CVE-2026-40188 - goshs is Missing Write Protection for Parametric Data Values
CVE ID :CVE-2026-40188
Published : April 10, 2026, 8:16 p.m. | 3 hours, 52 minutes ago
Description :goshs is a SimpleHTTPServer written in Go. From 1.0.7 to before 2.0.0-beta.4, the SFTP com...
Related Vulnerabilities
- CVE-2026-1924: The Aruba HiSpeed Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in all vers MEDIUM
- CVE-2026-4162: The Gravity SMTP plugin for WordPress is vulnerable to Missing Authorization in versions up to, and HIGH
- CVE-2026-2305: The AddFunc Head & Footer Code plugin for WordPress is vulnerable to Stored Cross-Site Scripting via MEDIUM
- CVE-2026-40021: Apache Log4net's XmlLayout https://logging.apache.org/log4net/manual/configuration/layouts.html#layo MEDIUM
- CVE-2026-34481: Apache Log4j's JsonTemplateLayout https://logging.apache.org/log4j/2.x/manual/json-template-layout. MEDIUM
Related Coverage
Threat Actors