[security] Vulnerabilities in golang.org/x/mod

46 views
Skip to first unread message

anno...@golang.org

unread,
Aug 13, 2026, 3:51:20 PM (10 hours ago) Aug 13
to golan...@googlegroups.com

Hello gophers,

We have tagged version v0.40.0 of golang.org/x/mod in order to address the following security issues:

x/mod/sumdb/tlog: fix transparency log tile verification bypass

A malicious GOPROXY was previously capable of forging
up to two sumdb tiles that allow for a requested module
to bypass the GOSUMDB check and persist attacker-controlled
module content to a local Go module cache.

This attack allows for a malicious GOPROXY to serve
malicious module content that cannot be detected
by evaluating the transparency log.

All tiles are now correctly verified against their parents.

In order to determine if you have been affected:

rm -r go.sum go.work.sum vendor/ && go mod tidy

Thanks to Filippo Valsorda (Geomys) for reporting this issue.

This is CVE-2026-56865 and Go issue https://go.dev/issue/80744.

x/mod/sumdb: ignore unrelated, unauthenticated hashes in Lookup

A malicious GOSUMDB was capable of serving arbitrary
module content not contained within the transparency
log.

This attack allows for a coordinating GOPROXY and
GOSUMDB to serve a client malicious module content
that cannot be detected by evaluating the transparency
log.

In order to determine if you have been affected:

rm -r go.sum go.work.sum vendor/ && go mod tidy

Thanks to mundur for reporting this issue.

This is CVE-2026-56864 and Go issue https://go.dev/issue/80745.

Cheers,
Go Security team

Reply all
Reply to author
Forward
0 new messages