VDB
Sign up
—

GO-2026-6132

goshs SFTP authentication bypass via empty password (incomplete fix of CVE-2026-40884) in goshs.de/goshs

Quick fix

GO-2026-6132 — goshs.de/goshs/v2: upgrade to the fixed version with the command below.

go get goshs.de/goshs/v2@v2.1.4

Details

goshs SFTP authentication bypass via empty password (incomplete fix of CVE-2026-40884) in goshs.de/goshs

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/goshs.de/goshs
Introduced in: 0

No fixed version published yet for goshs.de/goshs (go modules). Pin to a known-safe version or switch to an alternative.

Go/goshs.de/goshs/v2
Introduced in: 2.1.3Fixed in: 2.1.4
Fixgo get goshs.de/goshs/v2@v2.1.4

References