---
id: CVE-2026-56864
title: >-
  golang.org/x/mod/sumdb: golang.org/x/mod/sumdb: Integrity bypass via malicious
  GOSUMDB (CVE-2026-56864)
summary: >-
  A flaw was found in golang.org/x/mod/sumdb. A malicious Go checksum database
  (GOSUMDB) can serve arbitrary module content that is not recorded in the
  transparency log. This allows a coordinated Go proxy (GOPROXY) and GOSUMDB to
  deliver mal…
severity: high
cvss: 8.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N'
cvssSource: vendor
cwe: CWE-494
vendor: Red Hat
product: Red Hat Advanced Cluster Security for Kubernetes 4.11
affected:
  - externaldns_operator
  - openshift_pipelines
  - openshift_distributed_tracing 3
  - advanced_cluster_security_for_kubernetes 4.11
patched:
  - advanced_cluster_security_for_kubernetes 4.11
published: '2026-08-13'
updated: '2026-09-21'
sourceUpdated: '2026-09-21T10:37:31+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-56864.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-56864.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-56864'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2515836'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-56864'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-56864'
  - url: 'https://go.dev/cl/815000'
  - url: 'https://go.dev/cl/815020'
  - url: 'https://go.dev/issue/80745'
  - url: 'https://groups.google.com/g/golang-announce/c/94pEornpRlI'
  - url: 'https://pkg.go.dev/vuln/GO-2026-6180'
  - url: 'https://access.redhat.com/errata/RHSA-2026:67714'
tags:
  - csaf
  - vex
  - red-hat
  - osv
  - go
epss: 0.00316
epssPercentile: 0.21819
aliases:
  - GO-2026-6180
ecosystem: go
ingestedAt: '2026-08-14T19:18:46.695Z'
---

## Overview

A flaw was found in golang.org/x/mod/sumdb. A malicious Go checksum database (GOSUMDB) can serve arbitrary module content that is not recorded in the transparency log. This allows a coordinated Go proxy (GOPROXY) and GOSUMDB to deliver malicious module content to a client, which cannot be detected by examining the transparency log. This vulnerability could lead to a supply chain compromise, allowing attackers to distribute malicious code.

## Vendor advisories

- **RHSA-2026:67714** · Red Hat · fixed in: Red Hat Advanced Cluster Security for Kubernetes 4.11 · released 2026-09-15 · [advisory](https://access.redhat.com/errata/RHSA-2026:67714)
- **Red Hat VEX** · Important · affected: ExternalDNS Operator, OpenShift Pipelines, Red Hat OpenShift distributed tracing 3 · no fix planned: ExternalDNS Operator, OpenShift Pipelines, Red Hat OpenShift distributed tracing 3 · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-56864.json)

**golang.org/x/mod/sumdb: golang.org/x/mod/sumdb: Integrity bypass via malicious GOSUMDB** — rated Important by Red Hat. Released 2026-08-13, updated 2026-09-21.

Affected:

- ExternalDNS Operator
- OpenShift Pipelines
- Red Hat OpenShift distributed tracing 3

Fixed:

- Red Hat Advanced Cluster Security for Kubernetes 4.11

No fix planned:

- ExternalDNS Operator
- OpenShift Pipelines
- Red Hat OpenShift distributed tracing 3

Not affected:

- Red Hat Advanced Cluster Security for Kubernetes 4.11

## Remediation

If you are using an earlier version of RHACS, you are advised to
upgrade to the version of RHACS mentioned in the synopsis and release
notes in order to take advantage of the enhancements, bug fixes, and/or
security patches in the release. https://access.redhat.com/errata/RHSA-2026:67714

Workarounds / mitigations:

- Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

## Package advisory (CVE-2026-56864)

Affected packages:

- `toolchain >= 1.27.0-0, < 1.27.0-rc.3`
- `golang.org/x/mod < 0.40.0`

Patched in:

- `toolchain 1.27.0-rc.3`
- `golang.org/x/mod 0.40.0`

Source: https://osv.dev/vulnerability/GO-2026-6180
