Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 01 May 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Goshs
Goshs goshs |
|
| CPEs | cpe:2.3:a:goshs:goshs:*:*:*:*:*:go:*:* cpe:2.3:a:goshs:goshs:2.0.0:beta1:*:*:*:go:*:* cpe:2.3:a:goshs:goshs:2.0.0:beta2:*:*:*:go:*:* cpe:2.3:a:goshs:goshs:2.0.0:beta3:*:*:*:go:*:* cpe:2.3:a:goshs:goshs:2.0.0:beta4:*:*:*:go:*:* cpe:2.3:a:goshs:goshs:2.0.0:beta5:*:*:*:go:*:* |
|
| Vendors & Products |
Goshs
Goshs goshs |
Wed, 22 Apr 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 22 Apr 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Patrickhener
Patrickhener goshs |
|
| Vendors & Products |
Patrickhener
Patrickhener goshs |
Wed, 22 Apr 2026 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.6, goshs has an ArtiPACKED vulnerability. ArtiPACKED can lead to leakage of the GITHUB_TOKEN through workflow artifacts, even though the token is not present in the repository source code. This vulnerability is fixed in 2.0.0-beta.6. | |
| Title | Goshs - ArtiPACKED Vulnerability – GitHub Actions Credential Persistence | |
| Weaknesses | CWE-829 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-04-22T13:45:41.782Z
Reserved: 2026-04-15T16:37:22.767Z
Link: CVE-2026-40903
Updated: 2026-04-22T13:45:38.058Z
Status : Analyzed
Published: 2026-04-21T20:17:02.947
Modified: 2026-05-01T16:15:06.670
Link: CVE-2026-40903
No data.
OpenCVE Enrichment
Updated: 2026-04-22T11:45:22Z