PT-2026-25357 · Gokapi · Gokapi

Forceu

+1

·

Publicado

2026-03-13

·

Atualizado

2026-03-25

·

CVE-2026-30955

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Gokapi versions prior to 2.2.4
Description Gokapi is a self-hosted file sharing server that supports automatic expiration and encryption. An API endpoint is susceptible to accepting request bodies of unlimited size. An authenticated user can exploit this to cause an Out-Of-Memory (OOM) kill, leading to a complete service disruption for all users. The issue impacts the server's stability and availability. The affected API endpoint accepts unbounded request bodies. The request body is the vulnerable parameter.
Recommendations Update to version 2.2.4 or later.

Exploit

Correção

Resource Exhaustion

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-30955
GHSA-QWC6-VC2V-2GGJ
GO-2026-4698
SUSE-SU-2026:1042-1

Produtos afetados

Gokapi