CVE-2026-94444: Go Toolchain Cmd/go
EPSS: 0.1% chance of exploitation in the next 30 days.
Previously, a user operating inside of a malicious Go project that defines a bogus golang.org/fips140 and operates a malicious GOMODPROXY the user chooses to connect to can serve an arbitrary module in its place. We now unpack the trusted ziphash for the bundled golang.org/fips140 module and construct its entry in the GOMODCACHE such that it can be verified by the toolchain.
Affected products
- Go Toolchain Cmd/go: before 1.26.9 (fixed in 1.26.9); from 1.27.0-0, before 1.27.2 (fixed in 1.27.2)
Published 2026-10-08. Last modified 2026-10-09.