CVE-2026-35392
EUVD-2026-1948806.04.2026, 21:16
goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.3, PUT upload in httpserver/updown.go has no path sanitization. This vulnerability is fixed in 2.0.0-beta.3.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| goshs | goshs | 𝑥 < 2.0.0 |
| goshs | goshs | 2.0.0:beta1 |
| goshs | goshs | 2.0.0:beta2 |
𝑥
= Vulnerable software versions