Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-7h3j-592v-jcrp | goshs's public collaborator feed leaks .goshs ACL credentials and enables unauthorized access |
Mon, 27 Apr 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Goshs
Goshs goshs |
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:goshs:goshs:2.0.0:beta4:*:*:*:go:*:* cpe:2.3:a:goshs:goshs:2.0.0:beta5:*:*:*:go:*:* |
|
| Vendors & Products |
Goshs
Goshs goshs |
|
| Metrics |
cvssV3_1
|
Wed, 22 Apr 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Patrickhener
Patrickhener goshs |
|
| Vendors & Products |
Patrickhener
Patrickhener goshs |
Wed, 22 Apr 2026 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | goshs is a SimpleHTTPServer written in Go. From 2.0.0-beta.4 to 2.0.0-beta.5, goshs leaks file-based ACL credentials through its public collaborator feed when the server is deployed without global basic auth. Requests to .goshs-protected folders are logged before authorization is enforced, and the collaborator websocket broadcasts raw request headers, including Authorization. An unauthenticated observer can capture a victim's folder-specific basic-auth header and replay it to read, upload, overwrite, and delete files inside the protected subtree. This vulnerability is fixed in 2.0.0-beta.6. | |
| Title | goshs: Public collaborator feed leaks .goshs ACL credentials and enables unauthorized access | |
| Weaknesses | CWE-200 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-04-21T20:05:26.627Z
Reserved: 2026-04-15T15:57:41.719Z
Link: CVE-2026-40885
Updated: 2026-04-21T20:05:14.784Z
Status : Analyzed
Published: 2026-04-21T20:17:02.257
Modified: 2026-04-27T14:51:50.770
Link: CVE-2026-40885
No data.
OpenCVE Enrichment
Updated: 2026-04-28T16:30:35Z
Github GHSA