HarborGuard / CVE
Back to search
CRITICALCVE-2026-35392Published Modified CNA GitHub_M

CVE-2026-35392: goshs has an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs PUT Upload

goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.3, PUT upload in httpserver/updown.go has no path sanitization. This vulnerability is fixed in 2.0.0-beta.3.

Metrics

CVSS v3.0
9.8
Severity
CRITICAL
Fixed in
Affected Products
1
Affected packages
  • patrickhener / goshs
    < 2.0.0-beta.3
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H