github.com/forceu/gokapi
Activity
- Latest release
- 1y ago
- Total releases
- 31
- Cadence
- ~22 days
- Last 12 months
- 0
Reach
- Stars
- —
Details
- First release
- Mar 12, 2021
| Version | Released | |
|---|---|---|
v1.9.6
patch
10 CVEs
CVE-2026-30955
GO-2026-4698
GHSA-qwc6-vc2v-2ggj
Mar 16, 2026
Gokapi vulnerable to DoS in E2E Metadata Parser in github.com/forceu/gokapi Gokapi vulnerable to DoS in E2E Metadata Parser in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.4. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-30961
GO-2026-4695
GHSA-45vh-rpc8-hxpp
Mar 16, 2026
Gokapi's File Request MaxSize Limit Bypassed via Multi-Chunk Upload in github.com/forceu/gokapi Gokapi's File Request MaxSize Limit Bypassed via Multi-Chunk Upload in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.4. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-30943
GO-2026-4696
GHSA-j6jp-78w8-34x6
Mar 16, 2026
Gokapi vulnerable to Privilege Escalation in File Replace in github.com/forceu/gokapi Gokapi vulnerable to Privilege Escalation in File Replace in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.4. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-29084
GO-2026-4624
GHSA-hcff-qv74-7hr4
Mar 10, 2026
Gokapi has CSRF in Login Endpoint in github.com/forceu/gokapi Gokapi has CSRF in Login Endpoint in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-29060
GO-2026-4615
GHSA-m2hx-wjxc-9fp4
Mar 10, 2026
Gokapi has privilege escalation with auth token in github.com/forceu/gokapi Gokapi has privilege escalation with auth token in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28682
GO-2026-4613
GHSA-c36c-7pc2-f2ph
Mar 10, 2026
Gokapi has Data Leak in Upload Status Stream in github.com/forceu/gokapi Gokapi has Data Leak in Upload Status Stream in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-29061
GO-2026-4626
GHSA-q658-hfpg-35qc
Mar 10, 2026
Gokapi has privilege escalation via incomplete API-key permission revocation on user rank demotion in github.com/forceu/gokapi Gokapi has privilege escalation via incomplete API-key permission revocation on user rank demotion in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28683
GO-2026-4612
GHSA-3c22-5j5m-4jq7
Mar 10, 2026
Gokapi has Stored XSS in SVG Hotlinks in github.com/forceu/gokapi Gokapi has Stored XSS in SVG Hotlinks in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-48495
GO-2025-3736
GHSA-4xg4-54hm-9j77
Jun 03, 2025
Gokapi has stored XSS vulnerability in friendly name for API keys in github.com/forceu/gokapi Gokapi has stored XSS vulnerability in friendly name for API keys in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.0.0. References Updated Jun 03, 2025 · Source: OSV.dev
CVE-2025-48494
GO-2025-3737
GHSA-95rc-wc32-gm53
Jun 03, 2025
Gokapi vulnerable to stored XSS via uploading file with malicious file name in github.com/forceu/gokapi Gokapi vulnerable to stored XSS via uploading file with malicious file name in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.0.0. References Updated Jun 03, 2025 · Source: OSV.dev |
v1.9.6
patch
Dependencies (16)
+ 8 more |
|
v1.9.5
patch
10 CVEs
CVE-2026-30955
GO-2026-4698
GHSA-qwc6-vc2v-2ggj
Mar 16, 2026
Gokapi vulnerable to DoS in E2E Metadata Parser in github.com/forceu/gokapi Gokapi vulnerable to DoS in E2E Metadata Parser in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.4. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-30961
GO-2026-4695
GHSA-45vh-rpc8-hxpp
Mar 16, 2026
Gokapi's File Request MaxSize Limit Bypassed via Multi-Chunk Upload in github.com/forceu/gokapi Gokapi's File Request MaxSize Limit Bypassed via Multi-Chunk Upload in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.4. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-30943
GO-2026-4696
GHSA-j6jp-78w8-34x6
Mar 16, 2026
Gokapi vulnerable to Privilege Escalation in File Replace in github.com/forceu/gokapi Gokapi vulnerable to Privilege Escalation in File Replace in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.4. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-29084
GO-2026-4624
GHSA-hcff-qv74-7hr4
Mar 10, 2026
Gokapi has CSRF in Login Endpoint in github.com/forceu/gokapi Gokapi has CSRF in Login Endpoint in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-29060
GO-2026-4615
GHSA-m2hx-wjxc-9fp4
Mar 10, 2026
Gokapi has privilege escalation with auth token in github.com/forceu/gokapi Gokapi has privilege escalation with auth token in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28682
GO-2026-4613
GHSA-c36c-7pc2-f2ph
Mar 10, 2026
Gokapi has Data Leak in Upload Status Stream in github.com/forceu/gokapi Gokapi has Data Leak in Upload Status Stream in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-29061
GO-2026-4626
GHSA-q658-hfpg-35qc
Mar 10, 2026
Gokapi has privilege escalation via incomplete API-key permission revocation on user rank demotion in github.com/forceu/gokapi Gokapi has privilege escalation via incomplete API-key permission revocation on user rank demotion in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28683
GO-2026-4612
GHSA-3c22-5j5m-4jq7
Mar 10, 2026
Gokapi has Stored XSS in SVG Hotlinks in github.com/forceu/gokapi Gokapi has Stored XSS in SVG Hotlinks in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-48495
GO-2025-3736
GHSA-4xg4-54hm-9j77
Jun 03, 2025
Gokapi has stored XSS vulnerability in friendly name for API keys in github.com/forceu/gokapi Gokapi has stored XSS vulnerability in friendly name for API keys in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.0.0. References Updated Jun 03, 2025 · Source: OSV.dev
CVE-2025-48494
GO-2025-3737
GHSA-95rc-wc32-gm53
Jun 03, 2025
Gokapi vulnerable to stored XSS via uploading file with malicious file name in github.com/forceu/gokapi Gokapi vulnerable to stored XSS via uploading file with malicious file name in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.0.0. References Updated Jun 03, 2025 · Source: OSV.dev |
v1.9.5
patch
Dependencies (17)
+ 9 more |
|
v1.9.4
patch
10 CVEs
CVE-2026-30955
GO-2026-4698
GHSA-qwc6-vc2v-2ggj
Mar 16, 2026
Gokapi vulnerable to DoS in E2E Metadata Parser in github.com/forceu/gokapi Gokapi vulnerable to DoS in E2E Metadata Parser in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.4. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-30961
GO-2026-4695
GHSA-45vh-rpc8-hxpp
Mar 16, 2026
Gokapi's File Request MaxSize Limit Bypassed via Multi-Chunk Upload in github.com/forceu/gokapi Gokapi's File Request MaxSize Limit Bypassed via Multi-Chunk Upload in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.4. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-30943
GO-2026-4696
GHSA-j6jp-78w8-34x6
Mar 16, 2026
Gokapi vulnerable to Privilege Escalation in File Replace in github.com/forceu/gokapi Gokapi vulnerable to Privilege Escalation in File Replace in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.4. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-29084
GO-2026-4624
GHSA-hcff-qv74-7hr4
Mar 10, 2026
Gokapi has CSRF in Login Endpoint in github.com/forceu/gokapi Gokapi has CSRF in Login Endpoint in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-29060
GO-2026-4615
GHSA-m2hx-wjxc-9fp4
Mar 10, 2026
Gokapi has privilege escalation with auth token in github.com/forceu/gokapi Gokapi has privilege escalation with auth token in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28682
GO-2026-4613
GHSA-c36c-7pc2-f2ph
Mar 10, 2026
Gokapi has Data Leak in Upload Status Stream in github.com/forceu/gokapi Gokapi has Data Leak in Upload Status Stream in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-29061
GO-2026-4626
GHSA-q658-hfpg-35qc
Mar 10, 2026
Gokapi has privilege escalation via incomplete API-key permission revocation on user rank demotion in github.com/forceu/gokapi Gokapi has privilege escalation via incomplete API-key permission revocation on user rank demotion in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28683
GO-2026-4612
GHSA-3c22-5j5m-4jq7
Mar 10, 2026
Gokapi has Stored XSS in SVG Hotlinks in github.com/forceu/gokapi Gokapi has Stored XSS in SVG Hotlinks in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-48495
GO-2025-3736
GHSA-4xg4-54hm-9j77
Jun 03, 2025
Gokapi has stored XSS vulnerability in friendly name for API keys in github.com/forceu/gokapi Gokapi has stored XSS vulnerability in friendly name for API keys in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.0.0. References Updated Jun 03, 2025 · Source: OSV.dev
CVE-2025-48494
GO-2025-3737
GHSA-95rc-wc32-gm53
Jun 03, 2025
Gokapi vulnerable to stored XSS via uploading file with malicious file name in github.com/forceu/gokapi Gokapi vulnerable to stored XSS via uploading file with malicious file name in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.0.0. References Updated Jun 03, 2025 · Source: OSV.dev |
v1.9.4
patch
Dependencies (17)
+ 9 more |
|
v1.9.3
patch
10 CVEs
CVE-2026-30955
GO-2026-4698
GHSA-qwc6-vc2v-2ggj
Mar 16, 2026
Gokapi vulnerable to DoS in E2E Metadata Parser in github.com/forceu/gokapi Gokapi vulnerable to DoS in E2E Metadata Parser in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.4. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-30961
GO-2026-4695
GHSA-45vh-rpc8-hxpp
Mar 16, 2026
Gokapi's File Request MaxSize Limit Bypassed via Multi-Chunk Upload in github.com/forceu/gokapi Gokapi's File Request MaxSize Limit Bypassed via Multi-Chunk Upload in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.4. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-30943
GO-2026-4696
GHSA-j6jp-78w8-34x6
Mar 16, 2026
Gokapi vulnerable to Privilege Escalation in File Replace in github.com/forceu/gokapi Gokapi vulnerable to Privilege Escalation in File Replace in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.4. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-29084
GO-2026-4624
GHSA-hcff-qv74-7hr4
Mar 10, 2026
Gokapi has CSRF in Login Endpoint in github.com/forceu/gokapi Gokapi has CSRF in Login Endpoint in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-29060
GO-2026-4615
GHSA-m2hx-wjxc-9fp4
Mar 10, 2026
Gokapi has privilege escalation with auth token in github.com/forceu/gokapi Gokapi has privilege escalation with auth token in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28682
GO-2026-4613
GHSA-c36c-7pc2-f2ph
Mar 10, 2026
Gokapi has Data Leak in Upload Status Stream in github.com/forceu/gokapi Gokapi has Data Leak in Upload Status Stream in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-29061
GO-2026-4626
GHSA-q658-hfpg-35qc
Mar 10, 2026
Gokapi has privilege escalation via incomplete API-key permission revocation on user rank demotion in github.com/forceu/gokapi Gokapi has privilege escalation via incomplete API-key permission revocation on user rank demotion in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28683
GO-2026-4612
GHSA-3c22-5j5m-4jq7
Mar 10, 2026
Gokapi has Stored XSS in SVG Hotlinks in github.com/forceu/gokapi Gokapi has Stored XSS in SVG Hotlinks in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-48495
GO-2025-3736
GHSA-4xg4-54hm-9j77
Jun 03, 2025
