CVE-2026-30955 affects Gokapi, a self-hosted file sharing server, in versions prior to 2.2.4, due to an API endpoint accepting unbounded request bodies. This CWE-400 vulnerability allows an authenticated user to cause an Out-Of-Memory (OOM) kill, leading to complete service disruption for all users. Rated Medium with a CVSS score of 6.5, it has a network attack vector and low complexity, primarily impacting system availability. There is currently no evidence of active exploitation, no public exploit code available, and minimal community attention, with the CVE not listed on CISA's KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.2.4CPE matchmatch criteria | cpe:2.3:a:forceu:gokapi:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.