goshs.de/goshs/v2
Activity
- Latest release
- 3w ago
- Total releases
- 17
- Cadence
- ~4 days
- Last 12 months
- 17
Details
- First release
- Apr 14, 2026
| Version | Released | |
|---|---|---|
v2.1.6
patch
|
v2.1.6
patch
Dependencies (29)
+ 21 more |
|
v2.1.5
patch
|
v2.1.5
patch
Dependencies (29)
+ 21 more |
|
v2.1.4
patch
2 CVEs
CVE-2026-66064
GO-2026-6134
GHSA-964w-f6gj-5236
Aug 18, 2026
goshs has ACL Bypass & Path Traversal in github.com/patrickhener/goshs goshs has ACL Bypass & Path Traversal in github.com/patrickhener/goshs Fixed in
2.1.5-0.20260727065949-f3ef599e4091
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-66063
GO-2026-6137
GHSA-wg2q-39h6-66x9
Aug 18, 2026
goshs has a Path Traversal issue in github.com/patrickhener/goshs goshs has a Path Traversal issue in github.com/patrickhener/goshs Fixed in
2.1.5-0.20260727065949-f3ef599e4091
References Updated Aug 18, 2026 · Source: OSV.dev |
v2.1.4
patch
Dependencies (30)
+ 22 more |
|
v2.1.3
patch
4 CVEs
CVE-2026-66064
GO-2026-6134
GHSA-964w-f6gj-5236
Aug 18, 2026
goshs has ACL Bypass & Path Traversal in github.com/patrickhener/goshs goshs has ACL Bypass & Path Traversal in github.com/patrickhener/goshs Fixed in
2.1.5-0.20260727065949-f3ef599e4091
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-64863
GO-2026-6136
GHSA-hq33-8jgp-8qq3
Aug 18, 2026
goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite in github.com/patrickhener/goshs goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite in github.com/patrickhener/goshs Fixed in
2.1.4
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-66063
GO-2026-6137
GHSA-wg2q-39h6-66x9
Aug 18, 2026
goshs has a Path Traversal issue in github.com/patrickhener/goshs goshs has a Path Traversal issue in github.com/patrickhener/goshs Fixed in
2.1.5-0.20260727065949-f3ef599e4091
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-62325
GO-2026-6132
GHSA-rjrw-mjq6-hpmm
Aug 18, 2026
goshs SFTP authentication bypass via empty password (incomplete fix of CVE-2026-40884) in goshs.de/goshs goshs SFTP authentication bypass via empty password (incomplete fix of CVE-2026-40884) in goshs.de/goshs Fixed in
2.1.4
References Updated Aug 18, 2026 · Source: OSV.dev |
v2.1.3
patch
Dependencies (29)
+ 21 more |
|
v2.1.2
patch
3 CVEs
CVE-2026-66064
GO-2026-6134
GHSA-964w-f6gj-5236
Aug 18, 2026
goshs has ACL Bypass & Path Traversal in github.com/patrickhener/goshs goshs has ACL Bypass & Path Traversal in github.com/patrickhener/goshs Fixed in
2.1.5-0.20260727065949-f3ef599e4091
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-64863
GO-2026-6136
GHSA-hq33-8jgp-8qq3
Aug 18, 2026
goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite in github.com/patrickhener/goshs goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite in github.com/patrickhener/goshs Fixed in
2.1.4
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-66063
GO-2026-6137
GHSA-wg2q-39h6-66x9
Aug 18, 2026
goshs has a Path Traversal issue in github.com/patrickhener/goshs goshs has a Path Traversal issue in github.com/patrickhener/goshs Fixed in
2.1.5-0.20260727065949-f3ef599e4091
References Updated Aug 18, 2026 · Source: OSV.dev |
v2.1.2
patch
Dependencies (29)
+ 21 more |
|
v2.1.1
patch
3 CVEs
CVE-2026-66064
GO-2026-6134
GHSA-964w-f6gj-5236
Aug 18, 2026
goshs has ACL Bypass & Path Traversal in github.com/patrickhener/goshs goshs has ACL Bypass & Path Traversal in github.com/patrickhener/goshs Fixed in
2.1.5-0.20260727065949-f3ef599e4091
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-64863
GO-2026-6136
GHSA-hq33-8jgp-8qq3
Aug 18, 2026
goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite in github.com/patrickhener/goshs goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite in github.com/patrickhener/goshs Fixed in
2.1.4
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-66063
GO-2026-6137
GHSA-wg2q-39h6-66x9
Aug 18, 2026