Gokapi has stored XSS vulnerability in friendly name for API keys in github.com/forceu/gokapi Gokapi has stored XSS vulnerability in friendly name for API keys in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.0.0. References Updated Jun 03, 2025 · Source: OSV.dev
CVE-2025-48494
GO-2025-3737
GHSA-95rc-wc32-gm53
Jun 03, 2025
Gokapi vulnerable to stored XSS via uploading file with malicious file name in github.com/forceu/gokapi Gokapi vulnerable to stored XSS via uploading file with malicious file name in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.0.0. References Updated Jun 03, 2025 · Source: OSV.dev |
v1.9.3
patch
Dependencies (17)
+ 9 more |
|
v1.9.2
patch
10 CVEs
CVE-2026-30955
GO-2026-4698
GHSA-qwc6-vc2v-2ggj
Mar 16, 2026
Gokapi vulnerable to DoS in E2E Metadata Parser in github.com/forceu/gokapi Gokapi vulnerable to DoS in E2E Metadata Parser in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.4. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-30961
GO-2026-4695
GHSA-45vh-rpc8-hxpp
Mar 16, 2026
Gokapi's File Request MaxSize Limit Bypassed via Multi-Chunk Upload in github.com/forceu/gokapi Gokapi's File Request MaxSize Limit Bypassed via Multi-Chunk Upload in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.4. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-30943
GO-2026-4696
GHSA-j6jp-78w8-34x6
Mar 16, 2026
Gokapi vulnerable to Privilege Escalation in File Replace in github.com/forceu/gokapi Gokapi vulnerable to Privilege Escalation in File Replace in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.4. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-29084
GO-2026-4624
GHSA-hcff-qv74-7hr4
Mar 10, 2026
Gokapi has CSRF in Login Endpoint in github.com/forceu/gokapi Gokapi has CSRF in Login Endpoint in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-29060
GO-2026-4615
GHSA-m2hx-wjxc-9fp4
Mar 10, 2026
Gokapi has privilege escalation with auth token in github.com/forceu/gokapi Gokapi has privilege escalation with auth token in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28682
GO-2026-4613
GHSA-c36c-7pc2-f2ph
Mar 10, 2026
Gokapi has Data Leak in Upload Status Stream in github.com/forceu/gokapi Gokapi has Data Leak in Upload Status Stream in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-29061
GO-2026-4626
GHSA-q658-hfpg-35qc
Mar 10, 2026
Gokapi has privilege escalation via incomplete API-key permission revocation on user rank demotion in github.com/forceu/gokapi Gokapi has privilege escalation via incomplete API-key permission revocation on user rank demotion in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28683
GO-2026-4612
GHSA-3c22-5j5m-4jq7
Mar 10, 2026
Gokapi has Stored XSS in SVG Hotlinks in github.com/forceu/gokapi Gokapi has Stored XSS in SVG Hotlinks in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-48495
GO-2025-3736
GHSA-4xg4-54hm-9j77
Jun 03, 2025
Gokapi has stored XSS vulnerability in friendly name for API keys in github.com/forceu/gokapi Gokapi has stored XSS vulnerability in friendly name for API keys in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.0.0. References Updated Jun 03, 2025 · Source: OSV.dev
CVE-2025-48494
GO-2025-3737
GHSA-95rc-wc32-gm53
Jun 03, 2025
Gokapi vulnerable to stored XSS via uploading file with malicious file name in github.com/forceu/gokapi Gokapi vulnerable to stored XSS via uploading file with malicious file name in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.0.0. References Updated Jun 03, 2025 · Source: OSV.dev |
v1.9.2
patch
Dependencies (17)
+ 9 more |
|
v1.9.1
patch
10 CVEs
CVE-2026-30955
GO-2026-4698
GHSA-qwc6-vc2v-2ggj
Mar 16, 2026
Gokapi vulnerable to DoS in E2E Metadata Parser in github.com/forceu/gokapi Gokapi vulnerable to DoS in E2E Metadata Parser in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.4. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-30961
GO-2026-4695
GHSA-45vh-rpc8-hxpp
Mar 16, 2026
Gokapi's File Request MaxSize Limit Bypassed via Multi-Chunk Upload in github.com/forceu/gokapi Gokapi's File Request MaxSize Limit Bypassed via Multi-Chunk Upload in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.4. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-30943
GO-2026-4696
GHSA-j6jp-78w8-34x6
Mar 16, 2026
Gokapi vulnerable to Privilege Escalation in File Replace in github.com/forceu/gokapi Gokapi vulnerable to Privilege Escalation in File Replace in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.4. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-29084
GO-2026-4624
GHSA-hcff-qv74-7hr4
Mar 10, 2026
Gokapi has CSRF in Login Endpoint in github.com/forceu/gokapi Gokapi has CSRF in Login Endpoint in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-29060
GO-2026-4615
GHSA-m2hx-wjxc-9fp4
Mar 10, 2026
Gokapi has privilege escalation with auth token in github.com/forceu/gokapi Gokapi has privilege escalation with auth token in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28682
GO-2026-4613
GHSA-c36c-7pc2-f2ph
Mar 10, 2026
Gokapi has Data Leak in Upload Status Stream in github.com/forceu/gokapi Gokapi has Data Leak in Upload Status Stream in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-29061
GO-2026-4626
GHSA-q658-hfpg-35qc
Mar 10, 2026
Gokapi has privilege escalation via incomplete API-key permission revocation on user rank demotion in github.com/forceu/gokapi Gokapi has privilege escalation via incomplete API-key permission revocation on user rank demotion in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28683
GO-2026-4612
GHSA-3c22-5j5m-4jq7
Mar 10, 2026
Gokapi has Stored XSS in SVG Hotlinks in github.com/forceu/gokapi Gokapi has Stored XSS in SVG Hotlinks in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-48495
GO-2025-3736
GHSA-4xg4-54hm-9j77
Jun 03, 2025
Gokapi has stored XSS vulnerability in friendly name for API keys in github.com/forceu/gokapi Gokapi has stored XSS vulnerability in friendly name for API keys in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.0.0. References Updated Jun 03, 2025 · Source: OSV.dev
CVE-2025-48494
GO-2025-3737
GHSA-95rc-wc32-gm53
Jun 03, 2025
Gokapi vulnerable to stored XSS via uploading file with malicious file name in github.com/forceu/gokapi Gokapi vulnerable to stored XSS via uploading file with malicious file name in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.0.0. References Updated Jun 03, 2025 · Source: OSV.dev |
v1.9.1
patch
Dependencies (17)
+ 9 more |
|
v1.9.0
minor
10 CVEs
CVE-2026-30955
GO-2026-4698
GHSA-qwc6-vc2v-2ggj
Mar 16, 2026
Gokapi vulnerable to DoS in E2E Metadata Parser in github.com/forceu/gokapi Gokapi vulnerable to DoS in E2E Metadata Parser in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.4. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-30961
GO-2026-4695
GHSA-45vh-rpc8-hxpp
Mar 16, 2026
Gokapi's File Request MaxSize Limit Bypassed via Multi-Chunk Upload in github.com/forceu/gokapi Gokapi's File Request MaxSize Limit Bypassed via Multi-Chunk Upload in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.4. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-30943
GO-2026-4696
GHSA-j6jp-78w8-34x6
Mar 16, 2026
Gokapi vulnerable to Privilege Escalation in File Replace in github.com/forceu/gokapi Gokapi vulnerable to Privilege Escalation in File Replace in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.4. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-29084
GO-2026-4624
GHSA-hcff-qv74-7hr4
Mar 10, 2026
Gokapi has CSRF in Login Endpoint in github.com/forceu/gokapi Gokapi has CSRF in Login Endpoint in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-29060
GO-2026-4615
GHSA-m2hx-wjxc-9fp4
Mar 10, 2026
Gokapi has privilege escalation with auth token in github.com/forceu/gokapi Gokapi has privilege escalation with auth token in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28682
GO-2026-4613
GHSA-c36c-7pc2-f2ph
Mar 10, 2026
Gokapi has Data Leak in Upload Status Stream in github.com/forceu/gokapi Gokapi has Data Leak in Upload Status Stream in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-29061
GO-2026-4626
GHSA-q658-hfpg-35qc
Mar 10, 2026
Gokapi has privilege escalation via incomplete API-key permission revocation on user rank demotion in github.com/forceu/gokapi Gokapi has privilege escalation via incomplete API-key permission revocation on user rank demotion in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28683
GO-2026-4612
GHSA-3c22-5j5m-4jq7
Mar 10, 2026
Gokapi has Stored XSS in SVG Hotlinks in github.com/forceu/gokapi Gokapi has Stored XSS in SVG Hotlinks in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-48495
GO-2025-3736
GHSA-4xg4-54hm-9j77
Jun 03, 2025
Gokapi has stored XSS vulnerability in friendly name for API keys in github.com/forceu/gokapi Gokapi has stored XSS vulnerability in friendly name for API keys in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.0.0. References Updated Jun 03, 2025 · Source: OSV.dev
CVE-2025-48494
GO-2025-3737
GHSA-95rc-wc32-gm53
Jun 03, 2025
Gokapi vulnerable to stored XSS via uploading file with malicious file name in github.com/forceu/gokapi Gokapi vulnerable to stored XSS via uploading file with malicious file name in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.0.0. References Updated Jun 03, 2025 · Source: OSV.dev |
v1.9.0
minor
Dependencies (17)
+ 9 more |
|
v1.8.4
patch
10 CVEs
CVE-2026-30955
GO-2026-4698
GHSA-qwc6-vc2v-2ggj
Mar 16, 2026
Gokapi vulnerable to DoS in E2E Metadata Parser in github.com/forceu/gokapi Gokapi vulnerable to DoS in E2E Metadata Parser in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.4. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-30961
GO-2026-4695
GHSA-45vh-rpc8-hxpp
Mar 16, 2026
Gokapi's File Request MaxSize Limit Bypassed via Multi-Chunk Upload in github.com/forceu/gokapi Gokapi's File Request MaxSize Limit Bypassed via Multi-Chunk Upload in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.4. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-30943
GO-2026-4696
GHSA-j6jp-78w8-34x6
Mar 16, 2026
Gokapi vulnerable to Privilege Escalation in File Replace in github.com/forceu/gokapi Gokapi vulnerable to Privilege Escalation in File Replace in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.4. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-29084
GO-2026-4624
GHSA-hcff-qv74-7hr4
Mar 10, 2026
Gokapi has CSRF in Login Endpoint in github.com/forceu/gokapi Gokapi has CSRF in Login Endpoint in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-29060
GO-2026-4615
GHSA-m2hx-wjxc-9fp4
Mar 10, 2026
Gokapi has privilege escalation with auth token in github.com/forceu/gokapi Gokapi has privilege escalation with auth token in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28682
GO-2026-4613
GHSA-c36c-7pc2-f2ph
Mar 10, 2026
Gokapi has Data Leak in Upload Status Stream in github.com/forceu/gokapi Gokapi has Data Leak in Upload Status Stream in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-29061
GO-2026-4626
GHSA-q658-hfpg-35qc
Mar 10, 2026
Gokapi has privilege escalation via incomplete API-key permission revocation on user rank demotion in github.com/forceu/gokapi Gokapi has privilege escalation via incomplete API-key permission revocation on user rank demotion in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28683
GO-2026-4612
GHSA-3c22-5j5m-4jq7
Mar 10, 2026
