Description
A malicious GOSUMDB was capable of serving arbitrary module content not contained within the transparency log. This attack allows for a coordinating GOPROXY and GOSUMDB to serve a client malicious module content that cannot be detected by evaluating the transparency log. In order to determine if you have been affected: rm -r go.sum go.work.sum vendor/ && go mod tidy
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Affected products
- golang.org/x/mod / golang.org/x/mod/sumdb0 – 0.40.0
- Go toolchain / cmd/go0 – 1.25.13
- Go toolchain / cmd/go1.26.0-0 – 1.26.6
- Go toolchain / cmd/go1.27.0-0 – 1.27.0-rc.3
Updated 38m ago · 8 sources