Security Advisories for github.com/patrickhener/goshs/v2 in go
Moderate
15 days ago
goshs has ACL Bypass & Path Traversal
go
goshs.de/goshs, github.com/patrickhener/goshs, goshs.de/goshs/v2, github.com/patrickhener/goshs/v2
Moderate
15 days ago
goshs has a Path Traversal issue
go
github.com/patrickhener/goshs/v2, goshs.de/goshs/v2, github.com/patrickhener/goshs, goshs.de/goshs
Critical
15 days ago
goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite
go
github.com/patrickhener/goshs, goshs.de/goshs, github.com/patrickhener/goshs/v2, goshs.de/goshs/v2
High
15 days ago
goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx)
go
goshs.de/goshs/v2, goshs.de/goshs, github.com/patrickhener/goshs/v2, github.com/patrickhener/goshs
Critical
15 days ago
goshs SFTP authentication bypass via empty password (incomplete fix of CVE-2026-40884)
go
goshs.de/goshs/v2, github.com/patrickhener/goshs/v2
Moderate
4 months ago
goshs has Cross-Origin Arbitrary File Write via Missing CSRF on PUT and Wildcard CORS
go
github.com/patrickhener/goshs, github.com/patrickhener/goshs/v2
Low
4 months ago
Unauthenticated Open Redirect, Arbitrary HTTP Response Header Injection, Missing CSRF, and Invisible-Mode Bypass in goshs `/?redirect` endpoint
go
github.com/patrickhener/goshs/v2, github.com/patrickhener/goshs
High
4 months ago
goshs's public collaborator feed leaks .goshs ACL credentials and enables unauthorized access
go
github.com/patrickhener/goshs/v2
Moderate
4 months ago
goshs has CSRF in state-changing GET routes enables authenticated file deletion and directory creation
go
github.com/patrickhener/goshs/v2
Critical
4 months ago
goshs has an empty-username SFTP password authentication bypass
go
github.com/patrickhener/goshs/v2, github.com/patrickhener/goshs
High
4 months ago
SFTP root escape via prefix-based path validation in goshs
go
github.com/patrickhener/goshs/v2, github.com/patrickhener/goshs