CVE-2026-30955 PUBLISHED

Gokapi vulnerable to DoS in E2E Metadata Parser

Assigner: GitHub_M
Reserved: 07.03.2026 Published: 13.03.2026 Updated: 13.03.2026

Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to 2.2.4, An API endpoint accepts unbounded request bodies without any size limit. An authenticated user can cause an OOM kill and complete service disruption for all users. This vulnerability is fixed in 2.2.4.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS Score: 6.5

Product Status

Vendor Forceu
Product Gokapi
Versions
  • Version < 2.2.4 is affected

References

Problem Types

  • CWE-400: Uncontrolled Resource Consumption CWE