httpserver

package

Versions in this module

v1
Mar 13, 2026 GO-2026-4953 +15 more
Alert  GO-2026-4953: goshs is Missing Write Protection for Parametric Data Values in github.com/patrickhener/goshs
Alert  GO-2026-5146: SFTP root escape via prefix-based path validation in goshs in github.com/patrickhener/goshs
Alert  GO-2026-5186: goshs: Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) in github.com/patrickhener/goshs
Alert  GO-2026-5221: goshs's public collaborator feed leaks .goshs ACL credentials and enables unauthorized access in github.com/patrickhener/goshs
Alert  GO-2026-5232: Unauthenticated Open Redirect, Arbitrary HTTP Response Header Injection, Missing CSRF, and Invisible-Mode Bypass in goshs `/?redirect` endpoint in github.com/patrickhener/goshs
Alert  GO-2026-5303: goshs has an empty-username SFTP password authentication bypass in github.com/patrickhener/goshs
Alert  GO-2026-5394: goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs PUT Upload in github.com/patrickhener/goshs
Alert  GO-2026-5468: goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs POST multipart upload in github.com/patrickhener/goshs
Alert  GO-2026-5469: goshs has Auth Bypass via Share Token in github.com/patrickhener/goshs
Alert  GO-2026-5479: goshs has CSRF in state-changing GET routes enables authenticated file deletion and directory creation in github.com/patrickhener/goshs
Alert  GO-2026-5625: goshs has Cross-Origin Arbitrary File Write via Missing CSRF on PUT and Wildcard CORS in github.com/patrickhener/goshs
Alert  GO-2026-5728: goshs has a file-based ACL authorization bypass in goshs state-changing routes in github.com/patrickhener/goshs
Alert  GO-2026-6133: goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx) in github.com/patrickhener/goshs
Alert  GO-2026-6134: goshs has ACL Bypass & Path Traversal in github.com/patrickhener/goshs
Alert  GO-2026-6136: goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite in github.com/patrickhener/goshs
Alert  GO-2026-6137: goshs has a Path Traversal issue in github.com/patrickhener/goshs
Nov 12, 2025 GO-2026-4953 +15 more
Alert  GO-2026-4953: goshs is Missing Write Protection for Parametric Data Values in github.com/patrickhener/goshs
Alert  GO-2026-5146: SFTP root escape via prefix-based path validation in goshs in github.com/patrickhener/goshs
Alert  GO-2026-5186: goshs: Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) in github.com/patrickhener/goshs
Alert  GO-2026-5221: goshs's public collaborator feed leaks .goshs ACL credentials and enables unauthorized access in github.com/patrickhener/goshs
Alert  GO-2026-5232: Unauthenticated Open Redirect, Arbitrary HTTP Response Header Injection, Missing CSRF, and Invisible-Mode Bypass in goshs `/?redirect` endpoint in github.com/patrickhener/goshs
Alert  GO-2026-5303: goshs has an empty-username SFTP password authentication bypass in github.com/patrickhener/goshs
Alert  GO-2026-5394: goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs PUT Upload in github.com/patrickhener/goshs
Alert  GO-2026-5468: goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs POST multipart upload in github.com/patrickhener/goshs
Alert  GO-2026-5469: goshs has Auth Bypass via Share Token in github.com/patrickhener/goshs
Alert  GO-2026-5479: goshs has CSRF in state-changing GET routes enables authenticated file deletion and directory creation in github.com/patrickhener/goshs
Alert  GO-2026-5625: goshs has Cross-Origin Arbitrary File Write via Missing CSRF on PUT and Wildcard CORS in github.com/patrickhener/goshs
Alert  GO-2026-5728: goshs has a file-based ACL authorization bypass in goshs state-changing routes in github.com/patrickhener/goshs
Alert  GO-2026-6133: goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx) in github.com/patrickhener/goshs
Alert  GO-2026-6134: goshs has ACL Bypass & Path Traversal in github.com/patrickhener/goshs
Alert  GO-2026-6136: goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite in github.com/patrickhener/goshs
Alert  GO-2026-6137: goshs has a Path Traversal issue in github.com/patrickhener/goshs
Sep 22, 2025 GO-2026-4953 +15 more
Alert  GO-2026-4953: goshs is Missing Write Protection for Parametric Data Values in github.com/patrickhener/goshs
Alert  GO-2026-5146: SFTP root escape via prefix-based path validation in goshs in github.com/patrickhener/goshs
Alert  GO-2026-5186: goshs: Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) in github.com/patrickhener/goshs
Alert  GO-2026-5221: goshs's public collaborator feed leaks .goshs ACL credentials and enables unauthorized access in github.com/patrickhener/goshs
Alert  GO-2026-5232: Unauthenticated Open Redirect, Arbitrary HTTP Response Header Injection, Missing CSRF, and Invisible-Mode Bypass in goshs `/?redirect` endpoint in github.com/patrickhener/goshs
Alert  GO-2026-5303: goshs has an empty-username SFTP password authentication bypass in github.com/patrickhener/goshs
Alert  GO-2026-5394: goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs PUT Upload in github.com/patrickhener/goshs
Alert  GO-2026-5468: goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs POST multipart upload in github.com/patrickhener/goshs
Alert  GO-2026-5469: goshs has Auth Bypass via Share Token in github.com/patrickhener/goshs
Alert  GO-2026-5479: goshs has CSRF in state-changing GET routes enables authenticated file deletion and directory creation in github.com/patrickhener/goshs
Alert  GO-2026-5625: goshs has Cross-Origin Arbitrary File Write via Missing CSRF on PUT and Wildcard CORS in github.com/patrickhener/goshs
Alert  GO-2026-5728: goshs has a file-based ACL authorization bypass in goshs state-changing routes in github.com/patrickhener/goshs
Alert  GO-2026-6133: goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx) in github.com/patrickhener/goshs
Alert  GO-2026-6134: goshs has ACL Bypass & Path Traversal in github.com/patrickhener/goshs
Alert  GO-2026-6136: goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite in github.com/patrickhener/goshs
Alert  GO-2026-6137: goshs has a Path Traversal issue in github.com/patrickhener/goshs
Changes in this version
type FileServer
Jun 3, 2025 GO-2026-4953 +15 more
Alert  GO-2026-4953: goshs is Missing Write Protection for Parametric Data Values in github.com/patrickhener/goshs
Alert  GO-2026-5146: SFTP root escape via prefix-based path validation in goshs in github.com/patrickhener/goshs
Alert  GO-2026-5186: goshs: Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) in github.com/patrickhener/goshs
