PT-2026-108317 · Google · Go
CVE-2026-94444
·
Published
2026-10-08
·
Updated
2026-10-08
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions
Go (affected versions not specified)
Description
A flaw exists where a user working within a malicious project that defines a fake
golang.org/fips140 module and utilizes a malicious GOMODPROXY could be served an arbitrary module in place of the legitimate one. This occurs because the toolchain previously lacked a mechanism to ensure the integrity of the bundled golang.org/fips140 module within the GOMODCACHE (the local cache where Go stores downloaded modules).Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Go