A critical vulnerability tracked as CVE-2026-64863 affects goshs before version 2.1.4, allowing unauthenticated remote attackers to bypass the server’s --no-delete and --upload-only protections through flawed WebDAV request handling. The issue stems from MOVE being treated as a write-only method without properly enforcing deletion restrictions, while COPY operations were also insufficiently constrained. An attacker could use crafted WebDAV requests to move, overwrite, or effectively delete files, including by sending MOVE requests with the Overwrite: T header.
The flaw is classified as CWE-284 and has been rated high to critical severity, with reports citing CVSS 9.1 and a published vector of AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H. The vendor fixed the issue in goshs 2.1.4 through commit 0444ac6b1a8176ddae70d940adf7a26b2e5a6c29, adding a dedicated webdavGuard middleware to enforce separate restrictions for MOVE and COPY. Reporting also noted residual edge cases involving broken symbolic links and possible path-normalization discrepancies, underscoring the need for users to upgrade promptly.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
CVE-2026-64863 was publicly described as a critical access-control bypass in goshs WebDAV handling that allowed unauthenticated attackers to move, overwrite, or effectively delete files despite --no-delete or --upload-only protections. The disclosure notes the issue affects versions prior to 2.1.4 and includes severity assessments and exploitation details.
The WebDAV access-control bypass affecting goshs versions prior to 2.1.4 was remediated by introducing a dedicated webdavGuard middleware to enforce restrictions for MOVE and COPY operations. The fix is referenced as commit 0444ac6b1a8176ddae70d940adf7a26b2e5a6c29 and was released in goshs 2.1.4.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvereports.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.