BRIEFING NOTE: CVE-2026-35393 goshs, a SimpleHTTPServer implementation written in Go, contains a critical path traversal vulnerability in versions prior to 2.0.0-beta.3 where the POST multipart upload directory is not properly sanitized. This flaw allows attackers to upload files to arbitrary locations on the server, potentially compromising system integrity. The vulnerability carries a CVSS 3.0 score of 9.8 CRITICAL due to its network-based attack vector requiring no authentication, low attack complexity, and high impact across confidentiality, integrity, and availability. An unauthenticated remote attacker can exploit this weakness with minimal effort to read, modify, or delete sensitive files. There is currently no evidence of active exploitation in the wild, as the vulnerability is not listed on the CISA Known Exploited Vulnerabilities catalog and remains inactive on the Hot List. The EPSS score of 0.0004 indicates very low probability of near-term exploitation, suggesting this may represent a prospective or hypothetical CVE entry. Organizations using goshs should prioritize upgrading to version 2.0.0-beta.3 or later as a precautionary measure.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.0.0CPE matchmatch criteria | cpe:2.3:a:goshs:goshs:*:*:*:*:*:go:*:* | ||
2.0.0CPE matchmatch criteria | cpe:2.3:a:goshs:goshs:2.0.0:beta1:*:*:*:go:*:* | ||
2.0.0CPE matchmatch criteria | cpe:2.3:a:goshs:goshs:2.0.0:beta2:*:*:*:go:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.