Unrated severityNVD Advisory· Published Oct 8, 2026
CVE-2026-94447
CVE-2026-94447
Description
Previously, a user operating inside of a malicious Go project that defines a bogus golang.org/toolchain go.sum entry and operates a malicious GOMODPROXY the user chooses to use can bypass the intended checksum. We now ensure that golang.org/toolchain always goes to the network for the canonical checksum.
Affected products
1Patches
Vulnerability mechanics
References
4News mentions
0No linked articles in our index yet.