Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 20

Количество 20

fstec логотип

BDU:2026-08061

3 месяца назад

Уязвимость модулей GOMODPROXY и GOSUMDB языка программирования Go, позволяющая нарушителю обойти ограничения безопасности и получить доступ на чтение и изменение данных

CVSS3: 7.5
EPSS: Низкий
redos логотип

ROS-20260622-73-0031

около 1 месяца назад

Уязвимость golang

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2026-42501

3 месяца назад

A malicious module proxy can exploit a flaw in the go command's validation of module checksums to bypass checksum database validation. This vulnerability affects any user using an untrusted module proxy (GOMODPROXY) or checksum database (GOSUMDB). A malicious module proxy can serve altered versions of the Go toolchain. When selecting a different version of the Go toolchain than the currently installed toolchain (due to the GOTOOLCHAIN environment variable, or a go.work or go.mod with a toolchain line), the go command will download and execute a toolchain provided by the module proxy. A malicious module proxy can bypass checksum database validation for this downloaded toolchain. Since this vulnerability affects the security of toolchain downloads, setting GOTOOLCHAIN to a fixed version is not sufficient. You must upgrade your base Go toolchain. The go tool always validates the hash of a toolchain before executing it, so fixed versions will refuse to execute any cached, altered versio...

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-42501

3 месяца назад

A malicious module proxy can exploit a flaw in the go command's validation of module checksums to bypass checksum database validation. This vulnerability affects any user using an untrusted module proxy (GOMODPROXY) or checksum database (GOSUMDB). A malicious module proxy can serve altered versions of the Go toolchain. When selecting a different version of the Go toolchain than the currently installed toolchain (due to the GOTOOLCHAIN environment variable, or a go.work or go.mod with a toolchain line), the go command will download and execute a toolchain provided by the module proxy. A malicious module proxy can bypass checksum database validation for this downloaded toolchain. Since this vulnerability affects the security of toolchain downloads, setting GOTOOLCHAIN to a fixed version is not sufficient. You must upgrade your base Go toolchain. The go tool always validates the hash of a toolchain before executing it, so fixed versions will refuse to execute any cached, altered versions

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2026-42501

3 месяца назад

Malicious module proxy can bypass checksum database in cmd/go

EPSS: Низкий
debian логотип

CVE-2026-42501

3 месяца назад

A malicious module proxy can exploit a flaw in the go command's valida ...

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-qf3q-3h68-mmh2

3 месяца назад

A malicious module proxy can exploit a flaw in the go command's validation of module checksums to bypass checksum database validation. This vulnerability affects any user using an untrusted module proxy (GOMODPROXY) or checksum database (GOSUMDB). A malicious module proxy can serve altered versions of the Go toolchain. When selecting a different version of the Go toolchain than the currently installed toolchain (due to the GOTOOLCHAIN environment variable, or a go.work or go.mod with a toolchain line), the go command will download and execute a toolchain provided by the module proxy. A malicious module proxy can bypass checksum database validation for this downloaded toolchain. Since this vulnerability affects the security of toolchain downloads, setting GOTOOLCHAIN to a fixed version is not sufficient. You must upgrade your base Go toolchain. The go tool always validates the hash of a toolchain before executing it, so fixed versions will refuse to execute any cached, altered versio...

CVSS3: 7.5
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20763-1

2 месяца назад

Security update for go1.25

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20762-1

2 месяца назад

Security update for go1.26

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2093-1

2 месяца назад

Security update for go1.25-openssl

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2092-1

2 месяца назад

Security update for go1.26-openssl

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2079-1

2 месяца назад

Security update for go1.25-openssl

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2078-1

2 месяца назад

Security update for go1.26-openssl

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:1862-1

3 месяца назад

Security update for go1.25

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:1861-1

3 месяца назад

Security update for go1.26

EPSS: Низкий
oracle-oval логотип

ELSA-2026-22121

около 1 месяца назад

ELSA-2026-22121: golang security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-22120

10 дней назад

ELSA-2026-22120: golang security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-22112

около 2 месяцев назад

ELSA-2026-22112: go-toolset:ol8 security update (IMPORTANT)

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21254-1

24 дня назад

Security update for go1.26-openssl

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21319-1

18 дней назад

Security update for go1.25-openssl

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2026-08061

Уязвимость модулей GOMODPROXY и GOSUMDB языка программирования Go, позволяющая нарушителю обойти ограничения безопасности и получить доступ на чтение и изменение данных

