This attack allows for a coordinating GOPROXY and GOSUMDB to serve a client malicious module content that cannot be detected by evaluating the transparency log. In order to determine if you have been affected:   rm -r go.sum go.work.sum vendor/ && go mod tidy
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 22.03%
Debian logo
Debian Releases
Debian Product
Codename
golang-1.19
bookworm
postponed
golang-1.24
trixie
no-dsa
golang-1.25
forky
vulnerable
golang-1.26
forky
1.26.8-1
fixed
sid
1.26.8-1
fixed
golang-1.27
forky
1.27.1-2
fixed
sid
1.27.1-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
golang
jammy
dne
noble
dne
resolute
dne
golang-1.6
jammy
dne
noble
dne
resolute
dne
xenial
needs-triage
golang-1.8
bionic
needs-triage
jammy
dne
noble
dne
resolute
dne
golang-1.9
bionic
needs-triage
jammy
dne
noble
dne
resolute
dne
golang-1.10
bionic
needs-triage
jammy
dne
noble
dne
resolute
dne
trusty
needs-triage
xenial
needs-triage
golang-1.13
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
dne
resolute
dne
xenial
needs-triage
golang-1.14
focal
needs-triage
jammy
dne
noble
dne
resolute
dne
golang-1.16
bionic
needs-triage
focal
needs-triage
jammy
dne
noble
dne
resolute
dne
golang-1.17
jammy
needs-triage
noble
dne
resolute
dne
golang-1.18
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
dne
resolute
dne
xenial
needs-triage
golang-1.20
focal
needs-triage
jammy
needs-triage
noble
dne
resolute
dne
golang-1.21
focal
needs-triage
jammy
needs-triage
noble
needs-triage
resolute
dne
golang-1.22
focal
needs-triage
jammy
needs-triage
noble
needs-triage
resolute
dne
golang-1.23
jammy
needs-triage
noble
needs-triage
resolute
needs-triage
golang-1.24
jammy
needs-triage
noble
needs-triage
resolute
needs-triage
golang-1.25
jammy
dne
noble
dne
resolute
needs-triage
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
golang
Amazon Linux 2
0:1.26.7-1.amzn2.0.1
fixed
Amazon Linux 2023
0:1.26.7-1.amzn2023.0.1
fixed
golang-bin
Amazon Linux 2
0:1.26.7-1.amzn2.0.1
fixed
Amazon Linux 2023
0:1.26.7-1.amzn2023.0.1
fixed
golang-docs
Amazon Linux 2
0:1.26.7-1.amzn2.0.1
fixed
Amazon Linux 2023
0:1.26.7-1.amzn2023.0.1
fixed
golang-misc
Amazon Linux 2
0:1.26.7-1.amzn2.0.1
fixed
Amazon Linux 2023
0:1.26.7-1.amzn2023.0.1
fixed
golang-shared
Amazon Linux 2
0:1.26.7-1.amzn2.0.1
fixed
Amazon Linux 2023
0:1.26.7-1.amzn2023.0.1
fixed
golang-src
Amazon Linux 2
0:1.26.7-1.amzn2.0.1
fixed
Amazon Linux 2023
0:1.26.7-1.amzn2023.0.1
fixed
golang-tests
Amazon Linux 2
0:1.26.7-1.amzn2.0.1
fixed
Amazon Linux 2023
0:1.26.7-1.amzn2023.0.1
fixed