goshs.de/goshs/v2 vulnerabilities
CVEs whose affected-version data names the goshs.de/goshs/v2 package (go). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
7 CVEsRSS
CVE-2026-50138High· 8.1goshs is a SimpleHTTPServer written in Go
goshs is a SimpleHTTPServer written in Go. Prior to version 2.1.0, when `goshs` is launched with WebDAV enabled (`-w`), the mode-restriction flags `--read-only`, `--upload-only`, and `--no-delete` are enforced only on the primary HTTP po…
CVE-2026-50139Medium· 5.9goshs is a SimpleHTTPServer written in Go
goshs is a SimpleHTTPServer written in Go. Prior to version 2.1.0, `ShareHandler` reads the share token's `DownloadLimit` under `RLock`, releases the lock, serves the file, then re-acquires the lock to increment the counter. Concurrent r…
CVE-2026-62325Critical· 9.1goshs SFTP authentication bypass via empty password (incomplete fix of CVE-2026-40884)
goshs SFTP authentication bypass via empty password (incomplete fix of CVE-2026-40884)
CVE-2026-54719High· 7.5goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx)
goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx)
CVE-2026-64863Critical· 9.1goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite
goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite
CVE-2026-66063Medium· 6.5goshs has a Path Traversal issue
goshs has a Path Traversal issue
CVE-2026-66064Medium· 5.3goshs has ACL Bypass & Path Traversal
goshs has ACL Bypass & Path Traversal