github.com/drakkan/sftpgo/v2 vulnerabilities
CVEs whose affected-version data names the github.com/drakkan/sftpgo/v2 package (go). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-49244Medium· 5.9SFTPGo is an open source, event-driven file transfer solution
SFTPGo is an open source, event-driven file transfer solution. From 2.2.0 until 2.7.3, the public web-client partial ZIP download endpoint for a browsable share validates client-supplied files entries with a raw byte-prefix comparison ra…
▾ Sunlitdrakkan · github.com/drakkan/sftpgo/v2EPSS 0.37%via NVD
CVE-2026-49245Low· 3.7SFTPGo is an open source, event-driven file transfer solution
SFTPGo is an open source, event-driven file transfer solution. From 2.2.0 until 2.7.3, the inline query parameter on browsable-share file downloads and authenticated user-file downloads suppresses Content-Disposition: attachment, allowin…
▾ Sunlitdrakkan · github.com/drakkan/sftpgo/v2EPSS 0.20%via NVD