CVEReports
CVEReports

Automated vulnerability intelligence platform. Comprehensive reports for high-severity CVEs generated by AI.

Product

  • Home
  • Sitemap
  • RSS Feed

Company

  • About
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CVEReports. All rights reserved.

Made with love by Amit Schendel & Alon Barad



CVE-2026-54719

CVE-2026-54719: Access Control List Authorization Bypass in goshs via bulk ZIP Download Route

Alon Barad
Alon Barad
Software Engineer

Jul 28, 2026·6 min read·36 visits

Executive Summary (TL;DR)

Unauthenticated network attackers can completely bypass directory-level basic authentication and file blocklists in goshs by requesting protected files via the ?bulk ZIP-download route. This flaw is resolved in version 2.1.1.

CVE-2026-54719 is a high-severity Access Control List (ACL) authorization bypass vulnerability in goshs, a lightweight HTTPS-capable server used for file sharing. The issue allows unauthenticated network attackers to completely bypass file-level and directory-level authentication mechanisms and blocklists by requesting protected resources via the bulk ZIP-download route (?bulk). This vulnerability represents a residual flaw following a partial remediation attempt for CVE-2026-40189.

Vulnerability Overview

The goshs server is a lightweight, Go-based HTTPS-capable system designed for collaborative file sharing and serving local directory structures. To control permissions within the directories it serves, the application implements a file-based Access Control List (ACL) mechanism. Administrators can place a hidden .goshs configuration file inside any directory to enforce Basic Authentication or specify file blocklists, ensuring that sensitive files are protected from unauthorized readers.\n\nThe attack surface exposed by this application includes a bulk download route designed to package multiple files into a single ZIP archive for ease of retrieval. However, in version 2.1.0 and prior, this bulk ZIP download endpoint fails to check the directory-level ACL configuration files before reading resources. Consequently, unauthenticated attackers can request and download any file underneath the server webroot, even if those resources are explicitly blocked or password-protected. This bug class is categorized as Incorrect Authorization (CWE-863) and Missing Authorization (CWE-862).

Root Cause Analysis

The technical root cause of CVE-2026-54719 resides in the request-handling order and the execution flow of the bulk download route. Inside the HTTP router component, incoming parameters are analyzed during an early processing phase via the earlyBreakParameters routine. When the server detects the ?bulk query parameter, control is immediately diverted to the bulkDownload function, which is located inside the httpserver/updown.go source file.\n\nNormally, standard file and directory retrieval paths flow through the doDir, doFile, or sendFile routes. These standard routes act as gates that invoke the findEffectiveACL and applyCustomAuth routines. These security routines parse directory-level configuration files and validate client credentials or verify blocklists.\n\nBecause the bulkDownload route is processed outside the standard file-handling pipeline, it completely bypassed these security routines. The function processed targeted files by merely validating them against path-traversal patterns using sanitizePath to verify that the target path resolved inside the server webroot. Once confirmed, the file contents were retrieved directly from the disk and streamed to the attacker inside a generated ZIP file without checking for local credentials.

Code-Level Analysis of Vulnerability and Patch

An analysis of the patch submitted in commit 7cf911a26ace737e1a55b7dc073e307a25f7fd1d shows how the authorization logic was integrated into the updown.go file. Prior to the fix, the validation loop inside bulkDownload cleaned paths using sanitizePath but did not execute authorization logic:\n\ngo\n// Vulnerable loop in v2.1.0 and earlier\nfor _, file := range files {\n absPath, err := sanitizePath(fs.Webroot, file)\n if err != nil {\n continue\n }\n filesCleaned = append(filesCleaned, absPath)\n}\n\n\nThe patch inserts authorization validation inline directly inside the path sanitization loop of bulkDownload. The fix retrieves the directory's ACL configuration and enforces authentication and blocklist checks prior to adding the file paths to the packaging list:\n\ngo\n// Patched loop in v2.1.1\nfor _, file := range files {\n absPath, err := sanitizePath(fs.Webroot, file)\n if err != nil {\n continue\n }\n // Retrieve the target directory's effective ACL policy\n acl, aclErr := fs.findEffectiveACL(filepath.Dir(absPath))\n if aclErr == nil {\n // Validate authentication state against the ACL\n if ok := fs.applyCustomAuth(w, req, acl); !ok {\n return\n }\n // Verify if the requested file base name is in the blocklist\n if slices.Contains(acl.Block, filepath.Base(absPath)) {\n fs.handleError(w, req, fmt.Errorf(\"requested file is blocked\"), http.StatusNotFound)\n return\n }\n }\n filesCleaned = append(filesCleaned, absPath)\n}\n

