Goshs is a narrowly scoped web application or service product that sits in a more prominent position in the vulnerability landscape than typical single-product vendors. Vulnerabilities affecting this product skew strongly toward critical-severity outcomes and recur across access-control and input-handling weakness classes including path traversal, authentication bypass, cross-site request forgery, and exposure of sensitive information, which are endemic to web-facing applications with insufficient boundary enforcement. Defenders should prioritize Goshs advisories given the severity profile and monitor the product for these recurring flaw patterns; live exploitation and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Goshs over time
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-35471CRITICAL goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.3, tdeleteFile() missing return after path traversal check. This vulnerability is fixed in 2.0.0-beta.3. | Apr 6, 2026 | 9.8 | 34 | NO | NO |
CVE-2026-35393CRITICAL goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.3, the POST multipart upload directory not sanitized. This vulnerability is fixed in 2.0.0-beta.3. | Apr 6, 2026 | 9.8 | 34 | NO | NO |
CVE-2026-40189CRITICAL goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.4, goshs enforces the documented per-folder .goshs ACL/basic-auth mechanism for directory listings and file reads, bu | Apr 10, 2026 | 9.8 | 33 | NO | NO |
CVE-2026-35392CRITICAL goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.3, PUT upload in httpserver/updown.go has no path sanitization. This vulnerability is fixed in 2.0.0-beta.3. | Apr 6, 2026 | 9.8 | 33 | NO | NO |
CVE-2026-40884CRITICAL goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.6, goshs contains an SFTP authentication bypass when the documented empty-username basic-auth syntax is used. If the | Apr 21, 2026 | 9.8 | 32 | NO | NO |
CVE-2026-40903CRITICAL goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.6, goshs has an ArtiPACKED vulnerability. ArtiPACKED can lead to leakage of the GITHUB_TOKEN through workflow artifac | Apr 21, 2026 | 9.1 | 30 | NO | NO |
CVE-2026-34581HIGH goshs is a SimpleHTTPServer written in Go. From version 1.1.0 to before version 2.0.0-beta.2, when using the Share Token it is possible to bypass the limited selected file download | Apr 2, 2026 | 8.1 | 29 | NO | NO |
CVE-2026-42091MEDIUM goshs is a SimpleHTTPServer written in Go. Prior to version 2.0.2, the PUT upload handler (httpserver/updown.go) lacks the CSRF token validation that was added to the POST upload h | May 4, 2026 | 6.5 | 27 | NO | NO |
CVE-2026-40885HIGH goshs is a SimpleHTTPServer written in Go. From 2.0.0-beta.4 to 2.0.0-beta.5, goshs leaks file-based ACL credentials through its public collaborator feed when the server is deploye | Apr 21, 2026 | 8.8 | 27 | NO | NO |
CVE-2026-40876HIGH goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.6, goshs contains an SFTP root escape caused by prefix-based path validation. An authenticated SFTP user can read fro | Apr 21, 2026 | 8.8 | 27 | NO | NO |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Goshs.
Media articles that mention a CVE ID that affects a product developed by Goshs — matched by CVE ID, not by vendor name.