github.com/patrickhener/goshs
Feature-rich single-binary file server for red teamers and developers. HTTP/S · WebDAV · FTP/SFTP · SMB · LDAP/S · NTLM hash capture · DNS/SMTP callbacks · TLS · Auth · Share links. A powerful python3 -m http.server replacement.
Activity
- Latest release
- 6mo ago
- Total releases
- 20
- Cadence
- ~16 days
- Last 12 months
- 2
Reach
- Stars
- 964
Details
- First release
- Apr 10, 2024
| Version | Released | |
|---|---|---|
v1.1.4
patch
16 CVEs
CVE-2026-66064
GO-2026-6134
GHSA-964w-f6gj-5236
Aug 18, 2026
goshs has ACL Bypass & Path Traversal in github.com/patrickhener/goshs goshs has ACL Bypass & Path Traversal in github.com/patrickhener/goshs References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-64863
GO-2026-6136
GHSA-hq33-8jgp-8qq3
Aug 18, 2026
goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite in github.com/patrickhener/goshs goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite in github.com/patrickhener/goshs References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-54719
GO-2026-6133
GHSA-rmxw-pq4x-3fvh
Aug 18, 2026
goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx) in github.com/patrickhener/goshs goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx) in github.com/patrickhener/goshs References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-66063
GO-2026-6137
GHSA-wg2q-39h6-66x9
Aug 18, 2026
goshs has a Path Traversal issue in github.com/patrickhener/goshs goshs has a Path Traversal issue in github.com/patrickhener/goshs References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-40189
GO-2026-5728
GHSA-wvhv-qcqf-f3cx
Jun 25, 2026
goshs has a file-based ACL authorization bypass in goshs state-changing routes in github.com/patrickhener/goshs goshs has a file-based ACL authorization bypass in goshs state-changing routes in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42091
GO-2026-5625
GHSA-rhf7-wvw3-vjvm
Jun 25, 2026
goshs has Cross-Origin Arbitrary File Write via Missing CSRF on PUT and Wildcard CORS in github.com/patrickhener/goshs goshs has Cross-Origin Arbitrary File Write via Missing CSRF on PUT and Wildcard CORS in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-34581
GO-2026-5469
GHSA-jgfx-74g2-9r6g
Jun 25, 2026
goshs has Auth Bypass via Share Token in github.com/patrickhener/goshs goshs has Auth Bypass via Share Token in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35393
GO-2026-5468
GHSA-jg56-wf8x-qrv5
Jun 25, 2026
goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs POST multipart upload in github.com/patrickhener/goshs goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs POST multipart upload in github.com/patrickhener/goshs Fixed in
1.1.5-0.20260401172448-237f3af891a9
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40883
GO-2026-5479
GHSA-jrq5-hg6x-j6g3
Jun 25, 2026
goshs has CSRF in state-changing GET routes enables authenticated file deletion and directory creation in github.com/patrickhener/goshs goshs has CSRF in state-changing GET routes enables authenticated file deletion and directory creation in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35392
GO-2026-5394
GHSA-g8mv-vp7j-qp64
Jun 25, 2026
goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs PUT Upload in github.com/patrickhener/goshs goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs PUT Upload in github.com/patrickhener/goshs Fixed in
1.1.5-0.20260401172448-237f3af891a9
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40884
GO-2026-5303
GHSA-c29w-qq4m-2gcv
Jun 25, 2026
goshs has an empty-username SFTP password authentication bypass in github.com/patrickhener/goshs goshs has an empty-username SFTP password authentication bypass in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-5232
GHSA-7qx6-f23w-3w7f
Jun 25, 2026
Unauthenticated Open Redirect, Arbitrary HTTP Response Header Injection, Missing CSRF, and Invisible-Mode Bypass in goshs `/?redirect` endpoint in github.com/patrickhener/goshs Unauthenticated Open Redirect, Arbitrary HTTP Response Header Injection, Missing CSRF, and Invisible-Mode Bypass in goshs Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40885
GO-2026-5221
GHSA-7h3j-592v-jcrp
Jun 25, 2026
goshs's public collaborator feed leaks .goshs ACL credentials and enables unauthorized access in github.com/patrickhener/goshs goshs's public collaborator feed leaks .goshs ACL credentials and enables unauthorized access in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35471
GO-2026-5186
GHSA-6qcc-6q27-whp8
Jun 25, 2026
goshs: Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) in github.com/patrickhener/goshs goshs: Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) in github.com/patrickhener/goshs Fixed in
1.1.5-0.20260401172448-237f3af891a9
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40876
GO-2026-5146
GHSA-5h6h-7rc9-3824
Jun 25, 2026
SFTP root escape via prefix-based path validation in goshs in github.com/patrickhener/goshs SFTP root escape via prefix-based path validation in goshs in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40188
GO-2026-4953
GHSA-2943-crp8-38xx
May 20, 2026
goshs is Missing Write Protection for Parametric Data Values in github.com/patrickhener/goshs goshs is Missing Write Protection for Parametric Data Values in github.com/patrickhener/goshs References Updated May 20, 2026 · Source: OSV.dev |
v1.1.4
patch
Dependencies (18)
+ 10 more |
|
v1.1.2
patch
16 CVEs
CVE-2026-66064
GO-2026-6134
GHSA-964w-f6gj-5236
Aug 18, 2026
goshs has ACL Bypass & Path Traversal in github.com/patrickhener/goshs goshs has ACL Bypass & Path Traversal in github.com/patrickhener/goshs References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-64863
GO-2026-6136
GHSA-hq33-8jgp-8qq3
Aug 18, 2026
goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite in github.com/patrickhener/goshs goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite in github.com/patrickhener/goshs References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-54719
GO-2026-6133
GHSA-rmxw-pq4x-3fvh
Aug 18, 2026
goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx) in github.com/patrickhener/goshs goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx) in github.com/patrickhener/goshs References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-66063
GO-2026-6137
GHSA-wg2q-39h6-66x9
Aug 18, 2026
goshs has a Path Traversal issue in github.com/patrickhener/goshs goshs has a Path Traversal issue in github.com/patrickhener/goshs References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-40189
GO-2026-5728
GHSA-wvhv-qcqf-f3cx
Jun 25, 2026
goshs has a file-based ACL authorization bypass in goshs state-changing routes in github.com/patrickhener/goshs goshs has a file-based ACL authorization bypass in goshs state-changing routes in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42091
GO-2026-5625
GHSA-rhf7-wvw3-vjvm
Jun 25, 2026
goshs has Cross-Origin Arbitrary File Write via Missing CSRF on PUT and Wildcard CORS in github.com/patrickhener/goshs goshs has Cross-Origin Arbitrary File Write via Missing CSRF on PUT and Wildcard CORS in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-34581
GO-2026-5469
GHSA-jgfx-74g2-9r6g
Jun 25, 2026
goshs has Auth Bypass via Share Token in github.com/patrickhener/goshs goshs has Auth Bypass via Share Token in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35393
GO-2026-5468
GHSA-jg56-wf8x-qrv5
Jun 25, 2026
goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs POST multipart upload in github.com/patrickhener/goshs goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs POST multipart upload in github.com/patrickhener/goshs Fixed in
1.1.5-0.20260401172448-237f3af891a9
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40883
GO-2026-5479
GHSA-jrq5-hg6x-j6g3
Jun 25, 2026
goshs has CSRF in state-changing GET routes enables authenticated file deletion and directory creation in github.com/patrickhener/goshs goshs has CSRF in state-changing GET routes enables authenticated file deletion and directory creation in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35392
GO-2026-5394
GHSA-g8mv-vp7j-qp64
Jun 25, 2026
goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs PUT Upload in github.com/patrickhener/goshs goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs PUT Upload in github.com/patrickhener/goshs Fixed in
1.1.5-0.20260401172448-237f3af891a9
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40884
GO-2026-5303
GHSA-c29w-qq4m-2gcv
Jun 25, 2026
goshs has an empty-username SFTP password authentication bypass in github.com/patrickhener/goshs goshs has an empty-username SFTP password authentication bypass in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-5232
GHSA-7qx6-f23w-3w7f
Jun 25, 2026
Unauthenticated Open Redirect, Arbitrary HTTP Response Header Injection, Missing CSRF, and Invisible-Mode Bypass in goshs `/?redirect` endpoint in github.com/patrickhener/goshs Unauthenticated Open Redirect, Arbitrary HTTP Response Header Injection, Missing CSRF, and Invisible-Mode Bypass in goshs Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40885
GO-2026-5221
GHSA-7h3j-592v-jcrp
Jun 25, 2026
goshs's public collaborator feed leaks .goshs ACL credentials and enables unauthorized access in github.com/patrickhener/goshs goshs's public collaborator feed leaks .goshs ACL credentials and enables unauthorized access in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35471
GO-2026-5186
GHSA-6qcc-6q27-whp8
Jun 25, 2026
goshs: Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) in github.com/patrickhener/goshs goshs: Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) in github.com/patrickhener/goshs Fixed in
1.1.5-0.20260401172448-237f3af891a9
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40876
GO-2026-5146
GHSA-5h6h-7rc9-3824
Jun 25, 2026
SFTP root escape via prefix-based path validation in goshs in github.com/patrickhener/goshs SFTP root escape via prefix-based path validation in goshs in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40188
GO-2026-4953
GHSA-2943-crp8-38xx
May 20, 2026
goshs is Missing Write Protection for Parametric Data Values in github.com/patrickhener/goshs goshs is Missing Write Protection for Parametric Data Values in github.com/patrickhener/goshs References Updated May 20, 2026 · Source: OSV.dev |
v1.1.2
patch
Dependencies (18)
+ 10 more |
|
v1.1.1
patch
16 CVEs
CVE-2026-66064
GO-2026-6134
GHSA-964w-f6gj-5236
Aug 18, 2026
goshs has ACL Bypass & Path Traversal in github.com/patrickhener/goshs goshs has ACL Bypass & Path Traversal in github.com/patrickhener/goshs References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-64863
GO-2026-6136
GHSA-hq33-8jgp-8qq3
Aug 18, 2026
goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite in github.com/patrickhener/goshs goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite in github.com/patrickhener/goshs References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-54719
GO-2026-6133
GHSA-rmxw-pq4x-3fvh
Aug 18, 2026
goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx) in github.com/patrickhener/goshs goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx) in github.com/patrickhener/goshs References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-66063
GO-2026-6137
GHSA-wg2q-39h6-66x9
Aug 18, 2026
goshs has a Path Traversal issue in github.com/patrickhener/goshs goshs has a Path Traversal issue in github.com/patrickhener/goshs References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-40189
GO-2026-5728
GHSA-wvhv-qcqf-f3cx
Jun 25, 2026
goshs has a file-based ACL authorization bypass in goshs state-changing routes in github.com/patrickhener/goshs goshs has a file-based ACL authorization bypass in goshs state-changing routes in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42091
GO-2026-5625
GHSA-rhf7-wvw3-vjvm
Jun 25, 2026
