github.com/patrickhener/goshs/v2
Go5 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting github.com/patrickhener/goshs/v2page 1 of 1
- CVE-2026-40876HIGHCVSS 8.8EG 8.8✓ Fixed in 2.0.02026-04-21
goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.6, goshs contains an SFTP root escape caused by prefix-based path validation. An authenticated SFTP user can read from and write to filesystem paths outside the configured SFTP…
- CVE-2026-40883HIGHCVSS 8.1EG 8.1✓ Fixed in 2.0.0-beta.62026-04-21
goshs is a SimpleHTTPServer written in Go. From 2.0.0-beta.4 to 2.0.0-beta.5, goshs contains a cross-site request forgery issue in its state-changing HTTP GET routes. An external attacker can cause an already authenticated browser to trigg…
- CVE-2026-40884CRITICALCVSS 9.8EG 9.8✓ Fixed in 2.0.02026-04-21
goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.6, goshs contains an SFTP authentication bypass when the documented empty-username basic-auth syntax is used. If the server is started with -b ':pass' together with -sftp, gosh…
- CVE-2026-40885HIGHCVSS 8.8EG 8.8✓ Fixed in 2.0.0-beta.62026-04-21
goshs is a SimpleHTTPServer written in Go. From 2.0.0-beta.4 to 2.0.0-beta.5, goshs leaks file-based ACL credentials through its public collaborator feed when the server is deployed without global basic auth. Requests to .goshs-protected f…
- CVE-2026-42091MEDIUMCVSS 6.5EG 6.5✓ Fixed in 2.0.22026-05-04
goshs is a SimpleHTTPServer written in Go. Prior to version 2.0.2, the PUT upload handler (httpserver/updown.go) lacks the CSRF token validation that was added to the POST upload handler during the CVE-2026-40883 fix. Combined with the unc…
Check whether github.com/patrickhener/goshs/v2 is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for github.com/patrickhener/goshs/v2 CVEs against the assets you own.
Start Free Scan →