PT-2026-108317 · Google · Go

CVE-2026-94444

·

Published

2026-10-08

·

Updated

2026-10-08

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions Go (affected versions not specified)
Description A flaw exists where a user working within a malicious project that defines a fake golang.org/fips140 module and utilizes a malicious GOMODPROXY could be served an arbitrary module in place of the legitimate one. This occurs because the toolchain previously lacked a mechanism to ensure the integrity of the bundled golang.org/fips140 module within the GOMODCACHE (the local cache where Go stores downloaded modules).
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-94444
GO-2026-6601

Affected Products

Go