Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-42091 |
|
Cross-Site Request Forgery (CSRF) in github.com/patrickhener/goshs (CVE-2026-42091)
vulnerability in github.com/patrickhener/goshs (CVE-2026-42091). Data can be tampered with by attackers. Exploitable via ``e3c3d37``. Mitigation: upgrade to `2.0.2` or later.
|
| CVE-2026-35471 |
|
Path Traversal in github.com/patrickhener/goshs (CVE-2026-35471)
path traversal in github.com/patrickhener/goshs (CVE-2026-35471). Successful exploitation can lead to full system takeover. Exploitable via ``deleteFile``. Mitigation: upgrade to `1.1.5-0.20260401172448-237f3af891a9` or later.
|
| CVE-2026-35392 |
|
Path Traversal in github.com/patrickhener/goshs (CVE-2026-35392)
path traversal in github.com/patrickhener/goshs (CVE-2026-35392). Successful exploitation can lead to full system takeover. Exploitable via ``req.URL.Path``. Mitigation: upgrade to `1.1.5-0.20260401172448-237f3af891a9` or later.
|
| CVE-2026-35393 |
|
Path Traversal in github.com/patrickhener/goshs (CVE-2026-35393)
path traversal in github.com/patrickhener/goshs (CVE-2026-35393). Successful exploitation can lead to full system takeover. Exploitable via ``req.URL.Path``. Mitigation: upgrade to `1.1.5-0.20260401172448-237f3af891a9` or later.
|
| CVE-2026-34581 |
|
Vulnerability in github.com/patrickhener/goshs (CVE-2026-34581)
vulnerability in github.com/patrickhener/goshs (CVE-2026-34581). Confidential information can be exposed externally. Exploitable via ``BasicAuthMiddleware``.
|