PT-2026-33233 · Goshs · Goshs

·

CVE-2026-40884

·

Published

2026-04-14

·

Updated

2026-07-30

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions goshs versions prior to 2.0.0-beta.6
Description goshs contains an SFTP authentication bypass that occurs when the server is started with the -sftp flag and the basic-auth syntax -b ':pass' (where the username is left empty). In this configuration, the software fails to install an SFTP password handler, allowing an unauthenticated network attacker to connect to the SFTP service and access files without providing a password. This allows unauthorized reading, uploading, renaming, and deleting of files within the configured SFTP root, depending on the server mode and filesystem permissions.
Recommendations Update goshs to version 2.0.0-beta.6. As a temporary workaround, avoid using the -b ':pass' syntax when starting the server with the -sftp flag.

Exploit

Fix

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-40884
GHSA-C29W-QQ4M-2GCV
GO-2026-5303
OPENSUSE-SU-2026:21483-1

Affected Products

Goshs