CRITICAL9.8CVE-2026-40884goshs has an empty-username SFTP password authentication bypass in github.com/patrickhener/goshs from 0, < 2.0.0
CRITICAL9.8CVE-2026-40884goshs has an empty-username SFTP password authentication bypass in github.com/patrickhener/goshs from 0, < 2.0.0
HIGH8.8CVE-2026-40885goshs's public collaborator feed leaks .goshs ACL credentials and enables unauthorized access in github.com/patrickhener/goshs >= 2.0.0-beta.4, < 2.0.0-beta.6
HIGH8.8goshs's public collaborator feed leaks .goshs ACL credentials and enables unauthorized access in github.com/patrickhener/goshs
>= 2.0.0-beta.4, < 2.0.0-beta.6
HIGH8.8SFTP root escape via prefix-based path validation in goshs in github.com/patrickhener/goshs
from 0, < 2.0.0
HIGH8.8SFTP root escape via prefix-based path validation in goshs in github.com/patrickhener/goshs
from 0, < 2.0.0
HIGH8.1goshs has CSRF in state-changing GET routes enables authenticated file deletion and directory creation in github.com/patrickhener/goshs
>= 2.0.0-beta.4, < 2.0.0-beta.6
HIGH8.1goshs has CSRF in state-changing GET routes enables authenticated file deletion and directory creation in github.com/patrickhener/goshs
>= 2.0.0-beta.4, < 2.0.0-beta.6
MEDIUM6.5goshs has Cross-Origin Arbitrary File Write via Missing CSRF on PUT and Wildcard CORS in github.com/patrickhener/goshs
from 0, < 2.0.2