Description
Previously, a user operating inside of a malicious Go project that defines a bogus golang.org/toolchain go.sum entry and operates a malicious GOMODPROXY the user chooses to use can bypass the intended checksum. We now ensure that golang.org/toolchain always goes to the network for the canonical checksum.
Published: 2026-10-08
Score: n/a
EPSS: n/a
KEV: No
Impact: Bypass of module checksum verification allowing supply‑chain compromise
Action: Patch
AI Analysis

Impact

An attacker can supply a malicious Go project that contains a forged golang.org/toolchain entry in go.sum and point GOMODPROXY to a malicious proxy. The Go toolchain, which normally verifies module checksums against a database, will use the bogus checksum instead of the canonical one, allowing the attacker to inject arbitrary code. This is an integrity‑verification weakness (CWE‑20), which can lead to the execution of untrusted code and compromise of confidentiality and integrity within the user’s environment.

Affected Systems

The vulnerability affects the Go toolchain’s command‑line tool cmd/go across all installed versions; specific affected releases were not listed by the CNA. Users running any Go toolchain that fetches modules through GOMODPROXY are potentially impacted.

Risk and Exploitability

The exploit requires that the vulnerable user runs a Go project that references the fake golang.org/toolchain checksum and uses a malicious module proxy. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. The CVSS score is not provided. Given the supply‑chain nature of the attack, the risk is considered significant for environments that trust external module proxies.

Generated by OpenCVE AI on October 9, 2026 at 00:27 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to the latest Go toolchain version that enforces a network fetch for golang.org/toolchain checksums
  • Configure GOMODPROXY to a trusted proxy or use the default public proxy and consider setting GOPROXY=direct for critical builds
  • Run "go mod verify" after fetching modules to ensure checksum integrity before building or executing code

Generated by OpenCVE AI on October 9, 2026 at 00:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 09 Oct 2026 00:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20

Thu, 08 Oct 2026 23:00:00 +0000

Type Values Removed Values Added
Description Previously, a user operating inside of a malicious Go project that defines a bogus golang.org/toolchain go.sum entry and operates a malicious GOMODPROXY the user chooses to use can bypass the intended checksum. We now ensure that golang.org/toolchain always goes to the network for the canonical checksum.
Title Checksum database bypass for golang.org/toolchain in cmd/go
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Go

Published:

Updated: 2026-10-08T22:53:57.974Z

Reserved: 2026-09-21T16:43:04.757Z

Link: CVE-2026-94447

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-08T23:17:05.180

Modified: 2026-10-08T23:17:05.180

Link: CVE-2026-94447

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T00:30:17Z

Weaknesses
  • CWE-20

    Improper Input Validation