Security Weaknesses in Patch and Re-Exploitation Potential

A detailed analysis of the remediation in commit 7cf911a26ace737e1a55b7dc073e307a25f7fd1d reveals three structural design weaknesses that could allow residual bypasses.\n\nFirst, the ACL validation block is guarded by if aclErr == nil. This implementation creates a fail-open condition. If the findEffectiveACL function encounters a file system lock, a file system error, or a parsing error due to a malformed .goshs JSON file, it returns a non-nil error. Consequently, the server silently skips both the applyCustomAuth credential check and the blocklist verification, letting the download complete successfully.\n\nSecond, the blocklist validation uses slices.Contains to check file base names against acl.Block. This lookup is strictly case-sensitive. When goshs is hosted on case-insensitive filesystems (such as Windows NTFS or macOS APFS), an attacker can query for Secret.txt instead of secret.txt. If the blocklist only specifies secret.txt, the blocklist verification returns false, bypassing the block, while the underlying OS still opens and reads the target file.\n\nThird, physical symbolic links are not thoroughly resolved during sanitization. If the server does not enforce physical canonical path resolution, an attacker could exploit a symlink in an unrestricted directory pointing to a file in a restricted directory. This path manipulation can cause the ACL engine to read the security settings of the unrestricted parent folder instead of the target folder's settings.

Exploitation Methodology

An unauthenticated network attacker can exploit the vulnerability by constructing an HTTP GET request to the bulk download endpoint. This request uses the ?bulk query parameter alongside the file query parameter pointing to the target resource. No administrative credentials or prior authentication states are required to invoke this route.\n\nmermaid\ngraph LR\n client[\"Attacker Client\"] -->|\"GET /?bulk&file=/protected/secret.txt\"| router[\"Router (earlyBreakParameters)\"]\n router -->|\"Bypasses Standard Auth Route\"| bulk[\"bulkDownload Function\"]\n bulk -->|\"Reads directly from disk\"| zip[\"ZIP Archiver\"]\n zip -->|\"Streams raw data without basic auth check\"| client\n\n\nTo reproduce the exploit against an affected server, consider a target file located in a basic-auth protected folder named /protected/secret.txt. Sending a direct request for the file returns a 401 Unauthorized response. However, submitting the request as an argument to the bulk endpoint (GET /?bulk&file=/protected/secret.txt) causes the server to reply with a 200 OK status. The response body contains a ZIP archive containing the unredacted target file.\n\nThis same method successfully bypasses the directory-level blocklist. If the operator placed a file named blocked.txt into the ACL blocklist, a standard request results in a 404 response. Constructing a bulk request targeting /protected/blocked.txt bypasses the block check completely, packing the restricted file into the retrieved ZIP archive.

Detection, Logging, and Mitigation Guidance

Security teams should audit their goshs server logs for patterns matching the bulk-download attack vector. Specifically, look for requests targeting the root path / or sub-folders containing the query string ?bulk or &bulk combined with parameters pointing to path structures inside protected directories.\n\nBecause bulk downloads do not generate standard individual file access logs inside the standard handler, finding multiple files being zipped within single log entries is a primary indicator of compromise. Intrusion detection and prevention systems can be tuned to detect and drop these query string arguments.\n\nTo remediate the vulnerability, operators should update the server binary to version 2.1.1 or later. In environments where upgrading is not immediately feasible, operators should run goshs with a server-wide basic authentication profile using the -b CLI argument. This configuration implements authentication via a global middleware handler that processes requests before they reach the bulk download logic. Alternatively, reverse proxies such as Nginx or HAProxy can be configured to drop requests containing the bulk query parameter.