goshs has a Path Traversal issue in github.com/patrickhener/goshs goshs has a Path Traversal issue in github.com/patrickhener/goshs Fixed in
2.1.5-0.20260727065949-f3ef599e4091
References Updated Aug 18, 2026 · Source: OSV.dev |
v2.1.1
patch
Dependencies (29)
+ 21 more |
|
v2.1.0
minor
4 CVEs
CVE-2026-54719
GO-2026-6133
GHSA-rmxw-pq4x-3fvh
Aug 18, 2026
goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx) in github.com/patrickhener/goshs goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx) in github.com/patrickhener/goshs Fixed in
2.1.1
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-66064
GO-2026-6134
GHSA-964w-f6gj-5236
Aug 18, 2026
goshs has ACL Bypass & Path Traversal in github.com/patrickhener/goshs goshs has ACL Bypass & Path Traversal in github.com/patrickhener/goshs Fixed in
2.1.5-0.20260727065949-f3ef599e4091
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-64863
GO-2026-6136
GHSA-hq33-8jgp-8qq3
Aug 18, 2026
goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite in github.com/patrickhener/goshs goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite in github.com/patrickhener/goshs Fixed in
2.1.4
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-66063
GO-2026-6137
GHSA-wg2q-39h6-66x9
Aug 18, 2026
goshs has a Path Traversal issue in github.com/patrickhener/goshs goshs has a Path Traversal issue in github.com/patrickhener/goshs Fixed in
2.1.5-0.20260727065949-f3ef599e4091
References Updated Aug 18, 2026 · Source: OSV.dev |
v2.1.0
minor
Dependencies (24)
+ 16 more |
|
v2.0.9
patch
6 CVEs
CVE-2026-54719
GO-2026-6133
GHSA-rmxw-pq4x-3fvh
Aug 18, 2026
goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx) in github.com/patrickhener/goshs goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx) in github.com/patrickhener/goshs Fixed in
2.1.1
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-66064
GO-2026-6134
GHSA-964w-f6gj-5236
Aug 18, 2026
goshs has ACL Bypass & Path Traversal in github.com/patrickhener/goshs goshs has ACL Bypass & Path Traversal in github.com/patrickhener/goshs Fixed in
2.1.5-0.20260727065949-f3ef599e4091
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-64863
GO-2026-6136
GHSA-hq33-8jgp-8qq3
Aug 18, 2026
goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite in github.com/patrickhener/goshs goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite in github.com/patrickhener/goshs Fixed in
2.1.4
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-66063
GO-2026-6137
GHSA-wg2q-39h6-66x9
Aug 18, 2026
goshs has a Path Traversal issue in github.com/patrickhener/goshs goshs has a Path Traversal issue in github.com/patrickhener/goshs Fixed in
2.1.5-0.20260727065949-f3ef599e4091
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-50138
GO-2026-5878
GHSA-3whc-qvhv-xqjp
Jul 07, 2026
goshs: WebDAV listener ignores --read-only, --upload-only, and --no-delete mode flags in goshs.de/goshs goshs: WebDAV listener ignores --read-only, --upload-only, and --no-delete mode flags in goshs.de/goshs Fixed in
2.1.0
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50139
GO-2026-5881
GHSA-j48m-h7xq-2xpj
Jul 07, 2026
goshs: Share-link ?token=… redemption races past download limit in goshs.de/goshs goshs: Share-link ?token=… redemption races past download limit in goshs.de/goshs Fixed in
2.1.0
Updated Jul 07, 2026 · Source: OSV.dev |
v2.0.9
patch
Dependencies (24)
+ 16 more |
|
v2.0.8
patch
6 CVEs
CVE-2026-54719
GO-2026-6133
GHSA-rmxw-pq4x-3fvh
Aug 18, 2026
goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx) in github.com/patrickhener/goshs goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx) in github.com/patrickhener/goshs Fixed in
2.1.1
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-66064
GO-2026-6134
GHSA-964w-f6gj-5236
Aug 18, 2026
goshs has ACL Bypass & Path Traversal in github.com/patrickhener/goshs goshs has ACL Bypass & Path Traversal in github.com/patrickhener/goshs Fixed in
