CVE-2026-50138 PUBLISHED

goshs: WebDAV listener ignores --read-only, --upload-only, and --no-delete mode flags

Assigner: GitHub_M
Reserved: 03.06.2026 Published: 18.08.2026 Updated: 18.08.2026

goshs is a SimpleHTTPServer written in Go. Prior to version 2.1.0, when goshs is launched with WebDAV enabled (-w), the mode-restriction flags --read-only, --upload-only, and --no-delete are enforced only on the primary HTTP port. The WebDAV port is wired straight to golang.org/x/net/webdav.Handler with no equivalent guard, so an authenticated WebDAV client can PUT, DELETE, MKCOL, MOVE, and COPY despite the operator's stated intent. Version 2.1.0 patches the issue.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
CVSS Score: 8.1

Product Status

Vendor patrickhener
Product goshs
Versions
  • Version < 2.1.0 is affected

References

Problem Types

  • CWE-284: Improper Access Control CWE