Количество 25
Количество 25
BDU:2026-08061
Уязвимость модулей GOMODPROXY и GOSUMDB языка программирования Go, позволяющая нарушителю обойти ограничения безопасности и получить доступ на чтение и изменение данных
ROS-20260622-80-0037
Уязвимость golang
ROS-20260622-73-0031
Уязвимость golang
CVE-2026-42501
A malicious module proxy can exploit a flaw in the go command's validation of module checksums to bypass checksum database validation. This vulnerability affects any user using an untrusted module proxy (GOMODPROXY) or checksum database (GOSUMDB). A malicious module proxy can serve altered versions of the Go toolchain. When selecting a different version of the Go toolchain than the currently installed toolchain (due to the GOTOOLCHAIN environment variable, or a go.work or go.mod with a toolchain line), the go command will download and execute a toolchain provided by the module proxy. A malicious module proxy can bypass checksum database validation for this downloaded toolchain. Since this vulnerability affects the security of toolchain downloads, setting GOTOOLCHAIN to a fixed version is not sufficient. You must upgrade your base Go toolchain. The go tool always validates the hash of a toolchain before executing it, so fixed versions will refuse to execute any cached, altered versio...
CVE-2026-42501
A malicious module proxy can exploit a flaw in the go command's validation of module checksums to bypass checksum database validation. This vulnerability affects any user using an untrusted module proxy (GOMODPROXY) or checksum database (GOSUMDB). A malicious module proxy can serve altered versions of the Go toolchain. When selecting a different version of the Go toolchain than the currently installed toolchain (due to the GOTOOLCHAIN environment variable, or a go.work or go.mod with a toolchain line), the go command will download and execute a toolchain provided by the module proxy. A malicious module proxy can bypass checksum database validation for this downloaded toolchain. Since this vulnerability affects the security of toolchain downloads, setting GOTOOLCHAIN to a fixed version is not sufficient. You must upgrade your base Go toolchain. The go tool always validates the hash of a toolchain before executing it, so fixed versions will refuse to execute any cached, altered versio...
CVE-2026-42501
A malicious module proxy can exploit a flaw in the go command's validation of module checksums to bypass checksum database validation. This vulnerability affects any user using an untrusted module proxy (GOMODPROXY) or checksum database (GOSUMDB). A malicious module proxy can serve altered versions of the Go toolchain. When selecting a different version of the Go toolchain than the currently installed toolchain (due to the GOTOOLCHAIN environment variable, or a go.work or go.mod with a toolchain line), the go command will download and execute a toolchain provided by the module proxy. A malicious module proxy can bypass checksum database validation for this downloaded toolchain. Since this vulnerability affects the security of toolchain downloads, setting GOTOOLCHAIN to a fixed version is not sufficient. You must upgrade your base Go toolchain. The go tool always validates the hash of a toolchain before executing it, so fixed versions will refuse to execute any cached, altered versions
CVE-2026-42501
Malicious module proxy can bypass checksum database in cmd/go
CVE-2026-42501
A malicious module proxy can exploit a flaw in the go command's valida ...
GHSA-qf3q-3h68-mmh2
A malicious module proxy can exploit a flaw in the go command's validation of module checksums to bypass checksum database validation. This vulnerability affects any user using an untrusted module proxy (GOMODPROXY) or checksum database (GOSUMDB). A malicious module proxy can serve altered versions of the Go toolchain. When selecting a different version of the Go toolchain than the currently installed toolchain (due to the GOTOOLCHAIN environment variable, or a go.work or go.mod with a toolchain line), the go command will download and execute a toolchain provided by the module proxy. A malicious module proxy can bypass checksum database validation for this downloaded toolchain. Since this vulnerability affects the security of toolchain downloads, setting GOTOOLCHAIN to a fixed version is not sufficient. You must upgrade your base Go toolchain. The go tool always validates the hash of a toolchain before executing it, so fixed versions will refuse to execute any cached, altered versio...
