CVE-2026-94444 - Checksum bypass for golang.org/fips140 in cmd/go
CVE ID :CVE-2026-94444
Published : Oct. 8, 2026, 11:17 p.m. | 6 hours, 29 minutes ago
Description :Previously, a user operating inside of a malicious Go project that defines a bogus golang.org/fips140 and operates a malicious GOMODPROXY the user chooses to connect to can serve an arbitrary module in its place. We now unpack the trusted ziphash for the bundled golang.org/fips140 module and construct its entry in the GOMODCACHE such that it can be verified by the toolchain.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Oct. 8, 2026, 11:17 p.m. | 6 hours, 29 minutes ago
Description :Previously, a user operating inside of a malicious Go project that defines a bogus golang.org/fips140 and operates a malicious GOMODPROXY the user chooses to connect to can serve an arbitrary module in its place. We now unpack the trusted ziphash for the bundled golang.org/fips140 module and construct its entry in the GOMODCACHE such that it can be verified by the toolchain.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...