
[CVE-2026-35392: CRITICAL] goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.3, PUT upload in httpserver/updown.go has no path sanitization. This vulnerability is fixed in 2.0.0-beta.3.#cve,CVE-2026-35392,#cybersecurity https://cvefind.com/CVE-2026-35392
Post summary
A critical path‑sanitization flaw in the Go-based SimpleHTTPServer 'goshs' allows unrestricted PUT uploads, announced as CVE‑2026‑35392 and fixed in version 2.0.0‑beta.3.


