OVERVIEW CVE-2026-40189 is a critical authorization bypass vulnerability in goshs, a Go-based SimpleHTTPServer implementation. The flaw exists in versions prior to 2.0.0-beta.4 and allows unauthenticated attackers to circumvent access controls on protected directories by exploiting missing authorization checks on state-changing operations. SEVERITY The vulnerability carries a CVSS 3.1 score of 9.8 (CRITICAL) with a network attack vector requiring no authentication, low complexity, and no user interaction. An attacker can upload files via PUT or multipart POST requests, create directories, delete files, and critically, delete the .goshs configuration file itself to remove authentication protections entirely. This results in complete compromise of confidentiality, integrity, and availability for protected content. EXPLOITATION STATUS The vulnerability is currently inactive on vulnerability tracking lists with no evidence of active exploitation in the wild. The EPSS score of 0.00139 is significantly lower than the average CVE, suggesting minimal exploitation likelihood in practice. No public exploit code has achieved widespread attention, and the issue appears to have limited community exploitation activity at this time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.0.0CPE matchmatch criteria | cpe:2.3:a:goshs:goshs:*:*:*:*:*:go:*:* | ||
2.0.0CPE matchmatch criteria | cpe:2.3:a:goshs:goshs:2.0.0:beta1:*:*:*:go:*:* | ||
2.0.0CPE matchmatch criteria | cpe:2.3:a:goshs:goshs:2.0.0:beta2:*:*:*:go:*:* | ||
2.0.0CPE matchmatch criteria | cpe:2.3:a:goshs:goshs:2.0.0:beta3:*:*:*:go:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.