{"id":"CVE-2026-56865","title":"golang.org/x/mod/sumdb/tlog: golang.org/x/mod/sumdb/tlog: Supply chain compromise via transparency log tile verification bypass (CVE-2026-5…","summary":"A flaw was found in golang.org/x/mod/sumdb/tlog. A malicious Go proxy (GOPROXY) could exploit this vulnerability by forging sumdb tiles. This allowed the proxy to bypass integrity checks and serve malicious module content to a local Go mod…","severity":"high","cvss":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","cvssSource":"vendor","cwe":"CWE-347","vendor":"Red Hat","product":"Red Hat Advanced Cluster Security for Kubernetes 4.11","affected":["externaldns_operator","openshift_pipelines","openshift_distributed_tracing 3","advanced_cluster_security_for_kubernetes 4.11"],"patched":["advanced_cluster_security_for_kubernetes 4.11"],"published":"2026-08-13","updated":"2026-09-21","sourceUpdated":"2026-09-21T10:37:36+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-56865.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-56865.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-56865"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2515830"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-56865"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-56865"},{"url":"https://go.dev/cl/814960"},{"url":"https://go.dev/cl/815020"},{"url":"https://go.dev/issue/80744"},{"url":"https://groups.google.com/g/golang-announce/c/94pEornpRlI"},{"url":"https://pkg.go.dev/vuln/GO-2026-6179"},{"url":"https://access.redhat.com/errata/RHSA-2026:67714"}],"tags":["csaf","vex","red-hat","osv","go"],"epss":0.00107,"epssPercentile":0.01287,"aliases":["GO-2026-6179"],"ecosystem":"go","ingestedAt":"2026-08-14T19:18:46.661Z","slug":"CVE-2026-56865","body":"## Overview\n\nA flaw was found in golang.org/x/mod/sumdb/tlog. A malicious Go proxy (GOPROXY) could exploit this vulnerability by forging sumdb tiles. This allowed the proxy to bypass integrity checks and serve malicious module content to a local Go module cache, which would then go undetected by the transparency log. This could lead to a supply chain compromise where users unknowingly incorporate compromised modules.\n\n## Vendor advisories\n\n- **RHSA-2026:67714** · Red Hat · fixed in: Red Hat Advanced Cluster Security for Kubernetes 4.11 · released 2026-09-15 · [advisory](https://access.redhat.com/errata/RHSA-2026:67714)\n- **Red Hat VEX** · Important · affected: ExternalDNS Operator, OpenShift Pipelines, Red Hat OpenShift distributed tracing 3 · no fix planned: ExternalDNS Operator, OpenShift Pipelines, Red Hat OpenShift distributed tracing 3 · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-56865.json)\n\n**golang.org/x/mod/sumdb/tlog: golang.org/x/mod/sumdb/tlog: Supply chain compromise via transparency log tile verification bypass** — rated Important by Red Hat. Released 2026-08-13, updated 2026-09-21.\n\nAffected:\n\n- ExternalDNS Operator\n- OpenShift Pipelines\n- Red Hat OpenShift distributed tracing 3\n\nFixed:\n\n- Red Hat Advanced Cluster Security for Kubernetes 4.11\n\nNo fix planned:\n\n- ExternalDNS Operator\n- OpenShift Pipelines\n- Red Hat OpenShift distributed tracing 3\n\nNot affected:\n\n- Red Hat Advanced Cluster Security for Kubernetes 4.11\n- Red Hat Enterprise Linux 7\n- Red Hat Enterprise Linux 8\n\n## Remediation\n\nIf you are using an earlier version of RHACS, you are advised to\nupgrade to the version of RHACS mentioned in the synopsis and release\nnotes in order to take advantage of the enhancements, bug fixes, and/or\nsecurity patches in the release. https://access.redhat.com/errata/RHSA-2026:67714\n\nWorkarounds / mitigations:\n\n- No mitigation is available for this vulnerability. Update the affected packages to golang.org/x/mod version 0.40.0 or later, or Go toolchain version 1.25.13, 1.26.6, or 1.27.0-rc.3 or later.\n\n## Package advisory (CVE-2026-56865)\n\nAffected packages:\n\n- `toolchain >= 1.27.0-0, < 1.27.0-rc.3`\n- `golang.org/x/mod < 0.40.0`\n\nPatched in:\n\n- `toolchain 1.27.0-rc.3`\n- `golang.org/x/mod 0.40.0`\n\nSource: