CVE-2026-94447
EUVD-2026-9541808.10.2026, 23:17
Previously, a user operating inside of a malicious Go project that defines a bogus golang.org/toolchain go.sum entry and operates a malicious GOMODPROXY the user chooses to use can bypass the intended checksum. We now ensure that golang.org/toolchain always goes to the network for the canonical checksum.Enginsight
Awaiting analysis
This vulnerability is currently awaiting analysis.
Debian Releases
Vulnerability Media Exposure