Review reviewCritical
CVE-2026-35393
patrickhener goshs
goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.3, the POST multipart upload directory not sanitized. This vulnerability is fixed in 2.0.0-beta.3.
- CVSS
- 9.8
- EPSS
- 0.68% 49.0% percentile
- CISA KEV
- Not listed
- Published
- 2026.04.07