Alert  GO-2026-5221: goshs's public collaborator feed leaks .goshs ACL credentials and enables unauthorized access in github.com/patrickhener/goshs
Alert  GO-2026-5232: Unauthenticated Open Redirect, Arbitrary HTTP Response Header Injection, Missing CSRF, and Invisible-Mode Bypass in goshs `/?redirect` endpoint in github.com/patrickhener/goshs
Alert  GO-2026-5303: goshs has an empty-username SFTP password authentication bypass in github.com/patrickhener/goshs
Alert  GO-2026-5394: goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs PUT Upload in github.com/patrickhener/goshs
Alert  GO-2026-5468: goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs POST multipart upload in github.com/patrickhener/goshs
Alert  GO-2026-5469: goshs has Auth Bypass via Share Token in github.com/patrickhener/goshs
Alert  GO-2026-5479: goshs has CSRF in state-changing GET routes enables authenticated file deletion and directory creation in github.com/patrickhener/goshs
Alert  GO-2026-5625: goshs has Cross-Origin Arbitrary File Write via Missing CSRF on PUT and Wildcard CORS in github.com/patrickhener/goshs
Alert  GO-2026-5728: goshs has a file-based ACL authorization bypass in goshs state-changing routes in github.com/patrickhener/goshs
Alert  GO-2026-6133: goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx) in github.com/patrickhener/goshs
Alert  GO-2026-6134: goshs has ACL Bypass & Path Traversal in github.com/patrickhener/goshs
Alert  GO-2026-6136: goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite in github.com/patrickhener/goshs
Alert  GO-2026-6137: goshs has a Path Traversal issue in github.com/patrickhener/goshs
May 28, 2025 GO-2026-4953 +14 more
Alert  GO-2026-4953: goshs is Missing Write Protection for Parametric Data Values in github.com/patrickhener/goshs
Alert  GO-2026-5146: SFTP root escape via prefix-based path validation in goshs in github.com/patrickhener/goshs
Alert  GO-2026-5186: goshs: Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) in github.com/patrickhener/goshs
Alert  GO-2026-5221: goshs's public collaborator feed leaks .goshs ACL credentials and enables unauthorized access in github.com/patrickhener/goshs
Alert  GO-2026-5232: Unauthenticated Open Redirect, Arbitrary HTTP Response Header Injection, Missing CSRF, and Invisible-Mode Bypass in goshs `/?redirect` endpoint in github.com/patrickhener/goshs
Alert  GO-2026-5303: goshs has an empty-username SFTP password authentication bypass in github.com/patrickhener/goshs
Alert  GO-2026-5394: goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs PUT Upload in github.com/patrickhener/goshs
Alert  GO-2026-5468: goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs POST multipart upload in github.com/patrickhener/goshs
Alert  GO-2026-5479: goshs has CSRF in state-changing GET routes enables authenticated file deletion and directory creation in github.com/patrickhener/goshs
Alert  GO-2026-5625: goshs has Cross-Origin Arbitrary File Write via Missing CSRF on PUT and Wildcard CORS in github.com/patrickhener/goshs
Alert  GO-2026-5728: goshs has a file-based ACL authorization bypass in goshs state-changing routes in github.com/patrickhener/goshs
Alert  GO-2026-6133: goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx) in github.com/patrickhener/goshs
Alert  GO-2026-6134: goshs has ACL Bypass & Path Traversal in github.com/patrickhener/goshs
Alert  GO-2026-6136: goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite in github.com/patrickhener/goshs
Alert  GO-2026-6137: goshs has a Path Traversal issue in github.com/patrickhener/goshs
May 20, 2025 GO-2026-4953 +14 more
Alert  GO-2026-4953: goshs is Missing Write Protection for Parametric Data Values in github.com/patrickhener/goshs
Alert  GO-2026-5146: SFTP root escape via prefix-based path validation in goshs in github.com/patrickhener/goshs
Alert  GO-2026-5186: goshs: Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) in github.com/patrickhener/goshs
Alert  GO-2026-5221: goshs's public collaborator feed leaks .goshs ACL credentials and enables unauthorized access in github.com/patrickhener/goshs
Alert  GO-2026-5232: Unauthenticated Open Redirect, Arbitrary HTTP Response Header Injection, Missing CSRF, and Invisible-Mode Bypass in goshs `/?redirect` endpoint in github.com/patrickhener/goshs
Alert  GO-2026-5303: goshs has an empty-username SFTP password authentication bypass in github.com/patrickhener/goshs
Alert  GO-2026-5394: goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs PUT Upload in github.com/patrickhener/goshs
Alert  GO-2026-5468: goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs POST multipart upload in github.com/patrickhener/goshs
Alert  GO-2026-5479: goshs has CSRF in state-changing GET routes enables authenticated file deletion and directory creation in github.com/patrickhener/goshs
Alert  GO-2026-5625: goshs has Cross-Origin Arbitrary File Write via Missing CSRF on PUT and Wildcard CORS in github.com/patrickhener/goshs
Alert  GO-2026-5728: goshs has a file-based ACL authorization bypass in goshs state-changing routes in github.com/patrickhener/goshs
Alert  GO-2026-6133: goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx) in github.com/patrickhener/goshs
Alert  GO-2026-6134: goshs has ACL Bypass & Path Traversal in github.com/patrickhener/goshs
Alert  GO-2026-6136: goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite in github.com/patrickhener/goshs
Alert  GO-2026-6137: goshs has a Path Traversal issue in github.com/patrickhener/goshs
May 19, 2025 GO-2026-4953 +14 more
Alert  GO-2026-4953: goshs is Missing Write Protection for Parametric Data Values in github.com/patrickhener/goshs
Alert  GO-2026-5146: SFTP root escape via prefix-based path validation in goshs in github.com/patrickhener/goshs
Alert  GO-2026-5186: goshs: Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) in github.com/patrickhener/goshs
Alert  GO-2026-5221: goshs's public collaborator feed leaks .goshs ACL credentials and enables unauthorized access in github.com/patrickhener/goshs
Alert  GO-2026-5232: Unauthenticated Open Redirect, Arbitrary HTTP Response Header Injection, Missing CSRF, and Invisible-Mode Bypass in goshs `/?redirect` endpoint in github.com/patrickhener/goshs
Alert  GO-2026-5303: goshs has an empty-username SFTP password authentication bypass in github.com/patrickhener/goshs
Alert  GO-2026-5394: goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs PUT Upload in github.com/patrickhener/goshs
