github.com/patrickhener/goshs vulnerabilities
CVEs whose affected-version data names the github.com/patrickhener/goshs package (go). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
4 CVEsRSS
CVE-2026-54719High· 7.5goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx)
goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx)
▾ Twilightpatrickhener · github.com/patrickhener/goshsEPSS 0.28%via GHSA
CVE-2026-64863Critical· 9.1goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite
goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite
▾ Midnightgoshs · goshs.de/goshs/v2EPSS 0.36%via GHSA
CVE-2026-66063Medium· 6.5goshs has a Path Traversal issue
goshs has a Path Traversal issue
▾ Sunlitgoshs · goshs.de/goshs/v2EPSS 0.23%via GHSA
CVE-2026-66064Medium· 5.3goshs has ACL Bypass & Path Traversal
goshs has ACL Bypass & Path Traversal
▾ Sunlitpatrickhener · github.com/patrickhener/goshs/v2EPSS 0.31%via GHSA