goshs has Cross-Origin Arbitrary File Write via Missing CSRF on PUT and Wildcard CORS in github.com/patrickhener/goshs goshs has Cross-Origin Arbitrary File Write via Missing CSRF on PUT and Wildcard CORS in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-34581
GO-2026-5469
GHSA-jgfx-74g2-9r6g
Jun 25, 2026
goshs has Auth Bypass via Share Token in github.com/patrickhener/goshs goshs has Auth Bypass via Share Token in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35393
GO-2026-5468
GHSA-jg56-wf8x-qrv5
Jun 25, 2026
goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs POST multipart upload in github.com/patrickhener/goshs goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs POST multipart upload in github.com/patrickhener/goshs Fixed in
1.1.5-0.20260401172448-237f3af891a9
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40883
GO-2026-5479
GHSA-jrq5-hg6x-j6g3
Jun 25, 2026
goshs has CSRF in state-changing GET routes enables authenticated file deletion and directory creation in github.com/patrickhener/goshs goshs has CSRF in state-changing GET routes enables authenticated file deletion and directory creation in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35392
GO-2026-5394
GHSA-g8mv-vp7j-qp64
Jun 25, 2026
goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs PUT Upload in github.com/patrickhener/goshs goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs PUT Upload in github.com/patrickhener/goshs Fixed in
1.1.5-0.20260401172448-237f3af891a9
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40884
GO-2026-5303
GHSA-c29w-qq4m-2gcv
Jun 25, 2026
goshs has an empty-username SFTP password authentication bypass in github.com/patrickhener/goshs goshs has an empty-username SFTP password authentication bypass in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-5232
GHSA-7qx6-f23w-3w7f
Jun 25, 2026
Unauthenticated Open Redirect, Arbitrary HTTP Response Header Injection, Missing CSRF, and Invisible-Mode Bypass in goshs `/?redirect` endpoint in github.com/patrickhener/goshs Unauthenticated Open Redirect, Arbitrary HTTP Response Header Injection, Missing CSRF, and Invisible-Mode Bypass in goshs Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40885
GO-2026-5221
GHSA-7h3j-592v-jcrp
Jun 25, 2026
goshs's public collaborator feed leaks .goshs ACL credentials and enables unauthorized access in github.com/patrickhener/goshs goshs's public collaborator feed leaks .goshs ACL credentials and enables unauthorized access in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35471
GO-2026-5186
GHSA-6qcc-6q27-whp8
Jun 25, 2026
goshs: Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) in github.com/patrickhener/goshs goshs: Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) in github.com/patrickhener/goshs Fixed in
1.1.5-0.20260401172448-237f3af891a9
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40876
GO-2026-5146
GHSA-5h6h-7rc9-3824
Jun 25, 2026
SFTP root escape via prefix-based path validation in goshs in github.com/patrickhener/goshs SFTP root escape via prefix-based path validation in goshs in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40188
GO-2026-4953
GHSA-2943-crp8-38xx
May 20, 2026
goshs is Missing Write Protection for Parametric Data Values in github.com/patrickhener/goshs goshs is Missing Write Protection for Parametric Data Values in github.com/patrickhener/goshs References Updated May 20, 2026 · Source: OSV.dev |
v1.1.1
patch
Dependencies (18)
+ 10 more |
|
v1.1.0
minor
16 CVEs
CVE-2026-66064
GO-2026-6134
GHSA-964w-f6gj-5236
Aug 18, 2026
goshs has ACL Bypass & Path Traversal in github.com/patrickhener/goshs goshs has ACL Bypass & Path Traversal in github.com/patrickhener/goshs References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-64863
GO-2026-6136
GHSA-hq33-8jgp-8qq3
Aug 18, 2026
goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite in github.com/patrickhener/goshs goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite in github.com/patrickhener/goshs References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-54719
GO-2026-6133
GHSA-rmxw-pq4x-3fvh
Aug 18, 2026
goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx) in github.com/patrickhener/goshs goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx) in github.com/patrickhener/goshs References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-66063
GO-2026-6137
GHSA-wg2q-39h6-66x9
Aug 18, 2026
goshs has a Path Traversal issue in github.com/patrickhener/goshs goshs has a Path Traversal issue in github.com/patrickhener/goshs References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-40189
GO-2026-5728
GHSA-wvhv-qcqf-f3cx
Jun 25, 2026
goshs has a file-based ACL authorization bypass in goshs state-changing routes in github.com/patrickhener/goshs goshs has a file-based ACL authorization bypass in goshs state-changing routes in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42091
GO-2026-5625
GHSA-rhf7-wvw3-vjvm
Jun 25, 2026
goshs has Cross-Origin Arbitrary File Write via Missing CSRF on PUT and Wildcard CORS in github.com/patrickhener/goshs goshs has Cross-Origin Arbitrary File Write via Missing CSRF on PUT and Wildcard CORS in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-34581
GO-2026-5469
GHSA-jgfx-74g2-9r6g
Jun 25, 2026
goshs has Auth Bypass via Share Token in github.com/patrickhener/goshs goshs has Auth Bypass via Share Token in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35393
GO-2026-5468
GHSA-jg56-wf8x-qrv5
Jun 25, 2026
goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs POST multipart upload in github.com/patrickhener/goshs goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs POST multipart upload in github.com/patrickhener/goshs Fixed in
1.1.5-0.20260401172448-237f3af891a9
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40883
GO-2026-5479
GHSA-jrq5-hg6x-j6g3
Jun 25, 2026
goshs has CSRF in state-changing GET routes enables authenticated file deletion and directory creation in github.com/patrickhener/goshs goshs has CSRF in state-changing GET routes enables authenticated file deletion and directory creation in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35392
GO-2026-5394
GHSA-g8mv-vp7j-qp64
Jun 25, 2026
goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs PUT Upload in github.com/patrickhener/goshs goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs PUT Upload in github.com/patrickhener/goshs Fixed in
1.1.5-0.20260401172448-237f3af891a9
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40884
GO-2026-5303
GHSA-c29w-qq4m-2gcv
Jun 25, 2026
goshs has an empty-username SFTP password authentication bypass in github.com/patrickhener/goshs goshs has an empty-username SFTP password authentication bypass in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-5232
GHSA-7qx6-f23w-3w7f
Jun 25, 2026
Unauthenticated Open Redirect, Arbitrary HTTP Response Header Injection, Missing CSRF, and Invisible-Mode Bypass in goshs `/?redirect` endpoint in github.com/patrickhener/goshs Unauthenticated Open Redirect, Arbitrary HTTP Response Header Injection, Missing CSRF, and Invisible-Mode Bypass in goshs Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40885
GO-2026-5221
GHSA-7h3j-592v-jcrp
Jun 25, 2026
goshs's public collaborator feed leaks .goshs ACL credentials and enables unauthorized access in github.com/patrickhener/goshs goshs's public collaborator feed leaks .goshs ACL credentials and enables unauthorized access in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35471
GO-2026-5186
GHSA-6qcc-6q27-whp8
Jun 25, 2026
goshs: Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) in github.com/patrickhener/goshs goshs: Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) in github.com/patrickhener/goshs Fixed in
1.1.5-0.20260401172448-237f3af891a9
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40876
GO-2026-5146
GHSA-5h6h-7rc9-3824
Jun 25, 2026
SFTP root escape via prefix-based path validation in goshs in github.com/patrickhener/goshs SFTP root escape via prefix-based path validation in goshs in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40188
GO-2026-4953
GHSA-2943-crp8-38xx
May 20, 2026
goshs is Missing Write Protection for Parametric Data Values in github.com/patrickhener/goshs goshs is Missing Write Protection for Parametric Data Values in github.com/patrickhener/goshs References Updated May 20, 2026 · Source: OSV.dev |
v1.1.0
minor
Dependencies (17)
+ 9 more |
|
v1.0.9
patch
15 CVEs
CVE-2026-66064
GO-2026-6134
GHSA-964w-f6gj-5236
Aug 18, 2026
goshs has ACL Bypass & Path Traversal in github.com/patrickhener/goshs goshs has ACL Bypass & Path Traversal in github.com/patrickhener/goshs References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-64863
GO-2026-6136
GHSA-hq33-8jgp-8qq3
Aug 18, 2026
goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite in github.com/patrickhener/goshs goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite in github.com/patrickhener/goshs References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-54719
GO-2026-6133
GHSA-rmxw-pq4x-3fvh
Aug 18, 2026
goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx) in github.com/patrickhener/goshs goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx) in github.com/patrickhener/goshs References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-66063
GO-2026-6137
GHSA-wg2q-39h6-66x9
Aug 18, 2026
goshs has a Path Traversal issue in github.com/patrickhener/goshs goshs has a Path Traversal issue in github.com/patrickhener/goshs References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-40189
GO-2026-5728
GHSA-wvhv-qcqf-f3cx
Jun 25, 2026
goshs has a file-based ACL authorization bypass in goshs state-changing routes in github.com/patrickhener/goshs goshs has a file-based ACL authorization bypass in goshs state-changing routes in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42091
GO-2026-5625
GHSA-rhf7-wvw3-vjvm
Jun 25, 2026
goshs has Cross-Origin Arbitrary File Write via Missing CSRF on PUT and Wildcard CORS in github.com/patrickhener/goshs goshs has Cross-Origin Arbitrary File Write via Missing CSRF on PUT and Wildcard CORS in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35393
GO-2026-5468
GHSA-jg56-wf8x-qrv5
Jun 25, 2026
goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs POST multipart upload in github.com/patrickhener/goshs goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs POST multipart upload in github.com/patrickhener/goshs Fixed in
1.1.5-0.20260401172448-237f3af891a9
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40883
GO-2026-5479
GHSA-jrq5-hg6x-j6g3
Jun 25, 2026
goshs has CSRF in state-changing GET routes enables authenticated file deletion and directory creation in github.com/patrickhener/goshs goshs has CSRF in state-changing GET routes enables authenticated file deletion and directory creation in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35392
GO-2026-5394
GHSA-g8mv-vp7j-qp64
Jun 25, 2026
goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs PUT Upload in github.com/patrickhener/goshs goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs PUT Upload in github.com/patrickhener/goshs Fixed in
1.1.5-0.20260401172448-237f3af891a9
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40884
GO-2026-5303
GHSA-c29w-qq4m-2gcv
Jun 25, 2026
goshs has an empty-username SFTP password authentication bypass in github.com/patrickhener/goshs goshs has an empty-username SFTP password authentication bypass in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-5232
GHSA-7qx6-f23w-3w7f
Jun 25, 2026
Unauthenticated Open Redirect, Arbitrary HTTP Response Header Injection, Missing CSRF, and Invisible-Mode Bypass in goshs `/?redirect` endpoint in github.com/patrickhener/goshs Unauthenticated Open Redirect, Arbitrary HTTP Response Header Injection, Missing CSRF, and Invisible-Mode Bypass in goshs Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40885
GO-2026-5221
GHSA-7h3j-592v-jcrp
Jun 25, 2026