Alert  GO-2026-5468: goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs POST multipart upload in github.com/patrickhener/goshs
Alert  GO-2026-5479: goshs has CSRF in state-changing GET routes enables authenticated file deletion and directory creation in github.com/patrickhener/goshs
Alert  GO-2026-5625: goshs has Cross-Origin Arbitrary File Write via Missing CSRF on PUT and Wildcard CORS in github.com/patrickhener/goshs
Alert  GO-2026-5728: goshs has a file-based ACL authorization bypass in goshs state-changing routes in github.com/patrickhener/goshs
Alert  GO-2026-6133: goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx) in github.com/patrickhener/goshs
Alert  GO-2026-6134: goshs has ACL Bypass & Path Traversal in github.com/patrickhener/goshs
Alert  GO-2026-6136: goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite in github.com/patrickhener/goshs
Alert  GO-2026-6137: goshs has a Path Traversal issue in github.com/patrickhener/goshs
Changes in this version
type FileServer
May 12, 2025 GO-2026-5146 +13 more
Alert  GO-2026-5146: SFTP root escape via prefix-based path validation in goshs in github.com/patrickhener/goshs
Alert  GO-2026-5186: goshs: Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) in github.com/patrickhener/goshs
Alert  GO-2026-5221: goshs's public collaborator feed leaks .goshs ACL credentials and enables unauthorized access in github.com/patrickhener/goshs
Alert  GO-2026-5232: Unauthenticated Open Redirect, Arbitrary HTTP Response Header Injection, Missing CSRF, and Invisible-Mode Bypass in goshs `/?redirect` endpoint in github.com/patrickhener/goshs
Alert  GO-2026-5303: goshs has an empty-username SFTP password authentication bypass in github.com/patrickhener/goshs
Alert  GO-2026-5394: goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs PUT Upload in github.com/patrickhener/goshs
Alert  GO-2026-5468: goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs POST multipart upload in github.com/patrickhener/goshs
Alert  GO-2026-5479: goshs has CSRF in state-changing GET routes enables authenticated file deletion and directory creation in github.com/patrickhener/goshs
Alert  GO-2026-5625: goshs has Cross-Origin Arbitrary File Write via Missing CSRF on PUT and Wildcard CORS in github.com/patrickhener/goshs
Alert  GO-2026-5728: goshs has a file-based ACL authorization bypass in goshs state-changing routes in github.com/patrickhener/goshs
Alert  GO-2026-6133: goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx) in github.com/patrickhener/goshs
Alert  GO-2026-6134: goshs has ACL Bypass & Path Traversal in github.com/patrickhener/goshs
Alert  GO-2026-6136: goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite in github.com/patrickhener/goshs
Alert  GO-2026-6137: goshs has a Path Traversal issue in github.com/patrickhener/goshs
May 6, 2025 GO-2026-5146 +13 more
Alert  GO-2026-5146: SFTP root escape via prefix-based path validation in goshs in github.com/patrickhener/goshs
Alert  GO-2026-5186: goshs: Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) in github.com/patrickhener/goshs
Alert  GO-2026-5221: goshs's public collaborator feed leaks .goshs ACL credentials and enables unauthorized access in github.com/patrickhener/goshs
Alert  GO-2026-5232: Unauthenticated Open Redirect, Arbitrary HTTP Response Header Injection, Missing CSRF, and Invisible-Mode Bypass in goshs `/?redirect` endpoint in github.com/patrickhener/goshs
Alert  GO-2026-5303: goshs has an empty-username SFTP password authentication bypass in github.com/patrickhener/goshs
Alert  GO-2026-5394: goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs PUT Upload in github.com/patrickhener/goshs
Alert  GO-2026-5468: goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs POST multipart upload in github.com/patrickhener/goshs
Alert  GO-2026-5479: goshs has CSRF in state-changing GET routes enables authenticated file deletion and directory creation in github.com/patrickhener/goshs
Alert  GO-2026-5625: goshs has Cross-Origin Arbitrary File Write via Missing CSRF on PUT and Wildcard CORS in github.com/patrickhener/goshs
Alert  GO-2026-5728: goshs has a file-based ACL authorization bypass in goshs state-changing routes in github.com/patrickhener/goshs
Alert  GO-2026-6133: goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx) in github.com/patrickhener/goshs
Alert  GO-2026-6134: goshs has ACL Bypass & Path Traversal in github.com/patrickhener/goshs
Alert  GO-2026-6136: goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite in github.com/patrickhener/goshs
Alert  GO-2026-6137: goshs has a Path Traversal issue in github.com/patrickhener/goshs
May 2, 2025 GO-2025-3672 +14 more
Alert  GO-2025-3672: goshs route not protected, allows command execution in github.com/patrickhener/goshs
Alert  GO-2026-5146: SFTP root escape via prefix-based path validation in goshs in github.com/patrickhener/goshs
Alert  GO-2026-5186: goshs: Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) in github.com/patrickhener/goshs
Alert  GO-2026-5221: goshs's public collaborator feed leaks .goshs ACL credentials and enables unauthorized access in github.com/patrickhener/goshs
Alert  GO-2026-5232: Unauthenticated Open Redirect, Arbitrary HTTP Response Header Injection, Missing CSRF, and Invisible-Mode Bypass in goshs `/?redirect` endpoint in github.com/patrickhener/goshs
Alert  GO-2026-5303: goshs has an empty-username SFTP password authentication bypass in github.com/patrickhener/goshs
Alert  GO-2026-5394: goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs PUT Upload in github.com/patrickhener/goshs
Alert  GO-2026-5468: goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs POST multipart upload in github.com/patrickhener/goshs
Alert  GO-2026-5479: goshs has CSRF in state-changing GET routes enables authenticated file deletion and directory creation in github.com/patrickhener/goshs
Alert  GO-2026-5625: goshs has Cross-Origin Arbitrary File Write via Missing CSRF on PUT and Wildcard CORS in github.com/patrickhener/goshs
Alert  GO-2026-5728: goshs has a file-based ACL authorization bypass in goshs state-changing routes in github.com/patrickhener/goshs
Alert  GO-2026-6133: goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx) in github.com/patrickhener/goshs
Alert  GO-2026-6134: goshs has ACL Bypass & Path Traversal in github.com/patrickhener/goshs
Alert  GO-2026-6136: goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite in github.com/patrickhener/goshs
Alert  GO-2026-6137: goshs has a Path Traversal issue in github.com/patrickhener/goshs
Apr 16, 2025 GO-2025-3672 +14 more
Alert  GO-2025-3672: goshs route not protected, allows command execution in github.com/patrickhener/goshs
Alert  GO-2026-5146: SFTP root escape via prefix-based path validation in goshs in github.com/patrickhener/goshs
Alert  GO-2026-5186: goshs: Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) in github.com/patrickhener/goshs
Alert  GO-2026-5221: goshs's public collaborator feed leaks .goshs ACL credentials and enables unauthorized access in github.com/patrickhener/goshs
Alert  GO-2026-5232: Unauthenticated Open Redirect, Arbitrary HTTP Response Header Injection, Missing CSRF, and Invisible-Mode Bypass in goshs `/?redirect` endpoint in github.com/patrickhener/goshs
Alert  GO-2026-5303: goshs has an empty-username SFTP password authentication bypass in github.com/patrickhener/goshs
Alert  GO-2026-5394: goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs PUT Upload in github.com/patrickhener/goshs
Alert  GO-2026-5468: goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs POST multipart upload in github.com/patrickhener/goshs
Alert  GO-2026-5479: goshs has CSRF in state-changing GET routes enables authenticated file deletion and directory creation in github.com/patrickhener/goshs
Alert  GO-2026-5625: goshs has Cross-Origin Arbitrary File Write via Missing CSRF on PUT and Wildcard CORS in github.com/patrickhener/goshs
Alert  GO-2026-5728: goshs has a file-based ACL authorization bypass in goshs state-changing routes in github.com/patrickhener/goshs
Alert  GO-2026-6133: goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx) in github.com/patrickhener/goshs
Alert  GO-2026-6134: goshs has ACL Bypass & Path Traversal in github.com/patrickhener/goshs
Alert  GO-2026-6136: goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite in github.com/patrickhener/goshs
Alert  GO-2026-6137: goshs has a Path Traversal issue in github.com/patrickhener/goshs
Mar 7, 2025 GO-2025-3672 +14 more
Alert  GO-2025-3672: goshs route not protected, allows command execution in github.com/patrickhener/goshs
Alert  GO-2026-5146: SFTP root escape via prefix-based path validation in goshs in github.com/patrickhener/goshs
Alert  GO-2026-5186: goshs: Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) in github.com/patrickhener/goshs
Alert  GO-2026-5221: goshs's public collaborator feed leaks .goshs ACL credentials and enables unauthorized access in github.com/patrickhener/goshs
Alert  GO-2026-5232: Unauthenticated Open Redirect, Arbitrary HTTP Response Header Injection, Missing CSRF, and Invisible-Mode Bypass in goshs `/?redirect` endpoint in github.com/patrickhener/goshs
Alert  GO-2026-5303: goshs has an empty-username SFTP password authentication bypass in github.com/patrickhener/goshs
Alert  GO-2026-5394: goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs PUT Upload in github.com/patrickhener/goshs
Alert  GO-2026-5468: goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs POST multipart upload in github.com/patrickhener/goshs
Alert  GO-2026-5479: goshs has CSRF in state-changing GET routes enables authenticated file deletion and directory creation in github.com/patrickhener/goshs
Alert  GO-2026-5625: goshs has Cross-Origin Arbitrary File Write via Missing CSRF on PUT and Wildcard CORS in github.com/patrickhener/goshs
Alert  GO-2026-5728: goshs has a file-based ACL authorization bypass in goshs state-changing routes in github.com/patrickhener/goshs
Alert  GO-2026-6133: goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx) in github.com/patrickhener/goshs
Alert  GO-2026-6134: goshs has ACL Bypass & Path Traversal in github.com/patrickhener/goshs
Alert  GO-2026-6136: goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite in github.com/patrickhener/goshs
Alert  GO-2026-6137: goshs has a Path Traversal issue in github.com/patrickhener/goshs
Changes in this version
type FileServer
Nov 22, 2024 GO-2025-3672 +14 more
Alert  GO-2025-3672: goshs route not protected, allows command execution in github.com/patrickhener/goshs
Alert  GO-2026-5146: SFTP root escape via prefix-based path validation in goshs in github.com/patrickhener/goshs
Alert  GO-2026-5186: goshs: Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) in github.com/patrickhener/goshs
Alert  GO-2026-5221: goshs's public collaborator feed leaks .goshs ACL credentials and enables unauthorized access in github.com/patrickhener/goshs
Alert  GO-2026-5232: Unauthenticated Open Redirect, Arbitrary HTTP Response Header Injection, Missing CSRF, and Invisible-Mode Bypass in goshs `/?redirect` endpoint in github.com/patrickhener/goshs
Alert  GO-2026-5303: goshs has an empty-username SFTP password authentication bypass in github.com/patrickhener/goshs
Alert  GO-2026-5394: goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs PUT Upload in github.com/patrickhener/goshs
Alert  GO-2026-5468: goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs POST multipart upload in github.com/patrickhener/goshs
Alert  GO-2026-5479: goshs has CSRF in state-changing GET routes enables authenticated file deletion and directory creation in github.com/patrickhener/goshs
Alert  GO-2026-5625: goshs has Cross-Origin Arbitrary File Write via Missing CSRF on PUT and Wildcard CORS in github.com/patrickhener/goshs
Alert  GO-2026-5728: goshs has a file-based ACL authorization bypass in goshs state-changing routes in github.com/patrickhener/goshs
Alert  GO-2026-6133: goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx) in github.com/patrickhener/goshs
Alert  GO-2026-6134: goshs has ACL Bypass & Path Traversal in github.com/patrickhener/goshs
Alert  GO-2026-6136: goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite in github.com/patrickhener/goshs
Alert  GO-2026-6137: goshs has a Path Traversal issue in github.com/patrickhener/goshs
Nov 15, 2024 GO-2025-3672 +14 more
Alert  GO-2025-3672: goshs route not protected, allows command execution in github.com/patrickhener/goshs
Alert  GO-2026-5146: SFTP root escape via prefix-based path validation in goshs in github.com/patrickhener/goshs
Alert  GO-2026-5186: goshs: Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) in github.com/patrickhener/goshs
Alert  GO-2026-5221: goshs's public collaborator feed leaks .goshs ACL credentials and enables unauthorized access in github.com/patrickhener/goshs
Alert  GO-2026-5232: Unauthenticated Open Redirect, Arbitrary HTTP Response Header Injection, Missing CSRF, and Invisible-Mode Bypass in goshs `/?redirect` endpoint in github.com/patrickhener/goshs
