Количество 20
Количество 20
GHSA-qf3q-3h68-mmh2
A malicious module proxy can exploit a flaw in the go command's validation of module checksums to bypass checksum database validation. This vulnerability affects any user using an untrusted module proxy (GOMODPROXY) or checksum database (GOSUMDB). A malicious module proxy can serve altered versions of the Go toolchain. When selecting a different version of the Go toolchain than the currently installed toolchain (due to the GOTOOLCHAIN environment variable, or a go.work or go.mod with a toolchain line), the go command will download and execute a toolchain provided by the module proxy. A malicious module proxy can bypass checksum database validation for this downloaded toolchain. Since this vulnerability affects the security of toolchain downloads, setting GOTOOLCHAIN to a fixed version is not sufficient. You must upgrade your base Go toolchain. The go tool always validates the hash of a toolchain before executing it, so fixed versions will refuse to execute any cached, altered versio...
CVE-2026-42501
A malicious module proxy can exploit a flaw in the go command's validation of module checksums to bypass checksum database validation. This vulnerability affects any user using an untrusted module proxy (GOMODPROXY) or checksum database (GOSUMDB). A malicious module proxy can serve altered versions of the Go toolchain. When selecting a different version of the Go toolchain than the currently installed toolchain (due to the GOTOOLCHAIN environment variable, or a go.work or go.mod with a toolchain line), the go command will download and execute a toolchain provided by the module proxy. A malicious module proxy can bypass checksum database validation for this downloaded toolchain. Since this vulnerability affects the security of toolchain downloads, setting GOTOOLCHAIN to a fixed version is not sufficient. You must upgrade your base Go toolchain. The go tool always validates the hash of a toolchain before executing it, so fixed versions will refuse to execute any cached, altered versio...
CVE-2026-42501
A malicious module proxy can exploit a flaw in the go command's validation of module checksums to bypass checksum database validation. This vulnerability affects any user using an untrusted module proxy (GOMODPROXY) or checksum database (GOSUMDB). A malicious module proxy can serve altered versions of the Go toolchain. When selecting a different version of the Go toolchain than the currently installed toolchain (due to the GOTOOLCHAIN environment variable, or a go.work or go.mod with a toolchain line), the go command will download and execute a toolchain provided by the module proxy. A malicious module proxy can bypass checksum database validation for this downloaded toolchain. Since this vulnerability affects the security of toolchain downloads, setting GOTOOLCHAIN to a fixed version is not sufficient. You must upgrade your base Go toolchain. The go tool always validates the hash of a toolchain before executing it, so fixed versions will refuse to execute any cached, altered versions
CVE-2026-42501
Malicious module proxy can bypass checksum database in cmd/go
CVE-2026-42501
A malicious module proxy can exploit a flaw in the go command's valida ...
BDU:2026-08061
Уязвимость модулей GOMODPROXY и GOSUMDB языка программирования Go, позволяющая нарушителю обойти ограничения безопасности и получить доступ на чтение и изменение данных
ROS-20260622-73-0031
Уязвимость golang
openSUSE-SU-2026:20763-1
Security update for go1.25
openSUSE-SU-2026:20762-1
Security update for go1.26
SUSE-SU-2026:2093-1
Security update for go1.25-openssl
SUSE-SU-2026:2092-1
Security update for go1.26-openssl
SUSE-SU-2026:2079-1
Security update for go1.25-openssl
SUSE-SU-2026:2078-1
Security update for go1.26-openssl
SUSE-SU-2026:1862-1
Security update for go1.25
SUSE-SU-2026:1861-1
Security update for go1.26
ELSA-2026-22121
ELSA-2026-22121: golang security update (IMPORTANT)
ELSA-2026-22120
ELSA-2026-22120: golang security update (IMPORTANT)
ELSA-2026-22112
ELSA-2026-22112: go-toolset:ol8 security update (IMPORTANT)
openSUSE-SU-2026:21254-1
Security update for go1.26-openssl
openSUSE-SU-2026:21319-1
Security update for go1.25-openssl
