Arbitrary Code Execution Vulnerability in Go Project by Golang Developer
CVE-2026-94444
Currently unrated
What is CVE-2026-94444?
This vulnerability arises when a user operates within a compromised Go project that utilizes a forged golang.org/fips140 module and connects to a malevolent GOMODPROXY. The attack enables the malicious proxy to serve arbitrary Go modules, which could lead to unauthorized code execution within the user's environment. Recent fixes involve verifying the integrity of the bundled golang.org/fips140 module by unpacking its trusted ziphash and ensuring its proper entry in the GOMODCACHE, thus preventing exploitation and enhancing security practices in Go development.
Affected Version(s)
cmd/go 0 < 1.26.9
cmd/go 1.27.0-0 < 1.27.2
