CVE-2026-56864
published 2026-08-13CVE-2026-56864: A malicious GOSUMDB was capable of serving arbitrary module content not contained within the transparency log. This attack allows for a coordinating GOPROXY…
PriorityP346high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
0.30%
22.1th percentile
A malicious GOSUMDB was capable of serving arbitrary module content not contained within the transparency log. This attack allows for a coordinating GOPROXY and GOSUMDB to serve a client malicious module content that cannot be detected by evaluating the transparency log. In order to determine if you have been affected: rm -r go.sum go.work.sum vendor/ && go mod tidy
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| go_toolchain | cmd_go | < 1.25.13 | 1.25.13 |
| go_toolchain | cmd_go | >= 1.26.0-0 < 1.26.6 | 1.26.6 |
| go_toolchain | cmd_go | >= 1.27.0-0 < 1.27.0-rc.3 | 1.27.0-rc.3 |
| golang.org | x_mod_golang.org_x_mod_sumdb | < 0.40.0 | 0.40.0 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-08-13
Published