WebDAV Vulnerability in SimpleHTTPServer by goshs
CVE-2026-50138
8.1HIGH
What is CVE-2026-50138?
The SimpleHTTPServer, 'goshs', is vulnerable when WebDAV is enabled. Prior to version 2.1.0, it fails to enforce mode-restriction flags on the WebDAV port, leading to unauthorized actions such as PUT, DELETE, MKCOL, MOVE, and COPY by authenticated clients. This oversight allows malicious actors to perform operations counter to the operator's intent, potentially compromising data integrity and security. Version 2.1.0 addresses this vulnerability by implementing necessary guards.
Affected Version(s)
goshs < 2.1.0
