goshs has 4 CVEs on record. 4 were published in the last 90 days. The median CVSS is 7.3 (high), with 1 rated critical.
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.3
- Publish → KEV
- —
- Last 90 days
- 4 prev 0
Worst active — by depth score
goshs vulnerabilities
CVEs affecting goshs, newest first. Open any entry for full detail, references, and exploit status.
4 CVEsRSS
CVE-2026-50138High· 8.1goshs is a SimpleHTTPServer written in Go
goshs is a SimpleHTTPServer written in Go. Prior to version 2.1.0, when `goshs` is launched with WebDAV enabled (`-w`), the mode-restriction flags `--read-only`, `--upload-only`, and `--no-delete` are enforced only on the primary HTTP po…
CVE-2026-50139Medium· 5.9goshs is a SimpleHTTPServer written in Go
goshs is a SimpleHTTPServer written in Go. Prior to version 2.1.0, `ShareHandler` reads the share token's `DownloadLimit` under `RLock`, releases the lock, serves the file, then re-acquires the lock to increment the counter. Concurrent r…
CVE-2026-64863Critical· 9.1goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite
goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite
CVE-2026-66063Medium· 6.5goshs has a Path Traversal issue
goshs has a Path Traversal issue