CVE-2026-40903

EUVD-2026-24282
goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.6, goshs has an ArtiPACKED vulnerability. ArtiPACKED can lead to leakage of the GITHUB_TOKEN through workflow artifacts, even though the token is not present in the repository source code. This vulnerability is fixed in 2.0.0-beta.6.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.1 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 14%
Affected Products (NVD)
VendorProductVersion
goshsgoshs
𝑥
< 2.0.0
goshsgoshs
2.0.0:beta1
goshsgoshs
2.0.0:beta2
goshsgoshs
2.0.0:beta3
goshsgoshs
2.0.0:beta4
goshsgoshs
2.0.0:beta5
𝑥
= Vulnerable software versions