goshs-labs goshs是goshs-labs组织的一个Web服务器软件。 goshs-labs goshs 2.1.5之前版本存在安全漏洞,该漏洞源于sendFile处理程序在打开文件时从原始req.URL.Path获取授权文件名,可能导致尾部斜杠绕过.goshs ACL文件保护和阻止列表检查。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| goshs-labs | goshs | < 2.1.5 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| goshs-labs | goshs | < 2.1.5 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-62325 | 9.1 CRITICAL | goshs SFTP authentication bypass via empty password (incomplete fix of CVE-2026-40884) |
| CVE-2026-64863 | 9.1 CRITICAL | goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite |
| CVE-2026-54719 | 7.5 HIGH | goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauth |
| CVE-2026-66063 | 6.5 MEDIUM | goshs has a Path Traversal issue |
No comments yet