CVE-2026-34581
Last modified
CVE-2026-34581 is a high-severity vulnerability rated 8.1/10 on the CVSS scale. goshs is a SimpleHTTPServer written in Go. From version 1.1.0 to before version 2.0.0-beta.2, when using the Share Token it is possible to bypass the limited selected file download with all the gosh functionalities, including code exec. EPSS estimates a 0.39% chance of exploitation in the next 30 days.
Description
goshs is a SimpleHTTPServer written in Go. From version 1.1.0 to before version 2.0.0-beta.2, when using the Share Token it is possible to bypass the limited selected file download with all the gosh functionalities, including code exec. This issue has been patched in version 2.0.0-beta.2.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Goshs | Goshs | >= 1.1.0, < 2.0.0 | — |
| Goshs | Goshs | 2.0.0 | Beta1 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-34581?
How severe is CVE-2026-34581?
How do I fix CVE-2026-34581?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-34574Parse Server is an open source backend that can be deployed …5.4
- CVE-2026-34576Postiz is an AI social media scheduling tool. Prior to versi…7.7
- CVE-2026-34577Postiz is an AI social media scheduling tool. Prior to versi…8.6
- CVE-2026-34578OPNsense is a FreeBSD based firewall and routing platform. P…8.2
- CVE-2026-34579Mantis Bug Tracker (MantisBT) is an open source issue tracke…5.3
- CVE-2026-34580Botan is a C++ cryptography library. In 3.11.0, the function…7.5
- CVE-2026-34582Botan is a C++ cryptography library. Prior to version 3.11.1…9.1
- CVE-2026-34584listmonk is a standalone, self-hosted, newsletter and mailin…5.4
- CVE-2026-34585SiYuan is a personal knowledge management system. Prior to v…8.2
- CVE-2026-34586PdfDing is a selfhosted PDF manager, viewer and editor offer…6.5
- CVE-2026-34587Kirby is an open-source content management system. Prior to …8.1
- CVE-2026-34588OpenEXR provides the specification and reference implementat…7.8
Are you affected by CVE-2026-34581?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
