CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-64863

criticalCVSS 9.1covered by 2 sourcesfirst seen 2026-07-28
Summary The WebDAV mode-flag guard added to fix GHSA-3whc-qvhv-xqjp still does not enforce --no-delete on the WebDAV MOVE verb. MOVE deletes the source file (rename removes it from its original path), and with Overwrite: T it additionally performs an explicit RemoveAll on the destination. Under -w --no-delete, DELETE is correctly blocked (403) but MOVE still destroys existing files, defeating the documented "Disable the delete option" boundary. This is a residual of the parent fix: the guard classifies MOVE/COPY as write-only verbs (blocked only under --read-only) and never treats MOVE as a delete, so the --no-delete branch never covers it. Affected goshs v2.1.3 (current release, commit ba00ce3). The guard was introduced when GHSA-3whc-qvhv-xqjp was fixed and carries the gap forward. Details httpserver/server.go, wdGuard (lines 237-254): wdGuard := http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { switch r.Method { case http.MethodPut, "MKCOL", "MOVE", "COPY": if fs.ReadOnly { http.Error(w, "read-only", http.StatusForbidden) return } case http.MethodDelete: if fs.ReadOnly || fs.UploadOnly || fs.NoDelete { http.Error(w, "delete disabled", http.StatusForbidden) return } case http.MethodGet, http.MethodHead: if fs.UploadOnly { http.Error(w, "upload-only", http.StatusForbidden) return } } ... MOVE lives in the first case and is gated only by fs.ReadOnly. It is never checked against fs.NoDelete. But MOVE in golang.org/x/net/webdav (file.go, moveFiles) calls fs.Rename(ctx, src, dst), which removes the source from its original location, and when the Overwrite: T header is present it first calls fs.RemoveAll(ctx, dst) on an existing destination. Both are deletions. So --no-delete, whose help text reads "Disable the delete option", does not disable deletion via MOVE. The .goshs ACL layer (webdav_acl.go) checks auth and block-lists only; it does not enforce the mode flags, so it does not close this gap. Proof of concept Reproduced live against goshs v

⚡ Watch CVE-2026-64863

Get an email if CVE-2026-64863 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2026-64863

CVE.org record

Embed the live status

CVE-2026-64863 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-64863 status](https://www.csirts.com/badge/CVE-2026-64863)](https://www.csirts.com/cve/CVE-2026-64863)