Alert  GO-2026-5303: goshs has an empty-username SFTP password authentication bypass in github.com/patrickhener/goshs
Alert  GO-2026-5394: goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs PUT Upload in github.com/patrickhener/goshs
Alert  GO-2026-5468: goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs POST multipart upload in github.com/patrickhener/goshs
Alert  GO-2026-5479: goshs has CSRF in state-changing GET routes enables authenticated file deletion and directory creation in github.com/patrickhener/goshs
Alert  GO-2026-5625: goshs has Cross-Origin Arbitrary File Write via Missing CSRF on PUT and Wildcard CORS in github.com/patrickhener/goshs
Alert  GO-2026-5728: goshs has a file-based ACL authorization bypass in goshs state-changing routes in github.com/patrickhener/goshs
Alert  GO-2026-6133: goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx) in github.com/patrickhener/goshs
Alert  GO-2026-6134: goshs has ACL Bypass & Path Traversal in github.com/patrickhener/goshs
Alert  GO-2026-6136: goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite in github.com/patrickhener/goshs
Alert  GO-2026-6137: goshs has a Path Traversal issue in github.com/patrickhener/goshs
v0
Oct 17, 2024 GO-2025-3672 +14 more
Alert  GO-2025-3672: goshs route not protected, allows command execution in github.com/patrickhener/goshs
Alert  GO-2026-5146: SFTP root escape via prefix-based path validation in goshs in github.com/patrickhener/goshs
Alert  GO-2026-5186: goshs: Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) in github.com/patrickhener/goshs
Alert  GO-2026-5221: goshs's public collaborator feed leaks .goshs ACL credentials and enables unauthorized access in github.com/patrickhener/goshs
Alert  GO-2026-5232: Unauthenticated Open Redirect, Arbitrary HTTP Response Header Injection, Missing CSRF, and Invisible-Mode Bypass in goshs `/?redirect` endpoint in github.com/patrickhener/goshs
Alert  GO-2026-5303: goshs has an empty-username SFTP password authentication bypass in github.com/patrickhener/goshs
Alert  GO-2026-5394: goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs PUT Upload in github.com/patrickhener/goshs
Alert  GO-2026-5468: goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs POST multipart upload in github.com/patrickhener/goshs
Alert  GO-2026-5479: goshs has CSRF in state-changing GET routes enables authenticated file deletion and directory creation in github.com/patrickhener/goshs
Alert  GO-2026-5625: goshs has Cross-Origin Arbitrary File Write via Missing CSRF on PUT and Wildcard CORS in github.com/patrickhener/goshs
Alert  GO-2026-5728: goshs has a file-based ACL authorization bypass in goshs state-changing routes in github.com/patrickhener/goshs
Alert  GO-2026-6133: goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx) in github.com/patrickhener/goshs
Alert  GO-2026-6134: goshs has ACL Bypass & Path Traversal in github.com/patrickhener/goshs
Alert  GO-2026-6136: goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite in github.com/patrickhener/goshs
Alert  GO-2026-6137: goshs has a Path Traversal issue in github.com/patrickhener/goshs
Jul 11, 2024 GO-2025-3672 +14 more
Alert  GO-2025-3672: goshs route not protected, allows command execution in github.com/patrickhener/goshs
Alert  GO-2026-5146: SFTP root escape via prefix-based path validation in goshs in github.com/patrickhener/goshs
Alert  GO-2026-5186: goshs: Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) in github.com/patrickhener/goshs
Alert  GO-2026-5221: goshs's public collaborator feed leaks .goshs ACL credentials and enables unauthorized access in github.com/patrickhener/goshs
Alert  GO-2026-5232: Unauthenticated Open Redirect, Arbitrary HTTP Response Header Injection, Missing CSRF, and Invisible-Mode Bypass in goshs `/?redirect` endpoint in github.com/patrickhener/goshs
Alert  GO-2026-5303: goshs has an empty-username SFTP password authentication bypass in github.com/patrickhener/goshs
Alert  GO-2026-5394: goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs PUT Upload in github.com/patrickhener/goshs
Alert  GO-2026-5468: goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs POST multipart upload in github.com/patrickhener/goshs
Alert  GO-2026-5479: goshs has CSRF in state-changing GET routes enables authenticated file deletion and directory creation in github.com/patrickhener/goshs
Alert  GO-2026-5625: goshs has Cross-Origin Arbitrary File Write via Missing CSRF on PUT and Wildcard CORS in github.com/patrickhener/goshs
Alert  GO-2026-5728: goshs has a file-based ACL authorization bypass in goshs state-changing routes in github.com/patrickhener/goshs
Alert  GO-2026-6133: goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx) in github.com/patrickhener/goshs
Alert  GO-2026-6134: goshs has ACL Bypass & Path Traversal in github.com/patrickhener/goshs
Alert  GO-2026-6136: goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite in github.com/patrickhener/goshs
Alert  GO-2026-6137: goshs has a Path Traversal issue in github.com/patrickhener/goshs
Changes in this version
Jul 5, 2024 GO-2025-3672 +14 more
Alert  GO-2025-3672: goshs route not protected, allows command execution in github.com/patrickhener/goshs
Alert  GO-2026-5146: SFTP root escape via prefix-based path validation in goshs in github.com/patrickhener/goshs
Alert  GO-2026-5186: goshs: Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) in github.com/patrickhener/goshs
Alert  GO-2026-5221: goshs's public collaborator feed leaks .goshs ACL credentials and enables unauthorized access in github.com/patrickhener/goshs
Alert  GO-2026-5232: Unauthenticated Open Redirect, Arbitrary HTTP Response Header Injection, Missing CSRF, and Invisible-Mode Bypass in goshs `/?redirect` endpoint in github.com/patrickhener/goshs
Alert  GO-2026-5303: goshs has an empty-username SFTP password authentication bypass in github.com/patrickhener/goshs
Alert  GO-2026-5394: goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs PUT Upload in github.com/patrickhener/goshs
Alert  GO-2026-5468: goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs POST multipart upload in github.com/patrickhener/goshs
Alert  GO-2026-5479: goshs has CSRF in state-changing GET routes enables authenticated file deletion and directory creation in github.com/patrickhener/goshs
Alert  GO-2026-5625: goshs has Cross-Origin Arbitrary File Write via Missing CSRF on PUT and Wildcard CORS in github.com/patrickhener/goshs
Alert  GO-2026-5728: goshs has a file-based ACL authorization bypass in goshs state-changing routes in github.com/patrickhener/goshs