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-qf3q-3h68-mmh2 A malicious module proxy can exploit a flaw in the go command's validation of module checksums to bypass checksum database validation. This vulnerability affects any user using an untrusted module proxy (GOMODPROXY) or checksum database (GOSUMDB). A malicious module proxy can serve altered versions of the Go toolchain. When selecting a different version of the Go toolchain than the currently installed toolchain (due to the GOTOOLCHAIN environment variable, or a go.work or go.mod with a toolchain line), the go command will download and execute a toolchain provided by the module proxy. A malicious module proxy can bypass checksum database validation for this downloaded toolchain. Since this vulnerability affects the security of toolchain downloads, setting GOTOOLCHAIN to a fixed version is not sufficient. You must upgrade your base Go toolchain. The go tool always validates the hash of a toolchain before executing it, so fixed versions will refuse to execute any cached, altered versio... | CVSS3: 7.5 | 0% Низкий | 3 месяца назад | |
CVE-2026-42501 A malicious module proxy can exploit a flaw in the go command's validation of module checksums to bypass checksum database validation. This vulnerability affects any user using an untrusted module proxy (GOMODPROXY) or checksum database (GOSUMDB). A malicious module proxy can serve altered versions of the Go toolchain. When selecting a different version of the Go toolchain than the currently installed toolchain (due to the GOTOOLCHAIN environment variable, or a go.work or go.mod with a toolchain line), the go command will download and execute a toolchain provided by the module proxy. A malicious module proxy can bypass checksum database validation for this downloaded toolchain. Since this vulnerability affects the security of toolchain downloads, setting GOTOOLCHAIN to a fixed version is not sufficient. You must upgrade your base Go toolchain. The go tool always validates the hash of a toolchain before executing it, so fixed versions will refuse to execute any cached, altered versio... | CVSS3: 7.5 | 0% Низкий | 3 месяца назад | |
CVE-2026-42501 A malicious module proxy can exploit a flaw in the go command's validation of module checksums to bypass checksum database validation. This vulnerability affects any user using an untrusted module proxy (GOMODPROXY) or checksum database (GOSUMDB). A malicious module proxy can serve altered versions of the Go toolchain. When selecting a different version of the Go toolchain than the currently installed toolchain (due to the GOTOOLCHAIN environment variable, or a go.work or go.mod with a toolchain line), the go command will download and execute a toolchain provided by the module proxy. A malicious module proxy can bypass checksum database validation for this downloaded toolchain. Since this vulnerability affects the security of toolchain downloads, setting GOTOOLCHAIN to a fixed version is not sufficient. You must upgrade your base Go toolchain. The go tool always validates the hash of a toolchain before executing it, so fixed versions will refuse to execute any cached, altered versions | CVSS3: 7.5 | 0% Низкий | 3 месяца назад | |
CVE-2026-42501 Malicious module proxy can bypass checksum database in cmd/go | 0% Низкий | 3 месяца назад | ||
CVE-2026-42501 A malicious module proxy can exploit a flaw in the go command's valida ... | CVSS3: 7.5 | 0% Низкий | 3 месяца назад | |
BDU:2026-08061 Уязвимость модулей GOMODPROXY и GOSUMDB языка программирования Go, позволяющая нарушителю обойти ограничения безопасности и получить доступ на чтение и изменение данных | CVSS3: 7.5 | 0% Низкий | 3 месяца назад | |
ROS-20260622-73-0031 Уязвимость golang | CVSS3: 7.5 | 0% Низкий | около 1 месяца назад | |
openSUSE-SU-2026:20763-1 Security update for go1.25 | 2 месяца назад | |||
openSUSE-SU-2026:20762-1 Security update for go1.26 | 2 месяца назад | |||
SUSE-SU-2026:2093-1 Security update for go1.25-openssl | 2 месяца назад | |||
SUSE-SU-2026:2092-1 Security update for go1.26-openssl | 2 месяца назад | |||
SUSE-SU-2026:2079-1 Security update for go1.25-openssl | 2 месяца назад | |||
SUSE-SU-2026:2078-1 Security update for go1.26-openssl | 2 месяца назад | |||
SUSE-SU-2026:1862-1 Security update for go1.25 | 3 месяца назад | |||
SUSE-SU-2026:1861-1 Security update for go1.26 | 3 месяца назад | |||
ELSA-2026-22121 ELSA-2026-22121: golang security update (IMPORTANT) | около 1 месяца назад | |||
ELSA-2026-22120 ELSA-2026-22120: golang security update (IMPORTANT) | 10 дней назад | |||
ELSA-2026-22112 ELSA-2026-22112: go-toolset:ol8 security update (IMPORTANT) | около 2 месяцев назад | |||
openSUSE-SU-2026:21254-1 Security update for go1.26-openssl | 24 дня назад | |||
openSUSE-SU-2026:21319-1 Security update for go1.25-openssl | 18 дней назад |
Уязвимостей на страницу