Unrated severityNVD Advisory· Published Oct 8, 2026
CVE-2026-94444
CVE-2026-94444
Description
Previously, a user operating inside of a malicious Go project that defines a bogus golang.org/fips140 and operates a malicious GOMODPROXY the user chooses to connect to can serve an arbitrary module in its place. We now unpack the trusted ziphash for the bundled golang.org/fips140 module and construct its entry in the GOMODCACHE such that it can be verified by the toolchain.
Affected products
2Patches
Vulnerability mechanics
References
4News mentions
0No linked articles in our index yet.