CVE-2026-94444: Checksum bypass for golang.org/fips140 in cmd/go
Previously, a user operating inside of a malicious Go project that defines a bogus golang.org/fips140 and operates a malicious GOMODPROXY the user chooses to connect to can serve an arbitrary module in its place. We now unpack the trusted ziphash for the bundled golang.org/fips140 module and construct its entry in the GOMODCACHE such that it can be verified by the toolchain.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
Users operating inside a malicious Go project are exposed when that project defines a bogus golang.org/fips140 and the user connects to a malicious GOMODPROXY chosen by the project or user.
What does an attacker need to exploit it?
The attacker needs to control a malicious Go project that defines a bogus golang.org/fips140 and operate a malicious GOMODPROXY that the user connects to. Under those conditions, the proxy can serve an arbitrary module in place of the bundled golang.org/fips140 module.
How is the issue addressed by the updated toolchain behavior?
The toolchain unpacks the trusted ziphash for its bundled golang.org/fips140 module and constructs the module's GOMODCACHE entry so it can be verified by the toolchain.