CVE-2026-50138

Summary

goshs is a SimpleHTTPServer written in Go. Prior to version 2.1.0, when goshs is launched with WebDAV enabled (-w), the mode-restriction flags --read-only, --upload-only, and --no-delete are enforced only on the primary HTTP port. The WebDAV port is wired straight to golang.org/x/net/webdav.Handler with no equivalent guard, so an authenticated WebDAV client can PUT, DELETE, MKCOL, MOVE, and COPY despite the operator's stated intent. Version 2.1.0 patches the issue.

Affected Software

VendorProductVersion RangeStatus
patrickhenergoshs< 2.1.0affected

Weaknesses

  • CWE-284: CWE-284: Improper Access Control

References