malicious GOSUMDB was capable of serving arbitrary module content not contained within the transparency log
Details
CVE-2026-56864 affects multiple packages. A malicious GOSUMDB was capable of serving arbitrary module content not contained within the transparency log. See references for individual vulnerability details.