CVE-2026-94444: Checksum bypass for golang.org/fips140 in cmd/go

Published Oct 8, 2026
·
Updated

Previously, a user operating inside of a malicious Go project that defines a bogus golang.org/fips140 and operates a malicious GOMODPROXY the user chooses to connect to can serve an arbitrary module in its place. We now unpack the trusted ziphash for the bundled golang.org/fips140 module and construct its entry in the GOMODCACHE such that it can be verified by the toolchain.

Affected Software

1 affected component
go Go

Event History

Oct 8, 2026
CVE Published
via MITRE·10:53 PM
Data Sourced
via MITRE·10:53 PM
DescriptionWeakness

Frequently Asked Questions

1

Who is exposed to this issue?

Users operating inside a malicious Go project are exposed when that project defines a bogus golang.org/fips140 and the user connects to a malicious GOMODPROXY chosen by the project or user.

2

What does an attacker need to exploit it?

The attacker needs to control a malicious Go project that defines a bogus golang.org/fips140 and operate a malicious GOMODPROXY that the user connects to. Under those conditions, the proxy can serve an arbitrary module in place of the bundled golang.org/fips140 module.

3

How is the issue addressed by the updated toolchain behavior?

The toolchain unpacks the trusted ziphash for its bundled golang.org/fips140 module and constructs the module's GOMODCACHE entry so it can be verified by the toolchain.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203