CVE-2026-40189 - goshs has a file-based ACL authorization bypass in goshs state-changing routes
CVE ID :CVE-2026-40189
Published : April 10, 2026, 8:16 p.m. | 3 hours, 52 minutes ago
Description :goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.4, goshs enforces the docum...
Related Vulnerabilities
- CVE-2026-35664: OpenClaw before 2026.3.25 contains an authentication bypass vulnerability in raw card send surface t MEDIUM
- CVE-2026-4351: The Perfmatters plugin for WordPress is vulnerable to arbitrary file overwrite via path traversal in HIGH
- CVE-2026-5412: In Juju versions prior to 2.9.57 and 3.6.21, an authorization issue exists in the Controller facade. CRITICAL
- CVE-2026-29002: CouchCMS contains a privilege escalation vulnerability that allows authenticated Admin-level users t HIGH
- CVE-2026-40073: @sveltejs/adapter-node has a BODY_SIZE_LIMIT bypass HIGH
Related Coverage
Threat Actors