Skip to content
cyberMEDIUM2026-04-21 19:39 UTC

CVE-2026-40884 - goshs: Empty-username SFTP password authentication bypass in goshs

CVE ID :CVE-2026-40884 Published : April 21, 2026, 7:39 p.m. | 27 minutes ago Description :goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.6, goshs contains an SFTP authentication bypass when the documented empty-username basic-auth syntax is used. If the server is started with

ORIGINAL SOURCE →via CVE Feed Latest
ADVERTISEMENT
⚡ STAY AHEAD

Events like this, convergence-verified across 689 sources, land in your inbox every Sunday. Free.

GET THE SUNDAY BRIEFING →

RELATED · cyber