goshs's public collaborator feed leaks .goshs ACL credentials and enables unauthorized access in github.com/patrickhener/goshs goshs's public collaborator feed leaks .goshs ACL credentials and enables unauthorized access in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35471
GO-2026-5186
GHSA-6qcc-6q27-whp8
Jun 25, 2026
goshs: Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) in github.com/patrickhener/goshs goshs: Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) in github.com/patrickhener/goshs Fixed in
1.1.5-0.20260401172448-237f3af891a9
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40876
GO-2026-5146
GHSA-5h6h-7rc9-3824
Jun 25, 2026
SFTP root escape via prefix-based path validation in goshs in github.com/patrickhener/goshs SFTP root escape via prefix-based path validation in goshs in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40188
GO-2026-4953
GHSA-2943-crp8-38xx
May 20, 2026
goshs is Missing Write Protection for Parametric Data Values in github.com/patrickhener/goshs goshs is Missing Write Protection for Parametric Data Values in github.com/patrickhener/goshs References Updated May 20, 2026 · Source: OSV.dev |
v1.0.9
patch
Dependencies (17)
+ 9 more |
|
v1.0.8
patch
15 CVEs
CVE-2026-66064
GO-2026-6134
GHSA-964w-f6gj-5236
Aug 18, 2026
goshs has ACL Bypass & Path Traversal in github.com/patrickhener/goshs goshs has ACL Bypass & Path Traversal in github.com/patrickhener/goshs References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-64863
GO-2026-6136
GHSA-hq33-8jgp-8qq3
Aug 18, 2026
goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite in github.com/patrickhener/goshs goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite in github.com/patrickhener/goshs References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-54719
GO-2026-6133
GHSA-rmxw-pq4x-3fvh
Aug 18, 2026
goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx) in github.com/patrickhener/goshs goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx) in github.com/patrickhener/goshs References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-66063
GO-2026-6137
GHSA-wg2q-39h6-66x9
Aug 18, 2026
goshs has a Path Traversal issue in github.com/patrickhener/goshs goshs has a Path Traversal issue in github.com/patrickhener/goshs References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-40189
GO-2026-5728
GHSA-wvhv-qcqf-f3cx
Jun 25, 2026
goshs has a file-based ACL authorization bypass in goshs state-changing routes in github.com/patrickhener/goshs goshs has a file-based ACL authorization bypass in goshs state-changing routes in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42091
GO-2026-5625
GHSA-rhf7-wvw3-vjvm
Jun 25, 2026
goshs has Cross-Origin Arbitrary File Write via Missing CSRF on PUT and Wildcard CORS in github.com/patrickhener/goshs goshs has Cross-Origin Arbitrary File Write via Missing CSRF on PUT and Wildcard CORS in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35393
GO-2026-5468
GHSA-jg56-wf8x-qrv5
Jun 25, 2026
goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs POST multipart upload in github.com/patrickhener/goshs goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs POST multipart upload in github.com/patrickhener/goshs Fixed in
1.1.5-0.20260401172448-237f3af891a9
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40883
GO-2026-5479
GHSA-jrq5-hg6x-j6g3
Jun 25, 2026
goshs has CSRF in state-changing GET routes enables authenticated file deletion and directory creation in github.com/patrickhener/goshs goshs has CSRF in state-changing GET routes enables authenticated file deletion and directory creation in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35392
GO-2026-5394
GHSA-g8mv-vp7j-qp64
Jun 25, 2026
goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs PUT Upload in github.com/patrickhener/goshs goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs PUT Upload in github.com/patrickhener/goshs Fixed in
1.1.5-0.20260401172448-237f3af891a9
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40884
GO-2026-5303
GHSA-c29w-qq4m-2gcv
Jun 25, 2026
goshs has an empty-username SFTP password authentication bypass in github.com/patrickhener/goshs goshs has an empty-username SFTP password authentication bypass in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-5232
GHSA-7qx6-f23w-3w7f
Jun 25, 2026
Unauthenticated Open Redirect, Arbitrary HTTP Response Header Injection, Missing CSRF, and Invisible-Mode Bypass in goshs `/?redirect` endpoint in github.com/patrickhener/goshs Unauthenticated Open Redirect, Arbitrary HTTP Response Header Injection, Missing CSRF, and Invisible-Mode Bypass in goshs Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40885
GO-2026-5221
GHSA-7h3j-592v-jcrp
Jun 25, 2026
goshs's public collaborator feed leaks .goshs ACL credentials and enables unauthorized access in github.com/patrickhener/goshs goshs's public collaborator feed leaks .goshs ACL credentials and enables unauthorized access in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35471
GO-2026-5186
GHSA-6qcc-6q27-whp8
Jun 25, 2026
goshs: Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) in github.com/patrickhener/goshs goshs: Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) in github.com/patrickhener/goshs Fixed in
1.1.5-0.20260401172448-237f3af891a9
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40876
GO-2026-5146
GHSA-5h6h-7rc9-3824
Jun 25, 2026
SFTP root escape via prefix-based path validation in goshs in github.com/patrickhener/goshs SFTP root escape via prefix-based path validation in goshs in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40188
GO-2026-4953
GHSA-2943-crp8-38xx
May 20, 2026
goshs is Missing Write Protection for Parametric Data Values in github.com/patrickhener/goshs goshs is Missing Write Protection for Parametric Data Values in github.com/patrickhener/goshs References Updated May 20, 2026 · Source: OSV.dev |
v1.0.8
patch
Dependencies (17)
+ 9 more |
|
v1.0.7
patch
15 CVEs
CVE-2026-66064
GO-2026-6134
GHSA-964w-f6gj-5236
Aug 18, 2026
goshs has ACL Bypass & Path Traversal in github.com/patrickhener/goshs goshs has ACL Bypass & Path Traversal in github.com/patrickhener/goshs References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-64863
GO-2026-6136
GHSA-hq33-8jgp-8qq3
Aug 18, 2026
goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite in github.com/patrickhener/goshs goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite in github.com/patrickhener/goshs References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-54719
GO-2026-6133
GHSA-rmxw-pq4x-3fvh
Aug 18, 2026
goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx) in github.com/patrickhener/goshs goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx) in github.com/patrickhener/goshs References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-66063
GO-2026-6137
GHSA-wg2q-39h6-66x9
Aug 18, 2026
goshs has a Path Traversal issue in github.com/patrickhener/goshs goshs has a Path Traversal issue in github.com/patrickhener/goshs References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-40189
GO-2026-5728
GHSA-wvhv-qcqf-f3cx
Jun 25, 2026
goshs has a file-based ACL authorization bypass in goshs state-changing routes in github.com/patrickhener/goshs goshs has a file-based ACL authorization bypass in goshs state-changing routes in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42091
GO-2026-5625
GHSA-rhf7-wvw3-vjvm
Jun 25, 2026
goshs has Cross-Origin Arbitrary File Write via Missing CSRF on PUT and Wildcard CORS in github.com/patrickhener/goshs goshs has Cross-Origin Arbitrary File Write via Missing CSRF on PUT and Wildcard CORS in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35393
GO-2026-5468
GHSA-jg56-wf8x-qrv5
Jun 25, 2026
goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs POST multipart upload in github.com/patrickhener/goshs goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs POST multipart upload in github.com/patrickhener/goshs Fixed in
1.1.5-0.20260401172448-237f3af891a9
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40883
GO-2026-5479
GHSA-jrq5-hg6x-j6g3
Jun 25, 2026
goshs has CSRF in state-changing GET routes enables authenticated file deletion and directory creation in github.com/patrickhener/goshs goshs has CSRF in state-changing GET routes enables authenticated file deletion and directory creation in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35392
GO-2026-5394
GHSA-g8mv-vp7j-qp64
Jun 25, 2026
goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs PUT Upload in github.com/patrickhener/goshs goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs PUT Upload in github.com/patrickhener/goshs Fixed in
1.1.5-0.20260401172448-237f3af891a9
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40884
GO-2026-5303
GHSA-c29w-qq4m-2gcv
Jun 25, 2026
goshs has an empty-username SFTP password authentication bypass in github.com/patrickhener/goshs goshs has an empty-username SFTP password authentication bypass in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-5232
GHSA-7qx6-f23w-3w7f
Jun 25, 2026
Unauthenticated Open Redirect, Arbitrary HTTP Response Header Injection, Missing CSRF, and Invisible-Mode Bypass in goshs `/?redirect` endpoint in github.com/patrickhener/goshs Unauthenticated Open Redirect, Arbitrary HTTP Response Header Injection, Missing CSRF, and Invisible-Mode Bypass in goshs Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40885
GO-2026-5221
GHSA-7h3j-592v-jcrp
Jun 25, 2026
goshs's public collaborator feed leaks .goshs ACL credentials and enables unauthorized access in github.com/patrickhener/goshs goshs's public collaborator feed leaks .goshs ACL credentials and enables unauthorized access in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35471
GO-2026-5186
GHSA-6qcc-6q27-whp8
Jun 25, 2026
goshs: Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) in github.com/patrickhener/goshs goshs: Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) in github.com/patrickhener/goshs Fixed in
1.1.5-0.20260401172448-237f3af891a9
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40876
GO-2026-5146
GHSA-5h6h-7rc9-3824
Jun 25, 2026
SFTP root escape via prefix-based path validation in goshs in github.com/patrickhener/goshs SFTP root escape via prefix-based path validation in goshs in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40188
GO-2026-4953
GHSA-2943-crp8-38xx
May 20, 2026
goshs is Missing Write Protection for Parametric Data Values in github.com/patrickhener/goshs goshs is Missing Write Protection for Parametric Data Values in github.com/patrickhener/goshs References Updated May 20, 2026 · Source: OSV.dev |
v1.0.7
patch
Dependencies (17)
+ 9 more |
|
v1.0.6
patch
14 CVEs
CVE-2026-66064
GO-2026-6134
GHSA-964w-f6gj-5236
Aug 18, 2026
goshs has ACL Bypass & Path Traversal in github.com/patrickhener/goshs goshs has ACL Bypass & Path Traversal in github.com/patrickhener/goshs References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-64863
GO-2026-6136
GHSA-hq33-8jgp-8qq3
Aug 18, 2026
goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite in github.com/patrickhener/goshs goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite in github.com/patrickhener/goshs References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-54719
GO-2026-6133
GHSA-rmxw-pq4x-3fvh
Aug 18, 2026
goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx) in github.com/patrickhener/goshs goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx) in github.com/patrickhener/goshs References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-66063
GO-2026-6137
GHSA-wg2q-39h6-66x9
Aug 18, 2026
goshs has a Path Traversal issue in github.com/patrickhener/goshs goshs has a Path Traversal issue in github.com/patrickhener/goshs References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-40189
GO-2026-5728
GHSA-wvhv-qcqf-f3cx
Jun 25, 2026