Gokapi has Stored XSS in SVG Hotlinks in github.com/forceu/gokapi Gokapi has Stored XSS in SVG Hotlinks in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-48495
GO-2025-3736
GHSA-4xg4-54hm-9j77
Jun 03, 2025
Gokapi has stored XSS vulnerability in friendly name for API keys in github.com/forceu/gokapi Gokapi has stored XSS vulnerability in friendly name for API keys in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.0.0. References Updated Jun 03, 2025 · Source: OSV.dev
CVE-2025-48494
GO-2025-3737
GHSA-95rc-wc32-gm53
Jun 03, 2025
Gokapi vulnerable to stored XSS via uploading file with malicious file name in github.com/forceu/gokapi Gokapi vulnerable to stored XSS via uploading file with malicious file name in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.0.0. References Updated Jun 03, 2025 · Source: OSV.dev |
v1.8.4
patch
Dependencies (18)
+ 10 more |
|
v1.8.3
patch
10 CVEs
CVE-2026-30955
GO-2026-4698
GHSA-qwc6-vc2v-2ggj
Mar 16, 2026
Gokapi vulnerable to DoS in E2E Metadata Parser in github.com/forceu/gokapi Gokapi vulnerable to DoS in E2E Metadata Parser in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.4. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-30961
GO-2026-4695
GHSA-45vh-rpc8-hxpp
Mar 16, 2026
Gokapi's File Request MaxSize Limit Bypassed via Multi-Chunk Upload in github.com/forceu/gokapi Gokapi's File Request MaxSize Limit Bypassed via Multi-Chunk Upload in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.4. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-30943
GO-2026-4696
GHSA-j6jp-78w8-34x6
Mar 16, 2026
Gokapi vulnerable to Privilege Escalation in File Replace in github.com/forceu/gokapi Gokapi vulnerable to Privilege Escalation in File Replace in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.4. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-29084
GO-2026-4624
GHSA-hcff-qv74-7hr4
Mar 10, 2026
Gokapi has CSRF in Login Endpoint in github.com/forceu/gokapi Gokapi has CSRF in Login Endpoint in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-29060
GO-2026-4615
GHSA-m2hx-wjxc-9fp4
Mar 10, 2026
Gokapi has privilege escalation with auth token in github.com/forceu/gokapi Gokapi has privilege escalation with auth token in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28682
GO-2026-4613
GHSA-c36c-7pc2-f2ph
Mar 10, 2026
Gokapi has Data Leak in Upload Status Stream in github.com/forceu/gokapi Gokapi has Data Leak in Upload Status Stream in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-29061
GO-2026-4626
GHSA-q658-hfpg-35qc
Mar 10, 2026
Gokapi has privilege escalation via incomplete API-key permission revocation on user rank demotion in github.com/forceu/gokapi Gokapi has privilege escalation via incomplete API-key permission revocation on user rank demotion in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28683
GO-2026-4612
GHSA-3c22-5j5m-4jq7
Mar 10, 2026
Gokapi has Stored XSS in SVG Hotlinks in github.com/forceu/gokapi Gokapi has Stored XSS in SVG Hotlinks in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-48495
GO-2025-3736
GHSA-4xg4-54hm-9j77
Jun 03, 2025
Gokapi has stored XSS vulnerability in friendly name for API keys in github.com/forceu/gokapi Gokapi has stored XSS vulnerability in friendly name for API keys in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.0.0. References Updated Jun 03, 2025 · Source: OSV.dev
CVE-2025-48494
GO-2025-3737
GHSA-95rc-wc32-gm53
Jun 03, 2025
Gokapi vulnerable to stored XSS via uploading file with malicious file name in github.com/forceu/gokapi Gokapi vulnerable to stored XSS via uploading file with malicious file name in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.0.0. References Updated Jun 03, 2025 · Source: OSV.dev |
v1.8.3
patch
Dependencies (18)
+ 10 more |
|
v1.8.2
patch
10 CVEs
CVE-2026-30955
GO-2026-4698
GHSA-qwc6-vc2v-2ggj
Mar 16, 2026
Gokapi vulnerable to DoS in E2E Metadata Parser in github.com/forceu/gokapi Gokapi vulnerable to DoS in E2E Metadata Parser in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.4. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-30961
GO-2026-4695
GHSA-45vh-rpc8-hxpp
Mar 16, 2026
Gokapi's File Request MaxSize Limit Bypassed via Multi-Chunk Upload in github.com/forceu/gokapi Gokapi's File Request MaxSize Limit Bypassed via Multi-Chunk Upload in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.4. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-30943
GO-2026-4696
GHSA-j6jp-78w8-34x6
Mar 16, 2026
Gokapi vulnerable to Privilege Escalation in File Replace in github.com/forceu/gokapi Gokapi vulnerable to Privilege Escalation in File Replace in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.4. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-29084
GO-2026-4624
GHSA-hcff-qv74-7hr4
Mar 10, 2026
Gokapi has CSRF in Login Endpoint in github.com/forceu/gokapi Gokapi has CSRF in Login Endpoint in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-29060
GO-2026-4615
GHSA-m2hx-wjxc-9fp4
Mar 10, 2026
Gokapi has privilege escalation with auth token in github.com/forceu/gokapi Gokapi has privilege escalation with auth token in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28682
GO-2026-4613
GHSA-c36c-7pc2-f2ph
Mar 10, 2026
Gokapi has Data Leak in Upload Status Stream in github.com/forceu/gokapi Gokapi has Data Leak in Upload Status Stream in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-29061
GO-2026-4626
GHSA-q658-hfpg-35qc
Mar 10, 2026
Gokapi has privilege escalation via incomplete API-key permission revocation on user rank demotion in github.com/forceu/gokapi Gokapi has privilege escalation via incomplete API-key permission revocation on user rank demotion in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28683
GO-2026-4612
GHSA-3c22-5j5m-4jq7
Mar 10, 2026
Gokapi has Stored XSS in SVG Hotlinks in github.com/forceu/gokapi Gokapi has Stored XSS in SVG Hotlinks in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-48495
GO-2025-3736
GHSA-4xg4-54hm-9j77
Jun 03, 2025
Gokapi has stored XSS vulnerability in friendly name for API keys in github.com/forceu/gokapi Gokapi has stored XSS vulnerability in friendly name for API keys in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.0.0. References Updated Jun 03, 2025 · Source: OSV.dev
CVE-2025-48494
GO-2025-3737
GHSA-95rc-wc32-gm53
Jun 03, 2025
Gokapi vulnerable to stored XSS via uploading file with malicious file name in github.com/forceu/gokapi Gokapi vulnerable to stored XSS via uploading file with malicious file name in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.0.0. References Updated Jun 03, 2025 · Source: OSV.dev |
v1.8.2
patch
Dependencies (18)
+ 10 more |
|
v1.8.1
patch
10 CVEs
CVE-2026-30955
GO-2026-4698
GHSA-qwc6-vc2v-2ggj
Mar 16, 2026
Gokapi vulnerable to DoS in E2E Metadata Parser in github.com/forceu/gokapi Gokapi vulnerable to DoS in E2E Metadata Parser in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.4. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-30961
GO-2026-4695
GHSA-45vh-rpc8-hxpp
Mar 16, 2026
Gokapi's File Request MaxSize Limit Bypassed via Multi-Chunk Upload in github.com/forceu/gokapi Gokapi's File Request MaxSize Limit Bypassed via Multi-Chunk Upload in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.4. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-30943
GO-2026-4696
GHSA-j6jp-78w8-34x6
Mar 16, 2026
Gokapi vulnerable to Privilege Escalation in File Replace in github.com/forceu/gokapi Gokapi vulnerable to Privilege Escalation in File Replace in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.4. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-29084
GO-2026-4624
GHSA-hcff-qv74-7hr4
Mar 10, 2026
Gokapi has CSRF in Login Endpoint in github.com/forceu/gokapi Gokapi has CSRF in Login Endpoint in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-29060
GO-2026-4615
GHSA-m2hx-wjxc-9fp4
Mar 10, 2026
Gokapi has privilege escalation with auth token in github.com/forceu/gokapi Gokapi has privilege escalation with auth token in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28682
GO-2026-4613
GHSA-c36c-7pc2-f2ph
Mar 10, 2026
Gokapi has Data Leak in Upload Status Stream in github.com/forceu/gokapi Gokapi has Data Leak in Upload Status Stream in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-29061
GO-2026-4626
GHSA-q658-hfpg-35qc
Mar 10, 2026
Gokapi has privilege escalation via incomplete API-key permission revocation on user rank demotion in github.com/forceu/gokapi Gokapi has privilege escalation via incomplete API-key permission revocation on user rank demotion in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28683
GO-2026-4612
GHSA-3c22-5j5m-4jq7
Mar 10, 2026
Gokapi has Stored XSS in SVG Hotlinks in github.com/forceu/gokapi Gokapi has Stored XSS in SVG Hotlinks in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-48495
GO-2025-3736
GHSA-4xg4-54hm-9j77
Jun 03, 2025
Gokapi has stored XSS vulnerability in friendly name for API keys in github.com/forceu/gokapi Gokapi has stored XSS vulnerability in friendly name for API keys in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.0.0. References Updated Jun 03, 2025 · Source: OSV.dev
CVE-2025-48494
GO-2025-3737
GHSA-95rc-wc32-gm53
Jun 03, 2025
Gokapi vulnerable to stored XSS via uploading file with malicious file name in github.com/forceu/gokapi Gokapi vulnerable to stored XSS via uploading file with malicious file name in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.0.0. References Updated Jun 03, 2025 · Source: OSV.dev |
v1.8.1
patch
Dependencies (18)
+ 10 more |
|
v1.8.0
minor
10 CVEs
CVE-2026-30955
GO-2026-4698
GHSA-qwc6-vc2v-2ggj
Mar 16, 2026
Gokapi vulnerable to DoS in E2E Metadata Parser in github.com/forceu/gokapi Gokapi vulnerable to DoS in E2E Metadata Parser in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.4. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-30961
GO-2026-4695
GHSA-45vh-rpc8-hxpp
Mar 16, 2026
Gokapi's File Request MaxSize Limit Bypassed via Multi-Chunk Upload in github.com/forceu/gokapi Gokapi's File Request MaxSize Limit Bypassed via Multi-Chunk Upload in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.4. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-30943
GO-2026-4696
GHSA-j6jp-78w8-34x6
Mar 16, 2026
Gokapi vulnerable to Privilege Escalation in File Replace in github.com/forceu/gokapi Gokapi vulnerable to Privilege Escalation in File Replace in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.4. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-29084
GO-2026-4624
GHSA-hcff-qv74-7hr4
Mar 10, 2026
Gokapi has CSRF in Login Endpoint in github.com/forceu/gokapi Gokapi has CSRF in Login Endpoint in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-29060
GO-2026-4615
GHSA-m2hx-wjxc-9fp4
Mar 10, 2026
Gokapi has privilege escalation with auth token in github.com/forceu/gokapi Gokapi has privilege escalation with auth token in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28682
GO-2026-4613
GHSA-c36c-7pc2-f2ph
Mar 10, 2026
Gokapi has Data Leak in Upload Status Stream in github.com/forceu/gokapi Gokapi has Data Leak in Upload Status Stream in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-29061
GO-2026-4626
GHSA-q658-hfpg-35qc
Mar 10, 2026