Alert  GO-2026-6133: goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx) in github.com/patrickhener/goshs
Alert  GO-2026-6134: goshs has ACL Bypass & Path Traversal in github.com/patrickhener/goshs
Alert  GO-2026-6136: goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite in github.com/patrickhener/goshs
Alert  GO-2026-6137: goshs has a Path Traversal issue in github.com/patrickhener/goshs
Changes in this version
type FileServer
Jun 27, 2024 GO-2025-3672 +14 more
Alert  GO-2025-3672: goshs route not protected, allows command execution in github.com/patrickhener/goshs
Alert  GO-2026-5146: SFTP root escape via prefix-based path validation in goshs in github.com/patrickhener/goshs
Alert  GO-2026-5186: goshs: Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) in github.com/patrickhener/goshs
Alert  GO-2026-5221: goshs's public collaborator feed leaks .goshs ACL credentials and enables unauthorized access in github.com/patrickhener/goshs
Alert  GO-2026-5232: Unauthenticated Open Redirect, Arbitrary HTTP Response Header Injection, Missing CSRF, and Invisible-Mode Bypass in goshs `/?redirect` endpoint in github.com/patrickhener/goshs
Alert  GO-2026-5303: goshs has an empty-username SFTP password authentication bypass in github.com/patrickhener/goshs
Alert  GO-2026-5394: goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs PUT Upload in github.com/patrickhener/goshs
Alert  GO-2026-5468: goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs POST multipart upload in github.com/patrickhener/goshs
Alert  GO-2026-5479: goshs has CSRF in state-changing GET routes enables authenticated file deletion and directory creation in github.com/patrickhener/goshs
Alert  GO-2026-5625: goshs has Cross-Origin Arbitrary File Write via Missing CSRF on PUT and Wildcard CORS in github.com/patrickhener/goshs
Alert  GO-2026-5728: goshs has a file-based ACL authorization bypass in goshs state-changing routes in github.com/patrickhener/goshs
Alert  GO-2026-6133: goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx) in github.com/patrickhener/goshs
Alert  GO-2026-6134: goshs has ACL Bypass & Path Traversal in github.com/patrickhener/goshs
Alert  GO-2026-6136: goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite in github.com/patrickhener/goshs
Alert  GO-2026-6137: goshs has a Path Traversal issue in github.com/patrickhener/goshs
Changes in this version
Apr 30, 2024 GO-2025-3672 +14 more
Alert  GO-2025-3672: goshs route not protected, allows command execution in github.com/patrickhener/goshs
Alert  GO-2026-5146: SFTP root escape via prefix-based path validation in goshs in github.com/patrickhener/goshs
Alert  GO-2026-5186: goshs: Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) in github.com/patrickhener/goshs
Alert  GO-2026-5221: goshs's public collaborator feed leaks .goshs ACL credentials and enables unauthorized access in github.com/patrickhener/goshs
Alert  GO-2026-5232: Unauthenticated Open Redirect, Arbitrary HTTP Response Header Injection, Missing CSRF, and Invisible-Mode Bypass in goshs `/?redirect` endpoint in github.com/patrickhener/goshs
Alert  GO-2026-5303: goshs has an empty-username SFTP password authentication bypass in github.com/patrickhener/goshs
Alert  GO-2026-5394: goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs PUT Upload in github.com/patrickhener/goshs
Alert  GO-2026-5468: goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs POST multipart upload in github.com/patrickhener/goshs
Alert  GO-2026-5479: goshs has CSRF in state-changing GET routes enables authenticated file deletion and directory creation in github.com/patrickhener/goshs
Alert  GO-2026-5625: goshs has Cross-Origin Arbitrary File Write via Missing CSRF on PUT and Wildcard CORS in github.com/patrickhener/goshs
Alert  GO-2026-5728: goshs has a file-based ACL authorization bypass in goshs state-changing routes in github.com/patrickhener/goshs
Alert  GO-2026-6133: goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx) in github.com/patrickhener/goshs
Alert  GO-2026-6134: goshs has ACL Bypass & Path Traversal in github.com/patrickhener/goshs
Alert  GO-2026-6136: goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite in github.com/patrickhener/goshs
Alert  GO-2026-6137: goshs has a Path Traversal issue in github.com/patrickhener/goshs
Changes in this version
type FileServer
Apr 10, 2024 GO-2025-3672 +14 more
Alert  GO-2025-3672: goshs route not protected, allows command execution in github.com/patrickhener/goshs
Alert  GO-2026-5146: SFTP root escape via prefix-based path validation in goshs in github.com/patrickhener/goshs
Alert  GO-2026-5186: goshs: Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) in github.com/patrickhener/goshs
Alert  GO-2026-5221: goshs's public collaborator feed leaks .goshs ACL credentials and enables unauthorized access in github.com/patrickhener/goshs
Alert  GO-2026-5232: Unauthenticated Open Redirect, Arbitrary HTTP Response Header Injection, Missing CSRF, and Invisible-Mode Bypass in goshs `/?redirect` endpoint in github.com/patrickhener/goshs
Alert  GO-2026-5303: goshs has an empty-username SFTP password authentication bypass in github.com/patrickhener/goshs
Alert  GO-2026-5394: goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs PUT Upload in github.com/patrickhener/goshs
Alert  GO-2026-5468: goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs POST multipart upload in github.com/patrickhener/goshs
Alert  GO-2026-5479: goshs has CSRF in state-changing GET routes enables authenticated file deletion and directory creation in github.com/patrickhener/goshs
Alert  GO-2026-5625: goshs has Cross-Origin Arbitrary File Write via Missing CSRF on PUT and Wildcard CORS in github.com/patrickhener/goshs
Alert  GO-2026-5728: goshs has a file-based ACL authorization bypass in goshs state-changing routes in github.com/patrickhener/goshs
Alert  GO-2026-6133: goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx) in github.com/patrickhener/goshs
Alert  GO-2026-6134: goshs has ACL Bypass & Path Traversal in github.com/patrickhener/goshs
Alert  GO-2026-6136: goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite in github.com/patrickhener/goshs
Alert  GO-2026-6137: goshs has a Path Traversal issue in github.com/patrickhener/goshs
Sep 1, 2023 GO-2025-3672 +14 more
Alert  GO-2025-3672: goshs route not protected, allows command execution in github.com/patrickhener/goshs