goshs has a file-based ACL authorization bypass in goshs state-changing routes in github.com/patrickhener/goshs goshs has a file-based ACL authorization bypass in goshs state-changing routes in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42091
GO-2026-5625
GHSA-rhf7-wvw3-vjvm
Jun 25, 2026
goshs has Cross-Origin Arbitrary File Write via Missing CSRF on PUT and Wildcard CORS in github.com/patrickhener/goshs goshs has Cross-Origin Arbitrary File Write via Missing CSRF on PUT and Wildcard CORS in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35393
GO-2026-5468
GHSA-jg56-wf8x-qrv5
Jun 25, 2026
goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs POST multipart upload in github.com/patrickhener/goshs goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs POST multipart upload in github.com/patrickhener/goshs Fixed in
1.1.5-0.20260401172448-237f3af891a9
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40883
GO-2026-5479
GHSA-jrq5-hg6x-j6g3
Jun 25, 2026
goshs has CSRF in state-changing GET routes enables authenticated file deletion and directory creation in github.com/patrickhener/goshs goshs has CSRF in state-changing GET routes enables authenticated file deletion and directory creation in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35392
GO-2026-5394
GHSA-g8mv-vp7j-qp64
Jun 25, 2026
goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs PUT Upload in github.com/patrickhener/goshs goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs PUT Upload in github.com/patrickhener/goshs Fixed in
1.1.5-0.20260401172448-237f3af891a9
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40884
GO-2026-5303
GHSA-c29w-qq4m-2gcv
Jun 25, 2026
goshs has an empty-username SFTP password authentication bypass in github.com/patrickhener/goshs goshs has an empty-username SFTP password authentication bypass in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-5232
GHSA-7qx6-f23w-3w7f
Jun 25, 2026
Unauthenticated Open Redirect, Arbitrary HTTP Response Header Injection, Missing CSRF, and Invisible-Mode Bypass in goshs `/?redirect` endpoint in github.com/patrickhener/goshs Unauthenticated Open Redirect, Arbitrary HTTP Response Header Injection, Missing CSRF, and Invisible-Mode Bypass in goshs Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40885
GO-2026-5221
GHSA-7h3j-592v-jcrp
Jun 25, 2026
goshs's public collaborator feed leaks .goshs ACL credentials and enables unauthorized access in github.com/patrickhener/goshs goshs's public collaborator feed leaks .goshs ACL credentials and enables unauthorized access in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35471
GO-2026-5186
GHSA-6qcc-6q27-whp8
Jun 25, 2026
goshs: Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) in github.com/patrickhener/goshs goshs: Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) in github.com/patrickhener/goshs Fixed in
1.1.5-0.20260401172448-237f3af891a9
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40876
GO-2026-5146
GHSA-5h6h-7rc9-3824
Jun 25, 2026
SFTP root escape via prefix-based path validation in goshs in github.com/patrickhener/goshs SFTP root escape via prefix-based path validation in goshs in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev |
v1.0.6
patch
Dependencies (9)
+ 1 more |
|
v1.0.5
patch
14 CVEs
CVE-2026-66064
GO-2026-6134
GHSA-964w-f6gj-5236
Aug 18, 2026
goshs has ACL Bypass & Path Traversal in github.com/patrickhener/goshs goshs has ACL Bypass & Path Traversal in github.com/patrickhener/goshs References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-64863
GO-2026-6136
GHSA-hq33-8jgp-8qq3
Aug 18, 2026
goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite in github.com/patrickhener/goshs goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite in github.com/patrickhener/goshs References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-54719
GO-2026-6133
GHSA-rmxw-pq4x-3fvh
Aug 18, 2026
goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx) in github.com/patrickhener/goshs goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx) in github.com/patrickhener/goshs References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-66063
GO-2026-6137
GHSA-wg2q-39h6-66x9
Aug 18, 2026
goshs has a Path Traversal issue in github.com/patrickhener/goshs goshs has a Path Traversal issue in github.com/patrickhener/goshs References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-40189
GO-2026-5728
GHSA-wvhv-qcqf-f3cx
Jun 25, 2026
goshs has a file-based ACL authorization bypass in goshs state-changing routes in github.com/patrickhener/goshs goshs has a file-based ACL authorization bypass in goshs state-changing routes in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42091
GO-2026-5625
GHSA-rhf7-wvw3-vjvm
Jun 25, 2026
goshs has Cross-Origin Arbitrary File Write via Missing CSRF on PUT and Wildcard CORS in github.com/patrickhener/goshs goshs has Cross-Origin Arbitrary File Write via Missing CSRF on PUT and Wildcard CORS in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35393
GO-2026-5468
GHSA-jg56-wf8x-qrv5
Jun 25, 2026
goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs POST multipart upload in github.com/patrickhener/goshs goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs POST multipart upload in github.com/patrickhener/goshs Fixed in
1.1.5-0.20260401172448-237f3af891a9
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40883
GO-2026-5479
GHSA-jrq5-hg6x-j6g3
Jun 25, 2026
goshs has CSRF in state-changing GET routes enables authenticated file deletion and directory creation in github.com/patrickhener/goshs goshs has CSRF in state-changing GET routes enables authenticated file deletion and directory creation in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35392
GO-2026-5394
GHSA-g8mv-vp7j-qp64
Jun 25, 2026
goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs PUT Upload in github.com/patrickhener/goshs goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs PUT Upload in github.com/patrickhener/goshs Fixed in
1.1.5-0.20260401172448-237f3af891a9
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40884
GO-2026-5303
GHSA-c29w-qq4m-2gcv
Jun 25, 2026
goshs has an empty-username SFTP password authentication bypass in github.com/patrickhener/goshs goshs has an empty-username SFTP password authentication bypass in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-5232
GHSA-7qx6-f23w-3w7f
Jun 25, 2026
Unauthenticated Open Redirect, Arbitrary HTTP Response Header Injection, Missing CSRF, and Invisible-Mode Bypass in goshs `/?redirect` endpoint in github.com/patrickhener/goshs Unauthenticated Open Redirect, Arbitrary HTTP Response Header Injection, Missing CSRF, and Invisible-Mode Bypass in goshs Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40885
GO-2026-5221
GHSA-7h3j-592v-jcrp
Jun 25, 2026
goshs's public collaborator feed leaks .goshs ACL credentials and enables unauthorized access in github.com/patrickhener/goshs goshs's public collaborator feed leaks .goshs ACL credentials and enables unauthorized access in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35471
GO-2026-5186
GHSA-6qcc-6q27-whp8
Jun 25, 2026
goshs: Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) in github.com/patrickhener/goshs goshs: Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) in github.com/patrickhener/goshs Fixed in
1.1.5-0.20260401172448-237f3af891a9
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40876
GO-2026-5146
GHSA-5h6h-7rc9-3824
Jun 25, 2026
SFTP root escape via prefix-based path validation in goshs in github.com/patrickhener/goshs SFTP root escape via prefix-based path validation in goshs in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev |
v1.0.5
patch
Dependencies (9)
+ 1 more |
|
v1.0.4
patch
15 CVEs
CVE-2026-66064
GO-2026-6134
GHSA-964w-f6gj-5236
Aug 18, 2026
goshs has ACL Bypass & Path Traversal in github.com/patrickhener/goshs goshs has ACL Bypass & Path Traversal in github.com/patrickhener/goshs References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-64863
GO-2026-6136
GHSA-hq33-8jgp-8qq3
Aug 18, 2026
goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite in github.com/patrickhener/goshs goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite in github.com/patrickhener/goshs References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-54719
GO-2026-6133
GHSA-rmxw-pq4x-3fvh
Aug 18, 2026
goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx) in github.com/patrickhener/goshs goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx) in github.com/patrickhener/goshs References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-66063
GO-2026-6137
GHSA-wg2q-39h6-66x9
Aug 18, 2026
goshs has a Path Traversal issue in github.com/patrickhener/goshs goshs has a Path Traversal issue in github.com/patrickhener/goshs References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-40189
GO-2026-5728
GHSA-wvhv-qcqf-f3cx
Jun 25, 2026
goshs has a file-based ACL authorization bypass in goshs state-changing routes in github.com/patrickhener/goshs goshs has a file-based ACL authorization bypass in goshs state-changing routes in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42091
GO-2026-5625
GHSA-rhf7-wvw3-vjvm
Jun 25, 2026
goshs has Cross-Origin Arbitrary File Write via Missing CSRF on PUT and Wildcard CORS in github.com/patrickhener/goshs goshs has Cross-Origin Arbitrary File Write via Missing CSRF on PUT and Wildcard CORS in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35393
GO-2026-5468
GHSA-jg56-wf8x-qrv5
Jun 25, 2026
goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs POST multipart upload in github.com/patrickhener/goshs goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs POST multipart upload in github.com/patrickhener/goshs Fixed in
1.1.5-0.20260401172448-237f3af891a9
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40883
GO-2026-5479
GHSA-jrq5-hg6x-j6g3
Jun 25, 2026
goshs has CSRF in state-changing GET routes enables authenticated file deletion and directory creation in github.com/patrickhener/goshs goshs has CSRF in state-changing GET routes enables authenticated file deletion and directory creation in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35392
GO-2026-5394
GHSA-g8mv-vp7j-qp64
Jun 25, 2026
goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs PUT Upload in github.com/patrickhener/goshs goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs PUT Upload in github.com/patrickhener/goshs Fixed in
1.1.5-0.20260401172448-237f3af891a9
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40884
GO-2026-5303
GHSA-c29w-qq4m-2gcv
Jun 25, 2026
goshs has an empty-username SFTP password authentication bypass in github.com/patrickhener/goshs goshs has an empty-username SFTP password authentication bypass in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-5232
GHSA-7qx6-f23w-3w7f
Jun 25, 2026
Unauthenticated Open Redirect, Arbitrary HTTP Response Header Injection, Missing CSRF, and Invisible-Mode Bypass in goshs `/?redirect` endpoint in github.com/patrickhener/goshs Unauthenticated Open Redirect, Arbitrary HTTP Response Header Injection, Missing CSRF, and Invisible-Mode Bypass in goshs Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40885
GO-2026-5221
GHSA-7h3j-592v-jcrp
Jun 25, 2026
goshs's public collaborator feed leaks .goshs ACL credentials and enables unauthorized access in github.com/patrickhener/goshs goshs's public collaborator feed leaks .goshs ACL credentials and enables unauthorized access in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35471
GO-2026-5186
GHSA-6qcc-6q27-whp8
Jun 25, 2026
goshs: Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) in github.com/patrickhener/goshs goshs: Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) in github.com/patrickhener/goshs Fixed in
1.1.5-0.20260401172448-237f3af891a9
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40876
GO-2026-5146
GHSA-5h6h-7rc9-3824
Jun 25, 2026
SFTP root escape via prefix-based path validation in goshs in github.com/patrickhener/goshs SFTP root escape via prefix-based path validation in goshs in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-46816
