Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
GO-2026-6132
  • Go/goshs.de/goshs
  • Go/goshs.de/goshs/v2
goshs SFTP authentication bypass via empty password (incomplete fix of CVE-2026-40884) in goshs.de/goshs 18 Aug
  • Fix available
GO-2026-6133
  • Go/github.com/patrickhener/goshs
  • Go/goshs.de/goshs
  • Go/goshs.de/goshs/v2
goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx) in github.com/patrickhener/goshs 18 Aug
  • Fix available
GO-2026-6134
  • Go/github.com/patrickhener/goshs
  • Go/goshs.de/goshs
  • Go/goshs.de/goshs/v2
goshs has ACL Bypass & Path Traversal in github.com/patrickhener/goshs 18 Aug
  • Fix available
GO-2026-6136
  • Go/github.com/patrickhener/goshs
  • Go/goshs.de/goshs
  • Go/goshs.de/goshs/v2
goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite in github.com/patrickhener/goshs 18 Aug
  • Fix available
GO-2026-6137
  • Go/github.com/patrickhener/goshs
  • Go/goshs.de/goshs
  • Go/goshs.de/goshs/v2
goshs has a Path Traversal issue in github.com/patrickhener/goshs 18 Aug
  • Fix available
GHSA-964w-f6gj-5236
  • Go/github.com/patrickhener/goshs
  • Go/github.com/patrickhener/goshs/v2
  • Go/goshs.de/goshs
  • Go/goshs.de/goshs/v2
goshs has ACL Bypass & Path Traversal 28 Jul
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-wg2q-39h6-66x9
  • Go/github.com/patrickhener/goshs
  • Go/github.com/patrickhener/goshs/v2
  • Go/goshs.de/goshs
  • Go/goshs.de/goshs/v2
goshs has a Path Traversal issue 28 Jul
  • Fix available
  • Severity - 6.5 (Medium)
GHSA-hq33-8jgp-8qq3
  • Go/github.com/patrickhener/goshs
  • Go/github.com/patrickhener/goshs/v2
  • Go/goshs.de/goshs
  • Go/goshs.de/goshs/v2
goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite 28 Jul
  • Fix available
  • Severity - 9.1 (Critical)
GHSA-rmxw-pq4x-3fvh
  • Go/github.com/patrickhener/goshs
  • Go/github.com/patrickhener/goshs/v2
  • Go/goshs.de/goshs
  • Go/goshs.de/goshs/v2
goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx) 28 Jul
  • Fix available
  • Severity - 7.5 (High)
GHSA-rjrw-mjq6-hpmm
  • Go/github.com/patrickhener/goshs/v2
  • Go/goshs.de/goshs/v2
goshs SFTP authentication bypass via empty password (incomplete fix of CVE-2026-40884) 28 Jul
  • Fix available
  • Severity - 9.1 (Critical)
GO-2026-5878
  • Go/goshs.de/goshs
  • Go/goshs.de/goshs/v2
goshs: WebDAV listener ignores --read-only, --upload-only, and --no-delete mode flags in goshs.de/goshs 07 Jul
  • Fix available
GO-2026-5881
  • Go/goshs.de/goshs
  • Go/goshs.de/goshs/v2
goshs: Share-link ?token=… redemption races past download limit in goshs.de/goshs 07 Jul
  • Fix available
GHSA-j48m-h7xq-2xpj
  • Go/goshs.de/goshs/v2
goshs: Share-link ?token=… redemption races past download limit 01 Jul
  • Fix available
  • Severity - 5.9 (Medium)
GHSA-3whc-qvhv-xqjp
  • Go/goshs.de/goshs/v2
goshs: WebDAV listener ignores --read-only, --upload-only, and --no-delete mode flags 01 Jul
  • Fix available
  • Severity - 8.1 (High)
GO-2026-5519
  • Go/goshs.de/goshs
  • Go/goshs.de/goshs/v2
goshs: SSH host key verification disabled, allowing transparent MITM of every tunnelled HTTP request in goshs.de/goshs 25 Jun
  • Fix available
GO-2026-5625
  • Go/github.com/patrickhener/goshs
  • Go/goshs.de/goshs
  • Go/goshs.de/goshs/v2
goshs has Cross-Origin Arbitrary File Write via Missing CSRF on PUT and Wildcard CORS in github.com/patrickhener/goshs 25 Jun
  • Fix available