{"apiVersion":"1.0","identifier":"CVE-2026-50138","description":"goshs is a SimpleHTTPServer written in Go. Prior to version 2.1.0, when `goshs` is launched with WebDAV enabled (`-w`), the mode-restriction flags `--read-only`, `--upload-only`, and `--no-delete` are enforced only on the primary HTTP port. The WebDAV port is wired straight to `golang.org/x/net/webdav.Handler` with no equivalent guard, so an authenticated WebDAV client can `PUT`, `DELETE`, `MKCOL`, `MOVE`, and `COPY` despite the operator-s stated intent. Version 2.1.0 patches the issue.","publishedAt":"2026-08-18T15:16:54","lastModifiedAt":"2026-08-19T15:17:07","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-50138","cvssScore":8.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","epssProbability":0.00334,"riskScore":0.83,"affectedProduct":"goshs","affectedVersions":"<2.1.0","vulnerabilityType":"Other","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-50138","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-50138","en":"https://www.redsauce.net/en/cves/CVE-2026-50138","fr":"https://www.redsauce.net/fr/cves/CVE-2026-50138","pt":"https://www.redsauce.net/pt/cves/CVE-2026-50138","de":"https://www.redsauce.net/de/cves/CVE-2026-50138","sk":"https://www.redsauce.net/sk/cves/CVE-2026-50138","el":"https://www.redsauce.net/el/cves/CVE-2026-50138"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-50138"}}