VDB
CVE-2026-56864
CVE-2026-56864
PUBLISHED
CVSS 7.5 HIGH
Reported by Go · Published August 13, 2026
A malicious GOSUMDB was capable of serving arbitrary module content not contained within the transparency log. This attack allows for a coordinating GOPROXY and GOSUMDB to serve a client malicious module content that cannot be detected by evaluating the transparency log. In order to determine if you have been affected: rm -r go.sum go.work.sum vendor/ && go mod tidy
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Go toolchain | cmd/go | 0, 1.26.0-0, 1.27.0-0 |
| golang.org/x/mod | golang.org/x/mod/sumdb | 0 |
| chainguard | ipfs-cluster | *, *, * |
| wolfi | nvidia-container-toolkit | *, *, * |
| chainguard | crossplane-provider-aws-fis | *, *, * |
| wolfi | melange | *, *, * |
| chainguard | cloudbeat-fips-8.19 | *, *, * |
| chainguard | crossplane-provider-aws-vpclattice-fips | *, *, * |
| chainguard | opentofu-fips-1.10 | *, *, * |
| chainguard | cluster-api-1.12 | *, *, * |
| wolfi | datadog-agent-7.79 | *, *, * |
| wolfi | dex | *, *, * |
| chainguard | k9s | *, *, * |
| chainguard | crossplane-provider-azure-sql | *, *, * |
| wolfi | opentelemetry-collector-contrib | *, *, * |
| wolfi | minio-operator | *, *, * |
| chainguard | redpanda-operator-25.3 | *, *, * |
| chainguard | rancher-agent-2.10 | *, *, * |
| wolfi | datadog-agent-7.75 | *, *, * |
| chainguard | crossplane-provider-aws-backup | *, *, * |
…and 1272 more
Timeline
- Aug 13, 2026 CVE Published
- Aug 14, 2026 CVE Updated
- Aug 15, 2026 Coalition ESS Score
- Aug 20, 2026 Security Advisory
- Aug 24, 2026 EPSS Score
- Aug 28, 2026 EPSS Score
- Sep 3, 2026 EPSS Score
- Sep 8, 2026 EPSS Score
- Sep 9, 2026 EPSS Score
- Sep 12, 2026 EPSS Score
- Sep 16, 2026 EPSS Score
- Sep 18, 2026 EPSS Score