GO · JULY 2026 · EARLY WARNING

goshs Go Package: SFTP Authentication Bypass via Empty Password

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
CVE-2026-40884GHSA-C29W-QQ4M-2GCVGHSA-RJRW-MJQ6-HPMMSeverity: HIGH

An early warning has been issued regarding the goshs Go package, which reportedly allows SFTP authentication bypass via an empty password. This appears to be an incomplete fix of CVE-2026-40884, affecting versions up to v2.1.3.

What happened

The goshs Go package is under investigation for a critical vulnerability that allows SFTP authentication bypass using an empty password. This issue is reportedly an incomplete fix of CVE-2026-40884, which previously addressed the empty-username variant but not the empty-password variant. Affected versions include goshs (go) up to and including v2.1.3.

Professional software engineers using the goshs package should monitor for updates and consider applying a workaround or upgrading to a version where this issue is resolved. The severity of this vulnerability is high, and immediate action is recommended to mitigate potential risks.

For more detailed information, consult the primary sources: [GHSA-hq33-8jgp-8qq3] goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite and [GHSA-rjrw-mjq6-hpmm] goshs SFTP authentication bypass via empty password (incomplete fix of CVE-2026-40884).

How 0Day mitigates this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If goshs is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Join the 0Day waitlist →

← Back to all threats