PT-2026-25358 · Gokapi · Gokapi

Sijisu

·

Published

2026-03-13

·

Updated

2026-03-25

·

CVE-2026-30961

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions Gokapi versions prior to 2.2.4
Description Gokapi is a self-hosted file sharing server. The chunked upload completion path for file requests does not validate the total file size against the per-request MaxSize limit. An attacker with a public file request link can split an oversized file into chunks, each under MaxSize, and upload them sequentially, bypassing the size restriction. Files up to the server's global MaxFileSizeMB are accepted regardless of the file request's configured limit. This allows unauthorized storage consumption, circumvention of administrative resource policies, and potential service disruption through storage exhaustion.
Recommendations Update to version 2.2.4 or later.

Exploit

Fix

Allocation of Resources Without Limits

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-30961
GHSA-45VH-RPC8-HXPP
GO-2026-4695
SUSE-SU-2026:1042-1

Affected Products

Gokapi