<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-07T05:06:34.395624+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-342292</id>
    <title>EUVD-2026-342292</title>
    <updated>2026-10-07T05:06:34.443122+00:00</updated>
    <content>EUVD-2026-342292</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-342292"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-54719</id>
    <title>fkie_cve-2026-54719</title>
    <updated>2026-10-07T05:06:34.443159+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.1, the httpserver/updown.go bulkDownload handler for ?bulk&amp;file= ZIP downloads did not call findEffectiveACL or applyCustomAuth, allowing unauthenticated reads of files protected only by .goshs folder ACLs and block lists. This issue is fixed in version 2.1.1. This vulnerability exists due to an incomplete fix for CVE-2026-40189.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-54719"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-rmxw-pq4x-3fvh</id>
    <title>GHSA-rmxw-pq4x-3fvh — goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of G…</title>
    <updated>2026-10-07T05:06:34.443194+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/patrickhener/goshs, Go: github.com/patrickhener/goshs/v2, Go: goshs.de/goshs, Go: goshs.de/goshs/v2</p>
<p>GHSA-wvhv-qcqf-f3cx fixed the per-folder .goshs ACL bypass on the state-changing routes (PUT/POST upload/?mkdir/?delete) and added recursive ACL resolution, and its description states the read/list path correctly enforces .goshs. That premise does not hold for the ?bulk zip-download route. bulkDownload (httpserver/updown.go) takes one or more ?file= parameters, runs each through sanitizePath(fs.Webroot, file), and streams the contents back as a ZIP without ever calling findEffectiveACL/applyCustomAuth. It is dispatched from earlyBreakParameters (?bulk) before the normal doDir/doFile/sendFile flow that performs the ACL check. An unauthenticated attacker can therefore read any file under the webroot protected solely by a .goshs ACL, bypassing both the folder auth (401 on the normal path) and the per-file block list (404 on the normal path). Same authorization-inconsistency root cause as the original advisory, surviving on a read route the fix did not cover.</p>
<p>Proof of concept (live, against the fixed v2.1.0 build which includes fix commit f212c4f4, served with no global -b auth, only a per-folder .goshs):
  GET /protected/secret.txt              -&gt; 401 (ACL enforced on normal path)
  GET /protected/secret.txt -u admin:admin -&gt; 200
  GET /?bulk&amp;file=/protected/secret.txt  -&gt; 200, zip contains the protected file contents  (BYPASS)
  GET /?bulk&amp;file=/protected/blocked.txt -&gt; 200, zip contains the block-listed file        (block bypass)
  GET /protected/secret.txt?share        -&gt; 4…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-rmxw-pq4x-3fvh"/>
  </entry>
</feed>
