PT-2026-71901 · Google · Go

·

CVE-2026-56865

·

Published

2026-08-13

·

Updated

2026-09-04

CVSS v3.1

8.4

High

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Go (affected versions not specified)
Description A malicious GOPROXY could forge up to two sumdb tiles, enabling a requested module to bypass the GOSUMDB check. This allows attacker-controlled module content to persist in a local Go module cache, which cannot be detected by evaluating the transparency log (a public, append-only record used to verify the integrity of modules).
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. Run the command rm -r go.sum go.work.sum vendor/ && go mod tidy to determine if the system has been affected.

Improper Verification of Cryptographic Signature

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-96647
AZL-96683
AZL-98721
BIT-GOLANG-2026-56865
CVE-2026-56865
GO-2026-6179
OPENSUSE-SU-2026:11516-1
OPENSUSE-SU-2026:11517-1
OPENSUSE-SU-2026:11536-1
OPENSUSE-SU-2026:11575-1
OPENSUSE-SU-2026:21592-1
OPENSUSE-SU-2026:21593-1
OPENSUSE-SU-2026:21696-1
OPENSUSE-SU-2026:21705-1
OPENSUSE-SU-2026:21761-1
SUSE-SU-2026:23300-1
SUSE-SU-2026:23301-1
SUSE-SU-2026:3640-1
SUSE-SU-2026:3641-1
SUSE-SU-2026:3799-1
SUSE-SU-2026:3800-1
SUSE-SU-2026:3815-1
SUSE-SU-2026:3816-1
SUSE-SU-2026:3830-1

Affected Products

Go