CVE-2026-56865

EUVD-2026-58513
A malicious GOPROXY was previously capable of forging up to two sumdb tiles that allow for a requested module to bypass the GOSUMDB check and persist attacker-controlled module content to a local Go module cache. This attack allows for a malicious GOPROXY to serve malicious module content that cannot be detected by evaluating the transparency log. All tiles are now correctly verified against their parents. In order to determine if you have been affected:   rm -r go.sum go.work.sum vendor/ && go mod tidy
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.4 HIGH
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 2.61%
Debian logo
Debian Releases
Debian Product
Codename
golang-1.19
bookworm
postponed
golang-1.24
trixie
no-dsa
golang-1.25
forky
vulnerable
golang-1.26
forky
1.26.8-1
fixed
sid
1.26.8-1
fixed
golang-1.27
forky
1.27.1-2
fixed
sid
1.27.1-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
golang
jammy
dne
noble
dne
resolute
dne
golang-1.6
jammy
dne
noble
dne
resolute
dne
xenial
needs-triage
golang-1.8
bionic
needs-triage
jammy
dne
noble
dne
resolute
dne
golang-1.9
bionic
needs-triage
jammy
dne
noble
dne
resolute
dne
golang-1.10
bionic
needs-triage
jammy
dne
noble
dne
resolute
dne
trusty
needs-triage
xenial
needs-triage
golang-1.13
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
dne
resolute
dne
xenial
needs-triage
golang-1.14
focal
needs-triage
jammy
dne
noble
dne
resolute
dne
golang-1.16
bionic
needs-triage
focal
needs-triage
jammy
dne
noble
dne
resolute
dne
golang-1.17
jammy
needs-triage
noble
dne
resolute
dne
golang-1.18
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
dne
resolute
dne
xenial
needs-triage
golang-1.20
focal
needs-triage
jammy
needs-triage
noble
dne
resolute
dne
golang-1.21
focal
needs-triage
jammy
needs-triage
noble
needs-triage
resolute
dne
golang-1.22
focal
needs-triage
jammy
needs-triage
noble
needs-triage
resolute
dne
golang-1.23
jammy
needs-triage
noble
needs-triage
resolute
needs-triage
golang-1.24
jammy
needs-triage
noble
needs-triage
resolute
needs-triage
golang-1.25
jammy
dne
noble
dne
resolute
needs-triage
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
golang
Amazon Linux 2
0:1.26.7-1.amzn2.0.1
fixed
Amazon Linux 2023
0:1.26.7-1.amzn2023.0.1
fixed
golang-bin
Amazon Linux 2
0:1.26.7-1.amzn2.0.1
fixed
Amazon Linux 2023
0:1.26.7-1.amzn2023.0.1
fixed
golang-docs
Amazon Linux 2
0:1.26.7-1.amzn2.0.1
fixed
Amazon Linux 2023
0:1.26.7-1.amzn2023.0.1
fixed
golang-misc
Amazon Linux 2
0:1.26.7-1.amzn2.0.1
fixed
Amazon Linux 2023
0:1.26.7-1.amzn2023.0.1
fixed
golang-shared
Amazon Linux 2
0:1.26.7-1.amzn2.0.1
fixed
Amazon Linux 2023
0:1.26.7-1.amzn2023.0.1
fixed
golang-src
Amazon Linux 2
0:1.26.7-1.amzn2.0.1
fixed
Amazon Linux 2023
0:1.26.7-1.amzn2023.0.1
fixed
golang-tests
Amazon Linux 2
0:1.26.7-1.amzn2.0.1
fixed
Amazon Linux 2023
0:1.26.7-1.amzn2023.0.1
fixed
Azure Linux logo
Azure Linux Releases
Azure Package
Release
golang
Azure Linux 3.0
0:1.26.6-1.azl3
fixed