Vulnerability GO-2026-6180
Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
1 month ago
August 13, 2026 at 09:43 PM UTC
Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
v0.1.0 - v0.39.0
v0.1.0 - v0.39.0
Summary
Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Details
A malicious GOSUMDB was capable of serving arbitrary module content not contained within the transparency log.
This attack allows for a coordinating GOPROXY and GOSUMDB to serve a client malicious module content that cannot be detected by evaluating the transparency log.
In order to determine if you have been affected:
rm -r go.sum go.work.sum vendor/ && go mod tidy
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Unknown
9 hours ago
Checksum bypass for golang.org/fips140 in cmd/go
<1.26.9 GO-2026-6601
<1.26.9 GO-2026-6601
Unknown
9 hours ago
Checksum database bypass for golang.org/toolchain in cmd/go
<1.26.9 GO-2026-6602
<1.26.9 GO-2026-6602
Unknown
1 month ago
Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
<0.40.0 GO-2026-6179
<0.40.0 GO-2026-6179
Unknown
1 month ago
Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
<1.25.13 GO-2026-6179
<1.25.13 GO-2026-6179
Unknown
5 months ago
Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
<1.25.10 GO-2026-4978
<1.25.10 GO-2026-4978
Impacted packages
Timeline
Published
1 month ago
August 13, 2026 at 09:43 PM UTC
Last Modified
1 month ago
August 19, 2026 at 12:25 PM UTC