VYPR

fips140

by Golang

CVEs (1)

  • CVE-2026-94444Oct 8, 2026
    risk 0.00cvss —epss —

    Previously, a user operating inside of a malicious Go project that defines a bogus golang.org/fips140 and operates a malicious GOMODPROXY the user chooses to connect to can serve an arbitrary module in its place. We now unpack the trusted ziphash for the bundled…