Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:golang/github.com/patrickhener/goshs

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

The goshs SimpleHTTPServer written in Go versions prior to 2.0.0-beta.6 contains a critical vulnerability (CVE-2026-40903) involving inclusion of functionality from an untrusted control sphere. This vulnerability, classified as CWE-829, can cause leakage of the GITHUB_TOKEN through workflow artifacts despite the token not being present in the repository source code. The issue is fixed starting from version 2.0.0-beta.6. The vulnerability has a high CVSS score of 9.

Join the discussion

goshs is a SimpleHTTPServer written in Go. From 2.0.0-beta.4 to 2.0.0-beta.5, goshs leaks file-based ACL credentials through its public collaborator feed when the server is deployed without global basic auth. Requests to .goshs-protected folders are logged before authorization is enforced, and the collaborator websocket broadcasts raw request headers, including Authorization. An unauthenticated observer can capture a victim's folder-specific basic-auth header and replay it to read, upload, overwrite, and delete files inside the protected subtree. This vulnerability is fixed in 2.0.0-beta.6.

Join the discussion

CVE-2026-40884 is a critical vulnerability in goshs, a SimpleHTTPServer written in Go, affecting versions prior to 2.0.0-beta.6. The issue arises when the server is started with the -b ':pass' option together with -sftp, causing goshs to accept the configuration but fail to install any SFTP password handler. This results in an authentication bypass allowing unauthenticated network attackers to access files via the SFTP service without a password. The vulnerability is fixed in version 2.0.0-beta.6.

Join the discussion

goshs is a SimpleHTTPServer written in Go. From 2.0.0-beta.4 to 2.0.0-beta.5, goshs contains a cross-site request forgery issue in its state-changing HTTP GET routes. An external attacker can cause an already authenticated browser to trigger destructive actions such as ?delete and ?mkdir because goshs relies on HTTP basic auth alone and performs no CSRF, Origin, or Referer validation for those routes. This vulnerability is fixed in 2.0.0-beta.6.

Join the discussion

CVE-2026-40876 is a path traversal vulnerability in patrickhener goshs, a SimpleHTTPServer written in Go. Versions prior to 2.0.0-beta.6 improperly validate SFTP paths using a prefix-based check, allowing authenticated SFTP users to escape the intended root jail. This enables reading and writing files outside the configured SFTP root directory, potentially exposing or modifying unrelated server files. The issue arises because the path validation does not correctly enforce directory boundaries, allowing sibling directories with similar prefixes to bypass restrictions. This vulnerability has a high severity score of 8.7 and is fixed in version 2.0.

Join the discussion

goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.4, goshs enforces the documented per-folder .goshs ACL/basic-auth mechanism for directory listings and file reads, but it does not enforce the same authorization checks for state-changing routes. An unauthenticated attacker can upload files with PUT, upload files with multipart POST /upload, create directories with ?mkdir, and delete files with ?delete inside a .goshs-protected directory. By deleting the .goshs file itself, the attacker can remove the folder's auth policy and then access previously protected content without credentials. This results in a critical authorization bypass affecting confidentiality, integrity, and availability. This vulnerability is fixed in 2.0.0-beta.4.

Join the discussion

goshs is a SimpleHTTPServer written in Go. From 1.0.7 to before 2.0.0-beta.4, the SFTP command rename sanitizes only the source path and not the destination, so it is possible to write outside of the root directory of the SFTP. This vulnerability is fixed in 2.0.0-beta.4.

Join the discussion

CVE-2026-35471 is a critical path traversal vulnerability in patrickhener's goshs SimpleHTTPServer written in Go. Versions prior to 2.0.0-beta.3 are affected due to a missing return statement after a path traversal check in the tdeleteFile() function. This flaw allows an attacker to bypass directory restrictions and potentially access or modify unauthorized files. The vulnerability has a CVSS score of 9.8, indicating high impact on confidentiality, integrity, and availability. The issue is fixed starting from version 2.0.

Join the discussion

goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.3, the POST multipart upload directory not sanitized. This vulnerability is fixed in 2.0.0-beta.3.

Join the discussion

CVE-2026-35392 is a critical path traversal vulnerability in patrickhener's goshs, a SimpleHTTPServer written in Go. Versions prior to 2.0.0-beta.3 do not sanitize file paths during PUT uploads, allowing attackers to potentially write files outside the intended directory. This can lead to full compromise of confidentiality, integrity, and availability of the affected system. The vulnerability is fixed in version 2.0.0-beta.3.

Join the discussion

Showing 1 to 10 of 11 results

Filters:Package: pkg:golang/github.com/patrickhener/goshs
Page 1 of 2
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses