goshs.de/goshs
Go3 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting goshs.de/goshspage 1 of 1
- CVE-2026-42091MEDIUMCVSS 6.5EG 6.52026-05-04
goshs is a SimpleHTTPServer written in Go. Prior to version 2.0.2, the PUT upload handler (httpserver/updown.go) lacks the CSRF token validation that was added to the POST upload handler during the CVE-2026-40883 fix. Combined with the unc…
- CVE-2026-50138HIGHCVSS 8.1EG 8.12026-07-01
goshs: WebDAV listener ignores --read-only, --upload-only, and --no-delete mode flags # WebDAV listener ignores `--read-only`, `--upload-only`, and `--no-delete` mode flags **Ecosystem:** Go **Package:** `goshs.de/goshs/v2` (`github.com/…
- CVE-2026-50139MEDIUMCVSS 5.9EG 5.92026-07-01
goshs: Share-link ?token=… redemption races past download limit # Share-link `?token=…` redemption races past download limit **Ecosystem:** Go **Package:** `goshs.de/goshs/v2` (`github.com/patrickhener/goshs`) **Affected:** `<= v2.0.…
Check whether goshs.de/goshs is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for goshs.de/goshs CVEs against the assets you own.
Start Free Scan →