The goshs software has critical vulnerabilities that allow for an SFTP authentication bypass and potential leakage of GITHUB_TOKEN through workflow artifacts.
Claims
The goshs software has critical vulnerabilities that allow for an SFTP authentication bypass and potential leakage of GITHUB_TOKEN through workflow artifacts.
Parent: CybersecurityEntity: goshsImpact: negativeDate: Apr 21, 2026Target: The presence of critical vulnerabilities in goshs
Source posts
🔴 CVE-2026-40884 - Critical (9.8)
goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.6, goshs contains an SFTP authentication bypass when the documented empty-username basic-auth syntax is used. If the server is started with -b ':pass' together with -sftp, goshs accept...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-40884/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
0 boosts · 0 favs · 0 replies · Apr 21, 2026
#cve#vulnerability#infosec#cybersecurity#security#tenda
🔴 CVE-2026-40903 - Critical (9.1)
goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.6, goshs has an ArtiPACKED vulnerability. ArtiPACKED can lead to leakage of the GITHUB_TOKEN through workflow artifacts, even though the token is not present in the repository source c...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-40903/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
0 boosts · 0 favs · 0 replies · Apr 21, 2026
#cve#vulnerability#infosec#cybersecurity#security#tenda