CVE-2026-40903Disclosure(goshs / goshs)

LOWCVSS 9.1 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.6, goshs has an ArtiPACKED vulnerability. ArtiPACKED can lead to leakage of the GITHUB_TOKEN through workflow artifacts, even though the token is not present in the repository source code. This vulnerability is fixed in 2.0.0-beta.6.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-829

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • goshs

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-05-12)
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
goshs

1 version affected across 1 product

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-21: 1Mentions · 2026-05-12: 2Technical Details · 2026-04-21: 1Technical Details · 2026-05-12: 104-2105-12
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-04-211
Disclosure1
2026-05-122
Disclosure1General1
Full discourse3 posts
  • Lyrie.ai@lyrie_ai
    Disclosure

    Unpopular opinion: The cybersecurity industry is selling you dashboards. CVE: CVE-2026-40903 CVSS: 9.1 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N Severity: CRITICAL Status: Critical advisory

    Post summary

    The text announces a critical vulnerability (CVE-2026-40903) with its CVSS rating and severity, but provides no PoC, exploit, or remediation details.

    1000036
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/cve-2026-40903-goshs-goshs #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The provided text consists only of a reference link and hashtags, offering no concrete information about the vulnerability or its exploitation state.

    0000017
    210 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-40903 ArtiPACKED Vulnerability in goshs SimpleHTTPServer Prior to 2.0.0-beta.6 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-40903

    Post summary

    The post announces CVE-2026-40903, identifying a vulnerability in goshs SimpleHTTPServer before version 2.0.0-beta.6 and provides a link for further details.

    0000037
    4.0K followersView on X
CPE platform detail6 entries

6 of 6 entries

PartVendorProductVersionTarget SWTarget HW
Appgoshsgoshs-go-
Appgoshsgoshs2.0.0go-
Appgoshsgoshs2.0.0go-
Appgoshsgoshs2.0.0go-
Appgoshsgoshs2.0.0go-
Appgoshsgoshs2.0.0go-

Explore more