VYPR

golang.org/toolchain

by Golang.org/toolchain

CVEs (1)

  • CVE-2026-94447Oct 8, 2026
    risk 0.00cvss —epss —

    Previously, a user operating inside of a malicious Go project that defines a bogus golang.org/toolchain go.sum entry and operates a malicious GOMODPROXY the user chooses to use can bypass the intended checksum. We now ensure that golang.org/toolchain always goes to the network…