blob: 429b2c096f0a8253642ca22527afa039af51d5f7 [file]
{
"dataType": "CVE_RECORD",
"dataVersion": "5.0",
"cveMetadata": {
"cveId": "CVE-2026-56864"
},
"containers": {
"cna": {
"providerMetadata": {
"orgId": "1bb62c36-49e3-4200-9d77-64a1400537cc"
},
"title": "Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb",
"descriptions": [
{
"lang": "en",
"value": "A malicious GOSUMDB was capable of serving arbitrary module content not contained within the transparency log. This attack allows for a coordinating GOPROXY and GOSUMDB to serve a client malicious module content that cannot be detected by evaluating the transparency log. In order to determine if you have been affected: rm -r go.sum go.work.sum vendor/ \u0026\u0026 go mod tidy"
}
],
"affected": [
{
"vendor": "Go toolchain",
"product": "cmd/go",
"collectionURL": "https://pkg.go.dev",
"packageName": "cmd/go",
"versions": [
{
"version": "0",
"lessThan": "1.25.13",
"status": "affected",
"versionType": "semver"
},
{
"version": "1.26.0-0",
"lessThan": "1.26.6",
"status": "affected",
"versionType": "semver"
},
{
"version": "1.27.0-0",
"lessThan": "1.27.0-rc.3",
"status": "affected",
"versionType": "semver"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "golang.org/x/mod",
"product": "golang.org/x/mod/sumdb",
"collectionURL": "https://pkg.go.dev",
"packageName": "golang.org/x/mod/sumdb",
"versions": [
{
"version": "0",
"lessThan": "0.40.0",
"status": "affected",
"versionType": "semver"
}
],
"programRoutines": [
{
"name": "Client.Lookup"
}
],
"defaultStatus": "unaffected"
}
],
"problemTypes": [
{
"descriptions": [
{
"lang": "en",
"description": "CWE-347: Improper Verification of Cryptographic Signature"
}
]
}
],
"references": [
{
"url": "https://go.dev/issue/80745"
},
{
"url": "https://groups.google.com/g/golang-announce/c/94pEornpRlI"
},
{
"url": "https://go.dev/cl/815000"
},
{
"url": "https://go.dev/cl/815020"
},
{
"url": "https://pkg.go.dev/vuln/GO-2026-6180"
}
],
"credits": [
{
"lang": "en",
"value": "mundur"
}
]
}
}
}