CVE-2026-94444

CVE-2026-94444CVE-2026-94444

Description

Previously, a user operating inside of a malicious Go project that defines a bogus golang.org/fips140 and operates a malicious GOMODPROXY the user chooses to connect to can serve an arbitrary module in its place. We now unpack the trusted ziphash for the bundled golang.org/fips140 module and construct its entry in the GOMODCACHE such that it can be verified by the toolchain.

Scoring

Last modified2026-10-08
Sourced from NVD. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.