Gokapi has privilege escalation via incomplete API-key permission revocation on user rank demotion in github.com/forceu/gokapi Gokapi has privilege escalation via incomplete API-key permission revocation on user rank demotion in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28683
GO-2026-4612
GHSA-3c22-5j5m-4jq7
Mar 10, 2026
Gokapi has Stored XSS in SVG Hotlinks in github.com/forceu/gokapi Gokapi has Stored XSS in SVG Hotlinks in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-48495
GO-2025-3736
GHSA-4xg4-54hm-9j77
Jun 03, 2025
Gokapi has stored XSS vulnerability in friendly name for API keys in github.com/forceu/gokapi Gokapi has stored XSS vulnerability in friendly name for API keys in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.0.0. References Updated Jun 03, 2025 · Source: OSV.dev
CVE-2025-48494
GO-2025-3737
GHSA-95rc-wc32-gm53
Jun 03, 2025
Gokapi vulnerable to stored XSS via uploading file with malicious file name in github.com/forceu/gokapi Gokapi vulnerable to stored XSS via uploading file with malicious file name in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.0.0. References Updated Jun 03, 2025 · Source: OSV.dev |
v1.8.0
minor
Dependencies (18)
+ 10 more |
|
v1.8.0-beta.0
pre
10 CVEs
CVE-2026-30955
GO-2026-4698
GHSA-qwc6-vc2v-2ggj
Mar 16, 2026
Gokapi vulnerable to DoS in E2E Metadata Parser in github.com/forceu/gokapi Gokapi vulnerable to DoS in E2E Metadata Parser in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.4. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-30961
GO-2026-4695
GHSA-45vh-rpc8-hxpp
Mar 16, 2026
Gokapi's File Request MaxSize Limit Bypassed via Multi-Chunk Upload in github.com/forceu/gokapi Gokapi's File Request MaxSize Limit Bypassed via Multi-Chunk Upload in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.4. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-30943
GO-2026-4696
GHSA-j6jp-78w8-34x6
Mar 16, 2026
Gokapi vulnerable to Privilege Escalation in File Replace in github.com/forceu/gokapi Gokapi vulnerable to Privilege Escalation in File Replace in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.4. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-29084
GO-2026-4624
GHSA-hcff-qv74-7hr4
Mar 10, 2026
Gokapi has CSRF in Login Endpoint in github.com/forceu/gokapi Gokapi has CSRF in Login Endpoint in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-29060
GO-2026-4615
GHSA-m2hx-wjxc-9fp4
Mar 10, 2026
Gokapi has privilege escalation with auth token in github.com/forceu/gokapi Gokapi has privilege escalation with auth token in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28682
GO-2026-4613
GHSA-c36c-7pc2-f2ph
Mar 10, 2026
Gokapi has Data Leak in Upload Status Stream in github.com/forceu/gokapi Gokapi has Data Leak in Upload Status Stream in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-29061
GO-2026-4626
GHSA-q658-hfpg-35qc
Mar 10, 2026
Gokapi has privilege escalation via incomplete API-key permission revocation on user rank demotion in github.com/forceu/gokapi Gokapi has privilege escalation via incomplete API-key permission revocation on user rank demotion in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28683
GO-2026-4612
GHSA-3c22-5j5m-4jq7
Mar 10, 2026
Gokapi has Stored XSS in SVG Hotlinks in github.com/forceu/gokapi Gokapi has Stored XSS in SVG Hotlinks in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-48495
GO-2025-3736
GHSA-4xg4-54hm-9j77
Jun 03, 2025
Gokapi has stored XSS vulnerability in friendly name for API keys in github.com/forceu/gokapi Gokapi has stored XSS vulnerability in friendly name for API keys in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.0.0. References Updated Jun 03, 2025 · Source: OSV.dev
CVE-2025-48494
GO-2025-3737
GHSA-95rc-wc32-gm53
Jun 03, 2025
Gokapi vulnerable to stored XSS via uploading file with malicious file name in github.com/forceu/gokapi Gokapi vulnerable to stored XSS via uploading file with malicious file name in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.0.0. References Updated Jun 03, 2025 · Source: OSV.dev |
v1.8.0-beta.0
pre
Dependencies (18)
+ 10 more |
|
v1.7.2
patch
10 CVEs
CVE-2026-30955
GO-2026-4698
GHSA-qwc6-vc2v-2ggj
Mar 16, 2026
Gokapi vulnerable to DoS in E2E Metadata Parser in github.com/forceu/gokapi Gokapi vulnerable to DoS in E2E Metadata Parser in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.4. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-30961
GO-2026-4695
GHSA-45vh-rpc8-hxpp
Mar 16, 2026
Gokapi's File Request MaxSize Limit Bypassed via Multi-Chunk Upload in github.com/forceu/gokapi Gokapi's File Request MaxSize Limit Bypassed via Multi-Chunk Upload in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.4. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-30943
GO-2026-4696
GHSA-j6jp-78w8-34x6
Mar 16, 2026
Gokapi vulnerable to Privilege Escalation in File Replace in github.com/forceu/gokapi Gokapi vulnerable to Privilege Escalation in File Replace in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.4. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-29084
GO-2026-4624
GHSA-hcff-qv74-7hr4
Mar 10, 2026
Gokapi has CSRF in Login Endpoint in github.com/forceu/gokapi Gokapi has CSRF in Login Endpoint in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-29060
GO-2026-4615
GHSA-m2hx-wjxc-9fp4
Mar 10, 2026
Gokapi has privilege escalation with auth token in github.com/forceu/gokapi Gokapi has privilege escalation with auth token in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28682
GO-2026-4613
GHSA-c36c-7pc2-f2ph
Mar 10, 2026
Gokapi has Data Leak in Upload Status Stream in github.com/forceu/gokapi Gokapi has Data Leak in Upload Status Stream in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-29061
GO-2026-4626
GHSA-q658-hfpg-35qc
Mar 10, 2026
Gokapi has privilege escalation via incomplete API-key permission revocation on user rank demotion in github.com/forceu/gokapi Gokapi has privilege escalation via incomplete API-key permission revocation on user rank demotion in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28683
GO-2026-4612
GHSA-3c22-5j5m-4jq7
Mar 10, 2026
Gokapi has Stored XSS in SVG Hotlinks in github.com/forceu/gokapi Gokapi has Stored XSS in SVG Hotlinks in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-48495
GO-2025-3736
GHSA-4xg4-54hm-9j77
Jun 03, 2025
Gokapi has stored XSS vulnerability in friendly name for API keys in github.com/forceu/gokapi Gokapi has stored XSS vulnerability in friendly name for API keys in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.0.0. References Updated Jun 03, 2025 · Source: OSV.dev
CVE-2025-48494
GO-2025-3737
GHSA-95rc-wc32-gm53
Jun 03, 2025
Gokapi vulnerable to stored XSS via uploading file with malicious file name in github.com/forceu/gokapi Gokapi vulnerable to stored XSS via uploading file with malicious file name in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.0.0. References Updated Jun 03, 2025 · Source: OSV.dev |
v1.7.2
patch
Dependencies (16)
+ 8 more |
|
v1.7.1
patch
10 CVEs
CVE-2026-30955
GO-2026-4698
GHSA-qwc6-vc2v-2ggj
Mar 16, 2026
Gokapi vulnerable to DoS in E2E Metadata Parser in github.com/forceu/gokapi Gokapi vulnerable to DoS in E2E Metadata Parser in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.4. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-30961
GO-2026-4695
GHSA-45vh-rpc8-hxpp
Mar 16, 2026
Gokapi's File Request MaxSize Limit Bypassed via Multi-Chunk Upload in github.com/forceu/gokapi Gokapi's File Request MaxSize Limit Bypassed via Multi-Chunk Upload in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.4. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-30943
GO-2026-4696
GHSA-j6jp-78w8-34x6
Mar 16, 2026
Gokapi vulnerable to Privilege Escalation in File Replace in github.com/forceu/gokapi Gokapi vulnerable to Privilege Escalation in File Replace in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.4. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-29084
GO-2026-4624
GHSA-hcff-qv74-7hr4
Mar 10, 2026
Gokapi has CSRF in Login Endpoint in github.com/forceu/gokapi Gokapi has CSRF in Login Endpoint in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-29060
GO-2026-4615
GHSA-m2hx-wjxc-9fp4
Mar 10, 2026
Gokapi has privilege escalation with auth token in github.com/forceu/gokapi Gokapi has privilege escalation with auth token in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28682
GO-2026-4613
GHSA-c36c-7pc2-f2ph
Mar 10, 2026
Gokapi has Data Leak in Upload Status Stream in github.com/forceu/gokapi Gokapi has Data Leak in Upload Status Stream in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-29061
GO-2026-4626
GHSA-q658-hfpg-35qc
Mar 10, 2026
Gokapi has privilege escalation via incomplete API-key permission revocation on user rank demotion in github.com/forceu/gokapi Gokapi has privilege escalation via incomplete API-key permission revocation on user rank demotion in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28683
GO-2026-4612
GHSA-3c22-5j5m-4jq7
Mar 10, 2026
Gokapi has Stored XSS in SVG Hotlinks in github.com/forceu/gokapi Gokapi has Stored XSS in SVG Hotlinks in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-48495
GO-2025-3736
GHSA-4xg4-54hm-9j77
Jun 03, 2025
Gokapi has stored XSS vulnerability in friendly name for API keys in github.com/forceu/gokapi Gokapi has stored XSS vulnerability in friendly name for API keys in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.0.0. References Updated Jun 03, 2025 · Source: OSV.dev
CVE-2025-48494
GO-2025-3737
GHSA-95rc-wc32-gm53
Jun 03, 2025
Gokapi vulnerable to stored XSS via uploading file with malicious file name in github.com/forceu/gokapi Gokapi vulnerable to stored XSS via uploading file with malicious file name in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.0.0. References Updated Jun 03, 2025 · Source: OSV.dev |
v1.7.1
patch
Dependencies (16)
+ 8 more |
|
v1.7.0
minor
10 CVEs
CVE-2026-30955
GO-2026-4698
GHSA-qwc6-vc2v-2ggj
Mar 16, 2026
Gokapi vulnerable to DoS in E2E Metadata Parser in github.com/forceu/gokapi Gokapi vulnerable to DoS in E2E Metadata Parser in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.4. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-30961
GO-2026-4695
GHSA-45vh-rpc8-hxpp
Mar 16, 2026
Gokapi's File Request MaxSize Limit Bypassed via Multi-Chunk Upload in github.com/forceu/gokapi Gokapi's File Request MaxSize Limit Bypassed via Multi-Chunk Upload in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.4. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-30943
GO-2026-4696
GHSA-j6jp-78w8-34x6
Mar 16, 2026
Gokapi vulnerable to Privilege Escalation in File Replace in github.com/forceu/gokapi Gokapi vulnerable to Privilege Escalation in File Replace in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.4. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-29084
GO-2026-4624
GHSA-hcff-qv74-7hr4
Mar 10, 2026
Gokapi has CSRF in Login Endpoint in github.com/forceu/gokapi Gokapi has CSRF in Login Endpoint in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-29060
GO-2026-4615
GHSA-m2hx-wjxc-9fp4
Mar 10, 2026
Gokapi has privilege escalation with auth token in github.com/forceu/gokapi Gokapi has privilege escalation with auth token in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28682
