Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-56864

Опубликовано: 13 авг. 2026
Источник: debian

Описание

A malicious GOSUMDB was capable of serving arbitrary module content not contained within the transparency log. This attack allows for a coordinating GOPROXY and GOSUMDB to serve a client malicious module content that cannot be detected by evaluating the transparency log. In order to determine if you have been affected: rm -r go.sum go.work.sum vendor/ && go mod tidy

Пакеты

ПакетСтатусВерсия исправленияРелизТип
golang-1.27fixed1.27~rc3-1package
golang-1.26fixed1.26.6-1package
golang-1.25fixed1.25.13-1package
golang-1.24removedpackage
golang-1.24no-dsatrixiepackage
golang-1.19removedpackage
golang-1.15removedpackage

Примечания

  • https://github.com/golang/go/issues/80745

  • Fixed by: https://github.com/golang/go/commit/a3876703796b5d3db7a7c6f2193e8663399f2339 (go1.27rc3)

  • Fixed by: https://github.com/golang/go/commit/9f6980fd5c03840b0f6764e8ec7c705b90989eee (go1.26.6)

  • Fixed by: https://github.com/golang/go/commit/22e01669cdcabb9cfad02e0c2bffbce8198f6bfb (go1.25.13)

Связанные уязвимости

CVSS3: 7.5
ubuntu
23 дня назад

(A malicious GOSUMDB was capable of serving arbitrary module content no ...)

CVSS3: 7.5
nvd
23 дня назад

A malicious GOSUMDB was capable of serving arbitrary module content not contained within the transparency log. This attack allows for a coordinating GOPROXY and GOSUMDB to serve a client malicious module content that cannot be detected by evaluating the transparency log. In order to determine if you have been affected: rm -r go.sum go.work.sum vendor/ && go mod tidy