Golang: stdlib: security update to 1.26.9stdlib: security update to 1.27.2

high Tenable Self-Hosted Container Security Plugin ID 473930

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Previously, a user operating inside of a malicious Go project that defines a bogus golang.org/toolchain
go.sum entry and operates a malicious GOMODPROXY the user chooses to use can bypass the intended checksum.
We now ensure that golang.org/toolchain always goes to the network for the canonical checksum.
(CVE-2026-94447)

Solution

Update the stdlib library and its related packages to version 1.26.9 or later.

See Also

https://pkg.go.dev/vuln/GO-2026-6602

Plugin Details

Severity: High

ID: 473930

Version: Revision 1.1

Type: Local

Family: Golang

Published: 10/9/2026

Updated: 10/9/2026

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 10/8/2026

Vulnerability Publication Date: 10/8/2026

Reference Information

CVE: CVE-2026-94447