Alert  GO-2026-5146: SFTP root escape via prefix-based path validation in goshs in github.com/patrickhener/goshs
Alert  GO-2026-5186: goshs: Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) in github.com/patrickhener/goshs
Alert  GO-2026-5221: goshs's public collaborator feed leaks .goshs ACL credentials and enables unauthorized access in github.com/patrickhener/goshs
Alert  GO-2026-5232: Unauthenticated Open Redirect, Arbitrary HTTP Response Header Injection, Missing CSRF, and Invisible-Mode Bypass in goshs `/?redirect` endpoint in github.com/patrickhener/goshs
Alert  GO-2026-5303: goshs has an empty-username SFTP password authentication bypass in github.com/patrickhener/goshs
Alert  GO-2026-5394: goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs PUT Upload in github.com/patrickhener/goshs
Alert  GO-2026-5468: goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs POST multipart upload in github.com/patrickhener/goshs
Alert  GO-2026-5479: goshs has CSRF in state-changing GET routes enables authenticated file deletion and directory creation in github.com/patrickhener/goshs
Alert  GO-2026-5625: goshs has Cross-Origin Arbitrary File Write via Missing CSRF on PUT and Wildcard CORS in github.com/patrickhener/goshs
Alert  GO-2026-5728: goshs has a file-based ACL authorization bypass in goshs state-changing routes in github.com/patrickhener/goshs
Alert  GO-2026-6133: goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx) in github.com/patrickhener/goshs
Alert  GO-2026-6134: goshs has ACL Bypass & Path Traversal in github.com/patrickhener/goshs
Alert  GO-2026-6136: goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite in github.com/patrickhener/goshs
Alert  GO-2026-6137: goshs has a Path Traversal issue in github.com/patrickhener/goshs
Jun 21, 2023 GO-2025-3672 +14 more
Alert  GO-2025-3672: goshs route not protected, allows command execution in github.com/patrickhener/goshs
Alert  GO-2026-5146: SFTP root escape via prefix-based path validation in goshs in github.com/patrickhener/goshs
Alert  GO-2026-5186: goshs: Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) in github.com/patrickhener/goshs
Alert  GO-2026-5221: goshs's public collaborator feed leaks .goshs ACL credentials and enables unauthorized access in github.com/patrickhener/goshs
Alert  GO-2026-5232: Unauthenticated Open Redirect, Arbitrary HTTP Response Header Injection, Missing CSRF, and Invisible-Mode Bypass in goshs `/?redirect` endpoint in github.com/patrickhener/goshs
Alert  GO-2026-5303: goshs has an empty-username SFTP password authentication bypass in github.com/patrickhener/goshs
Alert  GO-2026-5394: goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs PUT Upload in github.com/patrickhener/goshs
Alert  GO-2026-5468: goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs POST multipart upload in github.com/patrickhener/goshs
Alert  GO-2026-5479: goshs has CSRF in state-changing GET routes enables authenticated file deletion and directory creation in github.com/patrickhener/goshs
Alert  GO-2026-5625: goshs has Cross-Origin Arbitrary File Write via Missing CSRF on PUT and Wildcard CORS in github.com/patrickhener/goshs
Alert  GO-2026-5728: goshs has a file-based ACL authorization bypass in goshs state-changing routes in github.com/patrickhener/goshs
Alert  GO-2026-6133: goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx) in github.com/patrickhener/goshs
Alert  GO-2026-6134: goshs has ACL Bypass & Path Traversal in github.com/patrickhener/goshs
Alert  GO-2026-6136: goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite in github.com/patrickhener/goshs
Alert  GO-2026-6137: goshs has a Path Traversal issue in github.com/patrickhener/goshs
Jun 1, 2023 GO-2025-3672 +14 more
Alert  GO-2025-3672: goshs route not protected, allows command execution in github.com/patrickhener/goshs
Alert  GO-2026-5146: SFTP root escape via prefix-based path validation in goshs in github.com/patrickhener/goshs
Alert  GO-2026-5186: goshs: Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) in github.com/patrickhener/goshs
Alert  GO-2026-5221: goshs's public collaborator feed leaks .goshs ACL credentials and enables unauthorized access in github.com/patrickhener/goshs
Alert  GO-2026-5232: Unauthenticated Open Redirect, Arbitrary HTTP Response Header Injection, Missing CSRF, and Invisible-Mode Bypass in goshs `/?redirect` endpoint in github.com/patrickhener/goshs
Alert  GO-2026-5303: goshs has an empty-username SFTP password authentication bypass in github.com/patrickhener/goshs
Alert  GO-2026-5394: goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs PUT Upload in github.com/patrickhener/goshs
Alert  GO-2026-5468: goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs POST multipart upload in github.com/patrickhener/goshs
Alert  GO-2026-5479: goshs has CSRF in state-changing GET routes enables authenticated file deletion and directory creation in github.com/patrickhener/goshs
Alert  GO-2026-5625: goshs has Cross-Origin Arbitrary File Write via Missing CSRF on PUT and Wildcard CORS in github.com/patrickhener/goshs
Alert  GO-2026-5728: goshs has a file-based ACL authorization bypass in goshs state-changing routes in github.com/patrickhener/goshs
Alert  GO-2026-6133: goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx) in github.com/patrickhener/goshs
Alert  GO-2026-6134: goshs has ACL Bypass & Path Traversal in github.com/patrickhener/goshs
Alert  GO-2026-6136: goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite in github.com/patrickhener/goshs
Alert  GO-2026-6137: goshs has a Path Traversal issue in github.com/patrickhener/goshs
Changes in this version
type FileServer
May 31, 2023 GO-2026-5146 +13 more
Alert  GO-2026-5146: SFTP root escape via prefix-based path validation in goshs in github.com/patrickhener/goshs
Alert  GO-2026-5186: goshs: Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) in github.com/patrickhener/goshs
Alert  GO-2026-5221: goshs's public collaborator feed leaks .goshs ACL credentials and enables unauthorized access in github.com/patrickhener/goshs
Alert  GO-2026-5232: Unauthenticated Open Redirect, Arbitrary HTTP Response Header Injection, Missing CSRF, and Invisible-Mode Bypass in goshs `/?redirect` endpoint in github.com/patrickhener/goshs
Alert  GO-2026-5303: goshs has an empty-username SFTP password authentication bypass in github.com/patrickhener/goshs
Alert  GO-2026-5394: goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs PUT Upload in github.com/patrickhener/goshs
