goshs Go Package: SFTP Authentication Bypass via Empty Password
An early warning has been issued regarding the goshs Go package, which reportedly allows SFTP authentication bypass via an empty password. This appears to be an incomplete fix of CVE-2026-40884, affecting versions up to v2.1.3.
What happened
The goshs Go package is under investigation for a critical vulnerability that allows SFTP authentication bypass using an empty password. This issue is reportedly an incomplete fix of CVE-2026-40884, which previously addressed the empty-username variant but not the empty-password variant. Affected versions include goshs (go) up to and including v2.1.3.
Professional software engineers using the goshs package should monitor for updates and consider applying a workaround or upgrading to a version where this issue is resolved. The severity of this vulnerability is high, and immediate action is recommended to mitigate potential risks.
For more detailed information, consult the primary sources: [GHSA-hq33-8jgp-8qq3] goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite and [GHSA-rjrw-mjq6-hpmm] goshs SFTP authentication bypass via empty password (incomplete fix of CVE-2026-40884).
How 0Day mitigates this
goshs is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.