Executive brief
A vulnerability in the Go programming language's command-line tool allows a malicious module proxy to bypass security checks when downloading software dependencies or toolchain updates. If an attacker controls the proxy server used by a developer, they could serve modified, malicious versions of the Go toolchain or libraries that the developer's computer will then execute. This could lead to a full system compromise or the introduction of backdoors into the developer's own software projects.
Technical details
The Go command (cmd/go) fails to properly validate responses from the checksum database (GOSUMDB) when a module is not already present in the go.sum file. Specifically, if a module proxy returns a successful response that contains no entry for the requested module, or a response for an unrelated module, the go command incorrectly permits validation to succeed. This allows a malicious proxy to serve altered versions of the Go toolchain or modules. Because the go command may automatically download new toolchains based on GOTOOLCHAIN settings or go.mod directives, this can result in the execution of untrusted code. The vulnerability is addressed in Go versions 1.25.10 and 1.26.3.
Affected products
- Google Go < 1.25.10, >= 1.26.0 < 1.26.3
Timeline
- 2026-04-30: disclosed: Issue opened on GitHub
- 2026-05-07: advisory: CVE published and Go vulnerability report released