Go cmd/go Module Injection via bogus golang.org/fips140 (<=1.27.1)
CVE-2026-94444 Published on October 8, 2026
Checksum bypass for golang.org/fips140 in cmd/go
Previously, a user operating inside of a malicious Go project that defines a bogus golang.org/fips140 and operates a malicious GOMODPROXY the user chooses to connect to can serve an arbitrary module in its place. We now unpack the trusted ziphash for the bundled golang.org/fips140 module and construct its entry in the GOMODCACHE such that it can be verified by the toolchain.
Products Associated with CVE-2026-94444
Want to know whenever a new CVE is published for GoLang Go? stack.watch will email you.
Affected Versions
Go toolchain cmd/go:- Before 1.26.9 is affected.
- Version 1.27.0-0 and below 1.27.2 is affected.