{"id":"CVE-2026-56864","title":"golang.org/x/mod/sumdb: golang.org/x/mod/sumdb: Integrity bypass via malicious GOSUMDB (CVE-2026-56864)","summary":"A flaw was found in golang.org/x/mod/sumdb. A malicious Go checksum database (GOSUMDB) can serve arbitrary module content that is not recorded in the transparency log. This allows a coordinated Go proxy (GOPROXY) and GOSUMDB to deliver mal…","severity":"high","cvss":8.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N","cvssSource":"vendor","cwe":"CWE-494","vendor":"Red Hat","product":"Red Hat Advanced Cluster Security for Kubernetes 4.11","affected":["externaldns_operator","openshift_pipelines","openshift_distributed_tracing 3","advanced_cluster_security_for_kubernetes 4.11"],"patched":["advanced_cluster_security_for_kubernetes 4.11"],"published":"2026-08-13","updated":"2026-09-21","sourceUpdated":"2026-09-21T10:37:31+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-56864.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-56864.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-56864"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2515836"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-56864"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-56864"},{"url":"https://go.dev/cl/815000"},{"url":"https://go.dev/cl/815020"},{"url":"https://go.dev/issue/80745"},{"url":"https://groups.google.com/g/golang-announce/c/94pEornpRlI"},{"url":"https://pkg.go.dev/vuln/GO-2026-6180"},{"url":"https://access.redhat.com/errata/RHSA-2026:67714"}],"tags":["csaf","vex","red-hat","osv","go"],"epss":0.00298,"epssPercentile":0.22703,"aliases":["GO-2026-6180"],"ecosystem":"go","ingestedAt":"2026-08-14T19:18:46.695Z","slug":"CVE-2026-56864","body":"## Overview\n\nA flaw was found in golang.org/x/mod/sumdb. A malicious Go checksum database (GOSUMDB) can serve arbitrary module content that is not recorded in the transparency log. This allows a coordinated Go proxy (GOPROXY) and GOSUMDB to deliver malicious module content to a client, which cannot be detected by examining the transparency log. This vulnerability could lead to a supply chain compromise, allowing attackers to distribute malicious code.\n\n## Vendor advisories\n\n- **RHSA-2026:67714** · Red Hat · fixed in: Red Hat Advanced Cluster Security for Kubernetes 4.11 · released 2026-09-15 · [advisory](https://access.redhat.com/errata/RHSA-2026:67714)\n- **Red Hat VEX** · Important · affected: ExternalDNS Operator, OpenShift Pipelines, Red Hat OpenShift distributed tracing 3 · no fix planned: ExternalDNS Operator, OpenShift Pipelines, Red Hat OpenShift distributed tracing 3 · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-56864.json)\n\n**golang.org/x/mod/sumdb: golang.org/x/mod/sumdb: Integrity bypass via malicious GOSUMDB** — rated Important by Red Hat. Released 2026-08-13, updated 2026-09-21.\n\nAffected:\n\n- ExternalDNS Operator\n- OpenShift Pipelines\n- Red Hat OpenShift distributed tracing 3\n\nFixed:\n\n- Red Hat Advanced Cluster Security for Kubernetes 4.11\n\nNo fix planned:\n\n- ExternalDNS Operator\n- OpenShift Pipelines\n- Red Hat OpenShift distributed tracing 3\n\nNot affected:\n\n- Red Hat Advanced Cluster Security for Kubernetes 4.11\n\n## Remediation\n\nIf you are using an earlier version of RHACS, you are advised to\nupgrade to the version of RHACS mentioned in the synopsis and release\nnotes in order to take advantage of the enhancements, bug fixes, and/or\nsecurity patches in the release. https://access.redhat.com/errata/RHSA-2026:67714\n\nWorkarounds / mitigations:\n\n- Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.\n\n## Package advisory (CVE-2026-56864)\n\nAffected packages:\n\n- `toolchain >= 1.27.0-0, < 1.27.0-rc.3`\n- `golang.org/x/mod < 0.40.0`\n\nPatched in:\n\n- `toolchain 1.27.0-rc.3`\n- `golang.org/x/mod 0.40.0`\n\nSource: https://osv.dev/vulnerability/GO-2026-6180","depth":"twilight","depthScore":45,"depthScoreParts":{"impact":44.6,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[{"seq":201805,"id":"CVE-2026-56864","ts":1789399725906,"field":"cvss","old":null,"new":"8.1"},{"seq":201804,"id":"CVE-2026-56864","ts":1789399725906,"field":"severity","old":"none","new":"high"},{"seq":200535,"id":"CVE-2026-56864","ts":1789397373847,"field":"cvss","old":"8.1","new":null},{"seq":200534,"id":"CVE-2026-56864","ts":1789397373847,"field":"severity","old":"high","new":"none"},{"seq":198452,"id":"CVE-2026-56864","ts":1789391968851,"field":"cvss","old":null,"new":"8.1"},{"seq":198451,"id":"CVE-2026-56864","ts":1789391968851,"field":"severity","old":"none","new":"high"},{"seq":196245,"id":"CVE-2026-56864","ts":1789383585255,"field":"cvss","old":"8.1","new":null},{"seq":196244,"id":"CVE-2026-56864","ts":1789383585255,"field":"severity","old":"high","new":"none"},{"seq":195174,"id":"CVE-2026-56864","ts":1789380475098,"field":"cvss","old":null,"new":"8.1"},{"seq":195173,"id":"CVE-2026-56864","ts":1789380475098,"field":"severity","old":"none","new":"high"},{"seq":193961,"id":"CVE-2026-56864","ts":1789378516410,"field":"cvss","old":"8.1","new":null},{"seq":193960,"id":"CVE-2026-56864","ts":1789378516410,"field":"severity","old":"high","new":"none"},{"seq":192748,"id":"CVE-2026-56864","ts":1789376407196,"field":"cvss","old":null,"new":"8.1"},{"seq":192747,"id":"CVE-2026-56864","ts":1789376407196,"field":"severity","old":"none","new":"high"},{"seq":191535,"id":"CVE-2026-56864","ts":1789373419743,"field":"cvss","old":"8.1","new":null},{"seq":191534,"id":"CVE-2026-56864","ts":1789373419743,"field":"severity","old":"high","new":"none"},{"seq":190320,"id":"CVE-2026-56864","ts":1789369300063,"field":"cvss","old":null,"new":"8.1"},{"seq":190319,"id":"CVE-2026-56864","ts":1789369300063,"field":"severity","old":"none","new":"high"},{"seq":189107,"id":"CVE-2026-56864","ts":1789368267049,"field":"cvss","old":"8.1","new":null},{"seq":189106,"id":"CVE-2026-56864","ts":1789368267049,"field":"severity","old":"high","new":"none"},{"seq":187890,"id":"CVE-2026-56864","ts":1789365143400,"field":"cvss","old":null,"new":"8.1"},{"seq":187889,"id":"CVE-2026-56864","ts":1789365143400,"field":"severity","old":"none","new":"high"},{"seq":186677,"id":"CVE-2026-56864","ts":1789363271457,"field":"cvss","old":"8.1","new":null},{"seq":186676,"id":"CVE-2026-56864","ts":1789363271457,"field":"severity","old":"high","new":"none"},{"seq":185463,"id":"CVE-2026-56864","ts":1789361101384,"field":"cvss","old":null,"new":"8.1"},{"seq":185462,"id":"CVE-2026-56864","ts":1789361101384,"field":"severity","old":"none","new":"high"},{"seq":184250,"id":"CVE-2026-56864","ts":1789358155721,"field":"cvss","old":"8.1","new":null},{"seq":184249,"id":"CVE-2026-56864","ts":1789358155721,"field":"severity","old":"high","new":"none"},{"seq":182501,"id":"CVE-2026-56864","ts":1789354222516,"field":"cvss","old":null,"new":"8.1"},{"seq":182500,"id":"CVE-2026-56864","ts":1789354222516,"field":"severity","old":"none","new":"high"},{"seq":181294,"id":"CVE-2026-56864","ts":1789353120659,"field":"cvss","old":"8.1","new":null},{"seq":181293,"id":"CVE-2026-56864","ts":1789353120659,"field":"severity","old":"high","new":"none"},{"seq":180087,"id":"CVE-2026-56864","ts":1789350169172,"field":"cvss","old":null,"new":"8.1"},{"seq":180086,"id":"CVE-2026-56864","ts":1789350169172,"field":"severity","old":"none","new":"high"},{"seq":178880,"id":"CVE-2026-56864","ts":1789348101500,"field":"cvss","old":"8.1","new":null},{"seq":178879,"id":"CVE-2026-56864","ts":1789348101500,"field":"severity","old":"high","new":"none"},{"seq":177673,"id":"CVE-2026-56864","ts":1789346277668,"field":"cvss","old":null,"new":"8.1"},{"seq":177672,"id":"CVE-2026-56864","ts":1789346277668,"field":"severity","old":"none","new":"high"},{"seq":176466,"id":"CVE-2026-56864","ts":1789343018826,"field":"cvss","old":"8.1","new":null},{"seq":176465,"id":"CVE-2026-56864","ts":1789343018826,"field":"severity","old":"high","new":"none"},{"seq":174583,"id":"CVE-2026-56864","ts":1789334771663,"field":"cvss","old":null,"new":"8.1"},{"seq":174582,"id":"CVE-2026-56864","ts":1789334771663,"field":"severity","old":"none","new":"high"},{"seq":173378,"id":"CVE-2026-56864","ts":1789333513381,"field":"cvss","old":"8.1","new":null},{"seq":173377,"id":"CVE-2026-56864","ts":1789333513381,"field":"severity","old":"high","new":"none"},{"seq":172192,"id":"CVE-2026-56864","ts":1789331018094,"field":"cvss","old":null,"new":"8.1"},{"seq":172191,"id":"CVE-2026-56864","ts":1789331018094,"field":"severity","old":"none","new":"high"},{"seq":171006,"id":"CVE-2026-56864","ts":1789328614648,"field":"cvss","old":"8.1","new":null},{"seq":171005,"id":"CVE-2026-56864","ts":1789328614648,"field":"severity","old":"high","new":"none"},{"seq":169801,"id":"CVE-2026-56864","ts":1789327051046,"field":"cvss","old":null,"new":"8.1"},{"seq":169800,"id":"CVE-2026-56864","ts":1789327051046,"field":"severity","old":"none","new":"high"}]}