GO-2026-4613
GHSA-c36c-7pc2-f2ph
Mar 10, 2026
Gokapi has Data Leak in Upload Status Stream in github.com/forceu/gokapi Gokapi has Data Leak in Upload Status Stream in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-29061
GO-2026-4626
GHSA-q658-hfpg-35qc
Mar 10, 2026
Gokapi has privilege escalation via incomplete API-key permission revocation on user rank demotion in github.com/forceu/gokapi Gokapi has privilege escalation via incomplete API-key permission revocation on user rank demotion in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28683
GO-2026-4612
GHSA-3c22-5j5m-4jq7
Mar 10, 2026
Gokapi has Stored XSS in SVG Hotlinks in github.com/forceu/gokapi Gokapi has Stored XSS in SVG Hotlinks in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-48495
GO-2025-3736
GHSA-4xg4-54hm-9j77
Jun 03, 2025
Gokapi has stored XSS vulnerability in friendly name for API keys in github.com/forceu/gokapi Gokapi has stored XSS vulnerability in friendly name for API keys in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.0.0. References Updated Jun 03, 2025 · Source: OSV.dev
CVE-2025-48494
GO-2025-3737
GHSA-95rc-wc32-gm53
Jun 03, 2025
Gokapi vulnerable to stored XSS via uploading file with malicious file name in github.com/forceu/gokapi Gokapi vulnerable to stored XSS via uploading file with malicious file name in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.0.0. References Updated Jun 03, 2025 · Source: OSV.dev |
v1.7.0
minor
Dependencies (16)
+ 8 more |
|
v1.6.2
patch
10 CVEs
CVE-2026-30955
GO-2026-4698
GHSA-qwc6-vc2v-2ggj
Mar 16, 2026
Gokapi vulnerable to DoS in E2E Metadata Parser in github.com/forceu/gokapi Gokapi vulnerable to DoS in E2E Metadata Parser in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.4. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-30961
GO-2026-4695
GHSA-45vh-rpc8-hxpp
Mar 16, 2026
Gokapi's File Request MaxSize Limit Bypassed via Multi-Chunk Upload in github.com/forceu/gokapi Gokapi's File Request MaxSize Limit Bypassed via Multi-Chunk Upload in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.4. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-30943
GO-2026-4696
GHSA-j6jp-78w8-34x6
Mar 16, 2026
Gokapi vulnerable to Privilege Escalation in File Replace in github.com/forceu/gokapi Gokapi vulnerable to Privilege Escalation in File Replace in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.4. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-29084
GO-2026-4624
GHSA-hcff-qv74-7hr4
Mar 10, 2026
Gokapi has CSRF in Login Endpoint in github.com/forceu/gokapi Gokapi has CSRF in Login Endpoint in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-29060
GO-2026-4615
GHSA-m2hx-wjxc-9fp4
Mar 10, 2026
Gokapi has privilege escalation with auth token in github.com/forceu/gokapi Gokapi has privilege escalation with auth token in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28682
GO-2026-4613
GHSA-c36c-7pc2-f2ph
Mar 10, 2026
Gokapi has Data Leak in Upload Status Stream in github.com/forceu/gokapi Gokapi has Data Leak in Upload Status Stream in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-29061
GO-2026-4626
GHSA-q658-hfpg-35qc
Mar 10, 2026
Gokapi has privilege escalation via incomplete API-key permission revocation on user rank demotion in github.com/forceu/gokapi Gokapi has privilege escalation via incomplete API-key permission revocation on user rank demotion in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28683
GO-2026-4612
GHSA-3c22-5j5m-4jq7
Mar 10, 2026
Gokapi has Stored XSS in SVG Hotlinks in github.com/forceu/gokapi Gokapi has Stored XSS in SVG Hotlinks in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-48495
GO-2025-3736
GHSA-4xg4-54hm-9j77
Jun 03, 2025
Gokapi has stored XSS vulnerability in friendly name for API keys in github.com/forceu/gokapi Gokapi has stored XSS vulnerability in friendly name for API keys in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.0.0. References Updated Jun 03, 2025 · Source: OSV.dev
CVE-2025-48494
GO-2025-3737
GHSA-95rc-wc32-gm53
Jun 03, 2025
Gokapi vulnerable to stored XSS via uploading file with malicious file name in github.com/forceu/gokapi Gokapi vulnerable to stored XSS via uploading file with malicious file name in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.0.0. References Updated Jun 03, 2025 · Source: OSV.dev |
v1.6.2
patch
Dependencies (15)
+ 7 more |
|
v1.6.1
patch
10 CVEs
CVE-2026-30955
GO-2026-4698
GHSA-qwc6-vc2v-2ggj
Mar 16, 2026
Gokapi vulnerable to DoS in E2E Metadata Parser in github.com/forceu/gokapi Gokapi vulnerable to DoS in E2E Metadata Parser in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.4. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-30961
GO-2026-4695
GHSA-45vh-rpc8-hxpp
Mar 16, 2026
Gokapi's File Request MaxSize Limit Bypassed via Multi-Chunk Upload in github.com/forceu/gokapi Gokapi's File Request MaxSize Limit Bypassed via Multi-Chunk Upload in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.4. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-30943
GO-2026-4696
GHSA-j6jp-78w8-34x6
Mar 16, 2026
Gokapi vulnerable to Privilege Escalation in File Replace in github.com/forceu/gokapi Gokapi vulnerable to Privilege Escalation in File Replace in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.4. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-29084
GO-2026-4624
GHSA-hcff-qv74-7hr4
Mar 10, 2026
Gokapi has CSRF in Login Endpoint in github.com/forceu/gokapi Gokapi has CSRF in Login Endpoint in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-29060
GO-2026-4615
GHSA-m2hx-wjxc-9fp4
Mar 10, 2026
Gokapi has privilege escalation with auth token in github.com/forceu/gokapi Gokapi has privilege escalation with auth token in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28682
GO-2026-4613
GHSA-c36c-7pc2-f2ph
Mar 10, 2026
Gokapi has Data Leak in Upload Status Stream in github.com/forceu/gokapi Gokapi has Data Leak in Upload Status Stream in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-29061
GO-2026-4626
GHSA-q658-hfpg-35qc
Mar 10, 2026
Gokapi has privilege escalation via incomplete API-key permission revocation on user rank demotion in github.com/forceu/gokapi Gokapi has privilege escalation via incomplete API-key permission revocation on user rank demotion in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28683
GO-2026-4612
GHSA-3c22-5j5m-4jq7
Mar 10, 2026
Gokapi has Stored XSS in SVG Hotlinks in github.com/forceu/gokapi Gokapi has Stored XSS in SVG Hotlinks in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-48495
GO-2025-3736
GHSA-4xg4-54hm-9j77
Jun 03, 2025
Gokapi has stored XSS vulnerability in friendly name for API keys in github.com/forceu/gokapi Gokapi has stored XSS vulnerability in friendly name for API keys in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.0.0. References Updated Jun 03, 2025 · Source: OSV.dev
CVE-2025-48494
GO-2025-3737
GHSA-95rc-wc32-gm53
Jun 03, 2025
Gokapi vulnerable to stored XSS via uploading file with malicious file name in github.com/forceu/gokapi Gokapi vulnerable to stored XSS via uploading file with malicious file name in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.0.0. References Updated Jun 03, 2025 · Source: OSV.dev |
v1.6.1
patch
Dependencies (14)
+ 6 more |
|
v1.6.0
minor
10 CVEs
CVE-2026-30955
GO-2026-4698
GHSA-qwc6-vc2v-2ggj
Mar 16, 2026
Gokapi vulnerable to DoS in E2E Metadata Parser in github.com/forceu/gokapi Gokapi vulnerable to DoS in E2E Metadata Parser in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.4. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-30961
GO-2026-4695
GHSA-45vh-rpc8-hxpp
Mar 16, 2026
Gokapi's File Request MaxSize Limit Bypassed via Multi-Chunk Upload in github.com/forceu/gokapi Gokapi's File Request MaxSize Limit Bypassed via Multi-Chunk Upload in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.4. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-30943
GO-2026-4696
GHSA-j6jp-78w8-34x6
Mar 16, 2026
Gokapi vulnerable to Privilege Escalation in File Replace in github.com/forceu/gokapi Gokapi vulnerable to Privilege Escalation in File Replace in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.4. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-29084
GO-2026-4624
GHSA-hcff-qv74-7hr4
Mar 10, 2026
Gokapi has CSRF in Login Endpoint in github.com/forceu/gokapi Gokapi has CSRF in Login Endpoint in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-29060
GO-2026-4615
GHSA-m2hx-wjxc-9fp4
Mar 10, 2026
Gokapi has privilege escalation with auth token in github.com/forceu/gokapi Gokapi has privilege escalation with auth token in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28682
GO-2026-4613
GHSA-c36c-7pc2-f2ph
Mar 10, 2026
Gokapi has Data Leak in Upload Status Stream in github.com/forceu/gokapi Gokapi has Data Leak in Upload Status Stream in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-29061
GO-2026-4626
GHSA-q658-hfpg-35qc
Mar 10, 2026
Gokapi has privilege escalation via incomplete API-key permission revocation on user rank demotion in github.com/forceu/gokapi Gokapi has privilege escalation via incomplete API-key permission revocation on user rank demotion in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28683
GO-2026-4612
GHSA-3c22-5j5m-4jq7
Mar 10, 2026
Gokapi has Stored XSS in SVG Hotlinks in github.com/forceu/gokapi Gokapi has Stored XSS in SVG Hotlinks in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-48495
GO-2025-3736
GHSA-4xg4-54hm-9j77
Jun 03, 2025
Gokapi has stored XSS vulnerability in friendly name for API keys in github.com/forceu/gokapi Gokapi has stored XSS vulnerability in friendly name for API keys in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.0.0. References Updated Jun 03, 2025 · Source: OSV.dev
CVE-2025-48494
GO-2025-3737
GHSA-95rc-wc32-gm53
Jun 03, 2025
Gokapi vulnerable to stored XSS via uploading file with malicious file name in github.com/forceu/gokapi Gokapi vulnerable to stored XSS via uploading file with malicious file name in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.0.0. References Updated Jun 03, 2025 · Source: OSV.dev |
v1.6.0
minor
Dependencies (14)
+ 6 more |
|
v1.6.0-beta1
pre
10 CVEs
CVE-2026-30955
GO-2026-4698
GHSA-qwc6-vc2v-2ggj
Mar 16, 2026
Gokapi vulnerable to DoS in E2E Metadata Parser in github.com/forceu/gokapi Gokapi vulnerable to DoS in E2E Metadata Parser in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.4. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-30961
GO-2026-4695
GHSA-45vh-rpc8-hxpp
Mar 16, 2026
Gokapi's File Request MaxSize Limit Bypassed via Multi-Chunk Upload in github.com/forceu/gokapi Gokapi's File Request MaxSize Limit Bypassed via Multi-Chunk Upload in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.4. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-30943
GO-2026-4696
GHSA-j6jp-78w8-34x6
Mar 16, 2026
Gokapi vulnerable to Privilege Escalation in File Replace in github.com/forceu/gokapi Gokapi vulnerable to Privilege Escalation in File Replace in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.4. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-29084
GO-2026-4624
GHSA-hcff-qv74-7hr4