2.1.5-0.20260727065949-f3ef599e4091
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-64863
GO-2026-6136
GHSA-hq33-8jgp-8qq3
Aug 18, 2026
goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite in github.com/patrickhener/goshs goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite in github.com/patrickhener/goshs Fixed in
2.1.4
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-66063
GO-2026-6137
GHSA-wg2q-39h6-66x9
Aug 18, 2026
goshs has a Path Traversal issue in github.com/patrickhener/goshs goshs has a Path Traversal issue in github.com/patrickhener/goshs Fixed in
2.1.5-0.20260727065949-f3ef599e4091
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-50138
GO-2026-5878
GHSA-3whc-qvhv-xqjp
Jul 07, 2026
goshs: WebDAV listener ignores --read-only, --upload-only, and --no-delete mode flags in goshs.de/goshs goshs: WebDAV listener ignores --read-only, --upload-only, and --no-delete mode flags in goshs.de/goshs Fixed in
2.1.0
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50139
GO-2026-5881
GHSA-j48m-h7xq-2xpj
Jul 07, 2026
goshs: Share-link ?token=… redemption races past download limit in goshs.de/goshs goshs: Share-link ?token=… redemption races past download limit in goshs.de/goshs Fixed in
2.1.0
Updated Jul 07, 2026 · Source: OSV.dev |
v2.0.8
patch
Dependencies (24)
+ 16 more |
|
v2.0.7
patch
6 CVEs
CVE-2026-54719
GO-2026-6133
GHSA-rmxw-pq4x-3fvh
Aug 18, 2026
goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx) in github.com/patrickhener/goshs goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx) in github.com/patrickhener/goshs Fixed in
2.1.1
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-66064
GO-2026-6134
GHSA-964w-f6gj-5236
Aug 18, 2026
goshs has ACL Bypass & Path Traversal in github.com/patrickhener/goshs goshs has ACL Bypass & Path Traversal in github.com/patrickhener/goshs Fixed in
2.1.5-0.20260727065949-f3ef599e4091
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-64863
GO-2026-6136
GHSA-hq33-8jgp-8qq3
Aug 18, 2026
goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite in github.com/patrickhener/goshs goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite in github.com/patrickhener/goshs Fixed in
2.1.4
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-66063
GO-2026-6137
GHSA-wg2q-39h6-66x9
Aug 18, 2026
goshs has a Path Traversal issue in github.com/patrickhener/goshs goshs has a Path Traversal issue in github.com/patrickhener/goshs Fixed in
2.1.5-0.20260727065949-f3ef599e4091
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-50138
GO-2026-5878
GHSA-3whc-qvhv-xqjp
Jul 07, 2026
goshs: WebDAV listener ignores --read-only, --upload-only, and --no-delete mode flags in goshs.de/goshs goshs: WebDAV listener ignores --read-only, --upload-only, and --no-delete mode flags in goshs.de/goshs Fixed in
2.1.0
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50139
GO-2026-5881
GHSA-j48m-h7xq-2xpj
Jul 07, 2026
goshs: Share-link ?token=… redemption races past download limit in goshs.de/goshs goshs: Share-link ?token=… redemption races past download limit in goshs.de/goshs Fixed in
2.1.0
Updated Jul 07, 2026 · Source: OSV.dev |
v2.0.7
patch
Dependencies (24)
+ 16 more |
|
v2.0.6
patch
7 CVEs
CVE-2026-54719
GO-2026-6133
GHSA-rmxw-pq4x-3fvh
Aug 18, 2026
goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx) in github.com/patrickhener/goshs goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx) in github.com/patrickhener/goshs Fixed in
2.1.1
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-66064
GO-2026-6134
GHSA-964w-f6gj-5236
Aug 18, 2026
goshs has ACL Bypass & Path Traversal in github.com/patrickhener/goshs goshs has ACL Bypass & Path Traversal in github.com/patrickhener/goshs Fixed in
2.1.5-0.20260727065949-f3ef599e4091
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-64863
GO-2026-6136
GHSA-hq33-8jgp-8qq3
Aug 18, 2026
goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite in github.com/patrickhener/goshs goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite in github.com/patrickhener/goshs Fixed in
2.1.4
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-66063
GO-2026-6137
GHSA-wg2q-39h6-66x9
Aug 18, 2026
goshs has a Path Traversal issue in github.com/patrickhener/goshs goshs has a Path Traversal issue in github.com/patrickhener/goshs Fixed in
2.1.5-0.20260727065949-f3ef599e4091
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-50138
GO-2026-5878
GHSA-3whc-qvhv-xqjp
Jul 07, 2026
goshs: WebDAV listener ignores --read-only, --upload-only, and --no-delete mode flags in goshs.de/goshs goshs: WebDAV listener ignores --read-only, --upload-only, and --no-delete mode flags in goshs.de/goshs Fixed in
2.1.0
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50139
GO-2026-5881
GHSA-j48m-h7xq-2xpj
Jul 07, 2026
goshs: Share-link ?token=… redemption races past download limit in goshs.de/goshs goshs: Share-link ?token=… redemption races past download limit in goshs.de/goshs Fixed in
2.1.0
Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5519
GHSA-mxg3-432p-mr72
Jun 25, 2026
goshs: SSH host key verification disabled, allowing transparent MITM of every tunnelled HTTP request in goshs.de/goshs goshs: SSH host key verification disabled, allowing transparent MITM of every tunnelled HTTP request in goshs.de/goshs Fixed in
2.0.7
References Updated Jun 25, 2026 · Source: OSV.dev |
v2.0.6
patch
Dependencies (24)
+ 16 more |
|
v2.0.5
patch
7 CVEs
CVE-2026-54719
GO-2026-6133
GHSA-rmxw-pq4x-3fvh
Aug 18, 2026
goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx) in github.com/patrickhener/goshs goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx) in github.com/patrickhener/goshs Fixed in
2.1.1
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-66064
GO-2026-6134
GHSA-964w-f6gj-5236
Aug 18, 2026
goshs has ACL Bypass & Path Traversal in github.com/patrickhener/goshs goshs has ACL Bypass & Path Traversal in github.com/patrickhener/goshs Fixed in
2.1.5-0.20260727065949-f3ef599e4091
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-64863
GO-2026-6136
GHSA-hq33-8jgp-8qq3
Aug 18, 2026
goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite in github.com/patrickhener/goshs goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite in github.com/patrickhener/goshs Fixed in
2.1.4
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-66063
GO-2026-6137
GHSA-wg2q-39h6-66x9
Aug 18, 2026
goshs has a Path Traversal issue in github.com/patrickhener/goshs goshs has a Path Traversal issue in github.com/patrickhener/goshs Fixed in
2.1.5-0.20260727065949-f3ef599e4091
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-50138
GO-2026-5878
GHSA-3whc-qvhv-xqjp
Jul 07, 2026
goshs: WebDAV listener ignores --read-only, --upload-only, and --no-delete mode flags in goshs.de/goshs goshs: WebDAV listener ignores --read-only, --upload-only, and --no-delete mode flags in goshs.de/goshs Fixed in
2.1.0
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50139
GO-2026-5881
GHSA-j48m-h7xq-2xpj
Jul 07, 2026
goshs: Share-link ?token=… redemption races past download limit in goshs.de/goshs goshs: Share-link ?token=… redemption races past download limit in goshs.de/goshs Fixed in
2.1.0
Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5519
GHSA-mxg3-432p-mr72
Jun 25, 2026
goshs: SSH host key verification disabled, allowing transparent MITM of every tunnelled HTTP request in goshs.de/goshs goshs: SSH host key verification disabled, allowing transparent MITM of every tunnelled HTTP request in goshs.de/goshs Fixed in
2.0.7
References Updated Jun 25, 2026 · Source: OSV.dev |
v2.0.5
patch
Dependencies (23)
+ 15 more |
|
v2.0.4
patch
7 CVEs
CVE-2026-54719
GO-2026-6133
GHSA-rmxw-pq4x-3fvh
Aug 18, 2026
goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx) in github.com/patrickhener/goshs goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx) in github.com/patrickhener/goshs Fixed in
2.1.1
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-66064
GO-2026-6134
GHSA-964w-f6gj-5236
Aug 18, 2026
goshs has ACL Bypass & Path Traversal in github.com/patrickhener/goshs goshs has ACL Bypass & Path Traversal in github.com/patrickhener/goshs Fixed in
2.1.5-0.20260727065949-f3ef599e4091
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-64863
GO-2026-6136
GHSA-hq33-8jgp-8qq3
Aug 18, 2026
goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite in github.com/patrickhener/goshs goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite in github.com/patrickhener/goshs Fixed in
2.1.4
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-66063
GO-2026-6137
GHSA-wg2q-39h6-66x9
Aug 18, 2026
goshs has a Path Traversal issue in github.com/patrickhener/goshs goshs has a Path Traversal issue in github.com/patrickhener/goshs Fixed in
2.1.5-0.20260727065949-f3ef599e4091
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-50138
GO-2026-5878
GHSA-3whc-qvhv-xqjp
Jul 07, 2026
goshs: WebDAV listener ignores --read-only, --upload-only, and --no-delete mode flags in goshs.de/goshs goshs: WebDAV listener ignores --read-only, --upload-only, and --no-delete mode flags in goshs.de/goshs Fixed in
2.1.0
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50139
GO-2026-5881
GHSA-j48m-h7xq-2xpj
Jul 07, 2026
goshs: Share-link ?token=… redemption races past download limit in goshs.de/goshs goshs: Share-link ?token=… redemption races past download limit in goshs.de/goshs Fixed in
2.1.0
Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5519
GHSA-mxg3-432p-mr72
Jun 25, 2026
goshs: SSH host key verification disabled, allowing transparent MITM of every tunnelled HTTP request in goshs.de/goshs goshs: SSH host key verification disabled, allowing transparent MITM of every tunnelled HTTP request in goshs.de/goshs Fixed in
2.0.7
References Updated Jun 25, 2026 · Source: OSV.dev |
v2.0.4
patch
Dependencies (23)
+ 15 more |
|
v2.0.3
patch
7 CVEs
CVE-2026-54719
GO-2026-6133
GHSA-rmxw-pq4x-3fvh
Aug 18, 2026
goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx) in github.com/patrickhener/goshs goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx) in github.com/patrickhener/goshs Fixed in
2.1.1
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-66064
GO-2026-6134
GHSA-964w-f6gj-5236
Aug 18, 2026
goshs has ACL Bypass & Path Traversal in github.com/patrickhener/goshs goshs has ACL Bypass & Path Traversal in github.com/patrickhener/goshs Fixed in
2.1.5-0.20260727065949-f3ef599e4091
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-64863
GO-2026-6136
GHSA-hq33-8jgp-8qq3
Aug 18, 2026
goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite in github.com/patrickhener/goshs goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite in github.com/patrickhener/goshs Fixed in
2.1.4
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-66063
GO-2026-6137
GHSA-wg2q-39h6-66x9
Aug 18, 2026
goshs has a Path Traversal issue in github.com/patrickhener/goshs goshs has a Path Traversal issue in github.com/patrickhener/goshs Fixed in
2.1.5-0.20260727065949-f3ef599e4091
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-50138
GO-2026-5878
GHSA-3whc-qvhv-xqjp
Jul 07, 2026
goshs: WebDAV listener ignores --read-only, --upload-only, and --no-delete mode flags in goshs.de/goshs goshs: WebDAV listener ignores --read-only, --upload-only, and --no-delete mode flags in goshs.de/goshs Fixed in
2.1.0
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50139
GO-2026-5881
GHSA-j48m-h7xq-2xpj
Jul 07, 2026
goshs: Share-link ?token=… redemption races past download limit in goshs.de/goshs goshs: Share-link ?token=… redemption races past download limit in goshs.de/goshs Fixed in
2.1.0
Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5519
