What is CVE-2026-50139?
CVE-2026-50139 is a race condition vulnerability in the `ShareHandler` of goshs, a SimpleHTTPServer written in Go. Concurrent requests can bypass the download limit due to an unsafe lock-release sequence. Affects versions prior to 2.1.0 and requires an update.
Azərbaycanca: CVE-2026-50139 Go dilində yazılmış goshs SimpleHTTPServer-in `ShareHandler` funksiyasındakı yarış vəziyyəti (race condition) zəifliyidir. Bu, eyni anda edilən sorğuların endirmə limitini yan keçməsinə imkan verir. 2.1.0 versiyasından əvvəlki versiyalara təsir edir və yeniləmə tətbiq edilməlidir.
FAQ2
In which function of goshs SimpleHTTPServer was CVE-2026-50139 discovered?
This vulnerability is related to a race condition in the `ShareHandler` function of goshs SimpleHTTPServer.
Which versions are affected by CVE-2026-50139?
This vulnerability affects versions of goshs SimpleHTTPServer prior to 2.1.0.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.