Critical severityNVD Advisory· Published Jul 28, 2026· Updated Jul 29, 2026
goshs SFTP authentication bypass via empty password (incomplete fix of CVE-2026-40884)
CVE-2026-62325
Description
goshs is a feature-rich single-binary file server for red teamers and developers. From 2.1.3 until 2.1.4, the sftpserver/sftpserver.go password handler used Username != "" && Password != "", so running goshs with -b 'admin:' -sftp and no -fkf left both SFTP authentication handlers unset and allowed unauthenticated file access. This issue is fixed in version 2.1.4.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/patrickhener/goshs/v2Go | >= 2.1.3, < 2.1.4 | 2.1.4 |
goshs.de/goshs/v2Go | >= 2.1.3, < 2.1.4 | 2.1.4 |
Affected products
1Patches
Vulnerability mechanics
References
4- github.com/advisories/GHSA-rjrw-mjq6-hpmmghsaADVISORY
- github.com/goshs-labs/goshs/commit/32f4a0e1790a709f722d0f3b2341f139d003180aghsax_refsource_MISCWEB
- github.com/goshs-labs/goshs/releases/tag/v2.1.4ghsax_refsource_MISCWEB
- github.com/goshs-labs/goshs/security/advisories/GHSA-rjrw-mjq6-hpmmghsax_refsource_CONFIRMWEB
News mentions
0No linked articles in our index yet.