Official Patches

goshs-labsGitHub Security Advisory for goshs bulk download bypass
goshs-labsPatch commit fixing the authorization bypass in updown.go
goshs-labsgoshs release v2.1.1 with vulnerability fixes

Fix Analysis (1)

Technical Appendix

CVSS Score
7.5/ 10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected Systems

goshs (goshs-labs)

Affected Versions Detail

Product
Affected Versions
Fixed Version
goshs
goshs-labs
< 2.1.1v2.1.1
AttributeDetail
CWE IDCWE-862, CWE-863
Attack VectorNetwork
CVSS Base Score7.5 (High)
EPSS Score0.00% (Insufficient telemetry data)
ImpactUnauthenticated arbitrary file read under the server's webroot
Exploit Statuspoc
KEV StatusNot Listed

MITRE ATT&CK Mapping

T1068Exploitation for Privilege Escalation
Privilege Escalation
CWE-862
Missing Authorization

The application fails to perform an authorization check or performs an incorrect authorization check when a user attempts to access a resource through an alternative path.

Known Exploits & Detection

Official AdvisoryAdvisory containing detailed reproduction steps and explanation of the bulk download route vulnerability.

Vulnerability Timeline

Security patch commit submitted by maintainer
2026-06-09
Security advisory published and CVE-2026-54719 assigned
2026-07-28

References & Sources

  • [1]GHSA-rmxw-pq4x-3fvh: ACL authorization bypass via ?bulk
  • [2]Fix Commit: Add ACL/Blocklist verification to bulkDownload
  • [3]goshs v2.1.1 Release Notes
Related Vulnerabilities
CVE-2026-40189

Attack Flow Diagram

Press enter or space to select a node. You can then use the arrow keys to move the node around. Press delete to remove it and escape to cancel.
Press enter or space to select an edge. You can then press delete to remove it or escape to cancel.

More Reports

•about 1 hour ago•CVE-2026-108261
9.3

CVE-2026-108261: Admin Preview Cross-Origin Bypass and GraphQL Hijacking in TinaCMS

A critical origin validation flaw in TinaCMS admin preview allows unauthenticated attackers to bypass cross-origin postMessage checks and execute unauthorized GraphQL queries and mutations under an authenticated editor's context.

Alon Barad
Alon Barad
5 views•5 min read
•about 2 hours ago•CVE-2026-108259
8.2

CVE-2026-108259: Code Injection in @tinacms/cli via Unsanitized Git Branch Name Interpolation

@tinacms/cli prior to version 3.0.0 dynamically constructs client source files using string interpolation without properly sanitizing runtime configuration variables. An attacker with permissions to create a branch or pull request can inject arbitrary JavaScript statements via a crafted Git ref name, leading to execution during automated build processes.

Amit Schendel
Amit Schendel
5 views•5 min read
•about 3 hours ago•CVE-2026-107804
5.3

CVE-2026-107804: Client IP Resolution Flaw & Authentication Lockout in Nginx UI

Nginx UI versions 2.2.0 through 2.5.10 fail to properly configure Gin framework trusted proxies when deployed behind a reverse proxy. This causes all incoming HTTP requests to be attributed to the loopback IP (127.0.0.1), enabling IP allowlist bypass and global authentication lockouts.

Amit Schendel
Amit Schendel
6 views•5 min read
•about 4 hours ago•CVE-2026-107805
7.5

CVE-2026-107805: Unauthenticated Storage Exhaustion in Nginx UI Node Authentication

Nginx UI versions 2.5.0 through 2.5.10 contain an uncontrolled resource consumption vulnerability in the node authentication handler. Unauthenticated remote attackers can exhaust host disk storage and I/O resources by submitting large HTTP request bodies to node-signature endpoints prior to cryptographic signature validation.

Alon Barad
Alon Barad
4 views•6 min read
•about 5 hours ago•GHSA-4HV6-XC92-J86G
6.5

GHSA-4HV6-XC92-J86G: Insufficient Session Expiration in Vikunja WebSocket Authentication Pipeline

Vikunja versions 2.3.0 through 2.6.0 contain an insufficient session expiration vulnerability (CWE-613) within the WebSocket authentication handler. Although Vikunja enforces server-side session tracking and revocation for REST API routes, the WebSocket handshake handler validates cryptographic JWT signatures without querying the database session state. Consequently, revoked JWT tokens can establish new real-time WebSocket connections, and existing connections persist after session revocation.

Alon Barad
Alon Barad
5 views•5 min read
•about 6 hours ago•GHSA-FPRF-R6RV-XG99
6.5

GHSA-FPRF-R6RV-XG99: Cross-Tenant Task Position Recalculation in Vikunja

A cross-tenant boundary breach vulnerability in Vikunja allows an authenticated user to trigger global task position recalculations across all tenant instances by creating a saved filter with an empty filter string payload.

Amit Schendel
Amit Schendel
5 views•4 min read