CVE-2026-34581

HIGH

goshs has Auth Bypass via Share Token

Title source: cna

Description

goshs is a SimpleHTTPServer written in Go. From version 1.1.0 to before version 2.0.0-beta.2, when using the Share Token it is possible to bypass the limited selected file download with all the gosh functionalities, including code exec. This issue has been patched in version 2.0.0-beta.2.

Scores

CVSS v3 8.1
EPSS 0.0003
EPSS Percentile 8.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-288
Status published
Products (4)
goshs/goshs 2.0.0 beta1
goshs/goshs 1.1.0 - 2.0.0
patrickhener/goshs 1.1.0Go
patrickhener/goshs >= 1.1.0, < 2.0.0-beta.2
Published Apr 02, 2026
Tracked Since Apr 03, 2026