Junglewise Threat Intelligence

CVE-2026-62325: goshs SFTP authentication bypass via empty password handler logic

CVE-2026-62325 · Severity: critical · CVSS 9.1 · Published 2026-07-28

Technologies: github.com/patrickhener/goshs/v2 (Go), goshs.de/goshs/v2 (Go), Goshs-Labs Goshs, goshs.de/goshs (Go). Vendors: Go.

Executive brief

goshs is a file server tool used by developers and security professionals to quickly share files over a network. A security flaw in the SFTP component allows unauthorized users to access, download, or delete files without providing a password if the server is configured with a username but no password. This could lead to the complete exposure or loss of sensitive data hosted on the server.

Technical details

A vulnerability in `sftpserver/sftpserver.go` exists because the SFTP password handler is only initialized if both a username and password are non-empty (`Username != "" && Password != ""`). When a user starts goshs with a username but an empty password (e.g., `-b 'admin:' -sftp`) and no public key file (`-fkf`), the `PasswordHandler` remains nil. The underlying `gliderlabs/ssh` library defaults to `NoClientAuth = true` when all authentication handlers are nil, allowing remote attackers to connect via SFTP without any credentials. This is an incomplete fix for a previous vulnerability (CVE-2026-40884) which only addressed empty usernames. The issue is resolved in version 2.1.4 by changing the logic to use an OR (`||`) operator, ensuring the handler is installed if either credential is provided.

Affected products

  • goshs-labs goshs >= 2.1.3, < 2.1.4

Timeline

  • 2026-06-26: disclosed: GHSA-rjrw-mjq6-hpmm published
  • 2026-07-03: patched: Version 2.1.4 released
  • 2026-07-28: advisory: NVD published CVE-2026-62325

References

Related threats