Executive brief
Go's module dependency system relies on a transparency log (GOSUMDB) to verify that downloaded modules are authentic and unmodified. A vulnerability allows a malicious GOSUMDB server, working in coordination with a compromised proxy, to serve fake module code that bypasses the transparency log verification. An attacker could trick developers into using backdoored versions of legitimate open-source libraries, potentially compromising any software built with the affected dependencies.
Technical details
The vulnerability exists in Go's module verification logic, which fails to adequately validate module content served by GOPROXY when GOSUMDB is compromised or malicious. The attack requires coordination between both the GOPROXY and GOSUMDB servers to succeed—the GOSUMDB can serve content not present in the transparency log without detection. An attacker must have control over or be able to man-in-the-middle both the proxy and sum database services. A developer running `go mod tidy` or similar commands will download and use the malicious module without warning. Patches should be available in updated Go releases that strengthen transparency log validation.
Affected products
- Google Go affected versions prior to patch
Timeline
- 2026-08-13: disclosed
- 2026-08-13: advisory: CVE-2026-56864