GO-2025-3672
GHSA-rwj2-w85g-5cmm
May 15, 2025
goshs route not protected, allows command execution in github.com/patrickhener/goshs goshs route not protected, allows command execution in github.com/patrickhener/goshs Fixed in
1.0.5
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.0.4
patch
Dependencies (9)
+ 1 more |
|
v1.0.3
patch
15 CVEs
CVE-2026-66064
GO-2026-6134
GHSA-964w-f6gj-5236
Aug 18, 2026
goshs has ACL Bypass & Path Traversal in github.com/patrickhener/goshs goshs has ACL Bypass & Path Traversal in github.com/patrickhener/goshs References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-64863
GO-2026-6136
GHSA-hq33-8jgp-8qq3
Aug 18, 2026
goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite in github.com/patrickhener/goshs goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite in github.com/patrickhener/goshs References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-54719
GO-2026-6133
GHSA-rmxw-pq4x-3fvh
Aug 18, 2026
goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx) in github.com/patrickhener/goshs goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx) in github.com/patrickhener/goshs References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-66063
GO-2026-6137
GHSA-wg2q-39h6-66x9
Aug 18, 2026
goshs has a Path Traversal issue in github.com/patrickhener/goshs goshs has a Path Traversal issue in github.com/patrickhener/goshs References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-40189
GO-2026-5728
GHSA-wvhv-qcqf-f3cx
Jun 25, 2026
goshs has a file-based ACL authorization bypass in goshs state-changing routes in github.com/patrickhener/goshs goshs has a file-based ACL authorization bypass in goshs state-changing routes in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42091
GO-2026-5625
GHSA-rhf7-wvw3-vjvm
Jun 25, 2026
goshs has Cross-Origin Arbitrary File Write via Missing CSRF on PUT and Wildcard CORS in github.com/patrickhener/goshs goshs has Cross-Origin Arbitrary File Write via Missing CSRF on PUT and Wildcard CORS in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35393
GO-2026-5468
GHSA-jg56-wf8x-qrv5
Jun 25, 2026
goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs POST multipart upload in github.com/patrickhener/goshs goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs POST multipart upload in github.com/patrickhener/goshs Fixed in
1.1.5-0.20260401172448-237f3af891a9
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40883
GO-2026-5479
GHSA-jrq5-hg6x-j6g3
Jun 25, 2026
goshs has CSRF in state-changing GET routes enables authenticated file deletion and directory creation in github.com/patrickhener/goshs goshs has CSRF in state-changing GET routes enables authenticated file deletion and directory creation in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35392
GO-2026-5394
GHSA-g8mv-vp7j-qp64
Jun 25, 2026
goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs PUT Upload in github.com/patrickhener/goshs goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs PUT Upload in github.com/patrickhener/goshs Fixed in
1.1.5-0.20260401172448-237f3af891a9
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40884
GO-2026-5303
GHSA-c29w-qq4m-2gcv
Jun 25, 2026
goshs has an empty-username SFTP password authentication bypass in github.com/patrickhener/goshs goshs has an empty-username SFTP password authentication bypass in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-5232
GHSA-7qx6-f23w-3w7f
Jun 25, 2026
Unauthenticated Open Redirect, Arbitrary HTTP Response Header Injection, Missing CSRF, and Invisible-Mode Bypass in goshs `/?redirect` endpoint in github.com/patrickhener/goshs Unauthenticated Open Redirect, Arbitrary HTTP Response Header Injection, Missing CSRF, and Invisible-Mode Bypass in goshs Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40885
GO-2026-5221
GHSA-7h3j-592v-jcrp
Jun 25, 2026
goshs's public collaborator feed leaks .goshs ACL credentials and enables unauthorized access in github.com/patrickhener/goshs goshs's public collaborator feed leaks .goshs ACL credentials and enables unauthorized access in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35471
GO-2026-5186
GHSA-6qcc-6q27-whp8
Jun 25, 2026
goshs: Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) in github.com/patrickhener/goshs goshs: Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) in github.com/patrickhener/goshs Fixed in
1.1.5-0.20260401172448-237f3af891a9
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40876
GO-2026-5146
GHSA-5h6h-7rc9-3824
Jun 25, 2026
SFTP root escape via prefix-based path validation in goshs in github.com/patrickhener/goshs SFTP root escape via prefix-based path validation in goshs in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-46816
GO-2025-3672
GHSA-rwj2-w85g-5cmm
May 15, 2025
goshs route not protected, allows command execution in github.com/patrickhener/goshs goshs route not protected, allows command execution in github.com/patrickhener/goshs Fixed in
1.0.5
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.0.3
patch
Dependencies (10)
+ 2 more |
|
v1.0.2
patch
15 CVEs
CVE-2026-66064
GO-2026-6134
GHSA-964w-f6gj-5236
Aug 18, 2026
goshs has ACL Bypass & Path Traversal in github.com/patrickhener/goshs goshs has ACL Bypass & Path Traversal in github.com/patrickhener/goshs References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-64863
GO-2026-6136
GHSA-hq33-8jgp-8qq3
Aug 18, 2026
goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite in github.com/patrickhener/goshs goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite in github.com/patrickhener/goshs References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-54719
GO-2026-6133
GHSA-rmxw-pq4x-3fvh
Aug 18, 2026
goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx) in github.com/patrickhener/goshs goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx) in github.com/patrickhener/goshs References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-66063
GO-2026-6137
GHSA-wg2q-39h6-66x9
Aug 18, 2026
goshs has a Path Traversal issue in github.com/patrickhener/goshs goshs has a Path Traversal issue in github.com/patrickhener/goshs References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-40189
GO-2026-5728
GHSA-wvhv-qcqf-f3cx
Jun 25, 2026
goshs has a file-based ACL authorization bypass in goshs state-changing routes in github.com/patrickhener/goshs goshs has a file-based ACL authorization bypass in goshs state-changing routes in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42091
GO-2026-5625
GHSA-rhf7-wvw3-vjvm
Jun 25, 2026
goshs has Cross-Origin Arbitrary File Write via Missing CSRF on PUT and Wildcard CORS in github.com/patrickhener/goshs goshs has Cross-Origin Arbitrary File Write via Missing CSRF on PUT and Wildcard CORS in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35393
GO-2026-5468
GHSA-jg56-wf8x-qrv5
Jun 25, 2026
goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs POST multipart upload in github.com/patrickhener/goshs goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs POST multipart upload in github.com/patrickhener/goshs Fixed in
1.1.5-0.20260401172448-237f3af891a9
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40883
GO-2026-5479
GHSA-jrq5-hg6x-j6g3
Jun 25, 2026
goshs has CSRF in state-changing GET routes enables authenticated file deletion and directory creation in github.com/patrickhener/goshs goshs has CSRF in state-changing GET routes enables authenticated file deletion and directory creation in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35392
GO-2026-5394
GHSA-g8mv-vp7j-qp64
Jun 25, 2026
goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs PUT Upload in github.com/patrickhener/goshs goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs PUT Upload in github.com/patrickhener/goshs Fixed in
1.1.5-0.20260401172448-237f3af891a9
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40884
GO-2026-5303
GHSA-c29w-qq4m-2gcv
Jun 25, 2026
goshs has an empty-username SFTP password authentication bypass in github.com/patrickhener/goshs goshs has an empty-username SFTP password authentication bypass in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-5232
GHSA-7qx6-f23w-3w7f
Jun 25, 2026
Unauthenticated Open Redirect, Arbitrary HTTP Response Header Injection, Missing CSRF, and Invisible-Mode Bypass in goshs `/?redirect` endpoint in github.com/patrickhener/goshs Unauthenticated Open Redirect, Arbitrary HTTP Response Header Injection, Missing CSRF, and Invisible-Mode Bypass in goshs Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40885
GO-2026-5221
GHSA-7h3j-592v-jcrp
Jun 25, 2026
goshs's public collaborator feed leaks .goshs ACL credentials and enables unauthorized access in github.com/patrickhener/goshs goshs's public collaborator feed leaks .goshs ACL credentials and enables unauthorized access in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35471
GO-2026-5186
GHSA-6qcc-6q27-whp8
Jun 25, 2026
goshs: Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) in github.com/patrickhener/goshs goshs: Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) in github.com/patrickhener/goshs Fixed in
1.1.5-0.20260401172448-237f3af891a9
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40876
GO-2026-5146
GHSA-5h6h-7rc9-3824
Jun 25, 2026
SFTP root escape via prefix-based path validation in goshs in github.com/patrickhener/goshs SFTP root escape via prefix-based path validation in goshs in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-46816
GO-2025-3672
GHSA-rwj2-w85g-5cmm
May 15, 2025
goshs route not protected, allows command execution in github.com/patrickhener/goshs goshs route not protected, allows command execution in github.com/patrickhener/goshs Fixed in
1.0.5
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.0.2
patch
Dependencies (10)
+ 2 more |
|
v1.0.1
patch
15 CVEs
CVE-2026-66064
GO-2026-6134
GHSA-964w-f6gj-5236
Aug 18, 2026
goshs has ACL Bypass & Path Traversal in github.com/patrickhener/goshs goshs has ACL Bypass & Path Traversal in github.com/patrickhener/goshs References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-64863
GO-2026-6136
GHSA-hq33-8jgp-8qq3
Aug 18, 2026
goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite in github.com/patrickhener/goshs goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite in github.com/patrickhener/goshs References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-54719
GO-2026-6133
GHSA-rmxw-pq4x-3fvh
Aug 18, 2026
goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx) in github.com/patrickhener/goshs goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx) in github.com/patrickhener/goshs References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-66063
GO-2026-6137
GHSA-wg2q-39h6-66x9
Aug 18, 2026
goshs has a Path Traversal issue in github.com/patrickhener/goshs goshs has a Path Traversal issue in github.com/patrickhener/goshs References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-40189
GO-2026-5728
GHSA-wvhv-qcqf-f3cx
Jun 25, 2026
goshs has a file-based ACL authorization bypass in goshs state-changing routes in github.com/patrickhener/goshs goshs has a file-based ACL authorization bypass in goshs state-changing routes in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42091
GO-2026-5625
GHSA-rhf7-wvw3-vjvm
Jun 25, 2026
goshs has Cross-Origin Arbitrary File Write via Missing CSRF on PUT and Wildcard CORS in github.com/patrickhener/goshs goshs has Cross-Origin Arbitrary File Write via Missing CSRF on PUT and Wildcard CORS in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35393
GO-2026-5468
GHSA-jg56-wf8x-qrv5
Jun 25, 2026
goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs POST multipart upload in github.com/patrickhener/goshs goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs POST multipart upload in github.com/patrickhener/goshs Fixed in
1.1.5-0.20260401172448-237f3af891a9