Mar 10, 2026
Gokapi has CSRF in Login Endpoint in github.com/forceu/gokapi Gokapi has CSRF in Login Endpoint in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-29060
GO-2026-4615
GHSA-m2hx-wjxc-9fp4
Mar 10, 2026
Gokapi has privilege escalation with auth token in github.com/forceu/gokapi Gokapi has privilege escalation with auth token in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28682
GO-2026-4613
GHSA-c36c-7pc2-f2ph
Mar 10, 2026
Gokapi has Data Leak in Upload Status Stream in github.com/forceu/gokapi Gokapi has Data Leak in Upload Status Stream in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-29061
GO-2026-4626
GHSA-q658-hfpg-35qc
Mar 10, 2026
Gokapi has privilege escalation via incomplete API-key permission revocation on user rank demotion in github.com/forceu/gokapi Gokapi has privilege escalation via incomplete API-key permission revocation on user rank demotion in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28683
GO-2026-4612
GHSA-3c22-5j5m-4jq7
Mar 10, 2026
Gokapi has Stored XSS in SVG Hotlinks in github.com/forceu/gokapi Gokapi has Stored XSS in SVG Hotlinks in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-48495
GO-2025-3736
GHSA-4xg4-54hm-9j77
Jun 03, 2025
Gokapi has stored XSS vulnerability in friendly name for API keys in github.com/forceu/gokapi Gokapi has stored XSS vulnerability in friendly name for API keys in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.0.0. References Updated Jun 03, 2025 · Source: OSV.dev
CVE-2025-48494
GO-2025-3737
GHSA-95rc-wc32-gm53
Jun 03, 2025
Gokapi vulnerable to stored XSS via uploading file with malicious file name in github.com/forceu/gokapi Gokapi vulnerable to stored XSS via uploading file with malicious file name in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.0.0. References Updated Jun 03, 2025 · Source: OSV.dev |
v1.6.0-beta1
pre
Dependencies (14)
+ 6 more |
|
v1.5.2
patch
10 CVEs
CVE-2026-30955
GO-2026-4698
GHSA-qwc6-vc2v-2ggj
Mar 16, 2026
Gokapi vulnerable to DoS in E2E Metadata Parser in github.com/forceu/gokapi Gokapi vulnerable to DoS in E2E Metadata Parser in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.4. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-30961
GO-2026-4695
GHSA-45vh-rpc8-hxpp
Mar 16, 2026
Gokapi's File Request MaxSize Limit Bypassed via Multi-Chunk Upload in github.com/forceu/gokapi Gokapi's File Request MaxSize Limit Bypassed via Multi-Chunk Upload in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.4. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-30943
GO-2026-4696
GHSA-j6jp-78w8-34x6
Mar 16, 2026
Gokapi vulnerable to Privilege Escalation in File Replace in github.com/forceu/gokapi Gokapi vulnerable to Privilege Escalation in File Replace in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.4. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-29084
GO-2026-4624
GHSA-hcff-qv74-7hr4
Mar 10, 2026
Gokapi has CSRF in Login Endpoint in github.com/forceu/gokapi Gokapi has CSRF in Login Endpoint in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-29060
GO-2026-4615
GHSA-m2hx-wjxc-9fp4
Mar 10, 2026
Gokapi has privilege escalation with auth token in github.com/forceu/gokapi Gokapi has privilege escalation with auth token in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28682
GO-2026-4613
GHSA-c36c-7pc2-f2ph
Mar 10, 2026
Gokapi has Data Leak in Upload Status Stream in github.com/forceu/gokapi Gokapi has Data Leak in Upload Status Stream in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-29061
GO-2026-4626
GHSA-q658-hfpg-35qc
Mar 10, 2026
Gokapi has privilege escalation via incomplete API-key permission revocation on user rank demotion in github.com/forceu/gokapi Gokapi has privilege escalation via incomplete API-key permission revocation on user rank demotion in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28683
GO-2026-4612
GHSA-3c22-5j5m-4jq7
Mar 10, 2026
Gokapi has Stored XSS in SVG Hotlinks in github.com/forceu/gokapi Gokapi has Stored XSS in SVG Hotlinks in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-48495
GO-2025-3736
GHSA-4xg4-54hm-9j77
Jun 03, 2025
Gokapi has stored XSS vulnerability in friendly name for API keys in github.com/forceu/gokapi Gokapi has stored XSS vulnerability in friendly name for API keys in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.0.0. References Updated Jun 03, 2025 · Source: OSV.dev
CVE-2025-48494
GO-2025-3737
GHSA-95rc-wc32-gm53
Jun 03, 2025
Gokapi vulnerable to stored XSS via uploading file with malicious file name in github.com/forceu/gokapi Gokapi vulnerable to stored XSS via uploading file with malicious file name in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.0.0. References Updated Jun 03, 2025 · Source: OSV.dev |
v1.5.2
patch
Dependencies (11)
+ 3 more |
|
v1.5.1
patch
10 CVEs
CVE-2026-30955
GO-2026-4698
GHSA-qwc6-vc2v-2ggj
Mar 16, 2026
Gokapi vulnerable to DoS in E2E Metadata Parser in github.com/forceu/gokapi Gokapi vulnerable to DoS in E2E Metadata Parser in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.4. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-30961
GO-2026-4695
GHSA-45vh-rpc8-hxpp
Mar 16, 2026
Gokapi's File Request MaxSize Limit Bypassed via Multi-Chunk Upload in github.com/forceu/gokapi Gokapi's File Request MaxSize Limit Bypassed via Multi-Chunk Upload in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.4. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-30943
GO-2026-4696
GHSA-j6jp-78w8-34x6
Mar 16, 2026
Gokapi vulnerable to Privilege Escalation in File Replace in github.com/forceu/gokapi Gokapi vulnerable to Privilege Escalation in File Replace in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.4. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-29084
GO-2026-4624
GHSA-hcff-qv74-7hr4
Mar 10, 2026
Gokapi has CSRF in Login Endpoint in github.com/forceu/gokapi Gokapi has CSRF in Login Endpoint in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-29060
GO-2026-4615
GHSA-m2hx-wjxc-9fp4
Mar 10, 2026
Gokapi has privilege escalation with auth token in github.com/forceu/gokapi Gokapi has privilege escalation with auth token in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28682
GO-2026-4613
GHSA-c36c-7pc2-f2ph
Mar 10, 2026
Gokapi has Data Leak in Upload Status Stream in github.com/forceu/gokapi Gokapi has Data Leak in Upload Status Stream in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-29061
GO-2026-4626
GHSA-q658-hfpg-35qc
Mar 10, 2026
Gokapi has privilege escalation via incomplete API-key permission revocation on user rank demotion in github.com/forceu/gokapi Gokapi has privilege escalation via incomplete API-key permission revocation on user rank demotion in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28683
GO-2026-4612
GHSA-3c22-5j5m-4jq7
Mar 10, 2026
Gokapi has Stored XSS in SVG Hotlinks in github.com/forceu/gokapi Gokapi has Stored XSS in SVG Hotlinks in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-48495
GO-2025-3736
GHSA-4xg4-54hm-9j77
Jun 03, 2025
Gokapi has stored XSS vulnerability in friendly name for API keys in github.com/forceu/gokapi Gokapi has stored XSS vulnerability in friendly name for API keys in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.0.0. References Updated Jun 03, 2025 · Source: OSV.dev
CVE-2025-48494
GO-2025-3737
GHSA-95rc-wc32-gm53
Jun 03, 2025
Gokapi vulnerable to stored XSS via uploading file with malicious file name in github.com/forceu/gokapi Gokapi vulnerable to stored XSS via uploading file with malicious file name in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.0.0. References Updated Jun 03, 2025 · Source: OSV.dev |
v1.5.1
patch
Dependencies (11)
+ 3 more |
|
v1.5.0
minor
10 CVEs
CVE-2026-30955
GO-2026-4698
GHSA-qwc6-vc2v-2ggj
Mar 16, 2026
Gokapi vulnerable to DoS in E2E Metadata Parser in github.com/forceu/gokapi Gokapi vulnerable to DoS in E2E Metadata Parser in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.4. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-30961
GO-2026-4695
GHSA-45vh-rpc8-hxpp
Mar 16, 2026
Gokapi's File Request MaxSize Limit Bypassed via Multi-Chunk Upload in github.com/forceu/gokapi Gokapi's File Request MaxSize Limit Bypassed via Multi-Chunk Upload in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.4. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-30943
GO-2026-4696
GHSA-j6jp-78w8-34x6
Mar 16, 2026
Gokapi vulnerable to Privilege Escalation in File Replace in github.com/forceu/gokapi Gokapi vulnerable to Privilege Escalation in File Replace in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.4. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-29084
GO-2026-4624
GHSA-hcff-qv74-7hr4
Mar 10, 2026
Gokapi has CSRF in Login Endpoint in github.com/forceu/gokapi Gokapi has CSRF in Login Endpoint in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-29060
GO-2026-4615
GHSA-m2hx-wjxc-9fp4
Mar 10, 2026
Gokapi has privilege escalation with auth token in github.com/forceu/gokapi Gokapi has privilege escalation with auth token in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28682
GO-2026-4613
GHSA-c36c-7pc2-f2ph
Mar 10, 2026
Gokapi has Data Leak in Upload Status Stream in github.com/forceu/gokapi Gokapi has Data Leak in Upload Status Stream in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-29061
GO-2026-4626
GHSA-q658-hfpg-35qc
Mar 10, 2026
Gokapi has privilege escalation via incomplete API-key permission revocation on user rank demotion in github.com/forceu/gokapi Gokapi has privilege escalation via incomplete API-key permission revocation on user rank demotion in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28683
GO-2026-4612
GHSA-3c22-5j5m-4jq7
Mar 10, 2026
Gokapi has Stored XSS in SVG Hotlinks in github.com/forceu/gokapi Gokapi has Stored XSS in SVG Hotlinks in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-48495
GO-2025-3736
GHSA-4xg4-54hm-9j77
Jun 03, 2025
Gokapi has stored XSS vulnerability in friendly name for API keys in github.com/forceu/gokapi Gokapi has stored XSS vulnerability in friendly name for API keys in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.0.0. References Updated Jun 03, 2025 · Source: OSV.dev
CVE-2025-48494
GO-2025-3737
GHSA-95rc-wc32-gm53
Jun 03, 2025
Gokapi vulnerable to stored XSS via uploading file with malicious file name in github.com/forceu/gokapi Gokapi vulnerable to stored XSS via uploading file with malicious file name in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.0.0. References Updated Jun 03, 2025 · Source: OSV.dev |
v1.5.0
minor
Dependencies (11)
+ 3 more |
|
v1.5.0-beta1
pre
10 CVEs
CVE-2026-30955
GO-2026-4698
GHSA-qwc6-vc2v-2ggj
Mar 16, 2026
Gokapi vulnerable to DoS in E2E Metadata Parser in github.com/forceu/gokapi Gokapi vulnerable to DoS in E2E Metadata Parser in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.4. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-30961
GO-2026-4695
GHSA-45vh-rpc8-hxpp
Mar 16, 2026
Gokapi's File Request MaxSize Limit Bypassed via Multi-Chunk Upload in github.com/forceu/gokapi Gokapi's File Request MaxSize Limit Bypassed via Multi-Chunk Upload in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.4. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-30943
