goshs has ACL Bypass & Path Traversal
Published Jul 28, 2026
5.3
MEDIUMCVSS 3.1
EPSS 0.45%
Description
goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.5, the httpserver/handler.go sendFile handler opened files using a cleaned path but derived the authorization filename from raw req.URL.Path, so a trailing slash could bypass .goshs ACL-file protection and block-list checks. This issue is fixed in version 2.1.5.
Affected products
-
Affected
- < 2.1.5
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Goshs-Labs | Goshs | unknown | Affected
|
No data.
No data.
No Red Hat product state for this CVE.
github.com/patrickhener/goshs/v2
Go
Introduced 0 Fixed 2.1.5-0.20260727065949-f3ef599e4091goshs.de/goshs/v2
Go
Introduced 0 Fixed 2.1.5-0.20260727065949-f3ef599e4091github.com/patrickhener/goshs
Go
Introduced 0 Fixed not fixedgoshs.de/goshs
Go
Introduced 0 Fixed not fixed
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | github.com/patrickhener/goshs/v2 | 0 | 2.1.5-0.20260727065949-f3ef599e4091 |
| Go | goshs.de/goshs/v2 | 0 | 2.1.5-0.20260727065949-f3ef599e4091 |
| Go | github.com/patrickhener/goshs | 0 | not fixed |
| Go | goshs.de/goshs | 0 | not fixed |
Remediation
No remediation recorded yet.
References (5)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-50083 Advisory
- https://github.com/advisories/GHSA-964w-f6gj-5236 Advisory
- https://github.com/goshs-labs/goshs/commit/f3ef599e409151d1380866e47de8b1afb0bb54fa x_refsource_MISC
- https://github.com/goshs-labs/goshs/pull/222 x_refsource_MISC
- https://github.com/goshs-labs/goshs/security/advisories/GHSA-964w-f6gj-5236 x_refsource_CONFIRM
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-50083 | Advisory | |
| https://github.com/advisories/GHSA-964w-f6gj-5236 | Advisory | |
| https://github.com/goshs-labs/goshs/commit/f3ef599e409151d1380866e47de8b1afb0bb54fa | x_refsource_MISC | |
| https://github.com/goshs-labs/goshs/pull/222 | x_refsource_MISC | |
| https://github.com/goshs-labs/goshs/security/advisories/GHSA-964w-f6gj-5236 | x_refsource_CONFIRM |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
Red Hat
No data
GitHub