CVE-2026-56865
Last modified
CVE-2026-56865 is a high-severity vulnerability rated 8.4/10 on the CVSS scale. A malicious GOPROXY was previously capable of forging up to two sumdb tiles that allow for a requested module to bypass the GOSUMDB check and persist attacker-controlled module content to a local Go module cache. This attack allows for a malicious GOPROXY to serve malicious module content that cannot be detected by evaluating the transparency log. EPSS estimates a 0.11% chance of exploitation in the next 30 days.
Description
A malicious GOPROXY was previously capable of forging up to two sumdb tiles that allow for a requested module to bypass the GOSUMDB check and persist attacker-controlled module content to a local Go module cache. This attack allows for a malicious GOPROXY to serve malicious module content that cannot be detected by evaluating the transparency log. All tiles are now correctly verified against their parents. In order to determine if you have been affected: rm -r go.sum go.work.sum vendor/ && go mod tidy
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Go toolchain | cmd/go | < 1.25.13; >= 1.26.0-0, < 1.26.6; >= 1.27.0-0, < 1.27.0-rc.3 |
| golang.org/x/mod | golang.org/x/mod/sumdb/tlog | < 0.40.0 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-56865?
How severe is CVE-2026-56865?
How do I fix CVE-2026-56865?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-56858Previously, pathological inputs could close an unescaped '/'…6.1
- CVE-2026-56859Previously, DecodeElement would reset the depth counter caus…7.5
- CVE-2026-5686A security flaw has been discovered in Tenda CX12L 16.03.53.…8.8
- CVE-2026-56860Previously, resolving relative paths containing parent direc…5.9
- CVE-2026-56862Handshake messages, such as KeyUpdate, are always considered…7.5
- CVE-2026-56864A malicious GOSUMDB was capable of serving arbitrary module …7.5
- CVE-2026-56867Rejected reason: reserved but not needed
- CVE-2026-56868Rejected reason: reserved but not needed
- CVE-2026-56869Rejected reason: reserved but not needed
- CVE-2026-5687A weakness has been identified in Tenda CX12L 16.03.53.12. T…8.8
- CVE-2026-56870Rejected reason: reserved but not needed
- CVE-2026-56871Rejected reason: reserved but not needed
Are you affected by CVE-2026-56865?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
