CVE-2026-35393
Critical · CVSS 9.8- CVSS
- 9.8
- nvd
- EPSS
- —
- KEV
- No
- Class
- oss containerizable
- CWE-22
Description
goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.3, the POST multipart upload directory not sanitized. This vulnerability is fixed in 2.0.0-beta.3.
Affected packages
| Go | github.com/patrickhener/goshs | 0 → 1.1.5-0.20260401172448-237f3af891a9 |
References
Status: profiled · ingested 2026-07-25T00:00:18.000Z