CVE-2026-40884Disclosure(goshs / goshs)

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch goshs goshs systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.6, goshs contains an SFTP authentication bypass when the documented empty-username basic-auth syntax is used. If the server is started with -b ':pass' together with -sftp, goshs accepts that configuration but does not install any SFTP password handler. As a result, an unauthenticated network attacker can connect to the SFTP service and access files without a password. This vulnerability is fixed in 2.0.0-beta.6.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • goshs

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 3 mentions (2026-04-16); latest day: 1
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
goshs

1 version affected across 1 product

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-04-16: 3Mentions · 2026-04-21: 1PoC Mentioned / Linked · 2026-04-16: 1Patch / Workaround · 2026-04-16: 1Technical Details · 2026-04-16: 3Technical Details · 2026-04-21: 104-1604-21
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-163
Disclosure2Patch1
2026-04-211
Disclosure1
Full discourse4 posts
  • Gray Hats@the_yellow_fall
    Patch

    Critical 9.8 flaw in goshs (CVE-2026-40884) allows unauthenticated SFTP access when using specific auth syntax. Secure your files—upgrade to v2.0.0-beta.6 now! #goshs #CVE202640884 #InfoSec #CyberSecurity #Pentesting #SFTP #BugBounty https://securityonline.info/goshs-sftp-authentication-bypass-cve-2026-40884/ https://t.co/cgMz4c4x7M

    Post summary

    The post highlights a critical flaw in goshs (CVE‑2026‑40884) that permits unauthenticated SFTP access and stresses the need to upgrade to v2.0.0‑beta.6, underscoring the immediate patch availability.

    080127649
    12.4K followersView on X
  • kokumօtօ@__kokumoto
    Disclosure

    goshsのSFTP実装に重大(Critical)な脆弱性。goshsはPythonのSimpleHTTPServerの多機能互換実装。CVE-2026-40884はCVSSスコア9.8で、特定のBasic認証書式における取扱不備。ユーザ名を特定せずパスワードのみを設定している場合、SFTPではパスワードが検証されない。 https://securityonline.info/goshs-sftp-authentication-bypass-cve-2026-40884/

    Post summary

    The passage announces the discovery of a critical vulnerability (CVE-2026-40884) in the goshs SFTP implementation, detailing the Basic authentication bypass and the high CVSS score, but does not include exploit code, active exploitation evidence, or patch information.

    01010788
    7.4K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-40884 SFTP Authentication Bypass in goshs Prior to 2.0.0-beta.6 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-40884

    Post summary

    The text announces CVE‑2026‑40884, an authentication bypass vulnerability affecting goshs versions prior to 2.0.0‑beta.6.

    0000040
    4.0K followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    `goshs` SFTP password authentication is vulnerable to a bypass via an empty username, leading to unauthorized access (CVE-2026-40884). Assess `goshs` deployments for exposure. #SFTP #AuthBypass #Cybersecurity https://www.pulsepatch.io/posts/cve-2026-40884-goshs-sftp-auth-bypass

    Post summary

    The post announces a newly discovered SFTP authentication bypass in goshs (CVE‑2026‑40884), detailing the exploit vector but not providing PoC, exploit code, or patch information.

    0000044
    12 followersView on X
CPE platform detail6 entries

6 of 6 entries

PartVendorProductVersionTarget SWTarget HW
Appgoshsgoshs-go-
Appgoshsgoshs2.0.0go-
Appgoshsgoshs2.0.0go-
Appgoshsgoshs2.0.0go-
Appgoshsgoshs2.0.0go-
Appgoshsgoshs2.0.0go-

Explore more