Junglewise Threat Intelligence

CVE-2026-64863: goshs WebDAV deletion bypass via MOVE and COPY methods

CVE-2026-64863 · Severity: critical · CVSS 9.1 · Published 2026-07-28

Technologies: github.com/patrickhener/goshs/v2 (Go), goshs.de/goshs/v2 (Go), Goshs-Labs Goshs, github.com/patrickhener/goshs (Go), goshs.de/goshs (Go). Vendors: Go.

Executive brief

goshs is a file server used by developers and security professionals to share files. A security flaw allows users to bypass the "no-delete" safety setting by using specific WebDAV commands. This means an attacker could delete or overwrite important files on the server even when the administrator has explicitly disabled file deletion, leading to data loss or service disruption.

Technical details

A vulnerability in the WebDAV implementation of goshs exists within the 'wdGuard' handler in 'httpserver/server.go'. While the server correctly blocks the DELETE method when the '--no-delete' flag is set, it incorrectly classifies the MOVE and COPY methods as write-only operations. Because a MOVE operation involves a rename (which deletes the source file) and can include an 'Overwrite: T' header (which deletes the destination file), attackers can bypass deletion restrictions. Similarly, a COPY operation with an overwrite header can destroy existing destination files. This allows unauthenticated network attackers to perform unauthorized file deletions and overwrites. The issue is resolved in version 2.1.4.

Affected products

  • goshs-labs goshs < 2.1.4

Timeline

  • 2026-07-03: patched: Version 2.1.4 released to fix the bypass.
  • 2026-07-28: disclosed: CVE-2026-64863 published.

References

Related threats