CVE-2026-94444
EUVD-2026-9541708.10.2026, 23:17
Previously, a user operating inside of a malicious Go project that defines a bogus golang.org/fips140 and operates a malicious GOMODPROXY the user chooses to connect to can serve an arbitrary module in its place. We now unpack the trusted ziphash for the bundled golang.org/fips140 module and construct its entry in the GOMODCACHE such that it can be verified by the toolchain.Enginsight
Awaiting analysis
This vulnerability is currently awaiting analysis.
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| golang |
| ||||||||||||
| golang-1.6 |
| ||||||||||||
| golang-1.8 |
| ||||||||||||
| golang-1.9 |
| ||||||||||||
| golang-1.10 |
| ||||||||||||
| golang-1.13 |
| ||||||||||||
| golang-1.14 |
| ||||||||||||
| golang-1.16 |
| ||||||||||||
| golang-1.17 |
| ||||||||||||
| golang-1.18 |
| ||||||||||||
| golang-1.20 |
| ||||||||||||
| golang-1.21 |
| ||||||||||||
| golang-1.22 |
| ||||||||||||
| golang-1.23 |
| ||||||||||||
| golang-1.24 |
| ||||||||||||
| golang-1.25 |
| ||||||||||||
| golang-1.26 |
| ||||||||||||
| golang-1.27 |
|
Vulnerability Media Exposure