Vendor
critical
advisory
Goshs WebDAV MOVE Method Bypasses No-Delete Flag
1 rule 1 TTPA critical vulnerability (CVE-2026-64863) in the goshs WebDAV server, affecting versions up to 2.1.3, allows an attacker to bypass the `--no-delete` security flag using the `MOVE` HTTP method, leading to unauthorized deletion of source files or overwriting of existing destination files, impacting data integrity.
goshs <= 2.1.3 +1
webdav
vulnerability
file-deletion
data-destruction
server
golang
1r
1t
high
advisory
Goshs File-Based ACL Authorization Bypass via Bulk Zip Download
1 rule 3 TTPsAn unauthenticated attacker can exploit CVE-2026-54719 in goshs versions up to 1.1.4 and goshs/v2 up to 2.1.0 to bypass file-based Access Control Lists (ACLs) and read any file under the webroot using the `?bulk` zip-download route, leading to unauthorized information disclosure.
goshs +1
authorization-bypass
webserver
vulnerability
cve
information-disclosure
1r
3t