CVE-2026-40189Disclosure(goshs / goshs)

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Prioritize remediation for goshs goshs systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.4, goshs enforces the documented per-folder .goshs ACL/basic-auth mechanism for directory listings and file reads, but it does not enforce the same authorization checks for state-changing routes. An unauthenticated attacker can upload files with PUT, upload files with multipart POST /upload, create directories with ?mkdir, and delete files with ?delete inside a .goshs-protected directory. By deleting the .goshs file itself, the attacker can remove the folder's auth policy and then access previously protected content without credentials. This results in a critical authorization bypass affecting confidentiality, integrity, and availability. This vulnerability is fixed in 2.0.0-beta.4.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • goshs

Threat summary

  • Public PoC and exploit tooling are both present
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 3 mentions (2026-04-10); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
goshs

1 version affected across 1 product

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-04-10: 3Mentions · 2026-04-11: 1Mentions · 2026-04-28: 1PoC Mentioned / Linked · 2026-04-10: 1Exploit Tool / Code · 2026-04-10: 1Technical Details · 2026-04-10: 3Technical Details · 2026-04-11: 1Technical Details · 2026-04-28: 104-1004-1104-28
Signal classification3 categories
Disclosure
360.0%
Exploit
120.0%
General
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-04-103
Disclosure1Exploit1General1
2026-04-111
Disclosure1
2026-04-281
Disclosure1
Full discourse5 posts
  • cvereports@_cvereports
    Disclosure

    CVE-2026-40189: CVE-2026-40189: Critical Authorization Bypass in goshs State-Changing Routes CVE-2026-40189 is a critical authorization bypass vulnerability in goshs, a Go-based simple HTTP server. Due to missing authorization checks on state-changing... https://cvereports.com/reports/CVE-2026-40189

    Post summary

    The text announces a critical authorization‑bypass vulnerability in the Go‑based goshs HTTP server, noting missing authorization checks on state‑changing routes, but it does not provide any PoC, exploit code, active‑exploitation evidence, or mitigation details.

    0000033
    36 followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    Goshs has a critical authorization bypass (CVE-2026-40189) affecting state-changing routes. Review access controls & monitor activity. #goshs #infosec #authbypass https://www.pulsepatch.io/posts/cve-2026-40189-goshs-acl-bypass

    Post summary

    The post announces a newly identified critical authorization bypass in Goshs, noting its impact on state‑changing routes and advising basic security reviews.

    0000060
    11 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-40189 goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.4, goshs enforces the documented per-folder .goshs ACL/basic-auth mechanism for directory listings and … https://www.cve.org/CVERecord?id=CVE-2026-40189

    Post summary

    The brief commentary refers to CVE‑2026‑40189 in the Go‑based SimpleHTTPServer, noting that earlier versions enforced per‑folder ACL/basic‑auth, but gives no evidence of exploits, attacks, or patches.

    0000084
    57.0K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-40189 Authorization Bypass in goshs SimpleHTTPServer Prior to 2.0.0-beta.4 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-40189

    Post summary

    CVE-2026-40189 reveals an authorization bypass in goshs SimpleHTTPServer before 2.0.0-beta.4; the entry provides the flaw type but no PoC, exploit, or patch information.

    0000027
    4.0K followersView on X
  • 0day Signal@0dayPublishing
    Exploit

    🚨 CVE-2026-40189: goshs has a file-based ACL autho... Delete the .goshs ACL file via unauthenticated ?delete param, then own the entire protected directory - classic state-c... https://zerodaysignal.com/vulnerability/CVE-2026-40189 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post highlights that CVE‑2026‑40189 allows an unauthenticated user to delete the .goshs ACL file via a delete parameter, enabling full directory takeover.

    0000086
    204 followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
Appgoshsgoshs-go-
Appgoshsgoshs2.0.0go-
Appgoshsgoshs2.0.0go-
Appgoshsgoshs2.0.0go-

Explore more