CVSS3: 7.5
0%
Низкий
3 месяца назад
redos логотип
ROS-20260622-73-0031

Уязвимость golang

CVSS3: 7.5
0%
Низкий
около 1 месяца назад
ubuntu логотип
CVE-2026-42501

A malicious module proxy can exploit a flaw in the go command's validation of module checksums to bypass checksum database validation. This vulnerability affects any user using an untrusted module proxy (GOMODPROXY) or checksum database (GOSUMDB). A malicious module proxy can serve altered versions of the Go toolchain. When selecting a different version of the Go toolchain than the currently installed toolchain (due to the GOTOOLCHAIN environment variable, or a go.work or go.mod with a toolchain line), the go command will download and execute a toolchain provided by the module proxy. A malicious module proxy can bypass checksum database validation for this downloaded toolchain. Since this vulnerability affects the security of toolchain downloads, setting GOTOOLCHAIN to a fixed version is not sufficient. You must upgrade your base Go toolchain. The go tool always validates the hash of a toolchain before executing it, so fixed versions will refuse to execute any cached, altered versio...

CVSS3: 7.5
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-42501

A malicious module proxy can exploit a flaw in the go command's validation of module checksums to bypass checksum database validation. This vulnerability affects any user using an untrusted module proxy (GOMODPROXY) or checksum database (GOSUMDB). A malicious module proxy can serve altered versions of the Go toolchain. When selecting a different version of the Go toolchain than the currently installed toolchain (due to the GOTOOLCHAIN environment variable, or a go.work or go.mod with a toolchain line), the go command will download and execute a toolchain provided by the module proxy. A malicious module proxy can bypass checksum database validation for this downloaded toolchain. Since this vulnerability affects the security of toolchain downloads, setting GOTOOLCHAIN to a fixed version is not sufficient. You must upgrade your base Go toolchain. The go tool always validates the hash of a toolchain before executing it, so fixed versions will refuse to execute any cached, altered versions

CVSS3: 7.5
0%
Низкий
3 месяца назад
msrc логотип
CVE-2026-42501

Malicious module proxy can bypass checksum database in cmd/go

0%
Низкий
3 месяца назад
debian логотип
CVE-2026-42501

A malicious module proxy can exploit a flaw in the go command's valida ...

CVSS3: 7.5
0%
Низкий
3 месяца назад
github логотип
GHSA-qf3q-3h68-mmh2

A malicious module proxy can exploit a flaw in the go command's validation of module checksums to bypass checksum database validation. This vulnerability affects any user using an untrusted module proxy (GOMODPROXY) or checksum database (GOSUMDB). A malicious module proxy can serve altered versions of the Go toolchain. When selecting a different version of the Go toolchain than the currently installed toolchain (due to the GOTOOLCHAIN environment variable, or a go.work or go.mod with a toolchain line), the go command will download and execute a toolchain provided by the module proxy. A malicious module proxy can bypass checksum database validation for this downloaded toolchain. Since this vulnerability affects the security of toolchain downloads, setting GOTOOLCHAIN to a fixed version is not sufficient. You must upgrade your base Go toolchain. The go tool always validates the hash of a toolchain before executing it, so fixed versions will refuse to execute any cached, altered versio...

CVSS3: 7.5
0%
Низкий
3 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:20763-1

Security update for go1.25

2 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:20762-1

Security update for go1.26

2 месяца назад
suse-cvrf логотип
SUSE-SU-2026:2093-1

Security update for go1.25-openssl

2 месяца назад
suse-cvrf логотип
SUSE-SU-2026:2092-1

Security update for go1.26-openssl

2 месяца назад
suse-cvrf логотип
SUSE-SU-2026:2079-1

Security update for go1.25-openssl

2 месяца назад
suse-cvrf логотип
SUSE-SU-2026:2078-1

Security update for go1.26-openssl

2 месяца назад
suse-cvrf логотип
SUSE-SU-2026:1862-1

Security update for go1.25

3 месяца назад
suse-cvrf логотип
SUSE-SU-2026:1861-1

Security update for go1.26

3 месяца назад
oracle-oval логотип
ELSA-2026-22121

ELSA-2026-22121: golang security update (IMPORTANT)

около 1 месяца назад
oracle-oval логотип
ELSA-2026-22120

ELSA-2026-22120: golang security update (IMPORTANT)

10 дней назад
oracle-oval логотип
ELSA-2026-22112

ELSA-2026-22112: go-toolset:ol8 security update (IMPORTANT)

около 2 месяцев назад
suse-cvrf логотип
openSUSE-SU-2026:21254-1

Security update for go1.26-openssl

24 дня назад
suse-cvrf логотип
openSUSE-SU-2026:21319-1

Security update for go1.25-openssl

18 дней назад

Уязвимостей на страницу