Bug 2467810 (CVE-2026-42501) - CVE-2026-42501 cmd/go: golang: Go command (cmd/go): Integrity bypass due to checksum validation flaw via malicious module proxy
Summary: CVE-2026-42501 cmd/go: golang: Go command (cmd/go): Integrity bypass due to c...
Keywords:
Status: NEW
Alias: CVE-2026-42501
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-05-07 20:01 UTC by OSIDB Bzimport
Modified: 2026-08-31 04:07 UTC (History)
29 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2026:22112 0 None None None 2026-06-01 01:04:40 UTC
Red Hat Product Errata RHSA-2026:22120 0 None None None 2026-06-01 00:43:26 UTC
Red Hat Product Errata RHSA-2026:22121 0 None None None 2026-06-01 01:00:30 UTC
Red Hat Product Errata RHSA-2026:49702 0 None None None 2026-08-03 15:59:04 UTC
Red Hat Product Errata RHSA-2026:49712 0 None None None 2026-08-03 17:33:29 UTC
Red Hat Product Errata RHSA-2026:57649 0 None None None 2026-08-20 18:47:11 UTC
Red Hat Product Errata RHSA-2026:61253 0 None None None 2026-08-31 04:07:40 UTC

Description OSIDB Bzimport 2026-05-07 20:01:18 UTC
A malicious module proxy can exploit a flaw in the go command's validation of module checksums to bypass checksum database validation. This vulnerability affects any user using an untrusted module proxy (GOMODPROXY) or checksum database (GOSUMDB). A malicious module proxy can serve altered versions of the Go toolchain. When selecting a different version of the Go toolchain than the currently installed toolchain (due to the GOTOOLCHAIN environment variable, or a go.work or go.mod with a toolchain line), the go command will download and execute a toolchain provided by the module proxy. A malicious module proxy can bypass checksum database validation for this downloaded toolchain. Since this vulnerability affects the security of toolchain downloads, setting GOTOOLCHAIN to a fixed version is not sufficient. You must upgrade your base Go toolchain. The go tool always validates the hash of a toolchain before executing it, so fixed versions will refuse to execute any cached, altered versions of the toolchain. The go tool trusts go.sum files to contain accurate hashes of the current module's dependencies. A malicious proxy exploiting this vulnerability to serve an altered module will have caused an incorrect hash to be recorded in the go.sum. Users who have configured a non-trusted GOPROXY can determine if they have been affected by running "rm go.sum ; go mod tidy ; go mod verify", which will revalidate all dependencies of the current module. The specific flaw in more detail: The go command consults the checksum database to validate downloaded modules, when a module is not listed in the go.sum file. It verifies that the module hash reported by the checksum database matches the hash of the downloaded module. If, however, the checksum database returns a successful response that contains no entry for the module, the go command incorrectly permitted validation to succeed. A module proxy may mirror or proxy the checksum database, in which case the go command will not connect to the checksum database directly. Checksums reported by the checksum database are cryptographically signed, so a malicious proxy cannot alter the reported checksum for a module. However, a proxy which returns an empty checksum response, or a checksum response for an unrelated module, could cause the go command to proceed as if a downloaded module has been validated.

Comment 1 errata-xmlrpc 2026-06-01 00:43:25 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:22120 https://access.redhat.com/errata/RHSA-2026:22120

Comment 2 errata-xmlrpc 2026-06-01 01:00:29 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:22121 https://access.redhat.com/errata/RHSA-2026:22121

Comment 3 errata-xmlrpc 2026-06-01 01:04:39 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:22112 https://access.redhat.com/errata/RHSA-2026:22112

Comment 6 errata-xmlrpc 2026-08-03 15:59:02 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10.0 Extended Update Support

Via RHSA-2026:49702 https://access.redhat.com/errata/RHSA-2026:49702

Comment 7 errata-xmlrpc 2026-08-03 17:33:27 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.6 Extended Update Support

Via RHSA-2026:49712 https://access.redhat.com/errata/RHSA-2026:49712

Comment 8 errata-xmlrpc 2026-08-20 18:47:09 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions

Via RHSA-2026:57649 https://access.redhat.com/errata/RHSA-2026:57649

Comment 10 errata-xmlrpc 2026-08-31 04:07:38 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions

Via RHSA-2026:61253 https://access.redhat.com/errata/RHSA-2026:61253


Note You need to log in before you can comment on or make changes to this bug.