GHSA-mxg3-432p-mr72
Jun 25, 2026
goshs: SSH host key verification disabled, allowing transparent MITM of every tunnelled HTTP request in goshs.de/goshs goshs: SSH host key verification disabled, allowing transparent MITM of every tunnelled HTTP request in goshs.de/goshs Fixed in
2.0.7
References Updated Jun 25, 2026 · Source: OSV.dev |
v2.0.3
patch
Dependencies (23)
+ 15 more |
|
v2.0.2
patch
7 CVEs
CVE-2026-54719
GO-2026-6133
GHSA-rmxw-pq4x-3fvh
Aug 18, 2026
goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx) in github.com/patrickhener/goshs goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx) in github.com/patrickhener/goshs Fixed in
2.1.1
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-66064
GO-2026-6134
GHSA-964w-f6gj-5236
Aug 18, 2026
goshs has ACL Bypass & Path Traversal in github.com/patrickhener/goshs goshs has ACL Bypass & Path Traversal in github.com/patrickhener/goshs Fixed in
2.1.5-0.20260727065949-f3ef599e4091
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-64863
GO-2026-6136
GHSA-hq33-8jgp-8qq3
Aug 18, 2026
goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite in github.com/patrickhener/goshs goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite in github.com/patrickhener/goshs Fixed in
2.1.4
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-66063
GO-2026-6137
GHSA-wg2q-39h6-66x9
Aug 18, 2026
goshs has a Path Traversal issue in github.com/patrickhener/goshs goshs has a Path Traversal issue in github.com/patrickhener/goshs Fixed in
2.1.5-0.20260727065949-f3ef599e4091
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-50138
GO-2026-5878
GHSA-3whc-qvhv-xqjp
Jul 07, 2026
goshs: WebDAV listener ignores --read-only, --upload-only, and --no-delete mode flags in goshs.de/goshs goshs: WebDAV listener ignores --read-only, --upload-only, and --no-delete mode flags in goshs.de/goshs Fixed in
2.1.0
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50139
GO-2026-5881
GHSA-j48m-h7xq-2xpj
Jul 07, 2026
goshs: Share-link ?token=… redemption races past download limit in goshs.de/goshs goshs: Share-link ?token=… redemption races past download limit in goshs.de/goshs Fixed in
2.1.0
Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5519
GHSA-mxg3-432p-mr72
Jun 25, 2026
goshs: SSH host key verification disabled, allowing transparent MITM of every tunnelled HTTP request in goshs.de/goshs goshs: SSH host key verification disabled, allowing transparent MITM of every tunnelled HTTP request in goshs.de/goshs Fixed in
2.0.7
References Updated Jun 25, 2026 · Source: OSV.dev |
v2.0.2
patch
Dependencies (23)
+ 15 more |
|
v2.0.0
initial
8 CVEs
CVE-2026-54719
GO-2026-6133
GHSA-rmxw-pq4x-3fvh
Aug 18, 2026
goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx) in github.com/patrickhener/goshs goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx) in github.com/patrickhener/goshs Fixed in
2.1.1
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-66064
GO-2026-6134
GHSA-964w-f6gj-5236
Aug 18, 2026
goshs has ACL Bypass & Path Traversal in github.com/patrickhener/goshs goshs has ACL Bypass & Path Traversal in github.com/patrickhener/goshs Fixed in
2.1.5-0.20260727065949-f3ef599e4091
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-64863
GO-2026-6136
GHSA-hq33-8jgp-8qq3
Aug 18, 2026
goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite in github.com/patrickhener/goshs goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite in github.com/patrickhener/goshs Fixed in
2.1.4
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-66063
GO-2026-6137
GHSA-wg2q-39h6-66x9
Aug 18, 2026
goshs has a Path Traversal issue in github.com/patrickhener/goshs goshs has a Path Traversal issue in github.com/patrickhener/goshs Fixed in
2.1.5-0.20260727065949-f3ef599e4091
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-50138
GO-2026-5878
GHSA-3whc-qvhv-xqjp
Jul 07, 2026
