What is CVE-2026-56865?
CVE-2026-56865 is a vulnerability in Go that allows a malicious GOPROXY to bypass GOSUMDB checks by forging up to two sumdb tiles. This enables attacker-controlled module content to be persisted in the local Go module cache, effectively serving malicious code to developers. Users should ensure they are using trusted module sources and update their Go environment to the latest patched version.
Azərbaycanca: CVE-2026-56865, Go proqramlaşdırma dilində GOSUMDB yoxlamasından yan keçməyə imkan verən bir zəiflikdir. Bu, zərərli GOPROXY serverinə 2-ə qədər sumdb tiles saxtalaşdırmağa və təcavüzkar tərəfindən idarə olunan modul məzmununu yerli Go modul keşinə yerləşdirməyə şərait yaradır. İstifadəçilər etibarlı modul mənbələrindən istifadə etməli və Go versiyalarını ən son təhlükəsizlik yeniləmələri ilə güncəlləməlidirlər.
FAQ1
What is CVE-2026-56865?
CVE-2026-56865 is a vulnerability in Go that allows a malicious GOPROXY to bypass GOSUMDB checks by forging up to two sumdb tiles. This enables attacker-controlled module content to be persisted in the local Go module cache.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.