Go cmd/go Checksum Bypass (Go <1.26.9, 1.27.0-1.27.2)
CVE-2026-94447 Published on October 8, 2026
Checksum database bypass for golang.org/toolchain in cmd/go
Previously, a user operating inside of a malicious Go project that defines a bogus golang.org/toolchain go.sum entry and operates a malicious GOMODPROXY the user chooses to use can bypass the intended checksum. We now ensure that golang.org/toolchain always goes to the network for the canonical checksum.
Products Associated with CVE-2026-94447
Want to know whenever a new CVE is published for GoLang Go? stack.watch will email you.
Affected Versions
Go toolchain cmd/go:- Before 1.26.9 is affected.
- Version 1.27.0-0 and below 1.27.2 is affected.