<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 04:41:55 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-281106</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-281106</link>
      <description>EUVD-2026-281106</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-281106</guid>
    </item>
    <item>
      <title>fkie_cve-2026-35471</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-35471</link>
      <description>&lt;p&gt;goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.3, tdeleteFile() missing return after path traversal check. This vulnerability is fixed in 2.0.0-beta.3.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.3, tdeleteFile() missing return after path traversal check. This vulnerability is fixed in 2.0.0-beta.3.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-35471</guid>
    </item>
    <item>
      <title>GHSA-6qcc-6q27-whp8 — goshs: Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-6qcc-6q27-whp8</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/patrickhener/goshs&lt;/p&gt;
&lt;p&gt;### Summary
* `deleteFile()` missing return after path traversal check | `httpserver/handler.go:645-671`&lt;/p&gt;
&lt;p&gt;The finding affects the default configuration, no flags or authentication required.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;**File:** `httpserver/handler.go:645-671`
**Trigger:** `GET /&amp;lt;path&amp;gt;?delete` (handler.go:157-160 dispatches to `deleteFile`)&lt;/p&gt;
&lt;p&gt;The function detects `..` in the decoded path but does not `return`.&lt;/p&gt;
&lt;p&gt;```go
func (fs *FileServer) deleteFile(w http.ResponseWriter, req *http.Request) {
    upath := filepath.FromSlash(filepath.Clean(&amp;#34;/&amp;#34; + strings.Trim(req.URL.Path, &amp;#34;/&amp;#34;)))&lt;/p&gt;
&lt;p&gt;fileCleaned, _ := url.QueryUnescape(upath)
    if strings.Contains(fileCleaned, &amp;#34;..&amp;#34;) {
        w.WriteHeader(500)
        _, err := w.Write([]byte(&amp;#34;Cannot delete file&amp;#34;))
        if err != nil {
            logger.Errorf(&amp;#34;error writing answer to client: %+v&amp;#34;, err)
        }
        // BUG: no return, falls through to os.RemoveAll
    }&lt;/p&gt;
&lt;p&gt;deletePath := filepath.Join(fs.Webroot, fileCleaned)
    err := os.RemoveAll(deletePath)  // always executes
```&lt;/p&gt;
&lt;p&gt;**Root causes:**
Missing `return` after the guard makes the check dead code&lt;/p&gt;
&lt;p&gt;**Impact:** Unauthenticated arbitrary file/directory deletion.&lt;/p&gt;
&lt;p&gt;**PoCs:**
```bash
#!/usr/bin/env bash
# Delete an arbitrary file/directory on a running goshs instance.
# Usage: ./arbitrary_delete.sh &amp;lt;host&amp;gt; &amp;lt;port&amp;gt; &amp;lt;absolute-path-to-delete&amp;gt;&lt;/p&gt;
&lt;p&gt;set -euo pipefail&lt;/p&gt;
&lt;p&gt;HOST=&amp;#34;${1:?Usage: $0 &amp;lt;host&amp;gt; &amp;lt;port&amp;gt; &amp;lt;absolute-path-to-delete&amp;gt;}&amp;#34;
PORT=&amp;#34;${2:?Usage: $0 &amp;lt;host&amp;gt; &amp;lt;port&amp;gt; &amp;lt;absolute-path-to-delete&amp;gt;}&amp;#34;
TARGET…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/patrickhener/goshs&lt;/p&gt;
&lt;p&gt;### Summary
* `deleteFile()` missing return after path traversal check | `httpserver/handler.go:645-671`&lt;/p&gt;
&lt;p&gt;The finding affects the default configuration, no flags or authentication required.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;**File:** `httpserver/handler.go:645-671`
**Trigger:** `GET /&amp;lt;path&amp;gt;?delete` (handler.go:157-160 dispatches to `deleteFile`)&lt;/p&gt;
&lt;p&gt;The function detects `..` in the decoded path but does not `return`.&lt;/p&gt;
&lt;p&gt;```go
func (fs *FileServer) deleteFile(w http.ResponseWriter, req *http.Request) {
    upath := filepath.FromSlash(filepath.Clean(&amp;#34;/&amp;#34; + strings.Trim(req.URL.Path, &amp;#34;/&amp;#34;)))&lt;/p&gt;
&lt;p&gt;fileCleaned, _ := url.QueryUnescape(upath)
    if strings.Contains(fileCleaned, &amp;#34;..&amp;#34;) {
        w.WriteHeader(500)
        _, err := w.Write([]byte(&amp;#34;Cannot delete file&amp;#34;))
        if err != nil {
            logger.Errorf(&amp;#34;error writing answer to client: %+v&amp;#34;, err)
        }
        // BUG: no return, falls through to os.RemoveAll
    }&lt;/p&gt;
&lt;p&gt;deletePath := filepath.Join(fs.Webroot, fileCleaned)
    err := os.RemoveAll(deletePath)  // always executes
```&lt;/p&gt;
&lt;p&gt;**Root causes:**
Missing `return` after the guard makes the check dead code&lt;/p&gt;
&lt;p&gt;**Impact:** Unauthenticated arbitrary file/directory deletion.&lt;/p&gt;
&lt;p&gt;**PoCs:**
```bash
#!/usr/bin/env bash
# Delete an arbitrary file/directory on a running goshs instance.
# Usage: ./arbitrary_delete.sh &amp;lt;host&amp;gt; &amp;lt;port&amp;gt; &amp;lt;absolute-path-to-delete&amp;gt;&lt;/p&gt;
&lt;p&gt;set -euo pipefail&lt;/p&gt;
&lt;p&gt;HOST=&amp;#34;${1:?Usage: $0 &amp;lt;host&amp;gt; &amp;lt;port&amp;gt; &amp;lt;absolute-path-to-delete&amp;gt;}&amp;#34;
PORT=&amp;#34;${2:?Usage: $0 &amp;lt;host&amp;gt; &amp;lt;port&amp;gt; &amp;lt;absolute-path-to-delete&amp;gt;}&amp;#34;
TARGET…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-6qcc-6q27-whp8</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:10542-1 — goshs-2.0.0-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10542-1</link>
      <description>&lt;p&gt;goshs-2.0.0-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;goshs-2.0.0-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:10542-1</guid>
    </item>
  </channel>
</rss>
