CVE-2026-64863 is an improper access control vulnerability in goshs affecting versions prior to 2.1.4. The flaw is in the WebDAV request-guard logic in httpserver/server.go, where the wdGuard treated the MOVE method as a write-only operation and failed to enforce deletion-prevention controls such as --no-delete. As a result, WebDAV clients could use MOVE semantics to rename files in a way that deletes the source as part of the operation, and could also overwrite an existing destination when the WebDAV Overwrite header permitted replacement. The issue affects deployments that relied on goshs safety flags to prevent destructive operations, because the guard logic did not correctly distinguish between ordinary writes and operations with deletion side effects. Version 2.1.4 corrects this by introducing dedicated WebDAV guard handling that blocks MOVE when read-only, upload-only, or no-delete restrictions are enabled and adds overwrite checks for COPY behavior under deletion-protection policies.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An improper authorization/access control vulnerability in goshs prior to version 2.1.4 allowed WebDAV clients to delete or overwrite files via the MOVE method because --no-delete was not enforced.
An access control bypass in goshs WebDAV handling prior to version 2.1.4 that allows destructive MOVE operations, and potentially overwriting COPY operations, despite deletion-prevention flags such as --no-delete and --upload-only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.