---
id: CVE-2026-56865
title: >-
  golang.org/x/mod/sumdb/tlog: golang.org/x/mod/sumdb/tlog: Supply chain
  compromise via transparency log tile verification bypass (CVE-2026-5…
summary: >-
  A flaw was found in golang.org/x/mod/sumdb/tlog. A malicious Go proxy
  (GOPROXY) could exploit this vulnerability by forging sumdb tiles. This
  allowed the proxy to bypass integrity checks and serve malicious module
  content to a local Go mod…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'
cvssSource: vendor
cwe: CWE-347
vendor: Red Hat
product: Red Hat Advanced Cluster Security for Kubernetes 4.11
affected:
  - externaldns_operator
  - openshift_pipelines
  - openshift_distributed_tracing 3
  - advanced_cluster_security_for_kubernetes 4.11
patched:
  - advanced_cluster_security_for_kubernetes 4.11
published: '2026-08-13'
updated: '2026-09-21'
sourceUpdated: '2026-09-21T10:37:36+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-56865.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-56865.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-56865'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2515830'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-56865'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-56865'
  - url: 'https://go.dev/cl/814960'
  - url: 'https://go.dev/cl/815020'
  - url: 'https://go.dev/issue/80744'
  - url: 'https://groups.google.com/g/golang-announce/c/94pEornpRlI'
  - url: 'https://pkg.go.dev/vuln/GO-2026-6179'
  - url: 'https://access.redhat.com/errata/RHSA-2026:67714'
tags:
  - csaf
  - vex
  - red-hat
  - osv
  - go
epss: 0.00138
epssPercentile: 0.02575
aliases:
  - GO-2026-6179
ecosystem: go
ingestedAt: '2026-08-14T19:18:46.661Z'
---

## Overview

A flaw was found in golang.org/x/mod/sumdb/tlog. A malicious Go proxy (GOPROXY) could exploit this vulnerability by forging sumdb tiles. This allowed the proxy to bypass integrity checks and serve malicious module content to a local Go module cache, which would then go undetected by the transparency log. This could lead to a supply chain compromise where users unknowingly incorporate compromised modules.

## Vendor advisories

- **RHSA-2026:67714** · Red Hat · fixed in: Red Hat Advanced Cluster Security for Kubernetes 4.11 · released 2026-09-15 · [advisory](https://access.redhat.com/errata/RHSA-2026:67714)
- **Red Hat VEX** · Important · affected: ExternalDNS Operator, OpenShift Pipelines, Red Hat OpenShift distributed tracing 3 · no fix planned: ExternalDNS Operator, OpenShift Pipelines, Red Hat OpenShift distributed tracing 3 · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-56865.json)

**golang.org/x/mod/sumdb/tlog: golang.org/x/mod/sumdb/tlog: Supply chain compromise via transparency log tile verification bypass** — rated Important by Red Hat. Released 2026-08-13, updated 2026-09-21.

Affected:

- ExternalDNS Operator
- OpenShift Pipelines
- Red Hat OpenShift distributed tracing 3

Fixed:

- Red Hat Advanced Cluster Security for Kubernetes 4.11

No fix planned:

- ExternalDNS Operator
- OpenShift Pipelines
- Red Hat OpenShift distributed tracing 3

Not affected:

- Red Hat Advanced Cluster Security for Kubernetes 4.11
- Red Hat Enterprise Linux 7
- Red Hat Enterprise Linux 8

## Remediation

If you are using an earlier version of RHACS, you are advised to
upgrade to the version of RHACS mentioned in the synopsis and release
notes in order to take advantage of the enhancements, bug fixes, and/or
security patches in the release. https://access.redhat.com/errata/RHSA-2026:67714

Workarounds / mitigations:

- No mitigation is available for this vulnerability. Update the affected packages to golang.org/x/mod version 0.40.0 or later, or Go toolchain version 1.25.13, 1.26.6, or 1.27.0-rc.3 or later.

## Package advisory (CVE-2026-56865)

Affected packages:

- `toolchain >= 1.27.0-0, < 1.27.0-rc.3`
- `golang.org/x/mod < 0.40.0`

Patched in:

- `toolchain 1.27.0-rc.3`
- `golang.org/x/mod 0.40.0`

Source: https://osv.dev/vulnerability/GO-2026-6179
