CVE-2026-40189 - goshs has a file-based ACL authorization bypass in goshs state-changing routes
CVE ID :CVE-2026-40189
Published : April 10, 2026, 8:16 p.m. | 3 hours, 52 minutes ago
Description :goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.4, goshs enforces the docum...
Related Vulnerabilities
- CVE-2026-40073: @sveltejs/adapter-node has a BODY_SIZE_LIMIT bypass HIGH
- CVE-2026-29002: CouchCMS contains a privilege escalation vulnerability that allows authenticated Admin-level users t HIGH
- CVE-2026-35661: OpenClaw before 2026.3.25 contains an authorization bypass vulnerability in Telegram callback query MEDIUM
- CVE-2026-39315: Unhead has a hasDangerousProtocol() bypass via leading-zero padded HTML entities in useHeadSafe() MEDIUM
- CVE-2026-3360: The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to an Insecu HIGH
Related Coverage
Threat Actors