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40883
GO-2026-5479
GHSA-jrq5-hg6x-j6g3
Jun 25, 2026
goshs has CSRF in state-changing GET routes enables authenticated file deletion and directory creation in github.com/patrickhener/goshs goshs has CSRF in state-changing GET routes enables authenticated file deletion and directory creation in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35392
GO-2026-5394
GHSA-g8mv-vp7j-qp64
Jun 25, 2026
goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs PUT Upload in github.com/patrickhener/goshs goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs PUT Upload in github.com/patrickhener/goshs Fixed in
1.1.5-0.20260401172448-237f3af891a9
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40884
GO-2026-5303
GHSA-c29w-qq4m-2gcv
Jun 25, 2026
goshs has an empty-username SFTP password authentication bypass in github.com/patrickhener/goshs goshs has an empty-username SFTP password authentication bypass in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-5232
GHSA-7qx6-f23w-3w7f
Jun 25, 2026
Unauthenticated Open Redirect, Arbitrary HTTP Response Header Injection, Missing CSRF, and Invisible-Mode Bypass in goshs `/?redirect` endpoint in github.com/patrickhener/goshs Unauthenticated Open Redirect, Arbitrary HTTP Response Header Injection, Missing CSRF, and Invisible-Mode Bypass in goshs Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40885
GO-2026-5221
GHSA-7h3j-592v-jcrp
Jun 25, 2026
goshs's public collaborator feed leaks .goshs ACL credentials and enables unauthorized access in github.com/patrickhener/goshs goshs's public collaborator feed leaks .goshs ACL credentials and enables unauthorized access in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35471
GO-2026-5186
GHSA-6qcc-6q27-whp8
Jun 25, 2026
goshs: Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) in github.com/patrickhener/goshs goshs: Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) in github.com/patrickhener/goshs Fixed in
1.1.5-0.20260401172448-237f3af891a9
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40876
GO-2026-5146
GHSA-5h6h-7rc9-3824
Jun 25, 2026
SFTP root escape via prefix-based path validation in goshs in github.com/patrickhener/goshs SFTP root escape via prefix-based path validation in goshs in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-46816
GO-2025-3672
GHSA-rwj2-w85g-5cmm
May 15, 2025
goshs route not protected, allows command execution in github.com/patrickhener/goshs goshs route not protected, allows command execution in github.com/patrickhener/goshs Fixed in
1.0.5
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.0.1
patch
Dependencies (10)
+ 2 more |
|
v1.0.0
major
15 CVEs
CVE-2026-66064
GO-2026-6134
GHSA-964w-f6gj-5236
Aug 18, 2026
goshs has ACL Bypass & Path Traversal in github.com/patrickhener/goshs goshs has ACL Bypass & Path Traversal in github.com/patrickhener/goshs References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-64863
GO-2026-6136
GHSA-hq33-8jgp-8qq3
Aug 18, 2026
goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite in github.com/patrickhener/goshs goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite in github.com/patrickhener/goshs References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-54719
GO-2026-6133
GHSA-rmxw-pq4x-3fvh
Aug 18, 2026
goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx) in github.com/patrickhener/goshs goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx) in github.com/patrickhener/goshs References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-66063
GO-2026-6137
GHSA-wg2q-39h6-66x9
Aug 18, 2026
goshs has a Path Traversal issue in github.com/patrickhener/goshs goshs has a Path Traversal issue in github.com/patrickhener/goshs References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-40189
GO-2026-5728
GHSA-wvhv-qcqf-f3cx
Jun 25, 2026
goshs has a file-based ACL authorization bypass in goshs state-changing routes in github.com/patrickhener/goshs goshs has a file-based ACL authorization bypass in goshs state-changing routes in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42091
GO-2026-5625
GHSA-rhf7-wvw3-vjvm
Jun 25, 2026
goshs has Cross-Origin Arbitrary File Write via Missing CSRF on PUT and Wildcard CORS in github.com/patrickhener/goshs goshs has Cross-Origin Arbitrary File Write via Missing CSRF on PUT and Wildcard CORS in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35393
GO-2026-5468
GHSA-jg56-wf8x-qrv5
Jun 25, 2026
goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs POST multipart upload in github.com/patrickhener/goshs goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs POST multipart upload in github.com/patrickhener/goshs Fixed in
1.1.5-0.20260401172448-237f3af891a9
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40883
GO-2026-5479
GHSA-jrq5-hg6x-j6g3
Jun 25, 2026
goshs has CSRF in state-changing GET routes enables authenticated file deletion and directory creation in github.com/patrickhener/goshs goshs has CSRF in state-changing GET routes enables authenticated file deletion and directory creation in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35392
GO-2026-5394
GHSA-g8mv-vp7j-qp64
Jun 25, 2026
goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs PUT Upload in github.com/patrickhener/goshs goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs PUT Upload in github.com/patrickhener/goshs Fixed in
1.1.5-0.20260401172448-237f3af891a9
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40884
GO-2026-5303
GHSA-c29w-qq4m-2gcv
Jun 25, 2026
goshs has an empty-username SFTP password authentication bypass in github.com/patrickhener/goshs goshs has an empty-username SFTP password authentication bypass in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-5232
GHSA-7qx6-f23w-3w7f
Jun 25, 2026
Unauthenticated Open Redirect, Arbitrary HTTP Response Header Injection, Missing CSRF, and Invisible-Mode Bypass in goshs `/?redirect` endpoint in github.com/patrickhener/goshs Unauthenticated Open Redirect, Arbitrary HTTP Response Header Injection, Missing CSRF, and Invisible-Mode Bypass in goshs Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40885
GO-2026-5221
GHSA-7h3j-592v-jcrp
Jun 25, 2026
goshs's public collaborator feed leaks .goshs ACL credentials and enables unauthorized access in github.com/patrickhener/goshs goshs's public collaborator feed leaks .goshs ACL credentials and enables unauthorized access in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35471
GO-2026-5186
GHSA-6qcc-6q27-whp8
Jun 25, 2026
goshs: Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) in github.com/patrickhener/goshs goshs: Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) in github.com/patrickhener/goshs Fixed in
1.1.5-0.20260401172448-237f3af891a9
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40876
GO-2026-5146
GHSA-5h6h-7rc9-3824
Jun 25, 2026
SFTP root escape via prefix-based path validation in goshs in github.com/patrickhener/goshs SFTP root escape via prefix-based path validation in goshs in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-46816
GO-2025-3672
GHSA-rwj2-w85g-5cmm
May 15, 2025
goshs route not protected, allows command execution in github.com/patrickhener/goshs goshs route not protected, allows command execution in github.com/patrickhener/goshs Fixed in
1.0.5
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.0.0
major
Dependencies (10)
+ 2 more |
|
v0.4.2
patch
15 CVEs
CVE-2026-66064
GO-2026-6134
GHSA-964w-f6gj-5236
Aug 18, 2026
goshs has ACL Bypass & Path Traversal in github.com/patrickhener/goshs goshs has ACL Bypass & Path Traversal in github.com/patrickhener/goshs References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-64863
GO-2026-6136
GHSA-hq33-8jgp-8qq3
Aug 18, 2026
goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite in github.com/patrickhener/goshs goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite in github.com/patrickhener/goshs References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-54719
GO-2026-6133
GHSA-rmxw-pq4x-3fvh
Aug 18, 2026
goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx) in github.com/patrickhener/goshs goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx) in github.com/patrickhener/goshs References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-66063
GO-2026-6137
GHSA-wg2q-39h6-66x9
Aug 18, 2026
goshs has a Path Traversal issue in github.com/patrickhener/goshs goshs has a Path Traversal issue in github.com/patrickhener/goshs References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-40189
GO-2026-5728
GHSA-wvhv-qcqf-f3cx
Jun 25, 2026
goshs has a file-based ACL authorization bypass in goshs state-changing routes in github.com/patrickhener/goshs goshs has a file-based ACL authorization bypass in goshs state-changing routes in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42091
GO-2026-5625
GHSA-rhf7-wvw3-vjvm
Jun 25, 2026
goshs has Cross-Origin Arbitrary File Write via Missing CSRF on PUT and Wildcard CORS in github.com/patrickhener/goshs goshs has Cross-Origin Arbitrary File Write via Missing CSRF on PUT and Wildcard CORS in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35393
GO-2026-5468
GHSA-jg56-wf8x-qrv5
Jun 25, 2026
goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs POST multipart upload in github.com/patrickhener/goshs goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs POST multipart upload in github.com/patrickhener/goshs Fixed in
1.1.5-0.20260401172448-237f3af891a9
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40883
GO-2026-5479
GHSA-jrq5-hg6x-j6g3
Jun 25, 2026
goshs has CSRF in state-changing GET routes enables authenticated file deletion and directory creation in github.com/patrickhener/goshs goshs has CSRF in state-changing GET routes enables authenticated file deletion and directory creation in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35392
GO-2026-5394
GHSA-g8mv-vp7j-qp64
Jun 25, 2026
goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs PUT Upload in github.com/patrickhener/goshs goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs PUT Upload in github.com/patrickhener/goshs Fixed in
1.1.5-0.20260401172448-237f3af891a9
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40884
GO-2026-5303
GHSA-c29w-qq4m-2gcv
Jun 25, 2026
goshs has an empty-username SFTP password authentication bypass in github.com/patrickhener/goshs goshs has an empty-username SFTP password authentication bypass in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-5232
GHSA-7qx6-f23w-3w7f
Jun 25, 2026
Unauthenticated Open Redirect, Arbitrary HTTP Response Header Injection, Missing CSRF, and Invisible-Mode Bypass in goshs `/?redirect` endpoint in github.com/patrickhener/goshs Unauthenticated Open Redirect, Arbitrary HTTP Response Header Injection, Missing CSRF, and Invisible-Mode Bypass in goshs Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40885
GO-2026-5221
GHSA-7h3j-592v-jcrp
Jun 25, 2026
goshs's public collaborator feed leaks .goshs ACL credentials and enables unauthorized access in github.com/patrickhener/goshs goshs's public collaborator feed leaks .goshs ACL credentials and enables unauthorized access in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35471
GO-2026-5186
GHSA-6qcc-6q27-whp8
Jun 25, 2026
goshs: Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) in github.com/patrickhener/goshs goshs: Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) in github.com/patrickhener/goshs Fixed in
1.1.5-0.20260401172448-237f3af891a9
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40876
GO-2026-5146
GHSA-5h6h-7rc9-3824
Jun 25, 2026
SFTP root escape via prefix-based path validation in goshs in github.com/patrickhener/goshs SFTP root escape via prefix-based path validation in goshs in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-46816
GO-2025-3672
GHSA-rwj2-w85g-5cmm
May 15, 2025
