Bypass Vulnerability in Go Toolchain Affecting Golang Projects
CVE-2026-94447

Currently unrated

Key Information:

Status
Vendor
CVE Published:
8 October 2026

What is CVE-2026-94447?

A vulnerability exists in the Go toolchain that allows users to bypass the intended checksum verification when working with malicious Go projects. Specifically, it can occur if a user is operating within a project that defines a deceptive go.sum entry, alongside utilizing a user-selected malicious GOMODPROXY. This flaw undermines the security intended by the Go checksum mechanism. To mitigate this issue, the Go toolchain will now always reach out to the network to retrieve the canonical checksum, ensuring that users cannot exploit this loophole.

Affected Version(s)

cmd/go 0 < 1.26.9

cmd/go 1.27.0-0 < 1.27.2

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.