Junglewise Threat Intelligence

CVE-2026-56865: Go malicious GOPROXY sumdb tile forgery bypass

CVE-2026-56865 · Severity: high · CVSS 8.4 · Published 2026-08-13

Technologies: toolchain (Go). Vendors: Go, Google.

Executive brief

Go developers rely on a transparency log (GOSUMDB) to verify that downloaded software modules have not been tampered with. A malicious proxy server could forge verification data to trick developers into caching compromised code that would pass the security check. This could allow attackers to inject malware into developers' local environments that would persist across builds.

Technical details

The vulnerability exists in Go's sumdb (sum database) tile verification logic. A malicious GOPROXY server could forge up to two sumdb tiles, allowing a requested module to bypass GOSUMDB verification checks and persist attacker-controlled content in the local Go module cache. The root cause is incomplete verification of tiles against their parent entries in the transparency log, permitting an attacker to inject false verification data. The attack requires network access to a compromised or attacker-controlled GOPROXY. Go modules downloaded through such a proxy could be cached locally with forged verification checksums that appear valid. The issue has been patched; tiles are now correctly verified against their parents.

Affected products

  • Google Go prior to fix (2026-08-13)

Timeline

  • 2026-08-13: disclosed: CVE-2026-56865 disclosed

References

Related threats