CVE-2026-94447: Go Toolchain Cmd/go

EPSS: 0.1% chance of exploitation in the next 30 days.

Previously, a user operating inside of a malicious Go project that defines a bogus golang.org/toolchain go.sum entry and operates a malicious GOMODPROXY the user chooses to use can bypass the intended checksum. We now ensure that golang.org/toolchain always goes to the network for the canonical checksum.

Affected products

  • Go Toolchain Cmd/go: before 1.26.9 (fixed in 1.26.9); from 1.27.0-0, before 1.27.2 (fixed in 1.27.2)

Published 2026-10-08. Last modified 2026-10-09.