goshs route not protected, allows command execution in github.com/patrickhener/goshs goshs route not protected, allows command execution in github.com/patrickhener/goshs Fixed in
1.0.5
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.4.2
patch
Dependencies (10)
+ 2 more |
|
v0.4.1
patch
15 CVEs
CVE-2026-66064
GO-2026-6134
GHSA-964w-f6gj-5236
Aug 18, 2026
goshs has ACL Bypass & Path Traversal in github.com/patrickhener/goshs goshs has ACL Bypass & Path Traversal in github.com/patrickhener/goshs References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-64863
GO-2026-6136
GHSA-hq33-8jgp-8qq3
Aug 18, 2026
goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite in github.com/patrickhener/goshs goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite in github.com/patrickhener/goshs References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-54719
GO-2026-6133
GHSA-rmxw-pq4x-3fvh
Aug 18, 2026
goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx) in github.com/patrickhener/goshs goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx) in github.com/patrickhener/goshs References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-66063
GO-2026-6137
GHSA-wg2q-39h6-66x9
Aug 18, 2026
goshs has a Path Traversal issue in github.com/patrickhener/goshs goshs has a Path Traversal issue in github.com/patrickhener/goshs References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-40189
GO-2026-5728
GHSA-wvhv-qcqf-f3cx
Jun 25, 2026
goshs has a file-based ACL authorization bypass in goshs state-changing routes in github.com/patrickhener/goshs goshs has a file-based ACL authorization bypass in goshs state-changing routes in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42091
GO-2026-5625
GHSA-rhf7-wvw3-vjvm
Jun 25, 2026
goshs has Cross-Origin Arbitrary File Write via Missing CSRF on PUT and Wildcard CORS in github.com/patrickhener/goshs goshs has Cross-Origin Arbitrary File Write via Missing CSRF on PUT and Wildcard CORS in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35393
GO-2026-5468
GHSA-jg56-wf8x-qrv5
Jun 25, 2026
goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs POST multipart upload in github.com/patrickhener/goshs goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs POST multipart upload in github.com/patrickhener/goshs Fixed in
1.1.5-0.20260401172448-237f3af891a9
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40883
GO-2026-5479
GHSA-jrq5-hg6x-j6g3
Jun 25, 2026
goshs has CSRF in state-changing GET routes enables authenticated file deletion and directory creation in github.com/patrickhener/goshs goshs has CSRF in state-changing GET routes enables authenticated file deletion and directory creation in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35392
GO-2026-5394
GHSA-g8mv-vp7j-qp64
Jun 25, 2026
goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs PUT Upload in github.com/patrickhener/goshs goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs PUT Upload in github.com/patrickhener/goshs Fixed in
1.1.5-0.20260401172448-237f3af891a9
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40884
GO-2026-5303
GHSA-c29w-qq4m-2gcv
Jun 25, 2026
goshs has an empty-username SFTP password authentication bypass in github.com/patrickhener/goshs goshs has an empty-username SFTP password authentication bypass in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-5232
GHSA-7qx6-f23w-3w7f
Jun 25, 2026
Unauthenticated Open Redirect, Arbitrary HTTP Response Header Injection, Missing CSRF, and Invisible-Mode Bypass in goshs `/?redirect` endpoint in github.com/patrickhener/goshs Unauthenticated Open Redirect, Arbitrary HTTP Response Header Injection, Missing CSRF, and Invisible-Mode Bypass in goshs Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40885
GO-2026-5221
GHSA-7h3j-592v-jcrp
Jun 25, 2026
goshs's public collaborator feed leaks .goshs ACL credentials and enables unauthorized access in github.com/patrickhener/goshs goshs's public collaborator feed leaks .goshs ACL credentials and enables unauthorized access in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35471
GO-2026-5186
GHSA-6qcc-6q27-whp8
Jun 25, 2026
goshs: Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) in github.com/patrickhener/goshs goshs: Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) in github.com/patrickhener/goshs Fixed in
1.1.5-0.20260401172448-237f3af891a9
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40876
GO-2026-5146
GHSA-5h6h-7rc9-3824
Jun 25, 2026
SFTP root escape via prefix-based path validation in goshs in github.com/patrickhener/goshs SFTP root escape via prefix-based path validation in goshs in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-46816
GO-2025-3672
GHSA-rwj2-w85g-5cmm
May 15, 2025
goshs route not protected, allows command execution in github.com/patrickhener/goshs goshs route not protected, allows command execution in github.com/patrickhener/goshs Fixed in
1.0.5
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.4.1
patch
Dependencies (8)
|
|
v0.4.0
minor
15 CVEs
CVE-2026-66064
GO-2026-6134
GHSA-964w-f6gj-5236
Aug 18, 2026
goshs has ACL Bypass & Path Traversal in github.com/patrickhener/goshs goshs has ACL Bypass & Path Traversal in github.com/patrickhener/goshs References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-64863
GO-2026-6136
GHSA-hq33-8jgp-8qq3
Aug 18, 2026
goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite in github.com/patrickhener/goshs goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite in github.com/patrickhener/goshs References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-54719
GO-2026-6133
GHSA-rmxw-pq4x-3fvh
Aug 18, 2026
goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx) in github.com/patrickhener/goshs goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx) in github.com/patrickhener/goshs References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-66063
GO-2026-6137
GHSA-wg2q-39h6-66x9
Aug 18, 2026
goshs has a Path Traversal issue in github.com/patrickhener/goshs goshs has a Path Traversal issue in github.com/patrickhener/goshs References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-40189
GO-2026-5728
GHSA-wvhv-qcqf-f3cx
Jun 25, 2026
goshs has a file-based ACL authorization bypass in goshs state-changing routes in github.com/patrickhener/goshs goshs has a file-based ACL authorization bypass in goshs state-changing routes in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42091
GO-2026-5625
GHSA-rhf7-wvw3-vjvm
Jun 25, 2026
goshs has Cross-Origin Arbitrary File Write via Missing CSRF on PUT and Wildcard CORS in github.com/patrickhener/goshs goshs has Cross-Origin Arbitrary File Write via Missing CSRF on PUT and Wildcard CORS in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35393
GO-2026-5468
GHSA-jg56-wf8x-qrv5
Jun 25, 2026
goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs POST multipart upload in github.com/patrickhener/goshs goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs POST multipart upload in github.com/patrickhener/goshs Fixed in
1.1.5-0.20260401172448-237f3af891a9
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40883
GO-2026-5479
GHSA-jrq5-hg6x-j6g3
Jun 25, 2026
goshs has CSRF in state-changing GET routes enables authenticated file deletion and directory creation in github.com/patrickhener/goshs goshs has CSRF in state-changing GET routes enables authenticated file deletion and directory creation in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35392
GO-2026-5394
GHSA-g8mv-vp7j-qp64
Jun 25, 2026
goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs PUT Upload in github.com/patrickhener/goshs goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs PUT Upload in github.com/patrickhener/goshs Fixed in
1.1.5-0.20260401172448-237f3af891a9
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40884
GO-2026-5303
GHSA-c29w-qq4m-2gcv
Jun 25, 2026
goshs has an empty-username SFTP password authentication bypass in github.com/patrickhener/goshs goshs has an empty-username SFTP password authentication bypass in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-5232
GHSA-7qx6-f23w-3w7f
Jun 25, 2026
Unauthenticated Open Redirect, Arbitrary HTTP Response Header Injection, Missing CSRF, and Invisible-Mode Bypass in goshs `/?redirect` endpoint in github.com/patrickhener/goshs Unauthenticated Open Redirect, Arbitrary HTTP Response Header Injection, Missing CSRF, and Invisible-Mode Bypass in goshs Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40885
GO-2026-5221
GHSA-7h3j-592v-jcrp
Jun 25, 2026
goshs's public collaborator feed leaks .goshs ACL credentials and enables unauthorized access in github.com/patrickhener/goshs goshs's public collaborator feed leaks .goshs ACL credentials and enables unauthorized access in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35471
GO-2026-5186
GHSA-6qcc-6q27-whp8
Jun 25, 2026
goshs: Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) in github.com/patrickhener/goshs goshs: Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) in github.com/patrickhener/goshs Fixed in
1.1.5-0.20260401172448-237f3af891a9
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40876
GO-2026-5146
GHSA-5h6h-7rc9-3824
Jun 25, 2026
SFTP root escape via prefix-based path validation in goshs in github.com/patrickhener/goshs SFTP root escape via prefix-based path validation in goshs in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-46816
GO-2025-3672
GHSA-rwj2-w85g-5cmm
May 15, 2025
goshs route not protected, allows command execution in github.com/patrickhener/goshs goshs route not protected, allows command execution in github.com/patrickhener/goshs Fixed in
1.0.5
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.4.0
minor
Dependencies (8)
|
|
v0.3.9
patch
15 CVEs
CVE-2026-66064
GO-2026-6134
GHSA-964w-f6gj-5236
Aug 18, 2026
goshs has ACL Bypass & Path Traversal in github.com/patrickhener/goshs goshs has ACL Bypass & Path Traversal in github.com/patrickhener/goshs References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-64863
GO-2026-6136
GHSA-hq33-8jgp-8qq3
Aug 18, 2026
goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite in github.com/patrickhener/goshs goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite in github.com/patrickhener/goshs References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-54719
GO-2026-6133
GHSA-rmxw-pq4x-3fvh
Aug 18, 2026
goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx) in github.com/patrickhener/goshs goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx) in github.com/patrickhener/goshs References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-66063
GO-2026-6137
GHSA-wg2q-39h6-66x9
Aug 18, 2026
goshs has a Path Traversal issue in github.com/patrickhener/goshs goshs has a Path Traversal issue in github.com/patrickhener/goshs References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-40189
GO-2026-5728
GHSA-wvhv-qcqf-f3cx
Jun 25, 2026
goshs has a file-based ACL authorization bypass in goshs state-changing routes in github.com/patrickhener/goshs goshs has a file-based ACL authorization bypass in goshs state-changing routes in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42091
GO-2026-5625
GHSA-rhf7-wvw3-vjvm
Jun 25, 2026
goshs has Cross-Origin Arbitrary File Write via Missing CSRF on PUT and Wildcard CORS in github.com/patrickhener/goshs goshs has Cross-Origin Arbitrary File Write via Missing CSRF on PUT and Wildcard CORS in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35393
GO-2026-5468
GHSA-jg56-wf8x-qrv5
Jun 25, 2026
goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs POST multipart upload in github.com/patrickhener/goshs goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs POST multipart upload in github.com/patrickhener/goshs Fixed in
1.1.5-0.20260401172448-237f3af891a9
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40883
GO-2026-5479
GHSA-jrq5-hg6x-j6g3
Jun 25, 2026
