CVE-2026-34581Disclosure(goshs / goshs)

LOWCVSS 8.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch goshs goshs systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

goshs is a SimpleHTTPServer written in Go. From version 1.1.0 to before version 2.0.0-beta.2, when using the Share Token it is possible to bypass the limited selected file download with all the gosh functionalities, including code exec. This issue has been patched in version 2.0.0-beta.2.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-288

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • goshs

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 3 mentions (2026-04-03); latest day: 1
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
goshs

1 version affected across 1 product

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-04-03: 3Mentions · 2026-05-02: 1Patch / Workaround · 2026-05-02: 1Technical Details · 2026-04-03: 3Technical Details · 2026-05-02: 104-0305-02
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-033
Disclosure3
2026-05-021
Patch1
Full discourse4 posts
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    Patch

    goshs share tokens are useless. CVE-2026-34581 lets attackers RCE your server with a token. Upgrade to 2.0.0-beta.2 immediately. #CVE #RCE #GoLang #git #gitlab #github info: https://www.valtersit.com/cve/2026/04/cve-2026-34581/

    Post summary

    CVE-2026-34581 enables RCE via a token, and the primary recommendation is to upgrade to version 2.0.0-beta.2 to mitigate the issue.

    00020115
    973 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-34581 goshs is a SimpleHTTPServer written in Go. From version 1.1.0 to before version 2.0.0-beta.2, when using the Share Token it is possible to bypass the limited selected… https://www.cve.org/CVERecord?id=CVE-2026-34581

    Post summary

    The post briefly discloses that CVE-2026-34581 allows Share Token bypass in the goshs SimpleHTTPServer across versions 1.1.0 to pre‑2.0.0‑beta.2.

    00010236
    56.9K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-34581 goshs is a SimpleHTTPServer written in Go. From version 1.1.0 to before version 2.0.0-beta.2, when using the Share Token it is possible to bypass the limited selected… https://www.cve.org/CVERecord?id=CVE-2026-34581 ----- Traducción: CVE-2026-34581 gos… http://infoflow.cloud`

    Post summary

    The tweet announces CVE-2026-34581, noting a token‑bypass vulnerability in goshs SimpleHTTPServer versions 1.1.0 to before 2.0.0‑beta2, with no evidence of exploitation or patch details.

    0000033
    65 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-34581 - High goshs is a SimpleHTTPServer written in Go. From version 1.1.0 to before version 2.0.0-beta.2, when using the Share Token it is possible to bypass the limited selected file download with all t... https://www.thehackerwire.com/vulnerability/CVE-2026-34581/ https://t.co/N1yV8lsdW8

    Post summary

    The article discloses a high‑severity flaw in goshs that allows bypassing download restrictions via the Share Token, but it provides no exploit code, active‑exploitation evidence, or patch information.

    0000064
    163 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appgoshsgoshs-go-
Appgoshsgoshs2.0.0go-

Explore more