Vulnerability GO-2026-6601
Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
8 hours ago
October 08, 2026 at 10:31 PM UTC
Checksum bypass for golang.org/fips140 in cmd/go
<1.26.9
<1.26.9
Summary
Checksum bypass for golang.org/fips140 in cmd/go
Details
Previously, a user operating inside of a malicious Go project that defines a bogus golang.org/fips140 and operates a malicious GOMODPROXY the user chooses to connect to can serve an arbitrary module in its place.
We now unpack the trusted ziphash for the bundled golang.org/fips140 module and construct its entry in the GOMODCACHE such that it can be verified by the toolchain.
References
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Unknown
8 hours ago
Checksum database bypass for golang.org/toolchain in cmd/go
<1.26.9 GO-2026-6602
<1.26.9 GO-2026-6602
Unknown
1 month ago
Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
<1.25.13 GO-2026-6179
<1.25.13 GO-2026-6179
Unknown
1 month ago
Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
<1.25.13 GO-2026-6180
<1.25.13 GO-2026-6180
Unknown
5 months ago
Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
<1.25.10 GO-2026-4978
<1.25.10 GO-2026-4978
Unknown
5 months ago
Invoking "go tool pack" does not sanitize output paths in cmd/go
<1.25.10 GO-2026-4979
<1.25.10 GO-2026-4979
Impacted packages
Timeline
Published
8 hours ago
October 08, 2026 at 10:31 PM UTC
Last Modified
8 hours ago
October 08, 2026 at 11:00 PM UTC