Skip to content

Fix possible fix(deps): golang.org/x/mod v0.38.0 → 0.40.0 (CVE-2026-56864) in go.mod - #1

Merged
czyt merged 1 commit into
ca-x:mainfrom
begininvoke:redgem/security-fix-f251da47
Sep 1, 2026
Merged

czyt merged 1 commit into
ca-x:mainfrom
begininvoke:redgem/security-fix-f251da47

Conversation

@begininvoke

Copy link
Copy Markdown
Contributor

Proposing a fix for something flagged in go.mod. It is around line 1.

The vulnerability CVE‑2026‑56864 is real: versions of golang.org/x/mod <0.40.0 allow a malicious GOSUMDB to serve module content not recorded in the transparency log, enabling a coordinated GOPROXY to feed undetected malicious code. This can lead to supply‑chain compromise of Go modules. The fix is to upgrade to a version ≥0.40.0 where the issue is patched.

Updates golang.org/x/mod from vulnerable version 0.38.0 to the fixed version 0.40.0, addressing CVE-2026-56864.

For reference: rule CVE-2026-56864. Rated high.

I may well be missing context here — if the current code is deliberate, feel free to close this.


Found with automated scanning (RedGem) and reviewed before opening. If it is not useful, closing it is completely fine.

@czyt
czyt merged commit c53e337 into ca-x:main Sep 1, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants