goshs SFTP Auth Bypass Persists: Empty-Password Variant Evades CVE-2026-40884 Fix
A new GHSA advisory (CVE-2026-62325, CVSS 9.1) reports that goshs v2.1.3's fix for CVE-2026-40884 only blocked empty-username SFTP auth bypass, leaving an empty-password variant (-b 'user:' -sftp) still exploitable for unauthenticated file access. A public PoC exists; no complete patch yet.