CVE-2026-40189 - goshs has a file-based ACL authorization bypass in goshs state-changing routes
CVE ID :CVE-2026-40189
Published : April 10, 2026, 8:16 p.m. | 3 hours, 52 minutes ago
Description :goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.4, goshs enforces the docum...
Related Vulnerabilities
- CVE-2026-35621: OpenClaw before 2026.3.24 contains a privilege escalation vulnerability where the /allowlist command HIGH
- CVE-2026-35654: OpenClaw before 2026.3.25 contains an authorization bypass vulnerability in Microsoft Teams feedback MEDIUM
- CVE-2026-35663: OpenClaw before 2026.3.25 contains a privilege escalation vulnerability allowing non-admin operators HIGH
- CVE-2026-34486: Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-2914 MEDIUM
- CVE-2026-5724: The frontend gRPC server's streaming interceptor chain did not include the authorization interceptor N/A
Related Coverage
Threat Actors