CVE-2026-94447

CVE-2026-94447CVE-2026-94447

Description

Previously, a user operating inside of a malicious Go project that defines a bogus golang.org/toolchain go.sum entry and operates a malicious GOMODPROXY the user chooses to use can bypass the intended checksum. We now ensure that golang.org/toolchain always goes to the network for the canonical checksum.

Scoring

Last modified2026-10-08
Sourced from NVD. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.