GO-2026-4696
GHSA-j6jp-78w8-34x6
Mar 16, 2026
Gokapi vulnerable to Privilege Escalation in File Replace in github.com/forceu/gokapi Gokapi vulnerable to Privilege Escalation in File Replace in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.4. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-29084
GO-2026-4624
GHSA-hcff-qv74-7hr4
Mar 10, 2026
Gokapi has CSRF in Login Endpoint in github.com/forceu/gokapi Gokapi has CSRF in Login Endpoint in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-29060
GO-2026-4615
GHSA-m2hx-wjxc-9fp4
Mar 10, 2026
Gokapi has privilege escalation with auth token in github.com/forceu/gokapi Gokapi has privilege escalation with auth token in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28682
GO-2026-4613
GHSA-c36c-7pc2-f2ph
Mar 10, 2026
Gokapi has Data Leak in Upload Status Stream in github.com/forceu/gokapi Gokapi has Data Leak in Upload Status Stream in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-29061
GO-2026-4626
GHSA-q658-hfpg-35qc
Mar 10, 2026
Gokapi has privilege escalation via incomplete API-key permission revocation on user rank demotion in github.com/forceu/gokapi Gokapi has privilege escalation via incomplete API-key permission revocation on user rank demotion in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28683
GO-2026-4612
GHSA-3c22-5j5m-4jq7
Mar 10, 2026
Gokapi has Stored XSS in SVG Hotlinks in github.com/forceu/gokapi Gokapi has Stored XSS in SVG Hotlinks in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-48495
GO-2025-3736
GHSA-4xg4-54hm-9j77
Jun 03, 2025
Gokapi has stored XSS vulnerability in friendly name for API keys in github.com/forceu/gokapi Gokapi has stored XSS vulnerability in friendly name for API keys in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.0.0. References Updated Jun 03, 2025 · Source: OSV.dev
CVE-2025-48494
GO-2025-3737
GHSA-95rc-wc32-gm53
Jun 03, 2025
Gokapi vulnerable to stored XSS via uploading file with malicious file name in github.com/forceu/gokapi Gokapi vulnerable to stored XSS via uploading file with malicious file name in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.0.0. References Updated Jun 03, 2025 · Source: OSV.dev |
v1.5.0-beta1
pre
Dependencies (11)
+ 3 more |
|
v1.3.1
patch
10 CVEs
CVE-2026-30955
GO-2026-4698
GHSA-qwc6-vc2v-2ggj
Mar 16, 2026
Gokapi vulnerable to DoS in E2E Metadata Parser in github.com/forceu/gokapi Gokapi vulnerable to DoS in E2E Metadata Parser in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.4. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-30961
GO-2026-4695
GHSA-45vh-rpc8-hxpp
Mar 16, 2026
Gokapi's File Request MaxSize Limit Bypassed via Multi-Chunk Upload in github.com/forceu/gokapi Gokapi's File Request MaxSize Limit Bypassed via Multi-Chunk Upload in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.4. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-30943
GO-2026-4696
GHSA-j6jp-78w8-34x6
Mar 16, 2026
Gokapi vulnerable to Privilege Escalation in File Replace in github.com/forceu/gokapi Gokapi vulnerable to Privilege Escalation in File Replace in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.4. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-29084
GO-2026-4624
GHSA-hcff-qv74-7hr4
Mar 10, 2026
Gokapi has CSRF in Login Endpoint in github.com/forceu/gokapi Gokapi has CSRF in Login Endpoint in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-29060
GO-2026-4615
GHSA-m2hx-wjxc-9fp4
Mar 10, 2026
Gokapi has privilege escalation with auth token in github.com/forceu/gokapi Gokapi has privilege escalation with auth token in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28682
GO-2026-4613
GHSA-c36c-7pc2-f2ph
Mar 10, 2026
Gokapi has Data Leak in Upload Status Stream in github.com/forceu/gokapi Gokapi has Data Leak in Upload Status Stream in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-29061
GO-2026-4626
GHSA-q658-hfpg-35qc
Mar 10, 2026
Gokapi has privilege escalation via incomplete API-key permission revocation on user rank demotion in github.com/forceu/gokapi Gokapi has privilege escalation via incomplete API-key permission revocation on user rank demotion in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28683
GO-2026-4612
GHSA-3c22-5j5m-4jq7
Mar 10, 2026
Gokapi has Stored XSS in SVG Hotlinks in github.com/forceu/gokapi Gokapi has Stored XSS in SVG Hotlinks in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-48495
GO-2025-3736
GHSA-4xg4-54hm-9j77
Jun 03, 2025
Gokapi has stored XSS vulnerability in friendly name for API keys in github.com/forceu/gokapi Gokapi has stored XSS vulnerability in friendly name for API keys in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.0.0. References Updated Jun 03, 2025 · Source: OSV.dev
CVE-2025-48494
GO-2025-3737
GHSA-95rc-wc32-gm53
Jun 03, 2025
Gokapi vulnerable to stored XSS via uploading file with malicious file name in github.com/forceu/gokapi Gokapi vulnerable to stored XSS via uploading file with malicious file name in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.0.0. References Updated Jun 03, 2025 · Source: OSV.dev |
v1.3.1
patch
Dependencies (4)
|
|
v1.3.0
minor
10 CVEs
CVE-2026-30955
GO-2026-4698
GHSA-qwc6-vc2v-2ggj
Mar 16, 2026
Gokapi vulnerable to DoS in E2E Metadata Parser in github.com/forceu/gokapi Gokapi vulnerable to DoS in E2E Metadata Parser in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.4. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-30961
GO-2026-4695
GHSA-45vh-rpc8-hxpp
Mar 16, 2026
Gokapi's File Request MaxSize Limit Bypassed via Multi-Chunk Upload in github.com/forceu/gokapi Gokapi's File Request MaxSize Limit Bypassed via Multi-Chunk Upload in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.4. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-30943
GO-2026-4696
GHSA-j6jp-78w8-34x6
Mar 16, 2026
Gokapi vulnerable to Privilege Escalation in File Replace in github.com/forceu/gokapi Gokapi vulnerable to Privilege Escalation in File Replace in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.4. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-29084
GO-2026-4624
GHSA-hcff-qv74-7hr4
Mar 10, 2026
Gokapi has CSRF in Login Endpoint in github.com/forceu/gokapi Gokapi has CSRF in Login Endpoint in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-29060
GO-2026-4615
GHSA-m2hx-wjxc-9fp4
Mar 10, 2026
Gokapi has privilege escalation with auth token in github.com/forceu/gokapi Gokapi has privilege escalation with auth token in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28682
GO-2026-4613
GHSA-c36c-7pc2-f2ph
Mar 10, 2026
Gokapi has Data Leak in Upload Status Stream in github.com/forceu/gokapi Gokapi has Data Leak in Upload Status Stream in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-29061
GO-2026-4626
GHSA-q658-hfpg-35qc
Mar 10, 2026
Gokapi has privilege escalation via incomplete API-key permission revocation on user rank demotion in github.com/forceu/gokapi Gokapi has privilege escalation via incomplete API-key permission revocation on user rank demotion in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28683
GO-2026-4612
GHSA-3c22-5j5m-4jq7
Mar 10, 2026
Gokapi has Stored XSS in SVG Hotlinks in github.com/forceu/gokapi Gokapi has Stored XSS in SVG Hotlinks in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-48495
GO-2025-3736
GHSA-4xg4-54hm-9j77
Jun 03, 2025
Gokapi has stored XSS vulnerability in friendly name for API keys in github.com/forceu/gokapi Gokapi has stored XSS vulnerability in friendly name for API keys in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.0.0. References Updated Jun 03, 2025 · Source: OSV.dev
CVE-2025-48494
GO-2025-3737
GHSA-95rc-wc32-gm53
Jun 03, 2025
Gokapi vulnerable to stored XSS via uploading file with malicious file name in github.com/forceu/gokapi Gokapi vulnerable to stored XSS via uploading file with malicious file name in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.0.0. References Updated Jun 03, 2025 · Source: OSV.dev |
v1.3.0
minor
Dependencies (4)
|
|
v1.2.0
minor
10 CVEs
CVE-2026-30955
GO-2026-4698
GHSA-qwc6-vc2v-2ggj
Mar 16, 2026
Gokapi vulnerable to DoS in E2E Metadata Parser in github.com/forceu/gokapi Gokapi vulnerable to DoS in E2E Metadata Parser in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.4. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-30961
GO-2026-4695
GHSA-45vh-rpc8-hxpp
Mar 16, 2026
Gokapi's File Request MaxSize Limit Bypassed via Multi-Chunk Upload in github.com/forceu/gokapi Gokapi's File Request MaxSize Limit Bypassed via Multi-Chunk Upload in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.4. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-30943
GO-2026-4696
GHSA-j6jp-78w8-34x6
Mar 16, 2026
Gokapi vulnerable to Privilege Escalation in File Replace in github.com/forceu/gokapi Gokapi vulnerable to Privilege Escalation in File Replace in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.4. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-29084
GO-2026-4624
GHSA-hcff-qv74-7hr4
Mar 10, 2026
Gokapi has CSRF in Login Endpoint in github.com/forceu/gokapi Gokapi has CSRF in Login Endpoint in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-29060
GO-2026-4615
GHSA-m2hx-wjxc-9fp4
Mar 10, 2026
Gokapi has privilege escalation with auth token in github.com/forceu/gokapi Gokapi has privilege escalation with auth token in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28682
GO-2026-4613
GHSA-c36c-7pc2-f2ph
Mar 10, 2026
Gokapi has Data Leak in Upload Status Stream in github.com/forceu/gokapi Gokapi has Data Leak in Upload Status Stream in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-29061
GO-2026-4626
GHSA-q658-hfpg-35qc
Mar 10, 2026
Gokapi has privilege escalation via incomplete API-key permission revocation on user rank demotion in github.com/forceu/gokapi Gokapi has privilege escalation via incomplete API-key permission revocation on user rank demotion in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28683
GO-2026-4612
GHSA-3c22-5j5m-4jq7
Mar 10, 2026
Gokapi has Stored XSS in SVG Hotlinks in github.com/forceu/gokapi Gokapi has Stored XSS in SVG Hotlinks in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-48495
GO-2025-3736
GHSA-4xg4-54hm-9j77
Jun 03, 2025
Gokapi has stored XSS vulnerability in friendly name for API keys in github.com/forceu/gokapi Gokapi has stored XSS vulnerability in friendly name for API keys in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.0.0. References Updated Jun 03, 2025 · Source: OSV.dev
CVE-2025-48494
GO-2025-3737
GHSA-95rc-wc32-gm53
Jun 03, 2025
Gokapi vulnerable to stored XSS via uploading file with malicious file name in github.com/forceu/gokapi Gokapi vulnerable to stored XSS via uploading file with malicious file name in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.0.0. References Updated Jun 03, 2025 · Source: OSV.dev |
v1.2.0
minor
Dependencies (1)
|
|
v1.1.3
patch
10 CVEs
CVE-2026-30955
GO-2026-4698
GHSA-qwc6-vc2v-2ggj
Mar 16, 2026
Gokapi vulnerable to DoS in E2E Metadata Parser in github.com/forceu/gokapi Gokapi vulnerable to DoS in E2E Metadata Parser in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.4. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-30961
GO-2026-4695
GHSA-45vh-rpc8-hxpp
