PT-2026-25357 · Gokapi · Gokapi

Forceu

+1

·

Published

2026-03-13

·

Updated

2026-03-25

·

CVE-2026-30955

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Gokapi versions prior to 2.2.4
Description Gokapi is a self-hosted file sharing server that supports automatic expiration and encryption. An API endpoint is susceptible to accepting request bodies of unlimited size. An authenticated user can exploit this to cause an Out-Of-Memory (OOM) kill, leading to a complete service disruption for all users. The issue impacts the server's stability and availability. The affected API endpoint accepts unbounded request bodies. The request body is the vulnerable parameter.
Recommendations Update to version 2.2.4 or later.

Exploit

Fix

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-30955
GHSA-QWC6-VC2V-2GGJ
GO-2026-4698
SUSE-SU-2026:1042-1

Affected Products

Gokapi