Bug 2548342 (CVE-2026-94447) - CVE-2026-94447 cmd/go: golang: cmd/go: Toolchain checksum verification bypass via crafted project configuration
Summary: CVE-2026-94447 cmd/go: golang: cmd/go: Toolchain checksum verification bypass...
Keywords:
Status: NEW
Alias: CVE-2026-94447
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2548365
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-10-08 23:01 UTC by OSIDB Bzimport
Modified: 2026-10-09 05:25 UTC (History)
28 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-10-08 23:01:43 UTC
Previously, a user operating inside of a malicious Go project that defines a bogus golang.org/toolchain go.sum entry and operates a malicious GOMODPROXY the user chooses to use can bypass the intended checksum. We now ensure that golang.org/toolchain always goes to the network for the canonical checksum.

Comment 2 Yadnyawalk Tale 2026-10-09 05:25:42 UTC
CVSS Justification
===================
AV:L -- Exploitation requires running the local go command on the victim host.
AC:H -- Attacker must supply a malicious Go project and the user must also use an untrusted module proxy.
PR:L -- A local account (developer/build user) is required to invoke the go toolchain; an unauthenticated remote party cannot trigger the flaw on its own.
UI:R -- The user must open/operate inside the malicious project (and choose that proxy).
S:U -- Impact stays in the same security authority as the user running go.
C:H -- Successful exploitation can execute attacker-controlled code in that user context.
I:H -- Attacker-controlled modules/toolchain can alter build integrity.
A:H -- Arbitrary code execution can disrupt or terminate the build/user environment.


Note You need to log in before you can comment on or make changes to this bug.