← All reports

The goshs software has critical vulnerabilities that allow for an SFTP authentication bypass and potential leakage of GITHUB_TOKEN through workflow artifacts.

CybersecurityTechnologyConflictApr 21, 2026score 0.172 posts · 0 replies across 1 instances
The thread discusses two critical vulnerabilities in the goshs software, CVE-2026-40884 and CVE-2026-40903, both affecting versions prior to 2.0.0-beta.6. These vulnerabilities involve an SFTP authentication bypass and a potential leakage of GITHUB_TOKEN through workflow artifacts, respectively. The issues highlight security risks in the software and the importance of timely patches.

Claims

The goshs software has critical vulnerabilities that allow for an SFTP authentication bypass and potential leakage of GITHUB_TOKEN through workflow artifacts.
Parent: CybersecurityEntity: goshsImpact: negativeDate: Apr 21, 2026Target: The presence of critical vulnerabilities in goshs

Source posts

@[email protected]
🔴 CVE-2026-40884 - Critical (9.8) goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.6, goshs contains an SFTP authentication bypass when the documented empty-username basic-auth syntax is used. If the server is started with -b ':pass' together with -sftp, goshs accept... 🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-40884/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
0 boosts · 0 favs · 0 replies · Apr 21, 2026
#cve#vulnerability#infosec#cybersecurity#security#tenda
@[email protected]
🔴 CVE-2026-40903 - Critical (9.1) goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.6, goshs has an ArtiPACKED vulnerability. ArtiPACKED can lead to leakage of the GITHUB_TOKEN through workflow artifacts, even though the token is not present in the repository source c... 🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-40903/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
0 boosts · 0 favs · 0 replies · Apr 21, 2026
#cve#vulnerability#infosec#cybersecurity#security#tenda