Mar 16, 2026
Gokapi's File Request MaxSize Limit Bypassed via Multi-Chunk Upload in github.com/forceu/gokapi Gokapi's File Request MaxSize Limit Bypassed via Multi-Chunk Upload in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.4. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-30943
GO-2026-4696
GHSA-j6jp-78w8-34x6
Mar 16, 2026
Gokapi vulnerable to Privilege Escalation in File Replace in github.com/forceu/gokapi Gokapi vulnerable to Privilege Escalation in File Replace in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.4. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-29084
GO-2026-4624
GHSA-hcff-qv74-7hr4
Mar 10, 2026
Gokapi has CSRF in Login Endpoint in github.com/forceu/gokapi Gokapi has CSRF in Login Endpoint in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-29060
GO-2026-4615
GHSA-m2hx-wjxc-9fp4
Mar 10, 2026
Gokapi has privilege escalation with auth token in github.com/forceu/gokapi Gokapi has privilege escalation with auth token in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28682
GO-2026-4613
GHSA-c36c-7pc2-f2ph
Mar 10, 2026
Gokapi has Data Leak in Upload Status Stream in github.com/forceu/gokapi Gokapi has Data Leak in Upload Status Stream in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-29061
GO-2026-4626
GHSA-q658-hfpg-35qc
Mar 10, 2026
Gokapi has privilege escalation via incomplete API-key permission revocation on user rank demotion in github.com/forceu/gokapi Gokapi has privilege escalation via incomplete API-key permission revocation on user rank demotion in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28683
GO-2026-4612
GHSA-3c22-5j5m-4jq7
Mar 10, 2026
Gokapi has Stored XSS in SVG Hotlinks in github.com/forceu/gokapi Gokapi has Stored XSS in SVG Hotlinks in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-48495
GO-2025-3736
GHSA-4xg4-54hm-9j77
Jun 03, 2025
Gokapi has stored XSS vulnerability in friendly name for API keys in github.com/forceu/gokapi Gokapi has stored XSS vulnerability in friendly name for API keys in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.0.0. References Updated Jun 03, 2025 · Source: OSV.dev
CVE-2025-48494
GO-2025-3737
GHSA-95rc-wc32-gm53
Jun 03, 2025
Gokapi vulnerable to stored XSS via uploading file with malicious file name in github.com/forceu/gokapi Gokapi vulnerable to stored XSS via uploading file with malicious file name in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.0.0. References Updated Jun 03, 2025 · Source: OSV.dev |
v1.1.3
patch
Dependencies (1)
|
|
v1.1.2
patch
10 CVEs
CVE-2026-30955
GO-2026-4698
GHSA-qwc6-vc2v-2ggj
Mar 16, 2026
Gokapi vulnerable to DoS in E2E Metadata Parser in github.com/forceu/gokapi Gokapi vulnerable to DoS in E2E Metadata Parser in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.4. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-30961
GO-2026-4695
GHSA-45vh-rpc8-hxpp
Mar 16, 2026
Gokapi's File Request MaxSize Limit Bypassed via Multi-Chunk Upload in github.com/forceu/gokapi Gokapi's File Request MaxSize Limit Bypassed via Multi-Chunk Upload in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.4. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-30943
GO-2026-4696
GHSA-j6jp-78w8-34x6
Mar 16, 2026
Gokapi vulnerable to Privilege Escalation in File Replace in github.com/forceu/gokapi Gokapi vulnerable to Privilege Escalation in File Replace in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.4. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-29084
GO-2026-4624
GHSA-hcff-qv74-7hr4
Mar 10, 2026
Gokapi has CSRF in Login Endpoint in github.com/forceu/gokapi Gokapi has CSRF in Login Endpoint in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-29060
GO-2026-4615
GHSA-m2hx-wjxc-9fp4
Mar 10, 2026
Gokapi has privilege escalation with auth token in github.com/forceu/gokapi Gokapi has privilege escalation with auth token in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28682
GO-2026-4613
GHSA-c36c-7pc2-f2ph
Mar 10, 2026
Gokapi has Data Leak in Upload Status Stream in github.com/forceu/gokapi Gokapi has Data Leak in Upload Status Stream in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-29061
GO-2026-4626
GHSA-q658-hfpg-35qc
Mar 10, 2026
Gokapi has privilege escalation via incomplete API-key permission revocation on user rank demotion in github.com/forceu/gokapi Gokapi has privilege escalation via incomplete API-key permission revocation on user rank demotion in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28683
GO-2026-4612
GHSA-3c22-5j5m-4jq7
Mar 10, 2026
Gokapi has Stored XSS in SVG Hotlinks in github.com/forceu/gokapi Gokapi has Stored XSS in SVG Hotlinks in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-48495
GO-2025-3736
GHSA-4xg4-54hm-9j77
Jun 03, 2025
Gokapi has stored XSS vulnerability in friendly name for API keys in github.com/forceu/gokapi Gokapi has stored XSS vulnerability in friendly name for API keys in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.0.0. References Updated Jun 03, 2025 · Source: OSV.dev
CVE-2025-48494
GO-2025-3737
GHSA-95rc-wc32-gm53
Jun 03, 2025
Gokapi vulnerable to stored XSS via uploading file with malicious file name in github.com/forceu/gokapi Gokapi vulnerable to stored XSS via uploading file with malicious file name in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.0.0. References Updated Jun 03, 2025 · Source: OSV.dev |
v1.1.2
patch
Dependencies (1)
|
|
v1.1.0
minor
10 CVEs
CVE-2026-30955
GO-2026-4698
GHSA-qwc6-vc2v-2ggj
Mar 16, 2026
Gokapi vulnerable to DoS in E2E Metadata Parser in github.com/forceu/gokapi Gokapi vulnerable to DoS in E2E Metadata Parser in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.4. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-30961
GO-2026-4695
GHSA-45vh-rpc8-hxpp
Mar 16, 2026
Gokapi's File Request MaxSize Limit Bypassed via Multi-Chunk Upload in github.com/forceu/gokapi Gokapi's File Request MaxSize Limit Bypassed via Multi-Chunk Upload in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.4. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-30943
GO-2026-4696
GHSA-j6jp-78w8-34x6
Mar 16, 2026
Gokapi vulnerable to Privilege Escalation in File Replace in github.com/forceu/gokapi Gokapi vulnerable to Privilege Escalation in File Replace in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.4. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-29084
GO-2026-4624
GHSA-hcff-qv74-7hr4
Mar 10, 2026
Gokapi has CSRF in Login Endpoint in github.com/forceu/gokapi Gokapi has CSRF in Login Endpoint in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-29060
GO-2026-4615
GHSA-m2hx-wjxc-9fp4
Mar 10, 2026
Gokapi has privilege escalation with auth token in github.com/forceu/gokapi Gokapi has privilege escalation with auth token in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28682
GO-2026-4613
GHSA-c36c-7pc2-f2ph
Mar 10, 2026
Gokapi has Data Leak in Upload Status Stream in github.com/forceu/gokapi Gokapi has Data Leak in Upload Status Stream in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-29061
GO-2026-4626
GHSA-q658-hfpg-35qc
Mar 10, 2026
Gokapi has privilege escalation via incomplete API-key permission revocation on user rank demotion in github.com/forceu/gokapi Gokapi has privilege escalation via incomplete API-key permission revocation on user rank demotion in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28683
GO-2026-4612
GHSA-3c22-5j5m-4jq7
Mar 10, 2026
Gokapi has Stored XSS in SVG Hotlinks in github.com/forceu/gokapi Gokapi has Stored XSS in SVG Hotlinks in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-48495
GO-2025-3736
GHSA-4xg4-54hm-9j77
Jun 03, 2025
Gokapi has stored XSS vulnerability in friendly name for API keys in github.com/forceu/gokapi Gokapi has stored XSS vulnerability in friendly name for API keys in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.0.0. References Updated Jun 03, 2025 · Source: OSV.dev
CVE-2025-48494
GO-2025-3737
GHSA-95rc-wc32-gm53
Jun 03, 2025
Gokapi vulnerable to stored XSS via uploading file with malicious file name in github.com/forceu/gokapi Gokapi vulnerable to stored XSS via uploading file with malicious file name in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.0.0. References Updated Jun 03, 2025 · Source: OSV.dev |
v1.1.0
minor
Dependencies (1)
|
|
v1.0.1
initial
10 CVEs
CVE-2026-30955
GO-2026-4698
GHSA-qwc6-vc2v-2ggj
Mar 16, 2026
Gokapi vulnerable to DoS in E2E Metadata Parser in github.com/forceu/gokapi Gokapi vulnerable to DoS in E2E Metadata Parser in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.4. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-30961
GO-2026-4695
GHSA-45vh-rpc8-hxpp
Mar 16, 2026
Gokapi's File Request MaxSize Limit Bypassed via Multi-Chunk Upload in github.com/forceu/gokapi Gokapi's File Request MaxSize Limit Bypassed via Multi-Chunk Upload in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.4. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-30943
GO-2026-4696
GHSA-j6jp-78w8-34x6
Mar 16, 2026
Gokapi vulnerable to Privilege Escalation in File Replace in github.com/forceu/gokapi Gokapi vulnerable to Privilege Escalation in File Replace in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.4. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-29084
GO-2026-4624
GHSA-hcff-qv74-7hr4
Mar 10, 2026
Gokapi has CSRF in Login Endpoint in github.com/forceu/gokapi Gokapi has CSRF in Login Endpoint in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-29060
GO-2026-4615
GHSA-m2hx-wjxc-9fp4
Mar 10, 2026
Gokapi has privilege escalation with auth token in github.com/forceu/gokapi Gokapi has privilege escalation with auth token in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28682
GO-2026-4613
GHSA-c36c-7pc2-f2ph
Mar 10, 2026
Gokapi has Data Leak in Upload Status Stream in github.com/forceu/gokapi Gokapi has Data Leak in Upload Status Stream in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-29061
GO-2026-4626
GHSA-q658-hfpg-35qc
Mar 10, 2026
Gokapi has privilege escalation via incomplete API-key permission revocation on user rank demotion in github.com/forceu/gokapi Gokapi has privilege escalation via incomplete API-key permission revocation on user rank demotion in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-28683
GO-2026-4612
GHSA-3c22-5j5m-4jq7
Mar 10, 2026
Gokapi has Stored XSS in SVG Hotlinks in github.com/forceu/gokapi Gokapi has Stored XSS in SVG Hotlinks in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.3. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-48495
GO-2025-3736
GHSA-4xg4-54hm-9j77
Jun 03, 2025
Gokapi has stored XSS vulnerability in friendly name for API keys in github.com/forceu/gokapi Gokapi has stored XSS vulnerability in friendly name for API keys in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.0.0. References Updated Jun 03, 2025 · Source: OSV.dev
CVE-2025-48494
GO-2025-3737
GHSA-95rc-wc32-gm53
Jun 03, 2025
Gokapi vulnerable to stored XSS via uploading file with malicious file name in github.com/forceu/gokapi Gokapi vulnerable to stored XSS via uploading file with malicious file name in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.0.0. References Updated Jun 03, 2025 · Source: OSV.dev |
v1.0.1
initial
Dependencies (1)
|