Alert  GO-2026-5468: goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs POST multipart upload in github.com/patrickhener/goshs
Alert  GO-2026-5479: goshs has CSRF in state-changing GET routes enables authenticated file deletion and directory creation in github.com/patrickhener/goshs
Alert  GO-2026-5625: goshs has Cross-Origin Arbitrary File Write via Missing CSRF on PUT and Wildcard CORS in github.com/patrickhener/goshs
Alert  GO-2026-5728: goshs has a file-based ACL authorization bypass in goshs state-changing routes in github.com/patrickhener/goshs
Alert  GO-2026-6133: goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx) in github.com/patrickhener/goshs
Alert  GO-2026-6134: goshs has ACL Bypass & Path Traversal in github.com/patrickhener/goshs
Alert  GO-2026-6136: goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite in github.com/patrickhener/goshs
Alert  GO-2026-6137: goshs has a Path Traversal issue in github.com/patrickhener/goshs
May 26, 2023 GO-2026-5146 +13 more
Alert  GO-2026-5146: SFTP root escape via prefix-based path validation in goshs in github.com/patrickhener/goshs
Alert  GO-2026-5186: goshs: Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) in github.com/patrickhener/goshs
Alert  GO-2026-5221: goshs's public collaborator feed leaks .goshs ACL credentials and enables unauthorized access in github.com/patrickhener/goshs
Alert  GO-2026-5232: Unauthenticated Open Redirect, Arbitrary HTTP Response Header Injection, Missing CSRF, and Invisible-Mode Bypass in goshs `/?redirect` endpoint in github.com/patrickhener/goshs
Alert  GO-2026-5303: goshs has an empty-username SFTP password authentication bypass in github.com/patrickhener/goshs
Alert  GO-2026-5394: goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs PUT Upload in github.com/patrickhener/goshs
Alert  GO-2026-5468: goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs POST multipart upload in github.com/patrickhener/goshs
Alert  GO-2026-5479: goshs has CSRF in state-changing GET routes enables authenticated file deletion and directory creation in github.com/patrickhener/goshs
Alert  GO-2026-5625: goshs has Cross-Origin Arbitrary File Write via Missing CSRF on PUT and Wildcard CORS in github.com/patrickhener/goshs
Alert  GO-2026-5728: goshs has a file-based ACL authorization bypass in goshs state-changing routes in github.com/patrickhener/goshs
Alert  GO-2026-6133: goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx) in github.com/patrickhener/goshs
Alert  GO-2026-6134: goshs has ACL Bypass & Path Traversal in github.com/patrickhener/goshs
Alert  GO-2026-6136: goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite in github.com/patrickhener/goshs
Alert  GO-2026-6137: goshs has a Path Traversal issue in github.com/patrickhener/goshs
Changes in this version
type FileServer
May 8, 2023 GO-2026-5146 +13 more
Alert  GO-2026-5146: SFTP root escape via prefix-based path validation in goshs in github.com/patrickhener/goshs
Alert  GO-2026-5186: goshs: Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) in github.com/patrickhener/goshs
Alert  GO-2026-5221: goshs's public collaborator feed leaks .goshs ACL credentials and enables unauthorized access in github.com/patrickhener/goshs
Alert  GO-2026-5232: Unauthenticated Open Redirect, Arbitrary HTTP Response Header Injection, Missing CSRF, and Invisible-Mode Bypass in goshs `/?redirect` endpoint in github.com/patrickhener/goshs
Alert  GO-2026-5303: goshs has an empty-username SFTP password authentication bypass in github.com/patrickhener/goshs
Alert  GO-2026-5394: goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs PUT Upload in github.com/patrickhener/goshs
Alert  GO-2026-5468: goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs POST multipart upload in github.com/patrickhener/goshs
Alert  GO-2026-5479: goshs has CSRF in state-changing GET routes enables authenticated file deletion and directory creation in github.com/patrickhener/goshs
Alert  GO-2026-5625: goshs has Cross-Origin Arbitrary File Write via Missing CSRF on PUT and Wildcard CORS in github.com/patrickhener/goshs
Alert  GO-2026-5728: goshs has a file-based ACL authorization bypass in goshs state-changing routes in github.com/patrickhener/goshs
Alert  GO-2026-6133: goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx) in github.com/patrickhener/goshs
Alert  GO-2026-6134: goshs has ACL Bypass & Path Traversal in github.com/patrickhener/goshs
Alert  GO-2026-6136: goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite in github.com/patrickhener/goshs
Alert  GO-2026-6137: goshs has a Path Traversal issue in github.com/patrickhener/goshs
Feb 28, 2023 GO-2026-5146 +13 more
Alert  GO-2026-5146: SFTP root escape via prefix-based path validation in goshs in github.com/patrickhener/goshs
Alert  GO-2026-5186: goshs: Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) in github.com/patrickhener/goshs
Alert  GO-2026-5221: goshs's public collaborator feed leaks .goshs ACL credentials and enables unauthorized access in github.com/patrickhener/goshs
Alert  GO-2026-5232: Unauthenticated Open Redirect, Arbitrary HTTP Response Header Injection, Missing CSRF, and Invisible-Mode Bypass in goshs `/?redirect` endpoint in github.com/patrickhener/goshs
Alert  GO-2026-5303: goshs has an empty-username SFTP password authentication bypass in github.com/patrickhener/goshs
Alert  GO-2026-5394: goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs PUT Upload in github.com/patrickhener/goshs
Alert  GO-2026-5468: goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs POST multipart upload in github.com/patrickhener/goshs
Alert  GO-2026-5479: goshs has CSRF in state-changing GET routes enables authenticated file deletion and directory creation in github.com/patrickhener/goshs
Alert  GO-2026-5625: goshs has Cross-Origin Arbitrary File Write via Missing CSRF on PUT and Wildcard CORS in github.com/patrickhener/goshs
Alert  GO-2026-5728: goshs has a file-based ACL authorization bypass in goshs state-changing routes in github.com/patrickhener/goshs
Alert  GO-2026-6133: goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx) in github.com/patrickhener/goshs
Alert  GO-2026-6134: goshs has ACL Bypass & Path Traversal in github.com/patrickhener/goshs
Alert  GO-2026-6136: goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite in github.com/patrickhener/goshs
Alert  GO-2026-6137: goshs has a Path Traversal issue in github.com/patrickhener/goshs

Other modules containing this package

github.com/patrickhener/goshs/v2

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL