Skip to content

unauthenticated user share share info

Critical
gtsteffaniak published GHSA-3jmg-p96m-m328 May 14, 2026

Package

gomod http (Go)

Affected versions

<= 1.3.1-stable
<= 1.4.0-beta

Patched versions

1.3.2-stable
1.4.1-beta

Description

Impact

Some sensitive info -- such as source and path can get exposed.

Patches

Update to the latest version

Workarounds

no

Severity

Critical

CVE ID

CVE-2026-46410

Weaknesses

No CWEs