Executive brief
Unauthenticated Open Redirect, Arbitrary HTTP Response Header Injection, Missing CSRF, and Invisible-Mode Bypass in goshs `/?redirect` endpoint
Affected products
- Go github.com/patrickhener/goshs/v2
- Go github.com/patrickhener/goshs
Junglewise Threat Intelligence
Severity: low · CVSS 3.1 · Published 2026-04-14
Technologies: github.com/patrickhener/goshs/v2 (Go), github.com/patrickhener/goshs (Go). Vendors: Go.
Unauthenticated Open Redirect, Arbitrary HTTP Response Header Injection, Missing CSRF, and Invisible-Mode Bypass in goshs `/?redirect` endpoint