<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 20:51:16 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-280198</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-280198</link>
      <description>EUVD-2026-280198</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-280198</guid>
    </item>
    <item>
      <title>fkie_cve-2026-34581</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-34581</link>
      <description>&lt;p&gt;goshs is a SimpleHTTPServer written in Go. From version 1.1.0 to before version 2.0.0-beta.2, when using the Share Token it is possible to bypass the limited selected file download with all the gosh functionalities, including code exec. This issue has been patched in version 2.0.0-beta.2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;goshs is a SimpleHTTPServer written in Go. From version 1.1.0 to before version 2.0.0-beta.2, when using the Share Token it is possible to bypass the limited selected file download with all the gosh functionalities, including code exec. This issue has been patched in version 2.0.0-beta.2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-34581</guid>
    </item>
    <item>
      <title>GHSA-jgfx-74g2-9r6g — goshs has Auth Bypass via Share Token</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-jgfx-74g2-9r6g</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/patrickhener/goshs&lt;/p&gt;
&lt;p&gt;### Summary
When using the `Share Token` it is possible to bypass the limited selected file download with all the gosh functionalities, including code exec.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The `BasicAuthMiddleware` checks for a `?token=` parameter **before** checking credentials. If the token exists in `SharedLinks`, the request passes through with **no auth check at all**. The handler then processes all query parameters — including `?ws` (WebSocket) which has higher priority than `?token`.&lt;/p&gt;
&lt;p&gt;```go
// middleware.go:22-30 — token check runs FIRST
token := r.URL.Query().Get(&amp;#34;token&amp;#34;)
if token != &amp;#34;&amp;#34; {
    _, ok := fs.SharedLinks[token]
    if ok {
        next.ServeHTTP(w, r)  // Full auth bypass
        return
    }
}
// ... normal auth checks never reached
```&lt;/p&gt;
&lt;p&gt;A share token is designed for **single-file, time-limited downloads**. But the middleware bypass grants access to everything — directory listing, file deletion, clipboard, WebSocket, and CLI command execution.&lt;/p&gt;
&lt;p&gt;**1. Create a webroot:**&lt;/p&gt;
&lt;p&gt;```bash
mkdir -p /tmp/goshs-webroot
echo &amp;#34;shareable file&amp;#34; &amp;gt; /tmp/goshs-webroot/shareable.txt
```&lt;/p&gt;
&lt;p&gt;**2. Start goshs with auth + TLS + CLI mode:**&lt;/p&gt;
&lt;p&gt;```bash
/tmp/goshs-test -d /tmp/goshs-webroot -b &amp;#39;admin:password&amp;#39; -s -ss -c -p 8000
```&lt;/p&gt;
&lt;p&gt;&amp;gt; CLI mode requires auth (`-b`) and TLS (`-s -ss`). This is the documented usage — not a weakened config.&lt;/p&gt;
&lt;p&gt;**3. Verify authentication is required:**&lt;/p&gt;
&lt;p&gt;```bash
curl -sk https://localhost:8000/
Not authorized
```&lt;/p&gt;
&lt;p&gt;**4. As a legitimate user, create a share link:**&lt;/p&gt;
&lt;p&gt;```bash
curl…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/patrickhener/goshs&lt;/p&gt;
&lt;p&gt;### Summary
When using the `Share Token` it is possible to bypass the limited selected file download with all the gosh functionalities, including code exec.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The `BasicAuthMiddleware` checks for a `?token=` parameter **before** checking credentials. If the token exists in `SharedLinks`, the request passes through with **no auth check at all**. The handler then processes all query parameters — including `?ws` (WebSocket) which has higher priority than `?token`.&lt;/p&gt;
&lt;p&gt;```go
// middleware.go:22-30 — token check runs FIRST
token := r.URL.Query().Get(&amp;#34;token&amp;#34;)
if token != &amp;#34;&amp;#34; {
    _, ok := fs.SharedLinks[token]
    if ok {
        next.ServeHTTP(w, r)  // Full auth bypass
        return
    }
}
// ... normal auth checks never reached
```&lt;/p&gt;
&lt;p&gt;A share token is designed for **single-file, time-limited downloads**. But the middleware bypass grants access to everything — directory listing, file deletion, clipboard, WebSocket, and CLI command execution.&lt;/p&gt;
&lt;p&gt;**1. Create a webroot:**&lt;/p&gt;
&lt;p&gt;```bash
mkdir -p /tmp/goshs-webroot
echo &amp;#34;shareable file&amp;#34; &amp;gt; /tmp/goshs-webroot/shareable.txt
```&lt;/p&gt;
&lt;p&gt;**2. Start goshs with auth + TLS + CLI mode:**&lt;/p&gt;
&lt;p&gt;```bash
/tmp/goshs-test -d /tmp/goshs-webroot -b &amp;#39;admin:password&amp;#39; -s -ss -c -p 8000
```&lt;/p&gt;
&lt;p&gt;&amp;gt; CLI mode requires auth (`-b`) and TLS (`-s -ss`). This is the documented usage — not a weakened config.&lt;/p&gt;
&lt;p&gt;**3. Verify authentication is required:**&lt;/p&gt;
&lt;p&gt;```bash
curl -sk https://localhost:8000/
Not authorized
```&lt;/p&gt;
&lt;p&gt;**4. As a legitimate user, create a share link:**&lt;/p&gt;
&lt;p&gt;```bash
curl…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-jgfx-74g2-9r6g</guid>
    </item>
  </channel>
</rss>
