Security: goshs-labs/goshs
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Unauthenticated attackers can bypass basic auth via the ConPtyShell route exemptionGHSA-6m5c-fv2q-jrj2 published
Jul 29, 2026 by patrickhenerCritical -
goshs WebDAV POST returns full file contents, bypassing --upload-onlyGHSA-rc9g-fmpg-c6pp published
Jul 29, 2026 by patrickhenerHigh -
goshs --no-delete/--upload-only bypass: PUT/POST overwrite of existing files destroys contents (HTTP and WebDAV)GHSA-966r-mw4j-rv64 published
Jul 29, 2026 by patrickhenerCritical -
Path TraversalGHSA-wg2q-39h6-66x9 published
Jul 27, 2026 by patrickhenerModerate -
ACL BypassGHSA-964w-f6gj-5236 published
Jul 27, 2026 by patrickhenerModerate -
goshs --no-delete WebDAV MOVE bypass allows file deletion/overwriteGHSA-hq33-8jgp-8qq3 published
Jul 3, 2026 by patrickhenerCritical -
goshs SFTP authentication bypass via empty password (incomplete fix of CVE-2026-40884)GHSA-rjrw-mjq6-hpmm published
Jun 26, 2026 by patrickhenerCritical -
File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx)GHSA-rmxw-pq4x-3fvh published
Jun 8, 2026 by patrickhenerHigh -
Share-link ?token=… redemption races past download limitGHSA-j48m-h7xq-2xpj published
May 28, 2026 by patrickhenerModerate -
WebDAV listener ignores --read-only, --upload-only, and --no-delete mode flagsGHSA-3whc-qvhv-xqjp published
May 28, 2026 by patrickhenerHigh