MEDIUM
goshs has a Path Traversal issue
Published Jul 28, 2026
6.5
MEDIUMCVSS 3.1
EPSS 0.34%
Description
goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.5, the httpserver/updown.go multipart upload handler split part.FileName() on / but did not reject .., allowing an unauthenticated upload with filename .. to create a file outside the served tree. This issue is fixed in version 2.1.5.
Affected products
-
- Version < 2.1.5StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Goshs-Labs | Goshs | n/a |
|
No data.
No data.
No Red Hat product state for this CVE.
github.com/patrickhener/goshs/v2
Go
Introduced 0 Fixed 2.1.5-0.20260727065949-f3ef599e4091goshs.de/goshs
Go
Introduced 0 Fixed not fixedgithub.com/patrickhener/goshs
Go
Introduced 0 Fixed not fixedgoshs.de/goshs/v2
Go
Introduced 0 Fixed 2.1.5-0.20260727065949-f3ef599e4091
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | github.com/patrickhener/goshs/v2 | 0 | 2.1.5-0.20260727065949-f3ef599e4091 |
| Go | goshs.de/goshs | 0 | not fixed |
| Go | github.com/patrickhener/goshs | 0 | not fixed |
| Go | goshs.de/goshs/v2 | 0 | 2.1.5-0.20260727065949-f3ef599e4091 |
Remediation
No remediation recorded yet.
Weaknesses (1)
References (4)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-50082 Advisory
- https://github.com/advisories/GHSA-wg2q-39h6-66x9 Advisory
- https://github.com/goshs-labs/goshs/commit/f3ef599e409151d1380866e47de8b1afb0bb54fa x_refsource_MISC
- https://github.com/goshs-labs/goshs/security/advisories/GHSA-wg2q-39h6-66x9 x_refsource_CONFIRM
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-50082 | Advisory | |
| https://github.com/advisories/GHSA-wg2q-39h6-66x9 | Advisory | |
| https://github.com/goshs-labs/goshs/commit/f3ef599e409151d1380866e47de8b1afb0bb54fa | x_refsource_MISC | |
| https://github.com/goshs-labs/goshs/security/advisories/GHSA-wg2q-39h6-66x9 | x_refsource_CONFIRM |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Jul 28, 2026
Updated Jul 29, 2026
Reserved Jul 23, 2026
Link CVE-2026-66063
CISA Vulnrichment
Updated Jul 29, 2026
ENISA EUVD
EUVD-2026-50082 GHSA-WG2Q-39H6-66X9 Assigner GitHub_M
Published Jul 28, 2026
Updated Jul 29, 2026
Exploited since n/a
Link EUVD-2026-50082