https://osv.dev/vulnerability/GO-2026-6179","depth":"twilight","depthScore":48,"depthScoreParts":{"impact":48.4,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":201807,"id":"CVE-2026-56865","ts":1789399725913,"field":"cvss","old":null,"new":"8.8"},{"seq":201806,"id":"CVE-2026-56865","ts":1789399725913,"field":"severity","old":"none","new":"high"},{"seq":200537,"id":"CVE-2026-56865","ts":1789397373862,"field":"cvss","old":"8.8","new":null},{"seq":200536,"id":"CVE-2026-56865","ts":1789397373862,"field":"severity","old":"high","new":"none"},{"seq":198454,"id":"CVE-2026-56865","ts":1789391968858,"field":"cvss","old":null,"new":"8.8"},{"seq":198453,"id":"CVE-2026-56865","ts":1789391968858,"field":"severity","old":"none","new":"high"},{"seq":196247,"id":"CVE-2026-56865","ts":1789383585262,"field":"cvss","old":"8.8","new":null},{"seq":196246,"id":"CVE-2026-56865","ts":1789383585262,"field":"severity","old":"high","new":"none"},{"seq":195176,"id":"CVE-2026-56865","ts":1789380475104,"field":"cvss","old":null,"new":"8.8"},{"seq":195175,"id":"CVE-2026-56865","ts":1789380475104,"field":"severity","old":"none","new":"high"},{"seq":193963,"id":"CVE-2026-56865","ts":1789378516542,"field":"cvss","old":"8.8","new":null},{"seq":193962,"id":"CVE-2026-56865","ts":1789378516542,"field":"severity","old":"high","new":"none"},{"seq":192750,"id":"CVE-2026-56865","ts":1789376407204,"field":"cvss","old":null,"new":"8.8"},{"seq":192749,"id":"CVE-2026-56865","ts":1789376407204,"field":"severity","old":"none","new":"high"},{"seq":191537,"id":"CVE-2026-56865","ts":1789373419751,"field":"cvss","old":"8.8","new":null},{"seq":191536,"id":"CVE-2026-56865","ts":1789373419751,"field":"severity","old":"high","new":"none"},{"seq":190322,"id":"CVE-2026-56865","ts":1789369300071,"field":"cvss","old":null,"new":"8.8"},{"seq":190321,"id":"CVE-2026-56865","ts":1789369300071,"field":"severity","old":"none","new":"high"},{"seq":189109,"id":"CVE-2026-56865","ts":1789368267063,"field":"cvss","old":"8.8","new":null},{"seq":189108,"id":"CVE-2026-56865","ts":1789368267063,"field":"severity","old":"high","new":"none"},{"seq":187892,"id":"CVE-2026-56865","ts":1789365143407,"field":"cvss","old":null,"new":"8.8"},{"seq":187891,"id":"CVE-2026-56865","ts":1789365143407,"field":"severity","old":"none","new":"high"},{"seq":186679,"id":"CVE-2026-56865","ts":1789363271465,"field":"cvss","old":"8.8","new":null},{"seq":186678,"id":"CVE-2026-56865","ts":1789363271465,"field":"severity","old":"high","new":"none"},{"seq":185465,"id":"CVE-2026-56865","ts":1789361101392,"field":"cvss","old":null,"new":"8.8"},{"seq":185464,"id":"CVE-2026-56865","ts":1789361101392,"field":"severity","old":"none","new":"high"},{"seq":184252,"id":"CVE-2026-56865","ts":1789358155736,"field":"cvss","old":"8.8","new":null},{"seq":184251,"id":"CVE-2026-56865","ts":1789358155736,"field":"severity","old":"high","new":"none"},{"seq":182503,"id":"CVE-2026-56865","ts":1789354222523,"field":"cvss","old":null,"new":"8.8"},{"seq":182502,"id":"CVE-2026-56865","ts":1789354222523,"field":"severity","old":"none","new":"high"},{"seq":181296,"id":"CVE-2026-56865","ts":1789353120667,"field":"cvss","old":"8.8","new":null},{"seq":181295,"id":"CVE-2026-56865","ts":1789353120667,"field":"severity","old":"high","new":"none"},{"seq":180089,"id":"CVE-2026-56865","ts":1789350169180,"field":"cvss","old":null,"new":"8.8"},{"seq":180088,"id":"CVE-2026-56865","ts":1789350169180,"field":"severity","old":"none","new":"high"},{"seq":178882,"id":"CVE-2026-56865","ts":1789348101515,"field":"cvss","old":"8.8","new":null},{"seq":178881,"id":"CVE-2026-56865","ts":1789348101515,"field":"severity","old":"high","new":"none"},{"seq":177675,"id":"CVE-2026-56865","ts":1789346277675,"field":"cvss","old":null,"new":"8.8"},{"seq":177674,"id":"CVE-2026-56865","ts":1789346277675,"field":"severity","old":"none","new":"high"},{"seq":176468,"id":"CVE-2026-56865","ts":1789343018834,"field":"cvss","old":"8.8","new":null},{"seq":176467,"id":"CVE-2026-56865","ts":1789343018834,"field":"severity","old":"high","new":"none"},{"seq":174585,"id":"CVE-2026-56865","ts":1789334771669,"field":"cvss","old":null,"new":"8.8"},{"seq":174584,"id":"CVE-2026-56865","ts":1789334771669,"field":"severity","old":"none","new":"high"},{"seq":173380,"id":"CVE-2026-56865","ts":1789333513545,"field":"cvss","old":"8.8","new":null},{"seq":173379,"id":"CVE-2026-56865","ts":1789333513545,"field":"severity","old":"high","new":"none"},{"seq":172194,"id":"CVE-2026-56865","ts":1789331018101,"field":"cvss","old":null,"new":"8.8"},{"seq":172193,"id":"CVE-2026-56865","ts":1789331018101,"field":"severity","old":"none","new":"high"},{"seq":171008,"id":"CVE-2026-56865","ts":1789328614656,"field":"cvss","old":"8.8","new":null},{"seq":171007,"id":"CVE-2026-56865","ts":1789328614656,"field":"severity","old":"high","new":"none"},{"seq":169803,"id":"CVE-2026-56865","ts":1789327051053,"field":"cvss","old":null,"new":"8.8"},{"seq":169802,"id":"CVE-2026-56865","ts":1789327051053,"field":"severity","old":"none","new":"high"}]}