Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rjrw-mjq6-hpmm

Опубликовано: 28 июл. 2026
Источник: github
Github: Прошло ревью
CVSS3: 9.1

Описание

goshs SFTP authentication bypass via empty password (incomplete fix of CVE-2026-40884)

Summary

Start goshs v2.1.3 with -b 'admin:' -sftp. No -fkf. SFTP accepts connections without password. CVE-2026-40884 blocks the empty-username variant (-b ':pass'). The empty-password variant bypasses that fix.

CVE-2026-40884

CVE-2026-40884 (GHSA-c29w-qq4m-2gcv, Apr 13 2026) reported the empty-username case: -b ':pass' with -sftp. sftpserver.go:85 uses &&:

if s.Username != "" && s.Password != "" { sshServer.PasswordHandler = func(ctx ssh.Context, password string) bool { return subtle.ConstantTimeCompare([]byte(ctx.User()), []byte(s.Username)) == 1 && subtle.ConstantTimeCompare([]byte(password), []byte(s.Password)) == 1 } }

Empty username → Username != "" false → PasswordHandler nil. No -fkf means PublicKeyHandler also nil. gliderlabs/ssh sees all handlers nil and sets NoClientAuth = true. Unauthenticated access.

Patrickhener fixed it with a sanity check at sanity/checks.go:114-118:

if opts.FTP && opts.FTPSFTPMode && strings.HasPrefix(opts.BasicAuth, ":") { logger.Fatal("When using SFTP with password authentication, the username cannot be empty. ...") }

HasPrefix(":") catches empty username. It does not catch empty password.

Empty Password Bypass

Same && at sftpserver.go:85. Same nil handler. Different input:

goshs -b 'admin:' -sftp
  • Username = "admin", Password = ""
  • Username != "" && Password != "" → false. Password is empty.
  • PasswordHandler not set. No -fkfPublicKeyHandler not set.
  • gliderlabs/ssh → NoClientAuth = true.

CVE-2026-40884 patched the symptom (empty username) with input validation. Root cause (&&) stayed in the code. v2.1.3 still has it. That makes any unanticipated input format exploitable.

PoC

#!/usr/bin/env bash set -euo pipefail HOST="${1:-127.0.0.1}" PORT="${2:-2121}" echo "[*] Connecting to goshs SFTP at $HOST:$PORT with empty password..." echo "ls -la /" | sftp -o StrictHostKeyChecking=no \ -o UserKnownHostsFile=/dev/null \ -o PreferredAuthentications=none,password \ -o PubkeyAuthentication=no \ -P "$PORT" -b - admin@"$HOST" 2>&1 && \ echo "[+] VULNERABLE: Connected without password!" || \ echo "[-] Connection failed (patched or not running)"

Root Cause

// Wrong: && if s.Username != "" && s.Password != "" { // Correct: || if s.Username != "" || s.Password != "" {

&& blocks PasswordHandler when either field is empty. || installs it when either field is set.

Incomplete Fix

Patrickhener added HasPrefix(":") at sanity/checks.go:116. Two gaps remain:

  1. && still at sftpserver.go:85 in v2.1.3
  2. No HasSuffix(":") check for empty password

Impact

  • Unauthenticated SFTP file access (read, write, delete, rename)
  • Same impact as CVE-2026-40884 via a different input
  • Exploitable with -b 'user:' and no -fkf

Affected

All goshs versions including v2.1.3. CVE-2026-40884 fix does not cover this variant.

Recommended Fix

  1. &&|| at sftpserver/sftpserver.go:85
  2. HasSuffix(":") check at sanity/checks.go
  3. Shared auth handler setup for HTTP and SFTP code paths

Пакеты

Наименование

github.com/patrickhener/goshs/v2

go
Затронутые версииВерсия исправления

= 2.1.3

2.1.4

Наименование

goshs.de/goshs/v2

go
Затронутые версииВерсия исправления

= 2.1.3

2.1.4

EPSS

Процентиль: 27%
0.00344
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-306

Связанные уязвимости

CVSS3: 9.1
nvd
17 дней назад

goshs is a feature-rich single-binary file server for red teamers and developers. From 2.1.3 until 2.1.4, the sftpserver/sftpserver.go password handler used Username != "" && Password != "", so running goshs with -b 'admin:' -sftp and no -fkf left both SFTP authentication handlers unset and allowed unauthenticated file access. This issue is fixed in version 2.1.4.

EPSS

Процентиль: 27%
0.00344
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-306