Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

goshs — Vulnerabilities & Security Advisories 20

All 20 CVE vulnerabilities found in goshs, with AI-generated Chinese analysis, references, and POCs.

This page aggregates known security vulnerabilities for the product goshs, categorized by specific weakness types and vendor advisories. It collects data on historical and recent security flaws affecting this software, covering a broad timeline from its initial release through current maintenance periods. Visitors can use this resource to track the security posture of goshs, examine common weakness classes such as buffer overflows or injection flaws, and review the complete vulnerability history associated with the product. The collection focuses on confirmed defects rather than speculative issues, providing a consolidated view for security teams and developers. By consolidating these records, the page enables users to identify recurring patterns in security failures, monitor updates from the vendor, and understand the evolution of risks over time. This aggregation supports risk assessment and patch management without requiring separate lookups across disparate databases. The data reflects publicly disclosed issues, ensuring transparency for stakeholders managing infrastructure dependent on goshs.

Vendor: patrickhener

CVE ID Title CVSS Severity Published
CVE-2026-50139 goshs: Share-link ?token=… redemption races past download limit CWE-362 5.9 Medium 2026-08-18
CVE-2026-50138 goshs: WebDAV listener ignores --read-only, --upload-only, and --no-delete mode flags CWE-284 8.1 High 2026-08-18
CVE-2026-66064 goshs has ACL Bypass & Path Traversal CWE-41 5.3 Medium 2026-07-28
CVE-2026-66063 goshs has a Path Traversal issue CWE-22 6.5 Medium 2026-07-28
CVE-2026-64863 goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite CWE-284 9.1 Critical 2026-07-28
CVE-2026-54719 goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of CVE-2026-40189) CWE-862 7.5 High 2026-07-28
CVE-2026-62325 goshs SFTP authentication bypass via empty password (incomplete fix of CVE-2026-40884) CWE-306 9.1 Critical 2026-07-28
CVE-2026-42091 goshs has Cross-Origin Arbitrary File Write via Missing CSRF on PUT and Wildcard CORS CWE-352 6.5 Medium 2026-05-04
CVE-2026-40903 Goshs - ArtiPACKED Vulnerability – GitHub Actions Credential Persistence CWE-829 9.1 Critical 2026-04-21
CVE-2026-40885 goshs: Public collaborator feed leaks .goshs ACL credentials and enables unauthorized access CWE-200 9.1AI Critical AI 2026-04-21
CVE-2026-40884 goshs: Empty-username SFTP password authentication bypass in goshs CWE-306 9.8 Critical 2026-04-21
CVE-2026-40883 goshs: CSRF in state-changing GET routes enables authenticated file deletion and directory creation CWE-352 8.1AI High AI 2026-04-21
CVE-2026-40876 SFTP root escape via prefix-based path validation in goshs CWE-22 8.8AI High AI 2026-04-21
CVE-2026-40189 goshs has a file-based ACL authorization bypass in goshs state-changing routes CWE-862 9.8AI Critical AI 2026-04-10
CVE-2026-40188 goshs is Missing Write Protection for Parametric Data Values CWE-1314 7.7 High 2026-04-10
CVE-2026-35471 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs CWE-22 9.1AI Critical AI 2026-04-06
CVE-2026-35393 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs POST multipart upload CWE-22 9.8AI Critical AI 2026-04-06
CVE-2026-35392 goshs has an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs PUT Upload CWE-22 9.1AI Critical AI 2026-04-06
CVE-2026-34581 goshs has Auth Bypass via Share Token CWE-288 8.1 High 2026-04-02
CVE-2025-46816 goshs route not protected, allows command execution CWE-284 9.8AI Critical AI 2025-05-06

All 20 known CVE vulnerabilities affecting goshs with full Chinese analysis, references, and POCs where available.