CVE-2026-56865High· 8.8▾ TwilightA flaw was found in golang.org/x/mod/sumdb/tlog. A malicious Go proxy (GOPROXY) could exploit this vulnerability by forging sumdb tiles. This allowed the proxy to bypass integrity checks and serve malicious module content to a local Go mod…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 48.4 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 14.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
0.1%
8.8 → —
high → none
— → 8.8
none → high
8.8 → —
high → none
— → 8.8
none → high
8.8 → —
high → none
— → 8.8
none → high
Last analysed / modified upstream
A flaw was found in golang.org/x/mod/sumdb/tlog. A malicious Go proxy (GOPROXY) could exploit this vulnerability by forging sumdb tiles. This allowed the proxy to bypass integrity checks and serve malicious module content to a local Go module cache, which would then go undetected by the transparency log. This could lead to a supply chain compromise where users unknowingly incorporate compromised modules.
golang.org/x/mod/sumdb/tlog: golang.org/x/mod/sumdb/tlog: Supply chain compromise via transparency log tile verification bypass — rated Important by Red Hat. Released 2026-08-13, updated 2026-09-21.
Affected:
Fixed:
No fix planned:
Not affected:
If you are using an earlier version of RHACS, you are advised to upgrade to the version of RHACS mentioned in the synopsis and release notes in order to take advantage of the enhancements, bug fixes, and/or security patches in the release. https://access.redhat.com/errata/RHSA-2026:67714
Workarounds / mitigations:
Affected packages:
toolchain >= 1.27.0-0, < 1.27.0-rc.3golang.org/x/mod < 0.40.0Patched in:
toolchain 1.27.0-rc.3golang.org/x/mod 0.40.0Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-56864High· 8.1golang.org/x/mod/sumdb: golang.org/x/mod/sumdb: Integrity bypass via malicious GOSUMDB (CVE-2026-56864)
CVE-2026-42501Medium· 5.3cmd/go: golang: Go command (cmd/go): Integrity bypass due to checksum validation flaw via malicious module proxy (CVE-2026-42501)
CVE-2026-39831High· 8.1golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check (CVE-2026-39831)
CVE-2026-49834Medium· 5.9github.com/sigstore/sigstore-go: sigstore-go: Security Policy Bypass via Compromised Log (CVE-2026-49834)
CVE-2026-95503Medium· 6.8A flaw was found in the Kerberos federation provider of Keycloak, an open-source identity and access management solution
CVE-2026-75939High· 7.4A flaw was found in openshift/oc-mirror