CVE-2026-56864High· 8.1▾ TwilightA flaw was found in golang.org/x/mod/sumdb. A malicious Go checksum database (GOSUMDB) can serve arbitrary module content that is not recorded in the transparency log. This allows a coordinated Go proxy (GOPROXY) and GOSUMDB to deliver mal…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 44.6 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 14.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
0.1%
0.1% → 0.3%
8.1 → —
high → none
— → 8.1
none → high
8.1 → —
high → none
— → 8.1
none → high
8.1 → —
high → none
— → 8.1
none → high
Last analysed / modified upstream
A flaw was found in golang.org/x/mod/sumdb. A malicious Go checksum database (GOSUMDB) can serve arbitrary module content that is not recorded in the transparency log. This allows a coordinated Go proxy (GOPROXY) and GOSUMDB to deliver malicious module content to a client, which cannot be detected by examining the transparency log. This vulnerability could lead to a supply chain compromise, allowing attackers to distribute malicious code.
golang.org/x/mod/sumdb: golang.org/x/mod/sumdb: Integrity bypass via malicious GOSUMDB — rated Important by Red Hat. Released 2026-08-13, updated 2026-09-21.
Affected:
Fixed:
No fix planned:
Not affected:
If you are using an earlier version of RHACS, you are advised to upgrade to the version of RHACS mentioned in the synopsis and release notes in order to take advantage of the enhancements, bug fixes, and/or security patches in the release. https://access.redhat.com/errata/RHSA-2026:67714
Workarounds / mitigations:
Affected packages:
toolchain >= 1.27.0-0, < 1.27.0-rc.3golang.org/x/mod < 0.40.0Patched in:
toolchain 1.27.0-rc.3golang.org/x/mod 0.40.0Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-56865High· 8.8golang.org/x/mod/sumdb/tlog: golang.org/x/mod/sumdb/tlog: Supply chain compromise via transparency log tile verification bypass (CVE-2026-5…
CVE-2026-63310High· 7.1Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-69263High· 7.5pnpm is a package manager
CVE-2026-95897Medium· 5.5A security vulnerability has been detected in Dask up to 2026.8.0
CVE-2026-13087High· 8.8A heap out-of-bounds write vulnerability was found in the Linux kernel's RPC-over-RDMA server reply path in net/sunrpc/xprtrdma/svc_rdma_sendto.c
CVE-2026-94640High· 7.5A flaw was found in rpcbind