CVE-2026-56864: Go Toolchain Cmd/go
High severity, CVSS 7.5. EPSS: 0.3% chance of exploitation in the next 30 days.
A malicious GOSUMDB was capable of serving arbitrary module content not contained within the transparency log. This attack allows for a coordinating GOPROXY and GOSUMDB to serve a client malicious module content that cannot be detected by evaluating the transparency log. In order to determine if you have been affected: rm -r go.sum go.work.sum vendor/ && go mod tidy
Affected products
- Go Toolchain Cmd/go: before 1.25.13 (fixed in 1.25.13); from 1.26.0-0, before 1.26.6 (fixed in 1.26.6); from 1.27.0-0, before 1.27.0-rc.3 (fixed in 1.27.0-rc.3)
- Golang.org/x/mod Golang.org/x/mod/sumdb: before 0.40.0 (fixed in 0.40.0)
Published 2026-08-13. Last modified 2026-09-03.