Dev.to Security πŸ” Cybersecurity πŸ‘ 0 πŸ“– 1 min read

CVE-2026-66064: CVE-2026-66064: Incorrect Authorization and ACL Bypass via Trailing Slash in goshs

CVE-2026-66064: Incorrect Authorization and ACL Bypass via Trailing Slash in goshs Vulnerability ID: CVE-2026-66064 CVSS Score: 5.3 Published: 2026-07-28 CVE-2026-66064 is an access control list (ACL) and blocklist

CVE-2026-66064: Incorrect Authorization and ACL Bypass via Trailing Slash in goshs

Vulnerability ID: CVE-2026-66064
CVSS Score: 5.3
Published: 2026-07-28

CVE-2026-66064 is an access control list (ACL) and blocklist bypass vulnerability in the goshs file server prior to version 2.1.5. Due to an inconsistency between uncleaned raw URI path evaluation and normalized file access, remote unauthenticated attackers can retrieve protected files, including the configuration file containing password hashes, by appending a trailing slash to the requested path.

TL;DR

A trailing slash on request paths allows remote attackers to bypass goshs ACLs and blocklists, exposing sensitive configuration files and password hashes.

⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-41
  • Attack Vector: Network
  • CVSS v3.1 Score: 5.3
  • Exploit Status: PoC / Regression Tests Available
  • Impact: Partial Confidentiality Loss
  • KEV Status: Not Listed

Affected Systems

  • goshs file server prior to version 2.1.5
  • goshs: < 2.1.5 (Fixed in: 2.1.5)

Code Analysis

Commit: f3ef599

Fix security bypass in sendFile by deriving target filename from file.Stat() rather than the raw request URL.

Mitigation Strategies

  • Upgrade the goshs binary to version 2.1.5 or later to apply the official patch.
  • Deploy WAF rules or reverse proxy policies to filter and reject HTTP request paths ending in .goshs/ or other restricted targets with a trailing slash.
  • Restrict the binding interface of goshs to localhost (127.0.0.1) unless external access is strictly required.

Remediation Steps:

  1. Identify all running instances of goshs in the environment and determine their current version.
  2. Build or download goshs version 2.1.5 using 'go install github.com/goshs-labs/[email protected]'.
  3. Replace the old goshs binary with the updated version and restart the file server.
  4. Rotate any bcrypt hashes stored in .goshs configuration files that were exposed to potential exploit attempts.

References

Read the full report for CVE-2026-66064 on our website for more details including interactive diagrams and full exploit analysis.

πŸ“° Read the original article on Dev.to Security

Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes β€” full credit and traffic to the original publisher.