Junglewise Threat Intelligence

GO-2026-5232 - Unauthenticated Open Redirect, Arbitrary HTTP Response Header Injection, Missing CSRF, and Invisible-Mode Bypass in goshs `/?redirect` endpo

Severity: info · Published 2026-06-25

Technologies: github.com/patrickhener/goshs/v2 (Go), github.com/patrickhener/goshs (Go). Vendors: Go.

Executive brief

Unauthenticated Open Redirect, Arbitrary HTTP Response Header Injection, Missing CSRF, and Invisible-Mode Bypass in goshs `/?redirect` endpoint in github.com/patrickhener/goshs

Affected products

  • Go github.com/patrickhener/goshs/v2
  • Go github.com/patrickhener/goshs

Related threats