goshs has CSRF in state-changing GET routes enables authenticated file deletion and directory creation in github.com/patrickhener/goshs goshs has CSRF in state-changing GET routes enables authenticated file deletion and directory creation in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35392
GO-2026-5394
GHSA-g8mv-vp7j-qp64
Jun 25, 2026
goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs PUT Upload in github.com/patrickhener/goshs goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs PUT Upload in github.com/patrickhener/goshs Fixed in
1.1.5-0.20260401172448-237f3af891a9
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40884
GO-2026-5303
GHSA-c29w-qq4m-2gcv
Jun 25, 2026
goshs has an empty-username SFTP password authentication bypass in github.com/patrickhener/goshs goshs has an empty-username SFTP password authentication bypass in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-5232
GHSA-7qx6-f23w-3w7f
Jun 25, 2026
Unauthenticated Open Redirect, Arbitrary HTTP Response Header Injection, Missing CSRF, and Invisible-Mode Bypass in goshs `/?redirect` endpoint in github.com/patrickhener/goshs Unauthenticated Open Redirect, Arbitrary HTTP Response Header Injection, Missing CSRF, and Invisible-Mode Bypass in goshs Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40885
GO-2026-5221
GHSA-7h3j-592v-jcrp
Jun 25, 2026
goshs's public collaborator feed leaks .goshs ACL credentials and enables unauthorized access in github.com/patrickhener/goshs goshs's public collaborator feed leaks .goshs ACL credentials and enables unauthorized access in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35471
GO-2026-5186
GHSA-6qcc-6q27-whp8
Jun 25, 2026
goshs: Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) in github.com/patrickhener/goshs goshs: Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) in github.com/patrickhener/goshs Fixed in
1.1.5-0.20260401172448-237f3af891a9
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40876
GO-2026-5146
GHSA-5h6h-7rc9-3824
Jun 25, 2026
SFTP root escape via prefix-based path validation in goshs in github.com/patrickhener/goshs SFTP root escape via prefix-based path validation in goshs in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-46816
GO-2025-3672
GHSA-rwj2-w85g-5cmm
May 15, 2025
goshs route not protected, allows command execution in github.com/patrickhener/goshs goshs route not protected, allows command execution in github.com/patrickhener/goshs Fixed in
1.0.5
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.3.9
patch
Dependencies (7)
|
|
v0.3.8
patch
15 CVEs
CVE-2026-66064
GO-2026-6134
GHSA-964w-f6gj-5236
Aug 18, 2026
goshs has ACL Bypass & Path Traversal in github.com/patrickhener/goshs goshs has ACL Bypass & Path Traversal in github.com/patrickhener/goshs References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-64863
GO-2026-6136
GHSA-hq33-8jgp-8qq3
Aug 18, 2026
goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite in github.com/patrickhener/goshs goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite in github.com/patrickhener/goshs References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-54719
GO-2026-6133
GHSA-rmxw-pq4x-3fvh
Aug 18, 2026
goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx) in github.com/patrickhener/goshs goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx) in github.com/patrickhener/goshs References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-66063
GO-2026-6137
GHSA-wg2q-39h6-66x9
Aug 18, 2026
goshs has a Path Traversal issue in github.com/patrickhener/goshs goshs has a Path Traversal issue in github.com/patrickhener/goshs References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-40189
GO-2026-5728
GHSA-wvhv-qcqf-f3cx
Jun 25, 2026
goshs has a file-based ACL authorization bypass in goshs state-changing routes in github.com/patrickhener/goshs goshs has a file-based ACL authorization bypass in goshs state-changing routes in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42091
GO-2026-5625
GHSA-rhf7-wvw3-vjvm
Jun 25, 2026
goshs has Cross-Origin Arbitrary File Write via Missing CSRF on PUT and Wildcard CORS in github.com/patrickhener/goshs goshs has Cross-Origin Arbitrary File Write via Missing CSRF on PUT and Wildcard CORS in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35393
GO-2026-5468
GHSA-jg56-wf8x-qrv5
Jun 25, 2026
goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs POST multipart upload in github.com/patrickhener/goshs goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs POST multipart upload in github.com/patrickhener/goshs Fixed in
1.1.5-0.20260401172448-237f3af891a9
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40883
GO-2026-5479
GHSA-jrq5-hg6x-j6g3
Jun 25, 2026
goshs has CSRF in state-changing GET routes enables authenticated file deletion and directory creation in github.com/patrickhener/goshs goshs has CSRF in state-changing GET routes enables authenticated file deletion and directory creation in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35392
GO-2026-5394
GHSA-g8mv-vp7j-qp64
Jun 25, 2026
goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs PUT Upload in github.com/patrickhener/goshs goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs PUT Upload in github.com/patrickhener/goshs Fixed in
1.1.5-0.20260401172448-237f3af891a9
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40884
GO-2026-5303
GHSA-c29w-qq4m-2gcv
Jun 25, 2026
goshs has an empty-username SFTP password authentication bypass in github.com/patrickhener/goshs goshs has an empty-username SFTP password authentication bypass in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-5232
GHSA-7qx6-f23w-3w7f
Jun 25, 2026
Unauthenticated Open Redirect, Arbitrary HTTP Response Header Injection, Missing CSRF, and Invisible-Mode Bypass in goshs `/?redirect` endpoint in github.com/patrickhener/goshs Unauthenticated Open Redirect, Arbitrary HTTP Response Header Injection, Missing CSRF, and Invisible-Mode Bypass in goshs Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40885
GO-2026-5221
GHSA-7h3j-592v-jcrp
Jun 25, 2026
goshs's public collaborator feed leaks .goshs ACL credentials and enables unauthorized access in github.com/patrickhener/goshs goshs's public collaborator feed leaks .goshs ACL credentials and enables unauthorized access in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35471
GO-2026-5186
GHSA-6qcc-6q27-whp8
Jun 25, 2026
goshs: Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) in github.com/patrickhener/goshs goshs: Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) in github.com/patrickhener/goshs Fixed in
1.1.5-0.20260401172448-237f3af891a9
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40876
GO-2026-5146
GHSA-5h6h-7rc9-3824
Jun 25, 2026
SFTP root escape via prefix-based path validation in goshs in github.com/patrickhener/goshs SFTP root escape via prefix-based path validation in goshs in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-46816
GO-2025-3672
GHSA-rwj2-w85g-5cmm
May 15, 2025
goshs route not protected, allows command execution in github.com/patrickhener/goshs goshs route not protected, allows command execution in github.com/patrickhener/goshs Fixed in
1.0.5
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.3.8
patch
Dependencies (7)
|
|
v0.3.7
initial
15 CVEs
CVE-2026-66064
GO-2026-6134
GHSA-964w-f6gj-5236
Aug 18, 2026
goshs has ACL Bypass & Path Traversal in github.com/patrickhener/goshs goshs has ACL Bypass & Path Traversal in github.com/patrickhener/goshs References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-64863
GO-2026-6136
GHSA-hq33-8jgp-8qq3
Aug 18, 2026
goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite in github.com/patrickhener/goshs goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite in github.com/patrickhener/goshs References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-54719
GO-2026-6133
GHSA-rmxw-pq4x-3fvh
Aug 18, 2026
goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx) in github.com/patrickhener/goshs goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx) in github.com/patrickhener/goshs References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-66063
GO-2026-6137
GHSA-wg2q-39h6-66x9
Aug 18, 2026
goshs has a Path Traversal issue in github.com/patrickhener/goshs goshs has a Path Traversal issue in github.com/patrickhener/goshs References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-40189
GO-2026-5728
GHSA-wvhv-qcqf-f3cx
Jun 25, 2026
goshs has a file-based ACL authorization bypass in goshs state-changing routes in github.com/patrickhener/goshs goshs has a file-based ACL authorization bypass in goshs state-changing routes in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42091
GO-2026-5625
GHSA-rhf7-wvw3-vjvm
Jun 25, 2026
goshs has Cross-Origin Arbitrary File Write via Missing CSRF on PUT and Wildcard CORS in github.com/patrickhener/goshs goshs has Cross-Origin Arbitrary File Write via Missing CSRF on PUT and Wildcard CORS in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35393
GO-2026-5468
GHSA-jg56-wf8x-qrv5
Jun 25, 2026
goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs POST multipart upload in github.com/patrickhener/goshs goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs POST multipart upload in github.com/patrickhener/goshs Fixed in
1.1.5-0.20260401172448-237f3af891a9
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40883
GO-2026-5479
GHSA-jrq5-hg6x-j6g3
Jun 25, 2026
goshs has CSRF in state-changing GET routes enables authenticated file deletion and directory creation in github.com/patrickhener/goshs goshs has CSRF in state-changing GET routes enables authenticated file deletion and directory creation in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35392
GO-2026-5394
GHSA-g8mv-vp7j-qp64
Jun 25, 2026
goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs PUT Upload in github.com/patrickhener/goshs goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs PUT Upload in github.com/patrickhener/goshs Fixed in
1.1.5-0.20260401172448-237f3af891a9
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40884
GO-2026-5303
GHSA-c29w-qq4m-2gcv
Jun 25, 2026
goshs has an empty-username SFTP password authentication bypass in github.com/patrickhener/goshs goshs has an empty-username SFTP password authentication bypass in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-5232
GHSA-7qx6-f23w-3w7f
Jun 25, 2026
Unauthenticated Open Redirect, Arbitrary HTTP Response Header Injection, Missing CSRF, and Invisible-Mode Bypass in goshs `/?redirect` endpoint in github.com/patrickhener/goshs Unauthenticated Open Redirect, Arbitrary HTTP Response Header Injection, Missing CSRF, and Invisible-Mode Bypass in goshs Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40885
GO-2026-5221
GHSA-7h3j-592v-jcrp
Jun 25, 2026
goshs's public collaborator feed leaks .goshs ACL credentials and enables unauthorized access in github.com/patrickhener/goshs goshs's public collaborator feed leaks .goshs ACL credentials and enables unauthorized access in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-35471
GO-2026-5186
GHSA-6qcc-6q27-whp8
Jun 25, 2026
goshs: Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) in github.com/patrickhener/goshs goshs: Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) in github.com/patrickhener/goshs Fixed in
1.1.5-0.20260401172448-237f3af891a9
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40876
GO-2026-5146
GHSA-5h6h-7rc9-3824
Jun 25, 2026
SFTP root escape via prefix-based path validation in goshs in github.com/patrickhener/goshs SFTP root escape via prefix-based path validation in goshs in github.com/patrickhener/goshs References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-46816
GO-2025-3672
GHSA-rwj2-w85g-5cmm
May 15, 2025
goshs route not protected, allows command execution in github.com/patrickhener/goshs goshs route not protected, allows command execution in github.com/patrickhener/goshs Fixed in
1.0.5
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.3.7
initial
Dependencies (6)
|