CVE-2026-28682

Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to version 2.2.3, the upload status SSE implementation on /uploadStatus publishes global upload state to any authenticated listener and includes file_id values that are not scoped to the requesting user. This issue has been patched in version 2.2.3.
Configurations

Configuration 1 (hide)

cpe:2.3:a:forceu:gokapi:*:*:*:*:*:*:*:*

History

09 Mar 2026, 18:50

Type Values Removed Values Added
References () https://github.com/Forceu/Gokapi/releases/tag/v2.2.3 - () https://github.com/Forceu/Gokapi/releases/tag/v2.2.3 - Release Notes
References () https://github.com/Forceu/Gokapi/security/advisories/GHSA-c36c-7pc2-f2ph - () https://github.com/Forceu/Gokapi/security/advisories/GHSA-c36c-7pc2-f2ph - Vendor Advisory
CPE cpe:2.3:a:forceu:gokapi:*:*:*:*:*:*:*:*
First Time Forceu
Forceu gokapi

09 Mar 2026, 13:36

Type Values Removed Values Added
Summary
  • (es) Gokapi es un servidor de intercambio de archivos autoalojado con expiración automática y soporte de cifrado. Antes de la versión 2.2.3, la implementación SSE del estado de carga en /uploadStatus publica el estado de carga global a cualquier oyente autenticado e incluye valores de file_id que no están acotados al usuario solicitante. Este problema ha sido parcheado en la versión 2.2.3.

06 Mar 2026, 05:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-06 05:16

Updated : 2026-03-09 18:50


NVD link : CVE-2026-28682

Mitre link : CVE-2026-28682

CVE.ORG link : CVE-2026-28682


JSON object : View

Products Affected

forceu

  • gokapi
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

CWE-284

Improper Access Control