openSUSE-SU-2026:20763-1
Security update for go1.25
openSUSE-SU-2026:20762-1
Security update for go1.26
SUSE-SU-2026:2093-1
Security update for go1.25-openssl
SUSE-SU-2026:2092-1
Security update for go1.26-openssl
SUSE-SU-2026:2079-1
Security update for go1.25-openssl
SUSE-SU-2026:2078-1
Security update for go1.26-openssl
SUSE-SU-2026:1862-1
Security update for go1.25
SUSE-SU-2026:1861-1
Security update for go1.26
RLSA-2026:22121
Important: golang security update
RLSA-2026:22120
Important: golang security update
RLSA-2026:22112
Important: go-toolset:rhel8 security update
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
BDU:2026-08061 Уязвимость модулей GOMODPROXY и GOSUMDB языка программирования Go, позволяющая нарушителю обойти ограничения безопасности и получить доступ на чтение и изменение данных | CVSS3: 7.5 | 0% Низкий | 5 месяцев назад | |
ROS-20260622-80-0037 Уязвимость golang | CVSS3: 7.5 | 0% Низкий | 3 месяца назад | |
ROS-20260622-73-0031 Уязвимость golang | CVSS3: 7.5 | 0% Низкий | 3 месяца назад | |
CVE-2026-42501 A malicious module proxy can exploit a flaw in the go command's validation of module checksums to bypass checksum database validation. This vulnerability affects any user using an untrusted module proxy (GOMODPROXY) or checksum database (GOSUMDB). A malicious module proxy can serve altered versions of the Go toolchain. When selecting a different version of the Go toolchain than the currently installed toolchain (due to the GOTOOLCHAIN environment variable, or a go.work or go.mod with a toolchain line), the go command will download and execute a toolchain provided by the module proxy. A malicious module proxy can bypass checksum database validation for this downloaded toolchain. Since this vulnerability affects the security of toolchain downloads, setting GOTOOLCHAIN to a fixed version is not sufficient. You must upgrade your base Go toolchain. The go tool always validates the hash of a toolchain before executing it, so fixed versions will refuse to execute any cached, altered versio... | CVSS3: 7.5 | 0% Низкий | 4 месяца назад | |
CVE-2026-42501 A malicious module proxy can exploit a flaw in the go command's validation of module checksums to bypass checksum database validation. This vulnerability affects any user using an untrusted module proxy (GOMODPROXY) or checksum database (GOSUMDB). A malicious module proxy can serve altered versions of the Go toolchain. When selecting a different version of the Go toolchain than the currently installed toolchain (due to the GOTOOLCHAIN environment variable, or a go.work or go.mod with a toolchain line), the go command will download and execute a toolchain provided by the module proxy. A malicious module proxy can bypass checksum database validation for this downloaded toolchain. Since this vulnerability affects the security of toolchain downloads, setting GOTOOLCHAIN to a fixed version is not sufficient. You must upgrade your base Go toolchain. The go tool always validates the hash of a toolchain before executing it, so fixed versions will refuse to execute any cached, altered versio... | CVSS3: 5.3 | 0% Низкий | 4 месяца назад | |
CVE-2026-42501 A malicious module proxy can exploit a flaw in the go command's validation of module checksums to bypass checksum database validation. This vulnerability affects any user using an untrusted module proxy (GOMODPROXY) or checksum database (GOSUMDB). A malicious module proxy can serve altered versions of the Go toolchain. When selecting a different version of the Go toolchain than the currently installed toolchain (due to the GOTOOLCHAIN environment variable, or a go.work or go.mod with a toolchain line), the go command will download and execute a toolchain provided by the module proxy. A malicious module proxy can bypass checksum database validation for this downloaded toolchain. Since this vulnerability affects the security of toolchain downloads, setting GOTOOLCHAIN to a fixed version is not sufficient. You must upgrade your base Go toolchain. The go tool always validates the hash of a toolchain before executing it, so fixed versions will refuse to execute any cached, altered versions | CVSS3: 7.5 | 0% Низкий | 4 месяца назад | |
CVE-2026-42501 Malicious module proxy can bypass checksum database in cmd/go | 0% Низкий | 4 месяца назад | ||
CVE-2026-42501 A malicious module proxy can exploit a flaw in the go command's valida ... | CVSS3: 7.5 | 0% Низкий | 4 месяца назад | |
GHSA-qf3q-3h68-mmh2 A malicious module proxy can exploit a flaw in the go command's validation of module checksums to bypass checksum database validation. This vulnerability affects any user using an untrusted module proxy (GOMODPROXY) or checksum database (GOSUMDB). A malicious module proxy can serve altered versions of the Go toolchain. When selecting a different version of the Go toolchain than the currently installed toolchain (due to the GOTOOLCHAIN environment variable, or a go.work or go.mod with a toolchain line), the go command will download and execute a toolchain provided by the module proxy. A malicious module proxy can bypass checksum database validation for this downloaded toolchain. Since this vulnerability affects the security of toolchain downloads, setting GOTOOLCHAIN to a fixed version is not sufficient. You must upgrade your base Go toolchain. The go tool always validates the hash of a toolchain before executing it, so fixed versions will refuse to execute any cached, altered versio... | CVSS3: 7.5 | 0% Низкий | 4 месяца назад | |
openSUSE-SU-2026:20763-1 Security update for go1.25 | 4 месяца назад | |||
openSUSE-SU-2026:20762-1 Security update for go1.26 | 4 месяца назад | |||
SUSE-SU-2026:2093-1 Security update for go1.25-openssl | 4 месяца назад | |||
SUSE-SU-2026:2092-1 Security update for go1.26-openssl | 4 месяца назад | |||
SUSE-SU-2026:2079-1 Security update for go1.25-openssl | 4 месяца назад | |||
SUSE-SU-2026:2078-1 Security update for go1.26-openssl | 4 месяца назад | |||
SUSE-SU-2026:1862-1 Security update for go1.25 | 4 месяца назад | |||
SUSE-SU-2026:1861-1 Security update for go1.26 | 4 месяца назад | |||
RLSA-2026:22121 Important: golang security update | 20 дней назад | |||
RLSA-2026:22120 Important: golang security update | 20 дней назад | |||
RLSA-2026:22112 Important: go-toolset:rhel8 security update | 20 дней назад |
Уязвимостей на страницу