PT-2026-25358 · Gokapi · Gokapi

Sijisu

·

Publicado

2026-03-13

·

Atualizado

2026-03-25

·

CVE-2026-30961

CVSS v3.1

4.3

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions Gokapi versions prior to 2.2.4
Description Gokapi is a self-hosted file sharing server. The chunked upload completion path for file requests does not validate the total file size against the per-request MaxSize limit. An attacker with a public file request link can split an oversized file into chunks, each under MaxSize, and upload them sequentially, bypassing the size restriction. Files up to the server's global MaxFileSizeMB are accepted regardless of the file request's configured limit. This allows unauthorized storage consumption, circumvention of administrative resource policies, and potential service disruption through storage exhaustion.
Recommendations Update to version 2.2.4 or later.

Exploit

Correção

Allocation of Resources Without Limits

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-30961
GHSA-45VH-RPC8-HXPP
GO-2026-4695
SUSE-SU-2026:1042-1

Produtos afetados

Gokapi