CLEANSTART-2026-RD72054
Dashboard / Vulnerabilities / CLEANSTART-2026-RD72054
CLEANSTART-2026-RD72054
Summary: malicious GOSUMDB was capable of serving arbitrary module content not contained within the transparency log
Details: Multiple security vulnerabilities affect the grype-fips package. A malicious GOSUMDB was capable of serving arbitrary module content not contained within the transparency log. See references for individual vulnerability details.
References: https://github.com/cleanstart-dev/cleanstart-security-advisories/tree/main/advisories/2026/CLEANSTART-2026-RD72054.json, https://osv.dev/vulnerability/CVE-2026-41178, https://osv.dev/vulnerability/CVE-2026-56864, https://osv.dev/vulnerability/CVE-2026-56865, https://nvd.nist.gov/vuln/detail/CVE-2026-41178, https://nvd.nist.gov/vuln/detail/CVE-2026-56864, https://nvd.nist.gov/vuln/detail/CVE-2026-56865
Affected packages
Package
Name: grype-fips
Purl:
Affected ranges
Type: ECOSYSTEM
Events:
