CVE-2026-34581 is a high-severity vulnerability (CVSS 8.1) affecting goshs, a SimpleHTTPServer written in Go, specifically versions 1.1.0 to before 2.0.0-beta.2. This flaw allows an unauthenticated attacker to bypass limited file download restrictions via a Share Token, granting access to all goshs functionalities, including remote code execution, which requires user interaction. The attack vector is network-based with low complexity, leading to high impacts on confidentiality and integrity. Although no public exploits or KEV entries exist, the vulnerability is on the Hot List and has generated some community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.1.0, < 2.0.0CPE matchmatch criteria | cpe:2.3:a:goshs:goshs:*:*:*:*:*:go:*:* | ||
2.0.0CPE matchmatch criteria | cpe:2.3:a:goshs:goshs:2.0.0:beta1:*:*:*:go:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.