PT-2026-71900 · Google · Go

·

CVE-2026-56864

·

Published

2026-08-13

·

Updated

2026-09-04

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Go (affected versions not specified)
Description A malicious GOSUMDB can serve arbitrary module content that is not present in the transparency log. This allows a coordinating GOPROXY and GOSUMDB to deliver malicious module content to a client, which cannot be detected by evaluating the transparency log.
Recommendations To determine if the system has been affected, execute the following command: rm -r go.sum go.work.sum vendor/ && go mod tidy.

Fix

Improper Verification of Cryptographic Signature

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-96659
AZL-96671
AZL-98577
BIT-GOLANG-2026-56864
CVE-2026-56864
GO-2026-6180
OPENSUSE-SU-2026:11516-1
OPENSUSE-SU-2026:11517-1
OPENSUSE-SU-2026:11536-1
OPENSUSE-SU-2026:11575-1
OPENSUSE-SU-2026:21592-1
OPENSUSE-SU-2026:21593-1
OPENSUSE-SU-2026:21696-1
OPENSUSE-SU-2026:21705-1
OPENSUSE-SU-2026:21761-1
SUSE-SU-2026:23300-1
SUSE-SU-2026:23301-1
SUSE-SU-2026:3640-1
SUSE-SU-2026:3641-1
SUSE-SU-2026:3799-1
SUSE-SU-2026:3800-1
SUSE-SU-2026:3815-1
SUSE-SU-2026:3816-1
SUSE-SU-2026:3830-1

Affected Products

Go