{"id":"GO-2026-6180","summary":"Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb","details":"A malicious GOSUMDB was capable of serving arbitrary module content not contained within the transparency log.\n\nThis attack allows for a coordinating GOPROXY and GOSUMDB to serve a client malicious module content that cannot be detected by evaluating the transparency log.\n\nIn order to determine if you have been affected:\n\nrm -r go.sum go.work.sum vendor/ && go mod tidy","aliases":["CVE-2026-56864"],"modified":"2026-08-14T09:41:57.749669092Z","published":"2026-08-13T21:43:54Z","related":["CGA-jjqg-jcfg-qc8v"],"database_specific":{"review_status":"REVIEWED","url":"https://pkg.go.dev/vuln/GO-2026-6180"},"references":[{"type":"REPORT","url":"https://go.dev/issue/80745"},{"type":"WEB","url":"https://groups.google.com/g/golang-announce/c/94pEornpRlI"},{"type":"FIX","url":"https://go.dev/cl/815000"},{"type":"FIX","url":"https://go.dev/cl/815020"}],"affected":[{"package":{"name":"toolchain","ecosystem":"Go","purl":"pkg:golang/toolchain"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.25.13"},{"introduced":"1.26.0-0"},{"fixed":"1.26.6"},{"introduced":"1.27.0-0"},{"fixed":"1.27.0-rc.3"}]}],"ecosystem_specific":{"imports":[{"path":"cmd/go"}]},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2026-6180.json"}},{"package":{"name":"golang.org/x/mod","ecosystem":"Go","purl":"pkg:golang/golang.org/x/mod"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.40.0"}]}],"ecosystem_specific":{"imports":[{"symbols":["Client.Lookup"],"path":"golang.org/x/mod/sumdb"}]},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2026-6180.json"}}],"schema_version":"1.9.0","credits":[{"name":"mundur"}]}