<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-08T03:32:52.125797+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-280198</id>
    <title>EUVD-2026-280198</title>
    <updated>2026-10-08T03:32:52.182363+00:00</updated>
    <content>EUVD-2026-280198</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-280198"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-34581</id>
    <title>fkie_cve-2026-34581</title>
    <updated>2026-10-08T03:32:52.182418+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>goshs is a SimpleHTTPServer written in Go. From version 1.1.0 to before version 2.0.0-beta.2, when using the Share Token it is possible to bypass the limited selected file download with all the gosh functionalities, including code exec. This issue has been patched in version 2.0.0-beta.2.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-34581"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-jgfx-74g2-9r6g</id>
    <title>GHSA-jgfx-74g2-9r6g — goshs has Auth Bypass via Share Token</title>
    <updated>2026-10-08T03:32:52.182466+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/patrickhener/goshs</p>
<p>### Summary
When using the `Share Token` it is possible to bypass the limited selected file download with all the gosh functionalities, including code exec.</p>
<p>### Details</p>
<p>The `BasicAuthMiddleware` checks for a `?token=` parameter **before** checking credentials. If the token exists in `SharedLinks`, the request passes through with **no auth check at all**. The handler then processes all query parameters — including `?ws` (WebSocket) which has higher priority than `?token`.</p>
<p>```go
// middleware.go:22-30 — token check runs FIRST
token := r.URL.Query().Get("token")
if token != "" {
    _, ok := fs.SharedLinks[token]
    if ok {
        next.ServeHTTP(w, r)  // Full auth bypass
        return
    }
}
// ... normal auth checks never reached
```</p>
<p>A share token is designed for **single-file, time-limited downloads**. But the middleware bypass grants access to everything — directory listing, file deletion, clipboard, WebSocket, and CLI command execution.</p>
<p>**1. Create a webroot:**</p>
<p>```bash
mkdir -p /tmp/goshs-webroot
echo "shareable file" &gt; /tmp/goshs-webroot/shareable.txt
```</p>
<p>**2. Start goshs with auth + TLS + CLI mode:**</p>
<p>```bash
/tmp/goshs-test -d /tmp/goshs-webroot -b 'admin:password' -s -ss -c -p 8000
```</p>
<p>&gt; CLI mode requires auth (`-b`) and TLS (`-s -ss`). This is the documented usage — not a weakened config.</p>
<p>**3. Verify authentication is required:**</p>
<p>```bash
curl -sk https://localhost:8000/
Not authorized
```</p>
<p>**4. As a legitimate user, create a share link:**</p>
<p>```bash
curl…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-jgfx-74g2-9r6g"/>
  </entry>
</feed>
