Junglewise Threat Intelligence

CVE-2026-50138: goshs is a SimpleHTTPServer written in Go. Prior to version 2.1.0, when `goshs` is launched with WebDAV enabled (`-w`), the mode-restriction

CVE-2026-50138 · Severity: high · CVSS 8.1 · Published 2026-08-18

Technologies: Patrickhener Goshs, goshs.de/goshs/v2 (Go), goshs.de/goshs (Go). Vendors: Go.

Executive brief

goshs is a tool used to serve files over the web. A security flaw allows users to bypass security restrictions like "read-only" or "no-delete" when using the WebDAV feature. This means an authorized user could delete or modify files even if the administrator explicitly configured the server to prevent such actions.

Technical details

The vulnerability is an improper access control issue (CWE-284) within the WebDAV implementation of goshs. While the primary HTTP handler correctly enforces mode-restriction flags, the WebDAV mux (located in httpserver/server.go) fails to apply the ReadOnly, UploadOnly, or NoDelete checks before passing requests to the underlying WebDAV handler. An attacker with valid credentials can use WebDAV methods like PUT, DELETE, MKCOL, MOVE, and COPY to bypass intended file system restrictions. This issue is resolved in version 2.1.0.

Affected products

  • patrickhener goshs <= 2.0.9

Timeline

  • 2026-05-27: other: Vulnerability reproduced by researcher
  • 2026-05-28: disclosed: Advisory published by maintainer
  • 2026-07-01: advisory: Published to GitHub Advisory Database

References

Related threats