
CVE-2026-40188 goshs is a SimpleHTTPServer written in Go. From 1.0.7 to before 2.0.0-beta.4, the SFTP command rename sanitizes only the source path and not the destination, so it is… https://www.cve.org/CVERecord?id=CVE-2026-40188
Post summary
CVE-2026-40188 impacts the goshs SimpleHTTPServer by sanitizing only the source path for SFTP rename operations, indicating a potential security flaw. No exploit, patch, or PoC details are provided.