goshs: WebDAV listener ignores --read-only, --upload-only, and --no-delete mode flags in goshs.de/goshs goshs: WebDAV listener ignores --read-only, --upload-only, and --no-delete mode flags in goshs.de/goshs Fixed in
2.1.0
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50139
GO-2026-5881
GHSA-j48m-h7xq-2xpj
Jul 07, 2026
goshs: Share-link ?token=… redemption races past download limit in goshs.de/goshs goshs: Share-link ?token=… redemption races past download limit in goshs.de/goshs Fixed in
2.1.0
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-42091
GO-2026-5625
GHSA-rhf7-wvw3-vjvm
Jun 25, 2026
goshs has Cross-Origin Arbitrary File Write via Missing CSRF on PUT and Wildcard CORS in github.com/patrickhener/goshs goshs has Cross-Origin Arbitrary File Write via Missing CSRF on PUT and Wildcard CORS in github.com/patrickhener/goshs Fixed in
2.0.2
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-5519
GHSA-mxg3-432p-mr72
Jun 25, 2026
goshs: SSH host key verification disabled, allowing transparent MITM of every tunnelled HTTP request in goshs.de/goshs goshs: SSH host key verification disabled, allowing transparent MITM of every tunnelled HTTP request in goshs.de/goshs Fixed in
2.0.7
References Updated Jun 25, 2026 · Source: OSV.dev |
v2.0.0
initial
Dependencies (22)
+ 14 more |
|
v2.0.1
patch
8 CVEs
CVE-2026-54719
GO-2026-6133
GHSA-rmxw-pq4x-3fvh
Aug 18, 2026
goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx) in github.com/patrickhener/goshs goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx) in github.com/patrickhener/goshs Fixed in
2.1.1
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-66064
GO-2026-6134
GHSA-964w-f6gj-5236
Aug 18, 2026
goshs has ACL Bypass & Path Traversal in github.com/patrickhener/goshs goshs has ACL Bypass & Path Traversal in github.com/patrickhener/goshs Fixed in
2.1.5-0.20260727065949-f3ef599e4091
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-64863
GO-2026-6136
GHSA-hq33-8jgp-8qq3
Aug 18, 2026
goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite in github.com/patrickhener/goshs goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite in github.com/patrickhener/goshs Fixed in
2.1.4
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-66063
GO-2026-6137
GHSA-wg2q-39h6-66x9
Aug 18, 2026
goshs has a Path Traversal issue in github.com/patrickhener/goshs goshs has a Path Traversal issue in github.com/patrickhener/goshs Fixed in
2.1.5-0.20260727065949-f3ef599e4091
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-50138
GO-2026-5878
GHSA-3whc-qvhv-xqjp
Jul 07, 2026
goshs: WebDAV listener ignores --read-only, --upload-only, and --no-delete mode flags in goshs.de/goshs goshs: WebDAV listener ignores --read-only, --upload-only, and --no-delete mode flags in goshs.de/goshs Fixed in
2.1.0
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50139
GO-2026-5881
GHSA-j48m-h7xq-2xpj
Jul 07, 2026
goshs: Share-link ?token=… redemption races past download limit in goshs.de/goshs goshs: Share-link ?token=… redemption races past download limit in goshs.de/goshs Fixed in
2.1.0
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-42091
GO-2026-5625
GHSA-rhf7-wvw3-vjvm
Jun 25, 2026
goshs has Cross-Origin Arbitrary File Write via Missing CSRF on PUT and Wildcard CORS in github.com/patrickhener/goshs goshs has Cross-Origin Arbitrary File Write via Missing CSRF on PUT and Wildcard CORS in github.com/patrickhener/goshs Fixed in
2.0.2
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-5519
GHSA-mxg3-432p-mr72
Jun 25, 2026
goshs: SSH host key verification disabled, allowing transparent MITM of every tunnelled HTTP request in goshs.de/goshs goshs: SSH host key verification disabled, allowing transparent MITM of every tunnelled HTTP request in goshs.de/goshs Fixed in
2.0.7
References Updated Jun 25, 2026 · Source: OSV.dev |
v2.0.1
patch
Dependencies (22)
+ 14 more |