{"apiVersion":"1.0","identifier":"CVE-2026-50139","description":"goshs is a SimpleHTTPServer written in Go. Prior to version 2.1.0, `ShareHandler` reads the share token-s `DownloadLimit` under `RLock`, releases the lock, serves the file, then re-acquires the lock to increment the counter. Concurrent requests all read the same `Downloaded`/`DownloadLimit` snapshot, all pass the check, and all are served — exceeding the operator-s intended cap. Version 2.1.0 patches the issue.","publishedAt":"2026-08-18T15:16:54","lastModifiedAt":"2026-08-19T15:17:08","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-50139","cvssScore":5.9,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","epssProbability":0.00246,"riskScore":0.6,"affectedProduct":"goshs","affectedVersions":"<2.1.0","vulnerabilityType":"Other","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-50139","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-50139","en":"https://www.redsauce.net/en/cves/CVE-2026-50139","fr":"https://www.redsauce.net/fr/cves/CVE-2026-50139","pt":"https://www.redsauce.net/pt/cves/CVE-2026-50139","de":"https://www.redsauce.net/de/cves/CVE-2026-50139","sk":"https://www.redsauce.net/sk/cves/CVE-2026-50139","el":"https://www.redsauce.net/el/cves/CVE-2026-50139"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-50139"}}