{"schema_version":"1.9.0","id":"GO-2026-6180","published":"2026-08-13T21:43:54Z","modified":"2026-08-19T12:25:49.995487491Z","aliases":["BIT-golang-2026-56864","CVE-2026-56864"],"related":["CGA-jjqg-jcfg-qc8v"],"summary":"Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb","details":"A malicious GOSUMDB was capable of serving arbitrary module content not contained within the transparency log.\n\nThis attack allows for a coordinating GOPROXY and GOSUMDB to serve a client malicious module content that cannot be detected by evaluating the transparency log.\n\nIn order to determine if you have been affected:\n\nrm -r go.sum go.work.sum vendor/ && go mod tidy","affected":[{"package":{"name":"toolchain","ecosystem":"Go","purl":"pkg:golang/toolchain"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.25.13"},{"introduced":"1.26.0-0"},{"fixed":"1.26.6"},{"introduced":"1.27.0-0"},{"fixed":"1.27.0-rc.3"}]}],"ecosystem_specific":{"imports":[{"path":"cmd/go"}]},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2026-6180.json"}},{"package":{"name":"golang.org/x/mod","ecosystem":"Go","purl":"pkg:golang/golang.org/x/mod"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.40.0"}]}],"ecosystem_specific":{"imports":[{"path":"golang.org/x/mod/sumdb","symbols":["Client.Lookup"]}]},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2026-6180.json"}}],"references":[{"type":"REPORT","url":"https://go.dev/issue/80745"},{"type":"WEB","url":"https://groups.google.com/g/golang-announce/c/94pEornpRlI"},{"type":"FIX","url":"https://go.dev/cl/815000"},{"type":"FIX","url":"https://go.dev/cl/815020"}],"database_specific":{"review_status":"REVIEWED","url":"https://pkg.go.dev/vuln/GO-2026-6180"},"credits":[{"name":"mundur"}]}