CVE-2026-94447: Checksum database bypass for golang.org/toolchain in cmd/go
Previously, a user operating inside of a malicious Go project that defines a bogus golang.org/toolchain go.sum entry and operates a malicious GOMODPROXY the user chooses to use can bypass the intended checksum. We now ensure that golang.org/toolchain always goes to the network for the canonical checksum.
Affected Software
Event History
Frequently Asked Questions
What conditions are required to exploit this issue?
The user must be operating inside a malicious Go project that includes a bogus golang.org/toolchain entry in go.sum and must use a malicious GOMODPROXY chosen by that user.
Who is realistically exposed?
Users who run Go commands within an untrusted or malicious project and configure Go to use an attacker-controlled module proxy are exposed under the described conditions.
What behavior changed to prevent the bypass?
The Go command now always retrieves the canonical checksum for golang.org/toolchain from the network rather than relying on the project-provided checksum entry.