Back

MEDIUM

goshs has ACL Bypass & Path Traversal

Published Jul 28, 2026

Description

goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.5, the httpserver/handler.go sendFile handler opened files using a cleaned path but derived the authorization filename from raw req.URL.Path, so a trailing slash could bypass .goshs ACL-file protection and block-list checks. This issue is fixed in version 2.1.5.

Affected products

Remediation

No remediation recorded yet.

References (5)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner GitHub_M
Published Jul 28, 2026
Updated Jul 29, 2026
Reserved Jul 23, 2026

CISA Vulnrichment

Updated Jul 29, 2026

NVD

Status Deferred
Modified Jul 30, 2026

Red Hat

No data

ENISA EUVD

Assigner GitHub_M
Published Jul 28, 2026
Updated Jul 29, 2026