CVE-2026-94444 PUBLISHED

Checksum bypass for golang.org/fips140 in cmd/go

Assigner: Go
Reserved: 21.09.2026 Published: 08.10.2026 Updated: 08.10.2026

Previously, a user operating inside of a malicious Go project that defines a bogus golang.org/fips140 and operates a malicious GOMODPROXY the user chooses to connect to can serve an arbitrary module in its place. We now unpack the trusted ziphash for the bundled golang.org/fips140 module and construct its entry in the GOMODCACHE such that it can be verified by the toolchain.

Product Status

Vendor Go toolchain
Product cmd/go
Versions Default: unaffected
  • affected from 0 to 1.26.9 (excl.)
  • affected from 1.27.0-0 to 1.27.2 (excl.)

References

Problem Types

  • CWE-354: Improper Validation of Integrity Check Value