CVE-2026-54719

HIGH

goshs < 2.1.1 - Unauthenticated Bulk Download ACL Bypass

Title source: manual
STIX 2.1

Description

goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.1, the httpserver/updown.go bulkDownload handler for ?bulk&file= ZIP downloads did not call findEffectiveACL or applyCustomAuth, allowing unauthenticated reads of files protected only by .goshs folder ACLs and block lists. This issue is fixed in version 2.1.1. This vulnerability exists due to an incomplete fix for CVE-2026-40189.

Scores

CVSS v3 7.5
EPSS 0.0028
EPSS Percentile 20.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-862 CWE-863
Status published
Products (5)
goshs/v2 0 - 2.1.1Go
goshs-labs/goshs < 2.1.1
goshs.de/goshs 0 - 1.1.4Go
patrickhener/goshs 0 - 1.1.4Go
patrickhener/goshs 0 - 2.1.1Go
Published Jul 28, 2026
Tracked Since Jul 29, 2026