Two high-severity vulnerabilities were disclosed in goshs, a Go-based SimpleHTTPServer, affecting multiple pre-release and stable versions. CVE-2026-34581 impacts versions 1.1.0 through before 2.0.0-beta.2 and allows attackers to abuse the Share Token feature to bypass download restrictions. The flaw can expose broader goshs functionality beyond intended file access controls and may lead to code execution. The issue is classified as CWE-288 and was fixed in 2.0.0-beta.2.
A second flaw, CVE-2026-40903, affects goshs versions before 2.0.0-beta.6 and is described as an ArtiPACKED vulnerability that can leak GITHUB_TOKEN values through GitHub Actions workflow artifacts, even when the token does not appear in repository source code. The issue is mapped to CWE-829 and carries high confidentiality and integrity impact, extending concern from application access control to CI/CD credential exposure. The vendor lists 2.0.0-beta.6 as the fix version, and a GitHub security advisory has been published.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
On 2026-04-21, CVE-2026-40903 was published for goshs, describing an ArtiPACKED vulnerability that could expose GITHUB_TOKEN values through workflow artifacts in versions before 2.0.0-beta.6. The vendor indicated the issue was remediated in goshs version 2.0.0-beta.6 and referenced a GitHub security advisory.
On 2026-04-02, a security advisory disclosed CVE-2026-34581 affecting goshs versions 1.1.0 through before 2.0.0-beta.2. The flaw lets attackers abuse the Share Token feature to bypass download restrictions and potentially gain broader functionality including code execution; the issue was fixed in version 2.0.0-beta.2.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.