Vulnerability GO-2026-6601

Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
8 hours ago
October 08, 2026 at 10:31 PM UTC
Checksum bypass for golang.org/fips140 in cmd/go
<1.26.9
<1.26.9

Summary

Checksum bypass for golang.org/fips140 in cmd/go

Details

Previously, a user operating inside of a malicious Go project that defines a bogus golang.org/fips140 and operates a malicious GOMODPROXY the user chooses to connect to can serve an arbitrary module in its place.

We now unpack the trusted ziphash for the bundled golang.org/fips140 module and construct its entry in the GOMODCACHE such that it can be verified by the toolchain.

Impacted packages

Timeline

Published
8 hours ago
October 08, 2026 at 10:31 PM UTC
Last Modified
8 hours ago
October 08, 2026 at 11:00 PM UTC