A vulnerability identified as critical has been detected in Google Go . The affected element is an unknown function of the component cmd/go/x-mod-sumdb . This manipulation causes improper verification of cryptographic signature. This vulnerability appears as CVE-2026-56864 . The attack may be initiated remotely. There is no available exploit.