Vulnerability GO-2026-6180

Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
1 month ago
August 13, 2026 at 09:43 PM UTC
Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
v0.1.0 - v0.39.0
v0.1.0 - v0.39.0

Summary

Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb

Details

A malicious GOSUMDB was capable of serving arbitrary module content not contained within the transparency log.

This attack allows for a coordinating GOPROXY and GOSUMDB to serve a client malicious module content that cannot be detected by evaluating the transparency log.

In order to determine if you have been affected:

rm -r go.sum go.work.sum vendor/ && go mod tidy

Timeline

Published
1 month ago
August 13, 2026 at 09:43 PM UTC
Last Modified
1 month ago
August 19, 2026 at 12:25 PM UTC